Sniffing Passwords with Wireshark

Installing the Wireshark Packet Sniffer

What you need for this task:
  • A computer with Internet access. You need administrator privileges.
  • I wrote the instructions with Windows 7
Open a Web browser and go to WireShark.org

Download and install the latest version of Wireshark. The installer will also install WinPCap.

Reboot the machine to load the WinPCap driver

Note: If you have problems with WinPCap under Windows 10, get the driver from http://www.win10pcap.org/

Starting a Packet Capture


Start Wireshark.

In the Capture menu, select Options

clip_image002

Make sure your interfaces are in promiscuous mode. Press Manage Interfaces.

clip_image004

In the Manage Interfaces windows, select the desired interface where you want to capture traffic

clip_image006

Back to the starting windows, double click on the interface to start the capture

clip_image008

You should see packets being captured and scrolling by, as shown below on this page. Every packet sent from or to your machine is shown here. But it shows a lot more information than you usually want to know.

clip_image010

Sending a password to a test site


Open a Web browser and go to:

http://testphp.acunetix.com/login.php

or

http://testasp.vulnweb.com/Login.asp?RetURL=%2FDefault%2Easp%3F

Enter a Username of YOURNAME@SOMEDOMAIN.LOCAL (using your own name, not the literal string "YOURNAME") and a password like topsecretpassword, as shown below:

clip_image011

Click the "login" button.

The login will fail but that is not important.

In the Wireshark window click on the red square button to stop the capture

clip_image013
 

Finding the password in Wireshark


In the Wireshark window, in the Filter bar, type as filter some of the text you entered as username, as shown below:

frame contains rumos.local

clip_image014

Wireshark shows an HTTP packet containing the searched text. In the upper pane of Wireshark, right-click the HTTP packet and click "Follow/TCP Stream", as shown below.

clip_image016

Expand the "Follow TCP Stream" box so that you can see YOURNAME and the topsecretpassword, as shown below.

clip_image018
 

Conclusion:


When login into plain HTTP websites, your credentials are sent in plaintext and can be easily captured and discovered.


Using a secure website


Start another packet capture by going to Wireshark’s menu bar, click Capture, Start (or click the blue fin button on the top left. A pop-up asks "Do you want to save the captured packets before starting a new capture?" Click "Continue without saving".

In a Web browser, go to http://gmail.com. Notice you are immediately redirected to https://accounts.google.com. (You can go to any safe website, it doesn’t have to be on GMail)

Enter a valid Gmail account and the same password topsecretpassword, as shown below.

Click the "Sign in" button.

clip_image019

Gmail will reject the credentials, just like the other website did.

In the Wireshark window, click Capture/Stop.
 

Searching for the password in Wireshark


In the Wireshark menu, click Edit/Find Packet.

clip_image020

In the "Wireshark: Find Packet" box, click the String button.

Enter a search string of secret, as shown below.

clip_image021

In the "Search In" section, click "Packet bytes". Click Find.

clip_image022

A message appears briefly in the status bar at the bottom of the Wireshark window, saying "No packet contained that string", as shown below. This means the password text cannot be found in any of the captured packets because the information exchange with Gmail’s website was properly encrypted.

clip_image024
 

Conclusion:

When login into secure websites, user credentials are encrypted by the SSL/TLS protocol and although the packet sniffers manages to captures the traffic, it’s virtually impossible to see the content of the encrypted information exchanged with the secure website

Previous post: Securing Virtual Machines in Windows 10

Next post: Cracking Windows Passwords

Securing Virtual Machines in Windows 10

 

Trusted Platform Module (TPM)


A TPM is a specialized chip soldered on an endpoint device’s motherboard that provides hardware-based device authentication, tamper detection, and encryption key storage.
The TPM generates RSA encryption keys specific to the host system making it impossible to recover data from an encrypted hard drive in a different computer than the one in which it was originally installed.
Further, the TPM generates a unique digital signature from the motherboard in which it was originally embedded, foiling any attempts to move the TPM chip itself to another machine.
This secure cryptographic integrated circuit provides a hardware-based approach to manage user authentication, network access and data protection. The TPM can be used with any major operating system and works best in conjunction with other security technologies such as firewalls, antivirus software, smart cards and biometric verification.

Secure Boot


When you boot a modern Windows PC, the Secure Boot feature in the UEFI firmware checks the operating system loader and its drivers to ensure they’re signed by an approved digital signature. On Windows PCs, the UEFI Secure Boot feature generally checks to see if the low level software is signed by Microsoft or the computer’s manufacturer. This prevents low-level malware like rootkits from interfering with the boot process. Note that the latest versions of popular Linux distributions, including Ubuntu, Mint and Fedora, already install just fine on a Windows PC that has Secure Boot enabled.
Besides, Linux operating systems can now take advantage of secure boot in Generation 2 VMs in Hyper-V on Windows 10. Both Ubuntu 14.04 and SUSE Linux Enterprise Server 12 are currently supported, and this trend will widen over time. These Linux VMs must be configured to use the Microsoft UEFI Certificate Authority (CA) as a Secure Boot template.

Linux VM Secure Boot

Measured Boot


One of the most concerning trends in malware over the last few years is the appearance of increasingly sophisticated rootkits that can hide from detection. In order to detect and resolve these early boot threats, Windows 8 introduced a new feature called Measured Boot, which measures each component, from firmware up through the boot start drivers, stores those measurements in the TPM on the machine, and then makes available a log that can be tested remotely to verify the boot state of a client machine.
The Measured Boot feature provides antimalware software with a reliable (resistant to tampering and spoofing) log of all boot components that started before the antimalware software. Thus, the software can use the log to determine whether components that ran before it are trustworthy or if they are infected with malware.



Virtual TPM on Windows 10 Hyper-V


Windows 10 version 1511 (Fall Update) brought a number of new features to Microsoft’s latest OS, namely the ability to use a virtual TPM inside Generation 2 (link) Virtual Machines. This virtual TPM isn’t emulated in software and therefore a physical TPM is required in the host device. If your machine doesn’t have a TPM (or if the chip is disabled in your BIOS/UEFI), your VM Security settings might be missing the entire Trusted Platform Module section.

Virtual TPM
As you can see in the picture, in order to use the virtual TPM in a VM, you’ll first need to enable the Isolated User Mode on your host computer. This can be easily done by turning on the required Windows feature and rebooting.

Isolated User Mode
The next step is to turn on Virtualization Based Security using the Local Group Policy Editor (gpedit.msc). Set the policy to Enabled and reboot again.

Device Guard
Last but not least, you need to configure Windows Remote Management on your host machine. Just run winrm quickconfig from an elevated command prompt.

Once you complete the above procedures, you can now enable the virtual TPM in your Generation 2 VMs.

Virtual TMP Inside a VM

Next post: Sniffing for Passwords with Wireshark

The Future of Cyber Threats


Cyber threats appear as quickly as new technologies themselves, and with computers now being such a critical part of our infrastructure – from our smartphones and cars to national energy systems and even prisons – the potential for damage is catastrophic. Large global multinationals and small local businesses and startups use the online infrastructure to facilitate economic and technological innovation. Defense and intelligence agencies depend on cyber networks to manage far-flung operations, analyze intelligence data and implement homeland security, military logistics and emergency services.

Global dependence on the Internet grows every day and many nations are now depending on a cyber infrastructure that enables the operation of financial markets, transportation networks, taxation and energy grids, as well as the public agencies protecting the health and security of their citizens. With this growth come ever-greater risks as well as opportunities.Advanced persistent threats reflect the risks posed by adversaries with the sophistication, resources and determination to cause real and permanent damage by exploiting the architecture of networks, and of cyberspace itself.

The biggest threat is state involvement. Where a rogue phisher or malware attack might be the criminal equivalent of a street mugger, state-sponsored attacks come with all the resources and technological sophistication of James Bond. Resistance is extremely hard and these attacks are very difficult to attribute to anyone; they can be routed via any country or written in any language.

Because the Internet is an evolving technology that carries enormous potential and vulnerabilities, cybersecurity problems implicate questions of Internet freedom, network architecture and the economic potential for cyberspace. We are at the beginning of a new and dangerous era of cyberwarfare and governments should be encouraged to cooperate in order to identify and punish the criminals. But let's not be naïve about it, they will also be engaging in cyber espionage against each other.  

Cyberthreats for 2013

 

Cloud-Based Botnets


The trend to move the computer infrastructure to the cloud can not only jeopardize data, but can also be used to quickly create a “zombie army” – also known as botnet. Over the last years, Africa has become highly connected but many of the operating systems in use are pirated, meaning they are not receiving patches or updates. Therefore, Africa is a huge target for hackers and it is being used as a hub to target other countries – using command and control attacks, denial of service, phishing and spam.

The new undersea fiber optic cable along the east coast of Africa has enabled rapid growth in the number of users obtaining high speed connections to the internet creating a great opportunity for attackers to infect new machines and create new bots. A growing number of users in countries served by the cable had access to broadband links but without awareness about the need for computer protection, opening a new front for botnets.

Now, Africa is not attacking – they are being attacked and used. While businesses in Africa get some security, government and end users are totally exposed due to a of lack of awareness and money to invest in safe and legitimate software.
 

More Dangerous Malware



Malware creators will harden their software with techniques similar to those used in Digital Rights Management (DRM), which locks malware to infected systems. Malware attackers are also enhancing their abilities to compromise Mac operating systems and mobile devices, making their software cross platform and taking advantage of all the new smartphone features.

  Advanced Malware Lifecycle  

Malicious software developers will become more aggressive and will continue to refine their techniques to avoid defenses and to harden their software, making it extremely difficult for automated systems to detect, thus preventing its easy removal.

   Advanced Malware Infection  

Search History Poisoning



Search engine poisoning is what happens when attackers manipulate a search engine’s algorithms to control the search results. Criminals often do this to get their own websites or clients’ websites on the first page of results. Search history may be the next step. With search history poisoning, criminals or politicians can manipulate a victim’s search history using cross-site request forgery.

Instead of compromising a computer, the attacker benefits because the manipulated history can become part of a user’s online profile so wherever that person goes online the forged history follows regardless of what device is used. The goal of this technique is to change what the victim reads online and is already being used by governments censoring what their citizens read.

Therefore, this can be a very powerful propaganda technique for politicians but also a super marketing idea for businesses trying to promote their products and services. This type of manipulation can also be used on social media sites, such as Facebook and Twitter, to falsely create an impression that there are many viewpoints to a certain post or that something is popular, when in reality, all boils down to one person is manipulating the algorithms.

 Previous Chapter