Mostrando entradas con la etiqueta Qubes-OS. Mostrar todas las entradas
Mostrando entradas con la etiqueta Qubes-OS. Mostrar todas las entradas
Desde hace tiempo llevo haciendo un seguimiento a este proyecto de la gente de InvisibleThings Labs, capitaneados por .

QubesOS era en principio un sistema operativo (ver más sobre lo qué es Qubes aquí) diseñado para ser seguro desde su diseño, utilizando la virtualización como una herramienta para proporcionar "seguridad" en la capa más alta, las aplicaciones - Apps -, así cada uno podría crear espacios virtuales aislados los unos de los otros para evitar que las acciones o eventos sucedidos en uno afectará a los otros, por ejemplo que la navegación por Internet pudiera significar una amenaza o riesgo para el usuario.

Con la versión R2 RC1 llegan importantes mejoras en la parte gráfica, donde la plantilla por defecto para la interfaz gráfica ha sido actualizada a Fedora 20, y además se han solucionado numerosos fallos de la versión anterior. Además ya soporta virtualización de aplicaciones windows en pantalla completa, una de las características más esperadas en QubesOS.

Download
http://sourceforge.net/projects/qubesos/files/Qubes-R2-rc1-x86_64-DVD.iso/download
http://wiki.qubes-os.org/trac/wiki/QubesDownloads

Instalación de QubesOS R2 RC1
http://wiki.qubes-os.org/trac/wiki/InstallationGuideR2rc1

#ST2Labs
www.st2labs.com
Introducción

Hace un tiempo escribí un artículo donde os presentaba el proyecto Qubes-OS, un sistema operativo seguro, donde cada aplicación/sistema se ejecuta en un entorno virtualizado totalmente independiente del resto del sistema, es lo que los propios desarrolladores bautizaron con las siglas NOSG (Next OS Generation), o lo que es lo mismo, la próxima generación de Sistemas Operativos.

[Qubes-OS] Tres dominios independientes entre si ejecutándose al mismo tiempo.

Desde el lanzamiento de la segunda versión del mismo, la novedad más interesante fue la posibilidad de ejecutar máquinas virtuales Windows, por lo que ya no hay excusas para no darle una oportunidad a este fantástico sistema.

[Qubes-OS R2b2] Running Windows 7 in a Virtual Secure Domain.
Con Qubes-OS puedes crear diferentes escritorios, o más bien dominios, cada dominio esta totalmente aislado de los otros, incluso a nivel de red, esto ultimo siempre que se cumplan algunos de los requisitos en el hardware,como por ejemplo, disponer de la tecnología de virtualización Intel-VT-d o AMD IOMMU (ejemplos: Cores i5, i7).

Novedades: Qubes-OS R2b2

Las principales novedades de la versión R2 Beta 2 que hace una semana fue lanzada, es la incorporación de:

  • Nueva compatibilidad para los últimos hardware gráficos (GPU drivers).
  • Se ha incluido la capacidad de elegir la interfaz gráfica KDE4 (4.9) o Xcfe 4.10.
  • Nuevas funcionalidad como por ejemplo, convertir potenciales PDF peligrosos en PDF seguros.
La nueva funcionalidad es muy interesante, voy a poner un ejemplo para introducir y explicar la nueva capacidad.

Imaginemos que estamos utilizando un "dominio Internet", normalmente este dominio, será peligroso, es decir, tenemos el dominio de Internet activado con Firefox o Chrome, y lo usamos para poder navegar libremente por Internet sin preocuparnos las páginas que visitamos, porque si llegase a comprometerse con una vulnerabilidad (ej: JAVA), esta quedaría aislada a ese entorno (dominio / sandbox) y cuando finalizaramos la sesión, desaparecería cualquier #malware que hubiera podido ejecutarse.

Pero digamos, que durante nuestra navegación por Internet, descargamos varios PDFs que necesitamos para nuestro trabajo, ¿cómo sabemos que esta seguros? o mejor aún, ¿sería posible pasar dichos documentos a un entorno seguro de trabajo sin correr riesgo alguno? La respuesta es SI, en esta versión se ha incluido la capacidad de convertir PDF no "confiables" a PDF seguros.

[Qubes-OS PDF Converter] | MECANISMO

El mecanismo es extremadamente sencillo, cuando se abre un fichero del tipo PDF, DOC, etc este se procesará dentro de un entorno VM independiente, es decir, se ejecutará dentro de un entorno seguro y controlado, similar a un sandbox, el tiempo aproximado de espera es de 5 segundos. Una penalización muy pequeña comparado con el peligro de convertir nuestro equipo en un "zombie" miembro de una botnet, o exponer nuestros datos a cualquier "atacante". ¿No creéis que 5 segundo de retardo en la apertura del documento bien lo merecen, si estamos seguros?

[Qubes-OS] Convertir PDF "inseguros/peligrosos" a PDF seguros

Download



Más Información
Qubes-OS Website
The Invisible Things Lab's blog | Qubes 2 Beta 2 has been released!

The last January, I was wrote about Qubes-OS in two post (The Next Security OS Generation and Creating a WiFi pen-testing VM). Now I have just been released the beta3 version of this.

Beta 3 fixes lots of annoying problems discovered in Beta 2 and earlier releases, and also implements a bunch of useful feature.






There are some new tools, one of this, is qvm-block, it has been introduced that makes mounting USB devices to any user AppVM very easy, no matter which actual VM is handling the USB controller


So, this allows to have untrusted USB domain(s), almost seamlessly integrated in the desktop system. One can consider to use it in order to preventvarious USB attacks. The next release (the 1.0) will bring this feature to the Qubes GUI manager as well, making it easy to use for non-command-line users too.
Furthermore, now you can do the deployment your "own Qubes-OS distro" more easily, with the new capability implemented in beta 3:

... have now introduced fully automatic Qubes build system, that allows to build all the Qubes packages, and also create the installation ISO, with just one command. More information on this system and on how to use it can be found in the ...ç
Installation and Downloading, all you need to know will find in the "Installation Guide". Or if you prefer, you can download the new ISO now.

The ISO and the digital signature for the ISO from here:


Via | Jorge Sanz and The Invisible Things Labs
One of the excellent qualities he has Qubes-OS is the ability to create virtual spaces dedicated to a specific task, such as: pentesting.

In this article I'm going to describe How to create a standalone VM for Pentesting purpose.

Steps:

1.- Create the VM first, and assign a WiFi card to it:

[dom0]$ qvm-create wififun --standalone --label yellow
[dom0]$ qvm-prefs -s wififun memory 800 # ensure at least this mem at startup
[dom0]$ qvm-prefs -s wififun kernel none # use own copy of kernel and modules
[dom0]$ qvm-pci -a wififun

It's important doesn't use the Wifi interface in other VM instance, for this reason is recomended use a external Wifi card. To planning your HDD Storage capacity, the standalone VM copy the whole root filesystem, thus It would eat about 5GB of your disk.

Architecture standalone VM for Pentesting purposes.

2.- Start the new VM and install it. The prerequisite software there, starting with downloading the reasonably new compat-wireless sources, together with the required injection patches, and then building and installing the new kernel modules.

In this case, the example is using a compact-wireless card, for this reason the following lines include this source to built and prepare de system:

[wififun]$ wget http://linuxwireless.org/download/compat-wireless-2.6/compat-wireless-2011-07-14.tar.bz2

[wififun]$ wget http://patches.aircrack-ng.org/channel-negative-one-maxim.patch
[wififun]$ wget http://patches.aircrack-ng.org/mac80211-2.6.29-fix-tx-ctl-no-ack-retry-count.patch
[wififun]$ wget http://patches.aircrack-ng.org/mac80211.compat08082009.wl_frag+ack_v1.patch

[wififun]$ sudo yum install kernel-devel patch gcc

[wififun]$ tar xjf compat-wireless-2011-07-14.tar.bz2
[wififun]$ cd compat-wireless-2011-07-14
[wififun]$ patch -p1 < ../channel-negative-one-maxim.patch
[wififun]$ patch -p1 < ../mac80211-2.6.29-fix-tx-ctl-no-ack-retry-count.patch
[wififun]$ patch -p1 < ../mac80211.compat08082009.wl_frag+ack_v1.patch

[wififun]$ make
[wififun]$ sudo make unload
[wififun]$ sudo make install

3.- Reboot VM to ensure that all the patched drivers will get properly loaded on each VM boot:

[dom0]$ qvm-run --shutdown --wait wififun
[dom0]$ qvm-run -a wififun gnome-terminal

If the wifi driver is load properly, then go on:

4.- Prepare the wifi security tools and resolve the problems like any Linux System, you can use dmesg log to debug any problem. For example:

[wififun]$ sudo bash
[wififun]# yum install aircrack-ng dnsmasq
[wififun]# airmon-ng start wlan0
[wififun]# iptables -F INPUT
[wififun]# iptables -F FORWARD
[wififun]# echo “1” > /proc/sys/net/ipv4/ip_forward

You don't need to add any explicit masquerading rules, as they are applied by default on Qubes VMs. Edit the /etc/dnsmasq.conf, so that it contains at least the following:

interface=at0
dhcp-range=192.168.0.50,192.168.0.150,12h


5.- Start dnsmasq daemon -- we will use it for providing DHCP to our fake AP:

[wififun]# /etc/init.d/dnsmasq start
[wififun]# airbase-ng -e free_wifi mon0

6.- Configure the at0 interface and check it (make sure it matches what you wrote into dnsmasq.conf):

[wififun]# ifconfig at0 192.168.0.1 up
[wififun]# tcpdump -i at0

Please note that as your wififun VM is a regular Qubes VM, it is automatically connected to the default Net VM, which in turn provides networking to it. That's why it is so easy to create a fully functioning fake AP

Some Issues:

Catch#1: When you start a driver domain late after system boot, so after some days of uptime and extensive use of VMs, Xen might not be able to allocate enough continues (in terms of MFNs) memory for a driver domain.

The work around is to close as many VMs as possible before starting such driver domain, and then also reducing, for a moment, the amount of memory assigned to Dom0:

[dom0]$ xm mem-set 0 1600m

and starting the driver domain should be fine.

Catch#2: Some network cards, notably Express Cards, might not work well with the 3.0.4 pvops kernel that we use in all VMs by default. try to use the 2.6.38.3 xenlinux kernel in your WiFi fun VM:

[dom0]$ sudo qvm-dom0-update kernel-qubes-vm-2.6.38.3-10.xenlinux.qubes
[dom0]$ cp /var/lib/qubes/vm-kernels/2.6.38.3/* /var/lib/qubes/appvms/wififun/kernels/
[dom0]$ qvm-prefs wififun -s kernelopts "swiotlb=force"

[wififun]$ sudo yum install kernel-devel-2.6.38.3-10.xenlinux.qubes


And rebuild the compat-wireless, unload, install modules, and then load drivers again.

Fuente | The Invisible Things Labs
Today I'm gonna write about Qubes-OS, the amazing project that provide you a Strong Security Desktop (SSD). I'm wishing to try it out. 

This project can become in the Next Generation Security OS. Sincerely I will bet for that.


What is Qube?

Qubes is an open source operating system designed to provide strong security for desktop computing. Qubes is based on Xen, X Window System, and Linux, and can run most Linux applications and utilize most of the Linux drivers. In the future it might also run Windows apps.

Architecture

Qubes implements Security by Isolation approach. To do this, Qubes utilizes virtualization technology, to be able to isolate various programs from each other, and even sandbox many system-level components, like networking or storage subsystem, so that their compromise don’t affect the integrity of the rest of the system.

Qubes lets the user define many security domains implemented as lightweight Virtual Machines (VMs), or “AppVMs”. E.g. user can have “personal”, “work”, “shopping”, “bank”, and “random” AppVMs and can use the applications from within those VMs just like if they were executing on the local machine, but at the same time they are well isolated from each other. Qubes supports secure copy-and-paste and file sharing between the AppVMs, of cours

Who doesn't want to try it out now?? I wanna try it out... so Where can I obtain it?

Screenshots: Amazing
In this example, the word processor runs in the “work” domain, which has been assigned “green” label, and is fully isolated from other domains, such as the “red” domain (assigned the “red” label -- “Watch out!”, “Danger!”) used for random Web browsing, news reading, etc. Apps from different domains run in different AppVMs and have different X servers, filesystems, etc. Notice the different color frames (labels), and VM names in the titlebar -- these are drawn by the trusted Window Manager running in Dom0 and apps running in domains cannot fake them.


Different Security AppVMs Domains.

This feature is one of my favorites:
All the networking runs in a special, unprivileged NetVM (notice the red frame around the NetworkManager dialog box on the screen bellow). Thanks to this, a potential compromise of your network card driver, or WiFi stack, or DHCP client, would not affect the integrity of the rest of the system! This feature requires Intel VT-d or AMD IOMMU hardware (e.g. Core i5/i7 systems)
Network Managed in Insolation NetVM.

Downloading


The most important documentation about the project is store and share it in the following wiki system:  http://wiki.qubes-os.org/trac

The Installation guide provide all you need to know for install and prepare your equipment before start the configuration process.

You can download the ISO and the digital signature for the ISO from here:
See this page for more info about how to download and verify our GPG keys. Then, verify the downloaded ISO:
gpg -v <iso>.asc
It's so important to know the System requeriments:

Minimum:
  • 4GB of RAM
  • 64-bit Intel or AMD processor (x86_64 aka x64 aka AMD64)
  • Intel GPU strongly preferred (if you have Nvidia GPU, prepare for some troubleshooting; we haven't tested ATI hardware)
  • 10GB of disk (Note that it is possible to install Qubes on an external USB disk, so that you can try it without sacrificing your current system. Mind, however, that USB disks are usually SLOW!)
  • Fat SSD disk strongly recommended
Additional requirements:
  • Intel VT-d or AMD IOMMU technology (this is needed for effective isolation of your network VMs)
----

How Can I install Qube-OS in an USB Stick? The response to this cuestion can be find out in the following guide.

This is all! Do you like this OS? I suppose that is yes! ...