Wednesday, 4 December 2013

DNC Registry - Why it will be a Failure

So two days ago on the 2nd Dec 2013, the PDPC (Personal Data Protection Commission) Singapore announced the Do Not Call Registry for Singaporeans to register if one does not wished to receive nuisance calls or SMS from telemarketeers.



All of the major local medias started to write and publish about it spreading the news about this so call awesome thing for consumers.



Source: http://business.asiaone.com/news/do-not-call-registry-opens-consumers

But will this work? Are you not going to be receiving any nuisance call from telemarketers? If one thing i learned about security and personal data protection is to NEVER give out my contacts to any public website. The reason is simple: SPAM! And worse...a potential SCAM!

5 years ago back when i was an IT support engineer, i received many 'cases' where users received many Junk or SPAM emails from external domains. My question to them is simple: Did you ever subscribe to any newsletter using your corporate email address? And alas, all of the answers were YES they did. Some even argued that those sites they subscribed using their corporate email had a fine print saying that their contacts will not be distributed...  Here's a fact... Thats hardly True! 

Recently, i just signed up a new line with a major telephone company here. No one knew our new house number except for ourselves yet days later someone called me and threatened me about me owing money to  a loan shark. They somehow knew my address as well as my name. Now how the hell did they get my information when that information was not shared.. I asked a friend about this so called phenomena and he shared that these loan sharks have contacts in the telephone companies and these loan sharks can get these information anytime they want. There's no such thing as privacy. I thought for a second and concluded... he was right! Our information will never be safeguarded no matter how many fine prints you read. 

Now back to the DNC registry. Why do i think that this wont work. While it may sound like a good initiative , i have to say that this eventually will not work and huge corporations will see this as an issue and if this affects potential businesses then be prepared to have this initiative back fire. Personally, i did not provide my email or phone numbers to the registry. Despite it being from an established organizationt, i still refuse to believe it. Call me a paranoid dude, but with the things i have experienced, that site could simply be another huge harvester to collect all my info and worse case scenario, sell/distribute them to private telemarketing companies. 

So how can we protect ourselves? 

For SMS advertisements, there is an option with every SMS to Unsubscribe. This is one of the rules that government enforced to telemarketers; to give the option for consumers to unsubscribe. So if we dislike the annoying SMSes, just type in the given number to Unsubscribe from the service. Its a bit irritating to do this with every sms but we have to do our part if we want to have peace. 

For Emails, i recommend people not to use their personal or corporate email address when subscribing or signing up for anything online. No matter how much you think your information will not be leaked to others, it will eventually. To prevent this, create a new email address and use that email address to sign up for anything. However, you need to do your part to check your new email address for incoming emails but 95% of the time, its just more advertisements and promotions that you can find it online. Also, do not input your full email address when writing blogs, sending messages online. Whenever you do that, your email address or phone number will be guaranteed 'stolen' by online harvesters. Put your email address like this instead:
name (at) organization (dot) com
This way, email harvesters will not be able to understand and will not collect this information.

For telephone calls, this is a tough one. Im pretty confident that everyone of us get/got a phone call from insurance companies or bank organizations trying to talk to you into buying their 'promotions'. Do not scold them or shout at them. What i usually do is this. When i received a call with a published number, i will listen for a few minutes until i verified that its just a call from companies trying to sell me something. I will then politely tell them that im in a meeting/lunch/in toilet/etc, and tell them to call back in 10mins or 30mins. Once acknowledged, save that number and set it to your Block List. Its easy right? You dont have to be angry or anything. But what if its a private number? Then politely tell them that you are busy and ask them for their number to call them back. Usually, they will not provide the number and usually, they will not call you back when you insist. 

Remember, YOU HAVE EVERY RIGHT TO DO IT! 


Privacy?


From the movie: Operation Takedown.






SSL/TLS use of Weak RC4 cipher - Validating the Findings

Results from Qualys Scan

ISSUE:
-SSL/TLS use of weak RC4 cipher

THREAT:
Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS ) protocols provide integrity, confidentiality and authenticity services to other protocols that lack these features.

SSL/TLS protocols use ciphers such as AES,DES, 3DES and RC4 to encrypt the content of the higher layer protocols and thus provide the confidentiality service. Normally the output of an encryption process is a sequence of random looking bytes. It was known that RC4 output has some bias in the output. Recently a group of researches has discovered that the there is a stronger bias in RC4, which make statistical analysis of ciphertext more practical.


The described attack is to inject a malicious javascript into the victim's browser that would ensure that there are multiple connections being established with a target website and the same HTTP cookie is sent multiple times to the website in encrypted form. This provides the attacker a large set of ciphertext samples, that can be used for statistical analysis.

IMPACT:
If this attack is carried out and an HTTP cookie is recovered, then the attacker can then use the cookie to impersonate the user who's cookie was recovered.


This attack is not very practical as it requires the attacker to have access to millions of samples of ciphertext, but there are certain assumptions that an attacker can make to improve the chances of recovering the cleartext from ciphertext. For examples HTTP cookies are either base64 encoded or hex digits. This information can help the attacker in their efforts to recover the cookie.

SOLUTION:
RC4 should not be used where possible. One reason that RC4 was still being used was BEAST and Lucky13 attacks against CBC mode ciphers in SSL and TLS. However, newer versions of TLSv addressed these issues.


Validating the Findings


Using SSLscan

#sslscan --no-failed <IP>


Using Nmap

#nmap --script ssl-enum-ciphers -p 443 <IP>


Using SSLAudit.exe









Tuesday, 19 November 2013

Hunting and Hacking MSSQL Servers - Published Article on PenTestMag.com

Me and my colleague wrote an article about how to pentest MSSQL end to end. As pentesters, we are always constantly researching on how to make our lives easier when performing ethical hacking engagements structurally and ensure that all possible methods are used based on methodologies such as OSSTMM.

We spent about a week browsing through the web and compile what could be done to properly assess a MSSQL server/services and sat down and test it on our testing servers (knowing that most customers do not allow us to exploit the systems).

So once we wrote the article, we send it to PenTestMag.com for review and cross our fingers hoping it will be reviewed and accepted. Fair enough, upon review, we had to elaborate, add, edit and explain the methods used so it will be easy for readers to understand and technically possible to follow on a step by step basis.

Hence, after all our hard work, it was finally accepted and a month later, it got published! So ladies and gentlemen, i present you some snapshots of the article! :)



The cover of the magazine


My Colleague and myself on the cover!

The content page


The first page of the article


The end of the article and our brief bio.


The article can be downloaded at:




Thursday, 14 November 2013

When it comes to Security - Nothing is Impossible

In 1995, the movie ‘Hackers’ premiered, and the feedback was unanimous: “Exaggerated! How on earth was that even possible?!”

Almost ten years on, and these ‘exaggerated’ ideas have become a reality. The film features a virus called ‘Da Vinci’ — a remote-controlled virus set to sink a fleet of oil tankers from afar. Exaggerated, right? Well, at this year’s Hack in the Box security conference, we learnt that the possibility of a virus hijacking an airline was not that far off.



An earlier film, ‘War Games’, sees Matthew Broderick playing a small-time hacker whose initial objective was simply to play games, but ends up hacking into the US Government’s mainframe. When challenged by his peers about the complexity of a system he has gained access to, he replies, “Hey, I don’t think any system is totally secure.”






This quote from a 1983 movie is still worryingly relevant in today’s society. Millions are spent on devising complex and diverse security architectures, but with every security advance, there are more determined and more specialised hackers attempting to break into the systems.

In today’s society, it takes a lot more than computer competence to become a hacker. Kevin Mitnick, one of the world’s best-known hackers and, at one time, America’s most wanted computer criminal, used simple social skills to overcome and bypass some of the most highly-secured facilities. Mitnick helped coin the term ‘social engineering’; using deception and emotional manipulation to gain access to otherwise impenetrable systems. As Bruce Schneier once said, “Amateurs hack systems. Professionals hack people.”



Electronic communications via email, chat applications, SMS, phone calls, or VoIP can all be broken down into zeros and ones. These days, communication means data, and data can mean information, which then leads to value. Controlling information means controlling the situation. Between 2007 and 2008, Chinese hackers were able to hack and control two US satellites for a total of 11 minutes, intercepting information transmitted between the satellite and NASA. Whoever gained access to the data chose not to do anything with it, but it became a landmark in highlighting issues of cyber security.


The new generation of hackers no longer just hack to disrupt services and infrastructure. They hack to take control of information and data. In the modern age of technology, the value of your data inside your flash drive could be one of the most valuable things in your arsenal.

The things that we have now, the systems we are using, the mobile phones we carry are the result of hacks that were done during the computer revolution back in the 70s. The technologies that you and I have at hand are partially the result of those people who broke the law to modify, create and innovate.

The gift of hindsight has allowed us to see the technological pathways that computer hacking has forged. Where once, hacking possibilities were at the hands of film directors and novelists, they now lie in the hands of anyone with imagination.

As industry leaders in communication, it is our job to have an awareness of the potential risks and pitfalls that hacking can create. By keeping an open mind to hackers and technological creativity, we can ensure that we are able to defend and foresee any threat in the digital world. As Einstein once said, “Imagination is sometimes better than knowledge.”


This article was also posted at http://tinyurl.com/m38xj2e

Wednesday, 13 November 2013

Winners of Symantec Cyber Readiness Challenge (Cloud Asia Expo, Singapore)

Finally we emerged as Champion!!!!
There were about 25 participants. Some grouped in 2, others went solo. But i have to say that this was a very very very tough CTF unlike the first Cyber Readiness Challenge where we got the first runner up.

This time, the organizers came prepared. There were no wireless network at the location and participants were encouraged to bring their 3/4G dongle. Me on the other hand totally forgot about it and luckily, the organizers brought some spares in case there are those people who forgot (me).

Started with a video showing the story of the situation. Once the clock starts, the challenge begins! Heck, it was one tough ride. Started with a flag that you need to be forensically knowledgable and of course, one must know LINUX!!! We took almost half an hour to figure out the first flag. But after that, it went to become tougher. Glad i used nmap to scan the whole network for live machines and start finding vulnerabilities and poking their ports. It was not as straight forward as i thought it would be.

Nevertheless, we managed to bring back glory by becoming the champion of the tournament and again, a very very tiring 4 hours event. We didnt even managed to have our breakfast. Just a cup of mineral water and a cup of coffee and off we go, non stop action.......

Kudos to Symantec Singapore for organizing such a wonderful event. I really hope Symantec will continue to organize such event in future and allow potential hackers to participate and challenge themselves in the given environment to hack, steal and win -----legally of course !

Event: Cloud Asia Expo
Competition: Symantec Cyber Readiness Challenge
Location: Suntec City Convention Center
Country: Singapore

Check out the photos:




The partnership of the Hulk and Juggernaut

Working towards winning

The 2nd Placed Winners

The First Place Winners!


Previous Symantec CRC Participation:
First Runner Up in the first ever APAC Symantec Cyber Readiness Challenge: 




Sunday, 10 November 2013

Never Give Up

In life, not many are/were born with a silver spoon. Some have to work very very hard and some simply ask and they have it. People who came from difficult background or humble beginnings are often admired when they carved their way to success. This is an article that was published on the 8th of November 2013 about how he overcame rejections and still make his way up to achieve his dream career.


Front Page
Translation:

Ethical Hacker in Global Firm

ITE graduate works hard to become a Consultant in BT

Now, he may have reached his dream of becoming a consultant  but not many know how much disappointments and rejections he faced. More than 10 years ago, with a Higher Nitec in Mechanical Electrical Engineering Design certificate, he tried to appeal to take a course in Infocomm Technology in Temasek Polytechnic but was not accepted  due to unsatisfactory results. Nevertheless, in 2005 and completed his NS, Fadli went on a hunt for a private diploma in Infocomm Security from Raffles Education Corporation. With that diploma, he hoped he would be accepted for a specialist course in Polytechnic but sadly, he was unable to be accepted. His appeal to study in both TP and NYP was rejected. According to Fadli, he was told he was not accepted because he did not have any local polytechnic diploma as part of the requirement.

Disappointed but did not give up, he tried again in 2007 and this time with another diploma in Information Technology from SMF. Once again, he got rejected due to the same reason. "I was disappointed  and worried at that time." said Mr Fadli, now 30 recalling it all back. "Disappointed as though i was ignored and worried about my loans," said Mr Fadli who loaned $16000 from a bank for his degree. He hoped he will be able to pay off all his loan of about $8000 by end of next year.

According to him, he was stubborn, searching for a career in the field of IT Security and has a huge interest in Hacking. "Im not sure why but ever since i watched the show 'Operation Takedown' and 'Hackers' i fell in love with Hacking," said Mr Fadli. Ever since that, he never gave up to chase his dream career.

In 2008, he started his degree with Murdoch University and now he has armed himself with a Degree double majoring in Cyber Forensics, Information Security Management and Business Information Systems, He is also now building up his career as an IT security consultant with BT and part of the Ethical Hacking Center of Excellence. The company offers IT solutions and services globally. 

Recently, hacking events has been the talk of the town in the media when the hacker known as 'The Messiah' and claimed to be from the group 'Anonymous' vowed to threated the IT infrastructure of the Singapore Government. PM Lee Hsien Loong told that this act is dangerous and true. Unsurprised, the services offered by the security  consultants like Mr Fadli who declared himself as 'Hacker for Hire' is on demand.

He said that he never would have thought becoming a security consultant one day since owning his first computer at the age of 18. "Without hard work, all these will never be in fruition", said Mr Fadli.

Page 17
Translation:

Hard Work is the key to Success

Work and overcoming the trials of life is not an alien concept to Mr Fadli, 30 years old. Since his father died in an accident in 1988, Mr Fadli was only 5 years old at that time and his 2 other siblings had to shift house to house while his mother goes to work. His studies was more or less affected, said Mr Fadli who had to change from school to school to accomodate the shifting of houses.

In a pressed state, his mother had to send her children to Jamiyah, Darul Mawa, an orphanage while he was 11 years old. "The challenge living in the home was many..if you think the influence in the school was great, imagine the influence you get living all day and night in the home", said Mr Fadli. Finally, Mr Fadli stayed in the home until he completed his O Levels from Serangoon Garden Technical school. 

To increase the family income, he had to work part time in a shop called Miz29 and selling satay while waiting for his O level results.

Upon completing his ITE education and National Service, he worked at HP as a media operator and then NCS. 3 years later, Mr Fadli went back to HP as a systems engineer. According to him, while getting different experiences in the field of IT, he often changed job in the hopes of getting a raise to pay off his education loans. In silence, he was still hoping to get a career in the field of IT Security.

The opportunity came when he was offered a position in BT Global Services in 2010. "Even though i had to stare at the computer for hours, i truly enjoyed my job. Not many have the interest in doing this kind of job but i loved it because of its challenging landscape and the need to have a strong sense of creativity and continuos learning," said Mr Fadli who has to always keep up with the knowledge of the neverending change of new threats in the cyber world.

"Most of the systems encountered are very vulnerable and able to be exploited and these vulnerabilities change in time," said Mr Fadli. As of now Mr Fadli has published at least 3 security articles at an international security magazine called PentestMag. Additionally, Mr Fadli was also a member of the BT team that won the hacking competition GWAPT, Catch the Flag in Bangkok, Thailand. He and his colleague also became the first runner up in the Cyber Readiness Challenge organized by Symantec last month. Next week, Mr Fadli and his colleague will be participating in another Catch the Flag hacking competition in the Cloud Expo Asia in Suntec. 

Mr Fadli, who now married with Mrs Siti Mariam realized how things have changed. Mr Fadli hopes that he would continue his studies once he completed his loans. He also advised teenagers with similar beginnings and background to never give up. "Our future will not change without hard work", he said.

Saturday, 9 November 2013

Be Humble and Shut Up

"Let sleeping dogs lie. Don't issue warnings or threats to the attackers via the media; this will only keep the issue alive, raise tempers and greatly enhance the possibility of another assault. Most DDoS attackers seek publicity, so don't hand to it to them on a silver platter." - Prolexic (The company giving advice to future targets of Anonymous)


In 2008, Anonymous attacked the Church of Scientology bringing down the website to its knees through DDoS attacks. 

The church then stepped up its security and hired Prolexic to help them guard itself from DDoS attacks which works.

But they made a huge mistake when they arrogantly announced to the media about the steps they had taken.

This attracted more Anons to attack the site and then took themselves to the streets to protest against the church. 


Moral of the story: Don't feed the trolls!

-----------------------------------------------------------------------------------------------------

In another event at the same year (2008), an Indian software company called Aiplex worked with MPAA (Motion Picture Association of America) whose job is to bring down websites that host pirated videos such as Piratebay to its knees via DDoS.



The Film Industry hired Aiplex which boasted about DDoS-ing websites hosting pirated stuffs. 


Thus began the attack of pirate websites which was lead by Aiplex
Source: http://www.techradar.com/news/internet/movie-industry-launching-cyber-attacks-on-pirate-websites-715149

And because of this arrogance stance, began the series of attacks on Aiplex which was called #Operation Payback


When the damage is done, there's no turning back. You can't simply erase your history...


Moral of the story: Payback is a bitch.