Monday, June 23, 2014
nfosec Professionals Don't Trust Endpoint Security
21 June 2014
End users are the cybersecurity staff's worst nightmare.
When it comes to endpoint protection, the overwhelming majority of information security professionals believe that their existing security solutions are unable to prevent all endpoint infections, and that anti-virus solutions are ineffective against advanced targeted attacks. Overall, end-users are their biggest security concern.
In a recent survey from Bromium, nearly 85% of respondents believe that their existing security technology is unable to prevent endpoint infections. Despite the proliferation of layered security solutions, attacks continue to exploit common vulnerabilities in operating systems, applications, browsers and plug-ins.
“The reality today is that existing endpoint protection, such as AV, is ineffective because it is based on an old-fashioned model of detecting and fixing attacks after they occur,” said Rahul Kashyap, chief security architect at Bromium, in a statement. “Sophisticated malware can easily evade detection to compromise endpoints, enabling cybercriminals to launch additional attacks that penetrate deeper into sensitive systems. Security professionals should explore a new paradigm of isolation-based protection to prevent these attacks.”
When it comes to AV specifically, nearly 85% of respondents believe that anti-virus solutions are unable to protect against advanced targeted attacks. That’s because sophisticated malware is designed and tested to ensure it evades current security technologies, such as signature-based detection and behavioral analysis.
End-users, meanwhile, are a weak link – nearly 75% of respondents believe that end-users are responsible for their biggest security headaches. End-users become infected by drive-by downloads, malicious URLs and email attachments, impacting productivity as security teams work to resolve compromises or restrict access.
“Despite the challenge in protecting end-users, it is encouraging so many security professionals are aware of the shortcomings of existing technology,” added Kashyap. “The recognition that the status quo is broken is the first step toward changing it for the better.”
Additional results from the survey found two-thirds (65%) of information security professionals are looking for endpoint protection that can stop both known and unknown threats. Further, three-quarters (75%) stated they would sleep better at night knowing a user could click on anything at any time without risk of infection.
This article is featured in:
Industry News • Malware and Hardware Security • Wireless and Mobile Security
Sunday, June 22, 2014
Terrible State Of Financial Software Code Plagues Investors
Comment Now
Follow Comments
The terrible state of software code in elements of the financial industry, including at locations linked to major trading venues, is a plague to investors and remains a ticking time bomb ready to badly damage the wider economy.
That is the verdict of several high-profile financial experts, who have warned of the widespread problems. Their comments follow a several-hour dive in the Dow Jones and S&P 500 that resulted from an apparently serious code flaw at the Institute of Supply and Management earlier this week – making that body release entirely incorrect US manufacturing figures.
While, as a whole, software coding in the financial trading arena is at the cutting edge of technology, costs in total billions of dollars a year and is perfected by some of the most talented software developers, some companies’ serious omissions are causing big problems and on occasion badly hitting the wider US economy.
Chris Skinner, chair at networking group the Financial Services Club, tells Forbes that several of these software errors are potentially serious for the economy, given the fact that in any one second of trading, enormous numbers of trades are processed. Wrong code can badly knock both automated and manual trade execution right off kilter.
The ISM situation, for which a detailed explanation has still not been given several days on, is “an example of both the interconnectivity of systems and the impact of real-time”, Skinner says. After the ISM released inaccurately low US manufacturing figures, the Dow Jones and S&P 500 dived by 34 points and 0.4 per cent respectively as traders rushed to sell stock – until the ISM corrected its figures later in the day, apologizing for the problem.
The ISM declined to reveal more details on what happened to its code, when asked, because of an ongoing internal investigation into the problems.
Money
Money (Photo credit: Tax Credits)
“When data is wrong, either through cyber attack or poor software,” Skinner says, “the markets respond in real-time by buying or selling based upon a belief in their data being right”. The failure of the ISM to solve its own problem was completely “dirisible”, Skinner says.
Risk Of Many More, And Worse, Problems
The confused state of software coding in some parts of the market is so bad that one expert says he is “surprised” there have not been many more of these problems. Ralph Silva, head of financial industry analysis firm SRN, says that the danger is partly caused by the serious disparity between the ways that coders and the heads of trading operations approach numbers.
In the days of Excel, when algorithms were much more straightforward (and achieved less) it was at least those who “actually understand the foundation of the math” who wrote and maintained the code. There is no desire to return to Excel because of low capabilities in a complex arena, so the connection between coders and business executives must improve to safeguard current code, Silva says.
“Today, algorithms are written to very elaborate coding systems that require specialised technical support. These people understand code, not business. They are more likely not to recognise a bad number,” he says.
There will likely be more of these problems in the future, as algorithms become more complex in order to meet the market’s appetite for advanced execution. “Ten years ago, the average algorithm would consider about four data sources,” Silva says. “Now we have algorithms considering 200, and that level of interdependency is going to cause problems.”
The awful economic climate of recent years has also seriously damaged the way in which software code is checked. Silva says that as companies continue to cut back costs, they usually – and mistakenly – remove testing and quality assurance staff because those people, “if they are doing their jobs, appear to be doing nothing – it’s like the CIA, you only hear about them when they screw up”.
How Can This Problem Be Solved?
Emmanuel Benzaquen, chief executive at code analysis firm Checkmarx, says that businesses need to constantly test code during development as well as when it is live, with sophisticated systems making the work more reliable. “Nowadays, testing is performed with automated tools that alert when a vulnerability is found,” he says.
The financial industry needs to pay particular attention to get its code right, given the “vast amounts of customer data and monetary funds” that it holds. For attackers to penetrate a system, they often look at the way to exploit “a vulnerability that exists in the company’s software”, he says, with coding errors being a prime target.
“Severe security flaws in the financial markets can allow access to enormous amounts of consumer data,” he warns, “and may also enable attackers to perform transfers and manipulate dollar values”. A breach could also lead the company that has been attacked to break regulatory rules, leading to a severe fine.
While the market tries to forget Monday’s events, and enjoys a substantial rise in the Dow Jones on Friday after positive US jobs data, the need for quality assurance and proper code testing is back in the spotlight. It is the accuracy and commitment to getting these processes right that can make or break not only the businesses involved, but the entire market’s stability.
More on Forbes:
Why Libor Urgently Needs Automation
ISM Software Code Knocks Down US Manufacturing, Dow Jones AND S&P 500
Volcker Compliance: The Ultimate Big Data Challenge
For more news for CIOs , with a special focus on social media, women in tech, security and breakthrough technology at the world’s largest organizations, follow me on Twitter. Please share your thoughts below.
Contents:
Intro
» What is a troll?
» Design Issues
» Content
» Newsgroup Selection
» Know Your Audience
» Following-Up
» The Successful Troll
» Troll RFC
« Beware of the troll
« Win online arguments!
« Mag homepage
Trolling the web: a guide
By Steve Spumante
There are some individuals out there who don't just enjoy winding up people on newsgroups and bulletin boards - it's their sad lifestyle choice! Using every known disruptive trick in the book, these troublesome types don't go out to the pub, meet members of the opposite sex or enjoy life. They spend their time hunched over their computers trolling.
Here's how they work:
INTRODUCTION
The object of this post is to bring together a definitive document to cover the phenomena of the Usenet Troll. To many a troll is nothing more than an annoying method of defeating the killfile whereas to the heavily killfiled, trolling can be a virtual Godsend.
What I want this document to focus on is how to create entertaining trolls. I have drawn on the expertise of the writer's of some of Usenet's finest and best remembered trolls. Trolls are for fun. The object of recreational trolling is to sit back and laugh at all those gullible idiots that will believe *anything*.
Section 1: What Is A Troll?
The WWW gives this as a definition:
troll v.,n. To utter a posting on Usenet designed to attract predictable responses or flames. Derives from the phrase "trolling for newbies"; which in turn comes from mainstream "trolling";, a style of fishing in which one trails bait through a likely spot hoping for a bite.
The well-constructed troll is a post that induces lots of newbies and flamers to make themselves look even more clueless than they already do, while subtly conveying to the more savvy and experienced that it is in fact a deliberate troll.
If you don't fall for the joke, you get to be in on it.
The following extract is from a broader expansion of the defining comments given above:
In Usenet usage, a troll is not a grumpy monster that lives beneath a bridge accosting passers-by, but rather a provocative posting to a newsgroup intended to produce a large volume of frivolous responses.
The content of a "troll posting generally falls into several areas. It may consist of an apparently foolish contradiction of common knowledge, a deliberately offensive insult to the readers of a newsgroup, or a broad request for trivial follow-up postings.
There are three reasons why people troll newsgroups:
People post such messages to get attention, to disrupt newsgroups, and simply to make trouble.
Career trollers tend for the latter two whilst the former is the mark of the clueless newbie and should be ignored.
top
Section 2: Design Issues
A troll is no different to any other Usenet posting. That needs to be stressed.
Any article that you decide to write should be written with a view to it actually being read by large numbers of people. Simply X-posting to large numbers of irrelevant newsgroups is not creative trolling - it is just spam and should be avoided.
The experienced troller spends time carefully choosing the right subject and delivering it to the right newsgroup. With trolls, delivery is just as important as the subject.
Start the troll in a reasonable and erudite manner. You have to engage your readers' interest and draw them in.
Never give too much away at the start - although a brief abstract with hints of what's to come can work wonders.
Construct your troll in a manner to make it readable. Use short paragraphs and lots of white space. Keep line length below eighty characters. Use a liberal amount of emphasis and even the occasional illustration.
A good rule of thumb is that as your troll becomes more and more ludicrous put extra effort into the presentation - this keeps the mug punter confused. Let confusion and chaos be your goal
top
Section 3: Content
Make your subject a relevant one. Posting "Star Trek Sucks" into hk.forsale is not going to work very well and is liable to utterly destroy your hard earned reputation as a troller overnight.
You do not have to make the subject clear. Trolls are aimed at two audiences, the respondees and the lurkers.
The best trolls reveal their true subject only to the lurkers. In every sense those who reply to your troll are your tools. So choose a theme for your troll and stick to it.
Outwardly you need to appear sincere, but at the same time you have to tell your *real* audience that this is blatant flamebait. Your skill is shown in the easy way that you manipulate large areas of the Usenet community into making public fools of themselves.
top
Section 4: Newsgroup Selection
Choice of newsgroup is as important as the subject, tone and structure of the troll. You want to appeal to each group you X-post into to ensure responses from each group.
A well delivered troll will anticipate what those responses will be and thus ensure that contradictions will arise amongst the different groups that you are setting up.
BAD:
Posting "USA Sucks" to alt.nuke.the.USA, alt.usa-sucks, aus.flame.usa
This is totally on-topic and obvious. A truly useless troll.
AVERAGE:
Posting "God Doesn't Exist" to all the alt.religion newsgroups
Here you are being too obvious. People recognise this sort of trouble making and have usually learned not to respond to it. However, if your troll is well written you can actually entrap a lot of newbies.
This, if executed correctly, can be exploited to cause great offence to those more experienced troll avoiders on the groups you are attacking. Go for it!
GOOD:
Posting an article that appears relevant to every group but with no connection between those groups other than the fact that you've just trolled them.
The best trolls go out to an average of around eight or nine newsgroups. This will stop them from becoming spam as it's not quite enough to be a real problem. However, to get by on so few groups you have to include a couple of popular ones in the list.
When posting to say seven groups you should try to break down your theme into seven areas - each of which will be of specific interest to just one of those groups.
You then write an eight paragraph troll with a paragraph for each group and a spare one for yourself with which to lob in a gratuitous insult to everyone who was dumb enough to read your troll.
It is a matter of choice whether you choose newsgroups before or after writing the troll.
Some experts claim that newsgroup selection is the key to successful trolling and should be done first, others will write general trolls and then apply the standard Perl script that trollers use for Automatic Random Newsgroup Selection.
top
Section 5: Know Your Audience
Remember that you have two audiences. The people who are going to get the maximum enjoyment out of your post are other trollers. You need to keep in contact with them through both your troll itself and the way you direct its effect.
It is trollers that you are trying to entertain so be creative - trollers don't just want a laugh from you they want to see good trolls so that they can also learn how to improve their own in the never ending search for the perfect troll.
The other audience is of course the little people in those newsgroups that your are attacking. Get to know them. Every newsgroup has its smartarse who will expose your troll if given half a chance.
Research your targets and learn what their arguments are. Then avoid those arguments like the plague.
Drag them off-topic - the further off-topic the better. Remember, you are trying to waste their time.
Never take sides - remember that your goal is not to win an argument, rather it is to provoke a futile one that runs forever.
If, for example you were attacking Fast Food then you should also X-post to Healthy Eating groups, Environmental Protection Groups, Animal Rights Groups etc....
You want to try to ensure that you have the broadest possible range of opinions as this is the easiest way to sow confusion.
The more confusion the less the likelihood of your troll being exposed for what it is.
It can also be shown that the inclusion of just one totally off-topic newsgroup can have dramatic effects.
The list above is taken from a genuine troll which also included an Artificial Intelligence group, the result of which was to draw Computer Guru Professor Marvin Minsky into a flamewar concerning Ronald McDonald's exploitation of the disabled - an all-time classic piece of trolling - written by a practising veggie.
top
Section 6: Following-Up
"Even if this is true......"
That represents the perfect response to any troll. The mark of a gullible lunatic that will almost certainly believe anything you tell them. A total group embarrassment. Award yourself a Troll Gold Star every time you get one!
Other good responses include, but are not limited to....
"Although this is on-topic....."
"I disagree...."
"Yes, but....."
"Can you provide a source for this...."
Try not to follow-up to your own troll. The troll itself quickly becomes forgotten in the chaos and if you just sit back you can avoid being blamed for causing it.
Remember, if you do follow up you are talking to an idiot. Treat them with the ill-respect they deserve.
You should also learn to recognise follow-ups from your fellow trollers. Sometimes an average troll can be elevated into majestic proportions when several trollers spontaneously join forces via the medium of the follow up troll.
Ignore cries of wasted bandwidth! This is pure drivel that will always be posted by the anti-troll lobby.
These jerks fail to understand that trolls are the best way to drive people off the internet thus making available multi-mbs for the rest of us to download our porn.
top
Section 7: The Successful Troll
A good example of troll success is the famous "How I Envy American Students" troll.
This troll was written by an English brick-layer posing as an American student. He correctly posted it to all the college news- groups and then left american students to do all the work spreading it.
His troll ran for over a year, it is known to have generated in excess of 3,500 responses (an average of 1 response every 160 minutes for a whole year) and the greatest coup of all was when an innocent american student lost not only her internet account but was also expelled from high school for abuse of the computer systems.
Somehow she had managed to get the blame for causing the troll.
top
Section 8: Troll RFC
Applications are requested for a standard API to the existing troller's tool the "Automatic Random X-Post Generator" - now in pre-release beta.
Experienced trollers and recovered trollees are invited to submit items for inclusion in this FAQ.
We are indebted to the author, trollfaq@altairiv.demon.co.uk, for permission to reproduce this piece.
FURTHER READING:
« Beware of the troll
« Win Usenet arguments!
EXTERNAL LINKS:
« Usenet Anti Troll FAQ
« Trolling Lore
Massive Cyber Security Tools list 2013
Submitted by CWZ on Wed, 05/08/2013 - 15:17
This list is an collection of cyberwarfare and cybercrime tools. Security tools that have been collected from the internet can be found here. They all have an legit and trusty source.
The tools that criminals use are mostly the same tools that security experts use to audit their systems. This goes the same for cyberwarfare and cybercrime tools. Cyberwarfare or hacktivism tools like DDOS scripts are used by pentesting experts to pentest and audit an environment.
Security tools like Firewall Analyzers and password cracking tools are needed to create and provide secure environments. This list offers an wide range of tools: real time protection tools, portable anti virus programs, anti rootkit tools, sniffing tools and several company provided tools.
Cyberwarzone has listed several cyber security tools to help you gain an better understanding of security.
Most of the products you can find for security are paid security solutions. Cyberwarzone has tried to collect tools that are being provided for FREE. So if you need an free cyber security tool then you are at the right address.
Backbox
Pro-actively protect your IT infrastructure with BackBox. It is the perfect security solution; providing pen-testing, incident response, computer forensics, and intelligence gathering tools. The most current release of BackBox Linux includes the latest software solutions for vulnerability analysis/assessment and pen-testing. It is one of the lightest/fastest Linux distros available on the Internet.
Download Backbox 2013
Kali Linux
From the creators of BackTrack comes Kali Linux, the most advanced and versatile penetration testing distribution ever created. BackTrack has grown far beyond its humble roots as a live CD and has now become a full-fledged operating system. With all this buzz, you might be asking yourself: - What's new ?
Security tools
You can find a lot of security tools on the internet. But it is hard to find the right tool for the right job. Here you will be able to download firewall analyzers and several security tools. Cyberwarzone has listed these tools for you.
If you believe we missed out on a security tool you can send us an message or simply post it as an comment.
Real time protection
Avast!
Free
Ad-Aware
Free
AVG
Free
Panda Cloud
Free
Avira free antivirus
Free
Microsoft Security Essentials
Free
Comodo
Free
Fprot (with Returnil)
Free
PC Tools Free
Free
FortiClient Lite
Free
Unthreat Antivirus
Free
Preventon
Free
Rising
Free
Zillya!
Free
NANO
Free
Digital Defender
Free
ClearSight
Free
Zoner
Free
BkavHome
Free
CMC Infosec
Free
Clam Sentinel
Free
Moon Secure
Free
ZenOK
Free
Ainvo Antivirus
Free
Portable anti-virus programs
DrWeb cureit
Emsisoft Emergency USB Stick files
Avira DE-Cleaner
Microsoft Safety Scanner
AVZ / AVZ database
Norman malware cleaner
Superantispyware
Panda ActiveScan Cleaner
Trendmicro Sysclean
NoVirusThanks
ArcaVir MicroScan
Zillya! Scanner
Spybot Portable
ClamWin Portable
Guardiano Assembler
Anti Root kit
TDSS Killer
Avast MBR Scanner
Gmer
RootRepeal
Kernel Detective
SpyDllRemover
VBA anti-rootkit
Sanity check
Rootkit Unhooker
Bitdefender Bootkit Removal Tool
RootkitRemover
mbr tool
catchme
Rootkitty
Kill bootkits
Hypersight Rootkit Detector
Rkdetector
Firewall analyzer
Security is effective when you know what is going on in your environment. The most of us protect ourselves with Firewalls, IDS, IPS and multiple monitor tools.
These devices and tools all create logfiles that can be analyzed to
Software
Free / Paid
Download link
Firemon
Paid
http://www.firemon.com
Barracudanetworks
Paid
http://www.barracudanetworks.com
Splunk
Paid
http://www.splunk.com
Monitor tools
If you want to monitor your environment you can use these monitor tools to find out what is happening in your environment.
Software
FREE / Paid
Download link
Zenoss Core
Free
http://community.zenoss.org/
NTA Monitor
Free
http://www.nta-monitor.com/tools/ike-scan/
Sniffers
Do you need to analyze an packet? You can use this packet analyzers to sniff packets that cross your network. You can analyze network problems, detect network intrusion attempts and more.
Software
Free / Paid
Download link
Wireshark
Free
http://www.wireshark.org
NMAP
Free
http://nmap.org/
Code Review Tools
Tools to review code.
Software
Free / Paid
Download link
Rough Auditing Tool for Security
Free
https://www.fortify.com
Config Review Tools
Tools to review config files.
Software
Free / Paid
Download link
Apache Benchmark
Free
http://www.cisecurity.org/
Microsoft Best Practice Analyzer
Paid
http://www.microsoft.com
Database Tools
Software
Free / Paid
Download link
SQL Server Express Utility
Free
http://www.microsoft.com
MySQL Command-Line Tool
Free
http://dev.mysql.com/
Leviathan
Free
http://leviathan.sourceforge.net/
WinSQL without installer
Free
http://web.synametrics.com/rawfiles.htm
Debugging Tools
Software
Free / Paid
Download link
OllyDbg
Free
http://www.ollydbg.de/
Forensic Tools
Software
Free / Paid
Download link
Mandiant Red Curtain
Free
http://www.mandiant.com/
Mandiant Red Line
Free
http://www.mandiant.com/
Fuzzer Tools
Software
Free / Paid
Download link
Skipfish
Free
http://code.google.com/p/skipfish/
WSFuzzer Project
Free
https://www.owasp.org/
FileFuzz
Free
http://www.securiteam.com/tools
Fuzzdb
Free
http://code.google.com/p/fuzzdb/
SAP tools
Software
Free / Paid
Download link
SAPYTO
Free
http://www.security-database.com/
Backdoor Tools
Software
Free / Paid
Download link
TINI
Free
http://ntsecurity.nu/toolbox/tini/
Brute Force Tools
Software
Free / Paid
Download link
Hydra Brute Force Utility
Free
http://www.madirish.net/
BRUTUS
Free
http://www.hoobie.net/brutus/
TSGrinder
Free
http://www.hammerofgod.com/
Patator
Free
http://code.google.com/p/patator/
Truecrack Password cracking for truecrypt encrypted volume files click here
Interception Tools
Software
Free / Paid
Download link
Echomirage
Free
http://www.bindshell.net/tools/
Password Cracking Tools
Software
Free / Paid
Download link
Cain & Abel
Free
http://www.oxid.it/cain.html
John the Ripper
Free
http://www.openwall.com/john/
Ophcrack
Free
http://ophcrack.sourceforge.net/
Password Retrieval Tools
Have you lost your password and you need to retrieve your password? Then take a look at these password retrieval tools.
Software
Free / Paid
Download link
Creddump
Free
http://code.google.com/p/creddump/
FGdump
Free
http://www.foofus.net/~fizzgig/fgdump/
Pass-The-Hash toolkit
Free
http://oss.coresecurity.com/
PWdump
Free
http://www.foofus.net/~fizzgig/pwdump/
Token Impersionation Tools
Software
Free
Download link
/ Paid
Incognito
Free
http://sourceforge.net/projects/incognito/
Pass-The-Hash toolkit
Free
http://oss.coresecurity.com/
Windows Credentials Editor
Free
http://www.ampliasecurity.com/research.html
LIVE CD's
Software
Free / Paid
Download link
Backtrack
Free
http://www.backtrack-linux.org/
Hiren
Free
http://www.hiren.info/pages/bootcd
Great Tool resources
Software
Free / Paid
Download link
HackArmoury
Free
http://hackarmoury.com/tools
Microsoft
Free
http://www.microsoft.com/download/
Phenoelit
Free
http://phenoelit.org/fr/tools.html
techsupportalert
Free
Massive tools list
Kaspersky Free Tools
Kaspersky Virus Removal Tool
free
Virus Removal Tool is a utility designed to remove all types of infections from your computer. It implies effective algorithms of detection used by Kaspersky Anti-Virus and AVZ. It cannot substitute a resident antivirus application. http://www.kaspersky.com/antivirus-removal-tool-register
Kaspersky Rescue Disk 10
free
Kaspersky Rescue Disk is designed to scan, disinfect and restore infected operating systems. It should be used when it is impossible to boot the operating system.
http://rescuedisk.kaspersky-labs.com/rescuedisk/updatable/kav_rescue_10.iso
Kaspersky Security Scan
free
Kaspersky Security Scan provides a free-of-charge, easy way to find viruses and other threats that may be hidden on your PC… plus get advice on your PC’s security status. http://products.kaspersky-labs.com/products/multilanguage/special/kss2/kss12.0.1.117mlg_en_ru_fr_de.exe
Mandiant free tools
Redline
Mandiant Redline is a free utility that accelerates the process of triaging hosts suspected of being compromised or infected while supporting in-depth live memory analysis.
More
IOC Editor
Mandiant IOC Editor is a free editor for Indicators of Compromise (IOCs).
More
IOC Finder
Mandiant IOC Finder is a free tool for collecting host system data and reporting the presence of Indicators of Compromise (IOCs).
More
Memoryze
Free memory forensics software designed to help incident responders find evil within live memory.
More
Audit Viewer
Audit Viewer is an open source tool that allows users to examine the results of Memoryze's analysis.
More
Highlighter
Highlighter is designed to help security analysts and system administrators rapidly review log and other structured text files.
More
Red Curtain
Software for incident responders that helps find and analyze unknown malware.
More
Web Historian
Assists users in reviewing websites that are stored in the history files of the most commonly used browsers.
More
Research: PdbXtract
PdbXtract is a tool to help you explore symbolic type information as extracted from Microsoft programming database files.
More
Research: Mandiant ApateDNS
ApateDNS is a tool for controlling DNS responses though an easy to use graphical user interface (GUI).
More
Research: Mandiant Find Evil
A malware discovery tool which uses disassembly to detect packed executables.
More
Research: Mandiant Heap Inspector
Heap Inspector is a heap visualization and analysis tool. It has the ability to collect a process' heaps using both API and raw methods.
More
Research: Mandiant Metasploit Forensic Framework
The Metasploit Forensic Framework (MSFF) is a proof of concept tool that can potentially reconstruct an attacker's meterpreter sessions.
More
Research: Mandiant MindSniffer
MindSniffer is a tool that will allow the user to translate snort signatures to either XML jobs or Python plug-ins that can be used to identify processes containing strings that match snort signatures.
More
Research: Mandiant Restore Point Analyzer
A simple forensic tool to analyze change.log files from restore points to determine the original paths and file names of files stored inside restore points.
More
BindShell Tools link
BeEF
BeEF is the browser exploitation framework. Its purposes in life is to provide an easily integratable framework to demonstrate the impact of browser and cross-site scripting issues in real-time. The modular structure has focused on making module development a trivial process with the intelligence existing within BeEF. Some of the basic functionality includes Keylogging and Clipboard Theft.
Become
The become utility changes the current effective, or real, user and group identity to those specified on the command line. The default shell (/bin/sh) is then executed. UID and GID are specified numercially and do not have to be currently defined on the system. Lots of fun when playing around with other peoples NFS exports.
Coder
A windows utility to encode and decode various encoding schemes. Currently supports Base64, Hex, HTTP URL Encoding and MD5.
Dnetj
Dnetj is a distributed client/server version of John the ripper. It is operated in much the same way as distributed.net or setiathome, but is designed to crack password hash files.
ETrace
ETrace is a configurable static port network tracing tool, similar to traceroute, but supporting ICMP, TCP, UDP and other IP protocols.
Echo Mirage
Echo Mirage is a generic network proxy. It uses DLL injection and function hooking techniques to redirect network related function calls so that data transmitted and received by local applications can be observed and modified.
GenIP
IA small utility, based on the NMap target specification code, for quickly and easily generating lists of IP addresses.
ICMPScan
Does what it says on the tin: Scans the specified address, or addresses, for ICMP responses. Handles echo (type 8 ), timestamp (type 13), address mask (type 17), information (type 15) and router solicitation (type 10) requests.
John The Ripper MPI Patch
This is an updated version of Ryan Lim's patch for john the ripper to support MPI, in addition to a large number of third party patches to support additional ciphers and such.
MassResolve
This program performs multi-threaded reverse DNS lookups. It can be passed a netblock or a file of IP addresses to process.
ObexSend
ObexSend is a simple command line tool to transfer a file via OBEX FTP to a device with a Bluetooth interface. It requires the user to specify the MAC address of the desination device, the OBEX FTP channel and the name of the file to send.
Odysseus
Odysseus is a proxy server, which acts as a man-in-the-middle during an HTTP session. A typical HTTP proxy will relay packets to and from a client browser and a web server. Odysseus will intercept an HTTP session's data in either direction and give the user the ability to alter the data before transmission.
RFIDTool
RFIDtool has been designed to perform atomic tasks on RFID tags. This focus allows for the tool to be easily incorporated into scripts to acheive more complex and useful tasks. One example is to load RFID tags with varying data depending up their storage size.
SSLCat
SSLCat is a netcat like utility with SSL support. SSLCat is a simple Unix utility that reads and writes data across an SSL enable network connection.
SSLCat accepts a hostname and optional port number (443 is used if none is specified) and attempts to form a SSLv2 connection to the specified host. If all goes well, data is read from stdin and sent across the encrypted connection, while incoming data from the encrypted connection is sent to stdout.
Screen Shooter
A windows utility to simplifies taking screen shots of either the currently focused window or the entire desktop. Screen Shooter uses configurable hot keys hot keys and supports Bitmap, GIF, JPEG, PNG and TIF image formats.
SynScan
A quick half-open portscanner. This tool will send TCP packets with the SYN flag set at the destination address. SynScan will send traffic as fast as the host network interface can support.
Telemachus
A companion utility for Odysseus allowing further analysis and manipulation of HTTP transactions.
Burp Suite
Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities.
Share to: Facebook Twitter LinkedIn
Additional Information
Crossdomain.xml Hacking – Proof of Concept Tool
After recently looking into how Adobe flash player does cross site requests I noticed that there was a shocking lack of tools to demonstrate crossdomain.xml insecurities. It seems like a pretty easy proof of concept to build so why isn’t there a tool to test this? Naturally I Googled around and couldn’t find anything so I decided to build my own over the weekend.
For those not familiar with Crossdomain.xml and how it applies to Flash/Adobe plugins…
Taken straight from Adobe’s website:
Why do you require a crossdomain.xml file?
A cross-domain policy file is an XML document that grants a web client, such as Adobe Flash Player or Adobe Acrobat (though not necessarily limited to these), permission to handle data across domains. When clients request content hosted on a particular source domain and that content make requests directed towards a domain other than its own, the remote domain needs to host a cross-domain policy file that grants access to the source domain, allowing the client to continue the transaction.
Source: http://www.adobe.com/devnet/adobe-media-server/articles/cross-domain-xml-for-streaming.html
To put it simply, the Adobe flash equivalent of Cross Origin Resource Sharing is accomplished by checking “http://yourdomain.com/crossdomain.xml” file for permissions.
So if you have a crossdomain.xml file that looks like this:
1
2
3
You are allowing any random domain to load a flash app which has permissions to do authenticated POST/GET requests on the clients behalf. So if they were logged into a site with a vulnerable crossdomain file they could potentially preform any action on behalf of the user (send money, messages, delete things, all sorts of stuff). It’s like a XSS vulnerability but with a flash requirement (not to make it sound unappealing or anything).
I also got the grand opportunity to discover Actionscript and all of it’s fun (missing) features. While trying to build a proof of concept I ran into a ridiculous amount of quirks – everything from not being able to read the response headers to not being able to send a POST request without body data (don’t worry it auto-converts the request to a GET for you). So, if the proof of concept is missing something (like the OPTIONS/DELETE/etc method) check to see if it’s not just an inadvertent HTML5 advertisement.
ANYWAYS, enough moaning!
Crossdomain.xml Proof of Concept Tool
( This is just an image, click to get to the tool )
( This is just an image, click to get to the tool )
If you know more than me about Actionscript (if you’ve spent more than a few hours on it you probably do) and see something missing from this tool – let me know and I’ll add it :)
Permalink: http://thehackerblog.com/crossdomain/
Till next time,
-mandatory
Related Posts:
More Advanced XSS Denial of Service Attacks?
xssless – Automatic XSS Payload Generator
A More Universal Router Payload – Backdooring the…
The Story of Bob and Mike, or How You Might Get Hacked By…
DNS (and ICMP) Tunneling or How to Get Free Wifi at the…
Posted in Perimeter Hacking, Web Application Hacking and tagged actionscript hack, adobe proof of concept, crossdomain tester, crossdomain.xml, crossdomain.xml hacking, flash csrf, flash hacking, URLhrequest hacking on April 15, 2014. 2 Comments
← More Advanced XSS Denial of Service Attacks?
2 comments
Pasi Salenius
May 8, 2014 at 10:44 am
Hi Matthew,
Could you add a user configurable parameter in the PoC tool for the crossdomain.xml URL? AFAIK this can be specified in the ActionScript code with Security.loadPolicyFile() method.
It would make this tool even more useful :)
thanks,
Pasi
Reply
mandatory
May 9, 2014 at 1:09 am
I agree that would be useful – I’ll have to add it when I have time.
Reply
Leave a Reply
Your email address will not be published. Required fields are marked *
Name *
Email *
Website
Comment
The Author
Matthew Bryant (mandatory)
@IAmMandatory
mandatory(cat)gmail.com
Github Repositories
San Francisco, CA
Recent Posts
Crossdomain.xml Hacking – Proof of Concept Tool
More Advanced XSS Denial of Service Attacks?
A Look Into Creating A Truley Invisible PHP Shell
Cryptorbit Decryptor Ransomware Website PHP Source Code Leak
A More Universal Router Payload – Backdooring the Linksys WRT54G Firmware
Tag Cloud
adware bob botnet botnet captcha solving brute force buy dns tunnel captcha comcast injection credential dump csaw 2013 writeup ctf decaptcha dns dns tunnel dns tunnel vpn dump enumeration firefox free wifi get around paid wifi hack.lu ctf hack.lu writeup hacked hacking hackers hacking hack wifi hash human botnet icmp tunnel iodine javascript worm malware mike password hash pastebin php shell pwned site leak subdomain thehackerblog thepiratebay web exploit wordlist xssless xss worm
Categories
Account Cracking
Enumeration
Malware & Botnets
Network Tunneling
Password Cracking
Perimeter Hacking
Reverse Engineering
Reversing
Stealth
Uncategorized
Web Application Hacking
1. The new data breach etiquette you'd better know
By David Weldon Comment | Forward | Twitter | Facebook | LinkedIn
In a sobering commentary on the times, a new data breach etiquette has emerged--the expected steps you will take when you become the victim of a significant breach. Notice the use of the word "when" here, not "if."
"Breaches and data theft have become the new normal, to the point where a data breach etiquette has developed--a set of best practices that set the pros apart from the flailers," says an article at InfoWorld.
An estimated 2,164 data breach incidents, exposing 822 million records, occurred in 2013, the largest number ever says a report by the firm Risk Based Security. The number is expected to increase this year by all accounts.
The result is that "there was a time when incidents like this, involving the theft of data from a prominent firm, were capable of shocking the public and sending corporate managers and public relations departments into a tizzy. No longer," the article notes.
CIOs are offered a series of nine data breach rules to follow after their organization has suffered a data breach. They range from disclosure, to damage control to technology fixes. Follow them faithfully, and a CIO may survive the ordeal, the article says.
As offered up by InfoWorld, the nine rules include the following:
No. 1 – Disclose sooner rather than later. "The biggest mistake that organizations make is to sit on evidence of a security incident, only to have word spread by way of a third party."
No. 2 – Tell the whole truth. "Say what you know (and what you don't know) and take your lumps."
No. 3 – Get your crypto straight. "In the heat of a security incident, the specifics of the technology your company used to secure its data may seem like a small and irrelevant detail, but it's not."
No. 4 – Communicate across channels. "Your organization needs a consistent and coherent message to convey, and it needs to communicate it across all available channels: email, blog posts and press releases."
No. 5 – Customers come first, Wall Street second. "Companies that seem overly concerned about the impact of an incident on their stock price risk alienating customers who want reassurance that their data is being protected."
Read more:
- Check out the InfoWorld article
Related Articles:
Cybercrime takes a slippery $400 billion toll
Thousands of credit, debit card numbers stolen from P.F. Chang's for sale [FierceITSecurity]
Cybercrime: The costs continue to rise [FierceITSecurity]
Read more about: Cybersecurity
back to top
This week's sponsor is Infinite Convergence.
Webinar: Drive Revenue Growth Using the Power of Mobile Messaging
Tuesday, June 24th, 12pm ET / 9am PT
The use of mobile messaging has become a powerful way for enterprises and brands of all sizes to communicate with their customers. In this webinar Myles Naughton, and John Puma Vice Presidents at Infinite Convergence will share use cases on how businesses harness the ubiquity and power of mobile messaging to drive business strategy.Register Today!
Management and Careers
1. LinkedIn latest tech firm to acknowledge diversity challenges
By David Weldon Comment | Forward | Twitter | Facebook | LinkedIn
LinkedIn has become the latest tech company to fall under scrutiny for its reported lack of diversity in hiring practices.
In a recent article at IT Pro, the firm "posted a demographic of their workforce, proving that there is a real lack of some ethnic groups in big companies."
The article notes that LinkedIn's demographics posting comes right on the heels of Google making a similar post. Google quickly drew attention to itself for similar reasons--a definite gender gap and diversity shortage among its workforce.
"Although LinkedIn fares better in gender equality than Google (39 percent female compared to Google's 30), the company is dominated by two ethnicity groups: 53 percent of LinkedIn's employees are white and 38 percent Asian," the article notes.
Acknowledging that some ethnic groups are underrepresented among the tech giant's workforce, Pat Wadors, vice president of global talent, wrote in the company blog that "In our pursuit to close the gaps, we've initiated programs and developed partnerships that we believe can make a difference."
Wadors said the company is undertaking a number of new programs to attract women to its ranks, and to also encourage interest in IT careers at the public school level.
"We may not be the first company to be transparent, and we hope we won't be the last," Wadors was quoted as saying. "Our goal is to improve over time and to make a lasting change at LinkedIn. Let's challenge each other to make it a more inclusive world in which we work."
Read more:
- see the IT Pro article
The RSA Research Team has discovered the offer of a complete collection of malware through open channels like social media and emails.
RSA Research has recently published an interesting update on the underground sale of malware tool, the experts have discovered a server who is offering a set of spyware tools for sale under the vendor names TampStore and Crown Softwares.
While researchers were investigating a Zeus Trojan sample have found the online store which is offering openly spyware tools as legitimate products despite they can be considered illegal in many countries.
The online store offers the following ‘products’:
TampZusa – stealer application for stealing information and images from browsers, email clients, keylogging, screen captures, webcam, and messenger clients
TampStealer – same as TampZusa, with a few extra bonuses added to the package
TampKelogger Classic – a basic case-sensitive keylogger that can also record window titles
TampKeylogger Premium – a full featured keylogger that also includes all the features of the TampStealer
TampSpammer – a basic mass-mailer spamming application Of all the listed products, the TampStealer appears to be the most complete package of spyware tools. The following is a list of the features advertised in the online store.
Also in this case cyber criminals show their ability to manage an efficient sale organization, the proposal includes a detailed advertising that explores also social media like Facebook.
Further analysis conducted by the RSA team have traced a number of entries posted by fraudster in a Romanian hacker forum as well as advertising his availability for hire in a web programming forum.
RSA team succeeded in the analysis of the administration panel and log files of the TampStealer spyware and has found numerous records of stolen login credentials as it is shown in the below image.
RSA malware tool
This case is considerable interesting not for the proposal itself, but for the advertising capabilities of the cyber criminals that propose it for sale on the open web and social networking sites.
“This particular software tool author does not seem to be afraid or concerned about exposing his software or his email addresses to the general public. Such behavior goes against the trend of pushing cybercriminal activity further underground as has been witnessed by RSA over the last two years.” states RSA in a report on the discovery.
Pierluigi Paganini
(Security Affairs – RSA, malware)
Subscribe to:
Posts (Atom)