Earlier quoted context omitted.
I don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.
If they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.
Ghidra: A software reverse engineering suite of tools developed by the NSA
111–120 of 147 posts
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#112Earlier quoted context omitted.
but literally the most important when you need to attack air gapped machine
No, it's not the most important. The most important was clearly obtaining the PLC zero days to infect the physical machines. It's unclear to me why you choose to be so explicitly obtuse but in any case, for your own personal edification, feel free to read some details on how it went down - [0] https://www.wikiwand.com/en/Stuxnet [1] https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ [1] https://www.hsdl.org…
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#113Earlier quoted context omitted.
Some people like me, can hear data movement on PCB's. The electrical circuit has noise signatures which change if other data is injected by Ethernet over powerline equipment. The distance from which this works is quite large, up to a few houses with consumer hardware. Fear equipment with built-in LoFi.. that's reachable without cooperation of LAN equipment..
When you say you can “hear data movement on PCBs”, do you mean you have some kind of superhuman ability, or that you know how to use some combination of instrumentation and analysis to “hear” the data?
Typically DC-DC converters are the easiest thing to hear, because of the sheer amount of energy involved. Normally these are operated at PWM (pulse) frequencies well outside hearing range—40–300 kHz—but often enough the feedback scheme for controlling those pulses oscillates in a way that generates audible subharmonics whose frequency depends on the power draw at any given moment. Modern computers are full of DC-DC converters.
Also, though, it's common for computers to contain sensitive low-noise audio-frequency amplifiers connected to a periodic sample-and-hold circuit which can alias high frequencies down into the audio range, with the output hooked up to loudspeakers; these are called "sound cards" and it's not at all unusual for them to produce clearly audible sounds that depend on the computation happening, at least if you turn the volume up all the way.
Finally, regular, non-super, humans can directly perceive radio frequency emissions as sounds: "The human auditory response to pulses of radiofrequency (RF) energy, commonly called RF hearing, is a well established phenomenon. RF induced sounds can be characterized as low intensity sounds because, in general, a quiet environment is required for the auditory response... Effective radiofrequencies range from 2.4 to 10000 MHz." https://pubmed.ncbi.nlm.nih.gov/14628312/
So "hearing data movement" because of "noise signatures that change" is not at all unusual. You can probably do it yourself if you have a quiet room to listen in. It's plausible that Ethernet-over-powerline equipment could produce audible sounds from the power supplies in the same house or nearby houses, but I haven't observed that myself and this is the first time I've heard of that happening.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#114Earlier quoted context omitted.
They kind of are though. If you have a LOT of money, time, and personnel -- and they do -- you can find a lot of vulnerabilities.
Yes and we've seen their shit get leaked over the years. From that we can see clear patterns in what they view as valuable and where they spend their significant, but still limited focus.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#115I used this again just the other day with the cantor.dust plugin. My rev.eng skills are dull and were never great to begin with, but for anything below a real APT with obfuscation, runtime decoding and unpacking, Ghidra is an equalizer. Between this and Chef from gchq, someone with devops skills can probably skill up to an entry level threat analyst level in a few weeks or months. The tooling available today is reall…
You mean my electricity has been backdoored? Now that's paranoia on a different level, how does that work
Helpfully in the mean time, someone has written a wiki page about some stuff we used to add to threat models: https://en.wikipedia.org/wiki/Radiofrequency_MASINT
Just because you're paranoid doesn't mean they aren't actually using RF side channels to steal your keys and passphrases.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#116It is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some secu…
I don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.
Whilst other companies and organisations hire staff quickly who can more freely experiment with the latest technology from a hip coffee shop or their home, someone at an organisation like the NSA after waiting a year to start the job and after having hiked 8km from their car to a windowless and soulless building in the middle of nowhere instead has to fill out dozens of forms and seek dozens of approvals just to consider the idea of experimenting with some new technology.
I am amazed something as useful as Ghidra could actually be built within such a large bureaucracy in modern times, and then even more amazed that someone managed to get it released as open source software to ensure it continues to be maintained and useful long after the next internal reorganisation and exodus of developers.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#117Earlier quoted context omitted.
It's best not to assume a physical presence is required. Who is to say that the people at Let's Encrypt, NoScript, any of the firmwares' authors, or many other places weren't compromised years ago? It's sometimes worthwhile to reflect on where trust is placed.
It would be hell of a trick to inflitrate air gapped machine without physical presence.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#118Earlier quoted context omitted.
Its used to reverse engineer an unknown binary without the matching source code. Since Ghidra already is open source it be no use to audit Ghidra itself except for learning purposes. It might be useful to reverse engineer a closed source driver so you can write an open source one from scratch.
I would expect there to be self-mutating code such that when the open source code is compiled with a particular compiler it activates a different code path (written into the compiler itself) such that the final resulting binary does not correspond to the source code if it were compiled with another compiler. And if this resulting binary is distributed, audits of the source code wouldn't catch these modifications.
2) The binary (or jar) can't lie about what it contains. Take it into an air gap and reverse engineer it, what's there is there. This includes compilers.
3) see posters comment about the impracticality of stopping someone with the money, talent, skills, and patience of the NSA :)
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#119Earlier quoted context omitted.
I don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.
I think a lot of people underestimate how hard it would be to build something like Ghidra not from a technical perspective, but from an avoiding big organisation bureaucracy perspective. Unlike a typical bureaucracy however, and amongst other problems[1], the barrier for entry for hiring is extremely high, everything happens within an echo chamber (closed community with little external influence) and paranoia and ove…
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#120Earlier quoted context omitted.
If they could install a virus on Iran's air-gapped uranium centrifuge industrial control systems, I'm pretty sure they could get one on your computer.
Bribing people in generally corrupt and poor countries to smuggle a USB stick is kind a different than just breaking into random persons home in a country with relatively low corruption. Latter might actually be more difficult. Obviously depends on what your end goal is