owning phone systems - thotcon · 2011. 6. 24. · why it (still) matters sunday, may 15, 2011....

148
Owning Phone Systems Why it (still) matters Sunday, May 15, 2011

Upload: others

Post on 13-Sep-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Owning Phone SystemsWhy it (still) matters

Sunday, May 15, 2011

Page 2: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Josh “savant42” BrasharsAppSec Consulting

Sunday, May 15, 2011

Page 3: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Obligatory “WTF are you?” slide

Pen Tester

Sometimes “telephone enthusiast”

Co-Founder of Mayhemic Labs

dc949

Sunday, May 15, 2011

Page 4: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

But before we begin...

Sunday, May 15, 2011

Page 5: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

My Wife = APT

Sunday, May 15, 2011

Page 6: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

My Wife = APTSeriously.

Sunday, May 15, 2011

Page 7: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Some quick math (Frank^2 loves math)

Sunday, May 15, 2011

Page 8: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

let “d” = Defconlet “m” = Months

Sunday, May 15, 2011

Page 9: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

x = (d * 19) - (m * 9)

Sunday, May 15, 2011

Page 10: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 11: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

And then...

Sunday, May 15, 2011

Page 12: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 13: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

No Defcon.

Sunday, May 15, 2011

Page 14: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 15: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Owning Phones

Sunday, May 15, 2011

Page 16: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Why this talk?

Phones have been around a long time

Tech may change but basic premise is the same

Everywhere

Sunday, May 15, 2011

Page 17: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Pen Testers

Always about the new hotness

Don’t care about the old and busted.

Sunday, May 15, 2011

Page 18: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 19: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

As a result...

Security stopped being important

PBXs became more complex, more obscure

Sunday, May 15, 2011

Page 20: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

“Nobody is attacking phones anymore”

Sunday, May 15, 2011

Page 21: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

“Phreaking is dead”

Sunday, May 15, 2011

Page 22: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Any creature without a predator...

Sunday, May 15, 2011

Page 23: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Remember when web “sites” became “applications?”

An orgy of shitty coding

“We’ll secure it later!”

(Or... never.)

Sunday, May 15, 2011

Page 24: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Needlessly Complex

Sunday, May 15, 2011

Page 25: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

So now we have all these horny bunnies...

Sunday, May 15, 2011

Page 26: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Hundreds of vendors

Acquisitions, Mergers, Leasing, Rebranding

Sunday, May 15, 2011

Page 27: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

In summary...

Telephones, one of the most important assets a business can posses, are more broken than they have ever been.

Sunday, May 15, 2011

Page 28: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Without the phones, most businesses will

hurt.

Sunday, May 15, 2011

Page 29: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Phones are “trusted”

Sunday, May 15, 2011

Page 30: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Phones make money.

Sunday, May 15, 2011

Page 31: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Money for Pen tests.

Sunday, May 15, 2011

Page 32: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

...and money to go to Thotcon.

Sunday, May 15, 2011

Page 33: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

In short, hack harder.

Sunday, May 15, 2011

Page 34: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Pen Test Engagements

Did you make sure to ask? (scope)

How hard do you look at them?

How well do you know telephony?

Sunday, May 15, 2011

Page 35: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The good news?

Sunday, May 15, 2011

Page 36: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The good news?(for pen testers)

Sunday, May 15, 2011

Page 37: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Easier than ever.

Sunday, May 15, 2011

Page 38: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

But first...

Sunday, May 15, 2011

Page 39: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Old School

Sunday, May 15, 2011

Page 40: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sweet!

Scaling!

Redundant!

Secure!

Sunday, May 15, 2011

Page 41: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

...uh, how to do routing?

Sunday, May 15, 2011

Page 42: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Let’s use sound!In-Band Signaling

Sunday, May 15, 2011

Page 43: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

In-Band Signaling

Secret tones within the existing channel

Security Through Obscurity

What could go wrong?!

Sunday, May 15, 2011

Page 44: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 45: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Blind telephone enthusiasts figured it out

Could drop call by whistling

Bell technical journal published frequencies

Phone phreaking is born.

Sunday, May 15, 2011

Page 46: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Making it Happin’

Sunday, May 15, 2011

Page 47: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Blind phreaks used cassettes and pianos to create Multi-Frequency (MF) tones

Met John “Capt. Crunch” Draper

Discovered Cap’n Crunch Bosun Whistle could create 2600 hz tone, seize trunk

Crunch created electronic device to phreak

Sunday, May 15, 2011

Page 48: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 49: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Toll fraud is huge

Production of “Blue Boxes” ignites, Metasploit for phones

Even Woz and Jobs get in on it.

Sunday, May 15, 2011

Page 50: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Genie is out of the bottle

Kids are controlling the phone network

Mafia and Political Dissidents get in on it

“Hacker” culture is in full swing

Sunday, May 15, 2011

Page 51: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Phones are Owned.

Sunday, May 15, 2011

Page 52: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

And then...

Sunday, May 15, 2011

Page 53: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The King is Dead(ish)

Party continued full swing until switches went digital

Control channels are (mostly) no longer in-band

Sunday, May 15, 2011

Page 54: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

We’re cool now, right?

Sunday, May 15, 2011

Page 55: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Wrong.

Sunday, May 15, 2011

Page 56: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Digital Era

Phone switches are basically giant computers.

Computers with modems.

Sunday, May 15, 2011

Page 57: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 58: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Damn kids.

As technology improves, so do attackers

Skill requirement goes up, somewhat

Mafia and Activists are less involved, but hacking remains rampant

Sunday, May 15, 2011

Page 59: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Damn kids.

Personal computers boom, BBSes are born

“K-Rad boards” lead to more fraud

Long Distance is $$$++

Victimless crime?

Sunday, May 15, 2011

Page 60: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Highly Skilled AttackersToll fraud leads the way to owning digital switches

LOD, Masters of Deception (MoD), etc...

Pranking!

Why does my house phone ask me for coins?!?

Eavesdropping

Sunday, May 15, 2011

Page 61: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Highly Skilled Attackers

Calls are maliciously re-routed

Denial of Service

Dogs and cats, living together.

Continued

Sunday, May 15, 2011

Page 62: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Mass Hysteria.

Sunday, May 15, 2011

Page 63: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 64: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

NO CARRIER

Sunday, May 15, 2011

Page 65: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 66: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

R.I.P.

Increased interest in hacking computers

Phone phreaking dies down

Long distance calls become reasonable

IP is the new hotness

BBSes are mostly gone

Sunday, May 15, 2011

Page 67: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

We’re cool NOW, right?

Sunday, May 15, 2011

Page 68: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

...

Sunday, May 15, 2011

Page 69: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 70: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The Honeymoon

Phone calls are now dirt cheap.

As little as .02 CENTS per minute.

Business is STOKED.

Who really cares about toll fraud?

Sunday, May 15, 2011

Page 71: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 72: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Old becomes new.

Sunday, May 15, 2011

Page 73: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Retro is in.

Old attacks, new techniques

Interception is now trivial.

Caller ID Spoofing

Voice Mail Attacks

Swatting

Paris Hilton

Sunday, May 15, 2011

Page 74: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Fast forward to...

Sunday, May 15, 2011

Page 75: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 76: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Today.

The honeymoon is over.

VoIP is everywhere

VoIP has been talked about to death

Everyone uses VoIP.

Sunday, May 15, 2011

Page 77: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Let’s get down to it.

Sunday, May 15, 2011

Page 78: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Threat Modeling

Sunday, May 15, 2011

Page 79: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Attack Vectors

Trust and Social Engineering Attacks

Information Disclosure

Interception

OS Attacks

Toll Fraud

Denial of Service

Sunday, May 15, 2011

Page 80: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Trust

Caller ID Spoofing

This is Jim From IT Services, I hear your computer is running slowly?

This is CEO Jim, gimme your passwords!

Sunday, May 15, 2011

Page 81: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Trust

Sunday, May 15, 2011

Page 82: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 83: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

VoIP Hopper

http://voiphopper.sourceforge.net/

Hop...er... VoIP.

Sunday, May 15, 2011

Page 84: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Information Disclosure

Convergence is here to stay.

“WebEx” style conferencing

Proprietary data uploaded as slide decks

“Confidential”, “Partner Only”

Saved to the file system

Sunday, May 15, 2011

Page 85: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Information Disclosure

Call Logs tell you who calls who

The CEO sure does call his secretary a lot.

Like, a LOT, a lot.

Dude, I think the CEO is @#%ing the secretary.

BLACKMAIL!

Sunday, May 15, 2011

Page 86: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Interception

Sunday, May 15, 2011

Page 87: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The old way

Sunday, May 15, 2011

Page 88: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

The New Way.

Sunday, May 15, 2011

Page 89: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Interception

Protocol attacks to eavesdrop on calls

SIP credentials are trivial to steal and re-use.

MITM

• PBX -> Attacker PBX -> Tubes

• Trivial to record, deny, etc.

Sunday, May 15, 2011

Page 90: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Wireless.

Sunday, May 15, 2011

Page 91: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

OS Attacks

Who patches the phone system? Sys admins? The telephony guys?

Not *MY* Problem, right?

Sunday, May 15, 2011

Page 92: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 93: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Default passwords.

Sunday, May 15, 2011

Page 94: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

“changeme”

Sunday, May 15, 2011

Page 95: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Toll Fraud

Easier than ever before

Like Perl, there’s more than one way to do it wrong.

Dial Plan Logic Errors = Outbound trunks

Default Telnet or VxWorks credentials

Sunday, May 15, 2011

Page 96: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Toll Fraud

Voicemail Collect Charges Attack

Stealing Credentials

Google for sip.conf & iax.conf

Sunday, May 15, 2011

Page 97: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Denial of Service

Childs play.

Sunday, May 15, 2011

Page 98: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 99: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Web Interfaces(Hi Raf!)

Sunday, May 15, 2011

Page 100: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

A whole new way to fail.

Sunday, May 15, 2011

Page 101: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Web Interfaces

Ease of Use = Ease of Compromise

Inherit the OWASP Top 10+++

Sunday, May 15, 2011

Page 102: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Just one example.

Sunday, May 15, 2011

Page 103: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

intitle:”index.of” (sip.conf | iax.conf) “last.modified”

Sunday, May 15, 2011

Page 104: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 105: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Remember when we had to scan for codes?

Sunday, May 15, 2011

Page 106: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 107: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

TFTP?!?

Sunday, May 15, 2011

Page 108: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 109: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 110: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Remember when we had to wardial for this?

Sunday, May 15, 2011

Page 111: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Derail: War Dialing

iWAR by da Beave

WarVOX by HDM

ToneLoc (yes, people still use it)

Sunday, May 15, 2011

Page 112: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Slow or ExpensiveYou pick.

Sunday, May 15, 2011

Page 113: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Pro Tip:

• CNAM lookups!

• Backspoof

• HTTP API

Sunday, May 15, 2011

Page 114: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 115: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Google for Asterisk + “CallerID” or “Asterisk CNAM”

$0.002 a query

(roughly one share of LGTT)

Sunday, May 15, 2011

Page 116: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Oh, right...

Where was I?

Sunday, May 15, 2011

Page 117: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Case Study:Owning the whole network via the phone

Sunday, May 15, 2011

Page 118: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

(not talking about SE here)

Sunday, May 15, 2011

Page 119: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 120: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

ShoreTel Conference

• “Convergence” - IM, Conference, WebEx

• Super secret software (Linux, shhh!)

• No root for you!

Sunday, May 15, 2011

Page 121: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 122: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

admin / changeme

Sunday, May 15, 2011

Page 123: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 124: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 125: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 126: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 127: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

via Burp Suite

Sunday, May 15, 2011

Page 128: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

syscmds.cgi

Sunday, May 15, 2011

Page 129: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Oops.

Sunday, May 15, 2011

Page 130: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

%26 is != “|”This is why phone people shouldn’t write webapps.

Sunday, May 15, 2011

Page 131: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 132: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Savant, who cares? ‘nobody’ is a nobody.

Sunday, May 15, 2011

Page 133: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 134: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 135: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Nightly automated backups.

Sunday, May 15, 2011

Page 136: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

...and it is run by root.

Sunday, May 15, 2011

Page 137: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 138: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 139: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 140: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 141: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Sunday, May 15, 2011

Page 142: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

john

Sunday, May 15, 2011

Page 143: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

“Ok, so that’s one box, impress me.”

Sunday, May 15, 2011

Page 144: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Remember this? Yeah, that’s active directory enabled.

Sunday, May 15, 2011

Page 145: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Simple to patch.

• Tweak login page to capture credentials to file.

• Same host, no problems with SSL cert

• Schedule a conference with CEO, IT, Ops.

Sunday, May 15, 2011

Page 146: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

I accidentally the whole org chart.

Sunday, May 15, 2011

Page 147: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

MSF Module(s)

• ShoreTel Brute by Keith Leigh

• http://code.google.com/p/shoretel-brute/

• MSF Root payload module coming soon.

Sunday, May 15, 2011

Page 148: Owning Phone Systems - THOTCON · 2011. 6. 24. · Why it (still) matters Sunday, May 15, 2011. Josh “savant42” Brashars AppSec Consulting ... “WebEx” style conferencing

Questions?@savant42 on the twitters

Sunday, May 15, 2011