Sunday, October 16, 2011

How I got back a returning customer

Background
A little background information for you folks... who don't understand what I do... I expose the ways in which your network, server, host, web application, website or any other system maybe vulnerable to real attacks. We are not talking about some obscure bug that can't be exploited. We are talking about DNS here...

Now DNS is not exactly rocket science, right? You think so? The customer whom I spoke to doesn't really concur with me on that point. He thinks it is rocket science, since he does not have enough technical knowledge to figure it out. I give him a demonstration of how to tunnel SSH over DNS (Ozyman) and SSH over HTTP :))

Show time (DNS Tunneling)
Once I do that, his auditor freaks out and tells me how I am doing bad things. What is my job again? I expose vulnerabilities and real threats to the customer, I don't perform simple scans and tell the customer to patch some bug without taking business productivity and impact in to consideration. In layman terms, tunneling a protocol over another like discussed above can cause the network to think SSH is just DNS traffic. Truth is some rogue hacker may get a reverse shell running through that port and hide in plain sight.

The customer and his new found "auditor" (read: CISSP / CISA holder, with no grasp of protocols). I had to show documentation, research and a tool. To top it off, I showed a live demo and used Wireshark to show the DNS traffic. I did my job and I did it so well, that the customer becomes scared, confused and everything else, but convinced. The customer does not want to understand the impact, or go with a quality security tester like me.

My mistake
I told them, I will test the environment without any bias and will not support their certification (compliance) efforts, if they fail to co-operate and patch all the important vulnerabilities. This causes a real stir and the next time, the customer (who happened to be a return customer - more than 4 engagements)... fails to choose ME for the 5th time.

Business 101
Guess why they didn't want me? I argued and I failed to co-operate with them for their namesake compliance... OK, from a business point of view I totally understand their hatred towards me. There's an old saying in sales, If You Win the Argument, You Lose the Sale (The auditor played a good part in convincing them, that I am not the right person for the job). When it comes to security and technical aspects, I put my money where my mouth was... and showed them a real demonstration.

Better Late Than Never
What did I learn? Be co-operative... or lose the sale. I'd rather have it my way or the highway... and a customer who can not appreciate quality is always going to end up in my bad books. I am a person that believes in quality over everything else.

What did they learn? The customer's network got hacked exactly 90 days, after they achieved compliance. The customer didn't hesitate to call me. The manager at their firm said some thing I am very proud of... He said, "We are calling you because you scared us just like that hacker..."

For a few dollars more
After the post mortem and forensic analysis, I helped them to set up an incident response plan. The customer now engages me for security testing and over all maintenance of their network. I have gained a returning customer, after losing them once. Selling is all about second chances ;))

P.S: This is NOT the First Time, I am getting a call from a customer that disagreed with me and got hacked!

Cheers,
Kish

Thursday, October 06, 2011

Wow, Goodbye Steve?

Is it that time of the century for an inventor to be gone? Gee, that sucks... Goodbye Steve :(



Steve is an inspiration at best and he braved - being born to unmarried parents, thrown to be adopted by his mother... Then he drops out of college, founder of apple, founder of pixar, rejoins apple - a revolution happens with iPhone, iPad, iPod and owning an Apple product doesn't make you exclusive anymore, they've turned from being a niche company to a mainstream company with nearly $350 Billion USD in stocks... The only company that makes more money than Apple is Exxon Mobil and they do it from oil, not from ideas !

R.I.P Steve, also R.I.P A.C Nielsen... Peace !

Saturday, August 27, 2011

iQuit... Steve job quits apple, what again?

I have stopped counting the number of times, he's quit and come back to Apple...


Really would be a relief, if he let M$ stay on top and generate serious revenue compared to Apple. Personally, I'd like to see iPhone and a lot of i Apps / i Hardware(s) to stop... The world becomes restricted to bullshit software provided by apple... and their updates, well you've got to pay for it? WTF?

A lot of apple fans are pissed because the software, drm and whole pay for your updates BS - what if, they introduce bugs just to push more updates... That is not happening now, but some thing like that isn't impossible... ;)

It would be ironic to have such ridiculous stuff going on, amidst their already high number of vulnerabilities. iHate - Apple... All that aside, Steve Jobs is a great guy (business strategy, promotion, ideas and inspiring), Good luck to him !

Saturday, July 09, 2011

Love Letters...

I just love this, love this mail, especially the part about monies... hahaha !



Thank you for the Love letters :D

Monday, June 06, 2011

Note: Top 5 Database Breaches in 2011

1. Victim: HBGary Federal
Assets Stolen/Affected: 60,000 confidential emails, executive social media accounts, and customer information.

2. Victim: RSA
Assets Stolen/Affected: Proprietary information about RSA's SecurID authentication tokens.

3. Victim: Epsilon
Assets Stolen: E-mail databases from 2 percent of the firm's 2,500 corporate clients.

4. Victim: Sony
Assets Stolen: More than 100 million customer account details and 12 million unencrypted credit card numbers.

5. Victim: Texas Comptroller's Office
Assets Stolen: The names, Social Security numbers, and mailing addresses of 3.5 million individuals, plus dates of birth and driver's license numbers of some.

Note for reference... :D

Thursday, April 28, 2011

And you thought online booking is safe

INOX Movies features - A lesson in "designing secure web pages"


Vulnerable URL: hxxp://www.inoxmovies.com/seatlayout.aspx

Incase you don't understand what will be the bug, it will be a SQL Injection!

INOX Movies is "Safe"... Come on, it uses "http"... it's unbreakable! :D

Sunday, April 17, 2011

APNIC runs out of IPv4 Address


http://www.apnic.net/publications/news/2011/final-8

If you haven't read this announcement, read it and act on IPv6... deployment for your enterprise environment.

Cheers,
Kish

Saturday, February 12, 2011

Ignorance is "THE" root of all evil

Example? HBGary's latest pwnage by Anonymous group... Can't understand why they don't maintain good passwords, different passwords for their account, some user awareness and why they can't get pro-active website maintenance and testing. They have so much capital and as the last line in the JPG says... "not expertly secured" ... Epic FAIL.



BTW, I had and still have respect for Greg Hoglund from HBGary. All in all, they lost clients and will have bad PR for the next month or so... please work on your security "before" you get hacked.

For all the guys, who insist on "no DoS, no stress testing, no client side testing and no social engineering" - [04:18] <&Sabu> greg, a 16 year old girl social engineered your admin jussi and got root to rootkit.com

Yes, that's straight from a IRC chat log involving Greg(HBGary), Penny (HBGary) and the anonymous group... I read the full log for the LOLs :D

Peace !

Saturday, December 18, 2010

Back... To Security Testing

After a recent flood of investigative, forensic and legal support requests... We are back ON-Track to security testing... Always great to have the 'hacker' tag :D

I certainly appreciate my clients who entrusted their resources to me for investigations and forensic work, but nothing like our bread-and-butter, haha.

The headlines from ArsTechnica read "MSE 2.0 arrives with heuristic scanning, network traffic inspection" & "December 2010 Patch Tuesday will come with most bulletins ever"... and ZDNet's headlines include "Microsoft delivers patches for IE, font driver; Puts Stuxnet to bed" & "Apple plugs 15 gaping security holes in QuickTime"

Some surprise that MSE 2.0 has been successful, because it was released earlier for as a pilot - and failed in 1.0 before they learned their lessons and launched 2.0 ;)

Same surprise about Windows Patch Tuesday - I love MS, they help us survive and stay in business... No Wonder, with tools like Metasploit and CANVAS around :D

Stuxnet has been put to bed and that is indeed good news...

We are going to have a blast, 3 pen-tests already lined up :))

Sunday, August 01, 2010

UIDAI Scheme - Or - Compromising my privacy?

What we know / heard from a few sources?

Basic Information:
The UID itself will collect only standard attributes such as name, date of birth, gender, father/mother/spouse/guardians name, address and a photograph. The only unique information is the biometrics (10 fingerprints and both IRIS scans).

Who / Why / Usage
The UID will be given to all residents who are in India and avail services and not just citizens.

The information in the database will be used only for authentication purposes and will not be shared or transmitted. Anyone seeking to authenticate the identity of another person using the UID database – will only get a response in YES or NO.

About working / operations:
The UIDAI is working on a partnership model with a variety of agencies and service providers ( both government and private sector) to enroll residents for UID Numbers and verify their identity. For e.g. Insurance companies, LPG marketing companies, RSBY, MG-NREGA etc. The UIDAI will also engage with Outreach Groups (essentially CSOs) to target, the homeless, urban poor, tribals, differently-abled population of the country etc.

About security:
The UID database will be guarded both physically and electronically by a few select individuals with high clearance. It will not be available even for many members of the UID staff and will be secured through encryption, and in a highly secure data vault.

Is your security up to the mark ? What is that secure data vault thing? Please don't use such terms, a layman maybe fooled into thinking "ultra secure" when in reality, you're storing it in the most haphazard manner.


Why do they (government) want a person's mother's name, father's name, and their respective UID numbers ?



Check this out ... the picture shows what info they are going to collect for the card. Add the present/permanent address thing to this mix, you can have one of our residing addresses, you are the government, you either choose permanent or present address, because parting with "everything" or too much of my private information to you - from me, a hacker's perspective... looks like asking to be stabbed !

All I'm saying is ... basically, devil knows who's got access to this DB once it is implemented. That's not all, they do say there may be an option for a person to escape their identity theft mechanisms and create a completely false identity and obtain a UID, d'uh !

Murphy's law folks, if you missed it ... "If anything can go wrong, it will"

Security Model for UIDAI Scheme



Always be prepared for the worst case scenarios, stop deducing cyber crime with just audit trails for a change.

Offences under UIDAI Act - Check out the screenshot



Addition about the IT Act 2000, and consequences if you compromise their DB,"All offences under the Information Technology Act shall be deemed to be offences under the UIDAI if directed against the UIDAI or its database."

Small FAQ I built for the readers,

Q. How will they (government) manage and secure 1.20 billion people's information ?
A. They wish to encrypt information and store it in a centralized DB...

Q. What security design will be implemented for Server and the Network/Client?
A. We have Firewall, IDS, IPS - alphabet soup basically, and Encryption with PKI.

Oh, my! the traditional defense-in-depth approach - Lauds the government. What about being proactive and conducting tests regularly? (Pen test, code review, DB security, red teaming, and compliance for the supporting infrastructure)

Q. Will my information be secure in the database?
A. Well, it depends... lol !
"The UID database will be susceptible to attacks and leaks at various levels. The UIDAI must have enough teeth to be able to address and deal with these issues effectively."

Q. What will the basic information and biometrics be integrated with?
A. Banks, Ration shop, Income Tax Dept, Passports, Credit Card/Debit Card, Online accounts. Precisely, enough sensitive data will be integrated with so-cal best practices to leave you stabbed from a lot of angles.

People who define security should not use the abbreviation for et-cetera (etc). Define and then write a document, because you are dealing with national security and a billion plus populous here. Don't be so naive and clueless by mentioning stuff like "Network, Client Security – Encryption, PKI etc"

From the looks of it, The way in which the government is dealing with our information is haphazard, to say the least.

Cheers,
Kish

Friday, July 23, 2010

Xchanging URLs now ;))

The vulnerable page is still there, and there is no fix... but hey, the web developers sure learned to redirect the vulnerable page to home.html... ironic ;))



Web development and Security @ Xchanging - EPIC FAIL... sorry folks... Try harder next time... If you want to contact me for a penetration test, here's my mail: kishfellow at yahoo dot com

Cheers,
Kish

Wednesday, July 21, 2010

Xchanging SQL Injections with you...

Xchanging - Xchanging plc (LSE: XCH) is a business processing company, with a wide range of multinational customers in 42 countries and employing over 8,000 people worldwide. It is listed on the London Stock Exchange and is in the FTSE 250 Index. Xchanging is also a member of the FTSE4Good index.

They have a potential SQL injection here, well... someone needs a pen-test?
http://selfservice.xchanging.com/serviceportal/default.aspx?offset=

Cheers,
Kish

Tuesday, July 06, 2010

Linux migration SNAFU

Disclaimer: The author is not against windows, the author is not against linux, the author is against "stupid" practices and communication gap while migrating from one OS to another. The author is an ardent Linux and BSD Fan, and supports FOSS/OSS movements.

The inspiration for this post comes from a REAL company whose employees were not so happy and almost resigned their posts owing to a bad migration.

Here is a story of a simple Linux migration gone-all-wrong.

The last thing any employee wants at the office on Monday morning is to turn on their workstation to find Linux instead of their beloved Windows operating system.

How NOT TO MIGRATE from Windows to Linux
- For Lower TCO, access to source code,
- For Economic benefit, Ethical Benefit,
- For Access to Source code,
- For whatever-else-you-deem-fit to trigger a migration

You certainly have to communicate to your employee formally - written as a memo circulated throughout the ranks, or a simple e-mail to all employees notifying the change.

Analysis : Why it went wrong ?
Things that made this particular migration go wrong...
1) The employees were not informed prior to the migration
2) Backup was not in place, only last minute backup was available
3) There was no Linux101, Command Line usage or any induction towards the new operating system at their disposal.
4) No clear planning, and deployment - Old versions of Ubuntu were deployed.
5) There was no consultant or subject matter expert to assist the migration.

How TO MIGRATE from Windows to Linux
- Prior to the transition from one OS to another - inform your employees formally
- Get them involved in the planning and ask for their views & suggestions
- After giving the heads-up, arrange for a backup (through System Administrator)
- To make the transition smooth decide who needs a Linux desktop and how many Windows systems can be retained (to reduce training budget)
- Choose a Linux distribution based on - User competence, prior experience, and business goal (why linux?)
- Engage an external consultant or subject matter expert
- Plan the switch with software used currently and alternate software available for linux
HINT: ptth://www.osalt.com
- Deploy a test bed and introduce the operating system functionality
- Arrange for a formal induction (hands-on) with the consultant
- Clarify doubts and exchange ideas, get tips and tricks and further reading
- Arrange for a dinner (makes employees happy to eat and learn, than just learning)
- Use linux philosophy from time to time - for motivation, increasing productivity, and squeezing employees to the max, hehe !

"The only thing worse than training good employees and losing them is NOT training your employees and keeping them."
- Zig ziglar


Point to be taken from this post: Next time you migrate to any linux distribution, make sure you Communicate the change, engage a subject matter expert, plan, test, and then deploy.

Cheers,
Kish

PS: We offer Linux migration services, and Open Source consulting of the best quality at very nominal pricing. Contact me for more information.

Monday, May 31, 2010

U Socket - USB Charging directly from plug points

Quoting from their website,
"U-Socket is a duplex AC receptacle with built-in USB ports that can power any device that is capable of being charged via a 5V power adapter, but without the need for the power adapter! When a U-Socket replaces a traditional 3-prong AC wall socket, you can eliminate the clutter of AC Adapters that stick out & take up space in your home or office. Everything stays neat & organized. In additional, U-Socket's energy efficient design only outputs power through the USB port if something is connected to it. This can save you up to $25 per year in reduced energy costs. Good for you, good for the environment and with our great prices, good for your wallet too!"



Neat little addition to your desk to charge your devices like iPad or mp3 players :)

For more information, click here

Cheers,
Kish

Sunday, February 07, 2010

No pun intended

Pen tester1: I have have very less issues related to security compared to my windows laptop
Kish: probably, because people own macs silently ;)
Pen tester1: ...

Saturday, October 17, 2009

Evil Maid - Pwnie for Overhyped bug

Hey dudes, and dudettes, Happy Diwali to y’all !

Today’s post is about the Evil maid's exploits on an unsuspecting computer user...

Scenario
Full disk encryption with Truecrypt in this case...

The author mentions PGP whole disk encryption but never mentions about testing it on the humor-me FAQ, LOL! :D


Attack
Joanna of Invisible things has come up with an attack (social engineering + physical access + usb drive?!) - WTF I say... If a person has physical access to your box, it is pretty much a goner... what difference does it make if I boot from a live-cd and use a keylogger or do the same thing from an USB drive?

Solution
Disable USB boot from BIOS options (this ain't nothing new to talk about, building a custom USB drive with a small kernel and a simple keylogger is NOT new)

If you know your way around in Linux, and you use it as a base for your penetration testing laptop. Try modprobe -r usb_storage and blacklist in your conf file, if you are paranoid.

You can easily convert the install/remove commands into a shell-script. Alternately, USB devices can be disabled at the kernel level via GRUB or any other boot loader by editing menu.lst / grub.conf

There is also a humor-me FAQ that says...

Q: Is this Evil Maid Attack some l33t new h4ck?
Nope, the concept behind the Evil Maid Attack is neither new, nor l33t in any way.

Q: So, why did you write it?
Because we believe it demonstrates an important problem, and we would like more attention to be paid in the industry to solving it.


As if nobody has covered these hardware based and/or social engineering attacks in the past?

Q: I've disabled boot from USB in BIOS and my BIOS is password protected, am I protected against EM?
No. Taking out your HDD, hooking it up to a USB enclosure case and later installing it back to your laptop increases the attack time by some 5-15 minutes at most. A maid has to carry her own laptop to do this though.


I loved this part... Every maid knows how to pull apart a laptop and remove the hard-drive enclosure without damaging the drive... Do all maids have prior training in corporate espionage, and basic computer/laptop hardware and operations? LOL!

Q: Why did you choose TrueCrypt and not some other product? Because we believe TrueCrypt is a great product, we use it often in our lab, and we would love to see it getting some better protection against such attacks.

Encryption must protect against physical attacks? Since when did that become a pre-requisite for a fool-proof encryption system/software... since the day "Evil maid was coded" I guess... ;))

Their solutions: Protect your laptop (wow, you discovered something here…), TPM (aka snake oil), Disk Hasher (oh, hashing is a “reasonable” solution even though it is broken)

Let me get this straight, you invent a problem out of nothing and you suggest YOUR own solution, roflmao!

Bottom-line
General unsuspecting public will leave a laptop like this fine lady here suggests. If a person identifies himself/herself a hacker, they are NOT supposed to leave their laptops in a hostile environment... When you leave like that, don't identify yourself as a hacker.

Acknowledgments
Thanks to the ennead@truecrypt.org for all the polemics we had which allowed me to better gather my thoughts on the topic. The same thanks to Alex and Rafal, for all the polemics I have had with them (it's customary for ITL to spend a lot of time finding bugs in each other's reasoning).


The person demonstrating such a GREAT attack will go to any extent to prove that an attack is possible, but will not think one bit as to whether it is practical??

Truecrypt clearly mentions about physical attacks in their documentation, which means they are not addressing the issue, and they want you to find something more serious and interesting to work on and if you don’t have a lot of ideas, ping Halvar Flake – He’s a smart guy with a lot of ideas which are innovative. Stop rehashing old attacks and building small Linux kernels with a simple keylogger and write a humor-me FAQ with “we want more attention” (you want the industry to pay attention to the attack or you?)

Truecrypt Dev: My answer was a good safety case or strongbox with a good lock. If you use it, then you will notice that the attacker has accessed your notebook inside (as the case or strongbox will be damaged and it cannot be replaced because you had the correct key with you). If the safety case or strongbox can be opened without getting damaged & unusable, then it's not a good safety case or strongbox. ;-)

Well, what can I say, except … he pwned you!

I nominate “the Evil Maid” for the Pwnie Awards 2010 - Most Overhyped bug… perhaps someone can beat Joanna to the race… Let’s see… hehe!

Errr...Where's all the rum gone?

Thursday, July 30, 2009

R.I.P - Fravia, the master

Fravia (Fjalar Ravia) from Germany is amongst one of the most finest and brave human beings on this planet. He was an ardent reverse-engineer and a master at what he did. In early 2005/06 he gravitated on to search related stuff. He's a good friend and a great guy personally... I didn't know he was dead until I was talking to a friend on RCE.

Without your teachings, emails and your website, I will not be where I am today.

R.I.P Fravia, the brave may not live forever, but the cautious don't live at all !

Monday, May 04, 2009

Warning: Don't be conned

Warning: Don't be conned

This POST is about an exceptionally serious issue, so don't be conned, or fall prey to impostors, and bad guys...

Message:

Don't dial 90# or 09#, #09 or any other combination requested by any technician / serviceman CLAIMING TO BE from your subscriber, on Nokia, and Motorola mobiles these codes are used by telephone service men to test line connectivity, these codes can also steal your number, and enable the caller to use your mobile to make calls, and bill it on your number.

Technically,the caller can SPOOF HIS NUMBER to make calls, which will be routed through and billed on your number so stay alert, terrorists have used these type of conning tricks in the past,and use it now so be careful, and spread the word ...

The information has been confirmed, by Nokia, Motorola, and CNN websites.

Saturday, April 25, 2009

Getting passwords with P2P

Getting passwords with p2p softwares
(Limewire/Bearshare/Kazaa/Shareaza/emule)

1. First you need to get any p2p software,download it with the crack.
2. When you get bearshare and have set it up, click the Search button.
3. Click on 'Documents' in the search section, and type anything like: My Passwords,Yahoo Passwords, Ebay Passwords, My Passes, Rapidshare Pass,XXX Pass, your best bet is My Passwords.txt
4. Now the syntax : Passwords or pass , you can include txt extension if required.
5. Search and download the files and you can see clear text passwords.

How is this possible?
Simple answer, most p2p are illegal, they share your whole hd even if you set restrictions to prevent the sharing of entire hd or ur best collections.

Wrote this a while ago, in some forum (this is from my 2006 scribbling), the funny thing is
"it still works!"

/Quit

Thursday, April 23, 2009



Recession ? Okay, but still cigarettes, gutkha, and beers cost the same amount ... ;)

Recession isn't something amazing, it's just another rough patch ... Get over it already!

Cheers,
Kish