Monday, February 2, 2009

SecureState Speaks at ShmooCon 2009

SchmooCon for SecureState! SecureState's Dave Kennedy and Matt Neely will be speaking at ShmooCon in Washington, D.C., the annual East coast hacker convention hell-bent on offering three days of an interesting atmosphere for demonstrating technology exploitation, inventive software & hardware solutions, and open discussions of critical infosec issues. The first day is a single track of speed talks, One Track Mind. The next two days, there are three tracks: Break It!, Build It!, and Bring It On!.

Principal at SecureState, Dave Kennedy focuses on the technical side of security, performing penetration tests, source code review, web application security, data forensics, electronic discovery and wireless assessments. Prior to SecureState, Dave worked for the National Security Agency (N.S.A.) and has worked with some of the nations most elite security groups. Dave is also the author of Fast-Track, an open-source penetration testing suite available in Linux, has previously presented at Defcon, and is a contributor to the BackTrack distributions.

Dave's presentation (The Fast-Track Suite: Advanced Penetration Techniques Made Easy) will be the last talk in the Bring It On! track where he will discuss attacks in detail and also release the newest version of Fast-Track.


Matt Neely, Profiling Manager at SecureState
Matt Neely, Profiling Manager at SecureState, will be presenting "Radio Reconnaissance in Penetration Testing - All Your RF Are Belong to Us," in the first talk of Bring It On! track this Saturday.

Read more!

Friday, January 16, 2009

SecureState Attends PCI Compliance Seminar with ISACA


Craig Monastra of Sterling Jewelers with Brian Telesz and Nicole McClain of SecureState
Today, ISACA’s membership—more than 86,000 strong worldwide—is characterized by its diversity. Members live and work in more than 160 countries and cover a variety of professional IT-related positions inlcuding but not limited to IS auditor, consultant, educator, IS security professional, regulator, chief information officer and internal auditor.

SecureState's Brian Telesz and Nicole McClain (pictured above with Craig Monastra of Sterling Jewelers) attended the most recent ISACA seminar at Harry's Steakhouse for good food and a great presentation on PCI Compliance. Keynote speaker was Lisa Peterson of Progressive Insurance.

The Information Systems Audit and Control Association is primarily focused on promoting quality IS audit and governance education to its members. The IS audit profession is based and dependent upon technological expertise. With Audit and Compliance being one of SecureState’s four divisions of expertise its helps our consultants and directors keep abreast on the latest hot topics, concerns and trends in the IT audit world. SecureState is a leader in the Audit and Compliance world. We engage in many different environments such as finance, insurance, manufacturing, retail and energy which gives us a very diverse expertise in the many compliances and security regulations that companies need to adhere to.

In addition to the importance of Audit and Compliance, SecureState belongs to the local chapter and attends the monthly meetings to keep SecureState in front our current and prospective clients who are members. We will also speak and present at these monthly meetings which helps educate ISACA chapter members on what SecureState sees out in the field during engagements and clarify and educate on IT audit issues.

Would you like SecureState to speak at your next event? Contact SecureState at 800.903.6264 for more information.

Read more!

Wednesday, December 24, 2008

Security Stuck at the Kids Table?

Where does the Security Department reside at your organization?

I am sure many readers with first answer this question with, “What Security Department?” That is a fair answer for many organizations out there in the real world and for those of you that answered the question that way, I feel sorry for you and your organization... It is only a matter of time before you end up on the front page on the newspaper with a headline reading something like, “Hacker Breaches Company ABC, takes 100,000 Social Security Numbers” or “Insider Steals 20,000 Credit Card Numbers from Company XYZ.” Trust me, I have seen it before. It is only a matter of time.
For the rest of you, where does Security sit? Under the Director of IT? Under the Chief Information Officer? How about under the Audit Department? While there are advantages to each, the disadvantages far outweigh the benefits.

Let’s examine.

Under the Director of IT: Last time I checked, the IT department’s main concern is the availability of resources and data. As a security guy, I really don’t care about availability. If our network is unavailable, we are secure. As such, every decision I make in the best interest of security is going to be analyzed based on the effects of availability, and if these decisions conflict with their goals, they are not going to go far.

Under the CIO: Same problems as above and also include problems with lack of funding, lack of power (i.e. the ability to make decisions and have them implemented), and lack of representation in senior management.

Under the Audit Department: Who is an auditor’s on friend? Another auditor! Okay, so that wasn’t a good joke, but there is truth to it. Most people don’t like auditors and being stuck under that department makes others think Security is one of them. Therefore, everyone from the bottom to the top will be generally “on guard” when you come around and resistant to your goals because of it.

So where is the best place for Security to sit? At the same level as the CIO, but independent from them. Security should be its own Department and have its own voice in the Senior Management circle. They should have their own budget and the ability to defend all decisions made in the best interest of security without being kyboshed before it makes it to the C-level.

In a world with increasingly more stringent regulations and compliances (i.e. PCI, HIPAA, SOX, GLBA), and more sophisticated hackers and hacking techniques, it’s time to move Security where it rightfully belongs, at the adult table.

Read more!

Tuesday, December 23, 2008

Economy bad… breaches go up!

Cut jobs, layoff people, hell don’t buy coffee, but don’t spend less on assessments during a down economy!

Contrary to popular belief during a down economy it is crucial that companies maintain an assessment program. Based on an article I recently wrote for law.com... when the economy is bad (which appears to be the case for 2009) the chance for theft of corporate assets increases. Based on the fraud triangle below are three areas that if aligned a person is willing to steal, commit fraud or worse.
  1. Rationalization- The day an employee starts they start to rationalize… I worked all weekend and no one else was here… especially my boss!
  2. Pressure- Given the economy this is an understatement; pressure is all over the place. With one in five homes being foreclosed on it’s a safe bet that one of your employees will have financial pressure.
  3. Opportunity- Probably the only area that we can actual control. Taking away or reducing the opportunity is key. Assessments are actually the lowest cost solution to identify the risky areas.
Correct use of assessments is key; you need to spend money wisely. What is the best use of your money and how do you maximum your return? You need understand where your greatest risk is and apply more resources in that spot. Seems easy, however most security professionals would rather secure the outside with a penetration test or scans. Spending $10k, did you actually identify the greatest risk? Probably not.

Getting budget gets tougher and tougher when you don’t know what the real risks are. Hence, next year (2009), spend money on a risk assessment. Yes risk assessments cost more, but they identify more risk and more importantly map the business requirements to those risks. Now you are telling the board or CEO of the risks, not just the results of a penetration test. This is key; we as security practitioners do not want to hold the risk!

Over the past several years I have noticed an increase in January/February breaches and hacking activity. While I can not statistically back up this observation, I can guarantee you that with a down economy and the holiday season, people will have more free time. Especially kids that are off from school, this is an ideal time to try some new hacks out, maybe the latest version of FastTrak.

Read more!

Monday, December 1, 2008

e.Discovery Planning

E-Discovery is a topic that is quickly becoming a more common conversation point. The average person really does not know what E-Discovery is and why it is important. The same can actually be said for a large amount of businesses out there today. E-Discovery is not a topic that most companies spend a lot of time talking about. That is until they find themselves part of a situation that makes them understand what E-Discovery is and they soon realize the importance of having a plan for preserving and gathering electronic data that may be used as evidence in a legal proceeding. What data would be important to preserve? The most common type of E-discovery evidence would be e-mail. A lot of transactions and conversations take place via e-mail. Companies such as internet service providers have more of a dilemma, as it is difficult for them to maintain large amounts of data, and they are often presented with requests to preserve information. Many ISP's only keep information for short periods of time due to storage space limits. Other types of data that could possibly be of importance could be database files, documents, picture files, audio, and video files. Many times there is more than is apparent on the surface of a file. The ability to hide incriminating evidence within an audio file or photo is not something that most people are aware of. Instant messaging data is also growing fast. So it becomes apparent that as technology evolves and companies are involved in legal proceedings more and more emphasis is going to be placed on E-Discovery. Many companies will experience this first hand, some will learn from the mistakes of others. Most large companies could potentially have several legal proceedings going on at any given time. This makes it necessary to implement some type of strategic plan for discovering electronic evidence.

A plan for discovering electronic data or evidence is known as Proactive E-Discovery. As mentioned earlier companies are beginning to realize the importance of E-Discovery. Electronic data is one of the most difficult forms of evidence to destroy completely. As data makes its way from system to system it creates another point of presence in which the data can be discovered or hidden. Data itself is growing rapidly, and this further complicates the matter. So why is it so important to have a plan in place for discovering electronic data? An answer that is becoming more and more a reality is "because you have to". A situation such as a legal proceeding could require the presentation or disclosure of relevant data in a very short time frame. According to the Federal Rules of Civil Procedure, data must be produced within 120 days. As part of the discovery phase of a legal proceeding it is required that known information such as data be presented to the opposing counsel. If there is not a plan in place for retrieving this data it is possible that a company could be levied with fines or sanctions for not complying or being unable to comply.

Having had the opportunity to begin studying this field as part of perusing a bachelor degree in computer and digital forensics it has become clear to me the focus the legal system is beginning to put on data that can be stored electronically, and the ability to quickly discover and present that data. As mentioned before the Federal Rules of Civil procedure have been modified, putting focus on the need for companies to know what they are storing and to have a procedure in place to quickly discover the necessary data and present it as evidence to legal counsel. Knowing what is stored is an issue companies will struggle with as any data that is stored can potentially be called into question and become part of an ongoing investigation. A major driving force behind the scramble to implement E-Discovery plans is the potential for sanctions. Courts have a good amount of leeway when imposing sanctions. These sanctions can amount to million dollar penalties that could potentially bankrupt an organization. In general the sanctions can be determined by the severity of the failure to comply and the actions taken by representatives to either help or hinder the discovery of data. The following link is an article that talks about the World Trade Center Insurer, and their legal counsel that were hit with E-Discovery sanctions: http://www.ediscoverylaw.com/2007/07/articles/case-summaries/wtc-insurer-and-its-counsel-hit-with-ediscovery-sanctions/

The E-Discovery business is the real deal, and as more and more companies are penalized for failing to comply, more and more companies will be looking to adopt policies and procedures that will allow them to know what it is they are archiving, and exactly how they will go about discovering and presenting this data. Their efforts will likely save them millions of dollars and the ugly embarrassment of their names being publicized as having violated E-Discovery regulations. E-Discovery compliance will also continue to grow and become more main-stream as society continues to move in the direction of electronic lifestyles. The more electronic data there is in the world, the more important E-Discovery will become.

Read more!

Friday, November 21, 2008

Intrepid Metasploit Ruby 1.8.7 Fix

Just a quick one here, if you use Ubuntu and have updated to the latest Intrepid release, you undoubtedly know that Metasploit hoses over short-name constants. The fix has been released already to Jaunty (the next Ubuntu release 9.04), however is still in intrepid-proposed for Intrepid. If you need Metasploit to work and can't wait for the release next week of the committed version to the normal repositories. If your seeing the following exploit failed message in Metasploit: "Exploit failed: uninitialized constant Msf::ModuleSet::NDR" or variances of that you have the issue. Additionally, when you load up metasploit you may see the following message:

***********************************************************************
***
*** This version of the Ruby interpreter has significant problems, we
*** strongly recommend that you switch to version 1.8.6 until these *
*** issues have been corrected. Alternatively, you can download,*
*** build, and install the latest Ruby snapshot from: *
*** - http://www.ruby-lang.org/ *
*** For more information, please see the following URL: *
*** - https://bugs.launchpad.net/bugs/282302 *
***
***********************************************************************

Heres a workaround:

Go to the software updates under Administration, click the "Updates" tab and select Proposed updates (intrepid-proposed)

If you don't want it to install everything in intrepid proposed you can do selective intrepid-proposed, to do this create a new file under /etc/apt/ and call it preferences and add the following:

Package: *
Pin: release a=intrepid-updates
Pin-Priority: 900

Package: *
Pin: release a=intrepid-proposed
Pin-Priority: 400

From there, simply go into synaptic package manager, reload the packages, and do a search for ruby1.8, mark for upgrade, install, and metasploit should be working without the short-name constants. The name of the new package is ruby1.8_1.8.7.72-1ubuntu1 (or 0.1).

References:
https://bugs.launchpad.net/ubuntu/+source/ruby1.8/+bug/282302

Read more!

Wednesday, November 12, 2008

And You Thought Graphics Cards Were Just For Gaming

I have always been a fan of the latest and greatest hardware and always been amazed on how fast new hardware is getting. Well now the Security field is going to have to start worrying about how this hardware is being leveraged to crack passwords. The Nvidia Corporation has harnessed the functionality of the C programming language and integrated it with their newest GPU’s to form the CUDA Technology.

In Fact, even the Lenovo T60 and T61’s are loaded with Nvidia Quadro graphics cards that can run CUDA software. There are even Python bindings for CUDA and many other languages may enter this arena. Applications for Fluid Dynamics, Digital Media, Electronic Design, Finance, Game Physics, Audio and Video, and many more have already been developed and more are on the way.

What I mentioned before is about Information Security. There is also software released to take advantage of “password recovery” and it is stunningly fast. Modern dual-core CPU’s such as the Intel Core 2 Duo and the AMD Athlon X2’s are able to test approximately 2 trillion passwords in about 3 days whereas CUDA based “Password Recovery” software can do 55 trillion in the same time frame. That is almost 25 times faster!

The reason these new cards are able to run software like this is because these new generation chips, named the G80 series, are able to compute fixed-point operations. The new Nvidia GTX 280 Graphics card boasts 1GB of 1100 MHz GDDR3 memory on a 512-bit path with 240 processing cores (actually called ALU’s) running at 600-650 MHz at a cost of $450/card.

Nvidia says the card is able to reach close to 1 Teraflop (Trillions of floating point operations per second) of compute capability. The first super computer to reach the 1 Teraflop barrier was in December of 1997 and was the size of a mid-sized house. It was 76 computer cabinets holding 9072 Pentium Pro Processors. (http://www.sandia.gov/media/online.htm) You can check back at http://www.top500.org/ for the fastest super computers in the world.

So with these Desktop Super-Computers doing tasks that multi-million dollar Teraflop computers are capable of, what if someone found a way to harness this technology to crack passwords in your organization? Or if they captured enough data and were able to un-encrypt classified data? How about AES-256 bit encrypted hard drives? Let’s look at it this way. Most likely your company’s password complexity is too weak. The only way to make it harder (still not impossible) is to force your users to use long pass-phrases, strengthen your domain policies and provide user awareness training.

The thing that makes this CUDA Technology so fast is that threads are able to communicate. These 240 cores work in tandem using Parallel Data Cache (A.K.A. shared memory http://www.beyond3d.com/content/articles/12/3) which saves clock cycles since it isn’t going all the way out to the card’s GDDR memory for additional data or temporary storage. Additionally, with the current Nvidia software and the proper hardware configuration, you can strap 1-4 of those cards to a quad core CPU and have an absolutely amazing system that could reach the 2 TeraFLOP range. And if that isn’t enough, Nvidia allows their consumers to over clock within the Nvidia Control Panel software.

One company has already gone the distance to “recover” passwords. Elcomsoft makes a software package that allows up to 10,000 distributed client workstations to “recover strong encryption keys” with each client having up to 4 GPU’s each. What government agency or research lab wouldn’t want something as powerful as that? The software is capable of “recovering” MS Office 97-07 passwords, Zip and RAR passwords, MS Money, Open Documents, all PGP passwords, Personal Information Exchange certificates - PKCS #12 (.PFX, .P12), Adobe Acrobat PDF, Domain Cached Credentials, Unix passwords, Intuit Quicken Passwords, MD5 Hashes, Oracle Passwords and WEP, WPA and WPA2 Passwords. (http://www.elcomsoft.com/edpr.html) Many of those operations are considered to be “GPU Accelerated” Options.

According to Elcomsoft’s own press release "Elcomsoft Distributed Password Recovery allows using laptop, desktop or server computers equipped with supported Nvidia video cards to break Wi-Fi encryption up to 100 times faster than by using CPU only." The software is said to support ATI Graphics cards early next year. I would find it only a matter of time until the underground community uses this technology to crack DRM as well as other cryptographic enabled media. (http://www.elcomsoft.com/pr.html)

Remember, this technology doesn’t have to be used in just password “recovery.” (http://www.nvidia.com/object/cuda_home.html#) There is such a large amount of science and technology that will benefit from this. Mathematics, Digital media, Programming and best of all, Games.

Read more!