0:06 Sometimes developers can create the backdoors intentionally or unintentionally. 0:14 So what are the backdoors in the source code? 0:20 Let's imagine that there are two scenarios. 0:22 One scenario is about legitimate guy. 0:25 So he comes to work, he likes his job, he doesn't have any issues with employer. 0:31 And he got the task that he needs to fix something on a weekend. 0:39 But he doesn't even have the access to his working computer. 0:44 But he still wants to finish his task. 0:47 So he thought, okay, let me do a little backdoor so I can connect through the website from home and fix it. 0:56 So how to do it? 0:58 There are like big amount of possibilities and he will just do it after he will forget it or after he will be fired and another guy will come and he never know about it. 1:09 So it will be there forever unless somebody will find it. 1:14 So this is like one stuff. 1:16 And I had even a story about the situation. 1:20 So it was a hack of one governmental website. 1:25 And I was analyzing the logs. 1:28 And I... 1:30 find out that that website had a backdoor. 1:34 So the hacker didn't hack the website. 1:37 The hacker found backdoor. 1:39 Hacker found backdoor when he was just enumerating the folders and completely accidentally he found the backdoor. 1:46 So he didn't upload the backdoor. 1:48 That backdoor was there for him. 1:50 Why? 1:51 And I started to analyze how the backdoor came there, why it was there. 1:57 And it was a system admin who was creating the backups. 2:04 And he didn't like the admin panel. 2:08 Which was done there. 2:10 And he didn't like, you know, the guys who were, you know, developing that admin panel. 2:15 It was too much complex and it didn't have capabilities to do the backup. 2:19 So he just uploaded the malicious PHP, you know, script, which helped him to create the backups. 2:29 In one hand, he just, you know, he did, nobody knew, and he was doing the backups. 2:35 In other hand, that folder was found and that folder had WebShell. 2:43 So let me show you a little bit more about WebShell. 2:51 So what is the web shell? 2:54 Let me just tell you. 2:56 If you have a website on PHP, the worst... 3:00 What can happen is that somebody will upload you the web shell code. 3:09 Let me show you the picture of that stuff. 3:12 Usually, it can look like this. 3:17 I will show you my favorite one. 3:20 This is from the forum where I spent many, many years. 3:24 So it's called anti-chat GitHub shell. 3:30 So that shell code looks like this. 3:34 And what it provides you, just to be clear, it provides you ability to use PHP. 3:46 To send commands directly to Linux or Windows operating system. 3:51 So PHP has capability to execute commands. 3:57 Now, let's imagine that somebody is uploading that stuff, and now he can send the commands through the internet to a computer. 4:10 It is called Shell. 4:13 But why this shell is really nice? 4:16 First of all, it has login and password. 4:19 So if you uploaded this shell, 4:24 You know, basically, the login and password. 4:28 So some other hackers... 4:31 Maybe, you know, we'll not be able to get there. 4:34 So you are protecting as hacker your shell code. 4:38 And I have articles about like two hackers who hacked the same stuff. 4:45 And one hacker, he fixed the vulnerability. 4:51 So what happened? 4:54 One guy, he uploaded shell code like this. 4:58 Another guy did the same. 5:00 That guy understood that there is vulnerability. 5:03 He fixed that vulnerability. 5:04 And that guy deleted his shell code, his shell. 5:08 And that guy seen the location of that shell. 5:12 And he tried to use his shell to get something. 5:17 But that guy, he changed the password. 5:20 So you got the point. 5:22 Sometimes there is even a fight for the... 5:27 For the victim. 5:28 And another example, there is, maybe you heard about Mirai. 5:34 Mirai is a big botnet. 5:37 And that botnet, it scans the full internet for IoT devices, for different open routers, for anything what is related to 5:52 IoT mostly. 5:53 So that Mirai botnet has, I think, more than 5 million devices. 6:00 I don't exactly remember, but think about this. 6:03 One guy, he created like multiple scripts, which are scanning the internet, finding specific, for example, software and 6:16 based on the default credentials, weak credentials. 6:20 vulnerability, infecting it. 6:23 And what happened? 6:24 So everyone was like saying, oh, my God, Mirai is hacking me, like blah, blah, blah. 6:29 So some other people thought, okay, so Mirai are hacking them. 6:34 So we will hack them again, remove Mirai and patch it. 6:39 So some hackers start to do the same, but they start to remove Mirai malware. 6:46 So they were like, you know, curing them from Mirai, putting their malware and closing the vulnerability. 6:54 So, yeah, that is another interesting story. 6:57 Mirai. 6:59 Mirai amount of bots. 7:05 Um, 7:09 So this is the Mirai malware. 7:12 I think it was, it is said in Japanese, but the Mirai itself is Chinese stuff. 7:20 So basically, look, only one million routers were hacked in Germany. 7:28 One million routers were infected with that stuff. 7:32 So you can understand how guys are hacking millions of devices. 7:39 They just find one vulnerability. 7:42 By finding one vulnerability, you can hack a big amount of items. 7:48 For example, for me, I found one vulnerability which was affecting not that much, but maybe like 12,000 hosts. 8:01 I can tell you a little bit more about that vulnerability. 8:06 And minor. 8:08 So, there is... 8:13 Antminer, not this one. 8:17 Monitor. 8:18 So. 8:25 there is a registered CV, which I submitted in 2021. 8:31 So if you find some vulnerability and the company is basically big, usually you can submit CV. 8:42 If it is at least recognized, right? 8:45 So let me show you what happened in this situation. 8:50 So what is Antminer monitor? 8:53 If you are mining bitcoins, in some point, you may buy like 10 different miners to mine bitcoins. 9:05 And in some point, maybe you will be interested to monitor activity around those ant miners. 9:14 For example, you have like 25 ant miners. 9:16 How are you going to manage each of them? 9:18 You don't want to, right? 9:19 You want just to see how much money you got and if they are online or offline. 9:23 That's it, right? 9:24 And maybe amount of energy they used. 9:28 So some guy, this guy, he created the Antminer monitor. 9:35 And that Antminer monitor allowed you to connect your Antminer to that software. 9:42 So I was interested in that type of software and I did the... 9:48 analysis. 9:49 So that analysis, I ran different static analyzers and they found nothing. 9:57 So I was like, okay, most likely it doesn't look vulnerable, but I just wanted to read the settings. 10:06 So I just wanted to read the most basic stuff, like settings of that application. 10:11 So sometimes inside the settings, 10:16 You can see gem because in the source code, it's complex. 10:23 Maybe it is vulnerable. 10:25 Maybe it's not. 10:27 But you will need to spend like days to understand where is the vulnerability. 10:32 But this is the settings.pu. 10:35 So can anyone try to spot where is the vulnerable part here? 10:41 So let's imagine that this is your application. 10:45 Where is the vulnerable part here? 10:48 It is super clear. 10:51 I will put it like this so it will be shown a little bit better. 10:59 Now, let's go back to the description of that vulnerability. 11:09 Super secret key is super secret key. 11:12 So how that application had to work? 11:16 That application had to create the random 11:19 key, but it said, you know, you can create the random key or use super secret key. 11:31 It doesn't make any sense. 11:33 And I couldn't understand why developer did it. 11:37 And after I understood, developer did it because on Windows, that specific command didn't work. 11:47 That command worked only on Linux. 11:48 And people start to complain why software is not running on Windows. 11:52 And he said, because random is not like that library for random didn't work, you know, well on Windows because that library is using the Linux random. 12:04 So he just created that, you know, stupid decision. 12:09 And what I did, I created this key. 12:13 So this key is based on the super secret key. 12:16 And I was able to access all, like all Antminer monitors in the internet. 12:25 I just put this in the cookie field and I was able to access all websites where they hosted that stuff.
0:06 Sometimes developers can create the backdoors intentionally or unintentionally. 0:14 So what are the backdoors in the source code? 0:20 Let's imagine that there are two scenarios. 0:22 One scenario is about legitimate guy. 0:25 So he comes to work, he likes his job, he doesn't have any issues with employer. 0:31 And he got the task that he needs to fix something on a weekend. 0:39 But he doesn't even have the access to his working computer. 0:44 But he still wants to finish his task. 0:47 So he thought, okay, let me do a little backdoor so I can connect through the website from home and fix it. 0:56 So how to do it? 0:58 There are like big amount of possibilities and he will just do it after he will forget it or after he will be fired and another guy will come and he never know about it. 1:09 So it will be there forever unless somebody will find it. 1:14 So this is like one stuff. 1:16 And I had even a story about the situation. 1:20 So it was a hack of one governmental website. 1:25 And I was analyzing the logs. 1:28 And I... 1:30 find out that that website had a backdoor. 1:34 So the hacker didn't hack the website. 1:37 The hacker found backdoor. 1:39 Hacker found backdoor when he was just enumerating the folders and completely accidentally he found the backdoor. 1:46 So he didn't upload the backdoor. 1:48 That backdoor was there for him. 1:50 Why? 1:51 And I started to analyze how the backdoor came there, why it was there. 1:57 And it was a system admin who was creating the backups. 2:04 And he didn't like the admin panel. 2:08 Which was done there. 2:10 And he didn't like, you know, the guys who were, you know, developing that admin panel. 2:15 It was too much complex and it didn't have capabilities to do the backup. 2:19 So he just uploaded the malicious PHP, you know, script, which helped him to create the backups. 2:29 In one hand, he just, you know, he did, nobody knew, and he was doing the backups. 2:35 In other hand, that folder was found and that folder had WebShell. 2:43 So let me show you a little bit more about WebShell. 2:51 So what is the web shell? 2:54 Let me just tell you. 2:56 If you have a website on PHP, the worst... 3:00 What can happen is that somebody will upload you the web shell code. 3:09 Let me show you the picture of that stuff. 3:12 Usually, it can look like this. 3:17 I will show you my favorite one. 3:20 This is from the forum where I spent many, many years. 3:24 So it's called anti-chat GitHub shell. 3:30 So that shell code looks like this. 3:34 And what it provides you, just to be clear, it provides you ability to use PHP. 3:46 To send commands directly to Linux or Windows operating system. 3:51 So PHP has capability to execute commands. 3:57 Now, let's imagine that somebody is uploading that stuff, and now he can send the commands through the internet to a computer. 4:10 It is called Shell. 4:13 But why this shell is really nice? 4:16 First of all, it has login and password. 4:19 So if you uploaded this shell, 4:24 You know, basically, the login and password. 4:28 So some other hackers... 4:31 Maybe, you know, we'll not be able to get there. 4:34 So you are protecting as hacker your shell code. 4:38 And I have articles about like two hackers who hacked the same stuff. 4:45 And one hacker, he fixed the vulnerability. 4:51 So what happened? 4:54 One guy, he uploaded shell code like this. 4:58 Another guy did the same. 5:00 That guy understood that there is vulnerability. 5:03 He fixed that vulnerability. 5:04 And that guy deleted his shell code, his shell. 5:08 And that guy seen the location of that shell. 5:12 And he tried to use his shell to get something. 5:17 But that guy, he changed the password. 5:20 So you got the point. 5:22 Sometimes there is even a fight for the... 5:27 For the victim. 5:28 And another example, there is, maybe you heard about Mirai. 5:34 Mirai is a big botnet. 5:37 And that botnet, it scans the full internet for IoT devices, for different open routers, for anything what is related to 5:52 IoT mostly. 5:53 So that Mirai botnet has, I think, more than 5 million devices. 6:00 I don't exactly remember, but think about this. 6:03 One guy, he created like multiple scripts, which are scanning the internet, finding specific, for example, software and 6:16 based on the default credentials, weak credentials. 6:20 vulnerability, infecting it. 6:23 And what happened? 6:24 So everyone was like saying, oh, my God, Mirai is hacking me, like blah, blah, blah. 6:29 So some other people thought, okay, so Mirai are hacking them. 6:34 So we will hack them again, remove Mirai and patch it. 6:39 So some hackers start to do the same, but they start to remove Mirai malware. 6:46 So they were like, you know, curing them from Mirai, putting their malware and closing the vulnerability. 6:54 So, yeah, that is another interesting story. 6:57 Mirai. 6:59 Mirai amount of bots. 7:05 Um, 7:09 So this is the Mirai malware. 7:12 I think it was, it is said in Japanese, but the Mirai itself is Chinese stuff. 7:20 So basically, look, only one million routers were hacked in Germany. 7:28 One million routers were infected with that stuff. 7:32 So you can understand how guys are hacking millions of devices. 7:39 They just find one vulnerability. 7:42 By finding one vulnerability, you can hack a big amount of items. 7:48 For example, for me, I found one vulnerability which was affecting not that much, but maybe like 12,000 hosts. 8:01 I can tell you a little bit more about that vulnerability. 8:06 And minor. 8:08 So, there is... 8:13 Antminer, not this one. 8:17 Monitor. 8:18 So. 8:25 there is a registered CV, which I submitted in 2021. 8:31 So if you find some vulnerability and the company is basically big, usually you can submit CV. 8:42 If it is at least recognized, right? 8:45 So let me show you what happened in this situation. 8:50 So what is Antminer monitor? 8:53 If you are mining bitcoins, in some point, you may buy like 10 different miners to mine bitcoins. 9:05 And in some point, maybe you will be interested to monitor activity around those ant miners. 9:14 For example, you have like 25 ant miners. 9:16 How are you going to manage each of them? 9:18 You don't want to, right? 9:19 You want just to see how much money you got and if they are online or offline. 9:23 That's it, right? 9:24 And maybe amount of energy they used. 9:28 So some guy, this guy, he created the Antminer monitor. 9:35 And that Antminer monitor allowed you to connect your Antminer to that software. 9:42 So I was interested in that type of software and I did the... 9:48 analysis. 9:49 So that analysis, I ran different static analyzers and they found nothing. 9:57 So I was like, okay, most likely it doesn't look vulnerable, but I just wanted to read the settings. 10:06 So I just wanted to read the most basic stuff, like settings of that application. 10:11 So sometimes inside the settings, 10:16 You can see gem because in the source code, it's complex. 10:23 Maybe it is vulnerable. 10:25 Maybe it's not. 10:27 But you will need to spend like days to understand where is the vulnerability. 10:32 But this is the settings.pu. 10:35 So can anyone try to spot where is the vulnerable part here? 10:41 So let's imagine that this is your application. 10:45 Where is the vulnerable part here? 10:48 It is super clear. 10:51 I will put it like this so it will be shown a little bit better. 10:59 Now, let's go back to the description of that vulnerability. 11:09 Super secret key is super secret key. 11:12 So how that application had to work? 11:16 That application had to create the random 11:19 key, but it said, you know, you can create the random key or use super secret key. 11:31 It doesn't make any sense. 11:33 And I couldn't understand why developer did it. 11:37 And after I understood, developer did it because on Windows, that specific command didn't work. 11:47 That command worked only on Linux. 11:48 And people start to complain why software is not running on Windows. 11:52 And he said, because random is not like that library for random didn't work, you know, well on Windows because that library is using the Linux random. 12:04 So he just created that, you know, stupid decision. 12:09 And what I did, I created this key. 12:13 So this key is based on the super secret key. 12:16 And I was able to access all, like all Antminer monitors in the internet. 12:25 I just put this in the cookie field and I was able to access all websites where they hosted that stuff.