This whole DNS issue has become a "circus" to put it in the words of Chris Hoff. First there was the ruckus around the fact the Dan Kaminsky was only releasing some details of the vulnerability. People called him names and said unkind things about him. Then he met with a group of people and gave them details. They agreed with him that it was a bad thing and that we needed to patch now. Those who said things about him apologized. Then people started publically speculating about what the problem could be. Those that knew were sworn to secrecy. The rest of us were left to make our own guesses or talk about what we heard others say it might be. Then Havlar Flake put his cards on the table and the guys at Matasano confirmed his speculation. That opened up a whole new series of discussions. Why did Matasano have a post read to go? Why did they post it and then retract it? Was it an accidental posting or done purposefully? Some got mad at them and others praised them for giving us the details.
Now HD Moore has released an exploit for Metasploit. This makes it much easier for script kiddies and others to now use this against unpatched DNS servers. It also makes it much easier for the bad guys who don't already have a exploit to get one to use against the rest of us. All of this has led to lots of discussion on the internet and twitter. Should HD Moore have released an exploit? But the bad guys probably already have one so what does it matter. If he didn't do it someone else would. Etc... Some of the comments are valid and some are just stupid. Some are speculating that HD, the Matasano team and others are trying to steal Dan's BlackHat spotlight. Then there is the whole arguement as to wether or not Dan should even have a BlackHat talk planned on this.
I am a proponent of tools such as Metasploit and Core Impact. I think that they serve a good purpose for those of us in information security. I use Metasploit myself to test my systems. Even if they can be used for bad that doesn't mean that they don't have their place in the world of technology. If we didn't have them to test our systems with then we wouldn't really know how vulnerable we are. But I think that HD stepped over the line with releasing this exploit at this time. There is NO valid reason for it to be released. There are LOTS of other ways to test if your system is vulnerable. You can go to Dan Kaminsky's site and test it there. If it's a windows machine you can run windows update. If it's a *nix system you can check to see when the last patch was applied. Lots of ways besides using Metasploit. Not to mention that it hasn't been that long since the patches were released. Lots of companies haven't patched yet due to testing, apathy, ignorance of the issue, etc.. From all I can tell AT&T still hase lots of unpatched servers used by the IPhones and DSL service. @Techdulla on Twitter commented that he called his ISP to ask them why they hadn't patched and one of their engineers said "What Patch are you refeering to?" I'm afraid that is the response of lots of DNS admins.
As security professionals we have to be responsible in how we practice our profession. If not then we are putting ourselves and our users at risk. We are even putting others at risk with our actions when we are irresponsible. Just as the guys at Matasano were irresponsible for having a ready to go post with details on the DNS vulnerability HD acted irresponsibly by releasing a exploit for this. We can't just do something to be the first on to do it. We have to act in a responsible manner or we risk losing the credibility that we have built within the community of other information security professionals.
Now I'm going to ask your opinion. I'll put up a poll shortly that I'd like you to participate in. Here is the question and the answer choices.
Should HD Moore have released an exploit for the DNS Vulnerability?
A. Yes, we deserve to have it
B. Yes, if he didn't someone else would
C. Yes, the bad guys already have their own
D. No, it was irresponsible of him to do so
E. No, it's too early and several people haven't patched their servers yet.
F. No, we don't need WhiteHat exploits.
Security's Everyman
Thursday, July 24, 2008
DNS 'sploit - Irresponsible?
Posted by
Andy, ITGuy
at
1:32 PM
Labels: Andy ITGuy, DNS Exploit, Ethics, information security
Monday, November 19, 2007
Ethics Quiz
Update to my quiz answers.
Matthew posted a comment to this original post asking for some clarification on the conditions on my answer to question #3. In his comment he mentioned something about "breaking government law" and my willingness to do so. It kind of caught me off guard so I went back and re-read the question and realized that it said "You are aware state law prohibits". I had made the incorrect assumption (due to not carefully reading the question) that the question was the same as #2 except it dealt with uninstalling software instead of installing software. Shame on me for not being more careful. So, that being said my answer is still D. Document the request and refuse to remove the software. I retract my conditional statement that follows. In this case there is no reason that I would uninstall the software and break State Law.
____________________________________________________________________
Matthew Rosenquist, the blogger who wrote the article that I referenced in my post "Are You Ethical?" wrote me a comment today and asked if I'd be willing to answer his questions and post them to the blog. So here it goes (my answers are in red).
- 1. You are conducting a confidential investigation of Employee ‘A'. An employee outside the team, asks "Are you investigating Employee ‘A'?"
You Answer:
A. Yes, we are
B. No, we are not
C. Maybe
D. I'm not sure/I don't know
E. Other: I can't/won't comment on any investigation that may or may not be going
on.
- 2. Policy prohibits any team member from installing software on Server ‘A'. In an emergency situation, senior management instructs you to install a critical piece of software on Server ‘A' to benefit the company.
You cite policy and:
A. Install the software
B. Refuse to install the software
C. Document the request and install the software
D. Document the request and refuse to install the software
(This is my answer based ONLY on these 4 choices)
My real answer would be dependent on exactly what the situation was, what the purpose of the server is, what the requested software is and what the implications of installing verse not installing it is.
- 3. You are aware state law prohibits any team member from removing software on Server ‘A'. In an emergency situation, your management instructs you to delete a critical piece of software on Server ‘A'.
You cite state law and:
A. Delete the software
B. Refuse to delete the software
C. Document the request and delete the software
D. Document the request and refuse to remove the software
(This is my answer based ONLY on these 4 choices)
My real answer would be dependent on exactly what the situation was, what the purpose of the server is, what the requested software is and what the implications of installing verse not installing it is.
- 4. Your manager instructs you to do something which is contrary to normal operating procedures. What do you do?
You cite the normal operating procedures and:
A. Do what is asked and report the incident to senior management
B. Refuse to do what is asked and report the incident to senior management
C. Document the request and do what is asked
D. Document the request, refuse to do what is asked, and report the incident to senior management
(This is my answer based ONLY on these 4 choices)
I chose to follow the request because this time it goes against SOP no policy. SOP has room to wiggle policy usually doesn't.
My real answer would be dependent on exactly what the situation was, what the purpose of the server is, what the requested software is and what the implications of installing verse not installing it is.
So, similar to Martin's comment most of these are very situational and not exactly black or white. I do believe that many situations are black and white but when dealing with technology and keeping a business safe and running situations play a big part in lots of issues. Ethics are still VERY important, but sometimes policy is wrong or hasn't taken into account every situation.
Posted by
Andy, ITGuy
at
1:03 PM
2
comments
Labels: Andy ITGuy, Ethics, information security
