Game Consoles - Are They Secure?
Total Page:16
File Type:pdf, Size:1020Kb
Game Consoles - Are they secure? Halvar Myrmo Master’s Thesis Master of Science in Information Security 30 ECTS Faculty of Computer Science and Media Technology Gjøvik University College, 2007 Avdeling for informatikk og medieteknikk Høgskolen i Gjøvik Postboks 191 2802 Gjøvik Faculty of Computer Science and Media Technology Gjøvik University College Box 191 N-2802 Gjøvik Norway Game Consoles - Are they secure? Abstract The new game consoles and handheld machines available on the market today are de- signed with Internet and multiplayer connectivity in mind. They are also designed to be used for several years to come, and to be connected to the Internet 24 hours a day. This combination of computational power and connectivity could make the game consoles lucrative targets for viruses, Trojans, botnets, spam and other malware. Users of home computers are slowly learning that they need to protect their comput- ers through the use of firewalls, antivirus and the like. But most of us probably do not consider a game console to be a computer, and therefore does not consider protecting it the same way we protect a normal computer. The goal of this thesis is to find out if new vulnerabilities are introduced into the home when connecting a gaming console to the Internet. We also take a look at children’s use of computer and video games, and what the parents know about it. We try to combine this information into an overview of how secure it is to use a game console and play computer and video games online. iii Game Consoles - Are they secure? Sammendrag De nye spillkonsollene og håndholdte maskinene som finnes på markedet i dag er de- signet med tanke på Internett og flerspiller muligheter. De er også designet for å vare i mange år og for å være koblet til Internett 24 timer i døgnet. Denne kombinasjonen av regnekraft og tilkoblingsmuligheter kan gjøre spillkonsoller ett lukrativt mål for virus, trojanere, botnet, spam og annen ondsinnet programvare. Eiere av datamaskiner begynner sakte men sikkert å lære at de trenger å beskytte datamaskinen sin med brannmur, antivirus og lignende. Men de fleste av oss anser nok ikke en spillkonsoll for å være en datamaskin, og vil derfor ikke tenke på å beskytte den på samme måte som en vanlig datamaskin. Målet med denne oppgaven er å finne ut om det introduseres nye sårbarheter i hjem- met når en spillkonsoll kobles til Internett. Vi tar også en nærmere kikk på barns bruk av data og videospill, og hva foreldre vet om dette. Vi prøve å sammenfatte denne infor- masjonen til ett helhetlig bilde over hvor trygt det er å bruke en spillkonsoll og spill data og videospill på Internett. v Game Consoles - Are they secure? Contents Abstract .......................................... iii Sammendrag ....................................... v Contents ......................................... vii List of Figures ...................................... xi List of Tables ....................................... xiii List of Definitions .................................... xv Preface .......................................... xvii 1 Introduction ..................................... 1 1.1 Chapter summary ................................ 1 1.2 Topic ....................................... 1 1.3 Problem description .............................. 1 1.4 Motivation .................................... 2 1.5 Research questions ............................... 2 1.6 Summary of claimed contributions ...................... 2 1.7 Outline of the report .............................. 2 2 Related work ..................................... 5 2.1 Chapter summary ................................ 5 2.2 The modification community ......................... 5 2.3 Lessons learned from the computer world .................. 6 2.4 Rootkits ..................................... 6 2.5 Distributed computing ............................. 8 2.6 Botnets ..................................... 8 2.7 Cheating in games ............................... 9 2.8 Homebrew ................................... 12 2.9 Child grooming ................................. 12 3 Choice of methods .................................. 15 3.1 Chapter summary ................................ 15 3.2 Our choice of method ............................. 15 3.3 The technical experiments ........................... 16 3.4 The questionnaire ............................... 17 4 Equipment ...................................... 19 4.1 Chapter summary ................................ 19 4.2 The consoles .................................. 19 4.2.1 PlayStation 2 .............................. 19 4.2.2 PlayStation 3 .............................. 20 4.2.3 PlayStation Portable .......................... 20 4.2.4 Xbox ................................... 21 4.2.5 Xbox 360 ................................ 21 4.2.6 Nintendo Wii .............................. 22 4.2.7 Nintendo DS .............................. 23 vii Game Consoles - Are they secure? 4.3 The software .................................. 23 4.3.1 Nmap .................................. 23 4.3.2 Nessus .................................. 24 4.3.3 Wireshark ................................ 24 4.3.4 Metasploit Framework ......................... 24 4.3.5 SPSS ................................... 24 5 Technical results ................................... 25 5.1 Chapter summary ................................ 25 5.2 The modified Xbox with the modchip enabled ................ 25 5.2.1 Known buffer-overflow vulnerabilities ................ 26 5.3 The modified Xbox with the modchip disabled ................ 26 5.4 The Xbox 360 .................................. 26 5.5 The Xbox Live service ............................. 27 5.5.1 Kerberos ................................. 28 5.5.2 Other security protocols ........................ 29 5.5.3 Protocol modifications ......................... 29 5.6 PlayStation 2 .................................. 30 5.7 PlayStation Portable .............................. 30 5.8 Nintendo Wii .................................. 31 5.8.1 Vulnerability in the Wii ......................... 31 5.8.2 Wii network services .......................... 32 5.8.3 Akamai Technologies .......................... 32 5.8.4 WiiConnect24 .............................. 33 5.9 Nintendo DS .................................. 33 6 Results from the questionnaire .......................... 35 6.1 Chapter summary ................................ 35 6.2 Question 23 ................................... 35 6.3 Question 24 ................................... 36 6.4 Question 25 ................................... 37 6.5 Question 26 ................................... 39 6.6 Question 27 ................................... 39 6.7 Question 28 ................................... 40 6.8 Question 29 ................................... 41 6.9 Question 30 ................................... 42 6.10 Question 31 ................................... 43 6.11 Game console statistics ............................. 44 6.12 Indexes ..................................... 45 6.12.1 Network enabled consoles ....................... 45 6.12.2 Negativity index ............................ 47 6.12.3 Vulnerability index ........................... 49 6.12.4 Own computer usage .......................... 51 6.12.5 Own video and computer game usage ................ 53 7 Discussion and conclusions ............................ 55 7.1 Discussion .................................... 55 7.2 Conclusions ................................... 57 8 Further work ..................................... 59 viii Game Consoles - Are they secure? 8.1 Chapter summary ................................ 59 Bibliography ....................................... 63 9 Appendices ...................................... 69 9.1 The questionnaire (Norwegian) ........................ 69 9.2 The questionnaire (English translation) .................... 74 ix Game Consoles - Are they secure? List of Figures 1 The setup of the test network. ......................... 16 2 An overview of a normal Kerberos protocol run. ............... 28 3 An overview of how the Xbox Live system works ............... 29 4 Question 23: I feel that playing computer/video games on the Internet is unsocial ..................................... 36 5 Question 24: I feel that it is smart to limit children’s time usage when it comes to playing computer and video games ................. 37 6 Question 25: I think children can become violent by playing computer/video games that contains violence ......................... 38 7 Question 26: I feel that children rather should be doing sports than playing computer/video games ............................. 39 8 Question 27: I think children become inactive by playing computer/video games ...................................... 40 9 Question 28: It is smart of adults to play computer/video games with the children, in order to get knowledge of children’s use of this medium .... 41 10 Question 29: It is safer for the child(ren) to play on a game console than surfing on the Internet ............................. 42 11 Question 30: Game consoles that are connected to the Internet are a target for virus ..................................... 43 12 Question 31: We use the built-in possibilities in the game consoles to con- trol what kind of contents the child(ren) has access to ........... 44 13 Game console statistics ............................. 45 14 Network enabled consoles ........................... 46 15 Question 3: We have game consoles that are connected to the Internet .. 47 16 Negativity towards computer and