{"id":5040,"date":"2015-03-10T14:08:36","date_gmt":"2015-03-10T19:08:36","guid":{"rendered":"http:\/\/www.zdziarski.com\/blog\/?p=5040"},"modified":"2015-03-10T14:24:56","modified_gmt":"2015-03-10T19:24:56","slug":"testing-for-a-compromised-xcode","status":"publish","type":"post","link":"https:\/\/www.zdziarski.com\/blog\/?p=5040","title":{"rendered":"Testing for the Strawhorse Backdoor in Xcode"},"content":{"rendered":"<p>In <a href=\"http:\/\/www.zdziarski.com\/blog\/?p=5009\">the previous blog post<\/a>, I highlighted the latest Snowden documents, which reveal a CIA project out of Sandia National Laboratories to author a malicious version of Xcode. This Xcode malware targeted App Store developers by installing a backdoor on their computers to steal their private codesign keys.<\/p>\n<p><a href=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-5028\" src=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-1024x469.png\" alt=\"Screen Shot 2015-03-10 at 2.09.50 PM\" width=\"584\" height=\"267\" srcset=\"https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-1024x469.png 1024w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-300x137.png 300w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-500x229.png 500w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM.png 1406w\" sizes=\"auto, (max-width: 584px) 100vw, 584px\" \/><\/a><\/p>\n<p>So how do you test for a backdoor you&#8217;ve never seen before? By verifying that the security mechanisms it disables are working correctly. Based on the document, the malware apparently infects Apple&#8217;s\u00a0<em>securityd<\/em>\u00a0daemon to prevent it from warning the user prior to exporting developer keys:<\/p>\n<p><em>&#8220;&#8230; which rewrites securityd so that no prompt appears when exporting a developer&#8217;s private key&#8221;<\/em><\/p>\n<p>A good litmus test to see if\u00a0<em>securityd<\/em>\u00a0has been compromised in this way is to attempt to export your own developer keys and see if you are prompted for permission.<\/p>\n<p><!--more--><\/p>\n<p>Following <a href=\"https:\/\/developer.apple.com\/library\/ios\/recipes\/xcode_help-accounts_preferences\/articles\/export_signing_assets.html\">these instructions<\/a> from Apple, you can export your signing identity.<\/p>\n<ol>\n<li>In the Xcode Preferences window, click Accounts<\/li>\n<li>Click the Action button (to the right of the minus button) in the lower-left corner.<\/li>\n<li>Select Export Accounts from the pop-up menu.<\/li>\n<\/ol>\n<p>When you export your accounts,\u00a0<em>securityd<\/em> should pop up a window asking for permission to allow this action.<\/p>\n<p><a href=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-5045\" src=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM-1024x581.png\" alt=\"Screen Shot 2015-03-10 at 3.15.40 PM\" width=\"584\" height=\"331\" srcset=\"https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM-1024x581.png 1024w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM-300x170.png 300w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM-500x284.png 500w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-3.15.40-PM.png 1092w\" sizes=\"auto, (max-width: 584px) 100vw, 584px\" \/><\/a><\/p>\n<p>If you don&#8217;t see this popup, something&#8217;s wrong, and it&#8217;s possible that your system may have been compromised to prevent the user from knowing their keys were being exported.<\/p>\n<p>Since we have no samples of the malware allegedly developed for CIA, there&#8217;s no way to guarantee that this is a sure-fire way to detect compromise. Based on the slides, however, this warning should be removed on compromised systems, at least under certain circumstances.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In <a href=\"http:\/\/www.zdziarski.com\/blog\/?p=5009\">the previous blog post<\/a>, I highlighted the latest Snowden documents, which reveal a CIA project out of Sandia National Laboratories to author a malicious version of Xcode. This Xcode malware targeted App Store developers by installing a backdoor on their computers to steal their private codesign keys.<\/p>\n<p><a href=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-5028\" src=\"http:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-1024x469.png\" alt=\"Screen Shot 2015-03-10 at 2.09.50 PM\" width=\"584\" height=\"267\" srcset=\"https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-1024x469.png 1024w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-300x137.png 300w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM-500x229.png 500w, https:\/\/www.zdziarski.com\/blog\/wp-content\/uploads\/2015\/03\/Screen-Shot-2015-03-10-at-2.09.50-PM.png 1406w\" sizes=\"auto, (max-width: 584px) 100vw, 584px\" \/><\/a><\/p>\n<p>So how do you test for a backdoor you&#8217;ve never seen before? By verifying that the security mechanisms it disables are working correctly. Based on the document, the malware apparently infects Apple&#8217;s\u00a0<em>securityd<\/em>\u00a0daemon to prevent it from warning the user prior to exporting developer keys:<\/p>\n<p><em>&#8220;&#8230; which rewrites securityd so that no prompt appears when exporting a developer&#8217;s private key&#8221;<\/em><\/p>\n<p>A good litmus test to see if\u00a0<em>securityd<\/em>\u00a0has been compromised in this way is to attempt to export your own developer keys and see if you are prompted for permission.<\/p>\n<p><a class=\"read-more\" href=\"https:\/\/www.zdziarski.com\/blog\/?p=5040\" title=\"Read More\"> <span class=\"button \">Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,14],"tags":[],"class_list":["post-5040","post","type-post","status-publish","format-standard","hentry","category-apple","category-security"],"_links":{"self":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5040","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5040"}],"version-history":[{"count":0,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/5040\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5040"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5040"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.zdziarski.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5040"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}