Hack-petya mission accomplished – Petya ransomware decryptor
github.com
github.com
Moral: your significant other may not be impressed by your hacking skills, but you might win the family over for life in a few hours.
I'm afraid of the moment when they get more clever. Or if they include filesystem drivers that silently encrypt every file... if done right, you can even compromise backups transparently for weeks until arming, so that backups are essentially useless too.
[1] http://www.symantec.com/connect/blogs/russian-ransomware-aut...
It can hardly be considered a backup if it's easily compromised from your every day computer. In a good backup configuration your computer only have read and "append only" privilages for the backup so past snapshots are safe.
Having said that not many people have this kind of config (including me).
That's pretty impressive! On the other hand, is it a general vulnerability of Salsa that genetic solvers can break it? Sounds like a huge vulnerability.
Looks like it used a [1-9a-xA-X]{8} key. Even with a CSPRNG that's only 46 bits of entropy. You can brute force that in 2-3 hours with adequate hardware.
That is, the closer the bits in the hash result for the candidate are to the target hash result, the better it considers the candidate (in particular, cardinality of symmetric difference for a bitset is the count of the number of one bits in the symmetric difference. It then sets the fitness to mean lower is better, so the smaller the number of different bits, the better it considers the candidate)
This means it just tweak input key bits through mutation until the result comes out right. Now, in theory, there should be no correlation, so this should be no better than random search, but ...
I'm not sure if there aren't clever ways to undo it, but at least it would resist such a simple method like that.
return int(bitset.From(c.qwords()).SymmetricDifferenceCardinality(target_bitset))
What really confuses me is how this can possibly work for a cryptographic function where any change in any one of the input bit is supposed to, on average, flip half of the output bits. But then again I am not curious enough to analyze the code in detail.* They used 16 bit math instead of 32 bit math (with, I'm assuming, a 32 bit output size rather than the recommended 64 bit output). Which has the effect of looking like 10 rounds, but it's a rather more serious security failure.
* They generated keys in the alphanumeric range (instead of the full byte range) significantly reducing entropy.
All which seems to have weakened it substantially (understatement).
Stop hand-rolling crypto, people! Ransomware needs security too. :(
The author probably wanted to be able to somewhat quickly encrypt/decrypt a full disk on potentially slow hardware.
It would have been smarter to bundle the ransomware with a 32-bit DOS extender so the known-good Salsa implementation could be used unchanged.
Also, does it apply to the PHP/Perl world of malware, the kind that gets installed on cracked, old and weak WordPress sites? There's 20 variations of "Web Shell by oRb" floating around, for example, and many, many versions of Perl IRC bots, for example.
Any suppositions as to why it would be deliberate?
/krazyconspiracy :-P
A reasonable Salsa20/20 implementation on a modest processor encrypts on the order of 400MiB/s [0][1]. So that the author went to the trouble of halving the number of rounds and changing the word-size when there are perfectly good and plenty fast off-the-shelf Salsa implementations strikes me as rather strange. Surely this is not the bottleneck on most employee's machines.
And then there's the apparently tiny keyspace used. You could argue that this makes the key more "user-friendly" (!), but just a hex representation of a random 256bit key would seem much more natural, and the poor targets are hardly in a position to complain.
[0] https://www.cryptopp.com/benchmarks.html [1] https://cr.yp.to/snuffle.html
So implementing weak crypto dramatically lowers the risk of prosecution or worse for the attackers.
Someone who has a hard time getting market rates might not be as qualified to fix the software as they think they are.
If I could have a dollar for everytime I put my head to a random problem and came out 3 months later... I'd have more than fifty dollars.
Amusingly the readme for the pirate version said "I cracked it with IDA Pro" or something along those lines.
It doesn't even allow installing non-Free software, FSF will love this.
According to https://www.cryptopp.com/benchmarks.html, Salta20 is 4x faster than AES - and if I understand it, Salsa10 is half the iterations.
The unusually reduced number of rounds is more difficult to explain, since I expect hard drive I/O would be the bottleneck in almost any situation. Maybe it's just a little more "stealthy" to not have elevated CPU usage while the ransomware is incubating.
hxxps://github(dot)com/ytisf/theZoo/tree/master/malwares/Binaries/Ransomware.Petya
Why Go?