[TOOL] McGrew Security RAM Dumper
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 3 Mar 2008 16:06:56 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
McGrew Security RAM Dumper
------------------------------------------------------------------------
SUMMARY
DETAILS
Overview:
A short while back, a <http://citp.princeton.edu/memory/> paper was
published by researchers at Princeton University, in which they talk about
the process of recovering encryption keys out of memory after a cold boot.
This was surprising to many people, as most just assume that, since RAM is
volatile storage, it is erased when power is removed. This is an incorrect
assumption.
When the idea of memory retaining state for a short time was first brought
to my attention a little over a year ago, Wesley McGrew ran a few
experiments similar to this one, just to prove it to myself. The desktop
machines Wesley McGrew tried would hold state for anywhere between 5 and
10 seconds without power, whereas my laptop, with no battery or wall
power, would maintain state for an amazing 10 minutes. Wesley McGrew used
a Linux bootable CD to get an image of memory from a Windows to data
carve, and found some interesting things. The footprint for the Linux OS
was huge, though, and this interfered with my ability to capture as much
memory from the previously running operating system as possible.
The Princeton researchers applied this method to the recovery of
encryption keys, with great results. They also cooked up a way to image
the contents of RAM with a very small footprint, only overwriting a small
amount of memory in the process. Unfortunately, at the time of writing
this, their tool hasn't been released. Wesley McGrew decided that it
wouldn't be hard to go ahead and implement one myself, based off their
paper and youtube video posted above, so that I (and others) can go ahead
and start having fun.
So, as a small side project, I've written "msramdmp", the McGrew Security
RAM Dumper. Enjoy!
ADDITIONAL INFORMATION
The information has been provided by <mailto:wesley@xxxxxxxxxxxxxxxxxx>
Wesley McGrew.
To keep updated with the tool visit the project's homepage at:
<http://mcgrewsecurity.com/projects/msramdmp/>
http://mcgrewsecurity.com/projects/msramdmp/
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [UNIX] Ghostscript Buffer Overflow (Exploit)
- Next by Date: [NT] SMSGate Denial of Service
- Previous by thread: [UNIX] Ghostscript Buffer Overflow (Exploit)
- Next by thread: [NT] SMSGate Denial of Service
- Index(es):
Relevant Pages
- [UNIX] Linux Kernel binfmt_elf ELF Loader Privilege Escalation
... Get your security news from a reliable source. ... or in other words to execute
a new program. ... One of the Linux format loaders is the ELF (Executable and Linkable
... of the memory map header in the binary image and the program ... (Securiteam) - [NEWS] Xbox 360 Hypervisor Privilege Escalation Vulnerability
... Get your security news from a reliable source. ... Xbox 360 Hypervisor Privilege
Escalation Vulnerability ... access to memory and provides encryption and decryption
services. ... to the syscall dispatcher, as illustrated below. ... (Securiteam) - Re: Executable Memory in a Driver
... >> criminal to expose users to the added bluescreen and security risk. ...
In a language that can't access outside an array, ... that doesn't need to move memory.
... > desired in the compiler. ... (microsoft.public.development.device.drivers) - [NT] Microsoft DCOM RPC Race Condition (MS04-012)
... Get your security news from a reliable source. ... the way Microsoft Windows
handles DCOM RPC requests. ... based DCOM activation requests has been prone to failure
in the past. ... may be overwritten depending on the block the memory management supplies
... (Securiteam) - Lost BlackBerry Could Open Security Breach
... misplaced items such as computer memory sticks and mobile e-mail ... colleague
lost one of the office's wireless messaging devices. ... Bluefire Security Technologies
Inc., who recently lost his iPaq 6315 ... (comp.dcom.telecom)