You are leaking metadata! Asbjrn Reglund.com Thorsen 10.06.2016 - - PowerPoint PPT Presentation

you are leaking metadata
SMART_READER_LITE
LIVE PREVIEW

You are leaking metadata! Asbjrn Reglund.com Thorsen 10.06.2016 - - PowerPoint PPT Presentation

hEp://www.observeit.com/blog/throw-back-hack-the-infamous-aol-data-leak You are leaking metadata! Asbjrn Reglund.com Thorsen 10.06.2016 EUNIS, Thessaloniki About me Work as head of group at FSAT in Norway PenetraQon tester since 2008


slide-1
SLIDE 1

You are leaking metadata!

Asbjørn Reglund.com Thorsen 10.06.2016 EUNIS, Thessaloniki

hEp://www.observeit.com/blog/throw-back-hack-the-infamous-aol-data-leak

slide-2
SLIDE 2

About me

  • Work as head of group at FSAT in Norway
  • PenetraQon tester since 2008
  • Background in programming
  • Security enthusiast

hEp://reglund.ninja/

slide-3
SLIDE 3

Goal of this talk

  • Make you aware of metadata
  • Show what a hacker can use metadata for
  • Make you check your own metadata
  • Maybe aVer this talk you will change your

rouQnes regarding washing documents of metadata?

hEp://www.referenceforbusiness.com/management/Ex-Gov/Goals-and-Goal-SeYng.html

slide-4
SLIDE 4

What is metadata?

  • Data about data
  • Greek: meta- (μετά-) meaning "aVer", or

"beyond")

slide-5
SLIDE 5
slide-6
SLIDE 6

Why metadata maEers

  • They know you rang a phone sex service at 2:24

am and spoke for 18 minutes. But they don’t know what you talked about

  • They know you called the suicide prevenQon

hotline from Golden Gate Bridge. But the topic

  • f the call remains a secret.
  • They know you spoke with an HIV tesQng

service, then your doctor, then your health insurance company in the same hour. But they don’t know what was discussed.

Source: 30C3 Electronic FronQer FoundaQon

slide-7
SLIDE 7

Metadata findings

  • Usernames
  • Mail addresses
  • Passwords
  • Printers
  • SoVware versions
  • GPS coordinates
  • Dates
  • Author
  • Camera type
  • RotaQon
  • Computer names
  • And much more..

hEps://hubslide.com/chema-alonso/defcon-21-fear-the-evil-foca-mitm-aEacks-using-ipv6-s56d4bd2f8d070ead0e63bd79.html

slide-8
SLIDE 8

We know where you are!

  • In a new tab, log in to your gmail account
  • hEps://maps.google.com/locaQonhistory/b/1/

hEp://www.bbc.com/news/blogs-news-from-elsewhere-30414032

slide-9
SLIDE 9
slide-10
SLIDE 10
slide-11
SLIDE 11
slide-12
SLIDE 12
slide-13
SLIDE 13

QuesQon…..

slide-14
SLIDE 14
slide-15
SLIDE 15

exiVool -gpsposiQon where_is_this.jpg

slide-16
SLIDE 16
slide-17
SLIDE 17

Μεταδεδομένα

  • Normally in all electronic files
  • Try to google yourself
  • Quick demo
slide-18
SLIDE 18

A ficQve scenario

  • Interpol contacted Mr. H. Acker
  • Prevent a killing
  • AVer the hunt for S. Niper for 2 years
  • Intelligence reveals a strange message in an

internet forum

slide-19
SLIDE 19

Forum message

UGxhY2U6IFRoZXNzYWxvbmlraQ0KSG90ZWwgYm9va2VkOiBFbG VjdHJhIFBhbGFjZQ0KUm9vbTogMTMzNw0KVGFyZ2V0OiBodHR wOi8vZm9say51aW8ubm8vYXNiam9ybnQvd2VpcmRfdGV4dA0K VGltZTogOCBKdW5lIGF0IDEyLjAwDQpXaGVyZTogVEJE

slide-20
SLIDE 20

Results aVer decoding

  • Place: Thessaloniki
  • Hotel booked: Electra Palace
  • Room: 1337
  • Target: hEp://folk.uio.no/asbjornt/weird_text
  • Time: 10 June at 11.20
  • Where: TBD
slide-21
SLIDE 21

Catching the Sniper

  • The Greek Police stormed room 1337
  • Sniper escaped nearly without a trace
  • The room was totally empty but for one thing
slide-22
SLIDE 22
slide-23
SLIDE 23

Analyzing the memory sQck

  • Would you put this usb sQck into your laptop?

– Why? – Why not?

slide-24
SLIDE 24
  • Lets look at the files on the memory sQck..
slide-25
SLIDE 25
slide-26
SLIDE 26

hEps://memegenerator.net/instance/57305385

slide-27
SLIDE 27

Interpol: GOT HIM!

slide-28
SLIDE 28

Sum up

  • Interpol found a strange forum post
  • We used some techniques to drill down to the

metadata

  • S. Niper did not think about the metadata
  • We did!
  • Google! Bing!
slide-29
SLIDE 29

ExiVool free and relaQvely simple

  • exiVool -all:all

=> read all the tags.

  • exiVool -all:all=

=> remove all the tags

  • Lots of other tools
  • Foca (Chema Alonso)
  • hEp://metadatascrubbing.blogspot.gr/

hEp://www.giantbomb.com/forums/off-topic-31/are-thumbs-ups-lame-434157/

slide-30
SLIDE 30

Slides or Hacked Your choice ;-) Thank you for your aEenQon!

slide-31
SLIDE 31

Contact info

  • Mail: asbjornt@fsat.no
  • TwiEer: @fuzzerman
  • Security blog: h.ps://Reglund.com
  • Linkedin:

h.ps://no.linkedin.com/in/reglund/ QuesQons?

23/06/16 Asbjørn Reglund Thorsen <asbjornt@fsat.no> TwiEer: @fuzzerman

hEp://launchany.com/10-quesQons-your-api-document-must-answer/