Tuesday, January 20, 2015

Educating non-InfoSec People

EA was hacked and isn't admitting, in my opinion. Let me explain. EA has an application used to buy games and in game things called Origin. I have an Origin account I almost never use, I used it to buy some single player games in the past. I got a your password was reset email and thought, that isn't good. So I tried and failed to login. I had a new password reset email sent to me and logged on to see many, many game purchase I didn't do, and lucky got me, they had all failed. I tried to turn on a security feature to alert me when the account logged in from another IP but couldn't because the answer to my secret password was changed. So I opened up a ticket. It turns out it was changed to a long string of text and not all english characters, joy. So I'm good now. But keep in mind a few things. One, I'm reasonably sure my home PC is not infected or owned in any way. Two, I use an email address for this I don't use for normal emails and is a domain I own not gmail, etc. Three, the password was strong and not reused other places. Four, to get the answer to the secret question from my PC they would have had to owned my PC since I opened the account back in 2013. All of this points to EA was the leak of my data not me, and they stored all of this in clear text or hashed or encrypted with poor key security but in any way stored it in a way that didn't keep the data private when stollen, clear text is my guess. The person on the phone that helped me was nice and said they are dealing with a lot of these and they are forwarding them all to their fraud department who is trying to figure out what is going on.

So I looked it up and found things like this: http://venturebeat.com/2014/12/30/hackers-are-breaking-into-origin-and-making-fraudulent-purchases/ So based on my experience and that is lines up with many others it seems to me that: EA was hacked, they store this info in the clear, they don't have the logging capabilities to determine they were hacked for sure but they suspect it, EA leadership has made the stance that without 100% positive confirmation of a breach they will just deal with it and tell people they have found no evidence of a breach. This is where it gets interesting.

I'm a member of a large online gaming community. So I warned them to change their EA Origin password AND their secret question/answer combo. The overwhelming response I got was disbelief a "large company" such as EA would have been hacked without telling everyone about it and that they wouldn't have been properly encrypting this information and instead the people kept trying to tell me how to scan my PC for malware. I finally gave up trying to explain this to them and they get what they get I warned them. But I found it rather shocking that a group of tech savvy but non-InfoSec people put so much faith in companies doing InfoSec correctly. If you are reading this you are probably in InfoSec and are probably saying the same thing I am. Almost no company does this correctly. It is totally believable EA doesn't encrypt this data. It is even more believable than they decide not to report a breach unless they have to and they have a hard time finding evidence of it. These aren't just believable they are likely based on all I've seen over the years. Yet the average person thinks so highly in the tech capabilities of these large companies it comes off as conspiracy theory craziness and you can't even explain it.

This struck me as very bad. If more people knew how poorly their data was secured people would be mad about it and things would change for the better. But I'm not sure what to do about it. I'm interested in what you all think on the topic, if anyone made it this far. How do you convince people how poorly most companies do InfoSec without them dismissing you as crazy?

Monday, January 5, 2015

Told you so...Almost

From my last post you can see I had serious doubts about the FBI claim that North Korea is involved int he Sony hack and I'm deeply concerned that the FBI is being used as a propaganda arm of the Executive branch of government. Here is an update:

Norse Corp took on the investigation and figured it out in more detail and shared their findings with the FBI. The FBI rejected it and still has not shared why they rejected it or what if any evidence they have against North Korea:
http://nypost.com/2014/12/30/new-evidence-sony-hack-was-inside-job-cyber-experts/

The US Govt sanctioned North Korea while admitting no real evidence exists and no one seems to care but NK:
http://boingboing.net/2015/01/02/obama-administration-north-ko.html

The stalled Cyber Security bill now has support of Republicans in the senate and will likely pass given the NK Sony hack link:
http://www.washingtonpost.com/blogs/post-politics/wp/2014/12/18/eyes-turn-to-the-next-congress-as-sony-hack-exposes-cybersecurity-flaws/

That bill is deeply flawed and shouldn't pass:
https://www.eff.org/issues/cyber-security-legislation

As far as I can tell the Sony hack happened, an insider working with some Russians to extort money as far as I can tell. The White House used the FBI to blame NK to get an unpopular cyber security bill passed. When the story lost it's legs over the holidays they sanctioned NK to keep it alive to try to keep momentum on the bill they want. Once the bill passes I bet they drop the NK story and arrest the insider. Time will tell though.

Friday, December 19, 2014

Sony, the FBI, and NK

The FBI came out saying they thought North Korea hacked Sony: http://www.fbi.gov/news/pressrel/press-releases/update-on-sony-investigation.

The main points are, malware code looked reused from previous code attributed to North Korea, the malware uses NK IP addresses, and the "tools" used were similar to a South Korea bank attack believed to be from NK, whatever that means. Here is the problem from the U.S. intelligence departments mouth:
Another indicator pointing to U.S. intelligence is the familiarity with Sony’s computer network. “It’s clear from the hard-coded paths and passwords in the malware that whoever wrote it had extensive knowledge of Sony’s internal architecture and access to key passwords,” Rogers notes. “While it’s plausible that an attacker could have built up this knowledge over time and then used it to make the malware, Occam’s razor suggests the simpler explanation of an insider.”


That is still all true, which makes the FBI release read like nonsense to me. Consider the possibility of a pure North Korea attack with no insider. That would mean the attacker would need to gain access to Sony's network, likely with an email phish attack or maybe an undetected web attack. Gain access to many files and find passwords in password files and system documentation and diagrams and piece together the information needed to make this malware. And while possible, that makes no sense at all to me. Once you have that level of access and understanding, making malware is the last thing you would do. At that point simply use normal system tools to extract all the data you want without being detected or leaving malware behind. Anyone knowledgeable to create this malware would know better than to use malware if they already had all the access they needed without it. This scenario makes no sense to me and as the quote above states, doesn't pass the Occam's razor test. Let's assume they had access, but couldn't use the tools they needed to get the data and needed to write their own code and...It just doesn't pass the test unless they know something they aren't telling us which is possible but still more assumptions and therefore still doesn't pass the test.

What does pass the test is an insider with this knowledge either is behind the attack, or willfully gave up this information to an attacker and is part of the attack. The attacker could still be North Korea, but only with an insider's help. But more likely that that, an insider working with another outside group with the skills needed and is intent on financial gain from extorting money from Sony and had the idea of trying to blame North Korea or just Korea in general for the attack to cover their tracks. If they knew how the company and media and governments would jump on it for their own self interests, they are brilliant. But I'm guessing they didn't know it would work out so well but rolled with it when the NK part of the story took on a life of its own. And why not? Now that the FBI said what they said, for whatever reason, it is hard for me to picture them finding and bringing to justice the criminals involved if it turns out NK wasn't behind it. And that is the dangerous part of this game which I predict will be played out again and again. How easy is it to get away with a crime like this and blame a nation state if we are so willing to let the nation state be blamed?


Monday, November 24, 2014

New Scripts and Old Script Changes

I pushed up some scripts I banged out today here: https://github.com/secjohn/nessus-reporting
I'm a blue team guy again and I needed a better way to share Nessus findings both vulnerability scans and compliance audit scans with my admins. The Nessus HTML and CVS exports just don't cut it, and I'm sick of manually editing the CVS exports to be something people want. So I made these scripts to turn .nessus files into spreadsheets my admins want and figured I would share them. They are freshly made and I'm sure some improvements are needed. But so far appear to work fine even on very large .nessus files.

I also commented out the crypter parts of obfy. It hasn't worked for a while now, even since some change to msfpayload. Obfy is still a quick way around McAfee, but that is about it at this point. I think it still works against some others if you manually run ditto on the payloads, but I never got ditto to work correctly with wine so I couldn't script it out. Veil is a better automated option for most things and I use it a lot now. Obfy is still good if you know you are going against McAfee or to edit an asm file you made yourself for a longer term custom payload like a signed payload for phishing, etc. But in general I wouldn't use obfy on a normal pentest if I didn't know the AV product anymore. I would highly recommend using it in AV testing if you are buying one.

Wednesday, October 29, 2014

Update to Kali-Scripts

It has been a while but I updated the Kali update script I have on github and added an kaliautoupgrade.sh script. They can ben found here: https://github.com/secjohn/kali-scripts

The kaliupdate.sh script has minor changes. The biggest one is I changed to dist-upgrade from just upgrade. When I wrote the script there was no difference and a dist-upgrade burned me once on BT5 back in the day so I didn't use it. The dist-upgrade seems to be needed and fine now though.

I'm on the blue team again and I now don't run everything from my laptop and having Kali on a server made me want a script for a cron job. So I edited down the script and tweaked the dist-upgrade line so conf files wouldn't stop it and made kaliautoupgrade.sh. If you have a Kali server and want to upgrade in cron, there you go. One warning, the script assumes things are there for the most part. The one time installs and checks are in the kaliupdate.sh script, you should run it once with a -a before setting up this job.

Kali Dist-Upgrade Issues Fun:
One note on the dist-upgrade, I did run into an issue with it. But is was resolvable. I got an error saying it couldn't finish and to run apt-get -f install to fix it. So I did and that failed. It said it needed to overwrite a file that was owned by another package. At the end it gives the deb file that has an error. If you run into that what you need to do is:
dpkg -i --force-overwrite /the/path/defilegivingtheerror.deb
apt-get -f install

That will let the file be overwritten. After the apt-get -f install finished you need to run the apt-get dist-upgrade again. I had it fail again and had to do the same steps above a second time. Life has been good since then.

Friday, October 24, 2014

SecureCIO Chicago and John McAfee

So I got invited to this thing. http://chicago.securecio.com/cm I wasn't sure how or why and I almost deleted it until I noticed John McAfee was speaking. Then I clicked the hell yes button. I figured either the people running this thing must be pretty cool or totally clueless and were going to freak out and either way this was going to be fun. So I went. It was a bit odd and slow for me at first. The host started with a urban legend a few seconds on snoops on my phone confirmed my hunch. Not long after that he said to use the news about big attacks to scare the crap out of our leaders to get more budget. I don't think he was kidding, maybe half kidding. Another speaker worked for a secure email company and talked about how his product helped secure email, joy. I was starting to wonder what I got myself into. Then at the break I found an old friend of mine and that was good. Then I saw Wendy's blue hair and I recognized her from B-Sides Vegas and I knew McAfee must be close and he was, playing the piano. I went and hung out with him as much as I could. The cool kids all came out to talk to him and as long as I was close to him I found it easier to talk to other people, these were my people. After his talk @minossec came over to say hi to him and it was cool to he him again too. It turns out the director of this thing is a cool guy and has worked with John McAfee before and like me was tying to hang out with him as much as possible and it was nice meeting him too. Finally John McAfee spoke. It was a good talk, different tone than B-Sides he knew the audience was different. Mostly he talked about phone insecurity and how we are all idiots for letting our flashlight app or bible reading app access our microphone and record us without telling us and how he has a new Android app which tells you when that happens and if you try it you will see how stupid you have been and how you are being spied on. I ended up at the bar there but bailed before it got too late and somehow totally forgot to eat dinner. McAfee left shortly after his talk unfortunately but it was great seeing him and hearing him speak.

Like I said, the person running this thing seems cool. Most of the more technical security leaders I know weren't there. We should try to fix that going forward, this thing has potential if we can get the right people to start showing up by mixing a bunch of burbsec/chisec folks in.

Thursday, October 16, 2014

DerbyCon 4 Recap

I'm a bit late but here it is anyway. DerbyCon was good overall this year and still is my new favorite security con. I must say I felt the talks were overall not as strong as the last two years and I didn't walk away with as many good pieces of data and ideas. A feeling I confirmed with several other people. But it was still good and it isn't clear how much of that is based on the talks that were selected, or that the talks in 2014 just aren't as good as a whole, or it is a bullshit feeling and we are building old DerbyCon's up in our mind. But like I said, still my favorite, and I still plan to go next year. On a side note I explored more of Louisville this year than the years past and I'm starting to really love that city.

All the videos can be found here:
http://www.irongeek.com/i.php?page=videos/derbycon4/mainlist

If you didn't get to go or missed some talks here are a few I liked:
Threat Modeling for Realz – Bruce Potter
Application Whitelisting: Be Careful Where The Silver Bullet Is Aimed – David McCartney
InfoSec – from the mouth of babes (or an 8 year old) – Reuben A. Paul (RAPstar) and Mano Paul
How to Secure and Sys Admin Windows like a Boss. – Jim Kennedy
Building a Modern Security Engineering Organization – Zane Lackey
Information Security Team Management: How to keep your edge while embracing the dark side – Stephen C Gay
RavenHID: Remote Badge Gathering -or- Why we sit in client bathrooms for hours – Lucas Morris – Adam Zamora
Building a Web Application Vulnerability Management Program – Jason Pubal

This list is far from complete, I haven't watched all the videos of talks I've missed and want to see yet. But it is taking a while and I wanted to get this out. So consider that list a starting point, there are a whole lot of good talks up there. Everyone should spend a few hours to watch the ones that applies to you the most.

So far I think the best piece of info I got was from Jason Pubal's talk that exposted me to ThreadFix. It was a pain for me to get it working on Debian but that is just because I'm too stubborn to use Windows I guess. I think that might be another blog post soon. But let me say, my developers already love the thing and I just got it working. If you have developers and have to give them scan data check this tool out.

Let me know what videos you think I should watch that I didn't link. I won't watch them all so let me know if you think I'm missing something cool.