Ads

New Domain

Blog has been moved to new domain: www.it-googled.com Enjoy!
Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Tuesday, 23 August 2011

Revised Security Auditing

Security Auditing


Security auditing is not very appreciated process within any organization due to the fact that someone external is going to check already hired individuals and their skills. It may be a bit difficult to explain why security is so important and why certain mechanisms should be implemented especially for non-technical management. On the other hand some businesses can appreciate the benefits from security auditing for in result many weaknesses are identified and countered or advise on better software or hardware is given to save that organization’s money.

The mechanism for security audit is hardly ever standard due to difference of environment between companies. Techniques such as interviews, vulnerability scans and observation/analyses are steps undertaken by security auditor. Often the companies’ security policies and procedures need to be analysed not only to check if there is lack of consistency within those documents but also to base the analyses and mechanism of auditing on these policies. CAAT’s (Computer-Assigned audit Technologies) are utilities to generate system reports that store all the logs and configuration files and sometimes even monitor activities. I think that it’s very useful as the information can be very well formatted and display to an auditor without him going into specific directories/volumes or configuration files to get the information needed. Some of these tools actually have programmed patterns of for instance default configuration files which are being matched to the tested system configuration files and it flags the auditor when positive.

Considering auditor role as an investigator there are certain areas that are need to be checked for instance the way the passwords are generated or the way backups are stored often by asking all sorts of questions based on the auditors experience. I think the very important issue to observe is that some companies have got their own internal auditors/security consultant/officers which can help however to gain objective system audit an external auditor is a must. In many companies that is a way to check how the IT Department is developing and progressing. External auditor will produce the report on their achieved goals and aims for the next audit. That is normally the formal report produced few weeks after the audit takes place. Some institutions like Higher education or some government bodies have a law that impose to make sure that externals audits are up to date and consistently maintained.

John Edwards. (2008). The Essential Guide to Security Audits. Available: http://www.itsecurity.com/features/security-audit-essentials-042908/#comments.

Friday, 1 July 2011

LulzSec malware hoax

"IDG News Service - The LulzSec hacking group sailed off into the sunset Saturday, leaving behind a treasure trove of stolen data along with what some antivirus programs identified as a nasty surprise for anyone who downloaded the Torrent file: a Trojan horse program.

But not so fast. On Monday several antivirus vendors took a close look at the file in question and decided that the program wasn't actually harmful. Consider it an inadvertent parting prank on the security industry the hacking grew took such delight in tormenting. More Lulz for the Lulz Boat.

Early in the day, 26 of the 42 security companies whose scanning products can be tested on the VirusTotal Web site reported that a file within LulzSec's "AT&T internal data" folder was malware, designed to give hackers remote access to the victim's computer.

But by Monday night Kaspersky Lab, McAfee and Trend Micro all reported that this was incorrect. According to Roel Schouwenberg, a researcher at Kaspersky Lab, other companies are flagging the file as a Trojan because it used pirated WinRar compression software that made the file look very similar to known malicious programs. These pirated compression programs are often used to compress malicious files and "a lot of companies are quite aggressive with these detections," he said in an interview.

In its final press release, LulzSec blamed the whole thing on AT&T, warning readers not to open the file and saying, "it is malware (due to AT&T using a pirated copy of WinRar)"

The file in question has reportedly been pulled from the LulzSec torrent, but the incident added to the chaos and confusion that the LulzSec crew seemed to love leaving in its wake.

LulzSec took particular pleasure in causing trouble for security companies, especially those it saw as aiding its enemies -- such as Prolexic, a provider of denial-of-service attack mitigation services, thought to be securing Sony's networks, and Endgame Systems, a company with links to the U.S. Central Intelligence Agency. The hackers released dox -- dossiers of information including phone numbers, addresses and online profiles of the executives at these companies and their family members." By Robert McMillan
June 28, 2011 04:14 AM ET
Good article written by Robert McMillan


LulzSec did it again, by proving that such companies are not protected against an entry-level hack. For the last few weeks I gathered that using some hacks dated back to 2002 still works due to loads of unpatched web servers/DNS servers etc. Seem like LulzSec in some sense will add importance and increase the level's of security worldwide.It's a Machiavelli's way to do so and many companies,students,entry-level IT staff will suffer. As for us professionals we have to make sure that we patch and monitor our system pro-actively on regular bases.

Final thought

Shouldn't authorities learn from them?!

Tuesday, 28 June 2011

LulzSec - my view on security

"The hacker group LulzSec released what it said are sensitive documents from the Arizona Department of Public Safety today to protest the agency's "racial-profiling anti-immigrant" policies.

Read more: http://news.cnet.com/8301-27080_3-20073843-245/lulzsec-releases-arizona-law-enforcement-data/#ixzz1QYXsKJr8"

I don't know what to think any more. I am not supporting them , I am not against them.
There are so many companies who don't hire enough IT professionals to protect their systems/networks and there are companies that do however they can't really monitor it efficiently.

The times where we could set up firewalls and zones and then just sit back and drink coffee are passed although loads of Network/Security Officers still think they are in the dreamland. IDS,IPS,Honeypots are a must and even if implemented won't guarantee the confidentiality, integrity and availability. Most of the companies who got hacked and reported it (rare) are the victim due to a lack of updates on their systems rather than 0 day exploits. It's quite easy these day for script-kiddies to download the existing tools and pull of some attacks which is also a problem for insecure companies. The number of web severs running on the old worldpress,apache etc are so massive that without proper knowledge and just by using existing tools can be all hacked as we speak.



Apparently UK spent loads of money on cyber-crime this and coming year, how come you can't see what they are doing? Fighting face-book abuse??!

Friday, 24 June 2011

Dropbox - no authentication for 4hours?! Rainy Clouds


Just when the world start to believe and use cloud computing Dropbox addmited having issues with their authentication systems on the 20th of June where anyone could log in on any account without correct password. Another question is the lack of encryption of the sync where files can be seen in plain text.

http://www.cio.co.uk/news/3287251/dropbox-hit-by-password-failure/?olo=rss

Wednesday, 8 June 2011

Honeypots , HoneyBOT vs Honeyd

Honeypot is a device on the computer network designed to capture malicious traffic. It disguises itself as real production system but contains dummy information. Often located behind the firewall inside the network and it is used to learn about intruders and detect vulnerabilities. Any connections to it on strange ports may mean that they may be a vulnerability or wrong configuration on the firewall. It can also disguise itself as routers or firewalls. Honeypots are becoming leading security tools especially detecting latest tricks and exploits.

Brief Overview

HoneyBOT – brief
“Development began as a small project to capture attacks of Code Red and Nimda worms which were propagating widely on the internet “in 2001. In September 2005 they had first public release and it’s maintained by Atomic Software solutions.

HoneyBOT open a large number of listening sockets on computer where it is installed. These sockets appear open so that any attempt to connect to them or even an attempt to scan a port is logged as shown on the Figure A1. It requires windows operating system and it has its own graphical user interface therefore is quite user friendly.



Honeyd.- brief

It has been created and developed by Niels Provos who is a Principal Engineer for Google Inc. It has been released it in 2007 under GNU General Public License therefore it developed rapidly due to many people who contributed by fixing bugs and developing the code.

Honeyd is a small daemon that allows you to create virtual nodes on the network.
They can disguise themselves as any operating system or device such as router or switch. It offers wide range of functionality for instance it allows for virtual host to claim multiple addresses. It is supported on unix based operating systems with some attempts towards windows platform - even more complex to set it up.



HoneyBOT functionality.
It has very simple and straightforward options. Even thought by default it opens large number of services (1339) it allows for selection of ports to be opened as well.
It has a build in email alert function that sends a daily e-mail with all the log files.It also checks for updates and allows for anytime log export.

Honeyd Functionality.
Honeyd is far more complex in terms of functionality, it emulates different operating systems using the same fingerprint database used by nmap (nmap.prints).It also can disguised itself as routers, here’s example:

create router
set router personality "Cisco 4500-M running IOS 11.3(6) IP Plus"
add router tcp port 23 "/usr/bin/perl scripts/router-telnet.pl"
set router default tcp action reset
set router uid 2500 gid 2500 set router uptime 1736485
bind 192.168.1.150 router
Another important function is ability to run subsystems, as in above example of router there is a script that is added to the port that will creating some interaction between the system and attacker. With the large number or these so called subsystems it’s possible to create the most ‘real’ environment and log the attackers moves.
An example of outcome for telneting into above router shown below:





I believe that two tools that I have compared has many strengths and weaknesses. Starting with HoneyBOT it is very easy to install and use due to graphical user interface and very user-friendly controls, there is plenty of web based guides and support and updates provided by Atomic software solutions. The weakness is the default configuration that opens more than a thousand ports which makes it look too obvious rather than a real production server. Another disadvantage is the way the file logs are presented , without any sort of programming skills to apply some filtering it may be really time talking to go through them in order to indentify the attacker. Lastly the fact that it’s a really small application and requires an operating system to run is a huge weakness due to power consumption, cost and management.

Honeyd is quite advanced in terms of functionality, it allows to create multiple honeypots at the time and to link multiple ip addresses with one honeypot. It can disguise itself as a real production system due to subsystem functionality that enables to run perl scripts that are executed while intruder tries to connect. Additionally it can also emulate routers and actually route traffic therefore ‘disguised’ network topologies may be created .Daemon is really small and it doesn’t need a dedicated server to run, all of the above can be managed from a single configuration file which is a big advantage. The most important weakness is the complexity of advanced functions and hardly any support.

To conclude even though honeyd scored slightly less points than HoneyBOT I believe it’s a better piece of software. The scope for further development is extraordinary, the implementation of the whole spoofed networks with subsystems and routing is just great environment for detection of latest exploits etc.It has some weaknesses but in my opinion support will come as soon as people realise the potential. The developer is currently working on the new release.

Wednesday, 19 January 2011

ITU X.800 brief overview

ITU X.800 is a security/threat model for end to end communication.
Standard consists of Planes and Layers as well as security dimensions to provide very efficient Architecture and security for end to end communication.
There are eight security dimensions addresses to network vulnerability which are listed below with brief explanation and a way of how can they be implemented:

• Access Control – as it can be understood by its name it controls the access to services such as routers, switches, firewalls etc. Implementation can be done in the configuration of such network element or host and for example linking authentication server with these elements.
• Authentication – request of proving subjects identity by for instance digital certificate.
• Non-repudiation – as far as I understand this section keeps the logs and has abilities to do some actions.
• Data Consistency – Provides for instance encryption based on our organization file classification to make sure that our sensitive data is protected.
• Communication Security – that’s security between point A and B. Uses of non-obscured protocols such as VPN so that sniffing or eavesdropping becomes very unlikely.
• Data integrity – checks that both incoming and outgoing data is correct – means for instance if we request 308kb we should receive the same size file on the destination host.
• Availability – makes sure that legitimate users have got access to all necessary network elements and application according to what they suppose to do (role).
• Privacy – provides again encryption of data as one way of implementation but also for instance Network Address Translation (NAT) to protect internal hosts and redirect all the incoming traffic to the border firewall.


Zachary Zeltsan,. (2005*). ITU/IETF Workshop on NGN

Wednesday, 12 January 2011

E-mail spoofing - brief

How easy is to spoof a e-mail address. All can be achieved by a simple PHP code accessible in many places across the internet. It often contains a html website layouts and signatures therefore it becomes even harder to detect. Most of the times it's being broadcast-ed to thousands at the time. Its a great tool to get some credentials or other personal information. It can also be used as a small clever denial of service attack depends on the target and aims.

$frm = "John@microsoft.com";
$attn1 = "Steve@bbc.co.uk";

$subject = 'Hi Steve';


$message = "
Hello x,

info,
malicious link

John \n
";
$from = "From: $frm\r\n";
mail($attn1, $subject, $message, $from);
?>

Wednesday, 15 December 2010

Security Auditing

Security auditing is not very appreciated process within any organization due to the fact that higher up people like managers would not like to have imposed any rules and due to the fact that they are not IT professionals it may be a bit difficult to explain why security is so important and why certain mechanisms should be implemented. On the other hand some businesses can appreciate the benefits from security auditing for instance when certain weaknesses are identified and countered or advise on better software or hardware is given to save that organization’s money.
The mechanism for security audit is hardly ever standard due to difference of environment between companies. Often techniques such as interview, vulnerability scans and observation/analyses of the logs etc are steps which security auditor undertakes Often the companies’ security policies and procedures need to be analyse not only to check if they may be an issue within those documents but also to base the analyses and mechanism of auditing on these policies. CAAT’s (Computer-Assigned audit Technologies) are utilities to generate system reports that store all the logs and configuration files and sometimes even monitor activities. I think that it’s very useful as the information can be very well formatted and display to an auditor without him going into specific directories/volumes or configuration files to get the information needed. Some of these tools actually have programmed patterns of for instance default configuration files which are being matched to the tested system configuration files and it flags the auditor when positive.
Considering auditor role as an investigator there are certain areas that are need to be checked for instance the way the passwords are generated or the way backups are stored often by asking all sorts of questions based on the auditors experience. I think the very important issue to observe is that some companies have got their own internal auditors/security consultant/officers which can help however to gain objective system audit an external auditor is a must. In many companies that is a way to check how the IT Department is developing and progressing for example the University of East London Dean’s assistants or so called management board may not be full of IT professionals so it may be difficult to judge the amount of work and progress the IT Department is doing, therefore by using an external auditor Dean or management board will receive the report on their achieved goals and aims for the next audit – if that is several visit of an auditor. That is normally the formal report produced few weeks after the audit takes place. Some institutions like Higher education or some government bodies have a law impose to make sure that externals audits are up to date and consistently maintained.

John Edwards. (2008). The Essential Guide to Security Audits. Available: http://www.itsecurity.com/features/security-audit-essentials-042908/#comments.

Tuesday, 14 December 2010

Communication Security threats

Communication will always require a certain security due to the sensitivity of information being stored. Networking can be explained really simple; all we have to do is send information from point A to the point B, although there are many of complex processes carried out while the information is being transferred. As the information is being sent from A to B is forwarded using different routes using Routers, Switches, Access Points, Firewalls etc, therefore is even more difficult to secure it. There are many threats to communication security therefore I have listed the most important ones by my understanding and experience.
Main vulnerabilities are:

• Packet Sniffing – when an intruder listen to the network traffic and analyses the packets having a possibility to read our incoming and outgoing information using obscure protocols (eg.FTP) in Voice over IP protocol also known as eavesdropping.

• IP Spoofing – where an intruder sends the packets to our network and disguises himself as a trusted host (that we could have communicated with in the past) or in order to try Denial of Service attack so that the packets are reflected on the actual target.

• Password breaking – where there are many methods, brutal-force using rainbow tables or disguising as trusted entity sends requests to the target to confirm his username and password (also known as phishing).

• Man in the middle attack – it’s an attack where intruder attack someone who has already established a trusted communication with us, for instance subcontractor or another company we do business with, therefore because our network is too secure intruder attacks less secure network we have connection with.

• Denial of Service attack – occurs where intruder is sending extremely high amount of packets/information so that our network/server can’t handle it. Sometimes it may be caused by the number of users using certain services at the same time causing ‘legitimate’ denial of service.

• There are also all the other threats that affect communication security like spyware, malware ,viruses ,Trojans ,backdoors ,net boots and other malicious software all designed to interrupt the confidentiality of our information to retrieve it or destroy it.

• General vulnerabilities – operating systems bugs, protocol bugs, transfer medium failure, data storage failure and bad organised physical security (data centre doors wide open).

Microsoft. (2007). Common Security Threats. Available: http://technet.microsoft.com/en-us/library/bb964031%28office.12%29.aspx.