Ghidra: A software reverse engineering suite of tools developed by the NSA
ghidra-sre.org
ghidra-sre.org
Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some security people have been closely looking at the sources to see if it contains any suspicious features. Besides, if the NSA really wants to install some software on your computer, they can probably do it themselves without your involvement.
It's pretty spectacular.
Radare2 has a plugin for using ghidra's decompiler too https://github.com/radareorg/r2ghidra
So you can get all of the terminal level unix like goodness of radare2, yet still get really great ghidra quality decompiler output.
(I believe IDA has a check to stop you from doing this. Cracking that was one of the "rite of passage" exercises back in the day.)
IDA has had watermarks and all sorts of other fancy stuff. The real challenge with IDA was extending the demo to allow it to save databases before they started publishing a working older free version.
I like IDA a lot more than I like all the other tools, especially since I consider the user experience and hotkeys far superior, but the other day I did look at something where the disassembly and decompilation was great compared to other tools(one of the r2+ghidra UIs). I think because flirt signatures were missing and I can't get Hexrays to sell me a new license.
https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
If you've never read it I highly encourage you to do so.
Perhaps in 1984 what he writes was groundbreaking, but to me it wasn't. Do I need to apologize now for not being bamboozled by Ken's genius this time?
And if this resulting binary is distributed, audits of the source code wouldn't catch these modifications.
2) The binary (or jar) can't lie about what it contains. Take it into an air gap and reverse engineer it, what's there is there. This includes compilers.
3) see posters comment about the impracticality of stopping someone with the money, talent, skills, and patience of the NSA :)
Still it might be quite a useful tool.
The most important was clearly obtaining the PLC zero days to infect the physical machines. It's unclear to me why you choose to be so explicitly obtuse but in any case, for your own personal edification, feel free to read some details on how it went down -
[0] https://www.wikiwand.com/en/Stuxnet
[1] https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/
We’ve found instead that the NSA can just take over your unpatched computer easily instead of putting in the effort of hacking Let’s Encrypt.
Please explain your comment about how key signing ceremonies stop people from being bribed. The creation of those keys creates a root of trust but doesn't stop leaf certs from being generated.
Still, there are hundreds of publicly trusted CAs so the chance for exploitation is higher.
On the other hand individual security professionals might have wildly different ideas about risk tolerance and convenience, which they also have privilege to change on the whim.
If it's not connected to a network you are probably right....otherwise 100% wrong, if your a enough valuable target. And just lets say for fun your OS is 100% bulletproof, your +30 firmware's are not.
Of course they could get access if I were a valuable target, but that might just as well be with a large wrench. But they cannot just take control of any device.
And I think many companies might even have better capabilities. Or defense, since intelligence work is very often about industrial espionage.
Are you talking about Snowden's powerpoint slides or the Shadow Brokers arsenal?
EternalBlue...and it was a part of the shadow broker package, but that was just one occasion, Snowden is one of the other.
One must probably wear a Tar-hat to think that this is impossible.
With unlimited money and the given job to crack encryption, hack into systems and secure the networks of the wealthiest nation and only superpower on earth atm. It IS pretty much a unicorn, and i am pretty sure they are +20 years in the future technology-wise, and with that:
>>Arthur C. Clarke — 'Magic's just science that we don't understand yet.'
So yes Magic Unicorn describes the NSA pretty well.
Oh man i don't know what to say. Does one distrohop the ssd/efi/net/wireless/keyboard/etc-firmware too?
One distrohoped for 15 years and that vuln existed all the time..but hey it would be just that one...it's an exception right? ;)
https://securityaffairs.co/wordpress/115565/security/linux-k...
How many completely different browsers exist? And how many local exploitable user to root exploits exist in the Apple/Linux/BSD world's? If your a valued target and you are connected to a network you WILL be hacked.
Seriously? Distro hop? My brain hurts, I need coffee.
This principle isn't scalable to every computer system out there and will definitely go against other requirements in most organizations, but if you are an individual, it's not hard to pull it off.
Are those parts vulnerable to the NSA?
I believe due to what was made public, that they do have that capability.
I would suggest more research. If you are actually changing distros every month, that seems like a very manual process, with many points to use an insecure config. I think your time could be better spent hardening a current system.
And yes the NSA could own your box every month (and would) if it suited them.
Check out this link, this stuff is fascinating.
> In some cases, the NSA has modified the firmware of computers and network hardware—including systems shipped by Cisco, Dell, Hewlett-Packard, Huawei, and Juniper Networks—to give its operators both eyes and ears inside the offices the agency has targeted. In others, the NSA has crafted custom BIOS exploits that can survive even the reinstallation of operating systems. And in still others, the NSA has built and deployed its own USB cables at target locations—complete with spy hardware and radio transceiver packed inside.
https://arstechnica.com/information-technology/2013/12/insid...
The threat modeling that you see in this thread is laughable. Nobody has infinite resources, not even NSA. They can't throw all their capability at you alone. In fact they are not even interested in any one individual. They might be interested in some groups of people like "terrorist leadership" but even in that case they don't have the need to hack all people matching that group. So at every step of the decision making process there is a cost benefit analysis. And in the end NSA will only hack some terrorist leaders, the ones deemed sufficiently significant but not any more risky then is necessary.
The amount of meetings and paperwork required for carrying out offensive action is significant and everyone involved is very risk averse. Getting superiors to sign up for an operation against an individual capable of detecting attack and thus risking attribution would only be possible if the proposed techniques can be shown to be extraordinarily stealthy. That requires replicating the system in the lab and rigorously testing methodology beforehand.
Yeah, it is hard to protect organizations from nation states. Because all sufficiently complex systems have bugs and given long enough time persistent attackers will find & exploit these bugs. But that's because organizations have other real-world priorities besides fighting NSA. These organizations can't change protocols overnight and replace core systems just for fun of it.
Individuals actually have an advantage here because they can rotate systems at will and have much higher control over their personal lives than any CEO/CTO/CISO has over their organization. As a result, yes you can raise the cost of an attack against you high enough that NSA won't bother hacking you - either because there are other people who are less protected but hacking them would fulfill the same objective or because your ass gets handed to another agency which is able to present more cost-effective solution.
Your link demonstrates this dichotomy between options that NSA has available for hacking organizations vs individuals. Individuals rarely have well documented procurement processes available for third party auditing you know.
I literally answer directly after the questions. Read for comprehension.
I can tell you with 100% certainty that your assumptions are 100% wrong. Interpret that statement as you may and update your threat model accordingly.
I'm not advocating for installing a fresh OS on an exploited hardware and calling it a day, no matter how hard you try to present my words this way.
The point is to keep any single environment around only for a short period of time so that adversaries don't have enough time for replicating your systems and crafting a targeted exploit chain.
It is not meant to be the only line of defense. You would still harden every system you own, putting particular focus on tamper & intrusion detection (including retrospective analysis).
Couple that with strong compartmentalization (e.g. using different hardware for different purposes, Qubes OS style virtualization approaches) and defense in depth (exploit mitigations, traffic anonymization).
Here, I have spelled it out for you. Feel free to outline how you would approach attacking such individual adversary, even with NSA level team at your disposal. Silent assumptions being that 1) if person's physical location is known, CIA is a cheaper option than NSA and 2) failed offensive operation leaving attributable evidence is considered by NSA worse than missed opportunity.
Please, stop low effort ad hominem attacks.
If you're someone who uses the Internet, the NSA can take over whatever you use to browse with and have their way with it. If you don't, well that's what their interdiction program is for.
The thing is though, the economics of 0day indicate that the more you use it, the more likely it is that it'll get burnt, and supply is limited.
They can certainly hack anyone, but it doesn't scale, so they can't simply hack everyone. They can maybe use these techniques on a handful of targets per year, so they make it count, but most of their intelligence comes from the data we all give away for free every day.
Whilst other companies and organisations hire staff quickly who can more freely experiment with the latest technology from a hip coffee shop or their home, someone at an organisation like the NSA after waiting a year to start the job and after having hiked 8km from their car to a windowless and soulless building in the middle of nowhere instead has to fill out dozens of forms and seek dozens of approvals just to consider the idea of experimenting with some new technology.
I am amazed something as useful as Ghidra could actually be built within such a large bureaucracy in modern times, and then even more amazed that someone managed to get it released as open source software to ensure it continues to be maintained and useful long after the next internal reorganisation and exodus of developers.
The computers of most people are vulnerable even to normal cyber criminals, the NSA is a lot more powerful.
I wish this topic received more discussion.
I agree with you completely. Let's not joke at the capabilities of a trillion dollar organization focused on "cyber".
If you are fortunate enough to be a United States citizen who gets up and contributes to society on a daily basis -- you will never have anything to worry about. The NSA won't care anything about your dealings on the internet. Everyone can safely get back to their weird browsing habits and making lame comments on youtube -- no one is watching, because no one cares :)
Running Linux with very few binblobs, I expect they will not be able to.
Running any OS published by $tax_evading_big_corp, I expect they can.
* under linux I mean mainstream distro here. Unless you use qubes os, it will not have good sandbox, everything runs as your user and can easily modify eg. .bashrc and start up a key logger to get sudo password.
https://arstechnica.com/information-technology/2013/12/insid...
Reading their processes is so fascinating.
[1] https://rizin.re
[2] https://github.com/rizinorg/rizin
But also. Cutter is the first time that either Rizin or Radare has been simple enough for me, an entry level RE enthusiast, to use. So thanks.
If people are worried about running systems backdoored by NSA, they probably shouldn't use things like electricity either. It's a threat actor you can't really do anything about.
Helpfully in the mean time, someone has written a wiki page about some stuff we used to add to threat models: https://en.wikipedia.org/wiki/Radiofrequency_MASINT
Just because you're paranoid doesn't mean they aren't actually using RF side channels to steal your keys and passphrases.
Typically DC-DC converters are the easiest thing to hear, because of the sheer amount of energy involved. Normally these are operated at PWM (pulse) frequencies well outside hearing range—40–300 kHz—but often enough the feedback scheme for controlling those pulses oscillates in a way that generates audible subharmonics whose frequency depends on the power draw at any given moment. Modern computers are full of DC-DC converters.
Also, though, it's common for computers to contain sensitive low-noise audio-frequency amplifiers connected to a periodic sample-and-hold circuit which can alias high frequencies down into the audio range, with the output hooked up to loudspeakers; these are called "sound cards" and it's not at all unusual for them to produce clearly audible sounds that depend on the computation happening, at least if you turn the volume up all the way.
Finally, regular, non-super, humans can directly perceive radio frequency emissions as sounds: "The human auditory response to pulses of radiofrequency (RF) energy, commonly called RF hearing, is a well established phenomenon. RF induced sounds can be characterized as low intensity sounds because, in general, a quiet environment is required for the auditory response... Effective radiofrequencies range from 2.4 to 10000 MHz." https://pubmed.ncbi.nlm.nih.gov/14628312/
So "hearing data movement" because of "noise signatures that change" is not at all unusual. You can probably do it yourself if you have a quiet room to listen in. It's plausible that Ethernet-over-powerline equipment could produce audible sounds from the power supplies in the same house or nearby houses, but I haven't observed that myself and this is the first time I've heard of that happening.
What does this even mean?
Was pleased to discover a few years later that they had open sourced it.
They're up to v10 now and it's so much better than IDA Pro/HexRays that it's probably going to put them out of business.
https://htmlpreview.github.io/?https://github.com/NationalSe...
Someone shared an article I had seen earlier that year. “Why would you share this? This is old news it’s already made the rounds on the web.” Like I expected everyone to have the same experience as me. Luckily someone told me to chill out or I’d be blocked, that the list was for any news people found interesting. I felt very embarrassed and didn’t post there again for a long time, but it was my own fault.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
There might or might not be discussion potential on any submission, so I understand arguing about their value, but that "news if you're a beginner" was very condescending. Why not be happy about today's lucky 10,000?
No, and I didn't mean to sound condescending. I'll take out the "only" in my message.
Edit: And to clarify what I meant, I may not have known every headline in 2017, but I sure as hell heard about most of the Vault 7 releases. An organization anonymously releasing a world power's cyber tooling is something out of a cyberpunk novel.
Some months later I used it to reverse engineer the on-board software of a satellite running on a SPARCv8 CPU. It worked great in both cases, can recommend.
Unfortunately, Ghidra handles vtables and OOP very poorly still. You have to do a lot of by-hand annotations for virtual calls, even with 3rd party analysis scripts, while IDA's C++ usually Just Works. This is the main pain point, imo. The other main thing is that IDA has been used by the reverse engineering community for so long that there's a massive body of tutorials and StackOverflow answers for it, and a much larger corpus of 3rd party plugins. It's not a big deal for me, personally, but if you already have a good workflow for IDA it's probably not worth it to switch. For beginners I'd recommend Ghidra instead, though, because a free and open source tool with good official documentation and UX is worth its weight in gold (although I've heard BinaryNinja is extremely good nowadays).
* Affordable for sane people (aka, free)... This of course pushed Hex-Rays to finally make a cheaper version of IDA, but it's massively hobbled and useless for uncommon architectures.
* Almost as good architecture coverage. Missing a few big ones for automotive RE still - SuperH is still hit and miss, and no real C167. But the user-contributed Tricore is really quite impressive.
* Decompiler works across all architectures.
* Debugger is still sketchy, but has progressed extremely quickly.
* Preferable UI (IMO), and better struct handling.
* Decent plugin interfaces but fewer available plugins.
IDA:
* Still slightly better decompilation and disassembly for x86-64. Doesn't get as "lost" in vtables and big switches.
* Much better C++ construct support.
* More plugins and scripts available off the shelf.
* Still a few architectures which Ghidra doesn't have yet.
* Debugger is more stable and works a bit better.
For most architectures I would not start using IDA today as a hobbyist, but if I had a good IDA workflow or was joining a company where it were the gold standard, I wouldn't feel compelled to move over.