Sunday, December 18, 2016

What lies behind the veil…



Preface: This article is solely for Security interests and research, nothing more. No political ideas or motivations shall be discussed herein.

Background/timeline information:
“On Friday October 21, 2016 from approximately 11:10 UTC to 13:20 UTC and then again from 15:50 UTC until 17:00 UTC, Dyn came under attack by two large and complex Distributed Denial of Service (DDoS) attacks against our Managed DNS infrastructure.” [1] [DYN website]

We all know about this DDoS attack and it has been discussed and analyzed by many, so this article will not address this attack, but rather I will discuss one of the events that was quietly going on in the background during this attack.

As a security researcher, the DDoS attack was interesting but I wanted to know if any other events were happening at the same time, so I headed over to BGP Stream [2] to see how/if any of the BGP routes might be affected by this attack. It did not take me very long to notice something very interesting. During the last part of the second attack on Dyn, there were a set of events that caught my attention. It appears that during this time, AS3267 State Institute of Information Technologies and Telecommunications (SIIT&T Informika) [3] controlled by the Russian Federation, was attempting to hijack several other AS routes between 10/21/2016  17:08:25 (UTC) and 10/21/2016  17:08:51 (UTC). In fact, all of the 42 events against 22 different AS’s occurred precisely at these times, with the advertisements starting at 17:08:25 (UTC) and all of them ending at 17:08:51 (UTC), a total of 26 seconds.

26 seconds doesn’t sound like a very long time, but for an AS, a tremendous amount of data can be gather during that brief time. It’s also short enough not to cause any serious outages and, most likely not to be noticed by many. I don’t pretend to know why this occurred, only that it did and during a time when much of the internet in the US was being affected by a larger scale attack. I’m not much of a believer in coincidences, especially when it comes to internet networking so in my mind this seemed to me to be some sort of test. (Pure speculation on my part)

Here is the breakdown, by country, of the AS’s affected by these hijack attempts:

Isle of Man (1)
United Kingdom (1)
Japan (1)
Slovakia (1)
Canada (2)
Ukraine (2)
Germany (2)
Netherlands (4)
United States (7)

As you can see from these stats, these events were not solely targeted at the US even though the US was the most targeted country. I will provide all of the AS’s affected at the end of this article for your own research, but so far as I can see, preliminarily, there isn’t a good solid connection between all of the AS’s that appear to have been targeted. Also interesting is the fact that all 22 AS’s were targeted twice in succession, all during the exact same time period.

Conspiracy theories abound these days and I have no intention of getting involved in those discussions, but I do believe that this information is relative due to the circumstances under which they occurred, but the inferences is yours to make, I’m just reporting on the data collected.

All data collected from BGP Stream:
                                          
Affected AS
Country
Expected Origin AS: Akamai Technologies, Inc. (AS 16625)
USA
Expected Origin AS: Akamai Technologies, Inc. (AS 35994)
USA
Expected Origin AS: Carolina Internet, Ltd. (AS 13618)
USA
Expected Origin AS: Contabo GmbH (AS 51167)
GER
Expected Origin AS: CW Vodafone Group PLC (AS 1273)
UK
Expected Origin AS: FOP Smirnov V'yacheslav Valentunovuch (AS 30860)
URK
Expected Origin AS: Host Europe GmbH (AS 8972)
GER
Expected Origin AS: Insitu, Inc (AS 27214)
USA
Expected Origin AS: Internet Initiative Japan Inc. (AS 2497)
JAP
Expected Origin AS: LeaseWeb Netherlands B.V. (AS 60781)
NED
Expected Origin AS: Lertas NET s.r.o. (AS 201924)
SLO
Expected Origin AS: Loco Digital LTD (AS 58277)
URK
Expected Origin AS: Mohawk Internet Technologies (AS 14537)
CAN
Expected Origin AS: Rackspace Hosting (AS 27357)
USA
Expected Origin AS: Rackspace Hosting (AS 33070)
USA
Expected Origin AS: Server Central Network (AS 23352)
USA
Expected Origin AS: Serverius Holding B.V. (AS 50673)
NED
Expected Origin AS: Velcom (AS 30407)
CAN
Expected Origin AS: Webhost Limited (AS 34738)
IOM
Expected Origin AS: Webzilla B.V. (AS 35415)
NED
Expected Origin AS: WIBO International s.r.o. (AS 59939)
NED


UPDATE: 12-19-16

@DynResearch responded with the following:

Explaining that will the advertisements were leaked, they were restricted to inside the AS3267 customer cone, meaning no one that wasn't already talking to AS3267 received the advertisements. (see links below for Tweets)

https://twitter.com/DynResearch/status/810949500323905537

https://twitter.com/DynResearch/status/810949822471671809


NOTE: Original data available on request. 




[1] http://hub.dyn.com/dyn-blog/dyn-analysis-summary-of-friday-october-21-attack
[2] https://bgpstream.com/
[3] http://bgp.he.net/AS3267

Sunday, October 2, 2016

Pumpkin-Spiced Cyber


So, ‘tis the season for all things Pumpkin-Spiced; from coffee, to pet shampoo, to Cheerio’s, to well, you get the picture. It has become one of the many jokes of the internet and it getting more prevalent every year. In thinking about this phenomenon, I immediately thought about how this could apply to cyber security and it didn’t really take very long to make the correlation.

The Pumpkin-Spiced phenomenon was born out of the seasonal events of Halloween and Thanksgiving in an attempt to “spice things up” a bit in order to boost sales of various products. And while there really aren’t too many seasonal event’s in cyber security (not including the increased malspam campaigns around Christmas and Tax season), the general principle of let’s “spices things up” still applies. After all, take the Pumpkin-Spiced away and the coffee is still just coffee, likewise, if you take away all of the blinky lights, buzzwords and the snazzy dashboards, security products are still just security products. So if the coffee was bad before it was “spiced up”, then you just have flavored bad coffee and the same goes for security products. In other words, if your product is not good at the core, then no matter what you add to it to make it more appealing, you still just have a bad product.

I believe that in the security industry, we understand this better than others as we have to deal with security products every day, usually the choice of these products being well beyond our control, so we end up with Pumpkin-Spiced tools that might look great in presentation, but normally fall well short in actual functionality. Thus when we see the next new Pumpkin-Spiced whatever, palms immediately go to faces.

This is the real world of marketing that we all face every day, in every aspects of our lives. It might be fine for coffee and various other personal products, because we have a choice in those matters, but in the marketing of security products, this could mean the difference between better security with a solid product or less security with a mediocre product that looks impressive to management.


So as much as this is a mild hit-piece on the marketing of Pumpkin-Spiced everything to the masses, it’s more of a call for rational marketing when it comes to security products. I know marketing will never go away, but I implore security vendors to concentrate on making strong products first and let the marketing come second. You’ll be surprised at the difference this will make, as the marketing of a really great product will come much easier, without the need for the meaningless splash of Pumpkin-Spice.

Monday, August 17, 2015

Major Identity Theft Protection Firm Compromised…


In a late day announcement, it was revealed that a major anti-identity theft company has been hit by a massive data breach that resulted in the loss of the personal information of tens of millions of customers. Citizens that have already been hit by one or more of the many data breaches that have occurred of the past couple of years are in shock, wondering what they will do now…

Yeah, this didn’t actually happen, not today at least, but one day and probably one day soon, I feel positive it will and when it does, it just might be the wake-up call to users that nothing is really truly safe. Of course if it doesn’t happen, then that means those anti-identity theft companies are doing it right!

But seriously, is this what it’s actually going to take to get customers and employees to start actively demanding that companies take more responsibility for the information they either willingly give them, or are forced to give them for the ‘privilege’ of doing business with their firms or to get a job? I personally believe that in the realm of information security, people will have to be backed into a corner, with nowhere left to turn before they get fed up with these companies and government organizations to take information security as seriously as it needs to be taken in this day and age.

Credit monitoring is a band-aid for the victims of a data breach and ‘cyber’ insurance is a crutch for the companies and organizations that are willing to pay the premiums rather than properly allocate sufficient resources to properly secure user’s data. Don’t believe me? Let a user’s cable, internet or cell phone access go down for even a few minutes and you will see hell raised with a fury! Just ask any service providers customer service reps, they’ll tell you. So until companies either willingly start doing what is necessary to properly protect customers, or until users take it upon themselves to demand such protections, the title of this article is destined to come true.


Discuss…

Saturday, May 30, 2015

Attiri-propaganda



No need to read a bunch into this, I’m simply writing this to confirm that attribution is the new propaganda. Shouldn't really even be surprised at this statement, but it needs to be said.

We all laugh and make jokes about attribution and how much bullshit revolves around this particular subject, but the plain and simple truth of the matter is that when the media talks about the attribution associated with most data breaches and stolen PII, the general public only sees one thing, whatever BS is spouted out. It doesn't matter if it’s CNN, MSNBC or Fox, the fact of the matter is that now attribution is being used as propaganda to sway the general population to whatever means is politically expedient at the moment.

It could be China, North Korea, the Russians, Anonymous, or any number of other “actors” that happen to be convenient at the time, and while a lot of this may be true, the means and uses of these disclosures are still suspect in my opinion, after all, we still don’t even know who pulled off the Sony hack right? I’m not trying to get too deep into the weeds with this, I’m just saying that we need to look outside our echo chamber and into the real world of normal people and what they think and believe about what they see when they see the things that the news reports. People believe what they want to believe and they are being pointed to conclusions that may or may not be true.

So, to my initial point, attribution is being used as propaganda. No surprise there right? I know the people that are reading this know the deal, so I’ll just stop for now…


Saturday, May 16, 2015

STD’s


Security, Tactics and Defenses

Note: This post is NOT about sex or porn, not really, but kinda, but no…

So, was listening to Paul’s Security Weekly podcast (@securityweekly) and they were talking about vulns and rankings and how they affect companies, and how CVE rankings aren't always relative to a company’s security policies because there’s no one size fits all method for a particular organizations.  So I had this idea about how security vulns relate to different organizations and how different diseases relates to the human body. I almost didn’t write this because Paul said he hated the medical references, but then he brought up a plot line from CSI: Cyber and I felt better about it…

So, much like was discussed on their show, not every company is vulnerable to every exploit out there, no matter how severe. Much like, if you’re a non-smoker you’re mostly not going to get lung cancer, although this is not always the case, but the odds are easily relatable. However, on the flip side, if there is a new virus out there, both companies and people can be affected by it (no, I didn't mean that the same virus can affect computers and people, so just stop that). Here are a few examples, you can run with it as you wish.

Case 1: Let’s say we have two people, Person A’s family has a history of heart disease and person B’s family doesn't have any history in their family of heart disease. Now, since person A knows this information, they pay very close attention to how they eat, going to regular doctor visits and exercising so they reduce their risks that they know they could potentially cause problems. This is a great security practice for an organization because they have identified that they could have issues if they just do nothing. But person B, not having a history of this issue, doesn't worry about all these preventive measures and just does what they want to do, eating everything bad for most people, blowing off doctor visits and being a couch potato.  

In this example we have two people with varying risks practicing very different strategies. One person has identified the risk and are actively working on mitigating that risk, while the other person doesn't have the same risk, but they’re not taking into account all of the other outlining circumstances that could potentially have devastating impacts. In truth, both are still very vulnerable to heart disease. Even though person A has been actively trying to prevent having a heart attack, they can still have one but even if they do, they’re body is still more prepared for the aftermath because they were prepared. Now if the same thing happens to person B, they will more than likely be surprised and, more to the point, their bodies will not be strong enough to recover from such a traumatic event. So, even though you might not be vulnerable to a particular disease, you still can’t completely ignore the possibilities.

Case number one was very specific, so let’s take a look at case number two.

Case 2: Viruses.
They can potentially affect everyone, no matter what you do, especially if you do nothing! But let’s just say that different people do different things to help prevent getting sick from viruses and yet we all still get sick at some point in our life, because that is a fact of being a human being. It might be something we did or didn't do, something we didn't think about or just by dumb luck. However, how often we get sick and how well we recover is directly related to the things we do to prevent getting sick to begin with, wouldn't you say?

Let’s say that person A always makes sure they take their vitamins and they are trying to be healthy but one day they catch a bad bug. Now, since they thought they were safe because of all of their preventative measure, when they actually do get really sick, they don’t have any remediation medicines in their house to take to help reduce the impact of the infection and in the end, have to go to the doctor to get medicine to help them recover.

Now let’s move to person B, who doesn't really do a lot to prevent catching a bug, but when they do get one, they have a whole plethora of medicines in their household to help them recover from the virus without having to go to the doctor? The answer is simple in this case, both methods combined are the true path to take. You should always try to not get sick, but not to the extreme, just like you shouldn't take any preventative and just be prepared if you do get sick. In this case, you should try to make sure you’re being healthy but always know and be prepared that you will probably get sick and have a plan when/if you do.


So, now let’s all go out there and be smart and healthy, but not naïve! 

Wednesday, March 25, 2015

Baseline – Not the Dubstep You’re Looking For…



Disclaimer: I have no real world ISC/SCADA system or security experience, I’m just a guy that takes in information and thinks about a better ways to do things.

We've all heard about taking a “baseline” of your network environment so you have some way to gauge and detect any anomalous behavior on your systems to, hopefully, help catch any type of malicious activity before it gets out of control, or in the very least, have a good idea of where to start when performing IR if there is a network breach. And, like most of us that already work in well-established networks, we know how difficult and time consuming a task this would be. But in a well-designed ICS production environment, this might be a bit less traumatic experience than one might think.

First of all, if a production ICS network is properly segregated (as it should be) the traffic flowing over the network is really not that complex because the protocols used aren't that complex. Modbus, DNP3 and most of the other ICS protocols out there operate on very small frame sizes and command lists compared to other network protocols, so while there may be a lot of traffic flowing back and forth between a controller and a device, the commands being sent are known and can generally be predicated based on their configuration and what action the system is designed to perform. In other words, you’re not going to see your Smart-Meter or valve controller performing Google searches or streaming YouTube videos unless something has gone terribly wrong! (Yes, that was a terribly joke).

This being the case, an ICS production environment is ripe for baselining even if it’s already up and running (which most are). So this is the first step in beginning to secure an ICS production network and there really isn't any reason why this should not be happening right now in all major and even minor critical infrastructure environments. We all know this isn't the case, but it should be the case none the less. If critical infrastructure company can get over this first, daunting hurdle, keeping this baseline up to date can actually become relatively easy in the future. Let me explain…

Once the major baseline is established and the network engineers know what normal traffic looks like and what might be abnormal, it becomes much easier to tune inline controls to recognize and flag real warning signs that something maybe amiss in their systems. And at this point, maintaining this baseline can become very easy if the proper deployment controls are put into place when the engineers either have to replace a controller or deploy a new system.

I am sure (or hopeful, however you want to look at it) that when a new ICS controller is replaced due to failure or through a system upgrade, or anytime a new piece of equipment is going to be introduced into the system, extensive testing occurs to make sure the new device is function properly before being deployed into the production environment. This is only logical and makes perfect sense, but this is also the time to not only make sure the operation and control of the system is well established, but also the perfect time to baseline the new system’s network traffic as it’s being run through all normal  conditional testing. By imposing this new deployment protocol you can capture all of the communications of the system in its purest form and have a perfect baseline of what to expect its typical traffic to look like; from normal operational commands, to fault conditions, to extreme fail-safe actuation or any anomalous traffic that might indicate that someone is trying or has breached the network.

This can be helpful in any kind of network, but ICS/SCADA networks can greatly leverage this kind of process with more precision than any other network environment I can imagine, to great benefit not only to the company, but to the environment and to the consumers of the products produced by critical infrastructure companies.

</my_two_cents>

Discuss…


Saturday, March 14, 2015

Of Cats and Security



So I was listening to Paul’s Security Weekly (@securityweekly) podcast last Thursday night when one of their guests, one Michael Santarcangelo (@catalyst), used the phrase, “Risk Catnip”. I almost fell on the floor laughing, as he weaved that phrase into his thought without any hesitation. It surprised everyone on the show and we all got a great laugh out of it.

The next day, since I loved that phrase so much, I decided to re-Tweet his phrase along with some other phrases ending with “catnip”. One of those phrases was “Threat Catnip”. A follower of mine by the name of @PeterGanzevles (Hacktic) replied with about the best response I believe I ever heard, he coined the term “Threatnip”, which got me thinking… (I know, I know, keep your jokes to yourself).


 Embedded image permalink


“Threatnip”, as it turns out, is actually a real thing and it’s used all the time as a lure to get executives to buy into Threat Intelligence products like reports, dashboards, blinky boxes and consultations. And much like catnip, once the prey has pounced on the lure and plays around a bit, the thrill is gone along with a considerable amount of money that could have been put to better use. Now I’m not saying that there is no use for Threat Intelligence, in fact, quite the opposite is true, but there has to be more than just the “Threat” part, because, as “Intelligence” implies, it must serve as a function of a continuous cycle of security posture improvement.

The morale of this short story is this: don’t be a “Threatnip” peddler, be a total solutions provider!


Here are some people that are much wiser than I on this subject:

Edward McCabe (@edwardmccabe):

John Berger

Rafal Los (@Wh1t3Rabbit)



Saturday, January 17, 2015

3NCRYP7ION is NOT a Crime!

3ncryp7ion is NOT a Crime!

Editors Note: In the first posting of the article, in my rush to get a blog post up I did not do my research thoroughly and I falsely attributed some statements to the French PM.  I have since edited this post, removing those incorrect statements and providing a link as a reference.  

This project came to light because of the recent terrorist attacks in France; a sad day indeed for the people of France, the families of those slain and for freedom of expression. The response by the people of France and the world was an amazing thing to witness, peoples of every nation banding together in solidarity to stand up against those that would attempt to quell freedom of expression, but then, some equally horrifying happened. Just days after the events and the rallies and marches, some European leaders, namely British PM David Cameron came out and floated some ideas for new laws that would weaken or eventually cripple encryption!  What the Verge called a "European Patriot Act". What irony there was in that statement and the follow up by other countries struggle to fight terrorism, support freedom of expression, but staunch privacy rights!

This did not sit well with me and many others in our community so I decided to do something about it, raise awareness and some money to help defend and educate people about not only encryption, but about privacy rights in general. So I created a shirt. Yeah, I know how it all sounds, but what better way to show your support and hopefully, get others to think about exactly how serious this issue is to everyone, even if they don't know why encryption is so important. If even one person asks you about your shirt and what it means, you'll have the opportunity to educate someone that might otherwise never have even bothered to think about this issue.

To order your shirt(s), go here -> 3ncryp7ion is NOT a Crime!

100% of the proceeds will go to somegreat charities, namely, Hackers for Charities and the EFF.
Hackers for Charities is doing great work in Africa to not only educate people in the use of computers, but also providing training for people who want to gain employment in the field. They also help provide internet access to remote villages and people that otherwise might not ever have that opportunity.
The EFF (Electronic Frontier Foundation) does a lot of work on behalf of computer users and the general public world wide by raising awareness of the various laws that are written involving computers and their communications and monitoring,

Please check out the charities here and when ordering, please specify which charity you would like to receive your money. (all un-allocated funds will be split between the two charities equally)

Hackers for Charities

EFF

Thanks to everyone for your support and encouragement in this project. It means a lot to me and I can see that it means a lot to many of you as well! I would also encourage other, more well-known bloggers out there to take up this cause and help raise awareness of the madness that is being proposed the help keep us "SAFE"

NOTE: For anyone ordering shirts that require international shipping, the shirt site does NOT support this, but I do and I will make that happen. just click on the Contact link on the site and send me an email with your order request and I will get back to you with the details.

Wednesday, January 14, 2015

Wi Fight?

So, we have TV shows and movies coming out that show “hackers” doing magical things with computers and we have the added hype from the MSM that shake in fear when a Twitter account gets hacked (really just pwned because of bad passwords, etc.) or when a gaming network has been taken offline using tools, that, well, anyone can use even if they only have basic computer skills and the money to rent a botnet.

And the result of such ignorance and misinformation? Changes to current laws that can practically make anyone in information security a criminal under the right circumstances. I’m not going to delve into that aspect, as Robert Graham has already addressed these issues in a great blog post today. Please read this, if you have not already: http://blog.erratasec.com/2015/01/obams-war-on-hackers.html#.VLcCZyvF9ps

As I perused the proposed changes to the current laws, I noticed something that really stuck out to me, the recurrence of this and similar phrases; “…or facilitate the commission of…” said crime. This line got me thinking, what do I possess that could be classified under that statement? Well, I have a TP-LINK WiFi adapter that can be initialized in promiscuous mode that can sniff WiFi traffic and using some simple programs actually capture this traffic. I also have a WiFi Pineapple that can accomplish the same tasks and a great deal more!

Do these devices make me a criminal? Does watching You Tube videos on how to best leverage these devices (on a perfectly and still legal pentest) make me a criminal? Sure, there is no “intent” here, but the equipment and knowledge can “facilitate”. And this is just hardware, not the software distros that are out there that make these tools even more effective, like Kali Linux, Pentoo, Pwnie Express, just to list a few.

Another, passive, but “facilitating” concept that is frequently used, even by hobbyist in the field, is wardriving, using programs like WiGLE that log and map SSID’s of a range of devices, even providing GPS locations of said devices. Will possession, let alone use, of such applications now be criminal offenses?

The answer, as it stands today, is most likely none of these devices and techniques will be “technically” illegal if the laws are changed, just because of the sheer volume of what’s already out there and the amount of people using them, but, as Jack Daniel said earlier today, “it depends on the aspirations of the prosecutor” on where these lines are drawn.

But, as we all well know, once this Pandora’s Box is opened, it’s going to be damn hard to shut and the talented people who do great research and help protect the public from people and organizations that are truly scary, will eventually become targets, for any number of reasons that some ambitious prosecutor can conjure.

NOTE: Consider this… A great and award winning journalist, and a person that a great many people in information security admire and trust as an authoritative source when it comes to data breaches, namely Brian Krebs, could easily be a prime target under these new laws. Just let that sink in for a moment.

ACTION: Take action, write your local federal legislators, try to engage them in a dialogue and inform them of what our community is really about, educate anyone and everyone you can, encourage discourse on the matter before it’s too late.

SUPPORT:
All the journalist and bloggers out there that have the courage to report and speak out about the truth of things.
Support groups that, on their own time, are fighting the good fight every day, like:

#MalwareMustDie
#WeAreTheCavalry
#WeAreTheArtillery


And other groups and individuals, for they are the militia of the internet as we know it!

Wednesday, January 7, 2015

(I)nternet (C)onnected (S)tuff


So yeah, there was a Target thing, a Home Depot thing, a J.P. Morgan thing and even a Sony thing. Was it bad, yeah, sorta, if you consider that some of our largest corporations were owned in a solid manner and, in some instances, it took months to even discover the breaches. But ironically, the most discussed incursion is the Sony hack, which in retrospect, is really nothing since it’s just an entertainment company (this statement, in no way minimizes the affect this incident had on the innocent employees and their personal information that was leaked). And yet with all the press this Sony debacle is getting these days, especially when the FBI is firmly sticking to “it was North Korea that pulled it off”, people seem to have lost sight of a major area of concern for our nation’s security and that is our ICS and SCADA infrastructure. 

We always hear about the IoT (Internet of Things) and how it will be a hackers paradise, being able to make toasters and refrigerators do all sorts of dastardly deeds, but there is another IoT that concerns me more than all of the other attack vectors combined, and that is our critical infrastructure, which, according to many experts is ripe for the picking. And if there are real nation-state actors out there that want to hurt us (and I believe there are), then they won’t be popping Target, Sony or Cuisinart, they’ll be targeting the systems that we rely on every day.

Just writing what I have so far I feel like I’ve already rehashed a lot of what has been reported for months on end, but I also feel that the truth needs to be repeated so everyone understands just how important these issues really are to our country’s very existence. Most of you work in private sector positions, fighting the good fight to keep our PII safe, and this is needed very much these days, but there is also a great need for the same kind of tenacity in the ICS/SCADA world. And, if you think it tough to evoke change in your particular organization, just think about how hard that same task is in the even larger world of the major utilities like power, nuclear, transportation, oil and gas, because when things go wrong in these areas, people can die and no cyber-insurance policy will ever be able to cover that adequately.

To be honest, I have no experience at all in any kind of ICS or SCADA environment (and very little real experience in the general infosec field), but I can say that if an event on the level of the Sony incident would have happened to one of our critical infrastructure assets, then the United States would be in a very vulnerable state at this moment.

Even though the Sony story is important in a great many aspects, there are bigger fish to fry out there and we’re deathly close to being in that frying pan. So if we really want to be concerned about the “nation-state” actors, we should be more concerned with our critical infrastructure and not so much with the breach of a Japanese based entertainment company.


REVISIONS:

1. As a general note, all governmental agencies need to cooperate with our critical infrastructure firms BEFORE the $hit hits the fan, not after the fact.

2. Disclaimer: To the authors knowledge, at no time were any squirrels harmed during the writing and revising of this post. however, we do not know if they reciprocated in kind. 


Note: A very special thank you to @chrissistrunk for his insight on this piece. Wanna know more about ICS, then he’s your man! 

Saturday, December 27, 2014

Doing the Un-Walk!



Well even after all the brouhaha about the FBI report coming out and (sorta) proclaiming that North Korea was responsible for the Sony Entertainment compromise, which most of the infosec community thought was bullshit from the start, they seem to be walking this back now. This is not surprising considering the evidence that has been presented to the contrary by many respected researchers in the field. On the other hand, a great many people do find this surprising, now why is this, which is the real question…

The real reason why this is surprising to so many people is many fold. First, most of us find it easy to think of North Korea as the “bad guy” just because of their past and current social and political status in the world. No one would ever argue that North Korea is not a bastion of anything other than the suppression and cruelty towards their own people and anyone they could potentially force their will upon (which sadly is only their own people). Second, as of late, they have been flexing what weak muscles they have towards Japan (hiding under the skirt of China since there is no love lost there) with missile tests and the like. And third, well, we all like bad guys being bad guys, it’s just so much simpler when the people we think are bad are, well, acting badly.

This is the perfect formula for a nice tight story, with backup that most people don’t understand, nor really care to for that matter, other than the word of our government, which, ironically, most people don’t trust to begin with! Strange bedfellows indeed! But a great formula for deceiving the masses through the attribution of ignorance. And I do not blame the masses for this, I blame the government (and most of the media) for this, as they are the ones that are attempting to take advantage of people that don’t know any better. Most people don’t know, nor should be expected to know how “sophisticated” cyber-attacks occur, after all, we pay experts to take care of this, right? I’m not trying to go all conspiracy theory on this breach, but the foundation is perfect for laying the blame wherever it’s convenient, especially considering the lack of understanding by most normal folks in society.

Fortunately, we have a lot of very talented and well-meaning people out there that know enough about attacks like this and have the balls to speak out about the research they have done on their own, without any compensation other than wanting to know the truth of the matter. The consensus, even before the FBI even floated their weak hypothesis, was that this attack never originated from North Korea. And now, through this pressure of wanting the “facts” revealed, the FBI is walking back their initial position that this was the work of the North Koreans, which even North Korea denied (which should tell you a great deal, since, as crazy as they are, would take credit for anything if it made them look good).

But enough of that for now…

So some might say it might have been Sony to help push their movie and whatever else. That’s just really crazy talk considering the money they spent on making the movie, not to mention the huge liability their responsible for at the moment, cyber-insurance notwithstanding. So the Sony Entertainment Corporation is out of the running, other than the fact that they obviously have some major security issues that were never addressed.

So who actually breached Sony and why? Well that is the real question isn't it? We can all speculate, from people with an informed perspective or people just being couch quarterbacks, but so far, no one has actually identified a person(s) or group that has left a traceable path of evidence. One group has claimed responsibility for the breach and despite all their threats, other than some data leaks, hasn't produced anything other than smack talk.

So I’ll just leave this out there for everyone to think about, especially since I know I am talking to a limited and intelligent audience; Sony is being hush-hush about this, which is to be expected, the Incidence Response firm will be shackled by NDA’s so no information will come from them and the government has now been discredited from their initial proposition by people that actually know what they’re talking about. But you know the FBI has talented people too, so that might just mean that they are hiding something, which is not unusual, but for what reason? And that is the real question isn't it?


Throughout this whole debacle there is one conclusion can definitely be drawn from all of this though and that is, attribution is now a weapon

Friday, December 19, 2014

Fully Bullshitical Intelligentsia

First off, I will declare that I am in no way an expert in any of the areas of expertise in which I’m going to make comments about. That said, I’m not a moron either and I truly disdain being treated as such, as should any person that relies on their governments intelligence agencies that are bound by law to be truthful to their people unless there is a damn good reason to withhold such information. I fully believe that there are times when certain “lettered” agencies can’t and shouldn't reveal what is truly going on during certain operations, but I don’t believe that the hacking of an entertainment company qualifies as one of those instances.

So, before today there was much speculation as to who the actual perpetrators of the Sony attack were and their reasons behind such a brutal assault against an entertainment company. Sure, the idea of North Korea was being floated about, but generally not in the circles of people that are truly in the “know” about this kind of attack. And yet today, our own FBI took it upon themselves to announce that the attack was in fact the work of hackers from North Korea, never mind that the whole supposed reason behind this attack was the premise of a two-bit movie about a meaningless country’s dictator.

Making any sense so far?

No?

That’s what I thought.

Some very intelligent, yet independent people have taken upon themselves to analyze the malware that was used in this attack and almost every one of them to a tee have concluded that either this was absolutely not the work of the North Koreans, or, in the least have cast considerable doubt to this claim. Yet, the FBI’s proclamation about their findings has been swallowed hook line and sinker but all of the media outlets reporting about this major breach.

So let’s all take a step back from this and see who has something to gain from their claims; the independent researchers who took their own time to investigate the actually, albeit minimal, evidence provided, or the big government agencies that have full access to all of the data, yet have to report to someone “above their pay grade”. Politics can be a bitch no matter your political leanings, but the 1’s and 0’s never lie, if you drill down deep enough. But never forget that any data can be made to appear to be something other than what it truly is. And from what I have seen so far, the independent researchers have offered up quite a bit more technical detail that any of the “three lettered” agencies have. And if these fine people can show their good scientific methods and their conclusions, it’s really not a national security matter, it’s just a matter of truth over narrative.

So, for honesty's sake, let’s lay all the cards on the table and see who has the winning hand.

P.S.

And to anyone who wants to wave the banner of national security, if someone wanted to truly hit us hard, they could cripple our critical infrastructure, rendering us vulnerable to a variety of attacks, but I doubt they would test these attacks on an entertainment company or because of a movie, so calm that shit down. Not that this issue isn’t a real threat that needs to be addressed, just that the events aren’t related, in my unprofessional opinion.

Tuesday, December 16, 2014

The (Story Of Negligent Years)

Our story begins many years in the past, ending in the present day (or does it?)

Antagonist: DERP

Read everything you can about the Sony breach (or just the headlines), especially the internal parts about movie stars, executives, leaked scripts, personal information and then, forget it all. This whole mess is just a security failure of their own making, not an act of war, or any other such nonsense, nor does it even matter who perpetrated the attack. The simple fact, and the lesson that should be learned from all of this is, SECURE YOUR NETWORK PROPERLY.



The End. 

Thursday, December 4, 2014

CISSP (Certified Insecure Sony Server Protocols)

MD5 hash: f46e64c568bd8816a2ca95835e2a2584
SHA-1 hash: e8da4dd2400ef4fc931a30625d8be59bf3a10eea

Well, now we know the recipe for the perfect crime: Have a 3 to 1 ratio of security executives over the people that are actually responsible for implementing and maintain said security. This, as reported by Fusion in this article: http://fusion.net/story/31469/sony-pictures-hack-was-a-long-time-coming-say-former-employees/ seems to be the template for success if you want a multi-billion dollar company to be completely pwned. But you don’t have to be a multi-billion dollar company to have this level of security, all you really have to have is an ability to pay ridiculous salaries to a few people who know very little about what they are managing, hire a few folks that actually do know what they’re doing, then underfund and require security to take a backseat to “productivity”. Boom, now you’re ready for the big time!

Now if you take this formula and apply it to practically any other business unit you can imagine, in any industry, do you know what you will get? Yep, you guessed it, complete and utter failure (excluding government agencies, which practically all of them excel at this!). And why is this? Well, most all of us know this is a self-answering question.

Again, using Sony as an example, when they make a movie, of course there are the executives making a lot of the decisions on the basic path of how making a movie will take, and while we might not all agree with their course, you can damn sure bet they are using their experience in making these calls. Sure, it may harm the storyline for some, but they are thinking of the bigger picture, making a marketable, money making movie, in other words, doing their job. But once those choices are made, they will spare no expense to make sure that all the assets, like good producers, directors, screenwriters, actors, effects groups and crew are in place to make this happen.

Now imagine a world in which security is treated with such a success oriented respect… and the irony is, the template for this success is actually a key part in Sony’s business model.

Oh the irony…


Monday, November 17, 2014

Insure-Sec-Future-Fail

A few days ago @Wh1t3Rabbit @dearestleader  and I had a nice little conversation about insurance companies and Information Security with regards to breaches and how companies handle the potential risks. We already have red-teamers that are tasked with doing risk compliance testing for companies and now it seems that the blue-teamers are going to be dragged into being the “adjusters” in this new realm of cyber-insurance. (to be fair to the others, I will take responsibility for this post just in case it fails utterly, their good names won't be besmirched, but if they agree, even better!)

Now the article I am going to cite does not come out and say this, but this would of course be the natural progression, in my humble opinion. So without commenting any further, here is the article from  ZDNET to which I am referring: http://www.zdnet.com/police-cant-stop-cybercrimals-but-maybe-insurers-can-7000035514/

Of particular note are the following quotes:

“Encouraging the creation of an insurance market for online crimes could help enforce standards of security, just as home insurers insist on a particular type of locks on doors and windows before they will agree a policy. This makes it harder for burglars to break in as well as potentially reduces the burden on the police.”

OK, so from this we can glean that, if insurers are involved, upper management might buy into more stringent security measures because it will save them money? Really, well if they would invest and promote the best practices in security to begin with, then they wouldn't need insurance in the first place, right? Also, this begs the question, which “lock” would be the preferred lock, opening an avenue that only “insurance” approved security appliances can be used in a system?

And it continues:

”The government argues that insurers are in a good position to encourage businesses - small ones especially - to improve their cybersecurity by asking tough questions about their breach and operational risk policies.”

Again, really, it takes insurers to encourage this? I’ll say it again, this is the job of the C-level folk to make this happen not some third party that will make money off a lazy corporate security climate, regardless of a breach. Think about it this way, a bank’s physical location might be insured but they spend a hell of a lot of money on security, not to mention those large and very expensive vaults that are installed at every location. Hell, it’s easier to break into a banks IT infrastructure than it is to literally rob a bank (and get away with a respectable amount of money). Let that sink in for a minute…

To their credit, there is a somewhat sane response in the article:

“Whilst insurance offers financial protection to businesses, it does not incentivize businesses to invest in enhancing their cyber security defenses."

However, the paragraph continues down the spending the money trail with this:

“He said organizations that demonstrate good cybersecurity should be rewarded through lower premiums, adding: "This would align to steps taken by insurers offering protection against wider business interruption and ensure that such risks were being appropriately managed by businesses and not just managed through insurance coverage.”

Which looks good in print, but sounds to me like this is compliance taken to the next level instead of truly focusing on the real issues; creating and maintaining a stalwart security posture, instead of just adding another level of “bandages” into the mix.


So, is everyone ready to work for an insurance company?

Sunday, November 16, 2014

So...

this started out as a joke tweet about a new company called Misguided Security, a firm that, as the blog states, will "tell you what you want to hear and check all your boxes". The reason this is such a novel idea is because this is exactly what a lot of companies want from their security auditors, a report and a checkoff sheet. But, as we all know, this is not what security is supposed to be about, in any shape or fashion.

Not sure what I will write about in this space, but it will be security related and most likely will involve some of the more insane tales that lead to security failures, hopefully with a humorous tone. But we'll see where this blog goes in the future as I'm notorious for abandoning blogs, but I'll try to make this one last, if there is an interest.