Security is dead, long life security

This is a repost of my company blog: http://blog.xebia.com/2015/10/12/security-is-dead-long-live-security/

Last week the 7th edition of BruCON was held. For those unfamiliar with it, BruCON is a security conference where everybody with an interest in security can share their views and findings. As always it was a great mixture of technology, philosophy, personal opinions and hands-on workshops.
This year however I noticed a certain pattern in some of the talks. Chris Nickerson gave a presentation about "how to make a pentester's life hell" based on experience, Shyma Rose shared her views on risk management, Mark Hillick showed us how the security was improved at Riot Games and David Kennedy provided his opinion on the state of the information security industry nowadays. All four of them basically told pieces of the same tale from a different perspective and I will try to provide my viewpoint on the matter in this blog.


The security bubble
Both Shyma and Dave said the term 'Risk' is inflated and is nowadays used as a buzz word that no longer has a connection with actual threats. I couldn't agree more on this. Nowadays it is almost normal, when someone identifies a new vulnerability, to launch a complete marketing campaign including fancy names and logos, dedicated websites and huge social media presence. Risk is no longer used as an indicator of 'badness', but instead used as a catalyst for pushing 'money making silver bullets' to customers. And, since most clients don't know any better, they get away with it. And, as Chris showed, even customers who do know better, still enable them to push their crappy services by providing them ideal conditions to prove their effectiveness.

Hackers != unstoppable evil geniuses
Hackers are looked upon as the extremely smart guys with elite skills, where reality is that most breaches happen due to stupid stuff and decade old problems. The infosec industry's solution is products and services that no longer qualify for the fast changing world we now live in. Most services rely on stopping or identifying known attacks. In a world that is changing almost every heartbeat and especially in a world of mobile devices and cloud solutions the 'castle and archers' approach no longer works. Facts show that in many hacks exploits weren't even necessary due to the possibilities of modern platforms. If an attacker has the possibility to access some maintenance or configuration part of your system it's game over. If an attacker can access some scripting environment, it's game over. If an attacker can lure one of your employers into going to a website or installing something, it's game over.

Ivory Towers
Another problem is the huge gap between security operations inside a company and the business and development departments. Many companies have internal security guidelines that are hardly aligned with the rest of the organization and therefor bypassed or ignored. The natural response to this is that the security departments push the guidelines ever harder, only causing the gap to increase even more. Based on experience Mark stated that security departments should get out of their ivory tower and start to understand what is really important. It's more effective to achieve 80% security with 100% alignment, than try to reach 100% security with 0% alignment.

Duct-tape
Both the infosec industry and clients nowadays have enough money and attention to change things, so we should get rid of the technology driven approach and start focusing on talent and smartness. When you look at the root causes of many hacks it's not the technology that is to blame, but instead ego, culture, miscommunication and the working environment. As long as security is considered as something you can bolt on or use external expertise for it will fail. We, both the suppliers and clients, should consider security as a standard quality attribute where everybody is responsible for.

Telling instead of training
In most companies the ratio between security and non-security minded people is way off. Security teams should therefor start acting as supporters and trainers. By becoming more visible in the organization and start aligning with it, the security awareness will rise within everyone. Every single person in the company should get a basic understanding of what security is about. And it isn't that hard to achieve. Developers should know secure coding, testers should learn to use security tooling, operations should know how hacking tools work and can be identified and taught the basics of forensic research. People also need to be trained to how to handle in case of an issue: build a good incident response program with flowcharts that everybody can use and apply. It's not rocket science, you can achieve a lot with good old common sense.

Secrecy
Another key item is visibility. Often incidents, breaches and other security related issues are 'kept under the radar' and only 'the chosen few' will know the details. By being open and transparent about these to the whole organization, people will start to understand the importance and challenge each other to prevent these in the future. By creating internal security challenges and promoting good ideas a community will form on itself. Use leaderboards and reward with goodies to stimulate people to improve themselves and get accustomed with the matter. Make sure successes are acknowledged. To quote Mark (who also quoted someone else) "If Tetris has taught me anything, it’s that errors pile up and accomplishments disappear."

Hackers don't only knock on the front door
Lastly start to implement defense by default and assess every situation as if a breach had occurred. Assume bad stuff will happen at some point and see how you can minimize the damage from each point. Do this on all levels; disable local admin accounts, use application protection like EMET and Applocker, implement strict password policies, apply network segmentation between byod, office automation and backends, using coding frameworks, patch all the time, test everything, monitor everything, and start analyzing your external and internal network traffic. The ultimate goal is to make it pentesters (and therefor hackers) as difficult as possible. Pentesters should cry and require weeks, months or even years to get somewhere.

There is no I in team!
We, as an infosec industry, are facing a future where change is the constant factor and we have find a way to deal with that. In order to be successful, we have to understand and acknowledge that we can no longer do it on our own. Unless we start to behave as a member of the team, we will fail horribly and become sitting ducks.
Inspiration

Just some testing related links (updated)

Training online

Hacker Contests / War Games

Deliberately Vulnerable Websites

Deliberately Insecure Applications

Deliberately Insecure Distributions

Vulnerable 'real' applications

Testing Tools

Security Tool Suites

Frameworks / Testing resources

Security Models

First Burp Extension


Yesterday I started converting the few Hiccup scripts I created (as in: tinkering with a mashup of existing scripts until it worked) in the past to the new Burp Extender format.
After some initial startup problems (with which http://www.burpextensions.com really helped out) I am proud to present my first simple extension :)

It doesn't do much more than highlighting requests of content-type text/xml and text/xhtml in the proxy tab. The reason I want that is that these content types are possibly vulnerable to html encoded XSS attacks and are often missed by scanners (thanks to mario heiderich for pointing that out to me in the past!). It is therefor useful to test them manually.

See http://www.thespanner.co.uk/2011/09/12/protecting-against-xss/ for some background info and PoC.

Link to the Burp Extension



Privacy is minder waard dan een cookie

Vandaag is het dan zover; de cookiewet is actief geworden. Vanaf vandaag moeten alle websites toestemming vragen voor het plaatsen van cookies die niet puur bedoelt zijn voor het functioneren van de site. Daarbij wordt geen onderscheid gemaakt tussen first-party en third-party cookies en ook maakt het niet uit of er nu wel of geen privacy gevoelige informatie in staat; alleen cookies bedoelt voor bijvoorbeeld het bijhouden van een sessie of winkelwagentjes mogen 'stil' worden geplaatst, alle andere cookies moet je vooraf toestemming voor vragen aan de bezoeker. Verder is de naamgeving 'cookiewet' misleidend, omdat het om alle mogelijkheden van 'local storage' gaat en niet alleen om de standaard cookies. Flash cookies en alle mogelijkheden van HTML storage vallen daar dus ook onder!

De wet heeft ook gelijk flink wat munitie gekregen; overtredingen kunnen door de OPTA beboet worden met sancties die op kunnen lopen tot € 450.000 ! Verder kan de wet ook met terugwerkende kracht worden toegepast; foute cookies die wel ooit geplaatst zijn (na vandaag), maar niet meer gebruikt worden kunnen ook beboet worden. Daarnaast is de OPTA niet verplicht eerst een waarschuwing te geven en mag het bij ernstige overtredingen direct overgaan tot beboeten.

Dit heeft nogal wat consequenties. Om te beginnen zijn alle site die gebruik maken van tracking of analyse mogelijkheden (zoals bijvoorbeeld Google Analytics) per direct in overtreding. Ook is het opslaan van persoonlijke voorkeuren in cookies niet meer toegestaan en zal iedere website dus een profiel voor iedere klant moeten gaan bijhouden.

En daar komen we gelijk op een heikel punt; door de cookiewet worden websites gedwongen om meer gegevens van de klant te verzamelen aan de server kant om personalisatie te kunnen aanbieden. Alle voorkeuren van een klant zullen voortaan in een klantprofiel moeten worden opgeslagen. Om dit klantprofiel uniek genoeg te maken moeten of alle klanten voortaan inloggen of zal de website zoveel mogelijk informatie moeten verzamelen over de klant. Gelukkig is hier geen persoonlijk identificeerbare informatie voor nodig; zelf met de informatie die je browser naar een website stuurt is een klant al behoorlijk uniek te identificeren, zelfs zonder dit direct te koppelen aan het IP adres. (ter info: de uniekheid van je browser kun je hier testen (je IP wordt hier niet bij gebruikt): https://panopticlick.eff.org/ )

Theoretisch levert dit natuurlijk een extra risico op in de vorm van datalekken die onder de Wet Bescherming Persoonsgegevens vallen, maar gelukkig moet zo'n lek eerst plaatsvinden en moet er aangetoond worden dat dit een overtreding is van de WBP. En zelfs als je verzuimd een lek te melden en dit wordt toch ontdekt dan is de maximale boete slechts € 200.000.

Vanaf vandaag is privacy dus minder waard dan een cookie!

Mostly Free Online Testing and Security Magazines

Just a list I collected over time. Many are free or provide free issues.

Software Test & QA
http://www.softwaretestpro.com/Publication/p/STPM

(IN)Secure Magazine
http://www.net-security.org/insecuremag.php

Hack in the Box Magazine
http://magazine.hackinthebox.org/

IT Expert Magazine
http://www.itexpertmag.com/

Hakin9 Magazine
http://hakin9.org/

Datacenter Magazine
http://datacentermag.com/category/magazine/

Pentest Magazine
http://pentestmag.com/

Security Acts
http://www.securityacts.com/

Security Kaizen Magazine
http://www.bluekaizen.org/security-kaizen-magazine/

Testing Experience
http://www.testingexperience.com/

N2100 modules mirror

For some years now I am a happy owner of a Thecus N2100 NAS.

Although it is getting a bit slow compared to the newer generations of NAS devices, one of the things I like about it is the way you can customize it to your own needs by using modules. Over the last years a fairly active community developed many of these modules and discussed them on the Thecus user groups Thecus Usergroup Forum.

Unfortunately the community is declining and moving to newer devices and many of the modules can no longer be downloaded from the original locations. I therefor downloaded as many modules as possible while I could and I am providing a mirror for it on Google Docs. You can find my mirror to the N2100 modules here.

Ideal Skill Set For Web Application Security Testers

Today I saw an interesting post by Keatron Evans on the "Ideal Skill Set For the Penetration Testing". You can find his blog here.

While I think it is a good summary about the skill-set for pentesters, I think it is not the correct skill-set for web application security testers. So I have made a slightly modified version of it for (what I think to be) the basic skill-set of a web application security tester.

I tried to maintain the original list as much as possible and provide the webappsec analogies of the items. I also copy/pasted the good bits and the things I thought to be applicable in both lists.

1. Mastery of web and application servers. Each and every web and application server has its own configuration options, behaviour, quirks and file locations. Learn them and learn how to abuse or break them.

2 Good knowledge of the HTTP protocol. Understand and learn the header fields, how cookies work and the different request methods. Understand how HTTPS works. Get the basics of AJAX, JSON, serialized streams, etc.

3. If you don’t understand the things in item 2, then you can’t possibly understand how session management, CSRF or a (layer 7) MiTM attack actually works.

4. Learn the ins and outs of HTML, javascript, CSS. Learn the different encoding mechanisms, their uses and limitations. Also learn how each browser handles exceptions and strange input (see 6)

5. Learn the ins and outs of the mechanisms behind IDS and IPS. Learn how to pass data past them using basic encoding and other simple techniques. There’s no better way to understand these concepts than to apply them. Once you’re mastered this, you can move to a WAF and start the process over again. Start experimenting with different encodings and obfuscation techniques and other attacks.

6. Know your browsers. Despite all the standards browsers tend to handle HTML, javascript and encodings in a (slightly) different way. Next to that, each browser has its own configuration options, behaviour, quirks and file locations.

7. Eventually learn a programming language. Focus on Java, Python and Ruby. Figure out something you want to automate, or think of something simple you’d like to create. For example, a simple fuzzer or request/response interceptor.

8, 9 and 10. Same as Keatron Evans' list.

Booting your Dual-boot OS in a virtual machine

In my previous post I showed how to boot from a USB device in a virtual machine by directly connecting a physical disk from the host to the VM. Just to see how far you can go with that I tried to boot my dual-boot OS in the same way.

Note: directly accessing your boot-disk from a VM can seriously mess up things. You are warned :)

Note: simultaneously running your host OS in a virtual machine is most definitely going to result in disaster; I strongly advise not to do that.

The process is basically the same as for attaching your USB stick, but this time you have to select PhysicalDrive0 in QEMU or VMWare player.



In VMWare player you have the option to select the partions the VM is allowed to access. The bootsector/MBR is always accessible, so you can use this option to prevent the VM from accessing your host OS. On my disk I have Samurai WTF installed next to my windows OS. I have 2 NTFS partions, 1 FAT32 partition and 2 ext partitions. In this example I booted in windows and want to have the VM boot the dual-boot linux so I only selected the ext partitions in the VM properties:



Booting the VM first shows the bootloader



And after selecting the Linux option it will boot without problems.



Attempting to boot from a partion not selected in the VM properties will result in an error, so you can use this option to prevent accidentally selecting the wrong OS:

Booting from USB flashdrive in virtual machine

The last weeks I have been playing a bit with bootable USB flashdrives and bootloaders/managers. One of the annoyances in doing that is testing if your changes work. The easiest way is to do this in a virtual machine of course, but not all virtual machine solutions support booting from a USB device. Many solutions found on the internet suggest booting an iso with a bootmanager (like plop) first, but there is a more direct solution in VMWare player and QEMU (maybe also in other products). A big advantage of this method is that directly accessing the disc is a lot faster than by using the USB stack of the virtual player.

Both VMWare player and QEMU support booting from "Physical Drives", which basically is nothing more that booting from a disk that is already present in the host.

When you are using QEMU with QEMU Manager the option can be found on the Drives tab:



The booting device of the host is typically PhysicalDrive0. Your USB devices should be PhysicalDrive1 or higher. Make sure you select the right one.

In VMWare the option is not directly available when creating a new VM. First you have to create a virtual hd of any size and finish the VM. After that edit the properties and delete the created HD. Now add a new hard disk and select the option "use a physical disk (for advanced users)":



Just as in QEMU the booting device of the host is typically PhysicalDrive0. Your USB devices should be PhysicalDrive1 or higher. Make sure you select the right one.



There is also a selection for using the whole drive or individual partitions, but for USB flashdrives you can leave this on "use entire disk" (as partitions on USB flashdrives are hardly supported and unusual).

A screenshot of a proof-of-concept running the miniXP from Hiren's BootCD in VMWare player. In this case the USB flashdrive was formatted as FAT32, but for me it also worked when it was formatted as NTFS. I used grub4dos as the bootloader/manager.



and the properties of the virtual machine in VMWare Player:



Update: to prevent the VM from hijacking the USB flashdrive remove the "USB controller" from the VM properties.

How to protect yourself from Firesheep (and other wolves in disguise)

About a month ago codebutler released a firefox plugin called firesheep and shook the world (or at least the internet using part of it). Firesheep makes it possible to sniff unencrypted networks for credentials and take over someones identity; the HORROR !

The vulnerability that firesheep (ab)uses is not new, known for a very long time, widely spread, and called "session hijacking". A very simple overview can be found at the OWASP page about it.

In fact, the problem is so big that a tool like firesheep was necessary to finally create some awareness for it and according to the website that was also the main reason for releasing it:
Websites have a responsibility to protect the people who depend on their services. They've been ignoring this responsibility for too long, and it's time for everyone to demand a more secure web. My hope is that Firesheep will help the users win.


Unfortunately the problem resides on the web server side and can only be solved there but the solutions are known.

So, where does that leave us? Are we completely helpless? Luckily not. Over the last few weeks several solutions were posted all over the internet, but I felt none of them provided a complete overview, so that's why I wrote this post.

Let's start with the obvious: "Do not use unencrypted networks"
Although this might seem an "open door" it's not. Many applications run in the background connecting at regular intervals for updates and not only on laptops, but nowadays also on smart-phones. Make sure to disable automatic connections to unsecured networks.

"Only use https"
When you need to access a webpage that requires you to login make sure it supports https. This can be trickier than it looks as many websites only support https on the login page and switch back to http after the login has completed, making sniffing and a successful session hijacking attack possible again. Some websites (e.g. gmail ) allow you to force the use of https in the settings, but more sites don't.

Firefox users can use add-ons like 'https everywhere' or 'noscript' to force the browser to always use https on certain sites, but the problem remains that many sites do not support it on all pages or functionalities (e.g. facebook chat or linkedin). Users of IE, Chrome or Opera cannot even use these plugins.

"HTTPS tunneling"
A better solution is the use of an https tunnel. With a tunnel you basically create an encrypted connection to a trusted location and reroute all traffic over it. Although many SSL supporting web proxies exist, I personally wouldn't trust them with my login data so a better idea it to setup one yourself.
For this you need to have a webserver, but this might be easier than you think. Many home-use devices like a NAS have build-in support for this and you don't need much power if you only use it yourself; a simple apache server with php+ssl support is all you need. Providing a complete guide to set this up for every device or webserver is impossible, but the basic steps to set this up are:

1) install a php based proxy on your webserver (I use phproxy, but alternatives exist)
2) setup ssl in apache
3) i also recommend to at least setup basic authentication to prevent unauthorized access
4) open up the port in your firewall

When everything is running it is as simple as first browsing securely to your proxy after which you can safely have the proxy access insecure sites. This solution does have a few drawbacks though, the biggest one being broken functionality, but security comes at a price... Another drawback is that this solution cannot be used for applications other than the browser.

When you want use other applications securely on an unencrypted network you need more advanced solutions like an SSH tunnel. Again, providing a complete guide to set this up for every device or webserver is impossible, but here and here you can find the basics for setting up an SSH tunneling proxy using putty.

Another solution is using a VPN connection, but that might prove to be more difficult to set up. Fortunately many providers offer these solutions relatively cheap so google a bit around.

Fun with regexes

Last year on one of the dutch OWASP chapters Adar Weidman gave a very interesting presentation about reDOS.

The principle behind a reDOS is feeding a regex input that will cause it to spawn a huge number of treads eventually exhausting all resources on the system. Take a look at the OWASP page for more information.

Ever since the presentation I was intrigued by the vulnerability, but did not really see much of it in the field (or I didn't search hard enough).

I mostly forgot about it until I read this post a few months ago. Apparently these things are more widespread than I suspected...

For those interested in regexes, lacking knowledge, and wanting to play with them:
http://xenon.stanford.edu/~xusch/regexp/analyzer.html
http://www.regular-expressions.info/

New Start

This week I decided to start twittering and thought it was also a good moment to revive my blog. Many things have occupied me the last year, some of which I will share here so stay tuned or follow me on twitter @Dave_von_S

BruCON 2009

This weekend I noticed the schedule for BruCON 2009 is almost complete, so now the hard part begins; deciding what to attend to and what to skip .. Tough decisions have to be made :)

If you're interested in BruCON an want to stay up-to-date; join the linkedin group:
http://events.linkedin.com/BruCON-Security-Conference/pub/31107

Pentest(ing) politics

This week I started on a long term assignment involving the implementation of web application security testing in the SDLC. Although it is fun to do something more structural than the average 'pentest a website and get out' assignment, there's also the element of politics that immediately shows it's head.

For example choosing a scanner .. Although you can get good results with a collection of open-source or freeware tools, sometimes a commercial scanner is the better choice from a political perspective. Especially when there are quite strict regulations about the format of your reporting, choosing a commercial scanner can make your life a lot easier... On the other hand it's absurd to decide on the acquisition of tools based on the format of a report.

It makes you wonder if you should deal with pentest politics or if you should pentest politics.

Corporate Espionage with Google Analytics

With the start of this blog I also installed Google Analytics just to see how it works and what data it collects. What surprised me is the fact that you can add any domain without any form of authentication. The only thing you need to do is add a piece of javascript to the site and add the domain to your profile.
Since most sites have a few XSS holes or other vulnerabilities which you can (ab)use to add this script, a scenario for corporate espionage or information gathering is easy to imagine ...
Am I just being paranoid or could it really be that simple ?

QEMU: Portable Virtualization

Sometimes you find yourself in a situation where you really need that one tool on another LiveCD, but that means rebooting and losing the stuff you're working on (or at least slow you down in the progress).

For this I found QEMU to be very useful. Combined with QEMU Manager this tool provides a nice GUI based portable virtualization tool. Best of all it's able to boot a CD, USB device or ISO.

So put QEMU, QEMU Manager and all of your favorite ISO's on a USB stick and you are able to use all the tools you want, whenever you want. (well .. off course you cannot run any WLAN hacking tools, but that goes without saying).

Fun with Firefox

Besides being a browser, Firefox can be a lot more due to availability of hundreds of add-ons. "FireCAT (Firefox Catalog of Auditing exTension) is a mindmap collection of the most efficient and useful firefox extensions oriented application security auditing and assessment"

The current official version of Firecat is still based on FF2, but most add-ons are also available on FF3. If you want to start using FF3, you should also take a look at some FF3 only add-ons: Cipherfox, Javascript Deobfuscator, JSON View, and Lazarus form recovery. The only big disadvantage of switching to FF3 is the incompatibility of XML developer toolbar for which I did not find a worthy successor yet....

The big disadvantage of using all these add-ons is that if you, for some reason, have to use another machine, you have to install all your favourite add-ons again. To tackle this problem, take a look at Firefox Portable. It is a modified installer of firefox that allows you to install it on an USB stick. All add-ons that you install on FF portable are also instantaneously portable. This way you can always have your fully customized Firefox with you !

LinkedIn group on Web Application Security Testing

I admit, I am spamming my own blog, but I created a LinkedIn group for discussions and knowledge exchange regarding Web Application Security Testing.
Please check it out en join if you're interested.

http://www.linkedin.com/groups?gid=1964541

Going to BruCON 2009 !

Completed the registration this weekend so I'll be at BruCON 2009 !

I'm also participating at one of the trainings to refresh my "hacker-skills", now all I have to do is find a course to refresh my ethics ;)

The beginning

I finally gave in; I started a blog.
I never saw the use of it, but seeing the fun my wive got out of it I thought "why not give it a try". I'm not sure yet how often I will post anything on it, but I can always delete it again .. i think .. you never know with a Google service, right ;)

Last week was a busy week; besides getting a new (actually reoccuring old) assignment I went to Belgium for a presentation and also to an OWASP meeting (for which I still had to create some minutes).

Full disclosure:
Check my LinkedIn profile: http://www.linkedin.com/in/dvstein

Anything else you can find about me: good for you ! :)