Friday, June 13, 2008

OSX Leopard in a Virtual Machine

Well, this morning started out good. For the longest time I have wanted to have OS X running in its own Virtual Machine (VM), so I can do some security testing without hosing my main box and because I don't have enough spare money to buy a kick around Mac. I started to research it earlier this week and found out that since the last time I looked into it someone has created a VMWare image of OS X, sweet!

After a few days of downloading (36 different rar files on a file share site, blah!), I have it running and here is a screen cap to prove it :).


Pretty cool, eh? Maybe it is the just the geek in me or the caffeine slowly seeping into my body but I am just f'ing happy right now.

The link I found this information at is http://pcwizcomputer.com/index.php?option=com_content&task=view&id=76&Itemid=48
(bonus points if you can tell me the CMS they are running just by looking at the URL :P).

Also, since it is 36 separate files to d/l this, if you want you can email me and I will post up one large archive for you to d/l off of my server.

So, what am I going to do with this? There are many different things I can/want to do. I think the first thing on my plate will be to fuzz the shit out of Safari and see what crashes and potential exploits can be found. I have had a client have a web page that crashes Safari so I am sure there is tons more I just don't think many people are looking yet :P.

Labels: ,

Wednesday, June 04, 2008

OSX == coffee house fun

I am sitting at my favorite coffee shop working while my girlfriend studies and every time I come here I see all of these macs showing up in my finder. Since I am not in that big of a mood to work I figured I would blog about this as it cracks me up every time. Here is what I see from iTunes and Finder (OSX's version of Windows Explorer).

Look at all of those computers! Most of them I can't read from (well without some work) but most of them I can write too, that isn't too big of a problem is it :P? I mean if I was a real dick I could just pump porn onto their hard drives or... I can steal their music, etc... This reminds me of the late 90s early 2000s with Windows 98 and the XP where sharing was on by default and you could get all sorts of goodies from people's machines.

Alright, back to work, but next time you are in a coffee house and have a mac see how many other computers pop-up in your Finder :).

Labels: ,

Tuesday, November 13, 2007

Instruments the built-in OSX hacking tool

Apple recently released their new operating system, Leopard. There are a few cool features to this OS but the one I am most excited about is a new development tool called Instruments. Instruments is a GUI tool and wrapper around a port of DTrace. What does this give us? Basically DTrace is a library that allows you to query kernel level events. For me I have been dying for something like FileMon or ProcessMon for the OSX platform now I have it but it is on steroids. Needless to say this made my day. What does Instruments look like? Kind of like this..



The above screen shot is showing a sample run looking at the file i/o of all processes on my system (looks like quicksilver is doing a scan). It is also possible to specify a specific process or to launch a new program you wish to monitor. So, what you say? You could see the file i/o of any process with the previous version of OSX with fsLogger (although it was kind of ugly, imho). Well Instruments is far more extendable (a later blog post) and there are a lot of default libraries that can be used.

There are 27 default "instruments" in the library that can be used. These range from monitoring network traffic, locks, i/o processes, memory usage and even UI recording. There are many libraries and some of them will only work for a single process while others will work for monitoring all processes. Since there are so many instruments it is a blog post in its own explaining all the different instruments.

Other things that are useful for Instruments is that you can do multiple runs and they will be shown side-by-side. Also, you can save your runs for later replaying or investigation.

So, why do I say this is a hacking tool and not a development tool? Because a lot of hacking (in my mind) is figuring out how programs work, how the person's mind works who wrote it and then finding the chinks in their thoughts or their laziness. Many development tools can be re-purposed for attacking the programs that were written with the same tools because when we get down to it we are just doing some weird ass debugging on the products :). Being able to see what files are being written/read from a program shows us some of the attack surface. But being able to view how the memory and other system resources from the program will show us even more of the attack surface. On top of that it gives anyone better insight into how a program or system resource works. Which means that Instruments is a development tool but I see it as being really really useful for "security research."

I will be posting a few more posts on this tool. I am not sure how many posts yet as I am still learning about this tool and OSX in general but if you liked this post stay tuned :).

Labels: , , ,