Most Recent Posts From My New Blog

Sunday, April 13, 2008

NEO InfoSec Forum Meeting This Wednesday!

This month's NEO InfoSec Forum meeting is this Wednesday. We have three talks lined up on Nagios, FreeRADIUS and Notacon. Everyone is welcome to attend. Meetings are free and include free pizza! More information on the meeting can be found here.

Cheers,
Matt

Friday, April 4, 2008

Bugtraq Post - Slowly Closing Door Race Condition

I'm not sure if this is an April Fools joke or not given the orginal release date. Either way on April 1st I)ruid from Computer Academic Underground released an interesting and entertaining security alert on a race condition that can exist with slow closing doors. I especially love the section explaining how to exploit the race condition.

It is always interesting to see what computer security folks come up with when they analyze physical security systems. Matt Blaze has a number of fascinating articles along these lines focusing on the mechanical security features used in locks and safes. I suspect we'll see more alerts like this as the convergence between physical and logical security continues to evolve.

Below is the advisory (original source):
                    ____      ____     __    __
/ \ / \ | | | |
----====####/ /\__\##/ /\ \##| |##| |####====----
| | | |__| | | | | |
| | ___ | __ | | | | |
------======######\ \/ /#| |##| |#| |##| |######======------
\____/ |__| |__| \______/

Computer Academic Underground
http://www.caughq.org
Security Advisory

===============/========================================================
Advisory ID: CAU-2008-0001
Release Date: 04/01/2008
Title: Slowly Closing Door Race Condition
Application/OS: Physical Structures
Topic: Physical structures employing exit doors with locks
are vulnerable to a race condition.
Vendor Status: Not Notified
Attributes: Physical, Race Condition
Advisory URL: http://www.caughq.org/advisories/CAU-2008-0001.txt
Author/Email: CAU
===============/========================================================

Overview
========

Physical structures which employ automatically locking doors to secure
exit points expose a race condition which may allow unauthorized entry.


Impact
======

Malicious outsiders may be able to enter a structure via an exit point.

Exit points may additionally provide an exit from a secure area of the
structure, allowing an outsider entering through the exit point to gain
direct access to the secure area.


Affected Systems
================

Physical structures which employ automatically locking doors at exit
points of the structure.


Technical Explanation
=====================

An exit's lock[1] generally converts a two-way door into a one-way
door, allowing a person to traverse the door's threshold in one
direction but not in the other. These types of locks are used to
secure exit points of structures so that people may exit via the door
but not re-enter without disabling the lock through force or
authentication.

When a person exits the structure through an exit point which is
secured by such a mechanism, a race condition exists wherein a
malicious outsider may be able to reach the door and enter through it
before it closes and locks itself.

Many doors, especially heavier ones, also employ closing mechanisms[2]
which are designed to cause the door to close slowly so as not to slam
the door shut and damage the door frame, or damage any human appendage
which may be in between the door and it's frame. Such closing
mechanisms can greatly increase the amount of time that the race
condition exists.


Solution & Recommendations
==========================

1) Always ensure that personnel exiting an exit door wait outside the
door until it has completely closed and locked before walking
away.

2) Employ a double door system such as is used in an air-lock where
the interior door must be secured prior to the exterior door being
allowed to open.


Exploitation
============

First identify the exit point that you want to exploit. Stand at a
safe distance during a high-traffic time and watch for people to use
the exit point. Time how long it takes for the door to close and
lock itself when someone traverses the exit point.

Next, identify a safe hiding place near the exit point, preferably
in a direction that would be behind a person exiting the door, but
which is within a distance to the exit point which you could traverse
in under the door's closing time at a brisk pace or run.

Finally, hide in this location during a lower traffic time and wait
for someone to utilize the exit point. After they have exited the
door and are walking away, run to the door and enter before it has
closed and locked. Extra points are awarded for a spectacular dive
and/or roll to catch the door at the very last second.


References
==========

[1] http://en.wikipedia.org/wiki/Lock_%28device%29
[2] http://en.wikipedia.org/wiki/Door_closer


Credits & Gr33ts
================

Theodor Geisel, AHA!, NMRC, Uninformed Journal, dc214

Thursday, April 3, 2008

Notacon This Weekend

Tomorrow I'll be heading off the Notacon for the weekend. If anyone else is going to be there and wants to meet up drop me an email or leave a comment.

Cheers,
Matt

Monday, March 31, 2008

Wireless Vulnerabilities and Exploits (WVE) Database

The Wireless Vulnerabilities and Exploit (WVE) database is a wonderful wireless security resource. The WVE is basically a clearing house for wireless vulnerabilities and exploits. It is similar to the Common Vulnerabilities and Exposure (CVE) database however the WVE focuses on wireless technology. Also the CVE database only tracks vulnerabilities where the WVE database tracks vulnerabilities and the exploits that can be used to attack those vulnerabilities.

When assessing the security of a wireless device this is one of the research tools I use to determine if there are any known weaknesses in that device.

If you have any interest in wireless security I highly recommend you explore the site and monitor it for updates. They even offer an RSS feed of the recent entries.

Cheers,
Matt

Wednesday, March 19, 2008

The Biggest Paradigm Shift in Mobile Security is...

This blog has been moved to a new site. This post can now be found here. Please update your bookmarks and links.

Tuesday, March 18, 2008

OWASP Meeting This Thurseday

The February OWASP meeting that got canceled has been reschedule to Thursday March 20th. It will be held at the Winking Lizard in Bedford Hts. More information and details on how to register can be found here.

Note: Last I checked the link had not been updated to include the new meeting time. However all the other information is still valid.

Cheers,
Matt

Saturday, March 15, 2008

Been Speaking, Looking for Feedback

I've been doing a lot of public speaking recently. The past two Wednesdays I gave workshops on how to use NetStumbler and Kismet to find wireless networks, and last Friday I gave a talk covering the risks related to m-commerce. If any of my readers attended these talks and have comments on ways to improve them please let me know by posting suggestions in the comments section, you can even post them anonymously if you like. I am always interested in improving my presentations so any feedback is greatly appreciated!

Cheers,
Matt