9 ms·
Analysis of the Comodo hacker's manifesto
- mukyu 16y ago> People believe that once you compile human readable "source" code, > that humans can no longer read the resulting binary "object" > code. That is in incorrect. Code can easily be decompiled > back to (nearly) the original source. In our (Errata > Security) pentests, we regularly find embedded usernames and > passwords that nobody believe hackers can read. It usually > takes us less than 5 minutes. Really now? When you are talking about .NET assemblies this is close to true (in some cases). Not so much for C. So much for a "high-end cyber security consulting company".
- daeken 16y agoDecompilation of native code for x86 and ARM has gotten pretty damn good these days. I still prefer to read straight disassembly, but Hex-Rays has raised the bar in recent years. For all intents and purposes, you can decompile non-obfuscated functions back to effectively original source, barring type propagation issues (which still plague Hex-Rays, sadly).
- alexgartrell 16y agoI'll add for the un-initiated that the ability to read and reverse engineer assembly dumps doesn't require witch craft or use of the force; it's pretty easy. At CMU, it's taught to sophomore Computer Science and Electrical and Computer Engineering Majors [1] [1] http://csapp.cs.cmu.edu/public/bomblab.pdf http://csapp.cs.cmu.edu/public/bomblab.pdf
- daeken 16y agoAgreed. My standard recommendation to those interested is to read the book Reversing by Eldad Eilam (Amazon referral link warning: http://www.amazon.com/gp/product/0764574817/ref=as_li_ss_tl?ie=UTF8&tag=iha0a-20&linkCode=as2&camp=1789&creative=390957&creativeASIN=0764574817 http://www.amazon.com/gp/product/0764574817/ref=as_li_ss_tl?... ) I'm also always willing to help people out here -- if anyone is interested in reversing, feel free to email me.
- burrows 16y agoThat's not accounting for security platforms though. Packers, crypters, vms, etc. Anyone can read assembler.
- mukyu 16y agohttp://i.imgur.com/yKHTP.png http://i.imgur.com/yKHTP.png I sure hope the original source code does not resemble this.
- quanticle 16y agoBarring deliberate obfuscation, it is equally easy to find embedded usernames and passwords in compiled C/C++ as it is in .Net and Java. You simply run `strings' over the binary and look/grep for likely values.
- burrows 16y agoIf the software is crap enough to the point where there are embedded usernames and passwords in the binary, it's barely even worth mentioning.
- moxie 16y agoThere is no magic in a C compiler, it's not like the string literals in your source somehow disappear. An ELF executable has them sitting in the data (or text) segment, so it's not a feat of engineering to pull them out. objdump, or even just running "strings yourbinary" will display them.
- tptacek 16y agoYou cannot "decompile" C/C++ code back to the original C/C++. You can, for a fairly low cost, decompile it back to valid C code. In practice, few people bother; assembly and the control flow graph are ordinarily more than good enough for vulnerability work. I didn't look carefully, but the screenshot in Rob's post didn't look like C/C++ code; I thought it might have been ActionScript.
- mukyu 16y agoIt is C#, thus the talk of .NET. That was my point. No sane person looks at the output of hex-rays and thinks they have received the original source code (minus comments and variable names). It is rare for me to find it even more readable than the assembly listing/graph view.
- moxie 16y agoMy analysis: This Comodo RA got hacked by a script kiddie, and it probably happens all the time.
- ianhawes 16y agoAgreed. He got lucky.
- burrows 16y agoI don't understand why anyone should care what 'errata' thinks. This is some of their past research. http://www.erratasec.com/research.html http://www.erratasec.com/research.html Really.
- hckrnewsx 16y agoerrata's analysis is good, no reason to not accept it. About hacker, we should accept he did something which seemed impossible to most of us, so stop taking is job easy, instead of it suggest solutions for prevention of such attacks in future