Check this tool out! Facebook Controller:
http://my.opera.com/quakerdoomer/blog/2009/04/30/fbcontroller-facebook-controller-the-ultimate-facebook-controller-without-the-pa
Nice, using social media against you to subvert authentication controls, do recon, and manipulate data. Great POC!
Friday, May 1, 2009
SSH Command Monitoring
This was an interesting post from the secureshell list. Thanks Richard!
Hi "J",
you can do that with your unix/linux onboard tools. just attach strace
to the sshd process of the user you want to monitor:
strace -s 4096 -e trace=read -p PROCESS_ID
than have a look for the shell prompt (e.g.):
read(10, "\33]0;USERNAME@HOSTNAME:~\7"..., 16384) = 22
now you know that the FD (file handle) is 10 for the users ssh session terminal.
then you can do something like that:
strace -s 4096 -e trace=read -p 10417 2>&1 | grep -E '^read\(10,' |
grep -oE '".+"'
and you should get an output like:
"uname -a"
"\r\n"
"Linux HOSTNAME 2.6.29.1 #1 SMP Sat Apr 18 11:22:05 CEST 2009 i686
Intel(R) Core(TM)2 Duo CPU L7500 @ 1.60GHz GenuineIntel GNU/Linux\r\n"
"\33]0;USERNAME@HOSTNAME:~\7"
well, this will only work if you have root permission on the server
running sshd.
have fun,
richard
Hi "J",
you can do that with your unix/linux onboard tools. just attach strace
to the sshd process of the user you want to monitor:
strace -s 4096 -e trace=read -p PROCESS_ID
than have a look for the shell prompt (e.g.):
read(10, "\33]0;USERNAME@HOSTNAME:~\7".
now you know that the FD (file handle) is 10 for the users ssh session terminal.
then you can do something like that:
strace -s 4096 -e trace=read -p 10417 2>&1 | grep -E '^read\(10,' |
grep -oE '".+"'
and you should get an output like:
"uname -a"
"\r\n"
"Linux HOSTNAME 2.6.29.1 #1 SMP Sat Apr 18 11:22:05 CEST 2009 i686
Intel(R) Core(TM)2 Duo CPU L7500 @ 1.60GHz GenuineIntel GNU/Linux\r\n"
"\33]0;USERNAME@HOSTNAME:~\7"
well, this will only work if you have root permission on the server
running sshd.
have fun,
richard
Saturday, April 18, 2009
Open Source Security Information Manager - OSSIM
I've been playing with OSSIM (http://www.ossim.net) for the last week. The stand-alone installation from AlienVault was trivially easy, thanks guys! I was able to install a main 'trusted net' stand-alone and integrate a DMZ sub-sensor in an hour. The dashboard is pretty, with many reporting features and does a decent job of aggregating the infeed of data from the wide collection of tools it provides.
But...
Having put this Unified Threat Management (http://en.wikipedia.org/wiki/Unified_Threat_Management) device on the network, I find it to be the least secure thing out there. While AlienVault did an excellent job of bringing all of these wonderful security monitoring tools together, having the production interface on the main network acting as both collector, sensor, and admin access is a bad idea. It also uses so many products and services that it is terribly insecure itself. Having the main sensor in the trusted network isn't too bad for this, but having one of these in the more exposed DMZ makes me wary. OSSIM needs a lot of custom configuration to implement restricted access, split the collection interface to a promiscuous-only and have a separate admin interface. This can be done with taps to ensure only one-way traffic occurs, but that still leaves the service open to injection if one were to expect the box to be there. In all, the UTM sensor-with-everything idea needs to be rethought.
It's been fun to play with, but ultimately I'm going to explore running with some functionalized implementations that might prove more secure.
But...
Having put this Unified Threat Management (http://en.wikipedia.org/wiki/Unified_Threat_Management) device on the network, I find it to be the least secure thing out there. While AlienVault did an excellent job of bringing all of these wonderful security monitoring tools together, having the production interface on the main network acting as both collector, sensor, and admin access is a bad idea. It also uses so many products and services that it is terribly insecure itself. Having the main sensor in the trusted network isn't too bad for this, but having one of these in the more exposed DMZ makes me wary. OSSIM needs a lot of custom configuration to implement restricted access, split the collection interface to a promiscuous-only and have a separate admin interface. This can be done with taps to ensure only one-way traffic occurs, but that still leaves the service open to injection if one were to expect the box to be there. In all, the UTM sensor-with-everything idea needs to be rethought.
It's been fun to play with, but ultimately I'm going to explore running with some functionalized implementations that might prove more secure.
Tuesday, March 3, 2009
Suggestions for Security Training
I respond to questions from time to time about a recommend security training pipeline for SOC operators at all levels. Here is the general recommendation I've developed.
(Jr Sec Analyst) Year 1 goals
- Security +
- GCIH
(Sr Sec Analyst) Year 2 goals
- begin CISSP study (reading, not a bootcamp yet)
- GCFA if doing investigations
- or GCIA if focused more on network management of IPS
(Sec Engineer/ Sr Sec Analyst, Principal) Year 3 goals
- CISSP course and testing
- GREM if moving toward malware investigation
- OR GPEN if moving toward software assurance (recommend GCIA prereq)
- begin local research projects and security defense-in-depth expansion through pilots
(Sec Architect) Year 4 goals
- CISSP/ISSEP certification
- additional SANS courses
- demonstrated local research and expansion projects
I choose to emphasize the CISSP over other equivalent certifications (CISA/CISM) becuase of its better ROI in the DOD8570.01M requirements structure. Any employee you are going to have in government service that you plan to invest in for more than a year, you should pursue this certification to maintain compliance and competitiveness. Not that it gets you knowledge without having equivalent experience, but it's a marker you have to have.
I have also chosen to emphasize SANS training as they are considered an industry gold-standard, are vendor neutral, and teach underlying concepts in addition to applied practices. Their courses are not a college degree or an 'academic' environment, but it is good training for directly applicable skills.
I think Rob Fuller has an interesting perspective at his Room362 blog entry on security credentials.
(Jr Sec Analyst) Year 1 goals
- Security +
- GCIH
(Sr Sec Analyst) Year 2 goals
- begin CISSP study (reading, not a bootcamp yet)
- GCFA if doing investigations
- or GCIA if focused more on network management of IPS
(Sec Engineer/ Sr Sec Analyst, Principal) Year 3 goals
- CISSP course and testing
- GREM if moving toward malware investigation
- OR GPEN if moving toward software assurance (recommend GCIA prereq)
- begin local research projects and security defense-in-depth expansion through pilots
(Sec Architect) Year 4 goals
- CISSP/ISSEP certification
- additional SANS courses
- demonstrated local research and expansion projects
I choose to emphasize the CISSP over other equivalent certifications (CISA/CISM) becuase of its better ROI in the DOD8570.01M requirements structure. Any employee you are going to have in government service that you plan to invest in for more than a year, you should pursue this certification to maintain compliance and competitiveness. Not that it gets you knowledge without having equivalent experience, but it's a marker you have to have.
I have also chosen to emphasize SANS training as they are considered an industry gold-standard, are vendor neutral, and teach underlying concepts in addition to applied practices. Their courses are not a college degree or an 'academic' environment, but it is good training for directly applicable skills.
I think Rob Fuller has an interesting perspective at his Room362 blog entry on security credentials.
Wednesday, February 25, 2009
Deobfuscating the Adobe 0-day
The folloiwng is a quick writeup of an analysis started on a PDF sample for the Adobe7/9 0-day. The exploit starts with an overflow, then attempts to run the javascript to drop a file c:/adobe.exe and execute it.
hexdump -C file.pdf > HEXDUMP_file.pdf.txt
less HEXDUMP_file.pdf.txt
[find the javascript near the end]
0x80301 - 525057 start of javascript exploit
0x821c8 - 532936 end of javascript exploit
=======
7879 - difference in decimal
Carve the javascript out.
dd if=file.pdf of=file.pdf.js.carve bs=1 skip=525086 count=7849
Add some stubs to cover for lack of spidermonkey functions. Not quite there, but gives the idea.
function document(){
this.write=printit;
}
var document=new document();
function address(){
this.length=0;
this.substring="";
}
var address=new address();
function nop(){
this.substring="";
}
var nop=new nop();
function jmp(){
this.length=0;
}
var jmp=new jmp();
function pointers(){
this.length=0;
this.substring="";
}
var pointers=new pointers();
function pointers1(){
this.length=0;
}
var pointers1=new pointers1();
Run and see if it prints the deobfuscated output.
./js 1.js
bt collectedfiles # ../scripts/js.sh 1.js
var address = unescape(r)
var jmp = unescape(r)
var nop = unescape(r)
var nop1 = unescape(r)
var shellcode = unescape(r)
1.js:84: TypeError: nop.substring is not a function
Only a few lines before a function missing. No luck this time, but its close. Keep playing.
hexdump -C file.pdf > HEXDUMP_file.pdf.txt
less HEXDUMP_file.pdf.txt
[find the javascript near the end]
0x80301 - 525057 start of javascript exploit
0x821c8 - 532936 end of javascript exploit
=======
7879 - difference in decimal
Carve the javascript out.
dd if=file.pdf of=file.pdf.js.carve bs=1 skip=525086 count=7849
Add some stubs to cover for lack of spidermonkey functions. Not quite there, but gives the idea.
function document(){
this.write=printit;
}
var document=new document();
function address(){
this.length=0;
this.substring="";
}
var address=new address();
function nop(){
this.substring="";
}
var nop=new nop();
function jmp(){
this.length=0;
}
var jmp=new jmp();
function pointers(){
this.length=0;
this.substring="";
}
var pointers=new pointers();
function pointers1(){
this.length=0;
}
var pointers1=new pointers1();
Run and see if it prints the deobfuscated output.
./js 1.js
bt collectedfiles # ../scripts/js.sh 1.js
var address = unescape(r)
var jmp = unescape(r)
var nop = unescape(r)
var nop1 = unescape(r)
var shellcode = unescape(r)
1.js:84: TypeError: nop.substring is not a function
Only a few lines before a function missing. No luck this time, but its close. Keep playing.
Sunday, July 13, 2008
USB as a Threat Vector
Over the past weeks I have monitored several incidences per week of clients bringing in infected USB media and hard drives. It seems that the USB-aware malware is increasing and becoming a more common feature of Internet-delivered maladies. This allows the malware access to infect machines laterally within an organization, as well as directly from the Internet.
Wednesday, July 2, 2008
Script to identify domains and IP addresses by ASN and CC
I wrote this more than a year ago and it has been tested pretty well. Figured since Jim over at ISC has released a similar tool, it's time to publish mine.
Usage:
# cat > queries.txt
domain1
domain2
ip3
domain4
ip5
...
^C
# perl finger.pl queries.txt
###### finger.pl ######
#This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 171 Second Street, Suite 300, San Francisco, California, 94105, USA.
if (-e "$ARGV[0]") {
open (IFILE, "$ARGV[0]");
while () {
chomp;
undef $ipaddr; undef @whois_results; undef @resolve_results; undef $domainname; undef $a; undef @results; undef @resultr;
if (/^\s*$/) {
next;
} elsif (/^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
$ipaddr = $_;
@whois_results = &whois($ipaddr);
foreach $a (@whois_results) {
print "$a\n";
}
} elsif (/.+?\...?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif (/.+?\....?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif (/.+?\.....?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} else { print "BAD INPUT LINE: $_\n"; }
}
} elsif ($ARGV[0] =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
$ipaddr = $ARGV[0];
@whois_results = &resolve($ipaddr);
# @whois_results = &whois($ipaddr);
foreach $a (@whois_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\...?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\....?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\.....?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} else { print "BAD INPUT: $ARGV[0]\n"; }
sub resolve {
undef $domain; undef @answersr; undef $answerr; undef @reresolve; undef @resultr; undef $infor;
my $domain = shift;
if ($domain =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
my @answersr = `dig +short -x $domain`;
@resultr;
foreach my $answerr (@answersr) {
my @whois_resultr = &whois($domain);
foreach my $whois_answerr (@whois_resultr) {
if ($answerr =~ /^\s*$/) {
$infor = join(' | ', "NO RDNS", $whois_answerr);
} else {
$infor = join(' | ', substr($answerr,0,$answerr-1), $whois_answerr);
}
@resultr = (@resultr,$infor);
}
}
return @resultr;
# } elsif ($domain =~ /.+?\.....?\.?$/) {
} else {
my @answersr = `dig +short $domain`;
chomp(@answersr);
@resultr;
foreach my $answerr (@answersr) {
if ($answerr =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
my @whois_resultr = &whois($answerr);
foreach my $whois_answerr (@whois_resultr) {
$infor = join(' | ', $domain, $whois_answerr);
@resultr = (@resultr,$infor);
}
# } elsif ($answerr =~ /.+?\.....?\.$/) {
} else {
my @reresolve = &resolve(substr($answerr,0,$answerr-1));
foreach $reresolve (@reresolve) {
@resultr = (@resultr,$reresolve);
}
# } else { print "COULD NOT RESOLVE: $domain\n"; }
}
}
return @resultr;
# } else {
# print "BAD DOMAIN: $domain\n";
# return("$domain \| UNKNOWN");
}
}
sub whois {
undef $octet1; undef $octet2; undef $octet3; undef $octet4;
undef @answers; undef @results;
my $ip = shift;
if ($ip =~ /^(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})$/) {
my $octet1 = $1;
my $octet2 = $2;
my $octet3 = $3;
my $octet4 = $4;
# Perform the IP WHOIS lookup and parse the result
my @answers = `dig +short -t TXT $octet4\.$octet3\.$octet2\.$octet1\.origin\.asn\.cymru\.com`;
chomp(@answers);
foreach my $answer (@answers) {
undef @afields;
undef $ip_as; undef $ip_netblock; undef $ip_cc; undef $ip_as_source; undef $ip_as_date;
undef $as_num; undef $as_cc; undef $as_source; undef $as_date; undef $as_desc;
undef $info;
$answer =~ s/\t//g;
$answer =~ s/\"//g;
$answer =~ s/\s\|\s/\|/g;
my @afields = (split/\|/,$answer);
my $ip_as = $afields[0];
my $ip_netblock = $afields[1];
my $ip_cc = $afields[2];
my $ip_as_source = $afields[3];
my $ip_as_date = $afields[4];
# Perform the AS WHOIS lookup and parse the result
$answer = `dig +short -t TXT AS$ip_as\.asn\.cymru\.com`;
chomp($answer);
$answer =~ s/\t//g;
$answer =~ s/\"//g;
$answer =~ s/\s\|\s/\|/g;
my @afields = (split/\|/,$answer);
my $as_num = $afields[0];
my $as_cc = $afields[1];
my $as_source = $afields[2];
my $as_date = $afields[3];
my $as_desc = $afields[4];
my $info = join(' | ',sprintf("%15.15s",$ip),sprintf("%18.18s",$ip_netblock),sprintf("%2.2s",$ip_cc),sprintf("%5.5s",$ip_as),$as_desc);
@results = (@results,$info);
}
return(@results);
} else {
print "BAD IP ADDRESS: $ip\n";
return("$ip \| UNKNOWN");
}
}
Usage:
# cat > queries.txt
domain1
domain2
ip3
domain4
ip5
...
^C
# perl finger.pl queries.txt
###### finger.pl ######
#This work is licensed under the Creative Commons Attribution-Share Alike 3.0 United States License. To view a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/us/ or send a letter to Creative Commons, 171 Second Street, Suite 300, San Francisco, California, 94105, USA.
if (-e "$ARGV[0]") {
open (IFILE, "$ARGV[0]");
while (
chomp;
undef $ipaddr; undef @whois_results; undef @resolve_results; undef $domainname; undef $a; undef @results; undef @resultr;
if (/^\s*$/) {
next;
} elsif (/^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
$ipaddr = $_;
@whois_results = &whois($ipaddr);
foreach $a (@whois_results) {
print "$a\n";
}
} elsif (/.+?\...?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif (/.+?\....?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif (/.+?\.....?$/) {
$domainname = $_;
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} else { print "BAD INPUT LINE: $_\n"; }
}
} elsif ($ARGV[0] =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
$ipaddr = $ARGV[0];
@whois_results = &resolve($ipaddr);
# @whois_results = &whois($ipaddr);
foreach $a (@whois_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\...?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\....?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} elsif ($ARGV[0] =~ /.+?\.....?$/) {
$domainname = $ARGV[0];
@resolve_results = &resolve($domainname);
foreach $a (@resolve_results) {
print "$a\n";
}
} else { print "BAD INPUT: $ARGV[0]\n"; }
sub resolve {
undef $domain; undef @answersr; undef $answerr; undef @reresolve; undef @resultr; undef $infor;
my $domain = shift;
if ($domain =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
my @answersr = `dig +short -x $domain`;
@resultr;
foreach my $answerr (@answersr) {
my @whois_resultr = &whois($domain);
foreach my $whois_answerr (@whois_resultr) {
if ($answerr =~ /^\s*$/) {
$infor = join(' | ', "NO RDNS", $whois_answerr);
} else {
$infor = join(' | ', substr($answerr,0,$answerr-1), $whois_answerr);
}
@resultr = (@resultr,$infor);
}
}
return @resultr;
# } elsif ($domain =~ /.+?\.....?\.?$/) {
} else {
my @answersr = `dig +short $domain`;
chomp(@answersr);
@resultr;
foreach my $answerr (@answersr) {
if ($answerr =~ /^\s*(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})\s*$/) {
my @whois_resultr = &whois($answerr);
foreach my $whois_answerr (@whois_resultr) {
$infor = join(' | ', $domain, $whois_answerr);
@resultr = (@resultr,$infor);
}
# } elsif ($answerr =~ /.+?\.....?\.$/) {
} else {
my @reresolve = &resolve(substr($answerr,0,$answerr-1));
foreach $reresolve (@reresolve) {
@resultr = (@resultr,$reresolve);
}
# } else { print "COULD NOT RESOLVE: $domain\n"; }
}
}
return @resultr;
# } else {
# print "BAD DOMAIN: $domain\n";
# return("$domain \| UNKNOWN");
}
}
sub whois {
undef $octet1; undef $octet2; undef $octet3; undef $octet4;
undef @answers; undef @results;
my $ip = shift;
if ($ip =~ /^(\d{1,3})\.(\d{1,3})\.(\d{1,3})\.(\d{1,3})$/) {
my $octet1 = $1;
my $octet2 = $2;
my $octet3 = $3;
my $octet4 = $4;
# Perform the IP WHOIS lookup and parse the result
my @answers = `dig +short -t TXT $octet4\.$octet3\.$octet2\.$octet1\.origin\.asn\.cymru\.com`;
chomp(@answers);
foreach my $answer (@answers) {
undef @afields;
undef $ip_as; undef $ip_netblock; undef $ip_cc; undef $ip_as_source; undef $ip_as_date;
undef $as_num; undef $as_cc; undef $as_source; undef $as_date; undef $as_desc;
undef $info;
$answer =~ s/\t//g;
$answer =~ s/\"//g;
$answer =~ s/\s\|\s/\|/g;
my @afields = (split/\|/,$answer);
my $ip_as = $afields[0];
my $ip_netblock = $afields[1];
my $ip_cc = $afields[2];
my $ip_as_source = $afields[3];
my $ip_as_date = $afields[4];
# Perform the AS WHOIS lookup and parse the result
$answer = `dig +short -t TXT AS$ip_as\.asn\.cymru\.com`;
chomp($answer);
$answer =~ s/\t//g;
$answer =~ s/\"//g;
$answer =~ s/\s\|\s/\|/g;
my @afields = (split/\|/,$answer);
my $as_num = $afields[0];
my $as_cc = $afields[1];
my $as_source = $afields[2];
my $as_date = $afields[3];
my $as_desc = $afields[4];
my $info = join(' | ',sprintf("%15.15s",$ip),sprintf("%18.18s",$ip_netblock),sprintf("%2.2s",$ip_cc),sprintf("%5.5s",$ip_as),$as_desc);
@results = (@results,$info);
}
return(@results);
} else {
print "BAD IP ADDRESS: $ip\n";
return("$ip \| UNKNOWN");
}
}
Subscribe to:
Posts (Atom)