Report of an NSA Employee about a Backdoor in the OpenSSH Daemon (2012) [pdf](spiegel.de)
spiegel.de
Report of an NSA Employee about a Backdoor in the OpenSSH Daemon (2012) [pdf]
http://www.spiegel.de/media/media-35663.pdf
7 comments
No, it's not a rootkit. Rootkit it not something that grants root access, it something that runs with root privileges and uses them to conceal its own existence.
This one is just a custom OpenSSH version with a backdoor.
This one is just a custom OpenSSH version with a backdoor.
http://en.wikipedia.org/wiki/Rootkit
"A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer"
...continued privileged access. In the *nix world, this is understood to mean root.
"A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer"
...continued privileged access. In the *nix world, this is understood to mean root.
> A rootkit is a stealthy type of software, typically malicious, designed to hide the existence of certain processes or programs from normal methods of detection
These are the primary characteristic of a rootkit. To wit, from that same article:
> Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only available solution to the problem.[2] When dealing with firmware rootkits, removal may require hardware replacement, or specialized equipment.
These problems are what rootkits are associated with. The backdoored SSH described in the paper does not qualify. Detecting it is fairly straightforward, and on its own it makes no attempt to hide any programs that it spawns. EDIT: further, as described it makes no efforts to avoid removal.
> enable continued privileged access to a computer
If you strip away the rest of the definition and only look at this part, then by your definition the vanilla SSH server is a rootkit.
These are the primary characteristic of a rootkit. To wit, from that same article:
> Rootkit detection is difficult because a rootkit may be able to subvert the software that is intended to find it. Detection methods include using an alternative and trusted operating system, behavioral-based methods, signature scanning, difference scanning, and memory dump analysis. Removal can be complicated or practically impossible, especially in cases where the rootkit resides in the kernel; reinstallation of the operating system may be the only available solution to the problem.[2] When dealing with firmware rootkits, removal may require hardware replacement, or specialized equipment.
These problems are what rootkits are associated with. The backdoored SSH described in the paper does not qualify. Detecting it is fairly straightforward, and on its own it makes no attempt to hide any programs that it spawns. EDIT: further, as described it makes no efforts to avoid removal.
> enable continued privileged access to a computer
If you strip away the rest of the definition and only look at this part, then by your definition the vanilla SSH server is a rootkit.
WTF is the purpose of a rootkit that runs as root, conceals its own existence, but doesn't grant root access?
It's a backdoor, but the title is misleading: this isn't about a persistent backdoor in the upstream openssh code, it's just a in-house patch/backdoor. Frabkly I thought equivalent code was available and open source? Either way, quoting [1] in full lenght to save others from thinking there's something alarming in the pdf:
Stefan Sperling Sat, 17 Jan 2015 14:44:15 -0800
On Sat, Jan 17, 2015 at 10:59:19PM +0100, Daniel Cegiełka wrote:
> http://www.spiegel.de/media/media-35663.pdf
>
> "PANT SPARTY is a backdoor in the SSH daemon for *NIX, based on
> OpenSSH portable"
They are not talking about the official OpenSSH code.
To save everyone a bit of time (and hassle with a PDF), from the same document:
"It allows a public key to be embedded in the sshd binary and will then always grant a root login shell if presented with the proper key pair for that key. [...] authorized_keys as a quick-and-easy method of persistence [...] obviously isn't very stealthy [...] The goal for this project was to provide the same level of persistence but embedded in the sshd binary itself (obviously, assuming root access, as before)"
In other works, no backdoor in sshd unless the system has already been rooted by other means and sshd replaced with a bugged binary. Boohoo.
[1] http://www.mail-archive.com/[email protected]/msg135510.html
Stefan Sperling Sat, 17 Jan 2015 14:44:15 -0800
On Sat, Jan 17, 2015 at 10:59:19PM +0100, Daniel Cegiełka wrote:
> http://www.spiegel.de/media/media-35663.pdf
>
> "PANT SPARTY is a backdoor in the SSH daemon for *NIX, based on
> OpenSSH portable"
They are not talking about the official OpenSSH code.
To save everyone a bit of time (and hassle with a PDF), from the same document:
"It allows a public key to be embedded in the sshd binary and will then always grant a root login shell if presented with the proper key pair for that key. [...] authorized_keys as a quick-and-easy method of persistence [...] obviously isn't very stealthy [...] The goal for this project was to provide the same level of persistence but embedded in the sshd binary itself (obviously, assuming root access, as before)"
In other works, no backdoor in sshd unless the system has already been rooted by other means and sshd replaced with a bugged binary. Boohoo.
[1] http://www.mail-archive.com/[email protected]/msg135510.html
The thing that strikes me from this report is that he or she (and most of these programmer types working for NSA groups) are just like many of the HN/tech crowd, except they're working for "the other side". Heck, many of them probably read HN every day.
> New Zealand was incredible! I wish I’d had more time there, but I did pretty well. I saw a handful of LOTR sights, Mount Cook, a number of gorgeous lakes, snow-capped mountains everywhere ... I absolutely loved my time in Australia, both in terms of work and travel, but I’m also looking forward to returning to the land of Chick-fil-A, college athletics, BBQ pork, and real bacon. Oh, and good beer.
It's great that they love their work, but it's too bad so many smart people are going to work on projects that violate so many people's rights.
> New Zealand was incredible! I wish I’d had more time there, but I did pretty well. I saw a handful of LOTR sights, Mount Cook, a number of gorgeous lakes, snow-capped mountains everywhere ... I absolutely loved my time in Australia, both in terms of work and travel, but I’m also looking forward to returning to the land of Chick-fil-A, college athletics, BBQ pork, and real bacon. Oh, and good beer.
It's great that they love their work, but it's too bad so many smart people are going to work on projects that violate so many people's rights.
But how is this particular guy in the wrong?
This exploit is something that needs to be specifically installed by someone - it's not something you'd use to exploit the masses, it's something you'd use to monitor a target further once you already had (perhaps temporary) root access.
In that sense, it's basically just bread-and-butter spy work. It's hard to accept that the government has any reason to monitor the population to the extent that the NSA does - but it would be conversely completely foolish to say that they have no business developing attacks for computers - it would be like saying they have no business developing lock pick tools or electronic bugs.
History has shown that a strong nation has at least some need for intelligence and counter-intelligence, and the US has historically had incredibly poor capabilities for both, which has lead to the deaths of thousands (thinking about Vietnam intelligence specifically).
It thus seems at least foolish to criticise what's clearly an impressive targeted exploit - which to some extent demonstrates the US' dominance in the field.
This isn't something that the public has any business knowing - this is just plain espionage.
This exploit is something that needs to be specifically installed by someone - it's not something you'd use to exploit the masses, it's something you'd use to monitor a target further once you already had (perhaps temporary) root access.
In that sense, it's basically just bread-and-butter spy work. It's hard to accept that the government has any reason to monitor the population to the extent that the NSA does - but it would be conversely completely foolish to say that they have no business developing attacks for computers - it would be like saying they have no business developing lock pick tools or electronic bugs.
History has shown that a strong nation has at least some need for intelligence and counter-intelligence, and the US has historically had incredibly poor capabilities for both, which has lead to the deaths of thousands (thinking about Vietnam intelligence specifically).
It thus seems at least foolish to criticise what's clearly an impressive targeted exploit - which to some extent demonstrates the US' dominance in the field.
This isn't something that the public has any business knowing - this is just plain espionage.
You're right, I shouldn't single this one person out. I'm thinking of the many who knowingly work on technologies or exploits that are being used to spy on their own citizens.
> violate so many people's rights
Don't worry. It's ok because the Good Guys(tm) would never do anything bad. They would make them Bad Guys(tm)!
Don't worry. It's ok because the Good Guys(tm) would never do anything bad. They would make them Bad Guys(tm)!
I'm going to go ahead and assume you're being farcical. :)
The sad thing is that a lot of them probably believe they are the good guys, and that they'll be able to clearly tell when they start crossing a line towards The Dark Side. We all live in our own bubbles, after all.
If you've never seen The Boxtrolls, it's a moderately funny newish kids movie, but some of the parts that I enjoyed the most about that movie were the scenes with the two evil henchmen. I enjoyed it because they'd convinced themselves that they were the good guys, fighting the good fight and all that. But as the movie goes on their perspective slowly changes as they become more aware of the impact they're having on the protagonists.
I firmly believe there are very few healthy people out there who honestly want to watch the world burn, we should all be aware of the impact we're having on those around us. It's easy to write off an opposing side as evil do-er, but in all likelihood they see themselves as fighting the good fight just as much as you do.
The sad thing is that a lot of them probably believe they are the good guys, and that they'll be able to clearly tell when they start crossing a line towards The Dark Side. We all live in our own bubbles, after all.
If you've never seen The Boxtrolls, it's a moderately funny newish kids movie, but some of the parts that I enjoyed the most about that movie were the scenes with the two evil henchmen. I enjoyed it because they'd convinced themselves that they were the good guys, fighting the good fight and all that. But as the movie goes on their perspective slowly changes as they become more aware of the impact they're having on the protagonists.
I firmly believe there are very few healthy people out there who honestly want to watch the world burn, we should all be aware of the impact we're having on those around us. It's easy to write off an opposing side as evil do-er, but in all likelihood they see themselves as fighting the good fight just as much as you do.
I was poking fun at the black-white views of the world that some people have, the "Us vs. Them" attitudes that crop up, and ideas like "it could never happen in America."
> SSH has a lot of checks to make sure you can't switch usernames in the middle of a login (go figure) so this was a bit tricky to bypass.
Go figure.
Go figure.
On debian/ubuntu you can detect modified packages with `debsums` - but the signatures seem to be MD5, for which it's possible to generate collisions with e.g. something like http://www.bishopfox.com/resources/tools/other-free-tools/md... .
With an unmodified `debsums`, of course.
> Currently DSD uses authorized_keys as a quick-and-easy method for persistence against certain *nix targets.
Good to know. Time for a security audit of every authorized_keys file I maintain.
Good to know. Time for a security audit of every authorized_keys file I maintain.
If they developed an alternative version of OpenSSH with backdoor how can they distribute it so that people will actually use it?
Crowbar attack versus the distribution maintainer.
Physical access to the target's system.
Control the network upstream of the target so that the modified checksum and package can be delivered during package upgrades.
Compromise the mirror used by the target to provide the modified checksum and package.
Hide the code changes in a series of semi-related ostensibly legitimate pull requests. Legitimise your pull requests by developing corner cases which expose "bugs" in the software you wish to attack.
Crowbar attack against the upstream maintainer.
"USB key in the carpark" attack.
Those are some ideas. I don't claim to be an expert in the area.
Physical access to the target's system.
Control the network upstream of the target so that the modified checksum and package can be delivered during package upgrades.
Compromise the mirror used by the target to provide the modified checksum and package.
Hide the code changes in a series of semi-related ostensibly legitimate pull requests. Legitimise your pull requests by developing corner cases which expose "bugs" in the software you wish to attack.
Crowbar attack against the upstream maintainer.
"USB key in the carpark" attack.
Those are some ideas. I don't claim to be an expert in the area.
Title should be "NSA Employee Reports Developing OpenSSH Rootkit".