Tuesday, 28 July 2015

RSA Asia Pacific & Japan in Singapore 2015

Had a chance to visit this annual RSA conference. Though technically, i didn't attend the conference, but instead, i went for the free visitor pass to visit the vendors booth. It was a great atmosphere though it was not as huge as the likes of GovWare or Interpol. I had a great time meeting my ex-colleagues and great to see them doing well in their respective professions.

At the RSA event

Ex-colleagues at the event

Random Pictures of the Vendors Booths



















Thursday, 9 July 2015

BOMTOTAL.com - Check your Bill of Materials

Bomtotal.com is an initiative created by Codenomicon to provide visibility into the bill of materials of an application. By uploading an executable file to bomtotal.com, you will be provided with a list of components inside your executable. This will also show you not just the third party components but also the versions associated with the components. 

How to use it? 

Simply go to www.bomtotal.com and upload any binary file to the site

Once uploaded, you will be shown the version of the application, the third party components used and the versions associated with it.

Why do you need the BOM?

In early December 2014, representatives from the US introduced H.R. 5793, the "Cyber Supply Chain Management and Transparency Act of 2014." The legislation will ensure all contractors of software, firmware or products to the federal government provide the procuring agency with a bill of materials of all third party and open source components used, and demonstrate that those component versions have no known vulnerabilities.


Which means, that the the "Cyber Supply Chain Management and Transparency Act of 2014" requires any Hardware/Software/Firmware sold to any agency must come with the Bill of Materials and vendors must prove that their HW/SW/FW must not use known vulnerable components or at least a less vulnerable version.


Wait a minute! BOM and Vulnerable components? 

By default, bomtotal.com do not provide the information whether or not the version of the components used are vulnerable. However, while Codenomicon's Appcheck is solely designed for this (and much much more visibility/reports/formats/interface), we can find out whether or not the components are vulnerable based on the version information manually. 

Taking example of the Citrix application that we have uploaded to Bomtotal.com, we can see that there are 2 components used. One is an OpenSSL with the version 0.9.8. 

Knowing the version, visit www.cvedetails.com and search for the version of the component


Select the appropriate link


And tadaaaa, you can see all the vulnerabilities associated to the component.


How this helps Organizations?
Having visibility to the BOM is one thing, knowing the vulnerabilities associated with the components is another. As stakeholders of the organization, one can have the transparency of the software composition during initial stages of procurement of software. Also, this will provide managers to understand the risks involved of an executable even before installing it to the corporate environment thereby making calculated decisions based on the risks involved. 

Advantages for Bomtotal.com

It is designed as its name, to provide the Bill of Materials of an application. Nothing more than that. Codenomicon's Appcheck does provide the BOM and more with automatically providing all the versions as well as the vulnerabilities associated with them, visibility of licenses used in these components, remediation via instant simulation, report generation in multiple formats and many many more. While the manual way can be done, it is definitely time consuming if one were to upload GBs of data size and contain hundreds to thousands of third party components. Surely, automation definitely helps alot in this form of binary analysis through software composition analysis via Codenomicon's AppCheck.

Curious about the power of AppCheck? Check out the link to find more information about it.






Tuesday, 16 June 2015

Null Singapore Security Meetup - June



Null Singapore is back for the fifth time and like last month, it was a full house and another record of an attendance! Credits given to NSHC Pte Ltd for providing us a room for us to have our meetup.





We start our meetup by introducing ourselves, what Null Singapore is all about, its aims, its objectives and how does this meetup benefit the audience from networking to potential cooperation with one another. This was presented by Prasanna or PK as Imran, the chapter leader was away.



Randen then presented on the security news bytes, the security events that happened in the last few weeks ranging from malware, phishing and critical infrastructures.



Michael Heinzl, from SEC Consult presented on the topic 'Finding vulnerabilities using Fuzzing'. It was an interesting topic as he demonstrates how fuzzing assist in the finding of unknown vulnerabilities and how such vulnerabilities could be turn into an exploit to further penetrate into the systems/applications. Sharing statistics of his research and end with a cool demo, Michael was able to show the audience not just in a theoretical sense but in a practical way as well.



Vincent Tan, from Vantage Point presented on the topic 'Breaking BYOD in IOS'. This was an extremely interesting talk as he shares his research and how IOS can be broken into with tools that he developed. I would not dive into the contents of his presentations (as agreed), but i'd say the delivery of the presentations, the demonstrations and the key takeaways are properly formatted and presented.



Both presenters ended with a round of applause and it was really great to see people enjoying the presentations and coming up to the speakers to know more about it. Alas, after it was all over, the 'after scene' networking session starts. I see people from different companies shaking each other's hands, getting to know each other despite the 'competition'. This is exactly what security meetups are all about... in conferences, we are never competitors...we are all enthusiasts...






Join us and get informed:

Wednesday, 20 May 2015

Null Singapore Security Meet Up - May


Null Singapore is back for the fourth time and this month's meetup was by far the best turnout with almost 60 people (it was around 18-20 people for the first one). Just like the previous month's meet up, it was held at ThoughtWorks (thanks to Prasanna K again and again for the location) 




As usual, started with introducing what Null Singapore is all about, the head organizer, Imran, shared with the crowd the objectives, benefits and direction of Null Singapore and how this meetup aims to help people gain knowledge and network with security pros, enthusiasts and professionals, n00b or expert, everyone has something to offer. 




Stefan from Vantage Point presented on an interesting topic 'Why Pentesting Sucks' on which he shared the challenges faced in developers as well as penetration testers on application security and the loopholes that exist in the software development process when it comes to security. I presented a comment and scenario where certain situation, organizations who buy software do not have access to its source code thus its tough to tackle the security assessment in the development stage of the software. This comment however turned out to generate a number of rebuttals and spurned into a mini discussion between the members of the audience providing their points on how that situation can be tackled through procurement processes and trust between the company and the software vendors. Definitely a potential avenue to have panel discussion with the audience in future meetups.





Prasanna K from Thoughtworks, then presented about hacking hypervisor, specifically Xen hypervisor in which he, not only shared the theory of the topic but also the practical demo on how easy it was to gain root access to the virtual machine from a less privileged user through taking advantage to one of the source codes. 




Overall, i believed it was a great turnout and again i had fun especially seeing more people attending the meetup. I can't wait to see what future will it holds for this Null Singapore... who knows it can be as awesome as BSides conferences! Now thats what i wanna see!

Follow and add yourself to Null Singapore. We are Social! Click on the images below to be part of it..

                                                 
                                                                    


#include <iostream>
using namespace std;
int main ( )

cout << "You Guys are Awesome" << endl;
return 0;
}