Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Tuesday, 16 June 2015

Null Singapore Security Meetup - June



Null Singapore is back for the fifth time and like last month, it was a full house and another record of an attendance! Credits given to NSHC Pte Ltd for providing us a room for us to have our meetup.





We start our meetup by introducing ourselves, what Null Singapore is all about, its aims, its objectives and how does this meetup benefit the audience from networking to potential cooperation with one another. This was presented by Prasanna or PK as Imran, the chapter leader was away.



Randen then presented on the security news bytes, the security events that happened in the last few weeks ranging from malware, phishing and critical infrastructures.



Michael Heinzl, from SEC Consult presented on the topic 'Finding vulnerabilities using Fuzzing'. It was an interesting topic as he demonstrates how fuzzing assist in the finding of unknown vulnerabilities and how such vulnerabilities could be turn into an exploit to further penetrate into the systems/applications. Sharing statistics of his research and end with a cool demo, Michael was able to show the audience not just in a theoretical sense but in a practical way as well.



Vincent Tan, from Vantage Point presented on the topic 'Breaking BYOD in IOS'. This was an extremely interesting talk as he shares his research and how IOS can be broken into with tools that he developed. I would not dive into the contents of his presentations (as agreed), but i'd say the delivery of the presentations, the demonstrations and the key takeaways are properly formatted and presented.



Both presenters ended with a round of applause and it was really great to see people enjoying the presentations and coming up to the speakers to know more about it. Alas, after it was all over, the 'after scene' networking session starts. I see people from different companies shaking each other's hands, getting to know each other despite the 'competition'. This is exactly what security meetups are all about... in conferences, we are never competitors...we are all enthusiasts...






Join us and get informed:

Sunday, 23 March 2014

Cyber Security - Passion vs Training

Recently i went to a cyber security seminar in Singapore where the target audience were from the financial industry. During one of the Q&A sessions, one of the audience asked a speaker how did he get into this (security) field and what is important for a cyber security professional to have to ensure that the person is right for the job. He replied that while the technicalities of products, tools and techniques are important, they can easily be trained.

I do not quite agree with the reply as the answer seems to assume anyone can be trained easily to become a knowledgeable cyber security professional. From what i've been through and seen, training is just a small part of being a well equipped security professional. Unlike some other professions, cyber security is a faculty where continuous learning is essential, needed and mandatory. Those who believed that having a qualification or certification certifies themselves as a security guru is actually making themselves fall into a well of delusion. The security risks, cyber attacks, viruses and trojans, processes and even methodologies are constantly changing over time. Those who fail to follow or fail to educate themselves with the latest security news or trends will be left out of the playing field.

Training is important but without passion in the field, then one can only hope you are prepared for the attacks that you are not trained to handle. Let's ask ourselves. Why the bad guys are winning? And why are they still winning despite having many security professionals in the organization trained to subdue or to protect from the bad guys? Take a recent example of a hacking incident where the website of EC-Council, the organization that provide Ethical Hacking training and certifications was hacked and defaced. Some even called it 'Hacking the Ethical Hackers'. And if we look at the profiles of these bad guys, hackers, script kiddies, black hats or whatever we decide to call, some were college students, some were jobless, some were not even working in the IT industry let alone being sent for expensive professional training yet they were and are still able to successfully hack and attack critical infrastructures of well known organizations. So the question is why even being professionally trained, do we still fail?

Passion. Merriam Webster defined it as 'a strong feeling of enthusiasm or excitement for something or about doing something'. If we learned one thing about these hackers, they are passionate about hacking. With such a strong sense of passion, comes the dedication they put into in training themselves to attack and educating themselves with the latest attacking tools and techniques from free courses/manuals online (God bless the Internet). If one thing that majority of the security professionals are lacking is this: PASSION.

Recently, my department head interviewed a candidate for a position to work with the ethical hacking team. The candidate had a degree and a CEH (Certified Ethical Hacker) certification but what initially seemed to be a prospect eventually was not. The reason shared was simple. The candidate did not seemed to know what's going on in the cyber security world for the past 5 years and basic penetration testing question couldn't be confidently answered let alone correct. Hence the reason why hiring a security professional is not as easy as simply by looking at the credentials.  


If we, the security professionals are as passionate as the bad guys out there, keep up with the latest news on cyber attacks, defense and protection technologies, then we may have a chance to level the playing field with the skillful hackers out there. 

Wednesday, 5 March 2014

Websense Security Seminar - A Presentation

So after our presentation at the ABS-FITA Cyber Security Seminar, we were invited to present our demo in another seminar organized by Websense.


It wasn't as big as the ABS-FITA seminar but it was still exciting nonetheless. The crowd was about 100-120 people from different backgrounds. It was great to see my brief bio on the speaker's website. 



Felt more confident this time round especially after the stressful pressure on the previous demo. Good thing was, we nailed it smoothly. Everything went smooth and we managed to put the 'WOW' look on some of the audience. After the demo, we were greeted by some of the audience who asked more about the capabilities of our team and pretty much the sales representatives from BT took over the conversation. 

Here are some of the photos taken by one of the attendees:

A Brief Bio

The Layout 

 The Finale

Bringing it all together

Notice the 'BT EHCOE' on Kali Wallpaper?

 Command and Commands


NEXT STOP: Presenting in DEFCON KERALA!!!!

Thursday, 12 December 2013

Cyber Security in Singapore - Opinions

Recently i was invited by a local radio station to give a talk about Cyber Security in Singapore but due to company and legal reason, i had to decline the opportunity. Nonetheless, these were the questions i was supposed to answer during the talk show.

1) Cyber security in Singapore - has the recent hacking episodes exposed a "weakness" in Singapore's cyber security?

I wouldnt call it a weakness but an eye opener as to what else could be done by potential skillful hackers. In one of the hacking movies back in the 80s called 'Wargames', David Lightman, the hacker stated that 'I dont believe that any systems is totally secure' when someone told him that it was impossible to gain access to the systems. Taking that quote, i believed that there is no way to say that a system, a server or a website is totally 100% secure. There will always bound to have a potential issue, potential backdoor, security misconfigurations, missing or outdated patches that can be taken advantage and exploited. Before the much talked hackings of government sites lately, back in 2011, 17 of our govt sites were defaced by a hacker group called Brazil Hack Team and fortunately, that was all they were able to do. The so called hacking of the Istana and PMO website were not really a hack. It was a client side exploitation of a vulnerability called XSS or Cross Site Scripting which do not affect the server side and still maintain the confidentiality, integrity and availability of the PMO's and Istana's website/server. In other words, nothing was leaked or compromised.


2) As an Ethical Hacker and Security Consultant, what do you think are the challenges in cyber security here, and worldwide?

One of the challenges that we faced not just in Singapore but also in other countries is investments in cyber security. Singapore, similarly like USA and Israel, we invested billions in physical military warfare but not much in the technology and manpower in cyber military. In my opinion, we should also invest not just the F-16s jets but also in technology and skills that could potentially bring down an F-16 jet by using a laptop. When i went to a security conference in Amsterdam, a hacker managed to show how he can potentially hack the control systems of an airplane. If we think that that is farfetched, in 2011, hackers from China managed to hack and control a NASA satellite for approximately 11minutes. Needless to say, when it comes to hacking, nothing is impossible.

Another thing is skillset. Before 2007, local instituitions, polytechnics and Universities do not have courses that involves Ethical hacking. These ethical hacking courses were mostly seen in private instituitions. In the US, schools are established for future and potential hackers. Hacker schools, hacking academy are created so that students are trained from young. In India for example, students are exposed to security at such a young age and you have people like Ankit Fadia, an Indian hacker who published a book on Ethical hacking at the age of 16. However, i am glad that the government understand the gravity of the importance of cyber security and since mid 2007 onwards, ethical hacking modules, courses are introduced in majority of the local institutions. The graduates from these faculties will be the ones who will safeguard our network and infrastructure.

The third thing is Security education and conferences. In Singapore there are not many security conferences that are open to public. There is one that holds annually here called Syscan and i believed that such a conference will benefit the security community here in Singapore. There are also other conferences such as GovWare but such government sponsored conferences are not open publicly and can be expensive at times. If we look at countries such as US, in Europe and even in Malaysia, there are a number of conferences held every year and are affordable and open to the public. Singapore must learn from such countries and organize more conferences open to public that can educate the public in security awareness and the importance of the roles they play in the organizations. Remember that security is a shared responsibility. 

3) Are companies here prepared to deal with cyber challenges? Why or why not?

As long as the company invests in cyber security, i believed that those companies are more or less prepared for potential cyber challenges. Whenever there's a hacking incident, security officers and management will question 3 important things: whether the Confidentiality, the Integrity and the Availability of the information got compromised. Therefore, even if the website got defaced at least the information or data are not compromised, stolen or leaked.
 
4) What have been your experiences in ethically "hacking" company sites? What more can be done?

One of the most important things before ethically hacking company sites or servers is to ensure we agreed on the rules of engagement, the DOs and the DONTs. Trust is a very important matter. Just imagine if we are able to compromise a credit card database,  this is where the word ethical comes into hacking. Such major findings will be alerted to the stakeholders and we will assist them through recommendations on how to remediate such findings. Security managers in organizations must also understand the difference between performing a vulnerability assessments and a penetration testing assessment. Both may sound similar but totally different when applied. 

Companies can additionally invest on security services that perform vulnerability assessments, risks analysis on a periodic basis instead of doing it just because they have to abide by their policies and audit requirements.