Showing posts with label rant. Show all posts
Showing posts with label rant. Show all posts

Friday, April 15, 2011

Data Driven Pentests...Don't You mean Vulnerability Assessments?

So first a disclaimer, i didnt listen to the referenced podcast, this is based solely of this blog post:


So I’m listening to the “Larry, Larry, Larry” episode of the Risk Hose podcast, and Alex is talking about data-driven pen tests. I want to posit that pen tests are already empirical. Pen testers know what techniques work for them, and start with those techniques.

What we could use are data-driven pen test reports. “We tried X, which works in 78% of attempts, and it failed.”

We could also use more shared data about what tests tend to work.

Thoughts?

Dre's response to the post was surprising to me, he listed a bunch of tools that seem to do correlating of pentest results into a portal so you can trend over time. Cool idea, i'll give the people that. But to me when we start jumping into repeatable metrics driven stuff we are in Vulnerability Assessment land, not pentesting land.

Here is the comment I left:

I like the idea and i think it could be useful.

However, they need to drop the pentest part. you are solidly into the vulnerability assessment part of things when you are talking about “ok, i tried 1,2,3,4,5 and 1 & 3 worked” ok on to the next set of tests… thats vulnerability assessment (with exploitation if you want to get technical) and not pentesting.

pentesting is about that human looking at the problem and figuring out how to break it, not some scanner, thats going to be very hard to standardize and put hard numbers on and i dont think its going to be possible without tying up your tester’s time with bullshit.

I'm all for "repeatable" pentests. You should have a methodology for each type of test, but when you are paying for human's time you should be paying for them to go after the site like a human would and not how a scanner would or not in a way where i'm worried about religiously following some checklist because if i don't the metrics get all fucked up. Your pentest should come after you have thrown the kitchen sink at it scanner wise.

as an added bonus this post was right below the new school post in my Google reader:


This post and really any methodology document you will ever read or write will have gaps, because no document on this subject can ever really be 100% all inclusive of every vulnerability and the myriad of variations that exist for many of these.

I think it drives the point home as well.

-CG

Tuesday, March 24, 2009

Moving Cybersecurity from DHS to White House

From here:
http://infosecurity.us/?p=7343

“Forthcoming legislation would wrest cybersecurity responsibilities from the U.S. Department of Homeland Security and transfer them to the White House, a proposed move that likely will draw objections from industry groups and some conservatives.
CNET News has obtained a summary of a proposal from Senators Jay Rockefeller (D-W.V.) and Olympia Snowe (R-Maine) that would create an Office of the National Cybersecurity Advisor, part of the Executive Office of the President. That office would receive the power to disconnect, if it believes they’re at risk of a cyberattack, “critical” computer networks from the Internet. “I regard this as a profoundly and deeply troubling problem to which we are not paying much attention,” Rockefeller said a hearing this week, referring to cybersecurity…”

and a DHS response here:
http://news.cnet.com/8301-13578_3-10048063-38.html

I'm a simple guy and I'm going to over simplify my response. So here goes.

Politics and money aside, because there is alot of both for this issue DHS would be dumb not to fight to keep control of mission for the sheer amount of $ being thrown at it, without strong leadership and authority it wont matter who is in charge of cybersecurity for the US.

When I was just getting interested in security and still in college I went to Black Hat New Orleans 2002, and listened to Erik Birkholz's "How To Fix a Broken Window" talk.

From the talk description:

C:\>net send * “Don’t expect secure networks if you haven’t empowered your internal security team.”

Security vs. usability may finally become a balanced equation. All the usability in the world isn’t worth a damn if your internal network is a wasteland of default configurations and blank passwords. Security teams are now a required internal resource. Contrary to popular belief there are NOT 24 working hours in a day. Security can not be treated as a side order. The excuses need to stop - now.


The amount of the above that still rings true 7 years later is just ridiculous but the important thing I took from that talk 7 years ago that is still true today is don't give people the responsibility of security and no authority to do anything about it.

So what does that have to do with DHS & the White House and who's calling the shots? Well, the fact that DHS and U.S. Cert have all the responsibility but no authority. The U.S. Cert can send .gov organizations alerts, advice, guidance, incidents, threats, whatever all day long, but at the end of the day they really cant make those .gov entities do shit. That is the sad reality, those other agencies in most situations don't have to listen to the cert or can merely say "we took care of it" and there is no secondary investigation to be done or allowed. Additionally, there seems to be no punishment for receiving failing FISMA grades or having numerous amounts of security incidents, unless you call getting extra funding "to fix the problem" a punishment.

The simple version is this:
If things don't change...if the authority to withhold funds, internet access, or the ability to fire people who show gross incompetence or the inability to handle the security responsibility of their organization, if we dont stop putting people in CSO/CIO positions who have no security background, if getting a failing FISMA grade doesn't actually mean anything, and if we dont change the broke ass way that some .gov agencies operate it wont matter who is responsible for cybersecurity or how much money you throw at the problem its still gonna be jacked up. In fact, who's to blame bad guys for breaking into networks that are just so damn easy to break into?

Thoughts On Pentesting Must Evolve Or Die

So the latest article by Brian Chess didnt stir up quite the controversy that that his pentesting dead in 2009 interview/article but this one is worth a read:

http://securitysa.com/news.aspx?pklNewsId=31945

Its a short article and not near as controversial as the dead in 2009 one but three quotes...

"People are now spending more money on getting code right in the first place than they are on proving it is wrong. However, this does not signal the end of the road for penetration testing, nor should it, but it does change things. Rather than being a standalone product, it is going to be more like a product feature. Penetration testing is going to cease being an end unto itself and re-emerge as part of a more comprehensive security solution."

"2009 will be the year this strategy comes together, and when we look back, it will be the year when most of the world began thinking about penetration testing as part of a larger offering."

All that is good news (I think), secure coding is where things need to go but I personally dont feel any amount of secure code will ever completely replace pentesting as long as its possible to mis-configure it or set it up insecurely. So Microsoft Windows at some point may be free of stack overflows (or any memory corruption exploits) but that wont stop some system admin setting up their domain in some insecure fashion. That will still need to be pentested to discover and help remediate. Which leads me to the last quote...

"More than ever before, people understand the software security challenge, and penetration testing deserves credit for helping spread the word. But knowing a security problem exists is not the same as knowing how to fix it. In other words, penetration testing is good for finding the problem but does not help in finding the solution – and that is why it must take a long hard look at itself and then make a change. Just like the venerable spell-checker, it is going to die and come back in a less distinct but more pervasive form and I, for one, cannot wait."

I dont agree with this. Penetration testing/testers should never leave you without a fix to security issues. I know alot of pentesters and I dont know any that dont give the customer recommendations for remediations and a customer shouldn't accept a pentest that doesnt have recommended fixes. I suspect that what Chess meant here were "problems" like SQL injection vulns or code bugs that a source code scanning tool could help find and recommend the secure way to code it where a pentester may say "recode it", "have your developers find and fix the code" or "you may have improper parameter checking in this public function", etc.

I do agree that pentesting should evolve, but I think it should begin to look more at assessing an organization from many angles and taking the path of least resistance than pentesting the network side one quarter, the web app side the next, physical security the next, etc. When we begin to identify what makes us money, then look at how we are protecting it across the enterprise, then testing all those defenses at the same time, then we are evolving in the right direction. The evolution should be Full Scope pentesting and not the way most shops do it now.

Anyone else have thoughts on the article?

175+ deleted blog spam posts later...

I've enabled comment moderation and captcha. Normally i wouldnt have cared but since I sat thru Val Smith's and Collin's talk twice on what they are doing with that stuff I couldnt let it linger.

sorry for the new hoop to jump through everyone.

if you come across any i missed please let me know.

Friday, February 20, 2009

Response to How to Choose a Pen Tester

So a response to "How to Choose a Pen Tester"

Let me start with that I agree with the core of Steve's argument. Yes if I pay someone to come in and do "anything" on my network I want to be able to trust them not steal info, plant trojans, or air my dirty laundry out on the net when they are done.

I don't disagree with that.

BUT

A few comments not sure they are quite counterpoints

1. I personally don't see a big prevalence of pentest shops doing pentests and posting customer data on the net in any form. If there are examples show me. He mentions in 6 months he heard ONE story about someone that did that and didn't provide a link...ummm ok. Is it believable that it does happen/has happened/could happen?...yes. That every pentest shop is doing it (except his which is really the point of the post)... doubtful. Its not a smart business decision to 1) as a company do that or 2) allow your testers to do that on their personal blogs.

2. As David Hull mentioned, what is the problem with talking about a pentest as long as the customer cant be derived from the post/presentation/email or there isnt enough actionable information to conduct the attack? If companyX was vulnerable to SQLI 6 months ago and I went in and found it using some creative method and i decided to share that experience on my blog or at a conference what is the problem with that? The company isn't vulnerable any more and if I had to figure out some new method of doing "whatever" unless it was explicitly in the contract not to share "new pentest methods" aren't those mine to share as a I see fit? It helps the community when others talk about things they have seen on a pentest even if its just to make the other guy feel a tad bit better than someone else lives in jacked up network hell. Even though I always get alot more out of peoples posts about their pentests.

3. I realize that Steve proposes you do a scorecard but really....trustworthiness over competence? Why on earth would you ever even consider doing business with someone you didn't trust? I don't see how anyone with half a brain would put themselves in the position of...hmmm do I choose the trustworthy CEH or the untrustworthy l33t ass hacker....ummm NEITHER! You pick a company that hires intelligent, competent, trustworthy, and the rest of the stuff on his scorecard people. Is there really that many companies that are that piss poor that even make it past a scoping call? and more importantly do the decision makers for choosing the testers not have the ability to pick the good from the bad?


I should insert a shameless plug here but I don't think its necessary :-)

Saturday, January 17, 2009

More on too much automation

I'm not the most articulate person, especially in writing, and while I thought by the people that bothered to comment on the blog, I got my point across other people make me think I didn't.

So, I'll try again, if this doesn't work I'll resign myself to just not being as l33t and skilled as other people in the community.

I'm not against ALL automation, by its very nature everything involved with "hacking" or penetration testing is automated but I'll try to restate. From the orginal post:

Automation is a good thing but when it comes to pentesting I really think there can be too much automation. Too much automation leads to "fire and forget" activities and lack of TLC.

Believe me, I'm all for bash running my nmap scan and rolling IPs for me all nite rather than stay there and do the stuff myself. I'm all for automating a tool that needs to run a set of commands on a subnet or group of hosts given the appropriate scenario. Hell I'm even all for running scripts that will log into every box and "do something" (go tebo!) also given the appropriate scenario.

But what I'm not for (but I do concede there are plenty of times when the following is perfectly acceptable and maybe regarded as "good" pentest):

Rolling in and run my full port nmap scan, nessus scan, core impact rapid pent test, connect to a couple of agents, take screenshots, high five with my team mates on how l33t I am, then head out and write the report.

I'm of the opinion that for the above scenario, a couple weeks of training and a couple of licenses later any in-house shop can do that for themselves.

I will propose that there is an alternate type of pentest where my goal is not to root as many boxes and I can but its too see if I can gain access to "what makes the company money". I am unannounced, trying to not get caught is part of the test, and where the customer actually has a great patching program, an IDS, possibly and IPS, an outbound proxy, somebody actively monitoring the previous technologies, and asking them to turn all that shit off is not going to happen....

how would our above scenario fair for that pentest?

how fast would your pentest be over if you did say....

"For example, I enumerate open shares on the entire subnet, then pull down all .doc documents, then search them for interesting information from the recon phase (i.e. the name of the CFO)."

I'd give it about 2 minutes before any SOC that doesn't totally suck blocks your ass and you have to go begging for them to unblock your IP...that's never any fun.

I wont address everything from the pauldotcom show notes, because frankly I think they completely missed the point of the post (because I am not against all automation), but I will address this.

"[PaulDotCom] - While I agree, automation can have a negative effect on risk identification,
its a vital part of every penetration test. Much of the post talked about how automated tools "Don't have the love" and "you need TLC". That's all well and good, but how do you show risk when you've got a meterpreter shell on 30 hosts? What are those hosts? Do you spend 3 weeks of your time and the customer's money to demonstrate risk? No, you automate the mundane tasks and pieces and parts that can be automated. "

I guess my response would be why do I need 30 shells to demonstrate a point? how would I have gotten those shells without being really sure about what/where the host was before I launched anything that would have gotten me a shell? but if ./autohack ran on a subnet and gave me 30 shells then I guess I might find myself wondering what are all those hosts and how did I get in. As for risk identification, if I got 30 shells the risk identification is an enterprise patching problem in this scenario.

"This does not make you any less skilled or a script kiddie, in fact, it makes you more of a master."

umm how? did I have to run a nessus with credentials to find those vulnerable hosts after checking 100's of KB's and throwing tons of traffic at the hosts or did core impact throw 20 exploits at each box before I got lucky and popped a few? Or did I limit my exposure and try to enumerate what services were running and what service pack the host was and try the latest exploit at one host to see what would happen?

I'll spare you the rest, like I said I think the point of the post was completely missed.

Wednesday, January 14, 2009

When automation is too much automation or where's the TLC??!!

Like the"hiring geeks" post by ax0n said, we automate. Automation is a good thing but when it comes to pentesting I really think there can be too much automation. Too much automation leads to "fire and forget" activities and lack of TLC.

For example there are a couple scripts out there that try to automate your whole scan, enumerate, and exploit process and all the pentest frameworks have some sort of autohack feature and they all suck (as much as it pains me to say that --especially because I am such a msf fanboy).

There is a certain amount of diligence I think that should be applied come actual "exploit" time. Scripts that automate or allow a "tester"(?) to script too much of the pentest while handy can cause real damage on a network, not to mention MISS things, possibly IMPORTANT things.

I've heard that some people will spend a ton of time writing a tool that will run everything from nmap and a bunch of different exes, some that do automated exploitation like adding rogue user accounts if it finds null passwords or something, or whatever random exe's that can find on the net. run that script and go for lunch.

The problems arises that:

1. That much output really saves you no time if you go back and actually go through and validate the results.

2. Seems like no one knows how to enumerate and certainly no one teaches it. Automating all the steps between scan and exploit don't help the lack of enumeration either.

2. There is no "test" you just ran a bunch of tools, the script did all the "work."

3. There is no personal experience or tester analysis if you just run a script. There is no thinking outside the box or expertise involved if you hit the autohack button or ./autohack.rb

4. What about stealth? what about tactics? what about proper footprinting? what about emulating anything besides a script kiddie attacker?

5. Where is the fun and challenge in having the script do all the work for you?

6. Every pentest is (at least should be) a battle of minds against the tester and the people admining and securing the network. If you've got any kind of decent admin the easy low hanging fruit should be patched up but that doesn't mean there still aren't vulnerabilities to be found and exploited by an experienced tester. Its all about finding the one thing that guy missed and then digging in from there.

7. There's no TLC with autohack, for the amount of cash you paid for a "real" pentest, there should be some love and work from your tester, that nessus report just aint cutting it.

Moral of the story, show some TLC, get good (better) at your craft and don't rely on the latest autohack script to do things for you.

Tuesday, June 24, 2008

Network Security Is Not Dead

There have been a few comments out on the blogosphere about NETSEC being dead. NETSEC is not dead, its not going to be dead for a LONG time if ever. If something is dead, I can unplug it, remove it from the rack, and never think about it again.

To me NETSEC is (short list) router ACLs, firewall rules, VLANs, IPSEC, & domain policy. I know thats not everything, but it should be enough to illustrate my point. We could also argue domain policy but I think that its a valuable and necessary piece of security in any MS network.

Now I agree that NETSEC as a primary defense and entry point is dead (there probably won't be another DCOM), I agree that client side attacks completely bypass firewall rules (initially--the exploitation piece anyway, the shell is another matter), I agree that the endpoint is now the new border, and I agree that Application Hacking (webapp, user, browser, etc) is where security IS/is heading.

What I don't agree with is that I don't need my firewall rules and router ACLs anymore. Some examples...

-without NETSEC do we still have DMZs?
-with no DMZs and no way to control who can talk to who on your network with either FW rules or router ACLs, what is going to stop the attacker once they exploit that web app and either get a shell or credentials to log in with?
-How do I stop the attacker once he has that shell with client side privileges? Do I just let them have free reign?
-How do I stop that outbound connection that alot of times can be caught with the right type of proxies (bluecoat and similar "appliances"). Is my layer7 FW going to catch that?

All of these people that say that network hacking is dead obviously don't have to do anything else in their pentests other than exploiting web applications. Unless you got really friggin lucky and that web application housed the data you were looking for, you are back to the old school network game of moving around the network, setting up shop on hosts in the LAN, doing privilege escalation and with no rules or devices in place what is going to stop the attacker from exfiltrating that data out without being seen? Where are your logs if you do catch them with no NETSEC devices?

thoughts? I'm wrong alot, so if I'm wrong do let me know.

Thursday, June 19, 2008

And a little further in the toilet we go...

From wired blog:

http://blog.wired.com/27bstroke6/2008/06/dems-agree-to-e.html

"Breaking months of acrimonious deadlock, House and Senate leaders from both parties have agreed to a bill that gives the nation's spy agencies the power to turn a wide swath of domestic communication companies into intelligence-gathering operations, and that puts an end to court challenges to telecoms such as AT&T that aided the government's secret, five-year warrantless wiretapping program."

There isnt much to say if you read the article, its shameful the FUD still flows and becomes law in the name of terrorism 7 years after 9/11.

Sunday, June 8, 2008

Hey United Airlines...Try Actually READING The Question

Its Sunday and I'm bitching.

We fly United Airlines alot for work and I'm getting close to getting my premier status and finally becoming a person according to United. In fact, on my next trip I'll reach enough miles on the outbound flight. Me hating to wait in line and being too paranoid about coughing up all my biometric info for the fly clear stuff I asked if United could "pre-upgrade" me based on the fact I will archive the required number of miles on the flight.

Here is the question I posed:

From: ME
To: United Airlines Web Question Form
Hi,I have an upcoming flight to Hawaii and will be gathering enough miles to become premier on the outbound leg of that flight. I wanted to see if it was possible to be upgraded to premier before the flight so i could use the premier check-in line at the airport.

thanks in advance.

and the response.

Thank you for your e-mail. Elite status is earned by our most frequent flyers. To qualify, you need to earn a given number of Elite Qualifying Miles (EQM) or Elite Qualifying Segments (EQS) in one calendar year. EQM and EQS can be earned by flying on United, Ted, United Express or any Star Alliance member airline and by participating in various promotions. Please visit www.united.com/staralliance or www.staralliance.com for an up-to-date list of Star Alliance members.

Once you qualify for elite status, your account is automatically upgraded. Members need to requalify each year. Elite status is not determined by the current balance of redeemable miles in an account. The three levels in our Elite program are:

Premier = 25,000 EQM or 30 EQS

Premier Executive = 50,000 EQM or 60 EQS

1K = 100,000 EQM or 100 EQS

**Yes all the information available on the website

To date, in 2008, you earned 22,053 Elite Qualifying Miles and 8.5 Elite Qualifying Segments. If you meet the elite membership criteria we can upgrade your status.

** More information I see when I log in

I wish you success in attaining your desired status.

** Then upgrade me!

Please contact us again if you have any questions concerning your Mileage Plus account.

Gisselle Dawson

Yup got it, pretty much what I stated in the question but no real answer. Now I figured the answer would be no, but you could at least read the friggin question and say no. At least I'll be a person on the return flight.

**Update, I actually sent a follow up email saying read my question and basically got the same response without a real answer (again). I wont bother putting it in here.

Friday, May 23, 2008

School District in PA "hacked" by a 15 year old

From Dark Reading:
15-Year-Old Steals Data on 55,000 People in School District Hack

A Pennsylvania school district suffered its second consecutive breach at the hands of one of its students – the latest attack involved personal information on students, staff, and county residents.
http://www.darkreading.com/document.asp?doc_id=154709

Before you click that link, read this one from the school district.
http://dasd.us/security/?cat=3

start from the bottom and read up, its an interesting chain of events. Especially conflicting reports of "that a student had overridden the security of a classroom computer" and "The breach occurred in the high school during the student’s study hall, a time when students are authorized to use the school’s computer for studying and research."

This is also pretty good:

"Prior to 2006, Social Security numbers had been used by the district as key indicators in our resident data base. The file the student accessed was a copy of a report that had been issued in 2005. (He did not access our secured database) Social Security numbers are no longer used by the district and our new database does not include this information. "

In response, the District has:
  • Tightened up folder security by confirming all folder permissions
  • Separated network servers to ensure that students have access only to student servers
  • Reconfirmed the integrity of the district’s firewall protection to prevent unauthorized outside users
  • Removed all access to folders that had been breached.
  • Continued to remind teachers and administrators to keep individual district passwords private.
  • Begun a Board authorized complete overhaul of the active directory file structures dealing with login, password security and folder access permissions.
I'm far removed from this, but it looks suspiciously like the "hack" was someone browsing the network shares that had crappy permissions on them. How that equates to "unauthorized access" in beyond me but i'm sure the kid will take the fall and not the school's network admins for doing a shitty job.

A better question is why a database or names, addresses and social security numbers is sitting unencrypted on a network share.

"Your personal information including your name, address and social security number in an unencrypted and un-redacted form were among those accessed."

and for a next to final kick in the nuts:

"We are providing you this notice so that you can take measures to contact the credit reporting agencies and monitor any unusual activity in your account....Under Federal law, you have the right to receive a free copy of your credit report once every 12 months from each of the three nationwide consumer reporting companies. To request your free annual report under that law, contact www.annualcreditreport.com..."

Yep we lost your data, we were irresponsible, our admins failed to safeguard your PII and you basically get the same thing you got if we had been doing the right thing.

and lastly:

"In December 2007, another DASD student circumvented the security of the district’s computer network by using unauthorized software. That student was arrested and has been charged. The district responded to this incident by researching and putting together a plan to overhaul the active directory file structures dealing with login, password security and folder access permissions. The second security breach will require complete additional security revamping."

Oh yeah? and six months later this happens? looks like you did a A+ job on that one. Someone should be sooooo fired.

Thursday, May 15, 2008

commuting and podcasting

We just bought a house so now my commute has gone from 20 minute to usually close to an hour (yea 66). so i've started listening to podcasts to pass the time and hopefully do something worthwhile with 2 hours a day.

I caught two podcasts the other day, cyberspeak and pauldotcom. I had heard of pauldotcom, they came mobbing into shmoocon a couple of years ago in their black t-shirts, but cyberspeak was a suggested podcast when I was subscribing to pauldotcom.

cyberspeak 10 may 2008 was on the Mac Lockpic and basically about flyclear.com. not much to say. i'll be looking into flyclear to help my butt get through the airport.

pauldotcom episode 106 was on some command line nessus for some checks, metasploit and some news. click the link for show notes, which are really handy.

comments on the show:
They used an outdated metasploit command "use -m Sam" which i guess still works, do a "use priv" instead. I had seen the nessus command line stuff. Joe pushed that out in a LearnSecurityOnline newsletter awhile back. They also dumped the hashes into john, thats so old school and not necessary. use pass the hash if you can dump the hashes. and big thanks to Stewart in the token passing #2 post about using "gsecdump -u" to see who's logged in.
Lastly, i'm failing to see the big deal about sslnetcat when its in perl. great for authorized uses on *nix, not so great for pushing a shell back from a compromised windows host unless they have perl installed, which you cant count on. A recompiled cryptcat or even better sbd will probably give you more bank for your so called buck.

Sunday, April 20, 2008

WTF Business Software Alliance

Have things really come down to this???

Snitching on your company or friends for a quick buck? The irony of course is that banner was on a security forum that pretty much caters to the last group of people that would pay for software.

Friday, April 11, 2008

CEH/CPTS Certification != competent pentester

Dean and I have talked about this more times than i can count and finally a discussion has taken place over on the pentest list about automated pentesting and a pentester's experience. The thread is here: "Penetration Testing Techniques" I wont get into all the issues wrong with whats going in the post. I'm going to harp on experience and certifications

from thread: http://seclists.org/pen-test/2008/Apr/0039.html

"Well, the results are definitely verified through nmap as well.OS is
win 2k3 running IIS 6.0 and only 80 being open.Yes indeed the client
has assigned us the job to perform the pen test and knows about it.
I do have the CPTS training dvd and am going through that, but it will
take time to digest that horde of information.Also downloading web
goat to get my hands wet with web app testing."

While the thread is initially about CORE IMPACT not finding any vulnerabilities with this particular server, the underlying issue is the lack of experience someone has and them being hired to do a pentest. Its a reoccurring thread on other sites as well; "Hey, I got my CEH, who wants to hire me to be a pentester" :-(

Bottom line, tools are just tools, they help humans get jobs done. They aren't and shouldn't be the only thing used on a pentest. The other point is experience is king, granted the original poster is getting experience, but giving CORE to a brand new tester is not going to help them get better. there is a reason A LOT of subjects are taught the hard way first then you get taught "the shortcut." Oh, and passing a multiple choice test is not a real demonstrable measure of ability.

Let me also add that if one of my employees posted some crap like that, i'd seriously be considering them finding another place to get their experience.

want to learn the right way? check out LearnSecurityOnline's Learning Model. LSO isnt the end all be all of security, but i think the Learning Model and the Core and Advanced Competencies is a solid foundation for any security professional.

Here are the Core & Advanced Competencies:

Four Core Competencies
• Operating Systems
• Networking
• Programming
• IT/IT Security Resources

Advanced Competencies
• Documentation, Policies, Procedures, Disaster Recovery
• Cryptography
• Forensics
• Penetration Testing
• Security Industry Certifications

Tuesday, March 11, 2008

Another Blog's TSA Post and My TSA Rant

Pretty funny post here about a guy missing his flight because of his MacBook Air

http://www.michaelnygard.com/blog/2008/03/steve_jobs_made_me_miss_my_fli.html


and a TSA rant from my last trip:

While TSA didnt hold me up I would have preferred they did. Just got back from an overseas flight. We cram all our gear for assessments in those big black pelican cases. I spent about 45 minutes getting everything packed in there nice and tight and where nothing would rattle around and break, since I had signed for it and we have the "you break it, you bought it policy." So I get to the airport early, some times no ones cares about the big black case sometimes they do. I also got a nice fat padlock for it, again, sometime they care sometimes they don't.

That morning they did, but I got lucky. I must have had the most polite nice TSA guy i have ever met. He was like what's in the case, I'm like computer equipment, he's like ok, iI have to look inside whats the combo? He gets the case open, starts going through it. He's behind a screen so i can only see his head and not what he is doing. I go can you please make sure you put things back in there properly i have to pay if stuff gets broken and he's like sure sure no problem. I'm waiting outside the roped area to make sure it everything gets locked up properly and back on its way. Finally i hear him closing it up and lock and throw the thing on the conveyor belt, smiles and says everything is good to go and to have a nice flight.

I get to the hotel on the other end like 20 hours later and open the case. EVERYTHING is all over the place not even remotely where it was placed. harddrives, switches, cables all over the case and he even put the laptops back in with the screens facing out so a nice hard kick to the bottom of the case should have taken care of me getting any work done on the trip (will save that piece of knowledge for later). Anyway, just annoying that the guy was so nice all the while doing such a crappy job. Thankfully nothing was broken. I understand the need to protect us, and i'm glad people are there trying to do that, but if they cant have enough respect for our stuff to put it back in there right or allow US to put it back in there then don't open the crap up.

Thursday, December 20, 2007

BackTrack3 is NOT an operating system either!!!

So BT3 beta is out, i wanted to see what all the fuss was about...

here are some screenshots, looks and acts pretty much the same. I like their graphics, graphic guy needs a Xmas bonus.





that being said, with the release of any new version of "hacking distro" comes the "how do I get metasploit autopwn to work" garbage from the person that didn't read the man page, didn't read the blog post(s) on autopwn, didnt search the list archives for how autopwn works, and now we get to field questions on why fasttrack.py doesn't work right, did you read (any of) the code? no... sigh. did you go thru dependency hell getting all those badass tools working so maybe you know a couple of things? no...double sigh. did you watch the hack videos on LSO using metasploit?...no...triple sigh.

i said most of it in a previous post here.

Going through dependency hell at least gives you an opportunity to learn and figure stuff out, building your own distro with the tools YOU use is much more helpful from a learning what the F you are doing standpoint.

Don't get me wrong, i'm not belittling the people that made backtrack. its a badass tool and i don't have near the linux kung fu to make it myself, so kudos to them for making a badass tool, its just irritating that it allows people that shouldn't take shortcuts in learning to take them.

what's the solution? build your own attack distro, you'll thank yourself in the morning.

Wednesday, November 14, 2007

Politics: Yahoo & China

So I've been kinda keeping up with the whole Yahoo giving up a journalist name to the Chinese government (at least what is on CNN) and that guy getting 10 years in prision.

if you are unfamiliar with it:
http://www.cnn.com/2007/US/10/16/yahoo.congress/index.html
http://www.cnn.com/2007/POLITICS/11/06/congress.yahoo.ap/index.html
http://www.cnn.com/2007/WORLD/asiapcf/11/13/yahoo.china/index.html

here is the short version:
"Shi Tao got in trouble three years ago, when the Chinese government told journalists not to report on the Tiananmen Square anniversary. He forwarded the notice to human rights groups. The regime then pressured Yahoo to give up the account holder who did that. Yahoo complied."

I caught a bit of the senate testimony online and it was the CEO getting his ass chewed by the senators basically saying he was a complete traitor to the US and what not.

Now, I am pro-American and anti communist but here are some things I thought about after reading the above articles and seeing it on TV:

-did the CEO personally give up the information freely or did one of Yahoo's employees in China do it after a direct warrant type request from the Chinese government. Do all of those types of requests go thru any type legal or ethics review? or any review by the CEO? -I doubt it.

-what was the extent of the data given. did they ask for an IP address? username? sign up info? etc. how much of that is given out normally and how sensitive is that information usually? did Yahoo know what the government wanted to do with it?

-if a foreign company operating inside the US was asked by the FBI to give up information about a US Citizen suspected of terrorism and was given a warrant to provide that information, they would be expected to give up that information...yes? i think they would be expected to do just that. isnt that the same thing?

-expectation of privacy is low i think on those free email services. anytime another entity stores and sends your email for you, there shouldnt be much of expectation of REAL privacy. if you dont own/control the server and cant encrypt your emails or data then privacy is at a minimum. In a place like China, being stealthy and careful must be at a premium especially if you are doing anti-govt type activities.

-if you want some real scary stuff check out Mark Rasch's current article on security focus on email privacy:

http://www.securityfocus.com/columnists/456

things might not be so different after all.

thoughts?

-CG

Sunday, August 26, 2007

BackTrack2 is NOT an operating system!!!

ok over on EH.net there are a couple of running threads on installing backtrack to Hard Disk/Drive so people can use BackTrack2 as their Operation System.

here is one of them link; i dont feel like looking up the rest (really not the point) but this has been going on for some time now (really since BT1).

OK i am going to vent for just a sec but i do have a point...

BACKTRACK IS NOT AN OPERATING SYSTEM! it is a TOOL!!

yes obviously you can run it as an operating system (hence the whole point of the rant) but why do your NEED to do that?

frankly the best education comes from building your own attack platform on the linux distro you installed, configured, and hardened yourself. You install, configure and mess with the tools YOU need to do your pentesting (or scanning your local ISP subnet) and dont have a bunch of extra crap you dont need. You get to work through library issues and crap breaking and getting so pissed at your box that you want to dropkick it out the window but guess what, you LEARN doing all that.

one of the biggest things i see over at LSO and during the rootwars is people having weak linux skills and not being able to compile and use their own tools, so naturally we ask what distro the run and mos of the time i get backtrack for an answer :-(

Dont get me wrong, i like backtrack2 as a TOOL, i boot the ISO in VMware i do what i need to do then i go back to my linux distro to read email and everything else. I have a couple of personal reasons for that one of them being denialability with the non-persistent option :-) but mostly for the reasons above; if i am going to go thru the trouble of installing a distro I might as well get something out of the install (linux knowledge-wise) instead of letting someone else do all the work for me.

just my thoughts on it. spend that effort installing that great set of tools that backtrack comes with on your own, you'll learn more and really get an idea if you actually NEED all of those tools and you get satisfaction of having control over your linux install.

-CG

Monday, July 23, 2007

Thoughts on Security Conferences versus Practical Knowledge

Over on SecurityFocus.com Don Parker posted an article on Security conferences versus practical knowledge.

Overall I see his point that the talks given at the average security conference actually gives little to the average participant to bring home to put into effect into his/her network. He asserts that the training given at conference (usually 2+ days before the talks) is top notch but the speakers fall short. He also says that a security conference focusing on "practical knowledge" would be far better.

From the article:
"Today's computer security conferences no longer offer relevant or practical knowledge to the attendee. Be honest now, when was the last computer security conference that you went to where you came away from with several ideas to implement immediately onto your networks? I would wager none. "
...
"What my not making the cut sank home for me though was that there are precious little practical talks going on today at computer security conferences."

Some thoughts on those quotes:
We have done this to ourselves by demanding that we hear talks on the latest research and 0-day, brand new exploit attack vector, uber l33t hack tool, etc when we go to these security conferences. At some point we moved away from talks on practical widespread attack vectors on our network to teeny tiny attack vectors because all the "practical talks" have been given already and why do people want to pay tons of money to hear someone talk about research or information that everyone already knows?

When was the last time i got something useful from a security conference? The last con i went to was shmoocon 07 (My posts on EH.net about it 1, 2, & 3)and while i wasnt able to go back to work, sit down at the domain admin MMC or router console and make changes that secured my network i still got alot out of the con. You can read my day by day if you want, but i'll assert that being able go back and make a change or implement something new on your network after a security con attendance is a poor metric to judge a conference selection of speakers or the value of the conference. Talks i did get alot out of were:

Avi Rubin's keynote talk on vulnerability disclosure. Do i do this every day, no. But great information to know when i have a enough fu to worry about doing disclosures.

Matt Fisher, Cygnus, and PresMike's talk on Web Application Incident Preparation. Again, i dont run a web server but if i did i would have gone back and looked at what we had in place to deal with incidents that could occur thru my web app.

I missed Richard Bejtlich's talk but i'll wager it was worth listening to :-)

Chris Paget's talk on WPAD, if we were using it, would have been a talk i would have had to sit down at the keyboard and do some fixing on.

There was more, i wont list them all, hell even the guys talking about guns was worthwhile but not something i could have used at work.

Link to the speakers

so what's my point???!!! first another quote...

"It is not everybody who can attend today's cutting edge security conferences and actually walk away having learned something. What is it that you are going to get out of it, and just how will it benefit our network? If the answers aren't there, you're not going. Practical knowledge is where it is at."

My point is that i think people (anyone if they have some brain cells and interest) do get things out of conferences even if they cant directly put it into action at work. New ways of thinking about attacking problems, hearing about things that will most likely become issues later, in my opinion is invaluable much for the same reason that subscribing to security mailing lists has value despite the noise, already knowing about that exploit you see on CNN or some of the other online computer site a few days after the code was dropped has value. Frankly being around some of the researchers that have that much "fu" is also valuable because it can show you that what's out in public knowledge about a system is probably not even remotely all that is known or doable with the system not to mention just the inspiration of being around some of these people with that much security brainpower. You wanna get motivated, go listen to Dan Kaminsky talk about bending DNS packets to his will or HD Moore 0wning some un-ownable app, or if packet fu is your thing go listen to Richard Bejtlich or if you are into reversing go listen to Havlar Flake. if that doesnt inspire you to do some work in the home lab or crack a book to be a better security guy/gal, well i dont know what to tell you except to maybe look at why you are in the field.

More random thoughts on the above quote:
At least it can maybe now justify the cost of training you can take at the conference since you usually get access to the talks for free if you took the training. On the other hand, how often has it been that the "obscure non-practical theory/idea" talk actually turned into a huge attack vector? I'm sure the people that first listened to a talk on the supposed vulnerabilities in WEP didn’t really come home with the "practical knowledge" to do anything about it on their networks, but we see later how widespread and dangerous of an attack vector it was. Unfortunately people don’t give a crap about a new vector (it isn’t practical yet) unless the guy is dropping a kiddie friendly tool anyway, then maybe they'll go home and fix or upgrade the network to defend against the attack.

If we do go the "practical knowledge" con route:
Another thing to think about is how do I justify to my boss sending me to a conference where they are going to talk about "practical knowledge" that I can 1) probably get in town from a local training center or 2) from a book for significantly less cost?

Don’t get me wrong, I’m all for a conference where I get something practical out of every talk but I would think its hard to organize a con like that because what might be new information for me might be old news to you. Of course that's probably why there are different tracks and more than one talk going on a time. Valid points though, something for those con organizers to think about at speaker selection time.

Wrap up:
so all that yaking, what's the point? the point, if you just scrolled down to the bottom, is that being able go back and make a change or implement something new on your network after a security con attendance is a poor metric to judge a conference selection of speakers or the value of the conference or of conference attendance. The value of a security conference is more than the talks and beer drinking (both important parts though) that can be done at the conference. The inspiration to do/learn more, exposure to new concepts/methods, and networking with like-minded individuals can pay dividends later as well.