From 0198667ca2da1a9d070ea17676de75079128f5d9 Mon Sep 17 00:00:00 2001 From: stefan Date: Sun, 22 Feb 2026 15:38:16 +0100 Subject: 300-NetBSD-RelEng-STRIDE --- .../100-GnuPG-Keysigning-DFD.png | Bin 57179 -> 57304 bytes .../100-GnuPG-Keysigning-DFD.svg | 2 +- .../100-GnuPG-Keysigning-SEQ-KSP-WoT.png | Bin 121411 -> 121531 bytes .../100-GnuPG-Keysigning-SEQ-KSP-WoT.svg | 2 +- .../300-NetBSD-RelEng-STRIDE.png | Bin 0 -> 79701 bytes .../300-NetBSD-RelEng-STRIDE.puml | 96 +++++++++++++++++++++ .../300-NetBSD-RelEng-STRIDE.svg | 1 + .../GnuPG-WoT-Download/README.adoc | 11 +++ 8 files changed, 110 insertions(+), 2 deletions(-) create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.puml create mode 100644 PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg (limited to 'PlantUML-ModelingTrust/GnuPG-WoT-Download') diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png index c1709eb..88aac4b 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.svg index 6e632bd..19381e4 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.svg +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-DFD.svg @@ -1 +1 @@ -Daten Flow Diagram - GnuPG Keysigning between Alice and BobDFD: Alice and Bob KeysigningCompiled: 2026-02-22 12:16 +0100Daten Flow Diagram - GnuPG Keysigning between Alice and BobAliceBobKeyserverAlice KeyringBob KeyringPubKey AlicePubKey Bobsigned PubKey of Alice -> Bobsigned PubKey of Bob -> Alice1. export own PubKey1. export own PubKey2. mail own PubKey to Bob2. mail own PubKey to Alice3. sign PubKey of Alice3. sign PubKey of Bob4. mail signed PubKey of Alice to the mail address in the key4. mail signed PubKey of Bob to the mail address in the key5. import signed PubKey5. signed PubKey6. send new signature to Keyserver6. send new signature to Keyserver \ No newline at end of file +Daten Flow Diagram - GnuPG Keysigning between Alice and BobDFD: Alice and Bob KeysigningCompiled: 2026-02-22 15:37 +0100Daten Flow Diagram - GnuPG Keysigning between Alice and BobAliceBobKeyserverAlice KeyringBob KeyringPubKey AlicePubKey Bobsigned PubKey of Alice -> Bobsigned PubKey of Bob -> Alice1. export own PubKey1. export own PubKey2. mail own PubKey to Bob2. mail own PubKey to Alice3. sign PubKey of Alice3. sign PubKey of Bob4. mail signed PubKey of Alice to the mail address in the key4. mail signed PubKey of Bob to the mail address in the key5. import signed PubKey5. signed PubKey6. send new signature to Keyserver6. send new signature to Keyserver \ No newline at end of file diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png index 0a906b4..80b30c8 100644 Binary files a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.svg index 72a3e65..9eb68c5 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.svg +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/100-GnuPG-Keysigning-SEQ-KSP-WoT.svg @@ -1 +1 @@ -Sequence Diagram - Mutual Key Signing with Owner Trust (<font:monospace>tsign</font>)Sequence Diagram - Mutual Key Signing with Owner Trust (tsign)AliceBobAlice GnuPGBob GnuPGAlice KeyringBob KeyringAlice Owner TrustBob Owner TrustAlice PassportBob PassportAliceAliceBobBobAlice GnuPGAlice GnuPGBob GnuPGBob GnuPGAlice KeyringAlice KeyringBob KeyringBob KeyringAlice Owner TrustAlice Owner TrustBob Owner TrustBob Owner TrustAlice PassportAlice PassportBob PassportBob PassportKey Signing PartyID Verification via PassportVerify Bobs Passportverify ID and Key-FingerprintVerify Alice Passportverify ID and Key-Fingerprint:wKeyExchangeKey ExchangeExport PubKeyRead PubKeyof AliceSend PubKeyof AliceExport PubKeyRead PubKeyof BobSend PubKeyof BobSigningSign Alice key(identity verified)Store signature on Alice keyMail signed Alice keySign Bob key(identity verified)Store signature on Bob keyMail signed Bob keyImportImport signed Alice keyUpdate keyringImport signed Bob keyUpdate keyringSet Owner TrustSet owner trust for BobStore trust levelSet owner trust for AliceStore trust levelTrust calculation voa Web of TrustWeb of Trust CalculationCheck validity of Bob keyRead signaturesRead owner trust valuesValidity status(unknown/marginal/full)Check validity of Alice keyRead signaturesRead owner trust valuesValidity status(unknown/marginal/full)Sequence of Key Signing with n==2Compiled: 2026-02-22 12:16 +0100Keysigning between Alice and Bob.gpg --recv-keys 0x11F4C41EB3FBAE33.gpg --edit-key 0x11F4C41EB3FBAE33.tsign.gpgarmorexport-options export-minimal --export 0xB3FBAE33 > 0xB3FBAE33.asc \ No newline at end of file +Sequence Diagram - Mutual Key Signing with Owner Trust (<font:monospace>tsign</font>)Sequence Diagram - Mutual Key Signing with Owner Trust (tsign)AliceBobAlice GnuPGBob GnuPGAlice KeyringBob KeyringAlice Owner TrustBob Owner TrustAlice PassportBob PassportAliceAliceBobBobAlice GnuPGAlice GnuPGBob GnuPGBob GnuPGAlice KeyringAlice KeyringBob KeyringBob KeyringAlice Owner TrustAlice Owner TrustBob Owner TrustBob Owner TrustAlice PassportAlice PassportBob PassportBob PassportKey Signing PartyID Verification via PassportVerify Bobs Passportverify ID and Key-FingerprintVerify Alice Passportverify ID and Key-Fingerprint:wKeyExchangeKey ExchangeExport PubKeyRead PubKeyof AliceSend PubKeyof AliceExport PubKeyRead PubKeyof BobSend PubKeyof BobSigningSign Alice key(identity verified)Store signature on Alice keyMail signed Alice keySign Bob key(identity verified)Store signature on Bob keyMail signed Bob keyImportImport signed Alice keyUpdate keyringImport signed Bob keyUpdate keyringSet Owner TrustSet owner trust for BobStore trust levelSet owner trust for AliceStore trust levelTrust calculation voa Web of TrustWeb of Trust CalculationCheck validity of Bob keyRead signaturesRead owner trust valuesValidity status(unknown/marginal/full)Check validity of Alice keyRead signaturesRead owner trust valuesValidity status(unknown/marginal/full)Sequence of Key Signing with n==2Compiled: 2026-02-22 15:37 +0100Keysigning between Alice and Bob.gpg --recv-keys 0x11F4C41EB3FBAE33.gpg --edit-key 0x11F4C41EB3FBAE33.tsign.gpgarmorexport-options export-minimal --export 0xB3FBAE33 > 0xB3FBAE33.asc \ No newline at end of file diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png new file mode 100644 index 0000000..d41c787 Binary files /dev/null and b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.png differ diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.puml b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.puml new file mode 100644 index 0000000..5de5cbe --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.puml @@ -0,0 +1,96 @@ +@startuml + ' keine farben!! +' !theme mimeograph + +skinparam shadowing false +skinparam rectangle { + BorderThickness 2 +} + +Title Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1) + +header += Attack Flows and Trust Boundaries +Timestamp: %date("yyyy-MM-dd kk:mm Z") +endheader + +legend right +|= STRIDE |= Abbrevation| +|S| Spoofing | +|T| Tampering | +|R| Repudiation | +|I| Information Disclosure | +|DoS| Denial of Service | +|EoP| Elevation of Privilege | + +Relationship Colour +|= Colour |= Attack Phase| +|<#ff0000> Red| Initial Exploit | +|<#800080> Deep Purple| Lateral Movement | +|<#ffa500> Orange| Integrity Violation | +|<#008000> Green| Legitimate Signing | + +LightGray box: Trust Boundary +Notes on Relation: STRIDE category +DF: Data Flow +AT: Attack Path +endlegend + +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' + + +rectangle "Internet" #line:LightGray { + actor "Black Hat"" as Attacker #FF0000 +} + +rectangle "DMZ" #line:LightGray { + rectangle "Public Web Server:" as WWW + note right of WWW : T, I, DoS, EoP +} + +rectangle "Internal Network" #line:LightGray { + rectangle "CVS RelEng" as BS + note right of BS : T, R, EoP + database "Release Repo HVT" as Repo + note right of Repo : S, T, R, I, DoS, EoP + actor "Security Officer" #00ff00 +} + + + + +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' + + +BS --> Repo : (DF1) Publish ISO + Checksums +"Security Officer" -[#green,thickness=2]-> Repo : (DF2) Sign Checksums (GnuPG) +Repo --> WWW : (DF3) Deploy Artifacts +WWW --> Attacker : (DF4) Distribute ISO + Checksums + Signature + + + +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' +' '''''''''''''''''''''''''''''''''''''''''''''''''''''''' + +Attacker -[#red,dashed]-> WWW : (AT1) Exploit Webserver Vuln +note on link: EoP + +WWW -[#purple,dashed]-> Repo : (AT2) Pivot to Repo +note on link: EoP [#Orange] + +Repo -[#orange,dashed,thickness=2]-> Repo : (AT3) Replace ISO\n&& Checksum\n&& Signature +note on link: Tamper + +' Repo -[#orange,dashed]-> Repo : (AT4) Modify Checksums\n +' note on link: Tamper +' +' Repo -[#orange,dashed]-> Repo : (AT5) Replace GPG Signature\n +' note on link: Tamper + + + + +@enduml diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg new file mode 100644 index 0000000..257ddfc --- /dev/null +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/300-NetBSD-RelEng-STRIDE.svg @@ -0,0 +1 @@ +Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)Attack Flows and Trust BoundariesTimestamp: 2026-02-22 15:37 +0100Attack Flow and Trust Boundaries: manipulated ISO image AND manipulated checksums/signatures (SLSA1)InternetDMZInternal NetworkBlack Hat"Public Web Server:T, I, DoS, EoPCVS RelEngT, R, EoPRelease RepoHVTS, T, R, I, DoS, EoPSecurity Officer(DF1) Publish ISO + Checksums(DF2) Sign Checksums (GnuPG)(DF3) Deploy Artifacts(AT2) Pivot to RepoEoP [#Orange](DF4) Distribute ISO + Checksums + Signature(AT1) Exploit Webserver VulnEoP(AT3) Replace ISO&& Checksum&& SignatureTamperSTRIDEAbbrevationSSpoofingTTamperingRRepudiationIInformation DisclosureDoSDenial of ServiceEoPElevation of Privilege Relationship ColourColourAttack PhaseRedInitial ExploitDeep PurpleLateral MovementOrangeIntegrity ViolationGreenLegitimate Signing LightGray box: Trust BoundaryNotes on Relation: STRIDE categoryDF: Data FlowAT: Attack Path \ No newline at end of file diff --git a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc index f3f7e37..59e3da1 100644 --- a/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc +++ b/PlantUML-ModelingTrust/GnuPG-WoT-Download/README.adoc @@ -12,3 +12,14 @@ image::100-GnuPG-Keysigning-DFD.png[] image::100-GnuPG-Keysigning-SEQ-KSP-WoT.png[] + + +== NetBSD RelEng Attack STRIDE + +The ISO Image is built, signed and uploaded to the WWW server, as well as the Signature file and checksums. + +Evil Black Hat hacks the webserver, and swaps the ISO image for a manipulated one with a valid Signature. + +The manipulated Signature verifies the fake-integrity of the manipulated ISO image, but not the authenticity. + +image::300-NetBSD-RelEng-STRIDE.png[] -- cgit v1.2.3