Paella for hackers and security pros

To celebrate the end of the sixth year of the securityandrisk blog, this time my post is an alternative post. Information security professionals, "hackers" and "itsecuriteers" need to explore IT systems but they also need to eat every now and then ;-). I share with all readers one of the most precious cooking recipes. A crown jewel: The recipe of a modest but tasty version of the well known Valencian Paella - a typical dish with rice from Valencia, Spain.

Ingredients per serving
2 portions of chicken
1 portion of rabbit (it can also be spare ribs)
a glass (250ml) of water
half a glass (125ml) of rice
a quarter of an onion
half a red pepper

Other ingredients (typically for 4 people)
some vegetables e.g. green beans and peas
some seafood e.g. squid, mussels and prawns
crushed tomatoes (125ml)
2 to 4 cloves of garlic
parsley
saffron (this is expensive, you can also find paella colouring - less pricey)
salt
olive oil

Directions
In a frying pan (or in the paella-pan, called paellera, if you have one) fry the salted portions of chicken and rabbit until they get a nice golden color. Once fried, place the fried portions on a plate nearby.
In the same frying pan, with the remaining oil, fry the chopped onions and peppers until they get slightly brown. Then, add the tomato and subsequently the selected vegetables and seafood. Once all those ingredients are lighthly brown, add the fried chicken and rabbit.

Mix the chopped garlic, salt and parsley in a wooden bowl with a wooden stick, if available. Otherwise, mix these spices as well as you can.

Add a glass of water (250 ml) per serving and the spice-mix until it starts boiling. Then, add 125 ml of rice per serving, well spread out through the paella-pan and finally the pinch of saffron. Cook all ingredients over a low heat for about 18 minutes and without a lid! Let the paella smell captivate you. Afterwards, turn off the heat, put the lid over the paella-pan and let it settle for 5 minutes.

You can now enjoy a paella for hackers and security pros!
Happy cooking and eating!

Security and cooking are human passions
Paella is a dish to share with people.
Tweet this post to those you will share the paella with!

SSL And The Future Of Authenticity: A talk by Moxie Marlinspike

These lines are a subjective summary and collection of thoughts triggered by the presentation that Mr. Moxie Marlinspike, co-founder of the start-up whispersys (very recently acquired by twitter), offered at Black Hat USA 2011. The title of this talk was SSL And The Future Of Authenticity. It is still available on youtube (with more than 30000 views!). It is a security talk worth watching from both the content and the delivery viewpoints.

The beginning of the presentation is surprisingly not devoted to providing a long and boring bio of the presenter. Let's keep that in mind as a nice intro to a talk: Sharing an anecdote with the audience. They will pay more attention to that than to a long list of achievements. Human beings like stories, remember!

The first part of the presentation deals with the news of the Comodo hack. He remembers that more than a quarter of the Internet's certificates are Comodo's. And, after the hack, actually, nothing happened to Comodo. The cool point here is that Comodo published the IP address from which the attack was supposedly performed and Moxie could identity the same IP address in his servers' logs, a day after the attack, trying to download his tool sslsniff. Moreover, the HTTP referrers that that IP address left in his logs did not hint at all that it was a highly sophisticated State-sponsored attack the one behind Comodo's.

Anyway, the story of Comodo illustrates, according to Moxie, the problem we have today related to the use of SSL as a secure protocol to identify sites on the Internet. He mentions the 3 requirements that a protocol like that should have:
  • secrecy
  • integrity
  • authenticity (something that SSL does not really cater for)
Moxie refers to the inadequacy of SSL, designed in the 90s of the past Century, to solve our current challenges, with more than more than 2 million server certificates in the Internet and more than 600 certificate authorities out there. Worth mentioning is the SSL threat model from Ivan Ristic.

It is then when Moxie introduces the concept of trust agility, something that would enable users to shift trust much quicker than with the current SSL certs. Trust agility should:
  • be very easy to revise
  • let users decide where to place the trust
He then confronts the highly centralised trust model proposed by DNSSEC with the highly uncentralised trust model that certificates require. In a nutshell, that is the reason why he does not think that registrars, top level domain name administrators (e.g. Verisign) and country code domain name administrators will come to save us all. They all provide very reduced trust agility.

What does he proposed then? He revives a Carnegie Mellon proposal called perspectives. It is based on checking that the certificate in the secure site is the same that the one held by an authority, the notary. These notaries will build a constellation of trust. However, perspectives will only validate the initial connection.

Based on perspectives, Moxie expands it and introduces convergence. Convergence includes a new authentication (expandable) protocol and provides a firefox add-on. In convergence, the user initiates the communication to check the certificate and decides the level of trust given to each certificate. The added value that this initiative provide consist of:
  • no notary lag (local caching possibility)
  • no privacy issues (detaching the site name from the requester via a proxy - using notary bouncing)
The hiccups he identifies in the use of convergence are:
  • mega-sites using a hundred different ssl certs (they exist but they are rare)
  • captive portals (where a DNS query would help)
Finally, he poses to telling questions to the audience:
  • who do I have to trust and for how long?
  • a prescribed set of people, forever?
My 2 humble cents on this: I welcome initiatives such as perspectives and convergence. They clearly signpost the need for Internet-based economic activities to come up with something more resilient than our good old friend SSL. However, let's remember Betamax and VHS VCR systems example, where the solution conquering the market was not the most technically viable option. We need more than a good engineered proposal to conquer the secure site market, and sometimes we don't know where is (or will be) the tipping point.

Enjoy the secure browsing!

Where does SSL lead us to?

Book review: Social Engineer - The art of human hacking by Chris Hadnagy


I wanted to post a personal review on a current social engineering reference book. Christopher Hadnagy's book, "the art of human hacking" deserves the label of reference book in the social engineering field.

I enjoyed reading the book. Those who listen to the social engineering podcast, in which the author takes part, will find in the book most of the topics dealt in the first 20 something podcast episodes. This book is the written witness of the spirit present in the social-engineer podcast.

SE book highlights
In this post, I fly over, following a very personal route, the main ideas that the 9 chapters of this book contain. The book is easy to read. Every chapter conveys some summary points plus a brief summary at the end. This facilitates the identification of the learning points.

The lessons learnt are applicable in almost every aspect of our lives. By no means this summary aims to replace the reading of the book. On the contrary, this is a book I recommend to read, not only to information security professionals, but also to anyone interested in knowing how human beings tick. This book is a valuable tool when modelling human behaviour. Actually, if there is intelligent life in outer space and they need to liaise with humans, this is one of the books that they need to read so that they can understand humans.

chapter 1 - introduction to social engineering
This first chapter describes the different types of social engineers. Interesting point: governments are also social engineering actors.

chapter 2 - information gathering
Chapter 2 mentions information gathering tools like BasKet and Dradis. There are also two telling examples, the USB example mixed with an encounter in a cafe and the stamp collector story. Some points that I highlight are the following:
  • Interesting their message that every one can have and have different personal realities (page 44).
  • Most of the time people want to help (page 52).

chapter 3 - elicitation
Elicitation is non-threatening and it is very successful (page 58). It is eye-opening to know that a simple light conversation is all it takes to get some of the best information out of many people (page 58).This chapter mentions the intricacies of elicitation, such as how preloading the target with info or ideas on how we wanted them to react to certain info is a good start (page 62). They mention an example related to "how to convince your partner to go for dinner to a steak house" (page 62) - it is worth-reading it - would that really work?

A basic way of elicitation is to start a conversation with "I would like to tell you a really funny story" (page 63). 

The author also mentions the concept of preloading. From an social engineering (SE) viewpoint, "preloading involves knowing your goals before you start". Expressing a mutual interest is more powerful than appealing to someone's ego: another important learning point (page 67). More information on elicitation can be found in the social-engineer.org site.

Some of the elicitation techniques that the book mentions are:
  • Appealing to one's ego.
  • Expression of mutual interest.
  • Deliberate false statements.
  • Volunteering information.
  • Assumed knowledge.
  • The effects of alcohol (not a different technique but equally effective).
  • Open ended questions, what do you think of the weather today?

Let's define some concepts that the book presents:
  • Elicitation is the process of extracting information from something or someone. Read the definition on the social-engineer.org site.
  • Pretexting is the act of creating an invented scenario to persuade a targeted victim to release information or perform some action.
  • Preloading is influencing subjects before the event. Think about a movie's pre-release trailers. They use desired outcome words such as “The best film you have ever seen!” This technique works great when introducing anything. Preloading is a component of a social engineer attack.

Some of the techniques the author mentions are:
  • Use open-ended questions to obtain detailed information (page 70).
  • Closed-ended questions are appropriate to lead the target to a goal (page 72).
  • Asking people a leading question in order to manipulate their memory (page 73).
  • Assumptive questions - you need knowledge before hand so they need to be used with care (page 73).

chapter 4 - pretexting 
The ideas mentioned around pretexting i.e. creating the background story that makes up the character you will be for the social engineering audit, rotate on these points:
  • On the Internet you can be anyone you want to be. 
  • Create a scenario where people are comfortable with providing information they would normally not provide. 
  • Practice makes a good pretext.
  • Self-confidence is always related to a situation.
  • Cognitive disonance: People have the tendency to seek consistency among beliefs, opinions and cognitions.
  • Dialect - you need to master the right pretexting dialect - at least spend some time listening to people in public talking to each other.
  • Play it back later (from the recorder) this is recommendable
  • Use an outline script.
  • Use sounds from e.g. thrivingoffice.com
  • Do not try to make the pretext elaborate
  • Keep yourself within the legal arena
chapter 5 - mind tricks
According to this chapter, we need to identify the target dominant's way of thinking. The author refers to Dr. Paul Ekman. He showed that emotions are universal across cultures and biological backgrounds. He worked with  basic emotions through the microexpressions that show those emotions. However, these skilled people could show those microexpressions in a different time.

This chapter mentions a possible way to overcome the client's reluctance to communicate: We need to identify whether they are a fan of sight, hearing or feeling (the site www.examiner.com is mentioned as a source of info).

We also need to try to identify deception by identifying contradiction, hesitation and changes in behaviour and hand gestures. Some of the NLP language patterns to influence change on interlocutors have to do with the voice tone (site mentioned: planetnlp.com).

There is also a general recommendation to watch for a group of signs and not only one sign to determine the baseline of our interlocutor. A set of leads on which we have to focus are microexpressions, body language cues, changes in verb tense and person use. An example of anchoring is linking a statement of a like kind with a certain gesture.

An valuable fact: People retain less than 50% of what they hear. As smart interlocutors, we need to react to the message, not to the person. For example, a way to state something could be "it sounds to me like you are" rather that using "you are" alone.

While practicing all these techniques, we need to develop a genuine interest and let the other person talk about herself until she gets bored of it. Let's remember that people's fundamental needs are:
  • Love/connecting
  • Power/significance
  • Freedom/responsibility
  • Fun/learning
  • The effect of young star photos
  • Breathe at the same pace as your target
  • People like people who are like themselves
  • Human buffer overflow = law of expectation + mental padding + embedded roles 
chapter 6 - influence: The power of perceptionThis chapter mentions concepts such as "kill them (verbally) with kindness", scarcity and concessions and again that 
simply asking the target a question can lead to amazing results. We can manipulate attention through the use of scarcity. Let's remember that people are driven to desire that which is hard to obtain.

Chapter 6 lists these types of authority:
  • Legal authority.
  • Organisational authority.
  • Social authority (in western countries, clothing, cars and titles).
The author also describes the value of commitment and consistency with actions (e.g. people are more prone to help you when you leave a bag unattended if you previously ask someone to look after it) and some additional ideas such as:
  • Liking (people like people who like them).
  • People need to be liked, they change their behaviour to be liked by others.
  • Good-looking people succeed more than not good-looking people.
  • Humans attribute more good traits and skills to good-looking people.
chapter 7 - the tools of the social engineer 
We can read about lock picking, intelligence gathering using public sources, tools like Maltego, SET and password profilers.

chapter 8 - case studies: Dissecting the social engineer 
This chapter provides a valuable set of examples coming from the author and from Mr Mitnick himself.


chapter 9 - prevention and mitigation 
The bottomline: Prevention and mitigation creating a personal security awareness culture and the importance of developing scripts and being aware of the criticality of the information you are dealing with.

Happy social engineering!
Congratulations Mr Hadnagy!



Hardening a wireless DSL router

Avoid that someone else uses your wireless DSL router

Most homes in developed countries use a home wireless DSL router to connect to the Internet. Remember that, in an increasing number of countries, the owner of the router is legally responsible for the data coming in and out of that home network to the Internet. Avoid being in an unwanted legal case by preventing that your DSL router (and your Internet connection) is used by an intruder to commit any illegal action. Make your DSL router relatively secure with the following preventive (and a final one, detective) security measures:

- Change the private IP address that the router has by default. How many routers come with 192.168.1.1 or with 10.0.0.1? Please, let your router be other than 192.168.1.1.

- Change the default IP addressing schema of your home LAN (cable or wireless). There is no obligation to always use 192.168.1.x or 10.0.0.x. As long as it is a private IP address (see RFC 1918), dare trying with e.g. 172.16.x.x.

- Limit the mac addresses that can connect to your router. Find out the mac addresses of all the gadgets that connect to your wireless LAN and input them into your router's mac ACL.

- Use WPA2 with a long password, you can get it for example here.

- Make the admin interface only available to your internal LAN (avoid making it available through the Internet). Easy way to check this: Find out your public IP address (e.g. using myipaddress), try to reach that public IP address and the admin web page.

- Are you a hardliner? Then disable the DHCP server in your router. Add the IP addresses. routing gateway (your router) and DNS servers in each of your wireless clients manually. Use different DNS servers on each of the gadgets (so that no unique DNS server gets a complete idea of your browsing behaviour).

These measures follow a defense-in-depth approach. None of them constitute the silver bullet, but the entire set of measures is a valid starting point.

If you would like to check your router's threat exposure to the Internet:
- Find your public IP address here.
- Install nmap in your box and launch the following two lines:

$ sudo nmap -sT -n -v -T4 -O -p- --reason yourpublicaddress
$ sudo nmap -sV -n -v -T4 -O -open ports coming out from first command yourpublicaddress


The nmap command line usage help can be found here.
- Limit the services you offer to the Internet.
Nmap should produce an output similar to this one:
All 65535 scanned ports on are filtered because of 65350 no-responses and 185 host-unreaches. Too many fingerprints match this host to give specific OS details.

If the result shows some open ports, identified by the -sV option as UPnP, review the expert view of the admin interface in your router, it is probable that you allow some firmware update, or push service provision coming from your ISP or a specific server app. Just check that it corresponds to your needs (e.g. a VPN server, a file server... or maybe, nothing is published to the Internet).
Finally, a detective measure: Check your router's logs frequently. Most routers can send their logs regularly to an email address. Use this feature. It is priceless to identify abnormal uses.

Happy scanning and happy secure home DSL router!
p.s. The "--reason" is a suggestion coming from a network jedi ;-)

Avoid misuses of your DSL router while you are on the beach
Additional measure (inspired by a comment left by an anonymous reader left)
Broadcast (but as little as you need ;-)
Scan the wireless networks that surround your place, choose a wireless channel that is not used, or at least very little used. This will enable you to decrease the level of energy used by your wireless router when broadcasting its signal. 
Fine tune the energy level so that the wireless signal is almost constrained to your place. This will definitely make a wireless attack to your network a little bit more "physically challenging". Here you are some command line tips to scan the wireless spectrum using aircrack-ng from a Linux box.

$ sudo apt-get install aircrack-ng
Information on aircrack-ng installation can be found here
Disconnect from your wireless network (keep the wireless driver working though)
$ sudo airmon-ng start wlan0
airmon will tell you the name of a wireless interface that can be used to scan (it will normally be mon0)
$ sudo airmon-ng start mon0
$ sudo airodump-ng mon0
and you will get a real-time list of active wireless networks (incluing channel numbers)

Thanks to the anonymous reader!

Hacking: The next generation by Dhanjani, Rios and Hardin - Book review

The following is a brief [and biased] review of the pages of Hacking: The Next Generation. In one sentence, I would recommend it to an IT student thinking of getting closer to security as a first-time security flavour.  

Disclaimer: These lines do not substitute the reading of the book. They are meant to provide a global overview of what the reader can find in the book. My kudos to the authors, writing a book is always a big effort. And even a greater effort if the books talks about a changing target as IT security. 

The authors: Nitesh Dhanjani, Billy Rios, Brett Hardin. 
Publication year:  August 2009.
Publisher: O'Reilly Media.



Chapter 1 Intelligence gathering: peering through the windows to your organization
The first chapter gives some actual tips on social engineering and intelligence gathering. They mention the Google Hacking Database and the Search Engine Assessment Tool and the usefulness of metadata and social networks to collect information that for a future attack. Tools like theHarverster.py and metagoofil.py are also mentioned. Syntax in google such as resume filetype:doc "current projects" and even the simple use of public google calendars can also render nice results.

Chapter 2 inside-out attacks: the attacker is the insider
This chapter proposes an easy path to understand how currently an external threat becomes an internal one thanks to threat vectors such as xss and xsrf. After reading this chapter, you will not use the remember password functionality in a browser.
Flash and Java are also mentioned. Another learning point in this chapter is that we should only share documents we trust with people we trust. Difficult task!

Chapter 3 The way it works: There is no patch
A varied chapter. It starts with the traditional description of the insecurities of telnet and ftp, both clear-text protocols. They also mention tools such as wireshark and a little python script named goog-mail.py to carve out email addresses. The authors also suggest the use of a password brute-force attacker tool such as hydra and John the ripper. 

This chapter also deals with session hijacking using tools such as hunt (to hijack clear-text TCP-based sessions). The fact that they are using private IP addresses makes sometimes some examples a little less realistic. On this topic, I miss a reference to the need to have a network card in promiscuous mode, also when we are trying to hijack session in a wireless network.

A basic description of SMTP snooping (with mail snarf) and spoofing is also part of this chapter. They finalise the chapter describing ARP poisoning with tools such as Cain&Abel and DNS Cache snooping with cache_snoop.pl.

Chapter 4 Blended threats: When applications exploit each other
The helicopter-view summary of this chapter is brief. Exploits currently constitute what authors name blended threats i.e. creating a big threat vector out of the combination, or beter said, chaining, of several harmless-looking vulnerabilities. 

The key concept to understand is the application protocol handler: a way for two applications to interact using the operating system. They provide examples both in Windows and Mac OS. 

Finally, the most flashy example of blended threats, conficker, with 9 million infected machines as of January 2009.

Chapter 5 Cloud insecurity: sharing the cloud with your enemy
This chapter presents the differences between cloud services offered by Amazon (based on what they call AMI - Amazon Machine Images) and Google (based on the Google App Engine). It is an eye-opener in the sense that insecurity now has a new meaning if we think of cloud services.

The apply common sense and present the two most visible vulnerability vectors i.e. misconfigured virtual machines and insecure management consoles.

Finally, they also present real vulnerabilities, already solved, (based on CSRF) that the authors discovered in Amazon Web Services.

Chapter 6 Abusing mobile devices: targeting our mobile workforce
These pages deal with ways to compromise corporate networks and information without even connecting ever to the corporate network. The rey resides in the threats targeted at mobile workforces.

First basic step to attack a corporate mobile force, spoof the MAC address of the attacking laptop. Second step, use a mix of common sense and social engineering. Certainly, also useful tools such as Burp Intruder and Cain & Abel. The first one useful to defeat easy entry portals and the second one excellent to get credentials used in services that do not use SSL permanently.

The authors also present man-in-the-middle attacks (e.g. although they don't mention it, they refer to a la ettercap-style attacks) and how easily users double click on any certificate warning appearing in their browsers.

The chapter ends with some words on metasploit, voicemail tapping and exploiting physical access to mobile devices.

Chapter 7 Infiltrating the phishing underground: learning from online criminals?
These pages deal with a real threat to our society and economy i.e. cybercrime and, more specifically, phishing (on page 177 I think there is a typo, when they refer to foreign companies, they really mean foreign countries. Some interesting facts they mention:
- phishing sites have a time to tlive (TTL) of just a few hours.
- www.phishtankcom publishes the URLs of phishing sites that are online. Very interesting for demo purposes!
- often an insecurely configured server becomes a phishing site for different phishers.
- all this points show the importance to securely configure any web server running on the Internet

The authors also mention a very useful tool for web testing, burp proxy and a skill that good phishers have: they know how to use different elements present on the Internet for their evil purposes (and they try to phish other phishers by inserting backdoors!).

They also talk about a phishing toolkit called the loot, offering phishing kits for many institutions, and about some phishing lingo such as "ReZultT" and "fullz" (all information required to steal someone's identity).

Chapter 8 Influencing your victims: do what we tell you, please
This chapter refers to human hacking. Rather than targeting a web application, sometimes accessing someone's calendar or eavesdropping a conference call (by knowing the conference ID) provide juicy information more easily.

The authors also mention the importance of social network in current hacking trends. For example, they created a fake identity in linkedin, or rather, they stole someone's identity and in several minutes this identity had received 82 incoming requests to be part of their network.

They also mention the evilness of the "forgot your password?" questions that some sites use to authenticate users, especially when complemented by facebook or linkedin information.

They complete this chapter with sentiment analysis based on tools such as Yahoo!Pipes,  sites like wefeelfine.org and concepts such a a word cloud.

Chapter 9: Hacking executives: can your CEO spot a targeted attack?
This is the flashiest chapter. Easy to read and really implementable. The authors talk about how to construct personalised attacks, with little effort, against executives based on network analysis (note that network here is a set of acquaintances and not cables and switches). Why attacking executives? They are normally the most informed members of the organisation.

They mention two main motives: financial gains and vengeance. Regarding how to monetise an attack, the authors mention that it is more profitable to try to sell the information to the company that actually owned it rather than trying to go to the competitor.

Information gathering using public sites and social networks is the first step in the attack. The input gathered helps identifying the executive's trusted circle and, specially, those with the most influence over the executive. A little but interesting detail, probably family members will not be in that trusted circle. Another one, sending the attack to the executive's assistant provide promising results given the trust existing between both players.

The authors also mention useful sites such as www.tweetstats.com, namechk.com, the phyton script titled theharvester and the enticing USB data stealer named USB switchblade.

Chapter 10 Case studies: different perspectives
In this last chapter they present two case studies. The first one clearly shows the need to disable old accounts and to control who joins a teleconference.The second one claims the importance of hardening ssh servers, the need not to publish IT information related to a company in Internet and the beauty of XSS based exploits.

Happy next generation hacking reading!