Showing posts with label metasploit. Show all posts
Showing posts with label metasploit. Show all posts

Monday, November 18, 2013

#08: France, CERN, and physical/personal security, and everything else

245 pageviews?!  What the hell?  I leave for holiday and come back, and it blows up!  Welcome to any new readers!! I promise to not disappoint. :D

I have been gone on holiday with my cruise group last month.  I had the utmost pleasure to visit the European Center for Nuclear Research or CERN.  This trip was one memory that will stick my mind for as long as I live.  Not just seeing the incredibly massive 15m long, 40 tonne (all Metric baby!) superconducting segments that ran the entire 17Km length of the LHC, but we also got to take an unexpected trip to the CMS, which was one of the two experiments that found enough sigma to confirm the Higgs Boson.  If you're interested, the Major Technicality podcast (@majortechnicality, or www.facebook.com/majortechnicality) will have it posted very soon.

One thing I did want to mention about my trip to CERN was the security controls in place.  Much of the main campus in Geneva was open, and they gave us pretty much carte blanche to visit the hallways, but to be quiet about it.  I was so enamored by the pure science of what was going on that I did not give the idea of physical or personal much of a thought.

There were no cameras, no access badges. Offices had locks, but the main campus appeared to be a recycled building from before the Cold War and the office sizes definitely had that feel.  I believed that everyone I looked in on as I walked by their office was comtemplating the very nature of the universe, or examining data to find that one thing, the one iota of information that would get them the next Nobel.  I hope I was not wrong.  Fantastic place.

My point was that a 'college' town like Geneva was incredibly "American" in it's attitudes.  Young people with their heads in their mobile devices (more Android than Apple oddly enough), and it just felt different, but no less safe.  I still carried my wallet in my front pocket, as I do in America, only out of habit.  I enjoyed the airports. No TSA, no body scanners... but in place of that, gentlemen with automatic rifles and paramilitary gear patrolled the airport.  It's interesting, we've spent billions of dollars "securing" our airports, inventing the DHS and TSA, when in fact, they are spending a fraction of that amount in Europe, and are arguably just as safe or safer even...

The heaviest security I saw was at the ATLAS project.  Cameras everywhere, badge access everywhere, including in the elevator, and the area just before you got into the experiment required an iris scan to get into the heart of of the machine. And the area with the iris scanner had a revolving door man trap operated by the control room.  When I asked our guide, who's name was 'Gerd' (hey Gerd!!!) he said that was to ensure that only necessary people could access the area, but also to protect people from the high energy radiation that gets kicked out by the ATLAS experiment.

I guess when we think of physical security, we often use it as a term to keep people out of sensitive areas, but security can be used as a protective mechanism, which I don't see that all that often.

Wireless security... Holy cow, I could not believe all the easy access to WPS enabled wifi.  If I lived in Geneva or Paris, I never would have needed to have bought Internet access.  Dozens of WPS enabled Wifi that could be easily cracked by Reaver.  All I needed was a few hours, and I'd have free, unfettered Internet. Which would have been a damn sight better than what we did have when we were able.  Hotels charge a lot for wifi, and my Verizon International data failed.  I need to get a hold of a good overseas phone that will at least allow me to access Google Maps...  But we travel over there so infrequently, doesn't really make much sense...

Well, now that I'm back from holiday, I really want to make this podcast deal happen.  Yes, I know everyone seems to have one, and "What's gonna make your podcast awesomer than everyone elses?"  Simple truth: it won't be.  I'm learning.  Hell, learning security is hard, but to learn rudimentary sound (video?) editing, as well as the bells and whistles of content creation (web page design, advertising/marketing, setup of interviews, etc) will be the real challenge.  Sitting down, spitting drivel into a microphone is easy.  I mean, look at all the talking heads on TV...  I'm at least 80% smarter than those people.  I just want to do a simple 30-40 minutes once a week (twice if I'm lucky), something really off the cuff, some security stories, and talk about security concepts I'm working on.  I'm dabbling with Python, and reading the Metasploit book written by @HackingDave (Dave Kennedy) and others, as well as doing my Pentester Academy stuff.  It's a full life.  But I would really like to do something that is mine.  I listen to enough podcasts that I realize I can't do much worse than the other folks.  And besides, even if no one listens, I'll be doing something I like.  I think "Adrift in the Security Sea Podcast" is too wordy.  I'll probably need to use an acronym to shorten it... like the A.S.S. Podcast... oh... well, guess that is off the table.  Well, it's a work in progress... I found some royalty-free music, worked on an intro... I just need to figure a few other things out...

Oh, went through a great class last Friday that discussed detecting malware in your network.  The folks over at @Mi2security, Michael Gough and Ian Robertson, showcased how the creation of a Master File Record, using file hashing, along with their brand new software Sniper Forensics Toolkit to reduce the ability for malware to take hold in a system.  It looks very promising, and I am going to try it at my home in the next few days.  Going to the class got you a 3 host license to try the software.  No Linux client yet, but they are diligently working on that.

Take care, and I'll update this post with the Major Technicality when it gets posted.  Take care... And tell your friends.

Thursday, October 10, 2013

#07: Interpreting frameworks... or 'the second opinion'

It's not everyday you're called into your bosses office with a 30 minute meeting titled 'Quick meeting'. Meetings called that rarely are.

As my colleague and I made our way to our bosses office, my paranoia set off, like any good security professional.  What did I do? What did we do?  Maybe it's about X or maybe it's about that other meeting yesterday.

Thankfully, it was none of those.  Our boss decided in his infinite wisdom, that we'd been remiss in our allowing one person to interpret what the bible, the framework that guides our actions, the PCI-DSS 2.1 framework, says.  "We may be misunderstanding certain portions, and what's worse, our relationship with our QSA is not what it should be", he says.  "We need to do better, to be better."

Silence... flabbergasted...

We thought that we'd been doing well.  Just passed our 3Q PCI milestones, and were working steadily towards implementing controls and policies that we didn't have about certain audits.  We were around CMMI Level 2 on many of these things.  No formal policy, but we were doing them.  We are working towards Level 3, 4, and 5.

So, why the re-evaluation?  Our compliance person has one idea of what PCI means, but after speaking with our QSA's superiors, we found that we may have been farther along in the PCI process than we thought.

For example, We went from 'all firewall ACLs had to be justified' to 'We must be doing regular audits on firewall logs' Which we had been doing that nearly everyday for the last 6 months.  What a pain in the ass to find out that we have been good to go.  We still plan on finding out how what is connecting to our networks, and why.

Compliance is a funny thing.  It's a gray area that I am not accustomed to.  It's 'check-box' security.  Security != Compliance, and yet making sure we are at the 'low common denominator' of security is what we do.

Now that we have some breathing room, we are finding that the 'compliance' marathon is helping us find more security related tasks that we can take ourselves beyond PCI compliance.  Which is what should be strived for... beyond compliance.  Some of our firewall ACLs are years old.  Are they still needed? Who uses them?  What's the hitcount on them?  We have revised our policies to say that anything more than 90 days old without a change in hitcount is going to put the ACL in a 'reviewable' status, and if there has been no change in 120 days, we will remove them.

If you haven't had a look at what is coming in and out of your environment, or even between your network segments, I think you should re-consider.  You may even find that white whale of issues, the dreaded 'any-any' rule... *shudders*  Gives me nightmares, especially if it's been in there for a while.

I am hoping to start some interactive content on my site soon.  I would like to go in the direction of securitytube, but maybe in a compliance bent.  Going over various compliance frameworks, methodologies, even get in the weeds with items like Meaningful Use for securing medical records. Maybe like what Vivek does for Metasploit, for his megaprimers...

Any who, that won't happen until after I get back from my holiday...  Take care, and hope you like what you see...

Thursday, September 26, 2013

#06: 'Checkbox security', and security tube, and milestones

<rant> I am so tired of hearing 'checkbox security'.  For me, that term means we aren't doing enough, and just trying to get by.  When I was in the Navy, you could just get by just doing the minimum, and people notice. Were there days when I felt like doing the minimum? Heck yes, but not when it came to my job protecting my network.

I need to switch that term back to what it should be called... 'Compliance'.  COMPLIANCE !== SECURITY.  It's the bare minimum to start with if you want security.  Or at least be more secure.  I'm tired of just getting by doing the minimum, and I'm gonna change that next week.  I'm gonna rise up and make some shit happen.
</rant>

I finished with the excellent C|EH All-in-one book, written by Matt Walker (ISBN: 978-0-07-177228-0).  If you're a n00b to the arena of ethical hacking and pentesting, like me, then you'll want to check this book out, especially if you're working toward getting your C|EH.  I was dismayed to find the C|EH test is just another multiple choice test.  You regurgitate what you 'know' and pass.  Much like the CISSP.  I think I am a little confused by how you go about taking the exam.  I've read the All-in-One, did fairly well on the practice tests in the back, and have attended a week-long ethical hacking course given by our local ISSA chapter.  Plus, there are tons of practice tests and questions that are free on the Internet.  Guess I just need to sit down, fill out the form and take the exam.

Now that I'm done reading the CEH book, I've started in earnest on learning Python.  Using the excellent 'Wood Rat' (Neotoma Muridae) book from O'Reilly, I usually read at night as I am going to bed. I can usually knock out about 10-12 pages a night.  To augment this, I saw that Vivek Ramachandran over at SecurityTube (http://www.securitytube.net/) has started the "Pentester Academy" which allows you to take advantage of all of his excellent video training.  I have started the "Securitytube Python Scripting Expert" megaprimer/track that has Vivek explaining concepts like tuples, immutable strings, and if/when type loops.  The loops are nothing new, but I've not worked with scripting to the level I am about to learn with this.  Python is a freaking powerful language, and very VERY flexible.

I initally balked at the cost. It's $99 for the first month, plus $39/month thereafter.  But I figure with the book I'm reading and this, I can learn a lot.  Vivek does a good job of explaining concepts and I am fairly confident that I can/will learn Python using him and the O'Reilly book as an augment to the training.  You can find Vivek on Twitter @securitytube.  He doesn't pay me to say any of this, and his site really has a lot of great content, even Metasploit training.  And I heard on last week's Pauldotcom security weekly podcast that he is working on a Burp Suite series, which I'm highly excited about. You can find his interview with @pauldotcom here: http://pauldotcom.com/2013/09/episode-346-guest-interview-wi.html

Lastly, we made our PCI milestones this quarter.  While I abhor the concept of 'compliance' frameworks, it's nice not to have that 500 pound gorilla on our collective backs, at least for a few days (that gorilla being 'management').  A lot of the stress was learning the processes for submitting reports to Tenable, our new QSA and inital setup of Nessus.  If you haven't find a good QSA, or are looking for a good vulnerability scanner, Nessus is very easy to learn, and the reporting is nice, concise, and easy to parse, and Tenable's QSA's are very knowledgeable and very efficient at explaining what is needed for the burden of proof.

Thanks for reading this.  You might be the only one.



Tuesday, August 13, 2013

#01: The tools we use...

**My opinions are not my employers, and thusly are mine and mine alone**

I am slowly coming around to understanding the nature of tools like Metasploit, Nmap, and the like. I thought that to become a security researcher, you have to understand exactly what the underlying code does, and you're required to grow your Unix-y beard and ponytail like everyone else.  I felt like Metasploit was a 'cheat' that people used to become pentesters.  I have been around long enough to see people get into positions they clearly were not ready for, and earned certifications because they could write a good test, yet had no knowledge of what they were doing.

I equate Metasploit to the blender a chef would use in a kitchen.  It's a tool, that automates a process that is time consuming or laborious.  Or a wrench that a mechanic would use to tighten bolts.  Everyone in a job has their tools, those little time savers that make work more efficient.  Someone else created the blender, and the wrench, but we gain an advantage by using them.

I always thought that I'd need to make my own exploits and learn C and Assembly, and I'd need to learn how to solder well enough to make my own circuits for hardware malware, etc.  While I would still love to have an in-depth knowledge of those ideas, I have realized that I ended up with a bit of scope creep, and that I need to dial it back a bit to keep from being overwhelmed.

That's why I'm learning Python, and someone else suggested Ruby (since Metasploit uses that)...  I do want to learn more about C, but right now, I just have the basics.  Plus, there isn't much in the way of C programming being used at my office, so I need to learn concepts that will relate directly to my job so I can keep my edge sharp...

So, Python and Ruby it is...  Also, gotta get back to shell scripting... I used to do it a lot in the past, but vulnerability scanning, and justification of firewall ACLs for PCI-DSS doesn't have a place for shell scripting...

I want to do a post once a week, even if it's just stream of consciousness shit.  The C|EH All-in-One book is a hard slog though... Just through the chapter on Social Engineering.  I realize now that we probably should give some kind of training on a regular basis to spot social engineering trickery, as well as proper disposal of papers with info on them... ooh... I wonder how difficult the shred bins locks are to pick...  Yep, even when you reduce scope, scope creeps back...

Friday, August 9, 2013

#00: the beginning

**My opinions are my own, and not of my employer**

I started this blog to help me to put down somewhere things that I am learning about with regard to security and things that interest me in the field of Security.  I don't want to say I'm an "Information Security Professional"... it's too constricting.  I mean, if you look out there, there is a whole world of security concepts and tasks, and you'd be hard pressed not to find something in there that doesn't tickle your fancy.

Security researchers these days are getting into all kinds things.  It used to be that networks (wireless or wired), servers and workstations, or databases were the only gems to exploit.  But in recent years, researchers like the late, great Barnaby Jack and others have been looking at SCADA systems, vehicles, medical devices, etc for security vulnerabilities. And let's not forget the whole mobile platform.  Tablets, phones, mini-PCs, all run a varied operating system with a user base that suffers from either lack of knowledge, or they don't want to know.

I got into security late into the game.  Sure, I've been doing it my entire career, whether that be Physical Security (access controls to COMSEC), or Network Security (typical IT admin stuff).  All the way up to what I'm doing with my current job, which is compliance, governance, and attempting to wrest control of the network out of the hands of users who just want to do what they feel is necessary to get the job done.

I want to start this blog to highlight my continuing journey across the Security "Sea".  It's vast, it's fraught with difficulties, and the metaphorical boat I'm riding on has holes in it, or tigers even (nod to "Life of Pi").  I want to talk about security in the news that matters to myself and others, but also to talk about things that I'm learning.  I'm reading the C|EHv8 All-in-One right now, and I am skimming through the fantastic "Metasploit: The Penetration Tester's Guide", and once I finish with the C|EH, I'll begin working on learning more on Ruby and Python, which run Metasploit.

There's just so much I want to learn, and I often feel like there's too much, and that I'll never learn it all, as though I'm just trying to keep my head above water.  So, making this will help me chart my progress, and who knows, it may even be fun.

Take care, and if you want to talk, I'm on Twitter  @bryanbrake