Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, 9 December 2009

Random Musings - Day #343

Been trying to find some useful documents for work. A good best practice site maybe at sans. Here's a comparison between OpenVPN and IPSec.

Wednesday, 30 September 2009

Random Musings - Day #273

Having flashbacks of all kinds including the recent the har2009, which included the lockpicking championships (dutch open). Your guide to lockpicking is there. A stranger flashback was the jingle for Cannings Ice Cream. Coincidently, could there be a connection with Canning Town? Apparently it was named after Ernest Canning.

PCI Standards are a bit unclear about whether using SSLv2 should fail a company or not. They claim it is only applicable if cardholder data is transmitted with it. To me, PCI Standards is just trying to a pleasure GELF, making you see what you want to see... and open to massive misintepretation!

Somebody went down on Virgin

Friday, 4 September 2009

Random Musings - Day #247

The Security Accounts Manager (SAM) can be stored in LANMAN hash and/or NTLM. LANMAN makes passwords brute-force attacks easy if the SAM is retrieved.

There is a registry setting to look for under "HKLM\System\CurrentControlSet\Control\LSA", there is a key "LMCompatibilityLevel" which has acceptable range of 0-5. 0 is usually default, which means all hashing is acceptable. You should really set it to 4 or 5. Microsoft discuss this on their support site

More useful links include: arp-scan, introduction to steganograhpy, XSS in the Cisco Ironport and how to look up reverse zones for ip addresses in DNS.

The well known SMB vulnerability ms09-001 does have POC exploits but they only crash the concerned system best demonstrated by 4xunderground.

Thursday, 3 September 2009

Random Musings - Day #246

On the Open Source Vulnerability Database (OSVDB), the first entry is the coldfusion information disclosure
Here's a good introduction to HTTP Response Splitting and the infamous cheat-sheet. All the finger abuse from yesteryear in a nice page.

Apparently, this is the way to lost the fat around your stomach.

Friday, 3 April 2009

Random Musings - Day #93

When I last looked the highly touted Europa Gym was still open for business.

Earn money fast by dancing (if male)
It looks like guys can get paid to dance because of so many women wanted to take ballroom dance classes after strict come dancing that they are sans partner. However I would take the article with a pinch of sale because the article was doing the rounds last month as in the evening standard and it looks like the same company, Simply Dance Partners were interviewed.

For your security
There's a useful benchmarking tool for Cisco routers and firewall.
Security Configuration Wizard (SCW) can be used to automagically set up system for specific jobs, e.g. DNS, mail, web, etc and autogenerate a policy for it.
Here's a precursor 'build your firewall rulebase' guide.

Saturday, 31 January 2009

Security Musings #1

Session Handling
Session management is far better than it used to be when session hijacking (example) and session fixation were common.
Problems can still be seen if the session management is handled in bespoke manner. A session id has been known to be configured with base64 encoding of parameters.
It is hard to get right manually and hence there are frameworks in place to stop the reinvention of the wheel.
But I have seen some websites that use the same preauth session id for its authenticated session. It is recommended that
Session ID regeneration should be used in Java and ASP.Net to prevent session fixation.
So on the face of it, it would be bad without. However, the session id is usually stored in the cookie, which in itself is a hard to fixate. The alternate way would to include the session ID as part of the URL (e.g. displayHomePage.do;jsessionid=B469usPwntry).
If that is blocked and throws away the session id set that should be sufficient. Furthermore, by hook or crook, additional cookies are set at preauth that change postauth. So your session fixator and session hijacker will need to know this additional information if there are checks for those cookies.

Clickjacking
Clickjacking is a new attack that uses code and transparent layers to trick users into visiting sites that are not exactly advertised in the browser. There is also some theory behind it.

Zero day initiative
Zero day (not to be confused with the finnish movie of the same name) is a computer threat that tries to exploit unknown, undisclosed or patchfree computer application vulnerabilities. Interestingly, you can get paid good money to find and post vulnerabilities with the zero day initiative. ZDNet have a blog called zero day as well. Whilst security researchers, eeye have a good tracker of new zero day attacks.

Web Application Scanners
Here is a very comprehensive evaluation of web vulnerability scanners. It compares Acunetix WVS, IBM Rational Appscan and HP Webinspect.

CESG Certified Products & Services
Here is a comprehensive directory of CCTM (CESG Claims Tested Mark) awards for products and services. Coincidently, here is a list of pen-testing companies according to google. At the time of writing, salaries for CESG-related jobs were rising modestly (unless you were in Checkpoint, which was taking a big knock).

Links

Wednesday, 28 January 2009

Random Musings - Day #28

After regailing shutdown messages on Unix boxes at university and discussing Calvin Harris. The thought crossed my mind. I am sure I remember seeing something computery about Calvin and Hobbes. It turns out, it possibly because one of the earliest ever websites (back in 1995) was the digital calvin and hobbes site. One of Calvin's quotes is also considered a famous computer quote

"I'm not dumb. I just have a command of throughly useless information."


Java vs Flash. Well Java look to be taking be on Adobe in terms of dynamic content over the web. Recently, they have been promoting JavaFX. This not to be confused with the go-between solution of JFlash.

Hacker Meetup? I'll be keeping a close eye on these boys from songkick. They are hoping to have meetups every month. Interesting to also the UK govenment have set up a security response team, similar to our friends in the states.

Staying in is the new going out. There looks to be a positive side to the credit crunch for certain companies. Sky are creating a 1000 jobs and my sources tell me that Coca-Cola are creating jobs in London. So business is good. Why? Well more people are staying in as it is perceived to be more expensive to go out. Hence people are buying more drinks and watching tv/entertainment. That said Sky recently increased their broadband 5 pounds across the range (including the 'free' broadband + tv package).
Talking of going out, the Notting Hill Carnival is under threat of being cancelled for 2009. Interesting this forum suggests it should be banned. :( Come on people, it's part of the sub-culture in London! I suspect there are political undertones as the council / government are trying to cutback on expenditure. Hence why they are making these difficult demands to ensure that they do not have to fund the event. That's what it all boils down to.

I'll sign off with this eerie video that Amy Winehouse recorded with Pete Doherty

Thursday, 13 September 2007

Sans Event in London

This just in, there's a training event offered up by sans in good old London town!

Wednesday, 22 August 2007

IT Conferences / Exhibitions

IT Conference

Today's keyword is: IT Conference

Whilst looking for random conferences, I spotted this article about a group of hackers wondered into a conference and spoofed a wireless login page that whoever connected downloaded some nice worms and viruses. That's funny. It's always turns out to be an inside job, doesn't it.

Anyhow let's have a look at what good development and security conferences that maybe of
interest:
You always join a developer community or too:
You can always attempt to shape great minds and gatecrash the party at Webdevconf [Bristol - Sep 26, 2007]

Thursday, 26 April 2007

Infosec

Well I went to Infosec on Wednesday (Apr 25), which is a more business-oriented internet security exhibition. It's good to know that there are exhibitions out there that are actually interesting and actually have some free goodies.

Anyhow, I got a lot of out this, particularly on SSL VPN systems. It looks like there are quite a plethora of solutions for this and endpoint security is something that simply isn't done that well from what I've seen from the big boys (Cisco and Checkpoint). I was impressed by Sonicwall, Wintegra and Zyxel. All of whom, have some form of patch management, firewall/anti-virus and key logging checking. The cost of which may be lower than the big boys.