Courses:

Offensive Countermeasures: The Art Of Active Defense: SANSFIRE June 15-16, Blackhat USA July 27-28 & 29-30


Defensive Countermeasures: Foundations for Becoming A Devious Defender: Blackhat USA July 27-28 & 29-30


Conferences:

Check out the entire PaulDotCom crew at BsidesRI June 14-15th!



Subscribe:

Blog:
Videos:
Podcast:


PaulDotCom Español


Hack Naked TV


Hack Naked At Night


Stogie Geeks


Sponsored By:


www.coresecurity.com


www.tenablesecurity.com


www.sans.org



Follow Us On:


twitter.com/pauldotcom

PaulDotCom YouTube Channel


January 2009 Archives

When Metadata steers you wrong...

|

han-solo.jpgAfter our recent post on President Obama's official metadata, erm, photograph, I had the pleasure of exchanging some e-mails on the subject with "ZT".

ZT and I made some assumptions about some of the metadata in the photo:

exiftool -a -u -g1 -b officialportrait.jpg 

Here's the output, significantly shortened for readability:

---- ExifTool ----
ExifTool Version Number         : 7.23
---- File ----
File Name                       : obama-officialportrait.jpg
Exif Byte Order                 : Big-endian (Motorola, MM)

Now, when ZT and I saw the Exif Byte Order value, we both had an "AHA!" moment. We both made the assumption that the JPEG had been created on a Mac with the PowerPC chipset. This knowledge would color some of the potential attacks that we could consider.

I, personally, had a bad feeling about this. So did ZT, so we did our own independent analysis. In my case, I used a photo that I took with my Canon EOS 20D, popped it through some similar post processing tools and exported to JPG on my Intel Macbook Pro. Guess what the
Byte Order was? Yup, you guessed it, Big Endian. Clearly my test case
was not on a PPC or big endian platform.

han-solo.jpgZT discovered some other items using some different methods that didn't make sense either. I'll let ZT share that information if he is able.

I originally thought that it was due to the processor of the camera that created the original output. I even went to far as to determine that different camera models in the EOS line used different endianness processors. I thought I was done.

I was wrong.

ZT passed along this link with comments from Phil Harvey, the author of EXIFtool. To distill the conversation down, it appears that any software (whether it is post processing or firmware) can set the Exif Byte Order, regardless of the endianness of the system. It is merely a way to make sure it is processed the same on any device, and can be implemented in either direction by the whim of the software creator.

This is a perfect example of how assumptions on metadata can steer you wrong. It is important to know what goes on behind the scenes when you attempt to utilize the information, and how it got there.

ZT, thanks for the help and for going on this particular EXIF Metadata journey with me.

The live stream should be active about 9:15 EST, Friday, January 30th. We should begin recording the live show at about 9:30 EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: PaulDotCom UStream Channel

Icecast: PaulDotCom Radio

Please join us, and thanks for listening!

- Larry, Paul & John

fail-owned-insert-memory-card-sign.jpg

PaulDotCom Security Weekly - Episode 137 Part 2 - January 22, 2009

|

Paul, Larry, and John talk security!

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program
  • Be sure to check out "Maltego" from Paterva, try the community edition for free!
  • Don't forget to sign up for our Mailing List, Forums, and log into our IRC Channel!
  • Full Show Notes
  • larry-and-his-toy.jpg

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

PaulDotCom Security Weekly - Episode 137 Part 1 - January 22, 2009

|

Paul, Larry, and John talk security with Dave Shackleford!

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program
  • Be sure to check out "Maltego" from Paterva, try the community edition for free!
  • Don't forget to sign up for our Mailing List, Forums, and log into our IRC Channel!
  • Full Show Notes
  • ShackPwn3d.jpg

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

The live stream should be active about 6:30 EST, Thursday, January 22nd. We should begin recording the live show at about 7:00 EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

This week we have a special guest, Dave "The Shack Attack" Shackleford!

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: PaulDotCom UStream Channel

Icecast: PaulDotCom Radio

Please join us, and thanks for listening!

- Larry, Paul & John

dshackleford.jpg

PaulDotCom Security Weekly - Episode 136 Part 2 - January 15, 2009

|

Paul, Larry, and John talk security!

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program
  • Be sure to check out "Maltego" from Paterva, try the community edition for free!
  • Don't forget to sign up for our Mailing List, Forums, and log into our IRC Channel!
  • Full Show Notes
  • Picture 100.png

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

PaulDotCom Security Weekly - Episode 136 Part 1 - January 15, 2009

|

Paul, Larry, and John talk security with Eric Cole!

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program
  • Be sure to check out "Maltego" from Paterva, try the community edition for free!
  • Don't forget to sign up for our Mailing List, Forums, and log into our IRC Channel!
  • Full Show Notes
  • eric5.jpg

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

Just to be clear, this post is not about political agenda. It is about document metadata.

President Elect Obama released his official photo; the first of a president taken with a Digital camera. obama_frame.jpgThe photographer is the new official White House photographer, Pete Souza. Take a look here. As a photography hobbyist, I've got to say, Mr. Souza does some nice work. But I suspect that there is more to this monumental technology occasion.

JPEG metadata!

Let's analyze the photo with exiftool. First, let's see if any intersting cropping has happened. Maybe he's holding his beloved Blackberry? Let's extract the Thumbnail image:

exiftool -b -ThumbnailImage officialportrait.jpg > thumb.jpg 

How about the Preview image as well:

exiftool -b -PreviewImage officialportrait.jpg > preview.jpg 

Unfortunately, nothing revealed here; the thumbnail exists and is the same as the original photo. The preview doesn't exist and should give you an error when you try to open the output.

So let's look deeper. If we examine the rest of the metadata we encounter other good info. Here's the command:

exiftool -a -u -g1 -b officialportrait.jpg 

Here is some of the output (shortened for readability):

---- ExifTool ----
ExifTool Version Number         : 7.23
---- File ----
File Name                       : obama-officialportrait.jpg
Directory                       : .
File Size                       : 785 kB
File Modification Date/Time     : 2009:01:15 10:12:02
File Type                       : JPEG
MIME Type                       : image/jpeg
Exif Byte Order                 : Big-endian (Motorola, MM)
Image Width                     : 1916
Image Height                    : 2608
Encoding Process                : Baseline DCT, Huffman coding
Bits Per Sample                 : 8
Color Components                : 3
Y Cb Cr Sub Sampling            : YCbCr4:4:4 (1 1)
---- IFD0 ----
Image Description               : Official portrait of President-elect Barack Obama on Jan. 13, 2009...(Photo by Pete Souza)..
Make                            : Canon
Camera Model Name               : Canon EOS 5D Mark II
Orientation                     : Horizontal (normal)
X Resolution                    : 300
Y Resolution                    : 300
Resolution Unit                 : inches
Software                        : Adobe Photoshop CS3 Macintosh
Modify Date                     : 2009:01:13 19:35:18
Artist                          : Pete Souza
White Point                     : 0.313 0.329
Primary Chromaticities          : 0.64 0.33 0.3 0.6 0.15 0.06
Copyright                       : © 2008 Pete Souza
---- ExifIFD ----
Exposure Time                   : 1/125
F Number                        : 10.0
Exposure Program                : Manual
ISO                             : 100
Exif Version                    : 0221
Date/Time Original              : 2009:01:13 17:38:39
Create Date                     : 2009:01:13 17:38:39
...
---- Photoshop ----
Photoshop 0x0425                : Ó\¯ıG›%œrè.ë+finº
XML Data                        : (Binary data 6160 bytes, use -b option to extract)
...
---- XMP-xmpMM ----
Instance ID                     : uuid:1B3097C0FCDADD11A476FD2238D714AD
Document ID                     : uuid:1A3097C0FCDADD11A476FD2238D714AD
Derived From                    : 
...
---- ICC-header ----
Profile CMM Type                : ADBE
Profile Version                 : 2.1.0
Profile Class                   : Display Device Profile
Color Space Data                : RGB
Profile Connection Space        : XYZ
Profile Date Time               : 1999:06:03 00:00:00
Profile File Signature          : acsp
Primary Platform                : Apple Computer Inc.
CMM Flags                       : Not Embedded, Independent

Now we have some interesting data! Date and time of creation and modification (about 2 days from shoot, to selection, proofing and retouch to final version the 13th to the 15th). Inappropriate 2008 copyright declaration for an item created in 2009? How about creation with Photoshop CS3 on a Mac? Camera type (and potential associated "connect" software)? That looks like a couple of vectors for client side exploits there.

There are a few other goodies here the bear investigating, such as the unique uuids and the XML data from photoshop (use the -b flag for exiftool).

So how would one deliver an exploit?

The data reveals the photographer (but we already knew that) and we know he's the new official White House photographer. A Google search for "pete souza obama" give you his website, and the Contact Info page gives you an e-mail address. Now we have a potential delivery method.

redaction-old-way.pngWhat do you think that folks will be e-mailing him about over, say the next 4 years? That history making photo? Chances are. Looks like we have something to talk about at that contact method.

But what about motivation for some? What are also the chances that the photographer will have his potentially compromised computer gear attached to networks with interesting information on them over the next 4 years? Sure, I'm sure the information on those networks is secure and segregated, but it only takes one person to make a mistake. We all know that mistakes happen.

Maybe this is evolution to the digital White House is a good thing. I think that it will take a little bit of time before the new technology catches up with some of the older rules; The government already does a good job of redacting sensitive information from documents. I think that in the coming years they will need to look deeper.

We are entering interesting times. Be careful out there. You too Mr. Souza.

The live stream should be active about 6:30 EST, Thursday, January 15th. We should begin recording the live show at about 7:00 EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

This week we have a special guest, the illustrious Dr. Eric Cole, CEO at Secure Anchor and prolific security author.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.pauldotcom.com:8000

Please join us, and thanks for listening!

- Larry, Paul & John

hackersbeware.jpg

PaulDotCom Security Weekly - Episode 135 Part 1 - January 8, 2008

|

Paul, Larry, and John talk security with special guests from Microsoft!

  • Sponsored by Core Security, listen for the new customer discount code at the end of the show
  • Sponsored by Tenable Network Security, creators of Nessus and makers of the Tenable Security Center, software that extends the power of Nessus through sophisticated reporting, remediation workflow, IDS event correlation and much more.
  • Want to register for any SANS conference? Please visit http://www.pauldotcom.com/sans/ for our referral program
  • Be sure to check out "Maltego" from Paterva, try the community edition for free!
  • Don't forget to sign up for our Mailing List, Forums, and log into our IRC Channel!
  • Full Show Notes
  • microsoft-1978.jpg

Hosts: Larry "HaxorTheMatrix" Pesce, Paul "PaulDotCom" Asadoorian, John Strand

Email: psw@pauldotcom.com

Direct Audio Download

Audio Feeds:

The live stream should be active about 6:30 EST, Thursday, January 8th. We should begin recording the live show at about 7:00 EST. Please keep in mind that these times are all estimates, but we will try to do the best that we can.

Don't forget to join in on the IRC channel during the stream - we can take live comments and discussion from the channel! Find us on IRC at irc.freenode.net #pauldotcom.

When active, the live stream(s) can be found at:

Ustream: http://ustream.tv/channel/pauldotcom-security-weekly

Icecast: http://radio.pauldotcom.com:8000

Please join us, and thanks for listening!

- Larry, Paul & John

We are very proud to present part I of this webcast series where Larry, John, and Paul will explore the "Best Of" security tools. Part I will cover the best of network penetration testing tools. Six tools in total will be discussed, including a tip, trick, and/or use case for each one! Come learn about Nmap's IPv6 scanning, Cain & Abel's VoIP functionality, and much more!

ninjas.jpg

Learn to be a security ninja at this free webcast! Below is the time/date and registration link:

Date: Tuesday, January 13, 2009

Time: 2:00 PM Eastern Standard Time (GMT -05:00, New York)

Duration: 1 hour

Presenters: Paul Asadoorian, Larry Pesce, John Strand

Sponsor: Core Security Technologies

Register Here

Paul Asadoorian

PaulDotCom Enterprises