Thursday, 3 April 2014

WinRAR 4.20 File Spoofing Vulnerability

So a few weeks ago, a 0 day vulnerability was found in WinRAR which allows someone to change the extension of the zipped file in WinRAR. This vulnerability is now being classified as a File Spoofing Vulnerability.

Here's how it works and if you want to try it.


Check that the version of WinRAR is 4.20.


If you have a Payload/malware in the .exe format, right click and 'Add to Archive'


Click on the ZIP and Click OK


 Once its zipped, when you double click on it, it will show that the file inside is a .exe file.



 Using a tool called xvi32, drag the zipped file to the application and you can see it in Hex format. Search for the .exe


 The searched file


Rename the .exe to .mp3 (an example) and save it


Open the zipped file and you can see it now changed to a .mp3 file.

What's scary is, when you execute the .mp3 file, it will execute as an .exe file which could allow the program to damage your computer depending on the creator of the malware.


Sunday, 23 March 2014

Cyber Security - Passion vs Training

Recently i went to a cyber security seminar in Singapore where the target audience were from the financial industry. During one of the Q&A sessions, one of the audience asked a speaker how did he get into this (security) field and what is important for a cyber security professional to have to ensure that the person is right for the job. He replied that while the technicalities of products, tools and techniques are important, they can easily be trained.

I do not quite agree with the reply as the answer seems to assume anyone can be trained easily to become a knowledgeable cyber security professional. From what i've been through and seen, training is just a small part of being a well equipped security professional. Unlike some other professions, cyber security is a faculty where continuous learning is essential, needed and mandatory. Those who believed that having a qualification or certification certifies themselves as a security guru is actually making themselves fall into a well of delusion. The security risks, cyber attacks, viruses and trojans, processes and even methodologies are constantly changing over time. Those who fail to follow or fail to educate themselves with the latest security news or trends will be left out of the playing field.

Training is important but without passion in the field, then one can only hope you are prepared for the attacks that you are not trained to handle. Let's ask ourselves. Why the bad guys are winning? And why are they still winning despite having many security professionals in the organization trained to subdue or to protect from the bad guys? Take a recent example of a hacking incident where the website of EC-Council, the organization that provide Ethical Hacking training and certifications was hacked and defaced. Some even called it 'Hacking the Ethical Hackers'. And if we look at the profiles of these bad guys, hackers, script kiddies, black hats or whatever we decide to call, some were college students, some were jobless, some were not even working in the IT industry let alone being sent for expensive professional training yet they were and are still able to successfully hack and attack critical infrastructures of well known organizations. So the question is why even being professionally trained, do we still fail?

Passion. Merriam Webster defined it as 'a strong feeling of enthusiasm or excitement for something or about doing something'. If we learned one thing about these hackers, they are passionate about hacking. With such a strong sense of passion, comes the dedication they put into in training themselves to attack and educating themselves with the latest attacking tools and techniques from free courses/manuals online (God bless the Internet). If one thing that majority of the security professionals are lacking is this: PASSION.

Recently, my department head interviewed a candidate for a position to work with the ethical hacking team. The candidate had a degree and a CEH (Certified Ethical Hacker) certification but what initially seemed to be a prospect eventually was not. The reason shared was simple. The candidate did not seemed to know what's going on in the cyber security world for the past 5 years and basic penetration testing question couldn't be confidently answered let alone correct. Hence the reason why hiring a security professional is not as easy as simply by looking at the credentials.  


If we, the security professionals are as passionate as the bad guys out there, keep up with the latest news on cyber attacks, defense and protection technologies, then we may have a chance to level the playing field with the skillful hackers out there. 

Wednesday, 19 March 2014

Defcon Kerala, India

Earlier this month, we were given the honor to present our paper with my colleague (Vikneshwaran Veeran) at Defcon Kerala. I was surprised and happy when our paper was accepted by the Defcon Kerala team. Coincidentally, i presented a similar demo at two security seminars in Singapore. But the difference was this, Defcon Kerala is a group of security enthusiasts, programmers, bug bounty hunters, application and tool developers and of course HACKERS! Unlike the seminars i presented in Singapore where the audience were geared towards business users and IT professionals, conferences like Defcon are more techie and how should i put it: subject matter experts!

During the day of the conference, we were warmly welcomed by the team. It wasn't as big as the Defcon conference in Vegas (thank God!) but it was a great experience. We get to meet the creator and founder of Xenotix (Ajin Abraham), the creator of Mandiant OS, the creator of IronWasp (Lava Kumar), the WatsApp hacker (Anto Joseph), a hardware hacker (Yasheen) who was only 19 and many other talented individuals. We were humbled by both the speakers as well as the audience who possessed such great knowledge and enthusiasm for security. Throughout the presentations before ours, the speakers were speaking and demonstrating the latest tools and techniques pertaining to applications and source codes. My colleague and i were dumbstruck-ed as we asked ourselves "Are we in the right place to present something different?" especially when our presentation was geared towards the web application and network penetration.  

Alas, when it was our turn to present, the hall was quiet. We felt a sudden silence and quickly set up the laptop to the projectors as my colleague starts to introduce ourselves to do the ice breaker. So ideally, this was how we prepared for the demo: For the introduction, my colleague will speak and when it comes to the demo, i will speak and when i started to run the demo, my colleague will continue the motion as to keep the presentation alive and not create any form of awkward silence in between.

During the demo, it was smooth but we encountered a small 2 minutes hiccup/delay. The 2 minutes delay was caused by the process of creating the payload. Usually it should be done within 30 seconds but at that point of time, it was not. After 1 minute, i started to look at my colleague and started to show signs of desperation. My colleague coolly told the audience about Murphy's Law. Well, i did prepare backups of the payload in case that doesn't work but after 2minutes, it did. Phewww!! Continue to the demo and when it finally completes, i was delighted. Sheesh, i stammered most of the time and even one of the audience jokingly commented that my 'accent' was funny. Argh! 

After the presentation, we came up to some of the other speakers and complimented them on their great work and tools. A big RESPECT to them all. One of the speakers, the creator of IronWasp complimented our demo saying it was one of the most complicated demos he had seen and he was nervous and glad when it managed to pull it off. (imagine how nervous we were on stage!) That was such an awesome feedback. 

After the conference ended we were swarmed by the members of the audience who spoke to us and took pictures with us. It was a great feeling. I also didnt miss the opportunity to take the photos with them as well. Whenever they took my pic, i will tell them "hang on, its my camera's turn to take". We managed to exchange contacts with them either via namecards or linkedin or facebook. 

Overall, it was a great experience and i really thank the Defcon Kerala Team for organizing this event. I believed it was a fruitful event that everyone could take away, learning something new or at least spurn them into wanting to go deeper into security. Although this was the second year of this conference, i believed that this will go into something bigger, perhaps in a few years time, it will garner a much larger audience possible rivaling conferences such as Hacker Halted. 

Here are some of the pictures of the event.




















Wednesday, 5 March 2014

Websense Security Seminar - A Presentation

So after our presentation at the ABS-FITA Cyber Security Seminar, we were invited to present our demo in another seminar organized by Websense.


It wasn't as big as the ABS-FITA seminar but it was still exciting nonetheless. The crowd was about 100-120 people from different backgrounds. It was great to see my brief bio on the speaker's website. 



Felt more confident this time round especially after the stressful pressure on the previous demo. Good thing was, we nailed it smoothly. Everything went smooth and we managed to put the 'WOW' look on some of the audience. After the demo, we were greeted by some of the audience who asked more about the capabilities of our team and pretty much the sales representatives from BT took over the conversation. 

Here are some of the photos taken by one of the attendees:

A Brief Bio

The Layout 

 The Finale

Bringing it all together

Notice the 'BT EHCOE' on Kali Wallpaper?

 Command and Commands


NEXT STOP: Presenting in DEFCON KERALA!!!!

Friday, 28 February 2014

ABS-FITA Cyber Security Seminar - Presentation

ABS-FITA : Cyber Security Seminar - An Experience


It was such a great honor to be invited to demonstrate our capabilities to the masses at the seminar. Believe it or not, although the demo was only 1 hour, it took me over 100 hours just to prepare the setup, ensuring my payloads work and the Anti Virus applications can be bypassed. The preparation was not as smooth as i hoped it would be.



The first time i prepped it and then showed it to a colleague, all failed! My Backtrack Linux wasn't working, the Xenotix unexpectedly hanged and it was such a mess. Then after hours and hours of reinventing the wheel, feeling confident and showed it to the internal staffs, again, it failed! Why? Why? Why?

Then came the day the organizers from the ABS-FITA to see the demo in the office. I prayed and i prayed and i prayed, please dont fail.. and thank God! It went smooth!


The 'Rehearsal'

The organizers told us to come as early as 7am to prep the stage and ensure the projectors and sound are all working. Well, to ensure that i would not be late by our 'reliable' MRT, i had to wake up as early as 4 am and leave the house at 5.15am reaching the Ritz Carlton hotel at 5.40am! There was no one around in the hall but without wasting time, i set up my machines and do a trial run on the whole demo process. Smooth...

During the Talk

While the event already started, instead of listening to the speaker, i was at the speaker's table with my two notebooks on, rerunning my demo process. Smooth....

During Lunch

Our presentation was scheduled at 4pm. In other words, we had 4 more hours before our turn. Everyone went to lunch but i was busy on stage testing my network (4G) connection and ensuring that i am able to send traffic within the tethered network environment.... Smooth...

Showtime

So when our turn begins, i was very nervous or in Hokkien (Gan Cheong), because i really really hope it will work. The problem was, its easier and more environment friendly doing the demo in front of an audience of hackers as they would understand if and when a Demo fails. But presenting it to an audience of business level, i need to ensure that everything must be perfect end to end... And here's the thing, it was all perfect until the part when i tried to connect into the database server's shell but connection was reset. I was like, Oh No! but my colleague who did all the talking coolly said "Looks like the connection was out, but he will try again. Not every hack is a perfect hack". And when i enter 'Exploit' and hit the Enter button.. loading...loading...loading and YES it went through!!! Total 'downtime' was 10 seconds! Phew!!!








Conclusion

I was glad to be able to show everything completely and as feedback-ed by the organizers "it was the highlight of the event". Some of the people came up to us and said they enjoyed the demo. Some said it opened their eyes after seeing it live. And finally, unexpectedly, i received a speaker's gift by the organizer... a Mont Blanc wallet! How nice!!

Next Week: Presentation @ Websense! 
Link: http://app.certain.com/profile/web/index.cfm?PKWebId=0x5770881342&varPage=info
Link to pictures: http://centres.smu.edu.sg/fita/events/photos-videos/cyber-security-seminar/

Wednesday, 19 February 2014

Curiosity Killed the Cat 5 Network

Last year, i wrote a technical article entitled 'Social Engineering: Penetration Testing the Human Element' to Pentestmag.com which focused on the process of social engineering assessment using the art of deception and how easy it could be with simply a smile accompanied by an act of confidence.

In the book by Kevin Mitnick, 'The art of deception', he dives deep into that art and shares the tricks he used to deceive people into giving him vital information. Not only did he succeed into tricking the common employees, he also managed to trick security administrators, managers, CIOs and other people holding top position in organizations.

Then again, not many can be as charming, as confident and as cunning as Kevin be it from tele conversation or face to face meetings. Thats when hackers use the art in other forms; from cloning a website and hoping someone fall for it (phishing) to sending malicious links or attachments via emails and crossing their fingers hoping someone clicks on it.

Earlier this month, KrebsonSecurity reported that the famous hack and breach at Target could be the result from an email attack, a malware-laced email phishing attack sent to employees.[1]


These trend of users easily falling prey to social engineering tactics even led to a vendor suggesting to punish careless employees to reduce security breaches. [2]



Looking back at the past, the spread of malware such as the famous 'I love you' virus, the 'Melissa' and the 'Zeus' viruses were all being spread via invoking the curiosity of humans. A single click. Thats all it takes.  And thanks to this curiosity, those viruses managed to spread over 50 million computers worldwide. Even important organizations such as the Pentagon, the CIA and the British Parliament were not spared. [3]

Employees play a huge role in ensuring the security of the organizations. 

Organizations may have placed the best security mechanism to block from any external intrusion but if one thing hackers learn from history is that they have evolved into attacking the human curiosity first because it is much easier to fool a person than a system. Like i wrote above, one click is all it takes to bring the organization down to its knees. 

To quote the security rockstar Bruce Schenier, "Amateurs hack systems. Professionals hack people." 

References:

Saturday, 8 February 2014

XSS (Cross Site Scripting) Vulnerability Found in Dell.com

According to OWASP, Cross-Site Scripting (XSS) attacks are a type of injection problem, in which malicious scripts are injected into the otherwise benign and trusted web sites. XSS attacks occur when an attacker uses a web application to send malicious code, generally in the form of a browser side script, to a different end user. Flaws that allow these attacks to succeed are quite widespread and occur anywhere a web application uses input from a user in the output it generates without validating or encoding it. An attacker can use XSS to send a malicious script to an unsuspecting user. The end user’s browser has no way to know that the script should not be trusted, and will execute the script. Because it thinks the script came from a trusted source, the malicious script can access any cookies, session tokens, or other sensitive information retained by your browser and used with that site. These scripts can even rewrite the content of the HTML page

From: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)

On May 28th 2013, an XSS vulnerability on Dell.com website was found and posted at pastebin.com.

(screenshot of the XSS on Dell)

As of now, the XSS vulnerability is fixed and could not be reproduced. However, on Jan 20th 2014, a security analyst by the name of Jordan Jones found the same issue on a different page of the same website and posted a screen shot of the POC on Twitter.

(the twitter post by Jordan Jones)

(the executed vulnerability)

He was kind enough to inform Dell Security team via Twitter about the vulnerability which led Dell to inform him the person to contact.

(Jordan Jones interaction with Dell Security)

At the same time, he also posted more information about the vulnerability on pastebin.com 

(more information about the vulnerability)

Further injection of script can be tested on the parameter besides the window alert as screengrabbed by Jordan Jones. Below, is another way to exploit the vulnerability. By injecting an image to the parameter which leads to this:

(image injection to the vulnerable parameter)

To date, Dell has yet to fix this vulnerability. XSS is a serious vulnerability that is rated as High or Critical by most vulnerability scanners including Qualys and Acunetix and a well known company like Dell should fix this vulnerability as soon as possible.