Showing posts with label Learn Security Online. Show all posts
Showing posts with label Learn Security Online. Show all posts

Monday, April 5, 2010

LearnSecurityOnline Advanced Penetration Testing Course

Everyone that knows me knows that I'm a huge LSO supporter. I wouldn't be where I am today without everything I learned from Joe and LearnSecurityOnline.

He let me get a preview of his new Advanced Penetration Testing (APT): Pentesting High Security Environments course.

The syllabus is available here:
http://www.learnsecurityonline.com/component/content/article/3-admin/222-apt

I got to look at a good chunk of the labs and its top notch training, plus you get it live from Joe who is by far one of the best instructors out there.

Of particular interest to me is the attacking from the web section:
Attacking From the Web

1. XSS to command-shell

2. SQL Injection to command-shell
MS-SQL
MySQL
Oracle

3. File Handling to command-shell

File Upload to command-shell
RFI to command-shell
LFI to command-shell

Course Dates
Course dates are 17th - 21st May 2010 Greenbelt Maryland
http://www.learnsecurityonline.com/component/content/article/3-admin/222-apt

2 Day version at Brucon 22-23 September 2010
http://2010.brucon.org/index.php/Training_1#description

Sunday, September 14, 2008

Toorcon X Workshop

As I mentioned before, Joe and I are doing a Crash Course In Pentesting 2 day workshop at ToorconX

http://sandiego.toorcon.org/content/section/4/8/

Here's a piece from the description:

"This course will cover some of the newer aspects of pen-testing covering; Open Source Intelligence Gathering with Maltego and other Open Source tools, Scanning, Enumeration, Exploitation (Both remote and client-side) and Post-Exploitation relying heavily on the features included in the Metasploit Framework. We'll discuss our activities from both the Whitebox and Blackbox approach keeping stealth in mind for our Blackbox activities.

Web Application penetration testing will be covered as well with focus on practical exploitation of cross-site scripting (XSS), cross-site request forgery (CSRF), local/remote file includes, and SQL Injection."

But I wanted to give a few more details.

Day 1 is network level pentesting and Day 2 is web application pentesting.

Network level is mostly my responsibility and I'll be focusing on black box information gathering, client side attacks, and post exploitation. Its hard to cover pentesting in a day, so I'll be talking heavily on client side attacks and how to implement those into your pentests and some of the tools you'll need to do it. A little bit on local/priv escalation attacks that you'll need to do once you have that userland shell and post exploitation. There is also a block on metasploit and the students will take home a copy of LSO's Metasploit Mini Course.

Web application is Joe's responsibility and it should be really good. We've had a custom web app built with vulnerabilities intentionally built in. So the students will be able run the tools he is going to discuss and then exploit the vulnerabilities they find. They also get to take the VM home with them.

If you have questions feel free to post up or email me with them.

Friday, August 15, 2008

Crash Course In Penetration Testing Workshop at Toorcon

Joe and I will be conducting our Crash Course In Penetration Testing Workshop at Toorcon in September.

http://sandiego.toorcon.org/content/section/4/8/

Description

Instructors: Joseph McCray & Chris Gates
Includes: 250GB 2.5" USB Harddrive preloaded with lab VMWare images

This course will cover some of the newer aspects of pen-testing covering; Open Source Intelligence Gathering with Maltego and other Open Source tools, Scanning, Enumeration, Exploitation (Both remote and client-side) and Post-Exploitation relying heavily on the features included in the Metasploit Framework. We'll discuss our activities from both the Whitebox and Blackbox approach keeping stealth in mind for our Blackbox activities.

Web Application penetration testing will be covered as well with focus on practical exploitation of cross-site scripting (XSS), cross-site request forgery (CSRF), local/remote file includes, and SQL Injection.

The course will come with a complementary USB Harddrive loaded with the lab Virtual Machine images for you to play with so you can continue to hone your skills and learn new techniques even after the course is finished. Attendees will walk away with a current knowledge of how to pen-test both a network and a web application, all of the basic tools needed, and a set of practice exercises that they can use to improve their skills.

Wednesday, April 16, 2008

LSO quoted on security.magnus.de

Hey LearnSecurityOnline.com got a shoutout on security.magnus.de

http://security.magnus.de/artikel/sicherheitstests-security-check-mit-metasploit-3-meterpreter.html

translated

translated quote:

" How can I get power over foreign computer? --That is a central question of all crackers. Exploits are the answer: They bring a computer cracker, to do what they want. So says the computer security side Learn Security Online www.learnsecurityonline.com together."

not sure where he got the quote, but hey i'll take it.

orginal screenshot:




translated screenshot:



neat!

Friday, April 11, 2008

CEH/CPTS Certification != competent pentester

Dean and I have talked about this more times than i can count and finally a discussion has taken place over on the pentest list about automated pentesting and a pentester's experience. The thread is here: "Penetration Testing Techniques" I wont get into all the issues wrong with whats going in the post. I'm going to harp on experience and certifications

from thread: http://seclists.org/pen-test/2008/Apr/0039.html

"Well, the results are definitely verified through nmap as well.OS is
win 2k3 running IIS 6.0 and only 80 being open.Yes indeed the client
has assigned us the job to perform the pen test and knows about it.
I do have the CPTS training dvd and am going through that, but it will
take time to digest that horde of information.Also downloading web
goat to get my hands wet with web app testing."

While the thread is initially about CORE IMPACT not finding any vulnerabilities with this particular server, the underlying issue is the lack of experience someone has and them being hired to do a pentest. Its a reoccurring thread on other sites as well; "Hey, I got my CEH, who wants to hire me to be a pentester" :-(

Bottom line, tools are just tools, they help humans get jobs done. They aren't and shouldn't be the only thing used on a pentest. The other point is experience is king, granted the original poster is getting experience, but giving CORE to a brand new tester is not going to help them get better. there is a reason A LOT of subjects are taught the hard way first then you get taught "the shortcut." Oh, and passing a multiple choice test is not a real demonstrable measure of ability.

Let me also add that if one of my employees posted some crap like that, i'd seriously be considering them finding another place to get their experience.

want to learn the right way? check out LearnSecurityOnline's Learning Model. LSO isnt the end all be all of security, but i think the Learning Model and the Core and Advanced Competencies is a solid foundation for any security professional.

Here are the Core & Advanced Competencies:

Four Core Competencies
• Operating Systems
• Networking
• Programming
• IT/IT Security Resources

Advanced Competencies
• Documentation, Policies, Procedures, Disaster Recovery
• Cryptography
• Forensics
• Penetration Testing
• Security Industry Certifications

Sunday, March 9, 2008

Hacker Defender article now available on LSO

While not a total membership drive, my HackerDefender rootkit article is available over on LearnSecurityOnline for registered members

Link to article on hakin9
http://www.hakin9.org/en/haking/issues/6_2007.html

if someone has serious heartburn about not wanting to sign up, leave a comment and maybe i'll get motivated to put it on the carnal main site or email it to you.

Saturday, December 29, 2007

Interview with Andres Riancho, creator of w3af

This interview was originally published over on LearnSecurityOnline.com.

==============================
Interview with Andres Riancho
==============================


In my opinion penetration testing frameworks and toolkits are fast becoming a necessity in today's audit process. Tools like Core Impact, Saint, BidiBlah and others are staking their claim in this service/client-side exploitation side of this market market and toolslike Web Inspect, Accunetix, Appscan, have staked their claim in the web application security side of the market.

I'm an open-source security tool user myself so my tools of choice for these two areas have been Metasploit (Service/Client-side), and Wapiti (Web App), but ladies and gentlemen there is a new kid on the block. The tool is called w3af (Web Application Attack and Audit Framework). The tool developer Andres Riancho has graciously agreed to an interview with LSO.

I have to say that Andres has been such a great help to me in not only developing a web application testing methodology/framework for my job, but also teaching me the basics of web app security auditing. He has so many skills from his years of experience so he was able give me little tips that really helped me connect the dots so to speak. So Andres, thanks for w3af - I really like the tool, and thanks for all of the help. I really appreciate it.

-j0e

# LSO #
How about some background about yourself, who you are? What you do? Who you work for? Location?

# AR #
First of all I'm a simple guy, that enjoys spending time with his friends, girlfriend, family and dog. On the other hand, I'm a security consultant that works at Cybsec (www.cybsec.com). I'm located in Argentina, land of "dulce de leche" and great meat.

# LSO #
How did you get into the security business (your specific field)?

# AR #
Like most of us, I'm a really curious person , so I started with security when I was 14. After some time, I got a job as an IPS administrator at a local ISP, when I got bored of it (pretty fast actually) I started working for Cybsec, mostly performing web application penetration tests. In other words, I started with security as a hobby, and now I make a living out of it.

# LSO #
How do you think technical aspects of web hacking have changed over time and how does one keep up with the current advances?

# AR #
Technical aspects of web hacking haven't changed much, the vulnerabilities are almost the same, but the "transport" method for the vulnerability is what keeps changing, before we had URL encoded strings, now it's XML and JSON, tomorrow it will be another type of encoding, but there always will be SQL injection, information leakage, etc.

# LSO #
Say I want to get into web security, it HUGE, where do i start?

# AR #
You should start by knowing how HTTP works, the basics of web application development and you should also read a lot about Cross Site Scripting, SQL injection, remote file inclusion and other common vulnerabilities. A good place to start is the OWASP site, and particularly the OWASP TOP 10.


# LSO #
Do you think Javascript is the new shellcode? If so why?

# AR #
I think that new things are still to be discovered about Javascript, but I don't really think it's going to be the "next generation shellcode". Browser security and cross site scripting are an important part of web security, but it's just that, a part of it. We should not focus all the attention on Javascript, there is still a lot of work to be done securing the web applications vulnerabilities that lead to the server being compromised.

# LSO #
Tell us what you think of the future of network enumeration via javascript. What are the attacks that we should look for in the coming years from javascript?

# AR #
Right now we have seen just the beginning of advanced javascript attacks, in the future someone will code a good framework for doing all kinds of attacks over cross site scripting. BeEF (http://bindshell.net/tools/beef/) is one of the cross site scripting exploitation frameworks I have been checking out, and I think it really has some potential.

# LSO #
How viable of a web application audit tool is Firefox? http://www.securityfocus.com/infocus/1879/1 shows Firefox being used for crawling websites, discovering hidden calls, and logic discovery - what are the top 5 tools that you use the most in web application/web services auditing and why?

# AR #
Browsers are the most powerful/useful tool to perform a web app audit, in the particular case of Firefox, this power is multiplied by100 if you use security aware extensions. The TOP5 tools I use while performing a web app audit are:

1- paros or burp ( two of the best local proxies, this tools are the most important in the whole process)
2- firefox ( as explained before )
3- firefox extensions like the web developer toolbar ( very usefull to test sites that have javascript )
4- w3af ( just because I coded it ;) )
5- nikto ( it's a classic, but it finds nice things once in a while )

# LSO #
Ajax is thought by some people to be what is going to lead us into "Web 2.0", and a great deal many security consultants see it as the ultimate attacker's playground. How do you see Ajax?

# AR #
There are only a few security consultants that do interesting work around web2.0, all the others out there are just reinventing the wheel every day; don't get me wrong, Ajax has introduced and will introduce a lot of new attack vectors, but the risk for users and companies IMHO will be low.

# LSO #
Do you plan to integrate ajax discovery/fingerprinting into w3af? Tools like fingerajax.rb/scanajax.rb are good for really simple stuff if you see a .aspx in the url, but there really isn't much of anything else on the market for command-line Linux tools for dealing with ajax.

# AR #
Well, actually I'm going to create a w3af plugin that wraps a browser or some other library/project that knows how to handle javascript. My idea is to wrap a browser, configure the browser to use a local proxy that will be run by w3af and then start interacting with the web application doing "clicks" on every HTML tag and recording the requests that are sent to the browser. Using this approach, w3af will be able to analyze most javascript-enabled sites!

I have been playing with pykhtml and discarded it because of some problems and the lack of portability to windows; and now I'm trying to achieve this task using zc.testbrowser.real, but I'm still working on this section of the project, so if anyone wants to help, just let me know.


# LSO #
Can you compare/rate the criticality of XSS, XSRF, SQLI?

# AR #
XSS: 3/10
XSRF: 2/10
SQLI: 9/10

As you may see, I'm not really into the "XSS is going to destroy the planet" thing, as I said before, it's something important but it's not so critical and we shouldn't loose our perspective and objectivity.


# LSO #
How important do you feel that programming is for this field, specifically how do you feel about Web Language programming? If yes, what language(s) do people need to know well?

# AR #
I think that you can't be a really good security expert if you don't know how to code in at least one low level programming language like C and one high level programming language, like Python. Source code is the base of all what happens in your computer, and if you don't know how to create it, you won't ever understand what happens when you click on a window button.

Web Language programming is something I don't personally enjoy, but it seems to be the future of programming. GWT is getting better and its user base is growing, so it seems that the future is going that way...

# LSO #
What tools need to be in every web application pen-tester's toolkit?

# AR #
w3af is in beta stage right now, but in a year or so it will be a must have tool for every web application pen-tester. Some other awesome tools I use are paros proxy, sqlmap and sqlninja.

# LSO #
What do you think are the 3 biggest changes in the security field in the last 5 years?

# AR #
The shift from attacking the servers, to attacking the clients has been an interesting change that started when most penetration testers found out that the servers weren't the weak link in the chain and that users would download and execute almost everything.

Big companies acquiring security companies was also a change that I was surprised with. Just to mention two of the most important business changes, IBM bought ISS and HP bought SPI Dynamics. I'm still expecting to see the long term repercussions in the world wide market!

One of the new things that have appeared in this last years are the vulnerability markets, like the zero day initiative and wabisabilabi. This business type is really interesting and gives freelance researchers good options to make money without the risks of selling their vulnerabilities and exploits to the Russian mafia.

# LSO #
Where do you see the security field going in the next 1-3 years?

# AR #
I think that many applications will be built over the HTTP protocol, and more than ever they will use Ajax and all the javascript tricks. So, more than ever a stable, complete and open source framework that can audit web applications will be needed.

# LSO #
What are the basics that you think every security person should know?

# AR #
The most important things to know in order to be a security professional are:
- Programming
- TCP/IP
- Web Application security
- Buffer overflows, format strings

# LSO #
What are the specifics that a person in your security field should know?

# AR #
Well, I mostly deal with web application penetration tests, so a person in my security field should really understand how HTTP works, it's internals, encodings, etc. It is also really important for a web application penetration tester to know how the information flows through a web application, type casting, data conversion, database queries, etc; so programming is one of the most important things. Finally but not least important, a good web application penetration tester should keep himself informed about new types of web vulnerabilities, this can only be achieved by reading mailing lists, reading the latest whitepapers and attending to one or two good security conferences a year.


# LSO #
Any suggestions on breaking into the security field? Or someone considering security for a career?

# AR #
There are two really important things to know when you are starting in the information security field:
- knowledge is power
- ask smart questions(http://catb.org/~esr/faqs/smart-questions.html),
no one will answer questions on the mailing lists if you don't ask them the right way

And of course, be ready to buy some glasses, work long hours and become really paranoid about sending non encrypted data over the wire.

# LSO #
Can you tell us about X, Y, Z (latest book, future book, current/future projects)?

# AR #
Right now, and at least for one more year, I'm going to be working on my main project, w3af. The framework has evolved a lot in the last year, and my personal objective is to create a stable and usable open source alternative to the commercial web application vulnerability scanners, that also includes among it's features the option to exploit the vulnerabilities that are found. Some new features I'm working at are Javascript and Flash support, this two features are going to be added to the almost impressive list of features, that include:

- Exploitation plugins
- Advanced post-exploitation payloads
- Integration with metasploit
- Detection of almost all web application vulnerabilities
- Information gathering using internet search engines
- Dynamic communication between plugins
- Easy to use console interface

w3af - Web Application Attack and Audit Framework

Tuesday, December 11, 2007

LearnSecurityOnline Interview with Andres Andreu

Originally published in the LearnSecurityOnline.com June 07 Newsletter

What we try to do with the Interviews with Security Professionals is ask people that are considered "Professionals" in the information/computer security field questions about their relevant field of research and advice on how for someone starting out to get to their level. Hopefully good information for people starting out.

============================
Interview with Andres Andreu
============================

[LSO]
How did you get into the security business, specifically penetration testing and penetration testing web applications?


[Andres]
I am at the core a software engineer so coding and architecting complex solutions is still an area of focus. I started getting into the security side of web software because I got sick of the weak app security that the network security world was providing. The Information Security industry needed much more than mere network security and those I was encountering that were in charge of security just couldn't see past the firewall/IDS/IPS paradigm. So I took it upon myself to do what I could so that the solutions I built wouldn't suffer from an overt lack of security.

Pen testing I kind of fell into by accident, it was something I informally did for years. AAMOF when I first heard the term I didnt know what it was but I had been performing those functions for some years. Earlier in my career I just took pleasure in breaking the coding work of others as well as my own. Pen testing is really a formalization of this otherwise devious activity. The web app realm was a natural progression because that kind of development work just started coming my way.


[LSO]
How about some background about yourself, who you are? What you do? Who you work for? Location?


[Andres]
I am a self employed native New Yorker but travel all over with work. I build custom software solutions as well as pen test anything I can legally get my hands on. Other then that I am a very dedicated husband,father of 4, artist (painting/illustration), and martial artist.


[LSO]
What do you think are the 3 biggest changes in the security field lately?


[Andres]
One change that really was inevitable, and is so evident these days, is a hard shift from the edge (network level security) to the core. The old guard of network based security is coming to terms with the fact that the security world is not boolean in nature. In the realm of core web app security there is also an interesting change in that Web 2.0 has brought about a resurgence of client side web computing. The web world of server side computing isn't going away anytime soon so the security field now has to contend with an interesting combination of the 2 tiers working simultaneously.

The field of information security is also getting a harsh dose of change with the distributed nature of things that are coming out these days. Mobile devices and their apps are a perfect example of this; and this concept of high mobility computing adds serious challenges. Moreover, users of these devices are becoming more and more savvy in terms of functionality. But as time has shown us all the more functionality at hand the more security challenges at hand. So expertise in this realm of security is an inevitable change.

Finally the information security field has been forced to get into the realm of compliance. It makes sense to an extent since security has an enforcement role. But time will tell if these moves are indeed wise because I travel the world and see the issue of policy creation and enforcement as a big area of challenge. I also see the frustration of otherwise technical security folk being forced into compliance related roles.


[LSO]
Where do you see the security field going in the next 1-3 years?

[Andres]
To hell! LOL, just joking. But all jokes aside the field has to change, adapt and overcome. It is still for all intents and purposes a reactive industry and that has to change. Many of the old school security people have not been able to keep up with the technological aspects of modern day info sec. They are network people at the core and just dont get the app space. So there will be a distinct shift in the industry where some people will enter the realm of security policy and wont deal with technology hands on. Those that do deal with hands on sec work will have a much richer skill set then what exists nowadays. They will truly be versed in the multiple layers of security, from the edge all the way down to code. This convergence is already starting from the inner world of developers, more and more of them are getting involved with security. And viewing info sec from a coders point of view is radically different then an edge perspective.


[LSO]
What are the basics that you think every security person should know?

[Andres]
The most basic set of knowledge is that of multiple tiers, or layers. No one layer is a silver bullet. I think your standard FW and IDS/IPS knowledge is important along with Proxy and Reverse Proxy technologies. The use of Proxy tiers is critical in todays web centric environments.

I find that protocol knowledge is lacking in the industry as is the handling of data. In reference to the latter, I mean an understanding of the effects that input data can have on a target and how to properly validate or dismiss such input. So those areas should be treated as basic along with the multi layer approach.


[LSO]
What are the specifics that a person in your security field should know?

[Andres]
To be effective in the field of web app security one has to understand how web apps work. So being familiar with the inner workings of web environments is important. Moreover, deeply understanding the OWASP Top 10 as areas of risk and remediation is a must.


[LSO]
Any suggestions on breaking into the security field?

[Andres]
Yeah, don't limit yourself and train yourself to be flexible. Adapting to constant environmental change is a way of life for modern day information technology professionals. The concept of wearing "many hats" is very real these days and maintaining pace with the chaos of modern day technology is key.

Don't be afraid of code, it is the at the heart of the problems most information security professionals have to solve. Familiarity with code will always be an advantage to anyone in the information security field. Also don't be afraid of RFC's, protocol knowledge is very important. You have to deeply understand what it is you will one day protect if you are to be truly effective.

Finally practice, practice and practice some more. An open mind coupled with practice on a myriad of platforms makes for a solid foundation. Virtual environments lend themselves well for all the practice and exposure necessary to be effective as a security professional these days. So build yourself a good virtual lab and hack/protect away.


[LSO]
Can you tell us about interesting things you are working on right now, or just recently finished (latest book, future book, current/future projects)?

[Andres]
I just wrote an article on XML Fuzzing for hackin9 magazine.

I am doing lots of Federated ID work these days. This represents a serious shift in security to that of heavily distributed data sets so it is quite challenging and exciting at the same time. So if for instance properly protecting one app/DB combo is challenging, now imagine protecting an object (of data) that doesn't actually fully exist in any one place. It exists partially in many places and some of those data sources you cant directly touch. This is very fun stuff that will be the norm in the future of the Internet.


[LSO]
Any cool new projects that you think we should let our members know about?

[Andres]
I have recently put some serious work into WSFuzzer, so check that out if you have any SOAP targets. I am also planning on kicking off a new project to deeply pen test REST services since I see them as an integral part of the future of web development.

Other then that I can't really expose my current work due to client confidentiality issues.

thx,

Andres Andreu, CISSP-ISSAP, GSEC
Author of "Professional Pen Testing for Web Applications" ISBN
0471789666

Sunday, December 2, 2007

LearnSecurityOnline: "Mad shit on that site"

this is good stuff...

Sunday, October 21, 2007

Crash Course In Penetration Testing Workshop at Toorcon

Just got back from doing a workshop with Joe at Toorcon. It was titled Crash Course in Penetration Testing

here is the blurb from the toorcon page:

"This course will start with the basics of pen-testing methodology covering Footprinting, Scanning, Enumeration, and Exploitation which will cover attacking Web Apps, Buffer Overflows, and will set you loose on a set of rootwars challenge servers. The course will come with a complementary USB Harddrive loaded with an attack VM and challenge VM images for you to play with so you can continue to hone your skills and learn new techniques even after the course is finished. Attendees will walk away with a working knowledge of how to pen-test a network, all of the basic tools needed, and a set of exercises that they can use to improve their skills."

All in all, I thought it went really well. we maxed out attendance (actually 2 over), the class was engaged and interested and responsive, so that's always good. What I thought was cool about the workshop is that we gave out 250GB hard disks with all the tools, Virtual Machines, and extra reading to the students. we had a minor issue with the firmware on the drives that they wouldn't mount under linux, so that's a good point for future classes where we do the same thing (not to get those types) but like I said we came away feeling like it went well.

Because Joe is a Pen-tester for his day job, he did most of the talking, but I chimed in when I had something to say and I, of course, did the metasploit section because I am a fanboy.

we really didnt have time to talk Buffer Overflows but we covered the other topics and tried to break them out based on if you are looking at a network internal or external and how to approach it from those perspectives.

I think we are going to run an online version on LSO for members, it will run for about a week each iteration.

Sunday, May 20, 2007

LearnSecurityOnline.com UnixChallenge 1

we finally got unix challenge 1 back online over at LSO.

details are here:

http://www.learnsecurityonline.com/index.php?option=com_content&task=view&id=87&Itemid=56