Tuesday, 12 August 2014

BSidesLV - An Awesome Security Conference!

BSidesLV is a security conference in the US, more specifically in Las Vegas! Yeap, that's right.. Sin City! I was excited and privileged to be accepted as a speaker at the conference. As it was my first time speaking in America, it was quite a challenge for me as i know that unlike audience in Asia, American audience seems to be more outspoken and when i was there it was indeed true.

After i arrived at the Tuscany Suites and Casino, my stomach started to hurt. That's right, the pressure, the stress...there's so many butterflies rampaging in my stomach as i walked to the reception. The queue to register was long. Initially i joined in the queue but then i saw some individuals 'bypassing' them. I assumed they must have been the speakers so i asked the volunteers and phew... i managed to get in without queuing.

Once i got in, i didn't waste any time and start to take as much pictures as i can. Well, i was a tourist when i was there so excuse my itchy fingers to snap pictures. The atmosphere was awesome, the people were friendly and the topics were great! Despite not properly socializing with the crowd, i was having a great time there. Well, i am a sucker for conferences, so such a con made me feel belonged.

When my time was up, i walked up to the 'stage' and connect my computer to the VGA cable to extend my monitor. I spent the first 4 minutes trying to get it connected. Resolution sadly gave me an issue so i had to make do with a slightly smaller yet still visible resolution on the projector. I was nervous and things that i was prepared to say, those words just got lost. But i was happy that the audience, despite my pressured state, were very supportive. Some were smiling, some were nodding their heads, showing signs of approval with every slides i went through. Of course, i was challenged by another speaker who told me off about the practicality of my talk after i shown two clips from Die Hard 4.0. After replying to him saying that, it is possible for a scene like Die Hard 4.0 to happen and telling him that my last few slides will show it how, he with his 3 other friends, all wearing black tshirts, stood up and walked out of the conference room..and i was just on my slide 4. I was a little demotivated but i am glad that the rest stayed until the end. What i didnt expect was the audience gave me a round of applause after my talk! I was very touched and felt a little emotional, feeling appreciated despite my stressed mode and pressure.

After the talk, i was approached by a handful of people from the audience, asking me more about my talk. Some asked about my talk and some congratulated me about my performance. I was very happy to hear from their own words that they enjoyed my presentation. And what's more important was that i got to meet some experts in the field i was talking about.

All in all, it was an amazing experience, this was indeed one of the best conferences i attended. The organizers, the volunteers, the speakers and the audience were simply awesome! It truly felt like home...

Here are some of the pictures...

Where it all happened!

The souvenirs!

 Bought and Free Tshirts!

Close up of the Badge!

Some sponsor banners!



Mini booths

WiFi Pineapple!! I bought one!

Protiviti! - Looking for Security Enthusiasts to join them.

Big Ass O-Wasp!

Hackers For Charity booth!

CTF Competition! 

Social Engineering Competition!

Creative Winning Trophy!

 The Topics!




 The start of my presentation 

 Me with Chris Sistrunk aka SCADA God!

Me and Jack Daniels, the co-founder of Security BSides conference!

This volunteer (on the left in yellow) was the man who motivated me and encouraged me not to be pressured and even helped me answered a question from the audience! Kudos to him! Wished i knew who he is..

Support our Troops! I mean..Sponsors... :)

Monday, 21 July 2014

World War Zero - Time Magazine

This month's Time magazine has a very fascinating cover and the title is quite enticing especially to those people in the information security field.

"World War Zero! The global battle to steal your secrets is turning hackers into arms dealers."


A short preview of the article below simply made me wanna get the magazine.


So after i got my hands on a copy, i flipped straight to the article. The article is mainly about a story of a hacker called Aaron Portnoy who loves to find bugs and zero days on software and applications and how bugs are now becoming a profitable business for both the good guys and bad.

The image below 'A Bug's Life' is a high level portrayal of the stages involved when selling a bug. 


$33,500 for a Facebook bug!!! Holy Molly!!


One scary thing about Critical Infrastructures is that there are many of them connected to the Internet!


And i loved the conclusion of this article.








Thursday, 10 July 2014

Speaking at Vegas!

It is my pleasure to share that my talk i submitted to BSidesLV entitled: "Vulnerability Assessments on SCADA: How i 'owned' the Power Grid' has been accepted!!!!


This will be my first time speaking at a security conference in the US! (also will be the first time to travel to the US!) I've spoken at conferences in Singapore, presented in Dubai and demoed in India. This will definitely be a new experience. Definitely i am very excited for this and will feel pressured especially knowing that the US audience are outspoken unlike its Asian counterparts.

Just a brief intro to my talk; i will be talking about the state of SCADA security, the typical vulnerabilities found in SCADA environment and how it's possible for someone to own and control a Power Grid. 

Check out the site: http://www.bsideslv.org/

Friday, 27 June 2014

First Published Article in Hakin9

Recently, i was selected to be involved to perform an assessment on a SCADA environment. It was an amazing experience getting to see the SCADA systems, the monitoring and the control systems that control the powerplants and power grids. Although there were many challenges faced during the assessment, it allowed me to develop my own methodology for performing a Vulnerability Assessment on SCADA networks.

I was more than happy to share the basic requirements and techniques on how to properly perform a VA on SCADA networks/systems to Hakin9. Unfortunately, you need to subscribe to Hakin9 before you can download a copy.


Link: https://hakin9.org/advanced-exploitation-with-metasploit/

Thursday, 26 June 2014

GISEC (Gulf Information Security Expo & Conference) Dubai - 2014

GISEC (Gulf Information Security Expo & Conference) Dubai - 2014

I was pleased to be selected as part of a team to demonstrate BT's capability in GISEC conference recently which was held at the Dubai World Trade Center. I contributed to the idea of having a 'Cyber Challenge' to the BT booth inspired by the exposure i have from attending to hackers conferences. I was also given an area to showcase the Ethical Hacking capability providing demonstration and presentation to passerby.

It was a very tiring and satisfying experience! Given the fact that i was able to come up with an end to end demo by myself without any critics from management gave me a sense of confidence they have on me to deliver.

First, it was the Cyber Challenge stand. This challenge is about the ability for a pentester to be able to find a XSS vulnerability and exploit it. Day 1 challenge was to inject a script inside the affected parameter and provide an alert pop up. Day 2 challenge was to 'deface' a website by embedding an image on it and Day 3 challenge was to inject a script that will come out with an output in the result section and upon clicking on it, will be redirected to another page.

Sound simple right? But during the 3 days, only 3-4 people managed to complete the challenge.

On the ethical hacking stand, my job was to perform demos on anyone who has the interest to see it. I was happy to know that some people came up to me and said that the booth managed to gather a huge number of people, mostly were curious to see the demo. I won't go into the details of my demo but all i can say is that the demo was similar to the demo i presented with a colleague at Defcon Kerala, India last year.

But one of the best and memorable moments was the fact that i got to meet many strangers in the professional world and exchanging contacts after that. Well, thats what we called 'Networking'. All in all, it was a great and superb experience and i am sure this will continue in the near future.

Below are some of the pictures taken:
















Thursday, 12 June 2014

Anti Virus is Dead..So What's Next?

When i was in GISEC (Gulf Information Security Expo & Conference) in Dubai this year, i presented demos on the BT booth demonstrating how a web vulnerability called XSS (Cross Site Scripting) can be further used to gain access to the browser as well as the systems using the art of social engineering. Through using two different exploit frameworks, i was able to demonstrate how i was able to create a payload to bypass any Anti Virus applications that was installed on the victim's machine.

After the demonstration, i showed them an online article and asked them, what do they think should be done to protect the hosts or workstations given the fact that, according to the article, Anti Virus is dead. Majority of them couldnt provide me a straight answer. Some mentioned to install firewalls, others said that patches must be properly updated and installed. While the answers might help to prevent, the solution i recommended to them was 'Endpoint Security'.


'Endpoint Security' has many definitions and one of the definitions i usually referenced to is the fact that it is a solution that consists of not just an Anti Virus but a host based behavioural blocking components such as an IDS/IPS (Intrusion Detection/Prevention Systems), a host based firewall, Anti Spyware component as well as NAC (Network Access Control). With these components installed, as i explained to them, although my payload will be able to bypass the Anti Virus and Anti Spyware components, the IPS will definitely detect it and will prevent it from being executed.


"But i have a NIPS (Network Intrusion Prevention Systems) and a firewall that will protect external attacks from penetrating my internal systems and servers." claimed a person. "But what about your own internal employees attacking your infrastructure?" I questioned him back while i showed him an online article. According to an article last last year, 58% of information security incidents were attributed to insider threat. We have seen many cases, due to relaxed policies, employees are able to bring their own devices to connect to the organization's network, able to bring external storage drives and plug it into the organization's machines and of course, users having administrative privileges to execute and install third party software in their organization's machines. These situations potentially allow malware coming into the internal networks and spreading throughout the organizations.



While there will never be a patch for human stupidity, security managers must quickly propose a solution to protect their networks from both external and internal attacks. While having security mechanisms protecting the perimeter of the organizations are able to deter external threats, most organizations fail to understand the critical need to protect for possible internal threats as well. Yes, one can argue that network based solutions can protect to the scenario i demonstrated but then again, is that really enough?

Sunday, 4 May 2014

Mobile Web Application Assessment (Android Emulator + Burpsuite)

In this tutorial, i will show how to set up an environment to perform Web Application assessment. In this tutorial, you will need to download and install the following things first:

1) Android Emulator  

2) BurpSuite 

3) Firefox Addon Proxy Selector


This tutorial assumes that you have downloaded and installed the above items. I will proceed to show how to set up the Android Emulator and Burpsuite.


1) Click on the SDK Manager
2) Click on Tools > Manage AVDs



3) Select the first AVD
4) Click Start


5) Click Launch


6) Allow Android to boot up. This can take up to 5mins


7) You will get to this screen once successfully loaded


8) Open Burpsuite and set the Specific Address to the local machine's IP address


9) On Android, go to Settings > Wireless & Networks > Mobile Networks > Access Point Names > Select the default APN > Edit Access Point and se the Proxy IP and the Port


10) Open up Firefox, go to the Proxy Selector and select Burpsuite-MobileApp (you may need to change the IP address accordingly to your given IP address)

*Take note that upon installing the Proxy Selector addon, you will need to set up the proxy settings manually before you can perform this portion.


11) Open the Browser in Android and ensure that BurpSuite Interceptor is set to On.
12) Traffic will be intercepted by Burp proxy.

There You Go! Now You Have My Permission to Intercept!