Friday, 28 February 2014

ABS-FITA Cyber Security Seminar - Presentation

ABS-FITA : Cyber Security Seminar - An Experience


It was such a great honor to be invited to demonstrate our capabilities to the masses at the seminar. Believe it or not, although the demo was only 1 hour, it took me over 100 hours just to prepare the setup, ensuring my payloads work and the Anti Virus applications can be bypassed. The preparation was not as smooth as i hoped it would be.



The first time i prepped it and then showed it to a colleague, all failed! My Backtrack Linux wasn't working, the Xenotix unexpectedly hanged and it was such a mess. Then after hours and hours of reinventing the wheel, feeling confident and showed it to the internal staffs, again, it failed! Why? Why? Why?

Then came the day the organizers from the ABS-FITA to see the demo in the office. I prayed and i prayed and i prayed, please dont fail.. and thank God! It went smooth!


The 'Rehearsal'

The organizers told us to come as early as 7am to prep the stage and ensure the projectors and sound are all working. Well, to ensure that i would not be late by our 'reliable' MRT, i had to wake up as early as 4 am and leave the house at 5.15am reaching the Ritz Carlton hotel at 5.40am! There was no one around in the hall but without wasting time, i set up my machines and do a trial run on the whole demo process. Smooth...

During the Talk

While the event already started, instead of listening to the speaker, i was at the speaker's table with my two notebooks on, rerunning my demo process. Smooth....

During Lunch

Our presentation was scheduled at 4pm. In other words, we had 4 more hours before our turn. Everyone went to lunch but i was busy on stage testing my network (4G) connection and ensuring that i am able to send traffic within the tethered network environment.... Smooth...

Showtime

So when our turn begins, i was very nervous or in Hokkien (Gan Cheong), because i really really hope it will work. The problem was, its easier and more environment friendly doing the demo in front of an audience of hackers as they would understand if and when a Demo fails. But presenting it to an audience of business level, i need to ensure that everything must be perfect end to end... And here's the thing, it was all perfect until the part when i tried to connect into the database server's shell but connection was reset. I was like, Oh No! but my colleague who did all the talking coolly said "Looks like the connection was out, but he will try again. Not every hack is a perfect hack". And when i enter 'Exploit' and hit the Enter button.. loading...loading...loading and YES it went through!!! Total 'downtime' was 10 seconds! Phew!!!








Conclusion

I was glad to be able to show everything completely and as feedback-ed by the organizers "it was the highlight of the event". Some of the people came up to us and said they enjoyed the demo. Some said it opened their eyes after seeing it live. And finally, unexpectedly, i received a speaker's gift by the organizer... a Mont Blanc wallet! How nice!!

Next Week: Presentation @ Websense! 
Link: http://app.certain.com/profile/web/index.cfm?PKWebId=0x5770881342&varPage=info
Link to pictures: http://centres.smu.edu.sg/fita/events/photos-videos/cyber-security-seminar/

Wednesday, 19 February 2014

Curiosity Killed the Cat 5 Network

Last year, i wrote a technical article entitled 'Social Engineering: Penetration Testing the Human Element' to Pentestmag.com which focused on the process of social engineering assessment using the art of deception and how easy it could be with simply a smile accompanied by an act of confidence.

In the book by Kevin Mitnick, 'The art of deception', he dives deep into that art and shares the tricks he used to deceive people into giving him vital information. Not only did he succeed into tricking the common employees, he also managed to trick security administrators, managers, CIOs and other people holding top position in organizations.

Then again, not many can be as charming, as confident and as cunning as Kevin be it from tele conversation or face to face meetings. Thats when hackers use the art in other forms; from cloning a website and hoping someone fall for it (phishing) to sending malicious links or attachments via emails and crossing their fingers hoping someone clicks on it.

Earlier this month, KrebsonSecurity reported that the famous hack and breach at Target could be the result from an email attack, a malware-laced email phishing attack sent to employees.[1]


These trend of users easily falling prey to social engineering tactics even led to a vendor suggesting to punish careless employees to reduce security breaches. [2]



Looking back at the past, the spread of malware such as the famous 'I love you' virus, the 'Melissa' and the 'Zeus' viruses were all being spread via invoking the curiosity of humans. A single click. Thats all it takes.  And thanks to this curiosity, those viruses managed to spread over 50 million computers worldwide. Even important organizations such as the Pentagon, the CIA and the British Parliament were not spared. [3]

Employees play a huge role in ensuring the security of the organizations. 

Organizations may have placed the best security mechanism to block from any external intrusion but if one thing hackers learn from history is that they have evolved into attacking the human curiosity first because it is much easier to fool a person than a system. Like i wrote above, one click is all it takes to bring the organization down to its knees. 

To quote the security rockstar Bruce Schenier, "Amateurs hack systems. Professionals hack people." 

References:

Saturday, 8 February 2014

XSS (Cross Site Scripting) Vulnerability Found in Dell.com

According to OWASP, Cross-Site Scripting (XSS) attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user in the output it generates without validating or encoding it. An attacker can use XSS to send a malicious script to an unsuspecting user. The end user’s browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by your browser and used with that site. These scripts can even rewrite the content of the HTML page

From: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)

On May 28th 2013, an XSS vulnerability on Dell.com website was found and posted at pastebin.com.

(screenshot of the XSS on Dell)

As of now, the XSS vulnerability is fixed and could not be reproduced. However, on Jan 20th 2014, a security analyst by the name of Jordan Jones found the same issue on a different page of the same website and posted a screen shot of the POC on Twitter.

(the twitter post by Jordan Jones)

(the executed vulnerability)

He was kind enough to inform Dell Security team via Twitter about the vulnerability which led Dell to inform him the person to contact.

(Jordan Jones interaction with Dell Security)

At the same time, he also posted more information about the vulnerability on pastebin.com 

(more information about the vulnerability)

Further injection of script can be tested on the parameter besides the window alert as screengrabbed by Jordan Jones. Below, is another way to exploit the vulnerability. By injecting an image to the parameter which leads to this:

(image injection to the vulnerable parameter)

To date, Dell has yet to fix this vulnerability. XSS is a serious vulnerability that is rated as High or Critical by most vulnerability scanners including Qualys and Acunetix and a well known company like Dell should fix this vulnerability as soon as possible.



Thursday, 30 January 2014

The Art of Deception - A Book by Kevin Mitnick

The Art of Deception - Controlling the Human Element of Security by Kevin D. Mitnick.


I've always enjoyed reading about the art of social engineering and i even wrote an article to Pentestmag entitled "Social Engineering: Penetration Testing the Human Element" back in 2013. So i got this book from Amazon and yes, Kevin goes in depth into this art sharing scenarios and what are ways to prevent such things from happening. 



Here are some of the contents that interests me.

On Stanley Rifkin

"A few days later Rifkin flew to Switzerland, picked up his cash, and handed over $8 million to a Russian agency for a pile of diamonds. He flew back, passing through U.S. Customs with the stones hidden in a money belt. He had pulled off the biggest bank heist in history-and done it without using a gun, even without a computer. Oddly, his caper eventually made it into the pages of the Guinness Book of World Records in the category of "biggest computer fraud. Stanley Rifkin had used the art of deception-the skills and techniques that are today called social engineering. Thorough planning and a good gift of gab is all it really took.  And that's what this book is about - the techniques of social engineering and how to defend against their being used at your company."


On Passwords
"On the surface this appears to be a simple message to get across to employees. It's not, because to appreciate this idea requires that employees grasp how a simple act like changing a password can lead to a security compromise. You can tell a child "Look both ways before crossing the street," but until the child understands why that's important, you're relying on blind obedience. And rules requiring blind obedience are typically ignored or forgotten."

 Educating Cleaners and Piggybacking
"Also, cleaning crews should be trained about piggybacking techniques (unauthorized persons following an authorized person into a secure entrance). The should also be trained not to allow another person to follow them into the building just because the person looks like they might be an employee."

On Security vs Productivity
"Of course, corporate security policy should mandate system administrators to enforce security policy through technical means whenever possible, with the goal of not relying on fallible humans any more than necessary. It's a no brainer that when you limit the number of successive invalid login attempts to a particular account, for example, you make an attacker's life significantly more difficult.

Every organization faces that uneasy balance between strong security and employee productivity, which leads some employees to ignore security policies, not accepting how essential these safeguards are for protecting the integrity of sensitive corporate information."

On using the power of Authority
"Because Kurt was pretexting as a vice president in his conversation with Anna, a clerk in Finance, he kenw that it would be very unlikely that she would question his authority. On the contrary, she might entertain the thought that helping a VP could gain her favor."

A Potential Fatal Mistake
"The nurses who received these instructions did not know the caller. They did not even know whether he was really a doctor (he was not). They received the instructions for the prescription by telephone, which was a violation of hospital policy. The drug they were told to administer was not authorized for use on the wards, and the dosage they were told to administer was twice the maximum daily dosage, and thus could have endangered the life of the patient."

Double Standards on Spyware?
 "Anitivirus software doesn't detect commercial spyware, thereby treating the software as not malicious even though the intent is to spy on other people. So the computer equivalent of wiretapping goes unnoticed, creating the risk that each of us might be under illegal surveillance at any time. Of course, the antivirus software manufacturers may argue that spyware can be used for legitimate purposes, and therefore should not be treated as malicious. But the developers of certain tools once used by the hacking community, which are now being freely distributed or sold as security-related software, are nonetheless treated as malicious code. There's a double standard here, and i'm left wondering why."

 On Baiting the Victims
"The attacker sends emails claiming that the first 500 people to register at the company's new Web site will win free tickets to a hot new movie. When an unsuspecting employee registers at the site, he is asked to provide his company email address and to choose a password. Many people, motivated by convenience, have the propensity to use the same or a similar password on every computer system they use. Taking advantage of this, the attacker then attempts to compromise the target's work and home computer systems with the username and password that have been enetered during the Web site registration process."


On the need to challenge the executives
"Employees must be trained not to assist people they do not personally know, even if the person making the request claims to be an executive. Once security policies concerning verification have been put in place, management must support employees in adhering to these policies, even when it means that an employee challeneges a member of the executive staff who is asking the employee to circumvent a security policy."

Wednesday, 22 January 2014

SANS Holiday Hack Challenge 2013 - Honorable Mention


So last year, i was introduced to this Holiday Hack Challenge organized by SANS and i took part in it. With a career as an Ethical Hacker and graduated from a Cyber Forensics Degree, i took this challenge to see how i can exploit my knowledge to answer this.



Well, it wasn't easy of course. Given just a PCAP file, i need to analyze, figure out the chain of events, create hypothesis and find evidence of attacks and finally suggest solutions on how to prevent this.

I spent over 3-5 nights using various PCAP analysis tools such as Wireshark, Network Miner, Xplico and Netwitness Investigator. One of the challenges i faced was the timestamp of the PCAP file. Since this PCAP file was created from the US, i only realized it 2 nights later that my Computer clock and Timezone settings was affecting the chain of events. Once i set it to the US timezone, then the chain of events made sense.

After completing the challenge, i submitted to SANS and the next day, i got a reply from Ed Skoudis! It was a compliment about my submission and it made me very confident about being one of the 4 winners.


When the results were out, i was a little disappointed that i didn't manage to get any of the top 4 positions. I looked at the answers by the Winners and i was shocked and satisfied..they were really in detail, diving deep into the technicalities of their analysis. They even managed to find something that i overlooked! A huge KUDOS to them! Truly deserved winners! 

But not all was gloomy for me. When i scrolled down under the section 'Honorable Mentions', i was excited to see my name was among the many other honorable submissions! This was what mentioned:

"Fadli B. Sidek: Fadli's response was amazingly detailed, lavishly illustrated, and beautifully formatted. It's an awesome entry from an obviously gifted information security analyst who knows how to convey information extremely effectively. This answer also pulls in the little lulzsec cartoon character near the end, to good comedic effect."


It made my day and put me in a cloud 9 for a while! I was happy that my nights spent to do this got rewarded! Anyhoo, i would like to share the report i submitted to SANS:










Special thanks to Ed Skoudis and the whole SANS team for organizing such as great challenge for all the nerds and geeks out there! Looking forward to participate in more challenges like this!

Wednesday, 15 January 2014

Books to Read in 2014

Ordered 5 books from Amazon and just arrived few days ago! Will be reading them all and hope to complete them by end of 2014.


Thursday, 9 January 2014

Check If You Have Been Pawned

Adobe made a huge news when it was hacked and millions of accounts compromised. Other accounts such as Yahoo and Sony also made the news about its users accounts being compromised.


There are several sites to check whether your Adobe accounts been compromised. Here are 2 of them:


And another one. This one also has a database of hacked accounts of Yahoo, Snapchat, Sony and others beside Adobe.