<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://rss.yashkadakia.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DU8FR3c5eSp7ImA9WxBVGUg.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983</id><updated>2010-02-24T02:13:36.921+05:30</updated><title>Yash Kadakia</title><subtitle type="html">One Perspective on Indian IT Security.</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.yashkadakia.com/" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>20</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://rss.yashkadakia.com/YashKadakia" /><feedburner:info uri="yashkadakia" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;CUEEQXw8fCp7ImA9WxBVE08.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-7272638777164094580</id><published>2010-02-16T17:55:00.004+05:30</published><updated>2010-02-16T18:03:20.274+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-02-16T18:03:20.274+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Process Audits" /><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Penetration Testing" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Assessments" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="System Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Device Security" /><title>Building security into business processes</title><content type="html">Earlier today after months of avoiding it, I finally decided to go a few days without my faithful Blackberry and get the camera repaired. As I handed over my Blackberry, the technician returned a zip-lock bag with the battery, back cover and sim card.&lt;br /&gt;
&lt;br /&gt;
This made me wonder, what about the hundreds of stored e-mails, thousands of accessible e-mails via imap, work documents, personal photos, phone records, contact information, etc that still remained on the device.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://3.bp.blogspot.com/_Cx2gSf_tH4U/S1sAxGd1pvI/AAAAAAAAAKo/L2AnzsgFDPI/s1600-h/blackberry-curve-8320-wi-fi-t-mobile.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5429935086518259890" src="http://4.bp.blogspot.com/_Cx2gSf_tH4U/S1sBMTFZ0LI/AAAAAAAAAK4/LO5PT1Z5LQ0/s200/blackberry-curve-8320-wi-fi-t-mobile.jpg" style="cursor: pointer; display: block; height: 101px; margin: 0px auto 10px; text-align: center; width: 56px;" /&gt;&lt;/a&gt;&lt;span class="fullpost"&gt;Of-course, I had the phone wiped clean several times and took my memory card home with me and disabled e-mail delivery from the online blackberry portal. But what was more concerning was the pile of Blackberry and other pda devices lying around the shop for repair or re-sale, most that previously belonged to Executives, IT professionals or Consultants.&lt;br /&gt;
&lt;br /&gt;
This made me think about the need for businesses to build security into their day-to-day processes. Would it be so difficult for the shop to include an additional step / process for their customer's security? Not really.&lt;br /&gt;
&lt;br /&gt;
Formatting a phone or implementing encryption on PDAs takes nothing more than a few minutes these days. Some may argue that not all users maintain regular backups of their phone data. There are several simple solutions:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;If the user has a memory card, simply create a in-store backup of their device on their memory card and format the phone a few times. This can be done from within the phone it-self. It would take about 3 minutes and would allow the user to walk away knowing that there is no chance of any data loss.&lt;/li&gt;
&lt;li&gt;If the user does not have a memory card, simply enable the phone encryption / access password option for the device and have the user type in a password.&lt;/li&gt;
&lt;/ol&gt;Implementing any of the options would not take more than a few minutes and would provide an additional and much appreciated level of concern for their customer's data-security.&lt;br /&gt;
&lt;br /&gt;
The point of this post isn't about a particular instance or a particular store or even a particular type of business. The point is, about the concept of implementing security into day-to-day processes that we take for granted. Many of these secure processes would require minimal modification, negligible time differences and minimal investment. Consider the following examples of some day-to-day processes where security could be implemented easily.&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;At petrol pumps, most attendants generally walk away with your credit card for several minutes while you're sitting in your car. Are mobile credit card readers really that difficult to implement? No.&lt;/li&gt;
&lt;li&gt;Same as point number 1, but for restaurants, coffee shops, etc.&lt;/li&gt;
&lt;li&gt;Almost 90% of hotel/resort reservations in India involve you giving your credit card details over the phone/e-mail. Implementing an online registration system, or even an automated phone system is not very expensive or difficult.&lt;/li&gt;
&lt;li&gt;Most people/shops throw away credit card or ATM receipts that contain your name, dob, cc number, expiry etc. Investing in a shredder should definitely be a must for businesses and most importantly, they must definitely be available at most ATMs/Banks for customer's to use.&lt;/li&gt;
&lt;/ol&gt;Day-to-day examples apart, lets think a bit more on the enterprise front:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Data security on mobile devices: Almost all organizations have executives that carry around laptops, tablets, pdas etc that contain sensitive information. Would it really be so inconvenient to add a step into their day-to-day processes to implement encryption? No. Full disk encryption would simply add one password prompt to their start-up and a fairly negligible performance difference. Passwords and encryption on Blackberry's and PDAs is also fairly easy to implement. A few clicks and your data's safe.&lt;/li&gt;
&lt;li&gt;Whiteboards: I cannot count the number of offices I have walked into and found whiteboards filled with username/password information for SSH/RDP/FTP/DB etc. Again, implementing an open-source application like keepsafe will allow your employees to have access to complex username/password details with minimal fuss or interruption. &lt;/li&gt;
&lt;/ol&gt;I could go on with examples for several pages, but the point to be made is: In most cases security is not so difficult. All it needs is for someone to sit down, make a step by step list of their various processes and how they could make them more secure with minimal interruption or problems to the end-user.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-7272638777164094580?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/bM9GV4i_jLM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/7272638777164094580/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=7272638777164094580" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7272638777164094580?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7272638777164094580?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/bM9GV4i_jLM/building-security-into-business.html" title="Building security into business processes" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Cx2gSf_tH4U/S1sBMTFZ0LI/AAAAAAAAAK4/LO5PT1Z5LQ0/s72-c/blackberry-curve-8320-wi-fi-t-mobile.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2010/02/building-security-into-business.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEcARH08eip7ImA9WxJREUw.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-3303506477522531048</id><published>2009-05-12T13:00:00.010+05:30</published><updated>2009-05-12T13:44:05.372+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-12T13:44:05.372+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Process Audits" /><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Bank" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Psychology in Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Psychology" /><title>Psychology in Security - Impact of Bad Banking Processes</title><content type="html">Quite a few of my recent posts have had to do with visits to the local bank.  This morning I made a quick trip to the local branch to carry out some wire transfers. So I sat down at the Foreign Transaction counter and was asked for the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Form providing details of wire transfer, amount etc. (no problem)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;A proof of transaction, i.e. an invoice etc. (ok)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;A blank cheque&lt;/span&gt;, with nothing but my signature/stamp on it. Nothing in the to field, nothing in the amount field. (WHAT!)&lt;/li&gt;&lt;/ul&gt;&lt;span class="fullpost"&gt;At this point, I couldn't help stare the bank employee in the face with the most ridiculous look and inquire about whether they also encourage customers to fund Nigerian officials in need.&lt;br /&gt;&lt;br /&gt;Eventually after realizing that I didn't have much of a choice and adding a "Not above RS. xx" statement, I conceded and started to leave the bank. At this point, the bank employee left my blank signed cheque on top of her desk while she walked away for a cup of tea!&lt;br /&gt;&lt;br /&gt;Sure, this might not be the most dangerous scenario since there are security cameras all around and the bank's employees have undergone background checks and are well trusted.  However, Banks need to realize the security has as much to do with process audits and security cameras as it has to do with customer's psychology. It is important that as responsible organizations, we send the correct message to customers about what is acceptable and what is not in-terms of security. Banks need to realize that if you encourage customers to give blank signed cheques, you are telling them that it is acceptable practice.&lt;br /&gt;&lt;br /&gt;It is processes like this one that let users believe that this sort of behavior is acceptable or safe. No wonder hotels and other organizations ask you to provide credit-card details over the phone/email, while the person on the other end writes them down.&lt;br /&gt;&lt;br /&gt;This particular incident reminded me of another instance where I have seen something similar.&lt;br /&gt;&lt;br /&gt;Another Bank where I have an account constantly sends me e-mails with new offers that have links like "offer_name.bank.com". I think it is a horrible idea to tell you users that it is OK to click links with "xyz.bank.com" as many phishing scams provide links like, "xyz.bank.malicious.com/bank.com" etc which might not look very different to a non-tech user.&lt;br /&gt;&lt;br /&gt;Banks need to realize and carefully analyze the psychological impact of their processes on what their customers deem to be acceptable or not. Proper and well thought out processes and policies could in the long-term be the difference between whether a user clicks a malicious phishing link or reports it.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-3303506477522531048?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/cr0DDi3XKmA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/3303506477522531048/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=3303506477522531048" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3303506477522531048?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3303506477522531048?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/cr0DDi3XKmA/psychology-in-security-impact-of-bad.html" title="Psychology in Security - Impact of Bad Banking Processes" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2009/05/psychology-in-security-impact-of-bad.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QFRXw6fSp7ImA9WxVWGEg.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-3672934868352517152</id><published>2009-02-28T09:35:00.007+05:30</published><updated>2009-03-01T01:31:54.215+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-03-01T01:31:54.215+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Sniffing" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Airtel Injecting Ads into User's Browsers</title><content type="html">Most businesses have one aim, maximize profits. However, while doing so there must be a balance between risk management, customer security and most importantly - &lt;span style="font-style: italic;"&gt;FAIR-PLAY&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Indian ISP and mobile communications provider Airtel seems to have forgotten this exact rule. For almost a week now, Airtel has been "hi-jacking" user's HTTP requests and injecting them with full-page ads of their own DTH service (&lt;a href="http://1.bp.blogspot.com/_Cx2gSf_tH4U/Sai8-_6rb0I/AAAAAAAAAKY/HaVFzcNZ8GY/s1600-h/airtel_ads.png"&gt;Screenshot&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Cx2gSf_tH4U/Sai4_dqE7ZI/AAAAAAAAAKI/3LC3XSqTJeY/s1600-h/airtel_logo.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 107px; height: 51px;" src="http://4.bp.blogspot.com/_Cx2gSf_tH4U/Sai4_dqE7ZI/AAAAAAAAAKI/3LC3XSqTJeY/s320/airtel_logo.gif" alt="" id="BLOGGER_PHOTO_ID_5307695561288510866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;To add even further security risk to this mess, I am fairly certain that the page used to display Advertisements is vulnerable to a Cross-Site Scripting attack. This means that an attacker can steal the cookies of an Airtel user even if the web-site in question has no obvious flaws.&lt;br /&gt;&lt;br /&gt;Besides for the obvious risks faced by the XSS flaw, there is also the matter of how they handle:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;SSL connections.&lt;/li&gt;&lt;li&gt;Client-side certificates.&lt;/li&gt;&lt;li&gt;Sensitive user data sent via web-forms only to be interrupted by Airtel ads.&lt;/li&gt;&lt;li&gt;Users carrying out Banking or other sensitive activities which when interrupted can result in multiple payments being processed.&lt;/li&gt;&lt;li&gt;and most importantly, what guarantee is Airtel providing in-regards to user requests and information being maliciously redirected and stored on the Airtel ad-server.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Also, what about the fact that they are further affecting web-publishers advertising revenues by placing ads on content they did not write or develop. This is an extremely grim move on the part of Airtel and I sincerely hope that no-other ISPs continue in its footsteps.&lt;br /&gt;&lt;br /&gt;Airtel may have made a few extra bucks from these ads, but I for one will never be using an Airtel service as far as I can help it.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-3672934868352517152?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/vWI17bHAMc0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/3672934868352517152/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=3672934868352517152" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3672934868352517152?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3672934868352517152?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/vWI17bHAMc0/airtel-injecting-ads-into-users.html" title="Airtel Injecting Ads into User's Browsers" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_Cx2gSf_tH4U/Sai4_dqE7ZI/AAAAAAAAAKI/3LC3XSqTJeY/s72-c/airtel_logo.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2009/02/airtel-injecting-ads-into-users.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMARnw4fSp7ImA9WxVWFUQ.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-2661464717232480065</id><published>2009-02-25T23:55:00.009+05:30</published><updated>2009-02-26T01:04:07.235+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-02-26T01:04:07.235+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Security ROI" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Government" /><title>Indian Information Security Incidents Gallery</title><content type="html">I was recently on the phone with &lt;a href="http://securambling.blogspot.com/"&gt;Dinesh O'Bareja&lt;/a&gt; and he mentioned a blog he started sometime back to document &lt;a href="http://infosecgallery.blogspot.com/"&gt;Indian Information Security Incidents&lt;/a&gt;. I think its a great initiative on his part and one that we definitely require in the Indian IT Security space.&lt;br /&gt;&lt;br /&gt;As anyone who has been involved in the Indian IT industry can tell you, for most organizations security is always a low priority. One of the reasons for this is the lack of corporate liability for the loss of customer data.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Most companies that are faced with a breach use the hush-hush approach and sweep the incident under the rug. This causes consumers who have had their personal information compromised to be left in the dark until their next statement shows up with fraudulent  transactions.&lt;br /&gt;&lt;br /&gt;In other countries, there are &lt;a href="http://en.wikipedia.org/wiki/Security_Breach_Notification_Laws"&gt;Security Breach Notifications Laws&lt;/a&gt; in place to ensure that the consumer is well informed and the responsible company either compensates the victim or subscribes them to an identity monitoring service.&lt;br /&gt;&lt;br /&gt;Coming back to the &lt;a href="http://infosecgallery.blogspot.com/"&gt;India InfoSec: Incidents Hall of Shame / Fame Gallery Blog&lt;/a&gt;, I think Dinesh has definitely taken the right step. Only when we have more attention given to Security Incidents will we see companies dealing with them in a more responsible/liable manner.&lt;br /&gt;&lt;br /&gt;So if anyone out there has witnessed any security incidents, go ahead drop Dinesh an e-mail.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-2661464717232480065?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/cf1tpOa1uuw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/2661464717232480065/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=2661464717232480065" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/2661464717232480065?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/2661464717232480065?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/cf1tpOa1uuw/indian-security-incidents.html" title="Indian Information Security Incidents Gallery" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2009/02/indian-security-incidents.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQNRH0yfip7ImA9WxVSF0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-1877435051013098102</id><published>2009-01-12T21:45:00.003+05:30</published><updated>2009-01-12T21:53:15.396+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-01-12T21:53:15.396+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Budgeting" /><category scheme="http://www.blogger.com/atom/ns#" term="Penetration Testing" /><category scheme="http://www.blogger.com/atom/ns#" term="Security ROI" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Education" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Budgeting for Web Application Security</title><content type="html">&lt;span&gt;Great post on &lt;a href="http://jeremiahgrossman.blogspot.com/2008/12/budgeting-for-web-application-security.html"&gt;Budgeting for Web Application Security by &lt;/a&gt;&lt;a href="http://jeremiahgrossman.blogspot.com/2008/12/budgeting-for-web-application-security.html"&gt;Jeremiah Grossman.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Some key approaches are:&lt;br /&gt;&lt;/span&gt;&lt;ol&gt;&lt;li&gt;&lt;span&gt;Risk Mitigation&lt;/span&gt;&lt;span&gt; - "If we spend $X on Y, we’ll reduce of risk of loss of $A by B%."&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Due Diligence&lt;/span&gt; -&lt;span&gt; "We must spend $X on Y because it’s an industry best-practice."&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Incident Response&lt;/span&gt; - &lt;span&gt;"We must spend $X on Y so that Z never happens again."&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span&gt;Regulatory Compliance&lt;/span&gt; - &lt;span&gt;"We must spend $X on Y because PCI-DSS says so."&lt;/span&gt;&lt;/li&gt;&lt;li&gt;Competitive Advantage - &lt;span&gt;"We must spend $X on Y to make the customer happy."&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-1877435051013098102?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/bHp34ftJiqA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/1877435051013098102/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=1877435051013098102" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1877435051013098102?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1877435051013098102?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/bHp34ftJiqA/budgeting-for-web-application-security.html" title="Budgeting for Web Application Security" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2009/01/budgeting-for-web-application-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYAR3wyeip7ImA9WxVSF0k.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-3142367403127260775</id><published>2009-01-12T13:20:00.002+05:30</published><updated>2009-01-12T13:45:46.292+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-01-12T13:45:46.292+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Backdoors" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Government" /><title>Police Backdoors</title><content type="html">I ran across this article titled "&lt;a href="http://www.timesonline.co.uk/tol/news/politics/article5439604.ece"&gt;Police set to step up hacking of home PCs&lt;/a&gt;" the other day. It details a new law approved by the UK government allowing police to hack into suspected home computers. In-order to carry out these Hacks, they will be sending E-mails with virus attachments or breaking into homes and installing keystroke loggers.&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;This kind of behavior is displayed by most governments these days. However, what did surprise me is that they asked security product/service providers to stop detecting/blocking their keystroke loggers and other malicious tools.&lt;br /&gt;&lt;br /&gt;I was glad to read that a few security vendors have taken issue and denied cooperation with this matter. As per ZDNet, security vendors Kaspersky Labs and Sophos told &lt;a href="http://news.zdnet.co.uk/security/0,1000000189,39589104,00.htm"&gt;ZDNet UK&lt;/a&gt; that they would not make any concession in their protective software for the police hack.&lt;br /&gt;&lt;br /&gt;Symantec declined to comment on whether it would block a police hack, saying the matter was "politically sensitive". However, the security vendor has said in the past that it would not scan for the FBI's Magic Lantern keystroke-logging software.&lt;br /&gt;&lt;br /&gt;I personally think the entire concept is ridiculous, especially the part where security vendors are expected to turn a blind eye to these police hacks. I feel that an AV that would voluntarily miss malicious code used for these police hacks would probably as a direct result miss other malicious code also.&lt;br /&gt;&lt;br /&gt;Also, If any malicious users or malware authors were to get their hands on this malicious police code (which is fairly likely since they are installing it on suspect PCs), it would be fairly easy to reverse engineer the code and create malware to mimic its behavior and bypass security software.&lt;br /&gt;&lt;br /&gt;Security through obfuscation, i.e. with the hope that no-one will look there, or look deep enough is always a bad idea. The entire concept of asking Vendors to create police backdoors sounds to me like a malformed version of "Security through obfuscation".&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-3142367403127260775?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/XnWDUETvYqg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/3142367403127260775/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=3142367403127260775" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3142367403127260775?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3142367403127260775?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/XnWDUETvYqg/police-backdoors.html" title="Police Backdoors" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2009/01/police-backdoors.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0EHRX4yeSp7ImA9WxRbF08.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-960733626398338279</id><published>2008-12-08T13:27:00.008+05:30</published><updated>2008-12-08T14:10:34.091+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-12-08T14:10:34.091+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Backdoors" /><category scheme="http://www.blogger.com/atom/ns#" term="Sniffing" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="System Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><title>AVID - Antivirus is Dead!</title><content type="html">Late last night I was surfing some forums looking at  interesting posts and I noticed one about an MD5 Cracker that utilized various Free Online Services.&lt;br /&gt;&lt;br /&gt;Intrigued I downloaded this utility, However suspecting a virus or trojan of some kind, I ran this utility through 37 Anti-Virus Scanners via &lt;a href="http://www.virustotal.com/"&gt;VirusTotal - Free Online Virus and Malware Scan&lt;/a&gt;. Nothing!!. Every scanner on the market gave it a clean-chit including every single heuristic feature these scanners boast.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Being as paranoid as I am, I finally ran this utility through &lt;a href="http://www.sandboxie.com/"&gt;Sandboxie.&lt;/a&gt; A few seconds later, &lt;a href="http://www.personalfirewall.comodo.com/"&gt;Comodo Firewall Pro&lt;/a&gt; came up with an alert: The utility was trying to connect to an FTP Server. Instantly I ran &lt;a href="http://www.wireshark.org/"&gt;Wireshark&lt;/a&gt; and sniffed the Username/Password credentials for the FTP Server.&lt;br /&gt;&lt;br /&gt;I put these details into &lt;a href="http://filezilla-project.org/"&gt;Filezilla&lt;/a&gt; and in a few seconds I was connect to the server. The server was filled with log files from hundreds of users. The malware had dumped Saved Passwords from IE, Chrome, Firefox etc and uploaded these log files onto the server. After downloading a few of these files for deeper investigation, I deleted every file on the server to ensure that the compromised users would not have their information hi-jacked.&lt;br /&gt;&lt;br /&gt;On further investigation of the log files, the virus seemed to be one from mutX.org. I was thoroughly disappointed that a known virus-strain could evade every single Anti-Virus scanner on the market even though it had such obvious heuristic traits such as: dumping information from browsers, msn messenger and uploading it to a rogue ftp server.&lt;br /&gt;&lt;br /&gt;This entire episode reminded me about a Podcast I heard last week where &lt;a href="http://www.it-director.com/"&gt;Robin Bloor&lt;/a&gt; was a guest discussing &lt;a href="http://www.it-director.com/blogs/Robin_Bloor/2007/3/avid_why_it_s_over_for_the_antivir_.html"&gt;AVID (Antivirus is Dead)&lt;/a&gt;. After this particular incident, I couldn't agree more with Robin. If this particular incident had targeted an Organization as opposed to some Security Forums, it could have cause massive damage and probable financial loss to these organizations.&lt;br /&gt;&lt;br /&gt;I have always been a fan of Layering Security and in this particular instance layering Avira Antivir, Comodo Firewall Pro, Sandboxie etc together really paid off.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-960733626398338279?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/jCsnGhaGICA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/960733626398338279/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=960733626398338279" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/960733626398338279?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/960733626398338279?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/jCsnGhaGICA/avid-antivirus-is-dead.html" title="AVID - Antivirus is Dead!" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/12/avid-antivirus-is-dead.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUESHYyeyp7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-7108279317388370865</id><published>2008-10-30T17:58:00.006+05:30</published><updated>2008-10-30T18:40:09.893+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:40:09.893+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Research" /><category scheme="http://www.blogger.com/atom/ns#" term="Fuzzing" /><category scheme="http://www.blogger.com/atom/ns#" term="System Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Fuzzing 101 - Introduction to Fuzzing</title><content type="html">I've spent most of today running &lt;a href="http://www.securitybrigade.com/"&gt;Security Brigade&lt;/a&gt;'s Proprietary Fuzzing Application under a variety of situations and conditions to find some very interesting vulnerabilities in a wide-range of products.&lt;br /&gt;&lt;br /&gt;Some of the products I've run it against yet are: Rediff's Toolbar for Internet Explorer, Microsoft Outlook 2007 and Mozilla Thunderbird; All of which have some very interesting vulnerabilities ranging from Denial-of-service to Buffer Overflows.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;I will not be going into detail about these vulnerabilities in this posts as I will wait for vendor responses and patch releases before I do so. However, I do want to talk about Fuzzing in general.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What is a Fuzzer?&lt;/span&gt;&lt;br /&gt;A Security fuzzer is a tool used by security professionals to test the parameters of an application. Typical fuzzers test an application for buffer overflows, format string vulnerabilities, and error handling. More advanced fuzzers incorporate functionality to test for directory traversal attacks, command execution vulnerabilities, SQL Injection and Cross Site Scripting vulnerabilities.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Common Fuzzing Tools&lt;/span&gt;&lt;br /&gt;There are many publicly available and open-source fuzzing applications that are designed for various purposes. Some of these are:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://antiparser.sourceforge.net/"&gt;antiparser&lt;/a&gt; -Written in Python, simple and limited fuzzing framework.&lt;br /&gt;&lt;a href="http://autodafe.sourceforge.net/"&gt;Autodafe&lt;/a&gt; - Can be perceived as a more powerful version of SPIKE. It’s main contribution is the introduction of a UNIX-based debugging agent capable of weighting the possibility of a crash on any given fuzz input.&lt;br /&gt;&lt;a href="http://metasploit.com/users/hdm/tools/axman/" target="_blank"&gt;AxMan&lt;/a&gt; - A web-based ActiveX fuzzing engine written by HD Moore.&lt;br /&gt;&lt;a href="http://www.fuzzing.org/wp-content/bugger.tgz"&gt;bugger&lt;/a&gt; - A Linux in-process fuzzer written by Michal Zalewski.&lt;br /&gt;&lt;a href="http://labs.idefense.com/software/fuzzing.php#more_comraider" target="_blank"&gt;COMRaider&lt;/a&gt; - A Windows GUI fuzzer written by David Zimmer, designed to fuzz COM Object Interfaces.&lt;br /&gt;&lt;a href="http://www.genexx.org/dfuz/"&gt;Dfuz&lt;/a&gt; -sWritten in C, exposes a custom and easy to use scripting language for fuzzer development.&lt;br /&gt;&lt;a href="http://metasploit.com/users/hdm/tools/domhanoi/domhanoi.html" target="_blank"&gt;DOM-Hanoi&lt;/a&gt; - Written by H D Moore and Aviv Raff, it is designed to identify common DHTML implementation flaws by adding/removing DOM elements&lt;br /&gt;&lt;a href="http://gunzip.altervista.org/webfuzzer/webfuzzer-latest.tar.gz"&gt;eFuzz&lt;/a&gt; - A generic TCP/IP protocol fuzzer. Easy to use, but maybe not as full featured as some others on this list.&lt;br /&gt;&lt;a href="http://www.vdalabs.com/tools/efs_gpf.html"&gt;Evolutionary Fuzzing System (EFS)&lt;/a&gt; -A fuzzer which attempts to dynamically learn a protocol using code coverage and other feedback mechanisms.&lt;br /&gt;&lt;a href="http://www.isecpartners.com/file_fuzzers.html" target="_blank"&gt;FileH&lt;/a&gt;-A haskell-based file fuzzer that generates mutated files from a list of source files and feeds them to an external program in batches.&lt;br /&gt;&lt;a href="http://www.idefense.com/iia/doDownload.php?downloadID=3"&gt;FileFuzz&lt;/a&gt; - A file format fuzzer for PE (Windows) binaries from iDefense.&lt;br /&gt;&lt;a href="http:///" target="_blank" title="http://www.isecpartners.com/file_fuzzers.html"&gt;FileP&lt;/a&gt;-A python-based file fuzzer that generates mutated files from a list of source files and feeds them to an external program in batches.&lt;br /&gt;&lt;a href="http://freshmeat.net/projects/fuzzled/"&gt;Fuzzled&lt;/a&gt; -A Perl based generic fuzzing framework.&lt;br /&gt;&lt;a href="http://www.cs.wisc.edu/%7Ebart/fuzz/fuzz.html"&gt;Fuzz&lt;/a&gt; - The ORIGINAL fuzzer developed by Dr. Barton Miller.&lt;br /&gt;&lt;a href="http://www.vdalabs.com/tools/efs_gpf.html"&gt;General Purpose Fuzzer (GPF)&lt;/a&gt; - Written in C, GPF has a number of modes ranging from simple pure random fuzzing to more complex protocol tokenization.&lt;br /&gt;&lt;a href="http://metasploit.com/users/hdm/tools/hamachi/hamachi.html" target="_blank"&gt;hamachi&lt;/a&gt; -Written by H D Moore and Aviv Raff, Hamachi will look for common DHTML implementation flaws by specifying common “bad” values for method arguments and property values.&lt;br /&gt;&lt;a href="http://lxapi.sourceforge.net/"&gt;(L)ibrary (E)xploit API - lxapi&lt;/a&gt; - A collection of python scripts for fuzzing.&lt;br /&gt;&lt;a href="http://freshmeat.net/projects/mangleme/" target="_blank"&gt;mangleme&lt;/a&gt; -An automated broken HTML generator and browser tester, originally used to find dozens of security and reliability problems in all major Web browsers.&lt;br /&gt;&lt;a href="http://www.idefense.com/iia/doDownload.php?downloadID=10"&gt;notSPIKFile&lt;/a&gt; - A ELF fuzzer closely related to FileFuzz, instead of using SPIKE as a starting point.&lt;br /&gt;&lt;a href="http://peachfuzz.sourceforge.net/"&gt;Peach&lt;/a&gt; -Written in Python, an advanced and robust fuzzing framework which successfully separates and abstracts relevant concepts. Learning curve is a bit overwhelming.&lt;br /&gt;&lt;a href="http://www.fuzzing.org/wp-content/Protocol%20Informatics.zip"&gt;Protocol Informatics&lt;/a&gt; - Slides, whitepaper and code from the last publicly seen snapshot from Marshall Beddoe’s work.&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c04/wap-wsp-request/c04-wap-r1.jar"&gt;PROTOS WAP&lt;/a&gt; - A fuzzer from the PROTOS project for fuzzing WAP.&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c05/http-reply/c05-http-reply-r1.jar"&gt;PROTOS HTTP-reply&lt;/a&gt; - Another fuzzer from the PROTOS dudes for attack HTTP responses, useful for broswer vulns.&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/ldapv3/c06-ldapv3-enc-r1.jar"&gt;PROTOS LDAP&lt;/a&gt; - For fuzzing LDAP, not as successful as the others from the PROTOS project&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/c06-snmpv1-req-app-r1.jar"&gt;PROTOS SNMP&lt;/a&gt; - Classic SNMP fuzzer, found a vuln in almost every networking gear available at the time (2002).&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/c06-snmpv1-req-app-r1.jar"&gt;PROTOS SIP&lt;/a&gt; - For fuzzing all those new VOIP SIP devices you see everywhere.&lt;br /&gt;&lt;a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c09/isakmp/c09-isakmp-r1.jar"&gt;PROTOS ISAKMP&lt;/a&gt; - For attacking IPSec implementations&lt;br /&gt;&lt;a href="http://media.wiley.com/product_ancillary/83/07645446/DOWNLOAD/Source_Files.zip"&gt;RIOT &amp;amp; faultmon&lt;/a&gt; - For attacking plain text protocols (Telnet, HTTP, SMTP). Used by Riley Hassell when he worked at eEye to discover the &lt;a href="http://www.iss.net/security_center/advice/Intrusions/2002607/default.htm"&gt;IIS .printer overflow&lt;/a&gt; and included in The Shellcoder's Handbook.&lt;br /&gt;&lt;a href="http://code.google.com/p/quefuzz/"&gt;QueFuzz&lt;/a&gt; - Small fuzzer that uses libnetfilter queue to take in packets from iptables. It’s fuzzing engine either randomly fuzzes binary or ASCII protocols or uses a basic fuzzing template to search and replace packet data.&lt;br /&gt;&lt;a href="http://www.fuzzware.net/Schemer/Schemer.htm"&gt;Schemer&lt;/a&gt; - XML driven generic file and protocol fuzzer.&lt;br /&gt;&lt;a href="http://www.dachb0den.com/projects/screamingcobra/screamingCobra-1.00.tar.gz"&gt;Screaming Cobra&lt;/a&gt; - Name makes the fuzzer sound better than it really is, but is good for finding CGI bugs. Also, its a perl scrpt so easy to modify or extend.&lt;br /&gt;&lt;a href="http://www.fuzzing.org/wp-content/SMUDGE.zip"&gt;SMUDGE&lt;/a&gt; - Pure Python network protocol fuzzer from nd@felincemenace.&lt;br /&gt;&lt;a href="http://www.immunitysec.com/resources-freesoftware.shtml"&gt;SPIKE&lt;/a&gt; - Written in C, exposes a custom API for fuzzer development.&lt;br /&gt;&lt;a href="http://www.idefense.com/iia/doDownload.php?downloadID=14"&gt;SPIKEFile&lt;/a&gt; - Another file format fuzzer for attacking ELF (Linux) binaries from iDefense.&lt;br /&gt;&lt;a href="http://www.eeye.com/html/resources/downloads/other/TagBruteForcer.zip"&gt;Tag Brute Forcer&lt;/a&gt; - Awesome fuzzer from Drew Copley at eEye for attacking all of those custom ActiveX applications.&lt;br /&gt;&lt;a href="http://theartoffuzzing.com/"&gt;TAOF (The Art of Fuzzing)&lt;/a&gt; - Written in Python, a cross-platform GUI driven network protocol fuzzing environment for both UNIX and Windows systems.&lt;br /&gt;&lt;a href="http://gunzip.altervista.org/webfuzzer/webfuzzer-latest.tar.gz"&gt;WebFuzzer&lt;/a&gt; - A fuzzer for web application vulnerabilities.&lt;br /&gt;&lt;br /&gt;My personal favourite Fuzzing utilities are SPIKE, Axman and Peach.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-7108279317388370865?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/kBUl8P5OGu8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/7108279317388370865/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=7108279317388370865" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7108279317388370865?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7108279317388370865?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/kBUl8P5OGu8/fuzzing-tutorial.html" title="Fuzzing 101 - Introduction to Fuzzing" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/10/fuzzing-tutorial.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQFRnczfCp7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-5965997469474974328</id><published>2008-10-16T06:09:00.012+05:30</published><updated>2008-10-30T18:41:57.984+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:41:57.984+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Bank" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Hackers Compromise the World Bank - Reflections on Indian IT Security</title><content type="html">According to this &lt;a href="http://www.usatoday.com/money/industries/banking/2008-10-12-world-bank-hackers_N.htm"&gt;article from the USA Today&lt;/a&gt;, Hackers broke into 18 Servers at the World Bank and had access to and possibly stole sensitive information from at-least 5 of the servers. Indian Banks have been relatively lucky, facing a majority of phishing/scam attacks rather then out-right "Hack" attempts from skilled organized criminals such as these.&lt;br /&gt;&lt;br /&gt;Throughout my time as a Security Professional whenever discussing Financial Fraud, Phishing and other attacks faced by Banks &amp;amp; Financial Institutions, I have always been of the opinion that they will soon face much more devastating attacks that will make the current attempts pale in comparison.&lt;br /&gt;&lt;br /&gt;Why the pessimistic view? Well its simple.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Attackers have always been "creative" coming up with new and complicated schemes in-order to get access to Credit-Card details and Banking Information. The reason they have the time and ability to do so is: &lt;span style="font-weight: bold;"&gt;Economics&lt;/span&gt;. Bottom-line is that most of these attackers are walking away with fistfuls of money at the expense of Banks and their Customers.&lt;br /&gt;&lt;br /&gt;If we consider a typical phishing scam, an attacker would send out a million e-mails (approximation) with a success rate at best of 1% (a very generous number considering that a good percent would be picked up by Anti-Spam, Anti-phishing, Mistargeted Users, Smart Users etc) they will walk away with 10000 working banking details.&lt;br /&gt;&lt;br /&gt;Instead if the attacker starts targeting servers belonging to Banks, systems belonging to Bank Employees and more importantly &lt;span style="font-weight: bold;"&gt;any of the thousands of Indian Shopping web-sites&lt;/span&gt; with Exposed Customer Information, SQL Injection vulnerabilities etc they could walk away with 100K - 200K Credit-Card details or Banking Information.&lt;br /&gt;&lt;br /&gt;As a matter of fact, last week, a colleague of mine ordered for a product from one of the most popular Indian Shopping Portals. When the product was delivered; the label was a print-out invoice at the bottom of which was the URL: http://shopping-website/ecommerce/admin/vieworders.php. After typing this into the browser we were shown WITHOUT AUTHENTICATION plain-text Credit Card details, Order Information, Banking Details etc.&lt;br /&gt;&lt;br /&gt;This for sure is one reason, why I do-not personally carry out Online Banking or Shopping besides for maybe on Amazon.com or my Bank Account with Free Fraud Insurance.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-5965997469474974328?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/veX4NeSO3vI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/5965997469474974328/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=5965997469474974328" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5965997469474974328?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5965997469474974328?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/veX4NeSO3vI/security-india-banking-online-shopping.html" title="Hackers Compromise the World Bank - Reflections on Indian IT Security" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/10/security-india-banking-online-shopping.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEQHR3o7eCp7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-3780482588360535562</id><published>2008-10-08T18:13:00.003+05:30</published><updated>2008-10-30T18:42:16.400+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:42:16.400+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="ClickJacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Browsers" /><title>ClickJacking Explained</title><content type="html">&lt;span style="font-weight: bold;"&gt;What is ClickJacking?&lt;/span&gt;&lt;br /&gt;ClickJacking is a relatively old vulnerabilitiy that has been around since 2003-2004, however it has been recently brought back to life by Robert Hansen and Jeremiah Grossman. ClickJacking is a little bit difficult to explain however try to imagine any button that you see in your browser from the Wire Transfer Button on your Bank, Post Blog button on your blog, Add user button on your web-site etc. ClickJacking gives the attacker to ability to invisibly float these buttons on-top of other innocent looking objects in your browser. So when you try to click on the innocent object, you are actually clicking on the malicious button that is floating on top invisibly.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;So while you are simply trying to close the javascript pop-up on your screen, play a flash game or interact with some ajax web-site -- you might really be clicking on the button to wire-transfer money to a russian bank account.&lt;br /&gt;&lt;br /&gt;A slightly more technical description would be: A malicious page in domain A may create an IFRAME pointing to an application in domain B, to which the user is currently authenticated with cookies. The top-level page may then cover portions of the IFRAME with other visual elements to seamlessly hide everything but a single UI button in domain B, such as 'delete all items,' 'click to add Bob as a admin,' etc. It may then provide its own, misleading UI that implies that the button serves a different purpose and is a part of site A, inviting the user to click it.&lt;br /&gt;&lt;br /&gt;In other words, the hacker would dupe users into visiting a malicious page -- through the usual methods -- but then hide the nasty bits under what appears to be the real-deal content from a legitimate site.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;How Serious is ClickJacking?&lt;/span&gt;&lt;br /&gt;On its own ClickJacking doesn't sound to be a very serious vulnerability, since user interaction is required. However as I have always said, in the world of vulnerabilities 1+1 does not always equal to 2, and might just equal to 10^2. By this I simply mean, that ClickJacking in combination with other vulnerabilities could become a very serious issue.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Example - ClickJacking can Spy on your Webcam and Microphone&lt;/span&gt;&lt;br /&gt;Just as I wrote this blogpost a new use for ClickJacking has been disclosed where it can be used to spy on your Microphone and Webcam. This is based on a new vulnerability discovered in Adobe's Flash Software and published about on &lt;a href="http://blog.guya.net/2008/10/07/malicious-camera-spying-using-clickjacking/"&gt;Guya.net&lt;/a&gt;, &lt;a href="http://ha.ckers.org/blog/20081007/clickjacking-details/"&gt;&lt;span style="text-decoration: underline;"&gt;Rsnake's Blog&lt;/span&gt;&lt;/a&gt; and &lt;a href="http://jeremiahgrossman.blogspot.com/2008/10/clickjacking-web-pages-can-see-and-hear.html"&gt;Jerremiah Grossman's Blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;A particular vulnerability exists in Adobe's Flash Software, which allows the malicious attacker to use ClickJacking to gain access to the user's web-cam and microphone.&lt;br /&gt;&lt;br /&gt;The vulnerability works as follows:&lt;br /&gt;1) You visit a web-page with a flash application/game embedded in it.&lt;br /&gt;2) You click on the flash button.&lt;br /&gt;3) Your click is "click-jacked" into allowing the server to access your web-cam and microphone.&lt;br /&gt;&lt;br /&gt;Whatis really happening:&lt;br /&gt;1) You visit the web-page, in the back the target application (in this case Adobe's Settings Panel) is loaded and made invisible. The Allow button is made to float invisibly.&lt;br /&gt;2) While you click on the flash button, the invisible Allow button is floating on top of the flash button and actually receives your click.&lt;br /&gt;3) The Flash application now has full permission to access your web-cam, microphone etc and even have it stream to a server where it is recorded for future viewing.&lt;br /&gt;&lt;br /&gt;You can see a video of this in action at:  &lt;a href="http://www.youtube.com/watch?v=gxyLbpldmuU"&gt;Youtube&lt;/a&gt; and &lt;a href="http://vimeo.com/1910089?pg=embed&amp;amp;sec=1910089"&gt;Vimeo&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-3780482588360535562?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/I1GJczQkjaY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/3780482588360535562/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=3780482588360535562" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3780482588360535562?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/3780482588360535562?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/I1GJczQkjaY/clickjacking-explained.html" title="ClickJacking Explained" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/10/clickjacking-explained.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkUHQH88fSp7ImA9WxRSFUk.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-9133467937526732098</id><published>2008-09-15T23:04:00.005+05:30</published><updated>2008-09-16T11:20:31.175+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-09-16T11:20:31.175+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Owasp" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Conference" /><category scheme="http://www.blogger.com/atom/ns#" term="Education" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>OWASP Mumbai Chapter Meeting - 22nd September 2008</title><content type="html">I will be attending the OWASP Mumbai Chapter Meeting on the 22nd of September 2008. The details are as follows:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Date: &lt;/span&gt;22nd September, 2008 - Monday&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Timing: &lt;/span&gt;2:30 PM to 5:30 PM&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Venue:&lt;/span&gt; Hotel Heavens India, Seepz, Andheri (e)&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;To Register&lt;/span&gt;&lt;br /&gt;Kindly drop a mail to dharmeshmm at owasp dot org with following details to register for the event.&lt;br /&gt;&lt;br /&gt;Your Name:&lt;br /&gt;Your Organization/Institution:&lt;br /&gt;Your Designation:&lt;br /&gt;Your Contact No.:&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;&lt;br /&gt;To Sponsor&lt;/span&gt;&lt;br /&gt;Send a mail to dharmeshmm at owasp dot org to understand the sponsorship details.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-9133467937526732098?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/jPLoGF4YWD8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/9133467937526732098/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=9133467937526732098" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/9133467937526732098?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/9133467937526732098?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/jPLoGF4YWD8/owasp-mumbai-chapter-meeting-22nd.html" title="OWASP Mumbai Chapter Meeting - 22nd September 2008" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/09/owasp-mumbai-chapter-meeting-22nd.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcAR3s5eSp7ImA9WxRQFkk.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-8273355673210534905</id><published>2008-09-15T18:35:00.006+05:30</published><updated>2008-10-10T19:44:06.521+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-10T19:44:06.521+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Wireless Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Education" /><category scheme="http://www.blogger.com/atom/ns#" term="Device Security" /><title>Securing Your Home Wireless Network</title><content type="html">As most of us in India have noticed, Wireless Networks have been in the news these days for all the wrong reasons. These open networks have always been used by tech-savvy users however lately they have been utilized by malicious organizations to carry out their nefarious purposes (e.g. the recent bomb blasts).&lt;br /&gt;&lt;br /&gt;The home user, small businesses that often cannot implement complex security solutions are the ones who primarily suffer the consequences which range from large broadband bills to authorities knocking on your door at 3 AM.&lt;br /&gt;&lt;br /&gt;I've put down a quick article with 10 Steps for Securing Your Home Wireless Network:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1. Change Default Administrator Usernames and Passwords&lt;/span&gt;&lt;br /&gt;Most routers or access points come enabled with a default set of username/password combinations. These combinations are well documented and available online for hackers to use. If a hacker can access your device’s administrative pages they can modify the configuration and control all aspects of your device. These username/password combinations can be changed from the administrative panel and should be set to something difficult to guess.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2. Turn on WPA / WEP Encryption&lt;/span&gt;&lt;br /&gt;All Wireless devices support some form of encryption. Encryption technology scrambles messages sent over the air and ensures that they cannot be intercepted by hackers. Several encryption technologies exist for Wireless communication today. WPA is the strongest commonly available encryption technology for home devices however WEP can also be used.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3. Change the Default SSID&lt;/span&gt;&lt;br /&gt;Access points and routers all use a network name called the SSID. Manufacturers normally ship their products with the same SSID set for all routers. For example, the SSID for Netgear devices is normally "NETGEAR". The Default SSID can be changed from the administrative panel and should be set to something unique.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;4. Enable MAC Address Filtering&lt;/span&gt;&lt;br /&gt;Each wireless device possesses a unique identifier called the physical address or MAC address. Access points and routers keep track of the MAC addresses for all devices that connect to them. Wireless routers offer the option to key in the MAC addresses of your home equipment so as to restrict the network to only allow connections from those devices. It ensures that rogue users cannot connect to the wireless router without using advanced MAC spoofing techniques.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;5. Disable SSID Broadcast&lt;/span&gt;&lt;br /&gt;The wireless access point or router typically broadcasts the network name (SSID) over the air at regular intervals. This feature was designed for businesses and mobile hotspots where wireless clients may roam in and out of range. For the home user, this roaming feature is unnecessary, and it increases the likelihood someone will try to log in to your home network. Fortunately, most wireless access points allow the SSID broadcast feature to be disabled by the network administrator. Your SSID name can be manually inputted into your devices to prevent the need for SSID Broadcasts to be enabled.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;6. Do Not Auto-Connect to Open Wireless Networks&lt;/span&gt;&lt;br /&gt;Connecting to an open wireless network such as a free wireless hotspot or your neighbor's router exposes your computer to security risks and attacks. Although not normally enabled, most computers have a setting available allowing these connections to happen automatically without notifying the user. This setting should not be enabled except in temporary situations.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;7. Assign Static IP Addresses to Devices&lt;/span&gt;&lt;br /&gt;Most home wireless devices use dynamic IP addresses. DHCP technology is indeed easy to set up. Unfortunately, this convenience also works to the advantage of network attackers, who can easily obtain valid IP addresses from your network's DHCP pool. Turn off DHCP on the router or access point, set a fixed IP address range instead and then configure each connected device to match. Using a private IP address range (like 10.0.0.x) prevents computers from being directly reached from the Internet.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;8. Enable Firewalls On Each Computer and Router&lt;/span&gt;&lt;br /&gt;Modern network routers contain built-in firewall capability, but the option also exists to disable them. Ensure that your router's firewall is turned on. For extra protection, consider installing and running personal firewall software on each computer connected to the router.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;9. Position the Router or Access Point Safely&lt;/span&gt;&lt;br /&gt;Wireless signals normally reach to the exterior of a home. A small amount of signal leakage outdoors is not a problem, but the further this signal reaches, the easier it is for others to detect and exploit. Wireless signals often reach through neighboring houses and into streets. When installing a wireless home network, the position of the access point or router determines its reach. Try to position these devices near the center of the home rather than near windows to minimize leakage. Many routers allow you to reduce the range of your router from the administrative panel to prevent the signal leakage.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;10. Turn Off Network During Extended Periods of Non-Use&lt;/span&gt;&lt;br /&gt;The ultimate in wireless security measures, shutting down your network will most certainly prevent outside hackers from breaking in! While impractical to turn off and on the devices frequently, at least consider doing so during travel or extended periods of downtime.&lt;br /&gt;&lt;br /&gt;Article Referenced By:&lt;br /&gt;http://www.dailypioneer.com/126829/High5-the-Wi-Fi.html&lt;br /&gt;http://www.rediff.com/getahead/2008/oct/10wifi.htm&lt;br /&gt;http://www.ibnlive.com/news/top-10-tips-for-home-users-to-secure-wifi-networks/73852-11.html?from=search&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-8273355673210534905?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/Go38AvjlI4E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/8273355673210534905/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=8273355673210534905" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/8273355673210534905?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/8273355673210534905?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/Go38AvjlI4E/securing-your-home-wireless-network.html" title="Securing Your Home Wireless Network" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/09/securing-your-home-wireless-network.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQASXcyeip7ImA9WxdaEkg.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-1448433883410619849</id><published>2008-08-20T23:38:00.004+05:30</published><updated>2008-08-21T00:05:48.992+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-08-21T00:05:48.992+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Penetration Testing" /><category scheme="http://www.blogger.com/atom/ns#" term="Vulnerability Assessments" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="System Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><title>Confusion between Vulnerability Assessment and Penetration Testing</title><content type="html">There has always been a fair amount of confusion between &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Testing&lt;/a&gt; and &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessments&lt;/a&gt;. In India however the problem takes a new turn with vendors confusing between the two.&lt;br /&gt;&lt;br /&gt;I was recently in a meeting with a potential customer and we were discussing their current vendors and what they provide in their &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Test&lt;/a&gt;. As I glanced over the reports I noticed that the service provided was purely a &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessment&lt;/a&gt; masquerading as a &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Test&lt;/a&gt;. The particular vendor in question had only conducted a port scan followed by listing possible vulnerabilities that exist for the service and operating system versions identified.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;In my opinion I would barely even classify this as a &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessment&lt;/a&gt;. A &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessment Engagement from Security Brigade&lt;/a&gt; goes through the following phases:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Pre-Assessment Analysis&lt;/li&gt;&lt;li&gt;Information Gathering&lt;/li&gt;&lt;li&gt;Port Scanning&lt;/li&gt;&lt;li&gt;Enumeration&lt;/li&gt;&lt;li&gt;Threat Profiling &amp;amp; Risk Identification&lt;/li&gt;&lt;li&gt;Network Vulnerability Assessment&lt;/li&gt;&lt;li&gt;Application Vulnerability Assessment&lt;/li&gt;&lt;li&gt;Engagement Analysis&lt;/li&gt;&lt;li&gt;Mitigation Strategies&lt;/li&gt;&lt;li&gt;Report Generation&lt;/li&gt;&lt;li&gt;Support&lt;/li&gt;&lt;/ul&gt;A &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Testing Service&lt;/a&gt; however goes many steps further with the following phases:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Pre-Assessment Analysis&lt;/li&gt;&lt;li&gt;Information Gathering&lt;/li&gt;&lt;li&gt;Port Scanning&lt;/li&gt;&lt;li&gt;Enumeration&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Social Engineering&lt;/li&gt;&lt;li&gt;Threat Profiling &amp;amp; Risk Identification&lt;/li&gt;&lt;li&gt;Network Vulnerability Assessment&lt;/li&gt;&lt;li&gt;Application Vulnerability Assessment&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Exploit Research &amp;amp; Development&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Exploitation&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Privilege Escalation&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Retaining Access&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Network Propagation&lt;/li&gt;&lt;li&gt;Engagement Analysis&lt;/li&gt;&lt;li&gt;Mitigation Strategies&lt;/li&gt;&lt;li&gt;Report Generation&lt;/li&gt;&lt;li&gt;Support&lt;/li&gt;&lt;/ul&gt;The difference can be clearly seen in the fact that a &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Testing&lt;/a&gt; goes further after analyzing the vulnerabilities into exploitation, privilege escalation, retaining access, network prorogation etc. Simply put a &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessment&lt;/a&gt; provides an overview of the flaws that exist on the system while a &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Testing&lt;/a&gt; goes on to provide an impact analysis of the flaws identified, the possible impact of the flaw on the underlying network, operating system, database etc.&lt;br /&gt;&lt;br /&gt;I believe it is fairly important for Clients and especially Vendors in India to understand the difference and represent the two services in their traditionally accepted form. I believe this is a crucial step for Indian IT Security to take a step forward and providing real security to customers.&lt;br /&gt;&lt;br /&gt;One of the white papers that I am currently working on specifically looks at the difference between &lt;a href="http://securitybrigade.com/services/vulnerability_assessment.php"&gt;Vulnerability Assessments&lt;/a&gt; and &lt;a href="http://securitybrigade.com/services/penetration_testing.php"&gt;Penetration Tests&lt;/a&gt; with a focus on:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;What is covered by each service&lt;/li&gt;&lt;li&gt;What factors should be considered while determining their requirements&lt;br /&gt;&lt;/li&gt;&lt;li&gt;How a Client can determine their requirements&lt;/li&gt;&lt;li&gt;Comparison of the benefits and draw-backs of both the services&lt;/li&gt;&lt;li&gt;etc.&lt;/li&gt;&lt;/ul&gt;The paper should be released sometime this month and can be found on Security Brigade's website.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-1448433883410619849?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/ns_GJGwdTMg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/1448433883410619849/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=1448433883410619849" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1448433883410619849?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1448433883410619849?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/ns_GJGwdTMg/confusion-between-vulnerability.html" title="Confusion between Vulnerability Assessment and Penetration Testing" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/08/confusion-between-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAAR3k7eSp7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-5569521012897561849</id><published>2008-08-10T00:26:00.010+05:30</published><updated>2008-10-30T18:49:06.701+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:49:06.701+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="DNS Vulnerability" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="UDP Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><title>Dan Kaminsky's DNS Cache Poisoning Vulnerability Explained</title><content type="html">There has been a lot of talk recently about Dan Kaminsky's DNS Cache Poisoning Vulnerability. Simply put there are an extremely large amount of publicly accessible DNS servers that can fairly easily be tricked into storing and serving up malicious DNS Information. The impact of this malicious DNS Information is that users can be unknowingly tricked into accessing malicious sites and possibly compromise sensitive information such as: username, passwords etc.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;DNS Cache Poisoning attacks have been around for years now. However this vulnerability is far more exploitable and dangerous than its predecessors. Luckily for the world and all of its administrators, &lt;a href="http://www.doxpara.com/"&gt;Dan Kaminsky of DoxPara Research&lt;/a&gt; raised awareness about the criticality of this vulnerability and coordinated a massive effort with vendors to issue patches.  He gave vendors time to make patches and the public time to apply them before releasing all the details.&lt;br /&gt;&lt;br /&gt;In regards to the exploitability of this vulnerability, there are a few challenges that need to be overcome by the attackers.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Knowing when a DNS Server will issue a particular DNS Lookup:&lt;/span&gt; If the server doesn't already have the name cached, you can try to spoof the response right then, but you only get one shot.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Guessing the DNS query's transaction ID:&lt;/span&gt; it should be possible to blast the server with 65,536 spoofed responses (one for each transaction ID). The fact that this ID is only 16 bit is generally accepted as being too weak.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Creating a proper spoofed packet with poisoned information in it:&lt;/span&gt; Vulnerable DNS servers reuse the same source port for every outgoing request, which makes crafting the spoofed return UDP packets trivial (DNS servers that already randomized the source port are generally seen as being practically immune to this exploit, since attackers would have to guess nearly 2^32 combinations instead of only 65,536).&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Getting the spoofed response to the DNS Server before the real response: &lt;/span&gt;Latency may work against an attacker. But an attacker attacking his own ISP might not face either of these problems.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;Overall, an attacker would need an insane amount of patience and luck to pull this off.&lt;br /&gt;&lt;br /&gt;The steps an attacker would take to exploit this vulnerability would be something like:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Attacker asks Victim DNS Server: Who is gmail.google.com?&lt;/li&gt;&lt;li&gt;Victim DNS server asks the authority for google.com, Who is gmail.google.com?&lt;/li&gt;&lt;li&gt;Attacker blasts Victim with spoofed responses, each containing a different transaction ID. The packet contains a response with an IP for gmail.google.com, as well as an additional RR stating www.google.com is an IP address of the Attacker's choosing.&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;(Exploit) &lt;/span&gt;If a valid, spoofed response is received before the real response comes back, the Victim updates its cache with both the requested info as well as the poisonous IP information contained in the RR. The subsequent response from the authority for google.com is discarded.&lt;/li&gt;&lt;/ol&gt;This is repeated as necessary with new sub-domain requests, until one of the spoofed responses takes. When it takes, the attacker has circumvented the TTL problem and outsmarted the same-domain defense. Reports are this can happen in less than 10 minutes. i.e. 10 minutes to replace cnn.com, or youtube.com, or any other popular site with a site of your own choosing. This means for a certain period of time and for the users of your victim DNS Server you control where these popular websites point. You will be able to deface the website, show them information of your choice, or try to phish for their personal information.&lt;br /&gt;&lt;br /&gt;An exploit is currently available from the &lt;a href="http://www.caughq.org/exploits/CAU-EX-2008-0003.txt"&gt;Computer Academic Underground&lt;/a&gt;. It provides a good technical summary on the vulnerability and how exploitation works.&lt;br /&gt;&lt;br /&gt;This exploit attacks a fairly ubiquitous flaw in DNS implementations which Dan Kaminsky found and disclosed ~Jul 2008. It caches a single malicious host entry into the target nameserver by sending random sub-domain queries to the target DNS server coupled with spoofed replies to those queries from the authoritative nameservers for the domain which contain a malicious host entry for the hostname to be poisoned in the authority and additional records sections. Eventually, a guessed ID will match and the spoofed packet will get accepted, and due to the additional hostname entry being within constraints of the original request the malicious host entry will get cached.&lt;br /&gt;&lt;br /&gt;So what's the fix?  There really is no fix, short of &lt;a href="http://www.isc.org/index.pl?/sw/bind/index.php"&gt;using DNSSEC&lt;/a&gt;, or moving to some other cryptographic method of trust.  &lt;a href="http://blogs.zdnet.com/security/?p=1552"&gt;Using TCP instead of UDP&lt;/a&gt; has come up (this would add the additional, now nearly impossible challenge of guessing sequence numbers), but was shot down as being too resource intensive.  So the accepted workaround is what was already mentioned above: DNS servers should &lt;a href="http://www.circleid.com/posts/87143_dns_not_a_guessing_game/"&gt;randomize their source ports&lt;/a&gt;.  Then attackers would have a much, much harder time spoofing the return packets.&lt;br /&gt;&lt;br /&gt;For those of us out of India, I don't see much hope in waiting for your respective ISPs to patch. In the meanwhile I recommend switching to the DNS Servers from &lt;a href="http://www.opendns.com/"&gt;OpenDNS&lt;/a&gt; as a precautionary measure.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-5569521012897561849?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/avLz2NDPc_U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/5569521012897561849/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=5569521012897561849" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5569521012897561849?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5569521012897561849?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/avLz2NDPc_U/dam-kaminskys-dns-cache-poisoning.html" title="Dan Kaminsky's DNS Cache Poisoning Vulnerability Explained" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/08/dam-kaminskys-dns-cache-poisoning.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcNQ30-eSp7ImA9WxdUFUw.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-624958412052257233</id><published>2008-07-29T02:58:00.009+05:30</published><updated>2008-07-31T19:18:12.351+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-31T19:18:12.351+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><category scheme="http://www.blogger.com/atom/ns#" term="Wireless Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Device Security" /><title>Wireless In-Security Used by Terrorists</title><content type="html">Most of you reading this, will have heard about the &lt;a href="http://afp.google.com/article/ALeqM5gJYkICtfUeHjP4nFiwixyb_JF3Ig"&gt;bomb-blasts&lt;/a&gt; &lt;a href="http://www.expressindia.com/latest-news/Blast-toll-revised--21-blasts--more-than-50-dead/341374/"&gt;that&lt;/a&gt; &lt;a href="http://www.arabnews.com/?page=7&amp;amp;section=0&amp;amp;article=112219&amp;amp;d=29&amp;amp;m=7&amp;amp;y=2008"&gt;have&lt;/a&gt; &lt;a href="http://www.hindustantimes.com/storypage/storypage.aspx?sectionName=&amp;amp;id=cf744f75-8c60-4a91-a5a4-9077659d2380&amp;amp;&amp;amp;Headline=Surat+on+high+alert%3b+10+live+bombs+found&amp;amp;strParent=strParentID"&gt;rocked&lt;/a&gt; &lt;a href="http://www.hindustantimes.com/Redir.aspx?ID=938dfd67-78db-44e1-95ba-32bf4e147f33&amp;amp;SectionName=IndiaSectionPage"&gt;Bangalore&lt;/a&gt; &lt;a href="http://www.hindustantimes.com/Redir.aspx?ID=28a8b1bf-a766-49f2-9da4-92360dd28906"&gt;and&lt;/a&gt; &lt;a href="http://www.hindustantimes.com/Redir.aspx?ID=cebd6562-f535-4ffe-a2e3-88ab437dd607&amp;amp;SectionName=IndiaSectionPage"&gt;Ahmedabad&lt;/a&gt;. Five minutes before each of the blasts the terrorists "Indian Mujahedin" sent out e-mails to the media warning about the threats and provoking the authorities to stop them in time.&lt;br /&gt;&lt;br /&gt;Through the investigation the authorities have identified a &lt;a href="http://www.hindustantimes.com/storypage/storypage.aspx?id=a0fbc9b9-bd1a-4b66-897c-d1ae1050e4e2&amp;amp;ParentID=cf744f75-8c60-4a91-a5a4-9077659d2380&amp;amp;&amp;amp;Headline=Navi+Mumbai%2c+the+new+terror+hub"&gt;wireless router&lt;/a&gt; belonging to an American Family in New Bombay as the source of the e-mails. Unfortunately for the family, their wireless router had no form of security or logging enabled.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Now not only is the family in a legal mess trying to prove their innocence without logs but also the terrorists will be able to easily get away without much hope of their identity being tracked. What concerns me most is that even if the family had enabled &lt;a href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy"&gt;WEP encryption&lt;/a&gt; on their router, it would have taken nothing more then a few minutes to crack the password.&lt;br /&gt;&lt;br /&gt;If you want to protect your wireless router from external threats, I would recommend implementing a combination of &lt;a href="http://en.wikipedia.org/wiki/Wired_Equivalent_Privacy"&gt;WEP&lt;/a&gt; or &lt;a href="http://en.wikipedia.org/wiki/Wi-Fi_Protected_Access"&gt;WPA encryption&lt;/a&gt; and &lt;a href="http://en.wikipedia.org/wiki/MAC_filtering"&gt;MAC Address Filtering&lt;/a&gt;. For instructions, you can refer to this article from &lt;a href="http://www.pcmag.com/article2/0,2704,1310389,00.asp"&gt;PC Magazine&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Update:&lt;/span&gt; Since I have last heard, the family is still being made to run around trying to prove their innocence. The wireless-router had no logging mechanism enabled, so its not possible to confirm whether the e-mail was sent by the family or a random passerby.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-624958412052257233?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/OYs7olV5zy8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/624958412052257233/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=624958412052257233" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/624958412052257233?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/624958412052257233?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/OYs7olV5zy8/wireless-in-security-used-by-terrorists.html" title="Wireless In-Security Used by Terrorists" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/07/wireless-in-security-used-by-terrorists.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMHRXk7eyp7ImA9WxdUEUw.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-5157376377724126012</id><published>2008-07-27T03:55:00.007+05:30</published><updated>2008-07-27T04:33:54.703+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-27T04:33:54.703+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Backdoors" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="Conference" /><category scheme="http://www.blogger.com/atom/ns#" term="Browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="Education" /><title>Browser Based Malware</title><content type="html">For some time now, I have been interested in browser based malware attacks and even more so after reading &lt;a href="http://www.armandoromeo.com/"&gt;Armando Romeo&lt;/a&gt;'s &lt;a href="http://hackerscenter.com/index.php?/Bloggers/1592-Exploiting-browsers-mental-diseases.html"&gt;Posts&lt;/a&gt; &lt;a href="http://hackerscenter.com/index.php?/Bloggers/1778-Firefox-Addons-own-ya-Keylogger-POC.html"&gt;about Backdoors&lt;/a&gt; &lt;a href="http://hackerscenter.com/index.php?/Bloggers/1935-More-Firefox-Addons-ownage-POC.html"&gt;in Firefox&lt;/a&gt;&lt;a href="http://hackerscenter.com/index.php?/Bloggers/1935-More-Firefox-Addons-ownage-POC.html"&gt; Extensions.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I've spent some time researching the topic and the various attack vectors and opportunities that are available through browser based malware. Consequently, I submitted a paper for the &lt;a href="http://www.aavar.org/avar2008/index.htm"&gt;Avar 2008 Conference&lt;/a&gt; on Browser Based Malware Attacks which will detail the research I've conducted.&lt;br /&gt;&lt;br /&gt;Avar is the largest Asia-Pacific conference for anti-malware technologies that is being brought to Delhi, India by &lt;a href="http://www.quickheal.com/"&gt;QuickHeal&lt;/a&gt; in December 08.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;I have been exploring the various attack vectors through which browser based malware could exist and analyzing their impact as compared to traditional malware.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_Cx2gSf_tH4U/SIusZi-4YcI/AAAAAAAAABw/_-QgsHYXkqQ/s1600-h/danger.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_Cx2gSf_tH4U/SIusZi-4YcI/AAAAAAAAABw/_-QgsHYXkqQ/s400/danger.png" alt="" id="BLOGGER_PHOTO_ID_5227461347380847042" border="0" /&gt;&lt;/a&gt;&lt;span class="fullpost"&gt;Browser-based malware use the user’s browser to disrupt computer functions. This type of malware is typically unleashed when someone visits a web page that appears harmless, but actually contains hidden malicious code intended to sabotage a computer or compromise the user's privacy. The result of the attack may be as simple as a crashed browser; or as serious as the theft of personal information or the loss of confidential proprietary data.&lt;br /&gt;&lt;br /&gt;Before the days of Web 2.0, browser based malware was fairly limited to drive-by-downloads, however since the discovery of JavaScript Attacks, CSS attacks etc the field has opened up. Some of the currently seen browser-based malware techniques are as follows:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Drive-By Downloads&lt;/li&gt;&lt;li&gt;JavaScript Worms and Viruses&lt;/li&gt;&lt;li&gt;CSS Attacks&lt;/li&gt;&lt;li&gt;Browser Add-ons Viruses and Worms&lt;/li&gt;&lt;/ul&gt;In the current state of the internet, much of a user’s life runs through their browser. With browser-based technologies such as: OSs, Storage/Backup systems, E-mails, Social Networking Web-sites, CRMs, Intranets etc. For an attacker, controlling a user's browser has suddenly become as fruitful as gaining access to their system.&lt;br /&gt;&lt;br /&gt;Also considering that System based viruses and worms have are being comparitively well covered by Anti-Virus, Anti-Malware and Internet Security Products, it leaves the door wide-open for Browser Based Malware Attacks.&lt;br /&gt;&lt;br /&gt;Through this research paper I intend to carry out a detailed analysis of browser-based malware threats and hope to dissect each threat and determine the following:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;How they work?&lt;/li&gt;&lt;li&gt;What is the threat posed and possible impact?&lt;/li&gt;&lt;li&gt;How they can be remediated?&lt;/li&gt;&lt;li&gt;Will any current security products thwart this attack?&lt;/li&gt;&lt;/ul&gt;Also: If anyone is going to be attending AVAR 08, drop me an e-mail or leave a comment.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-5157376377724126012?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/M6Xktfg7cKA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/5157376377724126012/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=5157376377724126012" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5157376377724126012?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5157376377724126012?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/M6Xktfg7cKA/browser-based-malware.html" title="Browser Based Malware" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp3.blogger.com/_Cx2gSf_tH4U/SIusZi-4YcI/AAAAAAAAABw/_-QgsHYXkqQ/s72-c/danger.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/07/browser-based-malware.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEANR3c6cSp7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-5568555838834400556</id><published>2008-06-24T09:56:00.008+05:30</published><updated>2008-10-30T18:49:56.919+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:49:56.919+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Physical Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Bank" /><category scheme="http://www.blogger.com/atom/ns#" term="Sniffing" /><category scheme="http://www.blogger.com/atom/ns#" term="Incident" /><title>Physical Security: The Lost Art</title><content type="html">I had to visit my local bank today to take care of some papers. As I was sitting across the table talking about how they spelled something wrong on of my documents; I notice that right next to the Manager's office is a small but well packed Server Room.&lt;br /&gt;&lt;br /&gt;I immediately started assessing the physical security of that server room and was disappointed by the fact that there was absolutely no access control mechanism; Just a door with a shoe rack outside. A few minutes later and a bit scared about my money, I walked out of the bank and headed back.&lt;br /&gt;&lt;br /&gt;As I walked away from the bank, I noticed a LAN wire coming out of a window. This window was positioned exactly where the Server Room had been. Imagine my surprise, a Bank's Server Room has its information transmitted through a exposed LAN wire that is lying on public property?!&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;This sounds like a bad combination and a easy opportunity to cut, crimp and sniff.  I decided to explore this further and see where the LAN wire led me. I walked around the bank and found an Enclosure that the wire was entering. This was of course exposed behind the bank and not monitored by anyone at anytime. Inside this unlocked box were routers, switches, and other devices up for grabs and sniffing.&lt;br /&gt;&lt;br /&gt;As a security professional, I am not only appalled by this but might be forced to give them a complimentary penetration testing service for the safety of my own money.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-5568555838834400556?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/nQdSG4XbfXk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/5568555838834400556/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=5568555838834400556" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5568555838834400556?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/5568555838834400556?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/nQdSG4XbfXk/physical-security-lost-art.html" title="Physical Security: The Lost Art" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/06/physical-security-lost-art.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8FRX8zfip7ImA9WxRWE0o.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-1621324866976534225</id><published>2008-06-06T12:42:00.029+05:30</published><updated>2008-10-30T18:50:14.186+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-10-30T18:50:14.186+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SNMP" /><category scheme="http://www.blogger.com/atom/ns#" term="UDP Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Network Security" /><category scheme="http://www.blogger.com/atom/ns#" term="Device Security" /><title>SNMP Hacking</title><content type="html">I've spent a lot of time exploring alternative attacking&lt;br /&gt;methods other than the traditional flaws. One of the routes I've really enjoyed exploring has been SNMP attacks. I thought I'd give an overview for those who are not very familiar with the subject.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_Cx2gSf_tH4U/SE45VZ5CMYI/AAAAAAAAABQ/-F2b8apJL-k/s1600-h/ninja.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_Cx2gSf_tH4U/SE45VZ5CMYI/AAAAAAAAABQ/-F2b8apJL-k/s320/ninja.jpg" alt="" id="BLOGGER_PHOTO_ID_5210164858804384130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;Simple Network Management Protocol (SNMP)&lt;/span&gt; is an application-layer protocol for managing TCP/IP based networks. SNMP runs over UDP (which runs over IP).  Most administrators/security guys fail to understand SNMP and its security impacts.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;What is SNMP Used For?&lt;/span&gt;&lt;br /&gt;SNMP is a protocol that is simply used to manage multiple devices on enterprise networks; i.e. where the administrative software can contact each device via SNMP and retrieve its status and diagnostic information. This way an administrator can keep an eye on all of his/her devices without much effort. Also with the "write string" mentioned below they can use it to change configuration information over a large number of devices.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Does SNMP Use Authentication?&lt;/span&gt;&lt;br /&gt;SNMP uses community strings as a key or password. Provide the right string and gain a different level of access.&lt;br /&gt;&lt;br /&gt;By default there is the "public" string that is enabled on most servers and "private" string that is enabled on some servers. It is possible however, to &lt;a href="http://www.securiteam.com/tools/5EP0N154UC.html"&gt;brute-force SNMP community strings&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;"public" and "private" strings will generally give you read-only access, however this can be fairly dangerous also (as seen in one of the examples below). Brute-forcing the write access strings is easy as SNMP is over the UDP protocol. The speed of attack can be improved significantly then one that is done over TCP and the Source IP can be easily spoofed.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;OID: Is a string (series of numbers, seperated by ".") that is used to tell the device what information you want. Different devices have different OIDs.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;The Threat&lt;br /&gt;&lt;/span&gt;SNMP "walking" is very dangerous even with read-only access. Windows servers disclosed full list of user-names via SNMP walking the oid "1.3.6.1.4.1.77.1.2.25". There exist many tools intended for the purpose of bruteforcing and identifying OIDs once a weak SNMP Server is found. This can be used to identify and modify a lot of sensitive information on the device.&lt;br /&gt;&lt;br /&gt;There are many tools that are included in the SNMPWalk kit for different purposes. I will walk through SNScan from Foundstone and SNMPWalk.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="http://www.foundstone.com/us/resources/proddesc/snscan.htm"&gt;SNScan&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;SNMP Scanner that can be used to scan IP ranges for SNMP Servers with weak strings, including a brute-force feature.&lt;br /&gt;&lt;br /&gt;&lt;a style="font-weight: bold;" href="http://www.net-snmp.org/"&gt;SNMPWalk&lt;/a&gt;&lt;br /&gt;The snmpwalk command is designed to perform a sequence of chained GETNEXT requests automatically, rather than having to issue the necessary snmpgetnext requests by hand.&lt;br /&gt;&lt;br /&gt;Simply: It is able to identify the various OID strings and retrieve their content.&lt;br /&gt;&lt;br /&gt;Example:&lt;br /&gt;D:\snmp&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;snmpwalk&lt;/span&gt; test.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;yash&lt;/span&gt;-home public&lt;br /&gt;.iso.3.6.1.2.1.1.1.0 = "Linux test.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;yash&lt;/span&gt;-home 2.6.9-023stab046.2 #1 Mon Dec 10 14:51&lt;br /&gt;:29 &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;MSK&lt;/span&gt; 2007 i686"&lt;br /&gt;.iso.3.6.1.2.1.1.2.0 = &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;OID&lt;/span&gt;: .iso.3.6.1.4.1.8072.3.2.10&lt;br /&gt;.iso.3.6.1.2.1.1.3.0 = &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;Timeticks&lt;/span&gt;: (248307958) 28 days, 17:44:39.58&lt;br /&gt;.iso.3.6.1.2.1.1.4.0 = "Root &lt;root@localhost&gt; (configure /etc/snmp/snmp.local.co&lt;br /&gt;nf)"&lt;br /&gt;.iso.3.6.1.2.1.1.5.0 = "test.yash-home"&lt;br /&gt;.iso.3.6.1.2.1.1.6.0 = "Unknown (edit /etc/snmp/snmpd.conf)"&lt;br /&gt;.iso.3.6.1.2.1.1.8.0 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.1 = OID: .iso.3.6.1.6.3.1&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.2 = OID: .iso.3.6.1.2.1.49&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.3 = OID: .iso.3.6.1.2.1.4&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.4 = OID: .iso.3.6.1.2.1.50&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.5 = OID: .iso.3.6.1.6.3.16.2.2.1&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.6 = OID: .iso.3.6.1.6.3.10.3.1.1&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.7 = OID: .iso.3.6.1.6.3.11.3.1.1&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.2.8 = OID: .iso.3.6.1.6.3.15.2.1.1&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.1 = "The MIB module for SNMPv2 entities"&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.2 = "The MIB module for managing TCP implementations"&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.3 = "The MIB module for managing IP and ICMP implementati&lt;br /&gt;ons"&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.4 = "The MIB module for managing UDP implementations"&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.5 = "View-based Access Control Model for SNMP."&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.6 = "The SNMP Management Architecture MIB."&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.7 = "The MIB for Message Processing and Dispatching."&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.3.8 = "The management information definitions for the SNMP&lt;br /&gt;User-based Security Model."&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.1 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.2 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.3 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.4 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.5 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.6 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.7 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.1.9.1.4.8 = Timeticks: (11) 0:00:00.11&lt;br /&gt;.iso.3.6.1.2.1.25.1.1.0 = Timeticks: (248309155) 28 days, 17:44:51.55&lt;br /&gt;End of MIB&lt;br /&gt;&lt;br /&gt;D:\snmp&gt;snmpwalk testios.yash public&lt;br /&gt;.iso.3.6.1.2.1.1.1.0 = "Cisco Internetwork Operating System Software ..IOS (tm)&lt;br /&gt;7200 Software (C7200-IK9O3S-M), Version 12.3(9b), RELEASE SOFTWARE (fc1)..Copyri&lt;br /&gt;ght (c) 1986-2004 by cisco Systems, Inc...Compiled Wed 18-Aug-04 15:31 by dchih"&lt;br /&gt;&lt;br /&gt;...... followed by a long list of information such as processes, users, modules, ports, etc.&lt;br /&gt;&lt;br /&gt;D:\snmp&gt;snmpwalk hp.yash public&lt;br /&gt;.iso.3.6.1.2.1.1.1.0 = "HP-UX gedis1 B.10.20 A 9000/803 2013446997"&lt;br /&gt;.iso.3.6.1.2.1.1.2.0 = OID: .iso.3.6.1.4.1.11.2.3.2.3&lt;br /&gt;.iso.3.6.1.2.1.1.3.0 = Timeticks: (2955823000) 342 days, 2:37:10.00&lt;br /&gt;&lt;br /&gt;D:\snmp&gt;snmpwalk snmp.yash public&lt;br /&gt;.iso.3.6.1.2.1.1.1.0 = "Sun SNMP Agent, Sun-Fire-480R"&lt;br /&gt;.iso.3.6.1.2.1.1.2.0 = OID: .iso.3.6.1.4.1.42.2.1.1&lt;br /&gt;.iso.3.6.1.2.1.1.3.0 = Timeticks: (422632606) 48 days, 21:58:46.06&lt;br /&gt;.iso.3.6.1.2.1.1.4.0 = "System administrator"&lt;br /&gt;.iso.3.6.1.2.1.1.5.0 = "mu-me01-ns-ctm001"&lt;br /&gt;.iso.3.6.1.2.1.1.6.0 = "System administrators office"&lt;br /&gt;&lt;br /&gt;D:\snmp&gt;snmpwalk win.yash public&lt;br /&gt;.iso.3.6.1.2.1.1.1.0 = "Hardware: x86 Family 15 Model 4 Stepping 1 AT/A&lt;br /&gt;T COMPATI&lt;br /&gt;BLE - Software: Windows 2000 Version 5.0 (Build 2195 Uniprocessor Free)"&lt;br /&gt;.iso.3.6.1.2.1.1.2.0 = OID: .iso.3.6.1.4.1.311.1.1.3.1.2&lt;br /&gt;.iso.3.6.1.2.1.1.3.0 = Timeticks: (466602853) 54 days, 0:07:08.53&lt;br /&gt;&lt;br /&gt;Anyway as you can see a LOT of information was revealed via SNMPWalking; and in the case of many other devices much more sensitive information can be disclosed.&lt;br /&gt;&lt;br /&gt;For e.g:&lt;br /&gt;Windows servers return the full list of user names by snmwalking the OID 1.3.6.1.4.1.77.1.2.25.&lt;br /&gt;&lt;br /&gt;BT Voyager 2000 router leaking the ISP credentials including the password.&lt;br /&gt;&lt;br /&gt;HP JetDirect printers leaking the admin password via SNMP read access (using OIDs .iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0 and .1.3.6.1.4.1.11.2.3.9.1.1.13.0).&lt;br /&gt;&lt;br /&gt;Dynamic DNS credentials disclosure on ZyXEL Prestige routers via the OID 1.3.6.1.4.1.890.1.2.1.2.6.0.&lt;br /&gt;&lt;br /&gt;SNMP servers contain a lot of information, in many cases revealing passwords and other sensitive information. However most security consultants are unaware of what SNMP Security is and how it can be used by hackers to manipulate your networks and systems.&lt;br /&gt;&lt;br /&gt;I am working on a paper on SNMP Security that will be published soon on &lt;a href="http://www.securitybrigade.com/"&gt;Security Brigade's Website.&lt;/a&gt;&lt;br /&gt;&lt;/root@localhost&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-1621324866976534225?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/5ZpZcXun_-8" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/1621324866976534225/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=1621324866976534225" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1621324866976534225?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/1621324866976534225?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/5ZpZcXun_-8/snmp-hacking.html" title="SNMP Hacking" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp3.blogger.com/_Cx2gSf_tH4U/SE45VZ5CMYI/AAAAAAAAABQ/-F2b8apJL-k/s72-c/ninja.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/06/snmp-hacking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0YNQXgyeip7ImA9WxdUEEU.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-8530890503573419140</id><published>2008-05-16T15:33:00.005+05:30</published><updated>2008-07-26T20:43:10.692+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-26T20:43:10.692+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Training" /><category scheme="http://www.blogger.com/atom/ns#" term="Security Industry" /><category scheme="http://www.blogger.com/atom/ns#" term="Education" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Security In The Education Process</title><content type="html">I recently read a couple of Blog posts about Security in the education process.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://securambling.blogspot.com/2008/04/catching-them-early-build-security-in.html"&gt;Catching them early ... build security in to the psyche - Dinesh O'Bareja&lt;/a&gt;&lt;br /&gt;&lt;a href="http://smartsecurity.blogspot.com/2008/04/can-security-be-incorporated-in.html"&gt;Can Security be incorporated in the Computer Science &amp;amp; IT courses? - Dharmesh M Mehta&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Both Dinesh and Dharmesh have a similar idea, i.e. integrating IT Security practices into the education process. However as much as I would like to see this happen, I think it would be an impractical idea in the current education system for India.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Most engineers and information technology professionals that are employed by the vast IT industry have a weak hold on programming languages and methodologies as they walk out of college. Most of what they know is learned on the job or in the pre-placement trainings. A lot of those brought into Systems Engineer or Developer positions are those that even lack an IT background.&lt;br /&gt;&lt;br /&gt;Further to make this an even harder task to achieve; the syllabus is already lacking and outdated. Its hard to teach security in the education process; when we are teaching students to use Visual C++ 6.0 and Visual Basic 6.0 instead of .NET.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_Cx2gSf_tH4U/SC1idvKaUQI/AAAAAAAAABI/tSXk-kVxDmU/s1600-h/HomerSimpson46.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp3.blogger.com/_Cx2gSf_tH4U/SC1idvKaUQI/AAAAAAAAABI/tSXk-kVxDmU/s320/HomerSimpson46.gif" alt="" id="BLOGGER_PHOTO_ID_5200921407698653442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;In my opinion, the first step to introducing Security in the education process is to educate the educators. To ensure that the teaching staff is well educated with Security Best Practices. When this happens; security practices will start trickling into their teaching methods and automatically show up in the students.&lt;br /&gt;&lt;br /&gt;I believe that instead of teaching security practices to students, we eliminate the insecure practices being taught to them. This way when students walk out with an engineer degree, they have only been taught secure coding for the last 4 years.&lt;br /&gt;&lt;br /&gt;At &lt;a href="http://www.securitybrigade.com/"&gt;Security Brigade&lt;/a&gt;, we are working on many training solutions, from implementing entire Security courses to Security for the educators. We will also be holding a few ethical hacking trainings in the next few months, possibly one in Mumbai in the last week of May.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-8530890503573419140?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/XSxRlmVNoOY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/8530890503573419140/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=8530890503573419140" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/8530890503573419140?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/8530890503573419140?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/XSxRlmVNoOY/security-in-education-process.html" title="Security In The Education Process" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp3.blogger.com/_Cx2gSf_tH4U/SC1idvKaUQI/AAAAAAAAABI/tSXk-kVxDmU/s72-c/HomerSimpson46.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/05/security-in-education-process.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UFQnk6cCp7ImA9WxdUEEU.&quot;"><id>tag:blogger.com,1999:blog-1365931735817725983.post-7231324189553499088</id><published>2008-05-15T13:10:00.009+05:30</published><updated>2008-07-26T20:43:33.718+05:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2008-07-26T20:43:33.718+05:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Backdoors" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="Browsers" /><category scheme="http://www.blogger.com/atom/ns#" term="Application Security" /><title>Trust you plugins? Think again</title><content type="html">Over the last weekend, &lt;a href="http://hackerscenter.com/index.php?/View-user-profile.html?user=62"&gt;Armando Romeo&lt;/a&gt; and I spent some time discussing the attack vectors possible by inserting "backdoor" code into the Firefox (Mozilla) browser through &lt;span style="font-style: italic;"&gt;Extensions, Themes and Language Packs.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_Cx2gSf_tH4U/SCw2avKaUPI/AAAAAAAAABA/LdZeSmPoFyE/s1600-h/070419_gimme_your_cache.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://bp2.blogger.com/_Cx2gSf_tH4U/SCw2avKaUPI/AAAAAAAAABA/LdZeSmPoFyE/s320/070419_gimme_your_cache.gif" alt="" id="BLOGGER_PHOTO_ID_5200591502670713074" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span class="fullpost"&gt;Romeo has the &lt;span style="font-style: italic;"&gt;proof-of-concepts&lt;/span&gt; ready for two scenarios - In-browser keylogger and Download and save executable. Two very dangerous scenarios for your "Mac OS X for FF Theme" to be playing with. It would be possible for this vulnerability to be used to map the network and carry out many other dangerous attacks on the intranet.&lt;br /&gt;&lt;br /&gt;Just as we went about playing with the fact that the same POCs worked well with Thunderbird and other Mozilla products, we found &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=432406"&gt;this&lt;/a&gt;. Turns out there were others in the wild who had already explored this concept and put it to work to compromise 10000s of people.&lt;br /&gt;&lt;br /&gt;This whole Mozilla incident brings me to a larger point: &lt;span style="font-weight: bold;"&gt;Do you trust your plugins?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Not just Mozilla; with a few minutes of Googling I was able to identify the following applications that allow plugins:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Internet Explorer&lt;/li&gt;&lt;li&gt;Miranda IM&lt;/li&gt;&lt;li&gt;Wordpress&lt;/li&gt;&lt;li&gt;Total Commander&lt;/li&gt;&lt;li&gt;Joomla&lt;/li&gt;&lt;li&gt;Ad-aware&lt;/li&gt;&lt;li&gt;Virtual-DJ&lt;/li&gt;&lt;li&gt;........&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;There are 1000s of applications out there that blindly trust third party plugins/addons.&lt;br /&gt;&lt;br /&gt;The concerning part of such attacks that can occur from plugins is that in most cases they would be missed by traditional control mechanisms such as Anti-viruses, Firewalls etc.&lt;br /&gt;&lt;br /&gt;I havn't had the time to play with each of these scenarios as of yet, but would definitely like to sometime soon. As for now, disabling javascript on your browser is no longer enough. You will need a source code audit on every extension/theme/language pack you install in Firefox or any other application. Until Mozilla fixes the issue, I recommend running Firefox from &lt;a href="http://www.sandboxie.com/"&gt;Sandboxie&lt;/a&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1365931735817725983-7231324189553499088?l=www.yashkadakia.com' alt='' /&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/YashKadakia/~4/LgL90y97r8w" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.yashkadakia.com/feeds/7231324189553499088/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=1365931735817725983&amp;postID=7231324189553499088" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7231324189553499088?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/1365931735817725983/posts/default/7231324189553499088?v=2" /><link rel="alternate" type="text/html" href="http://rss.yashkadakia.com/~r/YashKadakia/~3/LgL90y97r8w/trust-you-plugins-think-again.html" title="Trust you plugins? Think again" /><author><name>Yash Kadakia</name><uri>http://www.blogger.com/profile/13205115249569575292</uri><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="02129042022654743768" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://bp2.blogger.com/_Cx2gSf_tH4U/SCw2avKaUPI/AAAAAAAAABA/LdZeSmPoFyE/s72-c/070419_gimme_your_cache.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.yashkadakia.com/2008/05/trust-you-plugins-think-again.html</feedburner:origLink></entry></feed>
