Showing posts with label Solutions. Show all posts
Showing posts with label Solutions. Show all posts

Monday, December 22, 2014

Hacking...

I identify myself as a hacker... not as an ethical hacker. Hacking is an art, just like martial arts or painting. Hacking is about making a device or system do some thing the designer did not originally have in mind. When you exercise your creativity you can hack anything.


So just like a mechanic, painter or a martial artist... the term hacker is right. There can be a good martial artist and a bad martial artist, you don't call those people with one word or have multiple words mixed up in a haze. Similarly there can be a good hacker and a bad hacker. Like I explained earlier, the decision to adhere to ethics is up to each and every individual. When I became a hacker, I learned that I have to protect the word and clarify our stance to the world. The media has created a bad image about hackers and bad news / press sells faster and better than "normal" news.

As far as learning goes, You can learn the basics and then work on your own - for a few years to achieve good competency. Hacking your own XBox for example to store movies and stream it - on to your LCD Television is legal, provided you paid for the movies and the gaming console... ;) If you don't pay for the movies, but download them from the internet... then it is illegal.

The society / media that waves the "Ethical Hacker" tag must understand - The term is an oxymoron at best and incorrect. I am no lawyer, so I can't comment on Ethics of hacking or any deed. Mahabharata says there is no good or bad deed. Western culture also agrees with the same in multiple scripts that: all deeds are situational, whether good or bad depends on each individual's own judgement and justification. People mix things up badly and have a perception of smoke and mirrors created by the media about hackers.

We're simple people and we like breaking stuff for a living, just like software engineers build stuff for a living. Hacking can therefore be termed as creative destruction of a given system or program.

I'm taking a break from work soon, summer's here yipppeeeee :)

Cheers,
Kish

Saturday, April 12, 2014

OpenSSL Heartbleed Vulnerability

Myself and Digi from Crimemachine have whipped up a document to educate the public about this recent vulnerability. With all the information and buzz surrounding this vulnerability, comes a lot of confusion too... We provide this information with the standard disclaimer, this information is for educational purposes only.

Download the Heartbleed - Information Packet (Google Drive)


 You will be responsible for your own actions. Use the information sensibly.

Official Website: http://www.heartbleed.com 
OpenSSL Advisory: http://www.openssl.org/news/secadv_20140407.txt

Update: A simple shell script for those of you who are dabbling with the code,
root@crimemachine:~# while true;do ./heartbleed.py 192.168.220.133 -p 443;sleep2;done >> /tmp/heartbleed.log
You can iterate the loop and record login credentials when a user logs in to the site/server.

Cheers,
Kish

Wednesday, March 12, 2014

Talk to the real hackers...

In today's scenario, Every body is a penetration tester... :D
All the "me too" security providers, "engineer" pen-testers, one stop shops and yuppies are going to be mad at me now... An artist should rather let his work speak, if you want to see me in action, call me!

Cheers,
Kish

Thursday, February 28, 2013

Survey - Selling Security


Following is a survey conducted by me on 3 simple questions which a lot of security professionals may have seen, heard and answered in the course of their career. These three questions are simple, but cover the basic questions any client may ask frequently,

Question1: How much would you charge for a pen-test for a 500 user base? (involving Desktops & Servers). Scope of work is to conduct VA, PT and a Social Engineering exercise. Is Rs.20,000 a realistic number for the said scope?
A) Auditor X - Done generally to reduce price or show their objection (price/budget). There's all kinds of people who do these tests, For example, I've heard about people pricing a 50 server assessment for Rs.10,000 (with PoC Exploits). I have seen reports being copy / pasted from the scanner without any change for a lot of engagements.
B) Sec Consultant - The price has to be more, but preferably in double digits, not in lakhs!
C) Big4 Consultant - Practically not possible to price a pen-test of this magnitude at the client's budget
(Minimum 10 lakhs for the engagement would be my quote)
D) Customer X - 1.5 to 2 lakhs will be a realistic budget, Unrealistic to ask for 20K
E) Trainer X - Approximate number would be upwards of 1 lakh, I don't know what would be a realistic number.
F) Former Dev X - Definitely wouldn't do it for 20,000. Regardless of the tools used the skill set I've learnt over years, that's what demands pay.

Question2: Is it fair to compare a consultant's time, skill and experience with tool(s) license cost?
A) Auditor X - Obviously the tool's cost is cheaper, why do they need the consultant in this case?
B) Sec Consultant - Need for a mix of both things (tools and consultant's skillset)
C) Big4 Consultant - 10 lakhs minimum - 20,000 is not possible, manual effort, interpretation of vulns and skill involved is the differentiator.
D) Customer X - Based on the frequency, I will choose whether or not to hire... IF Quarterly or frequent tests (say 12) are warranted then I'll train in house personnel for the requirement.
E) Trainer X - Anybody can run a tool, but without properly understanding the vulns and what happens behind the scenes, the test results can't be interpreted properly.
F) Former Dev X - No it doesn't justify the argument, I wouldn't just rely on a guy who doesn't know security. 

Question3: Do Certification(s) like CEH, CPTS and a couple more enable you to carry out a penetration test?
A) Auditor X - People can't run tools properly, let alone conduct a proper test. You'll be shocked by the things I've heard about CEH and how it (CEH Training/Cert) can be procured for 15K inclusive of exam voucher.
B) Sec Consultant - Yes... but depends more on the foundation and creative ability...
C) Big4 Consultant - Certifications are theoretical, cover only basics of tools, do not impart practical knowledge.
D) Customer X - Real time experience and fundamentals are necessary... just certifications won't help in conducting a penetration test.
E) Trainer X - Absolutely not possible to perform a test in live environment.
Content provided in certification is theoretical and not a real indicator of skill.
MNCs may buy the argument, but even they conduct interviews to assess the credibility and skill set of a candidate.
F) Former Dev X - Honestly certifications are to "basically convince prospective employers and yourself" that you know something that you don't. Haha! The certification's content just scratches the surface of what's possible.

Participants of the Survey:
Auditor X - Infosec Auditor with over 5 years of experience, which includes areas such as VA, PT, Auditing, Operational Risk, Business Continuity
Sec consultant - Over 10 years of experience in GRC, Vulnerability Assessment, Pen-Testing
Big4 Consultant - Security analyst with 3 years experience in Web - Vulnerability Assessment, Pen-Testing
Customer X - Works as a manager for a manufacturing giant, over 8 years of experience.
Trainer X - Works as a trainer on mostly Windows, Networking and Security based topics.
Former Dev X - A former developer working for an MNC, With exposure towards Programming.
Former Dev X is also an experienced hacker, who currently performs all kinds of pen-tests and source code reviews (which he finds boring) ;)

The opinions are interesting when you read each person's - background, point of view, experience and current work profile. Based on general consensus, we have opted to make your identities anonymous; we respect your privacy... Thanks for taking the time to answer the questions politely...

Personal thanks to all the participants, interacting with y’all was fun!

Cheers,
Kish

Update: Found an > old bookmark < certainly worth a laugh... ;)