the internet's safety

camouflage-crack.txt

camouflage-crack.txt
Posted Jan 13, 2007
Authored by NT Wako, NoPh0BiA

Camouflage version 1.2.1 suffers from a vulnerability that allows access to encrypted files.

tags | exploit
MD5 | e55cf76cf98831630e2554aa141c3efd

camouflage-crack.txt

Change Mirror Download
A Major design Bug in Camouflage 1.2.1 (latest)

Direct Link: http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html

Disclaimer
==========
This material is presented for informational purposes ONLY. I do not condone or encourage vandalism or theft.

I do not accept any liability for anything anyone does with this information. So, don't shoot the messenger.
Remember: Use a computer in ways that ensure respect for your fellows.


Author
======
Adonis a.K.a. NtWaK0
Abed a.K.a. NoPh0BiA


Affected Product
================
Camouflage 1.2.1 (latest).
http://camouflage.unfiction.com/


Bug Type and Date
=================
Type: Very Bad Design
Date: 01/07/2007


Bug Results
===========
Cracking encrypted (Camouflage 1.2.1) files without any bruteforce.

WHY LOSING TIME ON MATH AND BRUTEFORCE WHEN YOU CAN PLAY WITH YOUR HEX EDITOR :-).


Bug Description
===============
Firstly, computer forensic investigators can take advantage of this bug to access file protected with (Camouflage 1.2.1) without the knowledge of the original password. Now it is time to check your cold cases for steganography files.

You can crack (Camouflage 1.2.1) encrypted files very easy, in fact in less than two minute. The problem is similar to the bug I found in PGP last year.


(Camouflage 1.2.1) leave a footprint after you stag a file.
If you look at the end of your stagged file you will notice the following:
http://homepage.mac.com/adonismac/Advisory/steg/camouf3.jpg

So now we have identified the stagged file our next step is to access the HIDDEN messages or files without cracking the password, here is how.


Proof-of-Concept (THIS WILL WORK HIDDEN FILES)
==============================================
For screen capture please check http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html

Step 01

1. We use a file cover (carrier file) called "Adonis_Carrier_File1.jpg"
2. We will hide inside it a file called "Adonis_Hidden_File1.txt"
3. We will right click "Adonis_Hidden_File1.txt" and select camouflage
4. We will use a password "aaaa"
5. We generated the stagged file we will call it "Adonis_Camouflage_Stagged_File.jpg"

http://homepage.mac.com/adonismac/Advisory/steg/camouf1.jpg


Step02

NOTE: We will use different carrier and different input file to show you it will work even if you have different input and different carriers.

To access the hidden file WITHOUT the original password "aaaa" we will do the followings:

1. We use a file cover (carrier file) called "Adonis_Carrier_File2.jpg"
2. We will hide inside it a file called "Adonis_Hidden_File2.txt"
3. We will right click "Adonis_Hidden_File2.txt" and select camouflage
4. We will use a password "a"
5. We generated the stagged file we will call it "Adonis_break_camouflage.jpg"
6. We will open Both pictures in a hex editor
7. We will replace as indicated in the screen capture below "Adonis_Camouflage_Stagged_File.jpg" with the one from "Adonis_break_camouflage.jpg"
8. We will Save the file.
9. We will right click "Adonis_Camouflage_Stagged_File.jpg" and select camouflage and use "a" as password. YES we overwrite the password with something we know.

Simple hein !!!


Now time to break camouflage.
=============================
We will open "Adonis_Camouflage_Stagged_File.jpg" and "Adonis_break_camouflage.jpg" in hex edit. We will start from the END of the file and try to locate 00 02 63 (like 10 lines from the end of the file).

Once we have located the values we start REPLACING from LEFT to right starting after 00 20 63 (63 is the first letter of the password a) (Do not replace 63 it is your password = a).

In this example I will replace the password aaaa with a. So I will replace F4 1B 43 with 20 20 20.

http://homepage.mac.com/adonismac/Advisory/steg/camouf2.jpg

To resume the password is saved starting from 00 00 20 00 (ANYTHING AFTER THIS POINT IS THE PASSWORD AND THIS CAN BE OVERWRITTEN AS YOU SEE)


Testing the results
===================
http://homepage.mac.com/adonismac/Advisory/steg/camouflage.html


Peace to you all


Copyright © 2007 Adonis a.K.a NtWaK0

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close