Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Tuesday, 2 December 2014

BSidesVienna - A Conference for the Cyber Geeks

Had the privileged to speak at BSidesVienna in Austria. When we reached there from Athens, we were excited and were pleasured by the cold breeze weather of the country. We stayed at the Intercontinental Wien and the conference, which was at Top Kino bar was located about 25mins away from the hotel.

Once we reached this cinema, we were greeted by the organizers, Chris, Olaf and other men in white. One awesome thing about BSides conferences is that they keep on to their tradition of providing free Tshirts! Hell, i waited no further to get myself one!

Despite two tracks in two different cinemas, i was pleased with the organization of the conference. Free drinks were provided in the bar and the cooling atmosphere simply gave me the addon pleasure of drinking hot chocolate! The couple serving at the bar were friendly.

Overall, the speakers had great topics to share. Some of the talks i enjoyed were the following:
1) The A, The P and the T by Marion Marschalek
2) Hijacking label switched networks in the cloud by Paul Coggin
3) Screw Compliance! Why security standards kill security! by Johannes Stillig

For my talk, i had abit of an issue both the words that came out of my mouth and the projector issues that was able to show only 70% of my slides. But i am glad that the audience understood and able to generate some giggles and laughter throughout my 40 mins presentation.

Overall, it was a great experience and since this was my first time speaking to an audience of European geeks, it will definitely be something i won't forget.

For more info: http://bsidesvienna.at/

Some of the pictures:



 


























Sunday, 23 March 2014

Cyber Security - Passion vs Training

Recently i went to a cyber security seminar in Singapore where the target audience were from the financial industry. During one of the Q&A sessions, one of the audience asked a speaker how did he get into this (security) field and what is important for a cyber security professional to have to ensure that the person is right for the job. He replied that while the technicalities of products, tools and techniques are important, they can easily be trained.

I do not quite agree with the reply as the answer seems to assume anyone can be trained easily to become a knowledgeable cyber security professional. From what i've been through and seen, training is just a small part of being a well equipped security professional. Unlike some other professions, cyber security is a faculty where continuous learning is essential, needed and mandatory. Those who believed that having a qualification or certification certifies themselves as a security guru is actually making themselves fall into a well of delusion. The security risks, cyber attacks, viruses and trojans, processes and even methodologies are constantly changing over time. Those who fail to follow or fail to educate themselves with the latest security news or trends will be left out of the playing field.

Training is important but without passion in the field, then one can only hope you are prepared for the attacks that you are not trained to handle. Let's ask ourselves. Why the bad guys are winning? And why are they still winning despite having many security professionals in the organization trained to subdue or to protect from the bad guys? Take a recent example of a hacking incident where the website of EC-Council, the organization that provide Ethical Hacking training and certifications was hacked and defaced. Some even called it 'Hacking the Ethical Hackers'. And if we look at the profiles of these bad guys, hackers, script kiddies, black hats or whatever we decide to call, some were college students, some were jobless, some were not even working in the IT industry let alone being sent for expensive professional training yet they were and are still able to successfully hack and attack critical infrastructures of well known organizations. So the question is why even being professionally trained, do we still fail?

Passion. Merriam Webster defined it as 'a strong feeling of enthusiasm or excitement for something or about doing something'. If we learned one thing about these hackers, they are passionate about hacking. With such a strong sense of passion, comes the dedication they put into in training themselves to attack and educating themselves with the latest attacking tools and techniques from free courses/manuals online (God bless the Internet). If one thing that majority of the security professionals are lacking is this: PASSION.

Recently, my department head interviewed a candidate for a position to work with the ethical hacking team. The candidate had a degree and a CEH (Certified Ethical Hacker) certification but what initially seemed to be a prospect eventually was not. The reason shared was simple. The candidate did not seemed to know what's going on in the cyber security world for the past 5 years and basic penetration testing question couldn't be confidently answered let alone correct. Hence the reason why hiring a security professional is not as easy as simply by looking at the credentials.  


If we, the security professionals are as passionate as the bad guys out there, keep up with the latest news on cyber attacks, defense and protection technologies, then we may have a chance to level the playing field with the skillful hackers out there. 

Friday, 3 January 2014

Like Dominoes they Fall One by One

Recently i received an email from my wife asking to help her as she was having financial problem in Norway. The moment i saw that, i knew it was a Spam. However, when i looked closer, i realized that when i clicked 'Reply', it was addressed to my wife's yahoo email address. I took a snapshot and sent it to my wife and informed her to quickly change her password. That's when my wife told me that she couldnt log in to her email account. Something was fishy.

The next thing i know, people started calling and messaging her on Facebook. According to the private messages, she was asking people in her friendlist for help and money. She got bombarded with calls of concern. To make matters worse, she could not log in to her Facebook as well as her Hotmail account.

30 minutes later, we realized that she was hacked! And she was not the only one. Over the last few weeks, i received news on my newsfeed how my other friends got their email accounts hacked and unable to log in as well. 

Thus, i went into a hunt for the hacker... (but this will be another story to post)

So i asked her whether her passwords were the same as the other accounts to which she replied No. All her 3 accounts have 3 different set of passwords which is a good thing. Then i asked her about the complexity of her passwords. With that i know why. 

Surprising Find

I went on a recon to find other victims to which the accounts were hacked. To my shocking surprise, i saw THOUSANDS of Yahoo, Hotmail, Gmail, Facebook accounts with passwords leaked out in the deep web! And they all have one thing in common: simple passwords! 

These are some of the accounts that was leaked.


I looked closely at the passwords combination used and i could tell that these passwords are easily guessed, simple combinations of alphabets and numbers. This is what we in the security community as WEAK passwords. 

10 years ago, a complex password would be at least 8 characters with a combination of alphabets and numbers. At that time, the technology for password cracking isn't as awesome and as fast as now hence the previous requirements was sufficient. But now, 8 characters is easily cracked especially when it is not complex enough. Another mistake that most of us make is using the same password for all other accounts. Thus it is not surprise when one account is hacked after another by using a single password. 

How Did the Hackers Hacked Then?

There are many ways a hacker could hack into our accounts. One of the ways i know is by collecting email addresses gathered by automatic scavengers tool and save it into a database. Once all these email addresses are collected, the hacker will run a cracker against a huge dictionary file or by other sophisticated crackers. All the hacker needs to do is to play the waiting game. Once the accounts are hacked, the hacker will publish it online, in forums and if they want to make a profit out of it, sell them to potential buyers and scammers. These scammers will then use the compromised account and start their phishing emails to the contacts in the email's address books. 

So How Can we Prevent this?

1. Use at least 16 characters long! Remember, the longer the better!
2. Raise the complexity of the passwords by using words that only YOU will know and not from the dictionary.
3. Use Uppercase and Lowercase alphabets
4. Use numbers
5. Use special characters such as &^%
6. Use different password for each account
7. Do not login to sites from public Wifi networks or LAN 
8. Do not provide your passwords from emails asking you to provide.
9. Provide contact number to the account for password reset. This is very important and a secure way to do password reset as only YOU would have your mobile phone/number and not the one in Nigeria.

A good example of a password is : UzuM@k!@P0C@l%p$3



Saturday, 21 December 2013

Saturday, 7 December 2013

Royal Bank of Scotland - When Modern Hackers meet Outdated Bankers

"As he apologised, RBS boss Ross McEwan admitted the bank had failed to invest in IT systems for decades."



This is one of the reasons why systems in organizations easily failed and get compromised. The failure to invest in IT systems is not just a problem for Ross McEwan but also with other CEOs or bosses. Many simply sees it as something troublesome and still adopting the idea that 'If nothing is wrong with it, why change?'. While it may be true depending on how one applies that theory, in this new generation of increasing threats and cyber criminals, that idea must no longer be practiced. 

Cyber threats are always increasing no matter how secure we think we are. One of the ways to counter these threats is to periodically upgrade and update the systems and servers in the organizations. Bankers should not just focus on the physical aspects of security such as advance money safes, patrolling guards be it human or electronic, security cameras and etc but also the IT aspects of it. This may be in the forms of management of patches, upgrading of OS to the latest available, performing periodic system security assessments and audits and complying to security standards. 

I have seen big companies still using unsupported versions of operating systems such as Windows XP. I have seen how critical services using Windows platform to serve as its host. I have seen how huge organizations still using the likes of Windows 2000 despite its now the year 2013. Of course one of the reasons why bosses do not want to change it is because of the amount of work and money to be invested in. Questions like will it support their current software, will there be an issue upgrading from this to that, will the migration be a painful process and some raise concerns such as whether hiring vendors to support in the migration, can they be trusted, how can they guarantee whether or not their data will not be leaked by these external parties.

The answer is not as easy as one might think but this is where trust comes into play. Agreement documents such as the NDA (Non Disclosure Agreement) and many legal aspects of it will play a part in the human-relationship aspects of it. Bosses should not take advantage of their current security posture into thinking "Why should i change when we have not been compromised before?"... that thinking will definitely be the beginning of the downfall and potential cyber criminals may eventually take advantage of that. Bosses should now think that they would rather 'waste' their money securing and upgrading their systems rather than millions of money being stolen and worse, customers impacted by it will switch banks because of such incidents leaving the affected bank/s into a dilemma situation and meltdown.

Money is no longer just a physical thing. Transactions are frequently made in Ones and Zeros in the digital world and financial organizations responsible in guarding these money should not just ensure that their physical safe is secured but also ensure that the electronic aspects of it are digitally secured as well. 

To quote Richard A. Clarke, the author of Cyber War - “If you spend more on coffee than on IT security, you will be hacked. What’s more, you deserve to be hacked."

Friday, 6 December 2013

Standard Chartered 'Hacked'

Hack, Evidence, Prosecution, Processes, Trust and Moving on.....



In a recent incident involving James Raj allegedly known as The Messiah, Standard Chartered client statements were found on James Raj's laptop. This quickly escalated to the readers on the journey to hate the Anonymous group that James Raj was supposedly part of. 

While we have no visibility as to how the data got into James Raj laptop, one thing i would questioned is the evidence gathered. It is not just simply about blaming him since the data was on his laptop. Investigators must find evidence that can illustrate that it was indeed James Raj who stole the information. This must be in the form of logs from both the laptop and Fuji Xerox. A company like Fuji Xerox would surely have all the log gatherings and management in place and investigators must ensure that the log tallies confirming that there was indeed a network connection being made from James Raj IP address to the Fuji Xerox's server. 

Cyber forensic investigators must also be able to retrieve the logs from the laptop to confirm that his laptop was not just being used but to confirm that there were no other connections made from other sources connecting to James Raj's machine and used it as a proxy to attack FX. Timing of connections made must be in sync. Metadata of logs should not be tampered (especially by amateurs evidence handlers)

Below is a high level graphical example as how James Raj's machine could be used in the stealing of data.



How could this be possible?

During #OpTunisia, there were alot of protests against the Tunisian government. This led to outsiders wanting to take part as well. As they were outside of Tunisia, they relied on the internet to voice out their unhappiness against the Tunisian government. Government websites were hacked and defaced (no information was stolen) by hackers. The Tunisian government fought back by blocking all connections outside of Tunisia to connect to the government websites. A hacker known as Sabu managed to find a Tunisian citizen machine to use as a proxy to connect to the government website. All he had to do was to connect to that machine as a proxy and attack the Tunisian government website from that machine. Reports stated that due to little pool of experts in handling such incidents, the owner of that machine was arrested and left the hacker free.  

Source: From the Book 'We are Anonymous' by Parmy Olson. Page 143 - 146

Lesson that we can Learn

Skillful hackers do not connect and hack directly to the target from their own machines but that does not mean that n00b hackers do not know how to hide their tracks as well. Investigators will need to identify the logs properly and securely and ensure that in no way the evidence are tampered during the course of investigation. These logs must be in both the machine and the server to ensure that the evidence that connections made are true and in sync. If logs or files are suspected to be deleted,  investigators should clone the entire image of the hard disk, use a data recovery tool and identify the evidence from there. The operating system itself should be checked whether ports such as telnet and other shell like services or vulnerabilities were opened/present. This could be another evidence to suggest that James Raj's laptop were already vulnerable to have other machines connecting to his laptop possibly using his machine to leverage on the attack. Until all these are gathered, only then will the public be confident of the methodologies, processes and techniques used during the gathering of the evidence and cover all possible factors of external party using Raj's machine as a proxy to attack.

Recent News may give Govt a Hard Time

Recent news about a government chemist in the States who was found guilty on tampering with evidence which resulted in many innocents going to jail will definitely be running in many minds questioning about the genuinity of the evidence and prosecution of James Raj should James Raj be found guilty of the charges made against him.




Moving Forward

In order for organizations and companies to know whether they are ready for such an attack is to perform vulnerability assessments on their network and servers. Only then will they know how they can fare against a potential attack. One of the mistakes made by organizations is trusting their own security department on handling such assessments but as they always say, its better to have a new pair of eyes to see what their own internal team may be blinded to (similarly like doing an audit). Hire ethical hackers/pentesters to simulate a real world attack on your servers and networks and see how deep they could penetrate into. Of course, rules of engagements and non disclosure agreement must be made to maintain confidentiality and integrity of the assessment with both parties involved. 

Thursday, 14 November 2013

When it comes to Security - Nothing is Impossible

In 1995, the movie ‘Hackers’ premiered, and the feedback was unanimous: “Exaggerated! How on earth was that even possible?!”

Almost ten years on, and these ‘exaggerated’ ideas have become a reality. The film features a virus called ‘Da Vinci’ — a remote-controlled virus set to sink a fleet of oil tankers from afar. Exaggerated, right? Well, at this year’s Hack in the Box security conference, we learnt that the possibility of a virus hijacking an airline was not that far off.



An earlier film, ‘War Games’, sees Matthew Broderick playing a small-time hacker whose initial objective was simply to play games, but ends up hacking into the US Government’s mainframe. When challenged by his peers about the complexity of a system he has gained access to, he replies, “Hey, I don’t think any system is totally secure.”






This quote from a 1983 movie is still worryingly relevant in today’s society. Millions are spent on devising complex and diverse security architectures, but with every security advance, there are more determined and more specialised hackers attempting to break into the systems.

In today’s society, it takes a lot more than computer competence to become a hacker. Kevin Mitnick, one of the world’s best-known hackers and, at one time, America’s most wanted computer criminal, used simple social skills to overcome and bypass some of the most highly-secured facilities. Mitnick helped coin the term ‘social engineering’; using deception and emotional manipulation to gain access to otherwise impenetrable systems. As Bruce Schneier once said, “Amateurs hack systems. Professionals hack people.”



Electronic communications via email, chat applications, SMS, phone calls, or VoIP can all be broken down into zeros and ones. These days, communication means data, and data can mean information, which then leads to value. Controlling information means controlling the situation. Between 2007 and 2008, Chinese hackers were able to hack and control two US satellites for a total of 11 minutes, intercepting information transmitted between the satellite and NASA. Whoever gained access to the data chose not to do anything with it, but it became a landmark in highlighting issues of cyber security.


The new generation of hackers no longer just hack to disrupt services and infrastructure. They hack to take control of information and data. In the modern age of technology, the value of your data inside your flash drive could be one of the most valuable things in your arsenal.

The things that we have now, the systems we are using, the mobile phones we carry are the result of hacks that were done during the computer revolution back in the 70s. The technologies that you and I have at hand are partially the result of those people who broke the law to modify, create and innovate.

The gift of hindsight has allowed us to see the technological pathways that computer hacking has forged. Where once, hacking possibilities were at the hands of film directors and novelists, they now lie in the hands of anyone with imagination.

As industry leaders in communication, it is our job to have an awareness of the potential risks and pitfalls that hacking can create. By keeping an open mind to hackers and technological creativity, we can ensure that we are able to defend and foresee any threat in the digital world. As Einstein once said, “Imagination is sometimes better than knowledge.”


This article was also posted at http://tinyurl.com/m38xj2e

Friday, 18 October 2013

HITB (Hack In The Box) Security Conference in KL 2013

Went to the Hack in the Box Security Conference held in Kuala Lumpur on the 16th -17th October 2013. Hosted in Intercontinental KL hotel, the conference was great. This is my third time in three years attending this conference and i have grown to love them. The tracks were good, the booths were awesome, the competitions such as Catch the Flag and HackWeekday were superb. Check out some of the photos of the conference.

Good Points: I will not deny that the topics of the presentations were great. They covered almost every aspects of hacking but focuses more on in depth hackings such as:
> OS/Software
> Exploitation
> Hardware

Some of the cool talks presented were the Facebook Hacking, Aviation Hacking and both Keynotes. For the HITB crew, i have to compliment them all the way. They were very friendly and approachable willing to assist and help anytime when approached. The food was superb and a 5 star class! I cant complain anything at all about the food and no one had to stand to eat (like some of the other conference i've been). The theme of the CTF was also eye catching! 'War of the Worlds: WMD'!! I mean like, seriously?!!! Even if i participated and didnt win, i still would feel good bragging to my friends that i participated in such a cool theme CTF event! The HackWeekday or should i say coding of applications competitions were superb and it had a number of categories giving each competitors to join in their respective specialized field. I've participated in several CTF competition but have yet to join one in HITB, and maybe one day i shall join. However i do like to put it out there that upon talking to the organizers of the HITB CTF, i can say that it is not those kind of straight forward network/web hacking competitions. One of crew shared that it involves more than just network/web hacking skills. One needs to have a fundamental knowledge on cryptography, steganography, reverse engineering, source code understanding, exploit engineering and binary analysis.. i was like..say what!!! damn..that is one tough CTF and whoever wins it should be respected for knowing and having the knowledge of all the mentioned aspects of computer security. Kudos to the Vietnam team for winning this.

Room for Improvement Points: While the topics were great, some of the deliveries were not. One example is the inability of some of the speakers to convey it in proper English (as some of them were from Europe and South America). One of the speakers were speaking out of a word document all the way with little interactions with the audience. Another were speaking without knowing the full stop. It was cute actually.

What i hope to see: Local Speakers at least! While the conference were attended by many locals, unfortunately none of the speakers/presenters were. Although im not a Malaysian, i would love to see some locals presenting their research in the conference. And of course, more ladies please! I've been to these conferences and sadly i rarely see any women hackers speaking. However there were a handful and countable women attending the conference. I also would hope to see topics in regards to penetration testing such as advanced network/web recon/exploitation, bypassing firewall and Anti Virus techniques which could attract more ethical hackers in these fields to attend. While there were booths that were very interesting especially when there's a mini 'challenge' or 'competition' to attract people, some were quite dull (there was even an empty booth with a single person sitting at it). I was impressed by Mozilla booth, because twice i was there, twice they had mini challenges. Such mini challenges can be seen in world class conferences such as Def Con and Black Hat and HITB booth representatives could take some tips from them. The Lock Picking by Toools were also a force to be reckoned with. Unlike Facebook booth where they were packed with people for free gifts and tshirts, the lock picking booth managed to attract more people with its complex challenges and outgoing reps.

Overall: I enjoyed myself. Its much much better than some of the conferences i've been to such as Hacker Halted hosted in Singapore. What i enjoyed most is making new friends, network and exchanging name cards and knowledge. The in between breaks were designed for that (i think) and i ended up making new friends! Great hotel, great food, awesome conference....what more could you ask? I've been to many conferences over the years and i have to say that HITB is one of the top 3 conferences that is in my list of MUST GO!!! Congrats HITB and Thanks for the great conference!

HITB Security Conference main logo banner

Tracks and Speakers displayed digitally



3 Different Tracks in 3 Different rooms

An interesting funny slide

The OWASP Booth


The Ship Captain Hackers!


The hardware used during the hack



CTF event in progress


Microsoft Wizards

Taking a pic with an Anonymous attendee

Winning a Mozilla Firefox Mug

Taking a pic with the winner of Best Windows 8 Application Competition

Stickers souvenirs from the Conference

For more information of future HITB events/conferences, visit http://conference.hitb.org/