Security's Everyman

Security's Everyman

Tuesday, September 30, 2008

Playing catchup

I think this may be the longest stretch that I've had with no blogging. My last post was on Sept 14th. Since then I've gone on vacation and been preparing for vacation and catching up after vacation. Needless to say it's been busy. Hopefully Ill be back to regular posting now.

I'm going to do a "catch-all" post to try and comment on a couple of things.

I'm going to start off by going back just over 2 months to a post that Rebecca Herold made regarding awareness training and a part 2 here. I starred this in Google Reader and then forgot all about it. I'm bad about that. I need things screaming at me so I will remember to go back and read it. Anyway, she talks about the fact that we often fail to give adequate awareness training to those who need it most. Specifically those who deal with customers on a daily basis. Our Receptionists, call center reps, etc. These folks are on the front lines but are often ignored as we focus our awareness training on those who are in "check box" positions. What I mean by that is that those who work with PCI data, financial info, etc.. Somewhere there is a regulation that says "train these people or else". We train them so we can claim compliance and then give the crumbs to the rest.

The next item is actually recent and both of these were posted within the last 24 hours. Two different stories with the same theme. I saw this one on Foxnews.com first and then a few minutes later this one on cccure.org. It seems that we still haven't learned basic security in many cases. What's really sad is that in both of these cases there is really no excuse for this happening. It seems that we are still disposing of devices that have not been sanitized. One case involves a British MI6 agent selling a digital camera on eBay that had all sorts of Top Secret data on it. There were pictures, fingerprints, names of terror suspects and other information. I can see this happening to someone who is a "regular" person (obviously not the top secret data but selling a camera with pictures still on it) but a MI6 agent. I'm sure they are trained in basic security such as this. The next article talks about a Cisco VPN Concentrator that was bought by Andrew Mason on eBay that was still configured to automatically connect to the central VPN concentrator at the company it originally belonged to. It's a good thing that Andrew is one of the good guys. According to him he had full access to the network by simply plugging it in and connecting to the internet.

A story that is close to home involves patient data for 45 people who were patients at Atlanta's Grady Hospital. It seems that their data was inadvertantly put on a unsecured web site instead of on a secured web site. There are lots of interesting facts and issues involved in this that you can read about here. First of all often companies give too many people access to their web sites to add content. Just as we don't give everyone access to our financial data we shouldn't give everyone, or even several people, rights to add content to web sites. There is way too much risk in insecure or unauthorized code/data getting put up. We have a hard enough time getting our web developers to write secure code much less allowing marketing to add content at will or any other department. The second problem that I see is that Grady outsourced the work to one company who outsourced it to another company who outsourced it to a 3rd company. I'm not totally opposed to outsourcing but this is ridiculous. Either legal didn't do their job in contract negotiations or they need to do a better job in ensuring that outsourcers are staying within the bounds of the contract.

One last thing that I want to comment on. Kudos to Jeremiah Grossman and Robert "RSnake" Hansen for the way that they handeled themselves when vendors requested that they not release information regarding their OWASP talk on clickjacking. It shows maturity on their part to be patient and not try to rush something out just to get name recognition. Not that either of them are hurting for name recognition.

There are lots of other things that have been going on over the last 2 weeks but many other bloggers have done a great job of covering them so hopefully you already know all you need to know about them.

Sunday, September 14, 2008

CSI Video Interview

Last week I was interviewed by Robert Richardson, the Director of the Computer Security Institute, about the FOI concept that I've written about a few times. The interview is now up and you can find it here.

Friday, September 12, 2008

I want my Cingular back!

Until AT&T bought Bell South a while back I had not had many dealings with them outside of a T1 circuit or two that I had to manage. Honestly I wasn't happy with them then and I'm even more unhappy with them now.

I've been a Bell South/Cingular customer for a long time. My first personal cell phone was with a company (I can't remember their name for the life of me) that merged with another company and became Cingular. I had always been pretty happy with them. Service and coverage were both good and dropped calls were rare. Then along came AT&T. Now coverage stinks and dropped calls are a common occurrence. I'm not sure what exactly changed to cause this. Did they knock down some towers to make coverage worse? Are they randomly pulling the plugs on some calls just to irritate customers? It seems to me that since they inherited a good network that things would only get better as they added their infrastructure to what already existed. Obviously I'm wrong there.

I also have a AT&T aircard that I use (or try to use) when I'm working remotely. Actually I was pretty happy with it at first. I'd go to my favorite local coffee shop to work and had good coverage and no real problems. The when that shop closed I had to move to other coffee shops to work and I can't find one that has decent coverage. I get 2 bars on a good day but mostly one. Try to run VPN with one bar. Not gonna happen. Then when I do get going I lose the connection and have to reinitiate it. There are 3 coffee shops within a short distance of my house that I've tried working from and all of them are in bad coverage areas. They are not all side by side either. They are spread out so that I should be able to find decent coverage. So now instead of driving 2 to 4 miles away to work I'm having to expand my reach. Last week I tried a coffee shop about 9 miles away and had poor coverage. Today I'm at another one about 7 miles away that sits right in between 2 interstates and still coverage is poor and it continues to drop. Even in downtown Atlanta I have problems.

So I want my Cingular back. I want to go back to good coverage and to times when dropped calls and connections are rare. I want to go back to the good ole days!

Slow to criticize, quick to applaud

I usually try to criticize too quickly but occasionally I do. I don't think that my criticism of Apple yesterday was quick considering their past record that I mentioned in that post. However I did have my doubts as to how they would handle the bad driver issue and how quickly they would correct it. Today I see that they have already fixed the problem and are sending out updates to ITunes.

According to my secret source (OK, so it's not a secret source but I've always wanted to have one) Ed Bott has a new post up talking about the fix and his experiences with installing ITunes now that the fix has been released.

Good job Apple. I had my doubts but you proved me wrong.

Thursday, September 11, 2008

FOI in depth

OK, so what started out as a funny comment on Twitter has started to turn into something. The FOI (Failure of Investment) concept has been picked up on by a few others who have added to it, questioned it and some think it has a future. I read one post in particular that I wanted to comment on and expand my thoughts a bit. So instead of doing it via a comment on the blog I decided to do it here. Before I go any further I recommend that you hop over to Jack Daniel's blog at Uncommon Sense Security and read his thoughts on this. After all he was kind of the brain child behind this. I'll wait patiently for you to read it and then I'll continue.

Oh good, You're back.

Today, Sara Peters, who blogs at Security Provoked the blog of CSI (Computer Security Institute) picked up on the FOI concept and said that she liked it but wasn't sure she bought it yet. One of her concerns was the FOI focused too much on straight security and not enough on risk management. I would say to her that FOI is all about risk management. After all security is managing risk. If we don't support the business, by understanding it and it's goals, then we have failed. If we don't look at what we are doing in light of the business objectives then we are not securing the business but we are securing the technology which misses the mark. Security for the sake of security is no security at all.

Can we continue to trust Apple?

If you've read my blog for very long you probably know that I'm not a big fan of Apple, inc. I think that they have some very cool technology and in many ways I'd love to actually have some of it. A Macbook Pro would be nice to have because I think it's a really good laptop. I'd love to have a IPod Touch because it gives me the flexibility of using it as a mp3 and video player as well as allowing me to surf the Internet via wireless networks. Yet, I just can't bring myself to buy any of them because I just don't trust them.

Apple has shown itself time and again to only care about themselves and not their customers. They appear to be willing to do whatever it takes to further their agenda even if it means being dishonest and underhanded. They will even try to ruin the careers of security researchers if it will keep their public image intact. They are willing to try and increase market share for their Safari browser by sneaking it in an update.

I've heard and read horror stories about support when you have to send things off for repair. I've heard them deny that a vulnerability exists and then quietly fix it a month or two later. Then they have the gall to say that the fix wasn't for the earlier announced vulnerability but for something that was not publicly known. They don't seem to care that they release patches that don't fix what they say the patch fixes.

To me this all says that Apple, inc has an ethics problem and when it is this blatant I have a hard time doing business with them. It definitely affects the level of trust that I have in them. The question is will you and other customers continue to trust them?

Why do I ask this? It seems that once again Apple is sneaking things into their updates that they don't feel the need to inform us about. Ed Bott does a good job of chronicling issues with the latest release of ITunes 8 and some things that are happening when you think that all you are updating is ITunes and Quicktime. If what he and others are saying is true then not only is Apple sneaking things into the update process but they are also causing all sorts of problems with windows systems. How will Apple deal with these problems? That is the big question here. Not so much the fact that they are installing things beyond ITunes, although that is an issue that they need to deal with.

I've not installed ITunes 8 yet and won't until I know that the problems are fixed. Why do I use ITunes at all since I'm not an Apple fan. Because I bought a IPod Nano from my Brother-in-Law a few years back and I use ITunes  because it came with the IPod. At that time I actually still had some respect for Apple. When my IPod dies I imagine I will get a different mp3 player and ditch ITunes all together.

Monday, September 08, 2008

Voting Security

The other day I was looking on ITunes for a new information security podcast. I ran across a couple that I thought I'd download and see if they were worth subscribing to. One of them is called the Data Security Podcast and I listened to it this morning on the way to work. The podcast was pretty good, at least good enough that I'll listen to a couple more episodes before deciding if it will stay on my list or regulars.

One thing that they talked about was how Ohio has come up with some new regulations of electronic voting security. Things like not allowing poll workers to transport machines and related items (cards, etc) in their personal cars and not allowing them to store them at home overnight. Then they went on to talk about the potential badness that could occur by this happening. What really intrigued me was a suggestion that they made. They thought that it would be a good idea for information security professionals to volunteer to work the polls on election day. Their premise is that many information security professionals have a good understanding of the risks associated with electronic voting and may be able to keep an eye on things and help to keep the polls more secure. Of course the potential for bad to happen because of this possible could increase if hackers also volunteered to "help" at the polls. I think all in all that it is a good thing for us to get more involved in the democratic process in any way that we can.

Friday, September 05, 2008

How NOT to work securely from a coffee shop

Many of you are aware that my favorite independent coffee shop closed about a month ago. Since then I'm having a hard time finding a good place to work from when I don't go into the office. I've tried another local coffee shop that is just too small and uncomfortable to work from. I've tried 2 different Starbucks that have very poor reception for my AT&T air card so VPN is out of the question. Today I decided to drive a little farther to another Starbucks to try it out. Air card reception is good, coffee is good, atmosphere (music, tables, light, etc) is good. So I'm pretty happy.

When I got here there there several people sitting around so I found a table next to a wall with an outlet and set up shop. The table is one of three along a long booth seat. The middle table was empty and the other end table was occupied by a lady who also was set up to work. Papers were out, cell phone on the table, laptop up and running.  Shortly after I got here a friend of her's walked in and spoke to her. After getting his coffee he came back and asked her if she had a minute to talk. She said sure and he said lock your laptop and come with me.  She looked at him like he was a little off in the head and said "What do you mean?" He told her to password protect her laptop so that this guy (looking at me) won't steal all of your personal info. I looked at him and said "Good advice, I am a hacker". Then, of course, I told him that I was one of the good guys. So she locks her laptop and they go to the parking lot.

While she is in the parking lot with this guy all of her stuff is right here. Laptop, purse, cell phone, papers (insurance settlement related I gathered from her phone conversations), purse (which I'm sure had here wallet with license, credit cards, etc). They were gone for several minutes, plenty of time for someone with less morals and ethics to do lots of damage. After a while she come back and unlocks her laptop and goes back to work. After a few minutes she places a call and starts talking about work stuff. I heard her mention a claim settlement and then she seemed to realize that she was in public so she gets up and walks to the back of the store. Again, everything is left right there but this time her Laptop is not locked. She can't see the table she was at and I can't see her. Another perfect opportunity to take something, read something, load keystroke logger, get CC #'s etc.... It's a good thing I'm a good guy.

After about 15 minutes she comes back and goes back to work. Again after just a short time she's talking on the phone and tells the person that she can go to her car and print something out. I guess she has a 12v converter in her car. So she unplugs her laptop, picks up her purse and leaves the building. She's getting better but she left her phone and papers sitting there. In a few minutes her phone rings and it's all I can do not to answer it. I resist and a few minutes later she returns with her purse and laptop. Plugs back up and gets to work.  She stayed with her stuff for the rest of the time she is in the store, that is right up to the time she is ready to leave. She shuts down, unplugs and stacks everything up in a nice and neat stack. Then she goes to the bathroom with her stuff nicely stacked up and ready to be walked out the door. The shop was empty by now except for myself, the lady and a couple of employees who were not in sight.

This is a perfect example of what not to do. She made so many mistakes that I started to wonder if maybe this was some sort of a sting operation. I envision agents in the parking lot waiting with hands on guns for someone to do something illegal. Maybe someone with a high power lens across the street snapping pictures. If so then they failed to make a bust today. Maybe next time they will have more luck. :)

Security ROI - The debate continues

It seems that blog topics are cyclical and raise their head every few months. A couple of the hot ones are full disclosure and ROI both of which have reared their ugly heads lately. ROI has been on the front pages again in the last few days and it seems that as usual we can't agree on whether or not there is such a thing as security ROI. The purist say that it doesn't exist because it doesn't meet the "true" definition of ROI. The "revisionist" say that there is ROI on security but you have to measure it differently. Yada, yada, yada, the debate goes on and on..............zzzzzzzzzzzzzzz.

Yesterday it hit Twitter and several people jumped in and commented but one that really struck me came from my friend Jack Daniel. He said that the true measure of security is failure or as the new buzz word says "Security Fail". That hit a cord with me and I have to agree 100%. That is the true measure of security whether it be a device, application, or program. If you fail you lose. So Jack and I coined the new term FOI, Failure of Investment. When it comes to buying, implementing, or doing anything in regards to security the value of the investment is determined by success or failure. Not how much it cost vs. saved. Not how easy it is to deploy or manage. Not how much time it saves, etc.... The real measure is made when it protects or fails to protect.

It may be that it does a great job of protecting most of the time but the one failure may be it's (or your) demise. Now we have to define failure though. In my mind failure doesn't come because a new flaw was discovered in your AV, firewall, IDS/IPS, or other security device or app. It comes when that flaw isn't managed properly by either the vendor or your team. If the vendor fails to respond properly and the vulnerability is exploited then they fail. If they do respond properly and you fail to implement the fix or if you fail to look for and implement other measures to protect yourself during the vulnerability window then you fail. 

As we all know failure can be fatal to your job. So it's in our best interest to quit debating and trying to define Security ROI and to focus on preventing FOI.

Saturday, August 23, 2008

MBTA and responsible disclosure

What is responsible disclosure? That is a question that has not and will not be answered. It all depends on who you ask. One researcher will give one answer and another will give another answer. The same goes for those who work in other areas of information technology and information security. Networkers and developers, security pros and server admins. All will give different answers depending on their view of information security and the importance of discovering flaws and disclosing them.

The key word in this discussion is "responsible". Unfortunately even responsible doesn't mean the same thing to everyone. I guess in reality the word responsible can/does have a moving definition. If you find a vulnerability and it will take lots of skill, special tools and lots of money to exploit it on a wide scale then the risk of it being exploited is pretty low and disclosing it w/o going to the vendor is not as big a deal. On the other hand if you take the opposite of those things and you disclose without giving the vendor a chance to fix it is irresponsible. Those are the two extreme sides of the debate. It's all the stuff in the middle that causes the masses to argue over what is responsible and what isn't.

Here is my take on this with some comments on the MBTA debacle thrown in.

  1. As Information Security Professionals it is our responsibility to act in a professional manner and to do all in our power to protect the company that we work for.
  2. If you are doing research on your own or for a company then you have a responsibility to protect your client or the company/vendor that you are researching.
  3. If you call yourself a White Hat researcher then you have a responsibility to act in responsible manner for all computer users.
  4. Responsible disclosure means that you give the vendor/company time to fix the issue before going public with it.
  5. The argument that vendors are not responsive a vulnerability is given to them is flawed because this is not the case most times.
In this instance the MIT students didn't act responsibly in several of these areas. #2, 3, 4 were all ignored for the most part. Giving a company 4 days advance notice is hardly responsible. Although there is some rumor floating around that the MBTA did have notice of some of the issues several months ago. Which if you think about it is true. They may not have known about this particular research from MIT but it has been public knowledge of the Mifare RFID chip being vulnerable since the Dutch researchers wrote their paper about a year ago. Not to mention the fact that the London Oyster Card also used the same chip and it was announced a few months back that it had been hacked.

If anyone would expect that the MBTA would be able to fix this in a short period of time then they are sadly mistaken. An issue such as this involves much more than just changing the encryption on the card. The software and firmware used in the readers and encoders have to be changed. The database has to has to be modified as well as the code in the vending machines that sell the tickets and much more. There has to be testing and QA before it can be rolled out into production. Not to mention that getting new cards is not something that you can just run down to Wal-Mart and pick up. Especially when you are dealing with something as big as this. There are specs that have to be figured out and agreed upon between the MBTA and their Fare collection vendor. Then they probably have to put out a bid on the new cards and give the card vendors time to submit proposals. Then they have to go through a selection process and then wait on a PO to be approved via their procurement process. Then they can place the order. Even at that point they are still not ready to go live. The vendor has to fill the order and once the new cards are in there is still the whole process of replacing the old cards. This means that the new specs will have to be backward compatable with the old ones because they can't just cut the old cards off and make everyone migrate to the new ones all in a day.

As things such as this and the DNS Metasploit exploit continue to happen it makes me less and less of a fan of disclosure until after vendors have released a patch and adequate time for the patch to be installed has passed. I'm not there yet. I still think that there is a place for researchers to find flaws and get the word to the vendor so they can be fixed. I'm even in favor of researchers releasing exploits prior to a patch if the vendor is ignoring the issue AND the issue is not of a nature that can cause serious widespread pwnage.

I have to admit that one thing that I recently read makes a lot of sense. I don't remember where I read it or who said it so if you know let me know so I can give them credit. Basically they said that instead of spending so much time looking for and focusing on vulnerabilities that have a very low risk to the public lets focus on fixing the ones we know about that do have the potential to cause serious problems. Let's also focus on writing better code and deploying more secure applications and infrastructures. This is where we can make a difference. Lets quit trying to make a name for ourselves by being the first to find something and make a name by being the ones who are willing to work together to make things better.

Wednesday, August 20, 2008

Sometimes things slip up on you

I was perusing my RSS feeds this morning and ran across this post by my friend Martin McKeay where he talks about missing his 5th year blog anniversary. That reminded me that I missed my 2nd year blog anniversary. I posted my first blog entry on Aug 9, 2006. It was an experiment to see how I would like it and it stuck. As Martin says in his post blogging has been a very good thing for me. It has opened many doors that more than likely would have remained closed if I had not started blogging. Ironically Martin is one of the key reasons that my blog has succeeded. I'm not sure how but he found my blog on Aug 11, 2006 and made a comment encouraging me to keep it up and he later linked to me and mentioned me on his podcast.

I've become a big fan of blogging and reading blogs. I consider reading blogs as a part of my job now because I learn from those I read and gain information and knowledge that I would not have. As I talk with other security and IT professionals who don't read blogs I'm amazed at how much more informed I am then they are about what is going on in the world of information security. I think the biggest benefit that I have gained from blogging is the friendships that I've developed w/ other bloggers and security professionals. Most of them I've never met, yet I know that I can call on them at any time if I need something. The next best thing has been the opportunity to interact with several of those of you who read my ramblings and then comment on them or send me emails. It's always good to know that what I have to say is enjoyed by others and occasionally adds value to them. Of course there are those who have disagreed with me from time to time and that's OK as well. Good healthy debate is good for the industry and helps to keep us sharp.

So, thanks to all of you who give me a few minutes of your time each day (that is when I don't go on a 2 week no blog spree). I hope that you stick around for the next several years.

Tuesday, August 19, 2008

I'm not an expert in all things security, but I am a thinker

My apologies to Glenn Beck for borrowing his line, but I think that it fits well. Not trying to toot my own horn just proud of the fact that I don't blindly follow the crowd. As you may know I haven't posted anything in over 2 weeks which is a first for me. Life continues to keep me busy and the last week or so have seen some personal events that have taken up lots of my time. During this time I've done a good bit of thinking and watching.

I'm not going to go into many details except to say that we had to buy a new vehicle recently due to my wife being the victim of another driver who wasn't paying attention while driving. At least not paying attention to driving, who was on the road near him, etc.. He may have been paying attention to something else but not these things. We also had to rent a car, talk to insurance adjusters and reps, make doctor visits, etc.... All the fun things that go along with something such as this. While I was doing these things I took advantage of the opportunity to practice my Johnny Long "No Tech Hacking" techniques. I noticed lots and lots of opportunities to gain access to personal information of other people and even to gain access into the computer systems of some of these companies.

I was left in offices alone w/ a logged on PC several times for various amounts of time. Several times there were also applications open that could spill their guts on other customers and clients. Many times I was left alone with documents loaded w/ PII right on the desk I was sitting at. I overheard lots of phone calls that involved names, addresses, credit scores, credit limits, etc...

Of course I was also asked to give sensitive information to many of these companies. Some needed it to fill out claim forms, reports, credit apps, etc... As usual many of the auto dealers wanted a copy of my drivers license before allowing me to test drive a car. When asked what they do with the copy I was told different things. Some said they were shredded, filed, thrown away and "I really don't know". Needless to say the answer given had a lot to do with whether or not I took a test drive and then I ensured that before I left the copy was truly destroyed.

In one office I was left alone w/ PII on the desk, several computers logged on w/ apps open, heard PII given out over the phone and then heard one girl tell the customer that the copy of the document was shredded to protect them. At least they have the right idea. They are just missing several pieces.

That's where the "I'm a thinker" part comes into play. What these companies need is to take a few minutes and think about what they are doing, why they are doing it and what they are not doing that needs to be done. The office above was taking a great step in shredding documents but they obviously either didn't have policies, processes and training in place to prevent lots of other errors. It's great that they shred a copy of a document that has my PII on it but what good does it do if all of the info on the document is freely available to others who are left alone in the office? This is why we can't just do "best practices" and move on. You have to take a look at the bigger picture of what is happening in your environment and work from there.

As the CSO or top security professional in a company it is difficult to know what all goes on out in user land unless you spend some time there. You need to talk to people who do the front line work and find out what they do that may need to be addressed. You need to either visit or at least have someone else visit different locations and departments to find out what is going on that the users would never be aware of. I'm talking about things such as giving out names, addreses and other information over the phone in front of other customers, leaving documents on a desk instead of filing them or at least putting them in a lockable drawer until you can get to them later. I realize that this is not the type of things that a busy security professional (especially if you are in the top spot) so this is where you can utilize your desktop support team and others who are in the field.

Another area that we need to pay attention to was made apparent recently by the legal department of the MBTA. In their efforts to stop a DefCon talk about how to hack the MBTA Charlie Card and other sloppy security issues, they released more info than would have been released by the talk. Not to mention that they brought lots more media attention to the fact than if they had just let the talk go on as scheduled. If they had bothered to consult with their security team they might have made better decisions in how to handle this.

As security professionals it's our job to protect the organization that we work for. We have to look out for their best interest even if it's in areas that we are not responsible for. What I mean by that is looking for things that aren't right and making them known to those who are responsible, doing our part to let others know that security is here to be an enabeler and not to hinder business. Letting them know that we can add value to all areas of the business if they will solicit our input (such as legal, HR, etc). Often these departments don't even think about how security can add value to what they do. Many times we think differently about problems because most of us think about how to make things do what they aren't supposed to do (or at least we are aware that the bad guys are doing this) and we see things from a point of view that the business units and even regular IT doesn't.

Sunday, August 03, 2008

One more post on DNS

OK, here is my reply to LonerVamps comments on HD Moore releasing Metasploit exploits for the DNS vulnerability that Dan Kaminsky discovered.
Loner broke his comments up into two different comments. I've posted both of them below and my response will be in red.

First Comment
With or without Druid's exploit, our users were at risk. And rather than sit in the dark and not want exploit code, I certainly don't mind having it around to learn from it. I'd even contend that we're better off researching exploit code; write more, learn more, write better ones, learn yet more, and so on. I agree that having exploit code can be beneficial as we learn more about the vulnerabilities and how to protect ourselves from them.

So, you would probably come back and say that HD Moore shouldn't have released it "at this time." But, what basis is there for when a time is appropriate to release exploit code? One year after the disclosure/patches? One month? After a committee of CISSPs gets together an votes on it? After 75% of servers are patched? Ever? I think that the answer to this question depends on what the vulnerability is and how easy the exploit is to deploy. In this case the vulnerability was big and had the potential to affect a large portion of the Internet. Potentially sending people to sites that could do all sorts of things from something as harmless to the user as auto clicking on ads to as harmful as dropping Trojans and other malware on systems as well as stealing account info for financial sites. If this had been just a browser vuln or an ActiveX issue then I wouldn't have been as concerned about HD releasing his exploit this early. Not because the end result is less but because even those who did do their due diligence were vulnerable to potential big problems.

And how does exploit code differ from vulnerability details? Should we not disclose details that could lead to exploit code for 1 month, 1 year, or ever? As for when to release vuln details that is a whole different question that has been debated for a long, long time. I'm too tired to deal with that now. :)

This set of questions simply cannot be answered, and never will. And since they can't be answered, I'd have to err on the side of reality: Exploit code is exploit code, and when it is released it is released. And then move on. :)

2nd Comment:
said my comment was too long :(

Andy, I fear you are arguing the side that is actually indefensible. :) Acting "responsibly" is far too relative to ever apply to such a set of people as security-aware geeks. Even though I agree with you in reality I disagree that we shouldn't expect "security-aware geeks" to act responsibly. Unfortunately we, as security professionals, often do not act responsibility I feel that we have a responsibility to our users and companies to be responsible. That doesn't mean that we blindly apply a patch just because the vuln is a big on or even because exploit code has been released. It also means that we don't release exploit code when other parties (researcher, vendors, most users) are acting responsibility and doing their job. It would be different if the vendors were ignoring this but they weren't. They acted responsibly and HD should have let things be.

Here's another way to tackle it. Should we manage our security posture based on whether exploit code is known or not? Yes, a vulnerability/patch does have a different value based on whether code is known or not, but when no known exploit code is in the wild, is it OK to put off the patching of your servers?

It might be argued that distributing details and exploit code will actually stimulate a more secure digital world. If your time frame for patching DNS was a month after the patches because the vuln wasn't known or the exploit created, but is now immediately because an exploit has been released...is that not a desirable state? Obviously the presence of code prompts action, and as such, this might be a benefit to us all... In today's world of the bad guys being ahead of us on almost every front and since as soon as a patch is released it is reverse engineered and an exploit is in the wild within hours then any security guy worth his salt knows this. So if he chooses to put off patching just because there is no known exploit then he is just asking for trouble. We all measure risk and then make a decision based on our level of comfort with each issue. Personally when you have an issue of this magnitude I think you are foolish to wait for known exploits.

Friday, August 01, 2008

Result from DNS Poll

This has been one of the most popular polls that I've had. My post about this garnered a good deal of comments and emails. Most of which disagree with me. Not surprising since usually people who do agree don't comment nearly as much as those who disagree. I'm not through with this either. LonerVamp has come good comments that I want to respond to when I have more time.

There were 106 votes on the poll almost 70% of you said that HD should have released the exploit for one of the 3 yes reasons. The totals were 70 yes and 26 no. For a while I thought I would be the only one to vote "No, It was irresponsible of him". I still stand by that statement and when I respond to Loners comment I'll explain why in more detail. But for now I will say that I'm not against him releasing an exploit at a later date, just not at the time he did.

Here is the breakdown by answer.

Yes, we deserve to have it
18 (16%)
Yes, if he didn't someone else would
24 (22%)
Yes, the bad guys already have their own
28 (26%)
No, it was irresponsible of him to do so
9 (8%)
No, it's too early and several people haven't patched their servers yet.
23 (21%)
No, we don't need WhiteHat exploits.
4 (3%)

I was a little surprised that 4 of you voted "No, we don't need WhiteHat exploits." I'd love to hear from you with your reasoning why you feel that way.

Hopefully by now everyone has patched their servers, including AT&T (that is another irresponsible matter in my opinion) and that this is behind us.

Wednesday, July 30, 2008

A little public transportation snooping

I started riding the bus from where I live into town a little over a year ago. When I first started there were 3 departures each morning and maybe 60 people total used the bus. Now that gas is $4 a gallon there are 4 departures each morning and about 200 people are riding. Of course when you ride with the same people daily you get to know them a little and conversation flows a little easier. This can be a paradise for a social engineer. Just today 2 events occurred on the ride home that caught my attention.

The first involved a man who was looking for a ride to the town where I live. He does not live there and was going to meet someone. He started asking questions of some of the riders about where the bus stopped and when it usually arrives, etc.. Then he made a phone call presumably to the person he is going to meet. The talked about the specifics of meeting and at some point the person wanted to give him a different phone number to call when he got closer to town. He said that he didn't have anything to write it down with but he would try to remember it. After he hung up the phone a nice lady sitting in front of him handed him a slip of paper with the number on it.

My first thought was "boy, she sure is nosey" but then again she probably was just being helpful and couldn't help but overhear the conversation. You could even say I was being nosey since I'm telling you the details. :) Then I thought of how easy it would have been for a similar scenario to have taken place regarding company information. As I write this I remember a couple of conversations that a network engineer that works for a big telephone company in the area had. He was talking to another engineer trying to help him solve a problem and router names and IP's were given over the phone. Other details regarding routes and ACL's were also freely given on a crowded bus.

The next issue that occurred today involves the guy sitting next to me. The first issue is that he woke me up to ask if he could sit next to me. Now that I look around I see that there are no other empty seats so I'll let it slide this time. :) Next he pulled out his laptop and started writing code, reading and writing emails and opened a database. All right there for me to see. All of it is company related (yes, I looked and I wish I had the nerve of Johnny Long to take a picture). I've got a perfect view of his screen and can tell that he is working on the database that he opened. His emails are being sent to work detailing what he is changing in the database. The one good piece of news is that he at least has his wireless radio turned off. I first pulled out NetStumbler to see if I could see him.

This just all goes to show you that you never know who is listening or looking over your shoulder. You really need to be careful when in a crowd.

For everything else there's karma

Thursday, July 24, 2008

DNS 'sploit - Irresponsible?

This whole DNS issue has become a "circus" to put it in the words of Chris Hoff. First there was the ruckus around the fact the Dan Kaminsky was only releasing some details of the vulnerability. People called him names and said unkind things about him. Then he met with a group of people and gave them details. They agreed with him that it was a bad thing and that we needed to patch now. Those who said things about him apologized. Then people started publically speculating about what the problem could be. Those that knew were sworn to secrecy. The rest of us were left to make our own guesses or talk about what we heard others say it might be. Then Havlar Flake put his cards on the table and the guys at Matasano confirmed his speculation. That opened up a whole new series of discussions. Why did Matasano have a post read to go? Why did they post it and then retract it? Was it an accidental posting or done purposefully? Some got mad at them and others praised them for giving us the details.

Now HD Moore has released an exploit for Metasploit. This makes it much easier for script kiddies and others to now use this against unpatched DNS servers. It also makes it much easier for the bad guys who don't already have a exploit to get one to use against the rest of us. All of this has led to lots of discussion on the internet and twitter. Should HD Moore have released an exploit? But the bad guys probably already have one so what does it matter. If he didn't do it someone else would. Etc... Some of the comments are valid and some are just stupid. Some are speculating that HD, the Matasano team and others are trying to steal Dan's BlackHat spotlight. Then there is the whole arguement as to wether or not Dan should even have a BlackHat talk planned on this.

I am a proponent of tools such as Metasploit and Core Impact. I think that they serve a good purpose for those of us in information security. I use Metasploit myself to test my systems. Even if they can be used for bad that doesn't mean that they don't have their place in the world of technology. If we didn't have them to test our systems with then we wouldn't really know how vulnerable we are. But I think that HD stepped over the line with releasing this exploit at this time. There is NO valid reason for it to be released. There are LOTS of other ways to test if your system is vulnerable. You can go to Dan Kaminsky's site and test it there. If it's a windows machine you can run windows update. If it's a *nix system you can check to see when the last patch was applied. Lots of ways besides using Metasploit. Not to mention that it hasn't been that long since the patches were released. Lots of companies haven't patched yet due to testing, apathy, ignorance of the issue, etc.. From all I can tell AT&T still hase lots of unpatched servers used by the IPhones and DSL service. @Techdulla on Twitter commented that he called his ISP to ask them why they hadn't patched and one of their engineers said "What Patch are you refeering to?" I'm afraid that is the response of lots of DNS admins.

As security professionals we have to be responsible in how we practice our profession. If not then we are putting ourselves and our users at risk. We are even putting others at risk with our actions when we are irresponsible. Just as the guys at Matasano were irresponsible for having a ready to go post with details on the DNS vulnerability HD acted irresponsibly by releasing a exploit for this. We can't just do something to be the first on to do it. We have to act in a responsible manner or we risk losing the credibility that we have built within the community of other information security professionals.

Now I'm going to ask your opinion. I'll put up a poll shortly that I'd like you to participate in. Here is the question and the answer choices.

Should HD Moore have released an exploit for the DNS Vulnerability?
A. Yes, we deserve to have it
B. Yes, if he didn't someone else would
C. Yes, the bad guys already have their own
D. No, it was irresponsible of him to do so
E. No, it's too early and several people haven't patched their servers yet.
F. No, we don't need WhiteHat exploits.

Wednesday, July 23, 2008

Good stuff in the SCC

I just wanted to take a minute and point you to a couple of good conversations going on in the Security Catalysts Community.

Stop by and check these and the other posts out. This is a great place to get information, interact with other security professionals and stay on top of your game.

Tuesday, July 22, 2008

DNS Problem

OK, so the news is out. Someone has figured out what it is that Dan Kaminsky discovered in DNS that has so many people concerned. Now that we know what the problem is that means that the bad guys know. If the bad guys know it's only a matter of hours (quiet possibly by now) before a exploit is released into the wild. That is bad news.

Even if you have patched your servers it could be bad news for you. Why? Because your DNS server relies on other DNS servers to tell it where web sites are. If your DNS server get bad information from a compromised DNS server it's game over. What are the chances that your DNS server will communicate with a unpatched, vulnerable DNS server? My guess is that the chances are pretty good. If you look at my little poll (which is a very small sampling of my readers and extremely small sampling of those who manage DNS servers worldwide) 42% have not patched their servers yet because they are still testing the patch. This number hopefully is smaller by now since they have had time to complete testing.

What has me worried is all of those who manage DNS servers and don't follow blogs, tech news sites and other forms of communication that would get the word to them. How are they going to know to patch their servers? I've not seen anything in the main stream media talking about this. Vendors don't have a good way of communicating with customers when problems such as this arise, especially those who download free software that doesn't require registration.

There is a lot of speculation around the release of the details of the issue. Should Halvar Flake have posted his speculations on his blog? Should the blogger at Matasano have posted his reply (which was promptly removed from the site)? People are arguing about whether or not Halvar was right or wrong in what he did. Others are complaining because Dan didn't release more details to the public. There is a place for all of this bickering and speculation but now is not the time. Now is the time to ensure that everyone patches their DNS servers and that we get the work out so that everyone knows that this needs to be done.

So get on the phone, compose emails, use Twitter or any way you can to make sure that all of your friends and contacts who manage DNS servers know about this. Call you ISP and ask them if they have patched yet and if they haven't then consider using a DNS server that you know has been patched. You can use Open DNS or another ISPs DNS servers that you know have been patched. Those of you who manage DNS servers may want to consider clamping down on who you allow your DNS servers to communicate with. This is a standard good practice any way but now you may want to be even more careful.

I'm not crying "the sky is falling" and I'm not trying to spread FUD (fear, uncertainity and doubt) but this has potential to be bad. It is something that needs to be taken seriously and dealt with. When you get this many people who are respected in the industry all saying the same thing then it needs to be heeded. When you get this many vendors working together to release a patch simultanously then we need to apply the patch.

Tuesday, July 15, 2008

Viacom takes the high road

According to this article on ComputerWorld.com Viacom has agreed to allow Google and YouTube to obfuscate the user names and IP addresses of those who view videos on YouTube. That is good news for all of us whether or not you feel that you have something to hide. It is still not a good thing that the Judge felt that our privacy had no place in this but hats off to Viacom and Google for working out this agreement.

One thing that we have to keep in mind is that when we allow our rights to be eroded little by little we will wake up one day and realize that we no longer have any rights. This is how we end up in places we don't want to be. Every time we give something up or compromise a core value, belief or right we open up the way for a little more to be taken away at another time. A good example from life is telling a "little white lie". We think that it won't hurt but then we have to remember what we said, who we said it to, who knows the truth, etc... Then if we are called on to defend it we have to either fess up or continue to lie and slip further down the slippery slope.

To tie this into information security this is also how a hacker works his way into our network. He starts out looking for a small flaw or vulnerability and then over time he increases his level of rights and authority. We have to be diligent to keep our systems, applications and infrastructure in good order to prevent him from finding and exploiting flaws. If we compromise little things then later the big things will come back to bite us.

Creative Commons License
This work is licensed under a Creative Commons Attribution-NC-SA 3.0.