{"id":330,"date":"2021-02-26T23:01:24","date_gmt":"2021-02-26T23:01:24","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=330"},"modified":"2021-05-31T14:26:02","modified_gmt":"2021-05-31T14:26:02","slug":"heartbleed-openssl","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/heartbleed-openssl\/","title":{"rendered":"Heartbleed OpenSSL"},"content":{"rendered":"<h2>1. Introduction<\/h2>\n<blockquote>\n<p>The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL\/TLS encryption used to secure the Internet. SSL\/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some virtual private networks (VPNs).<\/p>\n<p>The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.<\/p>\n<p>Source (and more information): heartbleed.com<\/p>\n<\/blockquote>\n<p>Please answer the following security questions in order to get full points for this challenge.<\/p>\n<ul>\n<li>Explain the security problem<\/li>\n<li>Explain your attack (exploit, screenshot, hacking journal)<\/li>\n<li>Explain mitigation (remedy)<\/li>\n<\/ul>\n<h2>2. Answers and solution<\/h2>\n<h3>2.1 Security Problem<\/h3>\n<p>The <code>SSL standard<\/code> includes a <code>&quot;heartbeat&quot; option<\/code>, which provides a way for a computer at one end of the SSL connection to double-check that there&#8217;s still someone at the other end of the line. This feature is useful because some internet routers will drop a connection if it&#8217;s idle for too long. In a nutshell, the heartbeat protocol works like this:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_1.png\" alt=\"\" \/><br \/>\nThe heartbeat message has three parts:<\/p>\n<ul>\n<li>a request for acknowledgement<\/li>\n<li>a short, randomly-chosen message (in this case, &quot;banana&quot;)<\/li>\n<li>and the number of characters in that message.<\/li>\n<\/ul>\n<p>The server is simply supposed to acknowledge having received the request and parrot back the message.<\/p>\n<p>The Heartbleed attack takes advantage of the fact that the server can be too trusting. When someone tells it that the message has 6 characters, the server automatically sends back 6 characters in response. A malicious user can take take advantage of the server&#8217;s gullibility:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_2.png\" alt=\"\" \/><\/p>\n<p>Obviously, the word &quot;giraffe&quot; isn&#8217;t 100 characters long. But the server doesn&#8217;t bother to check before sending back its response, so it sends back 100 characters. Specifically, it sends back the 7-character word &quot;giraffe&quot; followed by whichever 93 characters happen to be stored after the word &quot;giraffe&quot; in the server&#8217;s memory. Computers often store information in a haphazard order in an effort to pack it into its memory as tightly as possible, so there&#8217;s no telling what information might be returned. In this case, the bit of memory after the word &quot;giraffe&quot; contained sensitive personal information belonging to user John Smith.<\/p>\n<p>In the real Heartbleed attack, the attacker doesn&#8217;t just ask for 100 characters. The attacker can ask for around 64,000 characters of plain text. And it doesn&#8217;t just ask once, it can send malicious heartbeat messages over and over again, allowing the attacker to get back different fragments of the server&#8217;s memory each time. In the process, it can gain a wealth of data that was never intended to be available to the public.<\/p>\n<h3>2.2 Heartbleed Attack<\/h3>\n<p>I Fire up my metasploit console <code>msfconsole<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/metasploit_1.png\" alt=\"\" \/><\/p>\n<p><code>search heartbleed<\/code><br \/>\n<img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_3.png\" alt=\"\" \/><\/p>\n<p><code>use auxiliary\/scanner\/ssl\/openssl_heartbleed<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/metasploit_2.png\" alt=\"\" \/><\/p>\n<p><code>set rhost heartbleed.vm.vuln.land<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_4.png\" alt=\"\" \/><\/p>\n<p><code>set verbose true<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_6.png\" alt=\"\" \/><\/p>\n<p>Before we can attack, we also need to set the parameter <code>set action KEYS<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed_7.png\" alt=\"\" \/><\/p>\n<p>After 200 tries I had still no luck to dump the <code>private key<\/code>. If you wonder why the metasploit version has changed on the screenshot above, that&#8217;s because I thought maybe I&#8217;ve more luck if I try the online attacker VM from the Hackinglab instead of using my local one. Same result&#8230; \ud83d\ude09<\/p>\n<p>I also tried the tool <code>heartleech<\/code>. It&#8217;s allready part of the Hackinglab VM, but it can also be found here: <code>https:\/\/github.com\/robertdavidgraham\/heartleech<\/code><\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heart_leech.png\" alt=\"\" \/><\/p>\n<p>If you have any tipps for me how I can improve this attack, please let me know <code>:)<\/code><\/p>\n<h2>3. Mitigation<\/h2>\n<p>The fix for this problem is easy: the server just needs to be less trusting. Rather than blindly sending back as much data as is requested, the server needs to check that it&#8217;s not being asked to send back more characters than it received in the first place.<\/p>\n<p>That&#8217;s exactly what the OpenSSL fix for the heartbleed bug does:<br \/>\n<code>https:\/\/github.com\/openssl\/openssl\/commit\/96db9023b881d7cd9f379b0c154650d6c108e9a3#diff-2<\/code><\/p>\n<p>PDF Report<br \/>\n<a href=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/02\/heartbleed1.pdf\" class=\"mtli_attachment mtli_pdf\" title=\"heartbleed#1\">heartbleed#1<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL\/TLS encryption used to secure the Internet. SSL\/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-330","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/330","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=330"}],"version-history":[{"count":3,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/330\/revisions"}],"predecessor-version":[{"id":1354,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/330\/revisions\/1354"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=330"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}