Saturday, June 28, 2008

Everything you ever wanted to know about WAF (and more)

Is available over on the TS/SCI security blog.

http://www.tssci-security.com/archives/2008/06/15/what-web-application-security-really-is/
http://www.tssci-security.com/archives/2008/06/23/web-application-firewalls-a-slight-change-of-heart/
http://www.tssci-security.com/archives/2008/06/23/week-of-war-on-wafs-day-1-top-ten-reasons-to-wait-on-wafs/
http://www.tssci-security.com/archives/2008/06/25/week-of-war-on-wafs-day-2-a-look-at-the-past/
http://www.tssci-security.com/archives/2008/06/26/week-of-war-on-wafs-day-3-language-specific/
http://www.tssci-security.com/archives/2008/06/26/week-of-war-on-wafs-day-4-closer-to-the-code/
http://www.tssci-security.com/archives/2008/06/27/week-of-war-on-wafs-day-5-final-thoughts/

**As always on the TS/SCI blog, the comments is where the "real hotness" is and you should make sure you read them with each post.

Also check out this thread on Jeremiah Grossman's blog:
http://jeremiahgrossman.blogspot.com/2008/06/can-wafs-protect-against-business-logic.html

While I don't always agree with Dre, I have to admit that before I would drop $110k + yearly maintenance, I might have to crunch the numbers to see how much it would cost me for a real thorough web application code rewrite/review/& pentest before you get stuck with yet another appliance in the rack that you have to pay money for every year and I have to pay someone to run.

I'm not a SDLC guy but are we really to the point that we CANT write a secure web application for any amount of money? I would hope that isnt the case.

Read the posts. Dre and Marcin put it better than I ever will.

Quotes of the Week

Probably not going to be a weekly occurrence but wanted to share some quotes I heard this week and last week.

1. (For NoVA Drivers) "If you don't like being passed...F**king drive faster or get out of the left lane"

2. While in Hawaii for an assessment (yeah life is rough)... "We Hawaiian people are such nice, friendly, sharing people...that's probably why we don't have any land left" doh!

Free Advice For The Single People

If your significant other is talking about how they spent 4+ hours doing something in excel... DO NOT DO NOT DO NOT
1. Say "nothing should take 4 hours with excel!"
&
2. Start talking about how excel has these cool things called functions and how you can use functions to aggregate data in multiple worksheets...

more penalty points if they have been drinking and now you really cant talk your way out of it :-(

Wednesday, June 25, 2008

Hacker Defender Article in Hakin9 Magazine

Its been a year, might as well release to everyone else who hasn't bothered to just email me and ask for it :-)

from June 07 issue: http://www.hakin9.org/prt/view/back-issues/issue/690.html

Keep in mind

1. I wrote this over a year ago
&
2. I probably wont be rewriting it, so tailor comments accordingly

Hacker Defender: Rootkit for the Masses -- Link

Tuesday, June 24, 2008

Network Security Is Not Dead

There have been a few comments out on the blogosphere about NETSEC being dead. NETSEC is not dead, its not going to be dead for a LONG time if ever. If something is dead, I can unplug it, remove it from the rack, and never think about it again.

To me NETSEC is (short list) router ACLs, firewall rules, VLANs, IPSEC, & domain policy. I know thats not everything, but it should be enough to illustrate my point. We could also argue domain policy but I think that its a valuable and necessary piece of security in any MS network.

Now I agree that NETSEC as a primary defense and entry point is dead (there probably won't be another DCOM), I agree that client side attacks completely bypass firewall rules (initially--the exploitation piece anyway, the shell is another matter), I agree that the endpoint is now the new border, and I agree that Application Hacking (webapp, user, browser, etc) is where security IS/is heading.

What I don't agree with is that I don't need my firewall rules and router ACLs anymore. Some examples...

-without NETSEC do we still have DMZs?
-with no DMZs and no way to control who can talk to who on your network with either FW rules or router ACLs, what is going to stop the attacker once they exploit that web app and either get a shell or credentials to log in with?
-How do I stop the attacker once he has that shell with client side privileges? Do I just let them have free reign?
-How do I stop that outbound connection that alot of times can be caught with the right type of proxies (bluecoat and similar "appliances"). Is my layer7 FW going to catch that?

All of these people that say that network hacking is dead obviously don't have to do anything else in their pentests other than exploiting web applications. Unless you got really friggin lucky and that web application housed the data you were looking for, you are back to the old school network game of moving around the network, setting up shop on hosts in the LAN, doing privilege escalation and with no rules or devices in place what is going to stop the attacker from exfiltrating that data out without being seen? Where are your logs if you do catch them with no NETSEC devices?

thoughts? I'm wrong alot, so if I'm wrong do let me know.

Friday, June 20, 2008

More of why google ads rule

More on the updated FISA 2008 bill

From wired blog:

http://blog.wired.com/27bstroke6/2008/06/house-grants-te.html


"The bill allows the National Security Agency to order phone companies, ISPs and online service providers to turn over all communications that have one foreigner as a party to the conversation. If any Americans are party to the conversation, the government is supposed to mask their names, but these procedures to minimize privacy-invasion are easily overridden. The longstanding Foreign Intelligence Surveillance Act required specific court orders to wiretap phone and internet lines inside the United States, but did not regulate spying conducted on non-U.S. soil.

Under the so-called FISA Amendments Act of 2008, the government would need a court order to wiretap an American overseas, regardless of where the tap was. Under the current regime, targeted taps aimed at Americans overseas requires the sign-off of the attorney general.

The nation's telecoms will soon be freed from some 40 lawsuits accusing them of eavesdropping illegally, if the bill is passed into law as expected. The legality of the retroactive amnesty isn't clear, and groups like the American Civil Liberties Union and Electronic Frontier Foundation will likely challenge the provision on constitutional grounds."

I read about 20 pages of 100+ of the bill on the surface it seemed ok, but two issues bother me personally. First, it lets the ISPs off the hook for doing what their legal departments should have known and told them was illegal. In the military you are taught to never follow an illegal order, it should be the same outside of the military as well. Second, we mere virtual inches from a blanket wiretap on everyone deemed "a threat" and I've already heard from people that work at ISPs it doesn't take much to get a tap on your cable/DSL modem anyway. Sad times. Time to get good at PGP, TrueCrypt and secure protocols if you aren't there already.

For The Love Of God -- CISA != Pentester Either

I wasnt going to post about my CISA exam, but Dre's post on the CISSP got me motivated to do it even though its not really related.

Why CISA you ask? We'll they made me.

I'm not going to bitch and moan about the test (much). I took a whopping one question on the OSI model, alot of IT governance, and several on a dumbed down version of how PKI works. Dumbed down so much and with terms that made no sense that I had to sit there for a minute trying to figure out what they heck they were asking and I KNOW how PKI works. It was also poorly written, which I found surprising given the cert being around as long as it has. For the life of me I'll never understand why asking me a simple question in some obscure way makes me prove I know the material better. I understand that with math that might be the case but not with IT. Overall I felt it was very low tech, yet the CISA certification is now required for anyone doing CNA.

Work did send us to a 1 week bootcamp on the CISA, where my favorite quote of the class was "CISA, A technical certification for accountants"...yea! After a week of talking about it I would sum it up to say that the Auditor goes back and checks to see if the CISSP did his/her job properly and if their processes are meeting whatever requirements are required for that particular business.

Anyway, nothing in the course, books, or test helped me get or be better at the real duties of my job, I guess we could argue management and professional development but when you are talking a level 3 certification I want experience that helps me do my real job better not something that makes people that stopped being good at technical stuff long ago feel better about themselves.

Now let me cut the 8570 folks some slack, CNA is huge and pentesting is a small part of it. I can see that if you do IA inspections, blue teaming, or that kind of go through your checklists run a gazillion scanners vulnerability assessment stuff, the CISA is at least in your domain. Would having the CISA certification help them do their job better or prove that someone could do that job? I don't think so but its in their domain.

On a positive note, I was asked to think about a certification for pentesters for DoD for yet another update in the distant future. I personally don't have any experience with any (meaning I haven't taken the training or the test) that I would recommend. I think CEH & LPT is out, just ask an LPT and they'll tell you why. I will be looking in to the SANS GPEN or possibly the CEPT Link1 & Link2.

If anyone has any suggestions for certs to look into please post up. The "you don't need a certification" debate we can keep on another thread, we wont get be getting away from the need for certification in this case.

Thursday, June 19, 2008

And a little further in the toilet we go...

From wired blog:

http://blog.wired.com/27bstroke6/2008/06/dems-agree-to-e.html

"Breaking months of acrimonious deadlock, House and Senate leaders from both parties have agreed to a bill that gives the nation's spy agencies the power to turn a wide swath of domestic communication companies into intelligence-gathering operations, and that puts an end to court challenges to telecoms such as AT&T that aided the government's secret, five-year warrantless wiretapping program."

There isnt much to say if you read the article, its shameful the FUD still flows and becomes law in the name of terrorism 7 years after 9/11.

Wednesday, June 18, 2008

DIY Career in Ethical Hacking

My good friend Don Donzal of EthicalHacker.net spoke at the SANS Pentest Summit recently.

his slides and audio are available on the site

Main Link: http://www.ethicalhacker.net/content/view/201/1/

Slides: http://www.ethicalhacker.net/images/stories/columns/editor/diycareer/diy%20career%20in%20ethical%20hacking.pdf

Audio:
http://www.ethicalhacker.net/images/stories/columns/editor/diycareer/donzal_diycareerinethicalhacking_sanspentestsummit2008.mp3

He said some good things in the talk, here are two slides that bring alot of good information.


First slide I posted was on being honest with yourself about who you are, where you want to go, strengths and weaknesses, and the family concerns. Being gone alot isnt the best thing for a marriage.



Second slide was free or cheap ways to get there once you know where you want to go. I really like this slide because I would consider it the roadmap I have taken and I think its going pretty well.

The talk is about 50 minutes and worth the listen.

I had to laugh about his "flash resume" from back in the day, if someone sent me a flash resume I'd be too worried I'd be sending a reverse shell back to the guy by reading it.