Showing posts with label shmoocon 08. Show all posts
Showing posts with label shmoocon 08. Show all posts

Monday, February 18, 2008

Shmoocon 2008 (my $0.02)

So I missed day one of the con as I was stuck on planes and in airports for damn ages. After a few hours sleep I headed to DC to meet up with Chris and Joe and check out the presentations. Chris filled me in on H1kari's GSM presentation which sounded really cool. Gonna have to check that out.
I got to sit in on Jay Beale's "They're Hacking Our Clients!..." presentation. It was a repeat of the Toorcon talk and did not bring in much new material at all. Jay is a real sharp guy and a great presenter but he really was not talking about anything the folks listening did not already know. The user is the 'new' attack vector. He made good points and mentioned ideas for looking at user-agent strings from browsers, mail client identifiers and using those in conjunction with tools lie Squid to prevent access to mail or the web until the user patches. I believe the term is NAC. All Jay was proposing is a simple form of NAC. Still the method of implementation is not a bad idea but it's trivial to spoof user-agent strings to bypass that. Injecting iframes with mr-t into the user's brower once a day was also suggested. Not a bad way to detect third party plugins but what about when the user is on the road or at home?

I really want to see what happens when IT prevents a user from getting mail until he patches his computer. It seemed to me that the presentation forgot the fact the productivity trumps security every time. If what we do impacts a users ability to do perform their job we have failed at our job.

I'm not even going to comment on "Why are Databases so Hard to Secure" by Sheeri Cabral. She might be sharp and have DB knowledge but she really did not present well on what is an interesting topic. All I can remember is "ACLs are good".

Next up was "VoIP Penetration Testing: Lessons Learned" by John Kindervag and Jason Ostrom. This was an awesome talk. Great presenters and a really interesting topic. VLAN hopping with voiphopper! Damn cool and the did a live demo too! I can see sooo many networks getting owned with this! unplug phone, plug in laptop, own network!

At that point I was fried after no sleep and 24 hours of travel so I blew off the next talks and crashed in the hotel room for a few hours. Drinks and dinner with Chris and then hanging with Joe and talking up a storm. Lots of fun.

Today I got to see valsmiths and danny's talk on Malware Software Armoring Circumvention. All I can say is DAMN! Very, very cool stuff! Follow Chris's link below and check it out. Well worth it if you are into RCE at all.

I was really excited to see Josh Wright's and Brad Antoniewicz's presentation on attacking EAP implementations. I was not disappointed at all. A damn cool talk about a very cool topic. So many of my clients use PEAP, TTLS or another flavor of EAP and so I was really interested to see attacks against 802.1x implementations in action. They show how easy it is to capture credentials, either hashes in the case of ms-chapv1/2 or in plain text PAP credentials, simply using a rogue AP and a patched version of FreeRADIUS. A live demo too!

Chris and I ran into dre and Marcin. It was cool to put a face to the names. After that I had to run to a cab and head back to the train.

All in all it was a good con. It was definitely more about chilling with some friends and meeting new people.

dean

Sunday, February 17, 2008

Shmoocon 08 Day 3

alright Day3!

started the morning off right with coffee then off to Valsmith and Danny Quist talking about Malware Software Armoring Circumvention. very cool stuff and, for me, in that sit in a talk about things you dont know what much about. the offensive-computing.net guys built a tool (saffron) that can basically kick all these packer's asses and can allow you to unpack all different kinds of binaries that have been packed with different tools so you can disassemble them and do malware analysis.

Their slides and code are already up:
http://www.offensivecomputing.net/?q=node/637

keeping with the theme of stuff i that was above my skill level, next up was Vulncatcher: Fun with Vtrace and Programmatic Debugging by atlas. very cool talk on using some programmatic debugging to find vulnerabilities in different types of code and different types of data structures.
You can check out atlas' site for more info: http://atlas.r4780y.com/cgi-bin/atlas

He was also nice enough to do an interview with LSO after DEFCON:
http://www.learnsecurityonline.com/index.php?option=com_content&task=view&id=229&Itemid=46

Last up was dre and marcin from TS/SCI Security talking about Path X: Explosive Security Testing Tools using XPath. From their blog: "In this talk, we’ll discuss how using XPath can aid security testing during unit tests and in the integration phase of the software development lifecycle. By using XPath, it’s easier to share data between both open source and commercial quality testing, source code analysis tools and web application scanners."

http://www.tssci-security.com/archives/2008/02/17/path-x-explosive-security-testing/

After that I had to bug out, get home, and get ready for the week. thanks again to Don for the ticket!

Shmoocon 08 Day 2

Ok, i got up a little late and it took the spouse a min or two to get me to the metro, then the metro was doing work on one of the tracks, suffice to say i was late, i got there for noon talks, i tried to get a hotel room friday nite but no dice, did get on saturday nite so i didnt have to deal with the metro crap.

Day2

started with Jay Beale's They're Hacking Our Clients! Why are We Focusing Only on the Servers" talk. it didnt seem any different that the slides from toorcon. The jist is that we should incorporate client side testing into pen tests, because that's how people are getting in now and that we shouldnt allow customers to cop out and say "we have a user education program so no attacking the clients." He then went on to talk about some VA stuff like checking squid logs for clients on your network that are running vulnerable versions of apps like browsers or mail clients. You would then blackhole those guys off until patches were applied. I'll let Dean vent the most on that, because he raised the great point of if you blackhole some mucky muck's laptop and tell them to patch their box you're gonna get you ass fired up especially since its usually IT's job to patch stuff and most users dont have permissions to even update stuff most of the time.

next up was Why are Databases so Hard to Secure by Sheeri Cabral, i rolled in late and must have missed the good stuff because by the time i got in there i just saw a bunch of SQL in there and some talk about how developers should do something or the other...meh

after that was VoIP Penetration Testing: Lessons Learned by John Kindervag and Jason Ostrom for me the best talk of the day. they talked about some features they added to voiphopper. If you have seen the security focus article on VoIP hacking they just added to that. it was good though.

Got Citrix? Hack It! by Shanit Gupta talked about different ways to break out of Citrix apps to get command shells, IE boxes, or explorer boxes. pretty neat.

Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to "SPIKE Land"
by Enno Rey and Daniel Mende. I'm a big believer in listening to a few talks at a con that are above your skill level so you can rise up to that. i'm not an exploit-dev guy, i wish i was so i took the opportunity to listen to the layer 2 fuzzing talk. enno and daniel basically modifed SPIKE to fuzz layer 2 cisco protocol like DTP, VTP, MLPS and two others i dont remember. no exploitation, but they were able to get some "fun" reactions from different cisco products.

talked some way cool wireless stuff with one of the intelguardians. He showed me wi-spy and zigbee and talked about the cool things in the future that could be done against zigbee type products.

didnt make the shmoo party, had dinner with dean and talked about the talks and some other projects we got working then hung out, had beers, and talked SQLI with j0e and dean.

Saturday, February 16, 2008

Shmoocon 08 Day 1

hard to believe a year has gone by since the last shmoocon, but it has, here is a quick recap of Day1.

Day 1 started out really good.
Here is the schedule: http://www.shmoocon.org/schedule.html

probably the coolest talk that i caught was H1kari's on cracking GSM A 5/1 Traffic. him and his company essentially built a monster GSM session hash generator and cracker. its currently creating the tables (2 more months to go) and they built a high horsepower lookup computer too all using pico/FPGA cards. really really cool. a little expensive for the average "hacker" but a neat project. The impact is that with their cracker they will be able to crack the session key in about 30 seconds and at that point can intercept and listen to calls over the GSM network. not a whole ton of details on how all that "could" work but i'm sure they have it figured out.

I missed most of the other talks except for the phishing one, which was basically about a guy that did an unauthorized phishing training awareness webpage and campaign and how he did it, nothing spectacular.

There were tons of cool people running around, some of the guys from the chicago 2600 were there, Muts and the BackTrack/off-sec guys were there, met Chris Hoff (rational security), Ed, Jay and all the intelguardians, the hak5 guys recorded a show live, the guys from Iron::Guard security were there, of course Joe from LearnSecurityOnline, great networking going on which is always a big part of the con experience.

Hit up some of the vendors, the coolest vendor i talked to was the Blue Coat guys. Blue Coat is a proxy that basically does an authorized MITM of all the traffic entering and leaving your network, the big thing with that is that it can do SSL on the fly and allow you to stick a device in the middle and check out the traffic flying by, it also will check to make sure that the protocols are matching up so it will verify for you that if data is leaving your network on 21 or 80 that that traffic really is ftp traffic or http traffic instead of someone just using those allowed outbound ports to do evil things. pretty neat.

Anyway, talks I want to catch tomorrow will be Jay Beale's Client Side Penetration talk, the two SIP talks and probably the Citrix talk.

thanks again Don from EthicalHacker.net for letting me cover the event aka bought my ticket :-)