Thursday, July 2, 2020

EL EXAMEN DE HISTORIA DEL ARTE DE LA EBAU DE JUNIO DE 2018 DE LA COMUNIDAD DE MADRID

Aunque soy muy crítico con el sistema de exámenes de selectividad que realizan las distintas coordinadorsa de las asignaturas de Geografía e Historia de la Comunidad de Madrid, tengo que reconocer que en el caso de la Historia del Arte ha mejorado. Este nuevo examen creo que es más lógico y compensado. No se sobrevaloran como en el antiguo dos preguntas, el tema o la imagen, en donde el conjunto valía hasta 7 puntos del total, y donde podía haber mala o buena suerte en lo que te cayera. Ahora la evaluación es más variada y el desarrollo de un tema junto con el comentario de una imagen sólo tiene un valor de 4 puntos sobre 10. Juzgad vosotros mismos.

Los temas en ambas opciones son adecuados. No digo que en este caso sean fáciles, sino que tienen un valor correspondiente a su desarrollo, dos puntos. En este caso, podían ser más fáciles pero se pregunta sobre las características de la pintura gótica insistiendo en Giotto, lo que no parece disparatado y sobre las características de la arquitectura barroca poniendo el foco en Italia.

Pero en lo que, sin duda, hemos ganado todos es en tener una mayor seguridad a cerca de las imágenes que pueden caer. Son dos obras reconocibles y estándares evaluables.
La lámina de la opción A es de la fachada principal del Museo del Prado, obra neoclásica por excelencia de Juan de Villanueva y la opción B es el relieve del tímpano románico de la iglesia de Santa Fé de Conqués. En las dos se pueden aplicar las características de sus respectivos estilos y hablar de su importancia.



Pero si estoy contento es porque se ha dado más valor a los términos artísticos y a las preguntas cortas de autores (hasta seis puntos, 3+3), lo que te permite picotear sobre el conocimiento de los alumnos, pero a su vez éstos tienen la posibilidad de descartar algunos de los términos o personajes requeridos, ya que hay elección generosa.

En este caso los términos artísticos han sido (sólo 6 entre 8):
  • En la opción A: Arte Helenístico, Manierismo, Surrealismo, Tenebrismo, orden dórico, circo, cavea, collage.
  • En la opción B: Bauhaus, Neoclasicismo, Impresionismo, Plateresco, orden jónico, anfiteatro, termas, fresco.
Los personajes han sido (sólo 3 entre 5):
  • En la opción A: Lisipo, Ghiberti, Rubens, Matisse, Le Corbusier.
  • En la opción B: Praxiteles, Masaccio, Murillo, Gaudí, Delacroix.


More articles


  1. Viaje Friends And Family
  2. Lifestyle Network
  3. Curiosidades Google Maps
  4. Viaje En Bus
  5. Lifestyle Questions
  6. Viaje Jalapeno Cigar 2020
  7. Curiosidades Que Ninguém Sabia
  8. Curiosidades Rusia
  9. Who Lifestyle Guidelines
  10. Curiosidades Aleatorias
  11. Curiosidades Fast And Furious
  12. Viaje Interprovincial
  13. Lifestyle Youtube Channels
  14. Lifestyle Christianity
  15. Freestyle Libre
  16. Viaje 9 Dias Japon
  17. Lifestyle 94
  18. Viaje Sin Rumbo Letra
  19. Curiosidades Estranhas
  20. Lifestyle Journalist
  21. Viaje 1 De Mayo Animal Crossing
  22. Lifestyle Articles
  23. Viaje Por Europa
  24. Curiosidades Kim Jong Un
  25. Lifestyle Young Thug
  26. Lifestyle Rentals
  27. Viaje Oro Perfecto Review
  28. Quinto Viaje De Cristobal Colon
  29. Lifestyle 8321
  30. How To Say Viaje In Spanish
  31. Curiosidades Cientificas
  32. Curiosidades 31 Minutos
  33. Curiosidades 8M
  34. What Lifestyle Choices Cause Diabetes
  35. Lifestyle 650 Price
  36. Lifecycle 95C
  37. Why Lifestyle Center
  38. Viaje Util
  39. Viaje To English
  40. Curiosidades Holanda
  41. How Many Lifestyle Are There
  42. Viaje Hacia El Mar
  43. Viaje Masculine Or Feminine
  44. Viaje Nueva Zelanda
  45. Viaje Zombie Andre
  46. Are Contabilidade Curiosidades
  47. Lifestyle Vs Personal Blog
  48. Lifestyle Properties
  49. Lifestyle With Sahiba Youtube
  50. Curiosidades 777
  51. Curiosidades Legais
  52. Curiosidades Um Maluco No Pedaço
  53. Lifestyle 360
  54. Lifestyle To Reduce Blood Pressure
  55. How Much Do Lifestyle Models Make
  56. Curiosidades Lara Mesquite Nv
  57. Curiosidades 3 Temporada Stranger Things
  58. Lifestyle 740
  59. Lifestyle Examples
  60. Viaje Cigars
  61. Viaje 7 Dias Marruecos
  62. Viaje Koino Yokan
  63. Viaje Pelicula
  64. Curiosidades De Smells Like Teen Spirit
  65. Viaje Norte España
  66. Can Lifestyle Changes Reverse Hypertension
  67. Are Lifestyle Shoes Good For Walking
  68. Viaje En Helicoptero
  69. Is Lifestyle An Indian Brand
  70. Curiosidades Holanda
  71. Curiosidades Oceania
  72. Is It Love Curiosidades
  73. Viaje 5 Dias
  74. Lifestyle Remodeling
  75. Lifestyle Ultra Sensitive Review
  76. Lifestyle Coach
  77. Lifestyle Koramangala
  78. Curiosidades Japão
  79. Lifestyle Dubai
  80. Curiosidades 60 Segundos
  81. Who Sells Viaje Cigars
  82. Lifestyle Home Centre
  83. Lifestyle Wiki
  84. Lifestyle Resort
  85. Curiosidades William Shakespeare
  86. Lifestyle Expert
  87. Lifestyle Tint
  88. Curiosidades William Shakespeare
  89. Lifestyle Communities
  90. Viaje Japon
  91. Viaje 1 La Isla Misteriosa
  92. Curiosidades Inuteis
  93. Curiosidades Historicas
  94. Who Lifestyle Risk Factors
  95. Curiosidades 9 Semanas De Embarazo
  96. Viaje Oro Perfecto
  97. Lifestyle District
  98. What'S Viajar Mean
  99. Lifestyle 38
  100. Viaje Util
  101. Lifestyle 901
  102. Curiosidades Walking Dead
  103. Lifestyle Vlog Ideas
  104. Curiosidades Coreia Do Norte
  105. Lifestyle Hashtags
  106. Lifestyle When Trying To Conceive
  107. Viaje 9 Dias Nueva York
  108. 69 Curiosidades De Dragon Ball
  109. Curiosidades Netflix
  110. Why Lifestyle Entrepreneur
  111. What Lifestyle Can I Afford Calculator
  112. Viaje 7 Dias Nueva York
  113. Viaje Honey And Hand Grenades
  114. What Is Viaje In Spanish
  115. For Lifestyle Changes
  116. Viaje Virtual A Disney
  117. Curiosidades Resident Evil
  118. Lifestyle Vape
  119. Lifestyle Tattoo
  120. Lifestyle 2
  121. Curiosidades Nba
  122. Lifestyle Jay Gwuapo
  123. Viaje 3 Dias
  124. Lifestyle Podcasts
  125. Viaje How Do You Pronounce It
  126. Lifestyle Ultra Sensitive Size
  127. Viaje 2 La Isla Misteriosa
  128. What Lifestyle Causes Cancer
  129. Curiosidades Psicologicas
  130. Viaje Ricardo Arjona Letra
  131. Viaje 3 De La Tierra Ala Luna
  132. Lifestyle Parow
  133. Viaje Perdido
  134. Curiosidades 50 Sombras De Grey
  135. Curiosidades Portugal
  136. Lifestyle Where To Buy
  137. Lifestyle Asia
  138. Viaje Al Centro De La Tierra 2
  139. Lifestyle Health Plans
  140. Viaje Verde
  141. Viajar Quotes
  142. To Lifestyle Modification
  143. Viaje Cigars
  144. Curiosidades Religiosas
  145. Curiosidades Walking Dead
  146. Viaje Misionero De Pablo
  147. Curiosidades 3 É Demais
  148. Viaje Ultima Hora
  149. Curiosidades Zootopia
  150. Lifestyle Games Like Sims
  151. Viaje 6 Dias Egipto
  152. Lifestyle 180
  153. Curiosidades 9
  154. Lifestyle Screens
  155. 4 To Viaje De Colon
  156. Lifestyle Articles
  157. Curiosidades Sobre Gatos
  158. What Does Vieja Mean In Spanish
  159. Curiosidades William Shakespeare
  160. Viaje Tiempo Atras Letra
  161. Viajes Quinto Sol

Wednesday, July 1, 2020

Adelante Sevilla Presenta Una Batería De Alegaciones A Una Ampliación Del Tranvía Que "Es Insostenible, Innecesaria E Insolidaria"

* El portavoz municipal de Adelante, Daniel González Rojas, ha ofrecido esta mañana una rueda de prensa acompañado por Valle López-Telo, copartavoz de Equo Verdes Sevilla, e Indalecio de la Lastra, consejero de Adelante en EMASESA

El portavoz municipal de Adelante Sevilla, Daniel González Rojas, ha comparecido hoy ante los medios de comunicación, acompañado por Valle López-Tello e Indalecio de la Lastra, para presentar las alegaciones presentadas al procedimiento de calificación ambiental de la ampliación del tranvía en el tramo San Bernardo-Nervión. González Rojas ha manifestado que "estamos ante una ampliación del tranvía que es insostenible, innecesaria e insolidaria y que, además, no ha contado con la planificación ni la participación ciudadana necesarias". El portavoz de Adelante denuncia que "todas las mejoras que se iban a introducir tras la aprobación del Plan Especial no están recogidas en el proyecto constructivo".
Daniel González Rojas cree que "Juan Espadas y el PSOE siguen engañando a la ciudad con este proyecto" y asegura que "a Ciudadanos se la han dado con queso". El edil afirma que "Adelante es la única fuerza política que ha mantenido durante todo este tiempo la misma posición, definida por la seriedad y la coherencia". Sin embargo, según explica González Rojas, "Espadas únicamente quiere inaugurar algo antes de las próximas elecciones, el PP guarda silencio, Ciudadanos cambia vergonzosamente de postura y Vox aún no se ha enterado de qué va la cosa".
El portavoz de Adelante Sevilla ha explicado que "las alegaciones presentadas se aglutinan en torno a cuatro ejes". "En primer lugar", señala González Rojas, "la ampliación del tranvía no supone un cambio de usos del coche privado en favor del transporte público" y señala que "la documentación aportada en el proyecto prevé incluso que haya hasta 2.300 coches más en el tramo de San Francisco Javier y Luis de Morales". "En segundo lugar", prosigue el edil, "en el proyecto no se justifica que haya una reducción de emisiones contaminantes, puesto que se mantiene el mismo número de carriles, se prevén más coches y, sin embargo, se nos dice que se van a reducir hasta 2'8 toneladas de CO2, sin que se aclare de donde salen esas cuentas". Tal y como explica González Rojas, "la propia Junta de Andalucía reconoce que los cálculos están incompletos al no contemplarse el consumo del propio tranvía".
En tercer lugar, Adelante cree que "esta ampliación se ha diseñado para beneficiar directamente al coche, puesto que se ha desaprovechado la oportunidad de mejorar el espacio urbano en beneficio del peatón". González Rojas explica que "no se eliminan las vías de servicio, no se eliminan carriles para coches y, en algunos tramos, se prevé reducir las aceras hasta un 50%". El portavoz de Adelante detalla que "en el propio proyecto se explica que el giro soterrado, que va a costar 5'6 millones de euros, se realiza para no interferir en el tráfico y solo permite ahorrar 12 segundos de viaje". Por último, González Rojas ha denunciado que "es rotundamente falso que se vayan a plantar más árboles y que los anuncios del gobierno respecto a transplantes y nuevas plantaciones son directamente mentira, pues no se contemplan en el proyecto". El concejal señala "las grandes contradicciones del proyecto" y recuerda que "mientras el Servicio de Parques y Jardines dice que es imposible transplantar la mayoría de árboles, Ayesa dice lo contrario, y cuando Juan Espadas afirma que va a plantar más árboles, el proyecto lo considera inviable".
Valle López-Tello, coportavoz de Equo Verdes Sevilla, ha señalado que su formación "se opone no solo a esta ampliación del tranvía, sino a cualquier proyecto que no contemple la movilidad de toda la ciudad y de su área metropolitana". López-Tello cree que "se trata de un proyecto insolidario porque duplica el itinerario de una línea de metro ya existente y de varias líneas de autobuses, mientras deja al resto de la ciudad con graves problemas de movilidad". La coportavoz de Equo Verdes Sevilla ha destacado que "con los 40 millones de euros que cuesta cada kilómetro de este tranvía, se podrían construir 7 kilómetros de tranvibús, que es un tranvía mucho más moderno y por el que apuestan ya la mayoría de ciudades europeas". López-Tello ha afirmado que "el tranvibús es un medio de transporte mucho más flexible y que se puede adaptar a diversas circunstancias" y "su menor coste permitiría crear mucho antes una red que abarque toda la ciudad". La representante de Equo ha pedido a Juan Espadas "que no llegue a la modernidad con 20 años de retraso".
Indalecio de la Lastra, consejero de Adelante Sevilla en LIPASAM, ha comenzado su intervención afirmando que "hay una alternativa al actual proyecto de ampliación del tranvía" y ha explicado que "el proyecto de Juan Espadas implicaría un gasto de 200 millones de euros para llegar a las Setas". De la Lastra ha afirmado que "la mayoría de ciudades, como San Sebastián, no apuestan ya por el tranvía". El consejero de Adelante en EMASESA ha reclamado que "esa inversión se destine a favorecer la movilidad desde los barrios hasta el centro", señalando que "en tan solo un año se podría implantar este sistema y TUSSAM podría liderar esa transformación". "Es un proyecto antiguo, que aumenta la contaminación y que supone agotar la mayoría de los fondos previstos para movilidad en este mandato", ha continuado De la Lastra, quien critica "que se pretende talar la mayoría de árboles de Nervión a cambio de una promesa que no se concreta en el tiempo".
More articles

Expertos De Varios Países Debaten En RD Sobre La “Responsabilidad Social Empresarial En La Cultura”



Expertos de varios países debaten en RD sobre la "Responsabilidad social empresarial en la cultura" 

Durante la sesión de apertura del seminario, organizado por el Ministerio de Cultura y la Agencia de Cooperación Española,  el profesor e investigador chileno Cristian Antoine ofreció  la primara conferencia magistral "Mecenazgo, valioso instrumento para el desarrollo cultural". 
Viceministro de Cultura Juan Morales, Diomedes Núñez Polanco, director de la Biblioteca Nacional Pedro Henríquez Ureña y Víctor Guedez.
Santo Domingo.- Con la asistencia de expertos de varios países se desarrolla en Santo Domingo el seminario-taller "Responsabilidad Social Empresarial (RSE) en la Cultura", organizado por Ministerio de Cultura y la Agencia de Cooperación Española.
Destacados  expertos de Chile, Venezuela, España y República Dominicana, así como del Fondo de las Naciones Unidas para la Infancia (UNICEF) y RSE exponen sobre la actualidad mundial en temas de RSE (Responsabilidad Social Empresarial). El seminario-taller se desarrollará los días 13,14 y 15 de septiembre, con una amplia delegación de destacados panelistas nacionales e internacionales.
La actividad quedó inaugurada el martes y concluye el viernes. Se desarrolla en   la Sala Aída Cartagena Portalatín de la Biblioteca Nacional Pedro Henríquez Ureña, con la asistencia de representantes del sector empresarial y cultural de República Dominicana.
El acto inaugural fue encabezado por el viceministro de Cultura, Carlos Santos, quien representó al ministro Pedro Vergés; el embajador de España  en República Dominicana, Alejandro Abellán García de Diego y Cristian Antoine, quien tuvo a cargo la conferencia inaugural del seminario.
El viceministro de Cultura Carlos Santos al dirigirse a los presentes destacó que en la actual gestión que encabeza el ministro Pedro Vergés en el Ministerio de Cultura se hace un especial énfasis en lograr una relación entre el sector público y privado para alcanzar un efectivo apoyo al desarrollo cultural del país.
Esta relación abarca el apoyo de programas en área de la música, el teatro, industria editorial, la literatura, artesanía y preservación del patrimonio cultural, en el marco de cutos esfuerzos se desarrolla el seminario inaugurado este martes.
En tal sentido, el funcionario agradeció al embajador español por su empeño y dedicación para montar el país éste adiestramiento, al tiempo de resaltar la calidad de cada uno de los expositores.
En su opinión,  se trata de  un primer paso para  impulsar la línea de trabajo para convertir  la responsabilidad social en la cultura en políticas públicas.
Antes, en las palabras introductorias del acto, pronunciadas por el embajador Alejandro Abellán García de Diego, éste valoró la importancia del seminario de  capacitación dirigido  a  la formación en  el ámbito de la cultura,  en su interacción con el sector privado.
El diplomático ponderó los esfuerzos del gobierno y pueblo dominicanos  en lo relativo a sus prioridades en el sector de la cultura, en particular en lo relativo a propiciar la interacción con el sector privado y el público.
Abellán García de Diego puso de relieve que en República Dominicana cerca del  4 %  del Producto Interno Bruto (PIB) está relacionado o vinculado a la cultura, de acuerdo a mediciones oficiales que se han realizado.
En el acto inaugural del seminario estuvieron presentes el viceministro de Cultura Juan Morales; Diomedes Núñez  Polanco, director de la Biblioteca Nacional Pedro Henríquez  Ureña y Víctor  Guedez; la pintura Elsa Núñez y los poetas Basilio Belliard y Juan Freddy Armando.
Cristian Antoine: importancia del mecenazgo
El experto en mecenazgo y profesor historia,  Cristian Antoine, en su exposición trató sobre la contribución del sector privado a la cultura y los desafíos para el mecenazgo del sector cultural.
Asimismo, se refirió con amplitud a las fuentes de financiamiento para el desarrollo de distintos aspectos de la cultural, en lo atinente a los mecenas y su implicación en la  calidad de vida de las personas.


Planteó el mecenazgo como un instrumento de comunicación que sirve a las empresas para la proyección de imagen, siendo esto un recurso de marketing  y comunicación, lo cual no ocurría en el pasado.
Cristian Antoine, conversó  con los participantes de los distintos estudios del mecenazgo desde variadas disciplinas  como la historia del arte y la comunicación desde la antigüedad hasta el presente.
El evento, se realiza con la finalidad  de fomentar una comprensión integral del concepto de la responsabilidad social en el ámbito de la cultura para  incentivar el desarrollo de políticas que mejoren la competitividad  de las empresas y su incidencia  en el desarrollo cultural del país.

Fuente
http://diasporadominicana.com/2017/09/13/expertos-de-varios-paises-debaten-en-rd-sobre-la-responsabilidad-social-empresarial-en-la-cultura/

Continue reading


17 Useful Websites for Hackers

  1. Hacked Gadgets: A resource for DIY project documentation as well as general gadget and technology news.
  2. KitPloit: Leading source of Security Tools, Hacking Tools, CyberSecurity and Network Security.
  3. Hack Forums: Emphasis on white hat, with categories for hacking, coding and computer security.
  4. Makezine: Magazine that celebrates your right to tweak, hack, and bend any technology to your own will.
  5. Phrack Magazine: Digital hacking magazine.
  6. Packet Storm: Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers.
  7. DEFCON: Information about the largest annual hacker convention in the US, including past speeches, video, archives, and updates on the next upcoming show as well as links and other details.
  8. Exploit DB: An archive of exploits and vulnerable software by Offensive Security. The site collects exploits from submissions and mailing lists and concentrates them in a single database.
  9. NFOHump: Offers up-to-date .NFO files and reviews on the latest pirate software releases.
  10. HackRead: HackRead is a News Platform that centers on InfoSec, Cyber Crime, Privacy, Surveillance, and Hacking News with full-scale reviews on Social Media Platforms.
  11. The Hacker News: The Hacker News — most trusted and widely-acknowledged online cyber security news magazine with in-depth technical coverage for cybersecurity.
  12. SecurityFocus: Provides security information to all members of the security community, from end users, security hobbyists and network administrators to security consultants, IT Managers, CIOs and CSOs.
  13. Hakin9: E-magazine offering in-depth looks at both attack and defense techniques and concentrates on difficult technical issues.
  14. SecTools.Org: List of 75 security tools based on a 2003 vote by hackers.
  15. Black Hat: The Black Hat Briefings have become the biggest and the most important security conference series in the world by sticking to our core value: serving the information security community by delivering timely, actionable security information in a friendly, vendor-neutral environment.
  16. Offensive Security Training: Developers of Kali Linux and Exploit DB, and the creators of the Metasploit Unleashed and Penetration Testing with Kali Linux course.
  17. Metasploit: Find security issues, verify vulnerability mitigations & manage security assessments with Metasploit. Get the worlds best penetration testing software now.

Thursday, June 11, 2020

Probing For XML Encryption Weaknesses In SAML With EsPReSSO

Security Assertion Markup Language (SAML) is an XML-based standard commonly used in Web Single Sign-On (SSO) [1]. In SAML, the confidentiality of transferred authentication statements against intermediaries can be provided using XML Encryption [2]. However, implementing XML Encryption in a secure way can be tricky and several attacks on XML Encryption have been identified in the past [3] [4]. Therefore, when auditing a SAML endpoint, one should always consider testing for vulnerabilities in the XML Encryption implementation.

This blog post introduces our latest addition to the SAML Attacker of our BurpSuite extension EsPReSSO: the Encryption Attack tab. The new tab allows for easy manipulation of the encrypted parts within intercepted SAML responses and can, therefore, be used to quickly assess whether the SAML endpoint is vulnerable against certain XML Encryption attacks.


Weaknesses of XML Encryption

Implementations of XML Encryption can be vulnerable to adaptive chosen ciphertext attacks. This is a class of attacks in which the attacker sends a sequence of manipulated ciphertexts to a decryption oracle as a way to gain information about the plaintext content.
Falsely implemented XML Encryption can be broken using:
  • an attack against the CBC-mode decryption (quite similar to a padding oracle attack) [3] or
  • a Bleichenbacher attack against the RSA-PKCS#1 encryption of the session key  [4].
SAML makes use of XML Encryption and its implementations could, therefore, also be vulnerable to these attacks.

XML Encryption in SAML

To support confidential transmission of sensitive data within the SAML Assertion, assertions can be encrypted using XML Encryption. An EncryptedAssertion is shown in the abridged example below.

<EncryptedAssertion>
  <EncryptedData>
    <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
    <KeyInfo>
      <EncryptedKey>
        <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5"/>
        <CipherData>
          <CipherValue>
            [...]
          </CipherValue>
        </CipherData>
      </EncryptedKey>
    </KeyInfo>
    <CipherData>
        <CipherValue>
          [...]
        </CipherValue>
    </CipherData>
  </EncryptedData>
</EncryptedAssertion>

The EncryptedAssertion contains an EncryptedData element, which in turn is the parent of the EncryptionMethod, KeyInfo, and CipherData elements.  SAML makes use of what is referred to as a hybrid encryption scheme. This is done using a session key which symmetrically encrypts the payload data (the example uses AES-128 in CBC mode), resulting in the ciphertext contained in the EncryptedAssertion/EncryptedData/CipherData/CipherValue child element. The session key itself is encrypted using an asymmetric encryption scheme. In our example, RSA-PKCS#1.5 encryption is used with the public key of the recipient, allowing the contents of the the EncryptedKey child element to be derived from the KeyInfo element. 

Encryption Attacker

Our BurpSuite extension EsPReSSO can help detect vulnerable implementations with the newly integrated Encryption Attacker within EsPReSSO's SAML module.

Once a SAML response which contains an EncryptedAssertion has been intercepted, open the SAML tab, select the Attacks pane, and choose Encryption from the dropdown menu. This works in Burp's Proxy, as well as in the Repeater tool, and is depicted below.
As sketched out above, the symmetric session key is encrypted using the recipient's public key. Since the key is public, anybody can use it to encrypt a selected symmetric key and submit a valid encryption of arbitrary messages to the recipient. This is incredibly helpful because it allows us to produce ciphertexts that decrypt the chosen plaintexts. To accomplish this, one can purposefully send invalidly padded messages, or messages containing invalid XML, as a method to trigger and analyze the different reactions of the decryption endpoint (i.e, turning the endpoint into a decryption oracle). To facilitate these investigations, the new Encryption Attacker makes this process dead simple.
The screenshot above shows the essential interface of the new encryption tab:
At the top, the certificate used to encrypt the symmetric session key can be pasted into the text field. This field will be pre-filled automatically if the intercepted SAML message includes a certificate in the KeyInfo child element of the EncryptedData element. The Update Certificate checkboxes above the text area can be used to include the certificate in the manipulated SAML message.
In the Symmetric Key text field, the hexadecimal value of the symmetric session key can be set. Choose the asymmetric algorithm from the dropdown menu and click Encrypt key -- this will update the corresponding KeyInfo elements of the intercepted SAML message. 

The payload in the text area labeled XML data can now be entered. Any update in the XML data field will also be reflected in the hexadecimal representation of the payload (found on right of the XML data field). Note that this is automatically padded to the blocklength required by the symmetric algorithm selected below. However, the payload and the padding can be manually adjusted in the hex editor field.

Eventually, click the Encrypt content button to generate the encrypted payload. This will apply the changes to the intercepted SAML message, and the manipulated message using Burp's Forward or Go button can now be forwarded, as usual.

Probing for Bleichenbacher Oracles

Bleichenbacher's attack against RSA-PKCS1 v1.5 encryption abuses the malleability of RSA to draw conclusions about the plaintext by multiplying the ciphertext with adaptively chosen values, and observing differences in the received responses. If the (error-) responses differ for valid and invalid PKCS1 v1.5 ciphertexts, Bleichenbachers' algorithm can be used to decrypt the ciphertext without knowing the private key [6].

To determine whether or not a SAML endpoint is vulnerable to Bleichenbacher's Attack, we simply need to check if we can distinguish those responses received when submitting ciphertexts that are decrypted into invalidly formatted PKCS1 v1.5 plaintexts, from the responses we receive when sending ciphertexts that are decrypted into validly formatted plaintexts. 

Recall that PKCS1 v1.5 mandates a certain format of the encrypted plaintext, namely a concatenation of a BlockType 00 02, a randomized PaddingString (PS) that includes no 00 bytes, a 00 (NULL-byte) as delimiter, and the actual plaintext message. The whole sequence should be equal in size to the modulus of the RSA key used. That is, given the byte length k of the RSA modulus and the message length |m|, PS has the length |PS| = k - 3 - |m|. Furthermore, PKCS1 v1.5 demands that |PS| to be at least eight bytes long [5]. 

In SAML, the recipient's public key is usually known because it is published in the metadata, or even included in the EncryptedAssertion. For this reason, we do not need to fiddle around with manipulated ciphertexts. Instead, we simply submit a validly formatted RSA-PKCS1 v1.5 encrypted message and an encrypted message which deciphers into an invalidly formatted plaintext. As an example, assume an RSA public key of 2048 bits which we want to use to encrypt a 16 byte session key `01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10` (hexadecimal representation). |PS|$ is $2048/8 - 3 - 16 = 237, so a valid PKCS1 v1.5 plaintext, ready to be encrypted using `AA` for all 237 padding bytes, could look like the listing shown below.

00 02 AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA
AA AA AA AA AA AA AA AA AA AA AA AA AA AA AA 00
01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10
In the Encryption attack pane of EsPReSSO, ensure that the correct public key certificate has been added to the Certificate field. Insert a valid plaintext, such as the one above, into the Symmetric Key field and select Plain RSA encryption from the Algorithm drop down menu. Click the Encrypt button to compute the RSA transformation and apply the new EncryptedKey element to the intercepted SAML message. Now, submit the message by clicking Burp's Go or Forward button and carefully inspect the response.

Next, repeat the steps outlined above, but this time submit an invalid PKCS1 v1.5 message. For example, consider using an invalid BlockType of `12 34` instead of `00 02`, or replace the `00` delimiter so that the decryptor is unable to determine the actual message after decrypting the ciphertext. If you are able to determine from the recieved responses whether or not the submitted ciphertext decrypted into a valid PKCS1 v1.5 formatted plaintext, chances are high that the decryptor can be used as a Bleichenbacher oracle. Don't forget to take into account the actual XML data, i.e., the assertion encrypted with the new session key; by submitting valid or invalid XML, or by removing signatures from the SAML message or the assertion you may increase your chances of detecting differences in the returned responses.

Probing for Oracles in CBC-Mode Decryption

Another known attack on XML Encryption is aimed at the Cipher Block Chaining (CBC) mode, which can be used with the block ciphers AES or 3DES [2]. The attack is described in detail in this referenced paper [3] and is quite similar to Padding-Oracle attacks on CBC mode; the malleability of CBC mode encryption enables the attacker to perform a bytewise, adaptive manipulation of the ciphertext blocks which are subsequently sent to the decryptor. In most cases, the manipulated ciphertext will not decrypt to valid XML and an error will be returned. Sometimes, however, the plaintext will be parsed as valid XML, in which cases an error is thrown later on at the application layer. The attacker observes the differences in the responses in order to turn the decryptor into a ciphertext validity oracle which can be used to break the encryption.  Due to some particularities of the XML format, this attack can be very efficient, enabling decryption with about 14 requests per byte, and it is even possible to fully automate the process [7].

In order to determine if a particular SAML service provider is vulnerable to this attack, we can avoid the cumbersome ciphertext manipulation, if we are in possession of the decryptor's public key:
In the Encryption Attacker tab of EsPReSSO, add the public key certificate to the Certificate field (if necessary) and insert a symmetric key of your own devising into the  Symmetric Key text field. Select an appropriate RSA encryption method and click the Encrypt button to apply the new EncryptedKey element to the original SAML message. 

An XML message can now be inserted into the XML data text field. Select a CBC mode encryption algorithm and click Encrypt to apply the changes. As in the example above, press Burp's Go or Forward button to send the message and carefully inspect the response. Try sending invalid XML, e.g., by not closing a tag or using the `&` character without a valid entity and keep an eye open for differences in the returned responses. To manipulate the padding, the text field on the right side shows the hexadecimal representation of the plaintext, including the CBC padding. If you send a single block and set the last byte, which indicates the padding length to the blocksize, i.e. 16 or 0x10 for AES, the ciphertext should decrypt into an empty string and is generally considered "valid" XML.

Please refer to the original paper for more details, tips, and tricks for performing the actual attack [3]. 

Summary

The new XML Encryption attacker included in EsPReSSO can help security auditors to quickly assess if a SAML endpoint is vulnerable to known attacks against XML Encryption. To this end, the decryptor's public key is used in order to send suitable test vectors that can be provided in plaintext. Ciphertext manipulation is, therefore, not required. The actual process of decrypting an intercepted SAML message is, however, considered out of scope and not implemented in EsPReSSO.

In case you wonder how XML Encryption can be used in a secure fashion, here are some considerations [6]:
  • Always use an authenticated encryption mode such as AES-GCM instead of the CBC-mode encryption.
  • Using RSA-PKCS1 v1.5 within XML Encryption is particularly difficult to do in a secure manner, and it is recommended to use RSA with Optimal Asymmetric Encryption Padding (OAEP) instead [2].
  • Apply a digital signature over the whole SAML response, and ensure it is properly validated before attempting to decrypt the assertion. This should thwart the attack as a manipulated response can be recognized as such and should be rejected.
----------
Related posts
  1. Pentest Nmap
  2. Hacker Kevin Mitnick
  3. Hackerrank Sql
  4. Pentest Iso
  5. Hacking Linux
  6. Pentest Online Course
  7. Hacking Attack
  8. Hacking Bluetooth
  9. Hacker Types
  10. Hacking Site
  11. Hacking
  12. Hacking Books
  13. Hacking 3Ds
  14. Pentesting Tools
  15. Pentest Stages
  16. Pentest Dns Server