Showing posts with label android pentesting. Show all posts
Showing posts with label android pentesting. Show all posts

Sunday, 5 July 2015

Stealing Android Browser Cookies Using Cross Scheme Data Exposure Attack

android-cookies-stealing-cross-scheme-attack- picateshackz.com

tl;dr This exploit is an issue present in Android browser < 4.4 and several other android browsers which allows an attacker to read sqlite cookie database file and hence exposing all cookies. Along with it we will talk about a Cross Scheme Data exposure and intent URL scheme attack in Android < 4.4.


Introduction

During our research on ASOP (Stock Browser) we found out that is is possible to open links to local files using file:// protocol by from a webpage by selecting "Open Link in New tab" from the context menu". This itself is does not represent a vulnerability unless there is a way to read local files and use be able to retrieve the files remotely. However, what caught my attention here is this by default is not permitted browsers such as Chrome, Firefox, Opera etc.

The following screenshot demonstrates the error which is obtained when trying to access a local file from context menu.

android-cookies-stealing- picateshackz.com


Attack Plan 

In order to exploit this issue, the following was the attack plan we came up with:

  1. User visits Attacker.com.
  2. Attacker.com forces a download (exploit.html) on the victim's browser using content disposition header. The purpose of the exploit.html would be read local files and send it back to the attacker.
  3. The victim opens up a link by selecting "Open Link in New tab" which opens the local file exploit.html which was forced as download.
  4. Our file exploit.html would then be reading other local files and sending it back to the attacker.


In order to write an effective exploit for the attack, I coped up with Haru Sugiyama a Security researcher from Japan. He came up with the following POC:


Upon accessing the above page from android browser, it would first force the following file "exploit.html". Both FireFox and Android browser save files to '/sdcard/Download/exploit.html' in case sdcard is available. The exploit.html file would then try reading the other local files. However, this was not easy as it looked at first sight. Let's first talk about how the results from Android Gingerbread were different from Jellbeans.



Android Gingerbread:Observations 

In case of Android Gingerbread Emulator build 2.3 we are easily able to read other local files, this represents a vulnerability as in the browser, as it effectively allows a website to perform cross domains data theft and hence violating the same-origin-policy. The impact however is not large as roughly 11.4% of the users now use Android Gingerbread and they are dying slowly just like windows xp.

android-cookies-stealing- picateshackz.com



Android JellyBeans: Observations

In case jellybeans we found out that a local file was not able to read a local files, We then tried our old null byte trick and it worked like a charm.

The following is the POC:

<button onclick="exploit()">Read iframe</button>
<button onclick="window.open('\u0000javascript:alert(document.body.innerHTML)','test')">Try \u0000</button>
<iframe src="file:/default.prop" name="test" style='width:100%;height:200'></iframe>
<script>
function exploit() {
  var iframe = document.getElementsByTagName('iframe')[0];
  try{
    alert("Try to read local file.");
    alert("contentWindow:"+iframe.contentWindow);
    alert("document:"+iframe.contentWindow.document);
    alert("body:"+iframe.contentWindow.document.body);
    alert("innerHTML:"+iframe.contentWindow.document.body.innerHTML);
  } catch(e) {
    alert(e);
  }
}
</script>

However, due to the discovery of CVE-2014-6041 the nullbytes issue was already patched and the above exploit did not work on patched devices.


Intent URL Scheme Attack

Based upon our above findings it was concluded that in Android Jellybeans the access to local files was not an issue due to the fact that a local file could not read other local files. However Joe Vennix from metasploit team came up with a more strong way to exploit it by abusing the intent scheme. The following paper -> http://www.mbsd.jp/Whitepaper/IntentScheme.pdf describes a potential way of exploiting this issue. The following is the POC described in the paper:

android-cookies-stealing- picateshackz.com


The idea behind the attack vector is to saved a cookie containing javaScript code and trick the victim into opening the sqlite database file. Upon viewing the injected javascript would be executed in the context of a cookie file and would grab the rest of the cookies from the database file. Following is the basic POC, when when executed would read the entire webviewCookieChromium.db file.

<!doctype html> <html> <head><meta name="viewport" content="width=device-width, user-scalable=no" /></head> <body style='width:100%;font-size: 16px;'> <a href='file:///data/data/com.android.browser/databases/webviewCookiesChromium.db'> Redirecting... To continue, tap and hold here, then choose "Open in a new tab" </a> <script>

document.cookie='x=<img src=x onerror=prompt(document.body.innerHTML)>';


</script> </body> </html>

Joe has created a Metasploit module, which automates the process of stealing the cookies and sending it back to you , since the db file also contains httponly cookies as well this attack is quite dangerous.



Steps to Reproduce with Metasploit:

The following screenshots would walk you through the process of exploiting and retrieving the cookies:

If you don't know how to use metasploit then i suggest you to read this article: 
Introduction to using Metasploit in Kali Linux


Step 1 - Setting up the Module

android-cookies-stealing- picateshackz.com


Step 2 - Stealing The Cookies


All you need to sit back and watch the cookies coming to you.

android-cookies-stealing- picateshackz.com 3


Step 3 - Enjoy


android cookies stealing- picateshackz.com


Patch

The access to the data directory was tightened back in Feb 2014, however due to the android patch policies the patch did not make to most of the vendors.

Credits

I would like to thank Tod Beardsley and Joe Vennix from the metasploit team for their extensive support with analyzing and helping to co-ordinate with Google effectively. As well as Haru Sugiyama for his help and support.



Friday, 3 July 2015

Android Browser - Address Bar and Content Spoofing Vulnerability

android_address_content_spoofing- picateshackz.com


Address Bar Spoofing Vulnerability

Google security team themselves state that "We recognize that the address bar is the only reliable security indicator in modern browsers" and if the only reliable security indicator could be controlled by an attacker it could carry adverse affects, For instance potentially tricking users into supplying sensitive information to a malicious website due to the fact that it could easily lead the users to believe that they are visiting is legitimate website as the address bar points to the correct website.

Few months ago it discovered an address bar spoofing vulnerability affecting Android Stock Browser on all Android versions. The tests were carried out on Android Lollipop and later were confirmed on prior versions.

The issue is caused due to the fact that the browser fails to handle 204 error "No Content" responses when combined with window.open event and therefore allowing us to spoof the address bar.


Steps To Reproduce

1) Visit http://jsfiddle.net/dy4swq4o/show/ with Unpatched Android Stock Browser.

2) click the "Click here to be redirected" button

3) Android browser will open a new tab with the browser pointing to "http://www.google.com/csi" in the address bar, which makes the victim believe that they are infact visiting a legitimate website, however in reality the page is not hosted on google.com. 

4) As soon as the victim enters his/her credentials, they are sent to attacker.com.


Note: Please visit https://jsfiddle.net/dy4swq4o/ for unrendered version of the POC.


Proof of Concept

The following is a screenshot of Samsung Galaxy S5 running latest android stock browser, as you may notice that the address bar points to https://www.google.com/csi (Which returns a 204 response), which makes the user believe that he is infact visiting a legitimate site however it's hosted on attacker's domain name. 

android_address_content_spoofing- picateshackz.com

Notes: Joe Vennix suggests that you might have to play with my timeout value , and he found 1500 - 2000 to work much more consistently. This issue is due to the fact that, In case if the timeout fires too soon (before the NO CONTENT response is received from gmail.com), the new page will just have a blank URL bar.


Credits

The proof of concept was initially created by "Rafay Baloch", however it was later modified and improvised by "Joe Vennix" and "Tod Beardsley" from Rapid7 team handling the disclosure.


Mitigation

The Android security team has responded by releasing patches committed to both Kitkat and Lollipop main distributions. Users are advised to contact their carriers to determine if they have received updated versions of these operating systems."



Kitkat Content Spoofing Vulnerability

The following is a low risk vulnerability that was found few months ago while testing the latest Android Stock browser on Android Kitkat. The issue that was found is commonly referred as Content spoofing Vulnerability or dialog box spoofing vulnerability which could be used to fake an alert message on a legitimate website.

In other words, we could display an alert box (Of our choice) on the site of our choice. Whereas in chrome, Firefox and other browser the alert box appears on correct tab.


POC

<a onclick="test()">CLICK</a>
<script> function test()
{ window.open('http://bing.com/') setTimeout (function(){alert("HACKED");}, 5000) }
</script>


Upon executing the above code, the alert box would be displayed on bing.com.

android_address_content_spoofing- picateshackz.com

Technical Details

The issue resides inside of the ASOP browser, and more specifically due to the fact the webview fails to overwrite the WebChromeClient.onJsAlert() method which is responsible for displaying the javascript alert box and this way webview is not able to switch the JsAlert() to the correct tab.




Saturday, 7 February 2015

How to Install Kali Linux on Android - Tutorial With Screenshot

Kali Linux on Android - picateshackz.com

 Hacking with Kali Linux, hacking becomes much easier since you have all the tools (more than 300 pre-installed tools) you are probably ever gonna need. Others can be downloaded easily.


In my previous article i am explained about Introduction To Hacker’s OS: Kali Linux And Setup Tutorial for PC, but in this article i have a great idea to setup Kali Linux on Android devices, it will help you to turn your android device into a hacking tool with the greatest Hacker's OS Kali Linux.





Let's Start,
This tutorial helps you to run any GNU/Linux in your andoid device here am going to show the easy way to install Kali Linux in android phone and kali linux is the best hacking software ever.


Installing Kali Linux in Android phone is very very easy one you need the following requirements.


PREREQUISITES


1. Rooted Android Device.(Refer Here)
2. Busybox Installer.(Download)
3. Linux Deploy.(Download)
4. Android VNC Viewer.(Download)
5. 4GB Free Space on your External Memory.
6. High Speed Net Connection.


STEP 1:(Rooting Android Device)


Root your android device with the given tutorial.


STEP 2:(Installing Busybox)


First we need to install UNIX Scripts into our device using the Busybox Installer app. Download the app from above given link and install it in your tablet linux. Open the app and follow the given steps. 


1.Choose the Busybox Version from the drop down menu.

Kali Linux on Android - picateshackz


2.Tap the install buttom.

Kali Linux on Android - picateshackz


3.It will download the scripts to be install.

Kali Linux on Android - picateshackz


4.After installing you will get the success message.

Kali Linux on Android - picateshackz

Now you have successfully installed busybox in your android device.

Note: If the installing fails you need to choose different Busybox versions.


STEP 3:(Configure Linux Deploy)


Linux Deploy is the Official app to Download and install kali linux in android download the app and install it in your android. Now open the app and follow the given steps.

1.Tap the properties icon it will opens the properties screen.

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz


2. In properties select the distribution to be install.

Kali Linux on Android - picateshackz


3. Leave some setting to be default and select the desktop environment to GNOME.

Kali Linux on Android - picateshackz


4.Select all the components in Components Menu.

Kali Linux on Android - picateshackz


5. In GUI Settings just interchange the height and width values.

Kali Linux on Android - picateshackz


6. Now select the install button and then OK.

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz


7. Now the installation process starts be patient for the installation proccess to complete it takes too much of time to complete and prevent the incoming SMS and Voice Calls or Turn off the SIM and use WIFI to download because intreption of cellular data leads to cancellation of download process.

Kali Linux on Android - picateshackz


8. I cant add the screenshot of completed process because I already did it. Now tap the START button  and tap OK it will mount the linux file.

Kali Linux on Android - picateshackz


9. Note the IP address in the top left corner of Linux deploy it changes periodically.


STEP 4:(Configure Android vnc)


Now open the Android VNC Viewer, Enter Nickname and password the default password for Kali Linux ischangeme nd give the IP address copied from Linux deploy for me it is 192.168.1.35 and the port is 5900 and username is android and then color is 24-bit color(4bpp). Finally tap the Connect button you will see the Kali Linux in your android device.

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz


STEP 5:


To close the Kali Linux, exit from the VNC viewer and then go to Linux Deploy and simply tap the Stop Button and the OK it will close the Mounted Image. You can use the Linux Penetration Testing on your android phone and it is most popular for cyber hacking.

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz

Kali Linux on Android - picateshackz


I hope this will work I tested it in my XOLO A500S IPS, Infocus M2 3G and in Samsung Galaxy S3. If you have any problem please feel free to ask me. Thank you...