Sunday, September 28, 2014

Bashing the Big Bad Bash "shellshock"


Updated: 29/9/2014:  Updated video from SANS

How bad is it? Very.


What happened? Check out the SANS's video below:


As of today (28 Sep 2014), current patch is not adequate as it only fixed the first problem (CVE-2014-6271) but not the 2nd one (CVE-2014-7169). Vendors are still struggling to fix  , the second problems (CVE-2014-7169 and 4 other new bugs discovered.

Also, the folks at Fireye have written a very good piece about this with sample of attack vectors and exploits included.  Check out their blog post titled "Shellshock in the wild" 


Now, I'm sure by now you have been asked the one million dollar question by your boss or some senior managers:
Are we vulnerable? Can you quickly find out?
Quick is the keyword. You should first check your exposure from the internet.

But how? Ask google. Look for indication of usage of bash script on your website. For example:

filetype:sh OR filetype:bash site:bashing.badbash.com

If you see URLs with sh or bash extension, be paranoid. Check those first and disable them. Replace the script with something else e.g. Perl or Python.

Next, you may want to add a custom signature to your NIPS to detect/stop any potential exploits. Here is a quick snort signature signature (taken from Volecity's website)

alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:”Volex – Possible CVE-2014-6271 bash Vulnerability Requested (header) “; flow:established,to_server; content:”() {“; http_header;  threshold:type limit, track by_src, count 1, seconds 120; sid:2014092401;)

Or grab the official snort rules from snort's website here

Information security folks: If you play this game well, it could be another good business case for you to push for those legacy systems to be updated/upgraded!

Friday, August 8, 2014

Babusb in enterprise. Why you should not panic over it.



Hot topics of this past 2-3 weeks - Badusb. Until yesterday, most talks or write-ups are just speculations as there are no details released.

Folks at srlabs.de had released more details during their Black Hat 2014 presentation yesterday. You may grab the slides on their website here

As the CISO or Information Security Professional responsible for ensuring security within your organisation, you have every right to be worried. The good news is,  you can stop the panic mode now, if....

You don't allow admin right to your users. 
 
To successful attack a target machine, the attacker must have/gain access to a machine that has been logged in by a user that has admin privilege.

I find that WIBU Systems's alert explain it very well. Here are the excerpt:

"A BadUSB attack can be successfully accomplished only with logged-in users who have administrator privileges to their computer. In principle, the attack would also work for OS X and Linux; only the actual commands from the “keyboard” would be different."


Nowadays, most enterprise laptops/pcs are hardened and you rarely see users with admin right anymore. Of course, there are exceptions (really? If you are the CISO, shame on you!).

Of course, there are still risks. But I will say, the risk is low - if you have done the right things. 



Friday, June 27, 2014

Booting up evidence E01 image using free tools (FTK Imager & Virtualbox)



Being able to boot an acquired evidence image (hard drive) is always helpful for forensic and investigation. If you would do a Google search, you would find most methods or discussions are referring to usage of Vmware Workstation. As Vmware Workstation is not free, not a good news if you are on low budget or do not have one at all.

Don't worry....I will show you how you could boot an acquired E01 image using freely available tools.

What you will need:
1. FTP Imager 
2. Virtualbox and Virtualbox expansion pack-
3. Admin right (do not have one? You're joking right???)

I'm not going to detail down how you should install FTK and Virtualbox.... those are really easy.

Here are the steps:
1. Open FTK Imager. Go to File -> Image Mounting.

2. Select the E01 image you want to mount.
a) Mount Type: Physical Only
b) Mount Method: Block Device / Writeable (I know what you are thinking.... do not worry about tampering the evidence file. FTK Imager will create a cache file that will temporarily store all the "changes" you made)
c) Write Cache Folder: Take the default or point it to any folder that would make you happy :)

3. Click "Mount". You will see which physical drive the image is mapped to.


4. Create a new folder (for storing the virtual disk file later) e.g. c:\temp\securityisfun.net
5. Open a command prompt as administrator. Go to c:\Program Files\Oracle\VirtualBox. Run following command: vboxmanage internalcommands createrawvmdk -filename c:\temp\securityisfun.net\securityisfun.vmdk -rawdisk \\.\physicaldrive5

NOTE: Replace the path, file name to be created and physical drive as accordingly.



5. Run Virtualbox as administrator. Create a new virtual machine matching the OS of the image e.g. Windows XP or Windows 7.
a) RAM - set it to any amount you like. For me, normally I will set it to 2GB
b) Hard Drive - point it to the virtual disk file you just created in step 5 above


6. Well, start the virtual machine. It should run now. 

7. In case you get a blue screen.. which is not uncommon. Try changing the HDD controller type, which is IDE by default, to SATA, SCSI or SAS. You can change this by editing the settings of the virtual machine:
a) Delete the existing HDD controller
b) Add a new controller e.g. SATA
c) Add a new disk. Select "Choose an exiting disk". Point it to the virtual disk file you created (e.g. securityisfun.vmdk)





8. If you still get the blue screen... this might be due to Windows could not see the drive. Try following steps which involve editing the registry to enable SCSI and SAS drivers on boot:  
a) Unmount the image you mounted with FTK Imager
b) Mount the same image with FTK Imager but now with the option: 
Mount Type: Physical & Logical
Drive Letter: Take the default
Mount Method: Block Device / Writable
c) You should see the partitions of the image are now mounted and accessible

 

d) Run "regedit.exe" as administrator.
d) Expand "HKEY_Local_Machine". 
e) Select "Load Hive". Point it to the SYSTEM hive of the Windows partition of your mounted image. For example, if the image's Windows partition is mounted by FTK as K:, point it to K:\Windows\system32\config\SYSTEM


d) Enter any name when prompted e.g. securityisfun.net (sorry, a bit of marketing here :) ). You should now see additional registry key with the name you typed appeared.


e)  Navigate to securityisfun.net\ControlSet001\Services


 f) Look for "LSI_SCSI". Click on it and set the key "Start" value to "0" (zero). Setting it to "0" means Windows will start/load this driver at boot time. Repeat the same for "LSI_SAS, LSI_SAS2". 


g) Point to the "securityisfun.net" hive once you finish editing. Select "File, Unload Hive". Click "Yes". Close regedit.
h) Now try to boot your virtual machine again. Try using difference controllers e.g. SAS, SATA, SCSI if you still getting the blue screen.

9) If you are still getting the blue screen despite doing all this........ two words for you - bad luck! At this moment, I don't have any other solutions or workarounds. I will update this blog post if I (ever) come across something new :) 

Have fun!

Tuesday, June 3, 2014

HiTB Haxpo AMS 2014 - My takeaway



Yup. That's my crew T-shirt of Hack in the Box Amsterdam 2014 or now known as Haxpo. It was nice and fun meeting all the .MY and .NL folks again.

I have to admit, I feel like the presented conference topics are not as exciting as last year's.  However, the Haxpo (the part where you can enter for free) was quite a success.

Nevertheless, there are couple of interesting topics that caught my attention:

1.  Cool idea - splitting java exploits into multiple "innocent" looks Java applets in order to avoid detection. Check out Reloading Java Exploits: Long Live Old JRE! by renown security researcher (read Hacker) LUIGI AURIEMMA .

2. Wanna fly for free? Check-out Exploiting Passbook to Fly for Free by ANTHONY HARITON. This was the most funny presentation that I had seen this year. Full of fun and laughs. NOTE: He did not confirm nor deny whether he did indeed perform the "test: personally :)

See y'all again next year folks!

Friday, April 11, 2014

Heartbleed - A picture that tell a thousand words


20140414 Update #2
The server's private key can be obtained. This is confirmed. See here.

Update #1:
Apparently NSA KNEW about this since years ago. Surprised? Not really...


Well explained. Picture taken from xkcd - http://xkcd.com/1354/

How bad is heartbleed? Very bad. It affects not only https. But all other applications, servers , routers, firewalls that use OpenSSL.

We have heard all the bad news. But, there is a little good news. Retrieving private keys may not be that easy. This post explains it all. However, getting passwords are still easy if you are lucky (well, try a few times). There are a few websites that you can use to check if a website is vulnerable, but done give you the dumps. Here is the python script that give you the dump.
Tips: run it in debug mode.




Thursday, February 20, 2014

Encase vs Autopsy vs XWays


Over the past few months, I have had the chance to work more extensively with the following IT Forensic tools (at the same time):

1. Encase Examiner
2. XWF or X-Ways
3. Autopsy

Most IT forensic professionals would say that there is no single tool that fit for everything. I can't agree more.

Here are my personal views of each tool's pros and cons:

1. Encase:

Pros:
- Easy to use user interface.
- Renown tool and accepted by court of laws.
- Easy reporting features.
- Easy and free tool for acquisition (Encase Imager).
- Built-in support for Bitlocker.
- Nice and user friendly "Review Package" that can be sent to Requestor for reviewing the evidence.

Cons:
- Not cheap.
- Evidence processing can be slow, especially when processing large PST files.
- Not portable by default.

2. XWF (X-Ways)
Pros:
- Very customizable evidence processing options. Thus, you can select to process only certain things that you want to look at e.g. emails, registry.
- Very flexible and granular filtering options. Filter by column 1 + filter in colum 2 etc...
- Highly customizable search functions. For example, search for "xyz" only in Word documents.
- Multiple instances e.g. one doing "processing", the other doing live preview.
- Portable by default.
- Very frequent updates for new features. 

Cons:
- Complex interface. Technical in nature - not easy to learn for a beginner.
- Too many options to choose, thus could be confusing. (However, the default options are good enough for most of the cases).
- Dongle must be attached all the times to start the software.
- No option to create nice "Review Package" that you can forward to someone.
- No support for Bitlocker (the company I work for use this a lot).
- No nice "review package".

3. Autopsy:
Pros:
- Free for commercial use.
- Very fast and easy tool for analysis of user's browsing history or internet activities.

Cons:
- Limited function (but it is free!).
- No support for Bitlocker.
- No nice "review package".

Thus, it really depends on what you want to do. For example, if I would like to quickly find out how a malware infected a machine, I would use Autopsy first. If I would like to process evidence for fraud cases, I would go for Encase first. X-Ways will be the tool if I need to do complex filtering and fast extraction of some evidence.

Have fun!



Saturday, January 18, 2014

What's coming in 2014?


What's coming to information security world in 2014?

These are my views:
1. Malware will be for profit. No longer about fun.It will be harder to track who is behind it.
2. Cryptolockers or alike will go mainstream.
4. Demand for digital/IT forensic will go up.
5. More providers will enhance their services offering with encryption to respond to NSA's spying activities.
6. Companies and government organisations will collaborate more to fight cybercrimes. More join announcements will be made on successful take-downs of botnet or cybercrime networks.
7. Windows XP end of live will have a high impact and will directly contribute to higher botnet activities. The bad guys are holding their cards now, waiting for the right time to swallow their preys once XP is left orphaned.
8. More malware will target Android devices. I won't be surprised if Cryptolocker invades Android soon (if it does not already did that).
9. Data breaches will continue to rise. We will see more data breaches of big retail or non IT services companies.
10. Big Data will be one of the hot topics discussed.  

What's yours?

Acknowledgement: 
Picture's source - http://www.flickr.com/photos/danmoyle/11178388835/sizes/z/ 

Thursday, December 12, 2013

Live Forensic on Linux



Last month, I wrote a bit about doing live forensic on a Windows machine. Today, let's do Linux.

Let's do a bit of recall before we proceed. Since I'm lazy to repeat, here are excerpts of what I have written previously in Live Forensic on Windows:

Before we touch that, why do we need to do live forensic at the first place? For a few reasons:
a) It is a production server and the Business Owner or System Admin would not let you shut down the system/server for offline forensic
b) The server/system is at a location that you could not go there physically
c) We afraid that we may lost crucial information e.g. malware that runs in memory only if we were to shut down the system immediately

Next, what info or data should we gather? What tools to use? In IT Forensic, we normally talk about using trusted binaries. Why is it important? Because on a hacked or malware infected machines, it is not uncommon for the attacker/malware to install rootkits or replace some common commands/binaries of the system/server in order to hide or cover their tracks. Running these binaries might not give you the real output or info as they should be. Therefore, the first steps is to prepare a forensic kit (e.g. write protected USB stick, CD) with your trusted binaries/tools.


Now, what tools you can use? Unlike Windows, Linux binaries are quite sensitive to the kernel's version. Also, have you heard about dynamic library dependency hell? Basically one library depends on other library which depends on another libraries and so on... Thus, most of the time you can't just copy out the binary/program and expect it to work on another system. You can always compile your own binary statically, but that require lots of works as well. Luckily, I found a saviour - Busybox! Yes, it is the same tool you use to run commands on your rooted Android devices :)

So, go grab yourself the Linux version of Busybox now!

For memory dump acquisition:
1. Use LiME. However, it might not work if the system prevent loading of kernel module. it is also very kernel specific, thus you can't compile it on a system and expect it to work on any systems. It will only work on a system with a same kernel version. 
2.  dd if=/dev/mem of=host1/dd-dev-mem.img . However, this may not work with newer kernel or if the kernel is compiled with STRICT_DEVMEM=y option (check /boot/config-<KERNELVERSION>). 

Have fun!

No.
What to Acquire
Tools/Commands to Use (Output is saved to a file)
1.     
Hostname
·         ./busybox-i686 hostname > targethost/b-hostname.txt
·         hostname > targethost/hostname.txt
2.     
OS version
·         ./busybox-i686 uname –a > targethost/b-uname-a.txt
·         uname –a > targethost/uname-a.txt
·         cat /etc/os-release > targethost/os-release.txt
3.     
Current system date and time
·         ./busybox-i686 date > targethost/b-date.txt
·         date > targethost/date.txt
4.     
Current IP address
·         ./busybox-i686 ifconfig > targethost/b-ifconfig.txt
·         ifconfig –a > targethost/ifconfig-a.txt
5.     
Current running process list
·         ./busybox-i686 ps –eaf > targethost/b-ps-eaf.txt
·         ps –eaf > targethost/ps-eaf.txt
·         ./busybox-i686 lsof  –a > targethost/b-lsof.txt
·         lsof > targethost/lsof.txt  
6.     
 current network connection lis
·         ./busybox-i686 netstat –anp > targethost/b-netstat-anp.txt
·         netstat –anp > targethost/netstat-anp.txt
·         ./busybox-i686 netstat –anr > targethost/b-netstat-anr.txt
·         netstat –anr > targethost/netstat-anr.txt
7.     
 current list of current logon sessions
·         ./busybox-i686 who –a > targethost/b-who-a.txt
·         who –a > targethost/who-a.txt
·         w > targethost/w.txt
8.     
 list of auto start applications and services
·         chkconfig --list > targethost/chkconfig--list.txt
·         ./busybox-i686 ls –alR /etc/rc* > targethost/ls-al-etc-rc.txt
·         ./busybox-i686 ls –alR /etc/init.d > targethost/ls-al-rc-d.txt
·         more /etc/init.d/* > targethost/more-init-d.txt
·         cat /etc/inittab > targethost/inittab.txt
·         service –-status-all > targethost/service—status-all.txt
·         ./busybox-i686 ls -alR /etc/systemd* > targethost/ls-al-etc-systemd.txt
·         ./busybox-i686 cat /etc/inetd.conf > targethost/inetd.conf
·         cat /etc/inetd.conf > targethost/inetd.conf
9.     
 environment variables
·         ./busybox-i686 env > targethost/b-env.txt
·         env > targethost/env.txt
10.  
 list of cron jobs (scheduler)
·         ./busybox-i686 cat /etc/crontab > targethost/b-crontab.txt
·         cat /etc/crontab > targethost/crontab.txt
11.  
 system event (dmesg) log records
·         ./busybox-i686 dmesg > targethost/b-dmesg.txt
·         dmesg > targethost/dmesg.txt
12.  
 last user activity records
·         ./busybox-i686 last > targethost/b-last.txt
·         last > targethost/last.txt
·         lastb > targethost/lastb.txt
·         lastlog > targethost/lastlog.txt
13.  
 list of installed software
·         rpm –qa targethost/rpm-qa.txt
·         dpkg --get-selections > targethost/dpkg—get-selections.txt
14.  
 list of user accounts
·         ./busybox-i686 cat /etc/passwd > targethost/b-passwd.txt
·         cat /etc/passwd > targethost/passwd.txt
·         ./busybox-i686 cat /etc/group > targethost/b-group.txt
·         cat /etc/group > targethost/group.txt
15.  
 partition table and drive info
·         ./busybox-i686 df –h > targethost/b-df-h.txt
·         df –h > targethost/df-h.txt
·         ./busybox-i686 fdisk -l > targethost/b-fdisk-l.txt
·         fdisk -l > targethost/fdisk-l.txt
·         parted –l targethost/parted-l.txt
·         ./busybox-i686 cat /etc/fstab > targethost/b-fstab.txt
·         cat /etc/fstab > targethost/fstab.txt
·         ./busybox-i686 mount > targethost/b-mount.txt
·         mount > targethost/mount.txt
16.  
 list of loaded modules
·         ./busybox-i686 lsmod > targethost/b-lsmod.txt
·         lsmod > targethost/lsmod.txt
·         ./busybox-i686 cat /proc/modules > targethost/b-proc-modues.txt
·         cat /proc/modules > targethost/proc-modues.txt
17.  
 information about memory usage
·         ./busybox-i686 cat /proc/meminfo > targethost/b-proc-meminfo.txt
·         cat /proc/meminfo > targethost/proc-meminfo.txt

18.  
 iptables rules (firewall)
·         iptables --list > targethost/iptables--list.txt
19.  
 system logs normally stored in /var/log
·         ./busybox-i686 tar –czvf targethost/b-var-log.tgz /var/log
20.  
 memory dump with LiME
As the LiME software needs to be specially built for the target system Linux’s kernel, there are more steps to be done before the tool can be used:
a.     Extract the LiME source file you downloaded.
b.     Change directory into the “src” directory. Type: cd src
c.     Compile the module. Type: make
·         If successful, a new file starting with “lime’ and ending with “.ko” will be created. Example: lime-3.2.6.ko
·         insmod lime*.ko “path=targethost/lime.mem format=lime”
The module is then loaded to the kernel and the memory dump will happen automatically. If you need to run it again, you must first remove the module from the kernel. Type: rmmod lime


21.  
 /dev/mem and /dev/kmem via dd
·         dd if=/dev/mem of=targethost/dd-dev-mem.img
·         dd if=/dev/kmem of=targethost/dd-dev-kmem.img