Enchanting... also in IT security

Intro
A new excellent guest on the Entrepreneurial Thought Leaders Lecture Series - Guy Kawasaki - I recommend viewing the video or, at least, listening to the podcast. The following paragraphs are a personal summary of the ideas presented by Mr Kawasaki. My proposal will be to have the IT security world in mind when reading this text and think how much (or less) of all this we already do (or can do)?

He presented some recommendations on how to be enchanting. He used the 10 point format so that the audience know when the presentation ends. He mentioned that normally CxOs go long and they are boring when they present. Sometimes, in security conferences, I wish the presenter could be both specific and entertaining.

Tips for the art of enchantment
First, you need to be likeable. For this, improve your smile, using the muscles that surround your eyes, and certainly the jaw muscles, dress for a tie with your audience i.e. follow their same level of elegance and have a great handshake because first impressions are important.

Second, after likeability, the next step is trustworthiness. For that, I highlight these points:
- If you can't do something, find someone who could do it for you better.
- Don't ask someone something you would not do yourself.
- Empower people to do tasks.
- Don't micromanage.
- Provide people with a high purpose.

How to enchant as a leader
Provide your people with a MAP:
- Mastery: The possibility to learn and excel on the things they do.
- Autonomy: The chance to perform tasks themselves.
- A higher purpose.

- Any company needs first to trust their people (employees, customers) and then they will trust the company.
- There are 2 kinds of people, eaters and bakers, the first ones see situations as zero sum games, the bakers see ways to get bigger and more pies for everyone.
- If you would like to enchant, then default to yes, think how you can help that person.

How to enchant with your products
Your products need to be DICEE:
- deep
- intelligent
- complete
- elegant
- empowering

- Your message need to be short sweet and "swallowable".
- Important point, present in many thought leaders today, tell a story, why did you start your company, your plan, your adventure?


- Before failing, consider you have failed and conduct a pre-mortem analysis, that way everyone around a product can speak freely and with less emotional load.
- Plant many seeds to obtain your critical mass.
- Use simple and understandable features, salient points, to sell your product.
- Discover who are the influencers? Most of the times, the influencers are not the executives. Executives are very high in the ladder. The air is thinner high in the ladder. Thin air is not good for intelligence.
- Forget the use of money with your customers, it brings complexity and lack of veracity.
- Sharing and glory, people don't do it for money

Invoke reciprocation
More than answering a "thank you" with a "you are welcome", tell them "I know you would do the same thing for me". This way, you tell them that you have class and ...that they owe you. 

Enchanting up
Do what managers tell you to do, create a quick prototype, take little time to come back to show them if you are on the right track and, show them problems early, and preferably, propose a way forward.

Final thoughts
- in every presentation, customise the intro with local photos, sell your dream when you speak, use 10 slides for 20 minutes and 30 points font.
- Eliminate complexity.
- Answer within 24 hours.
- Use social networking, don't leave it only for when you have spare time.

Do you enchant while doing your job in IT security?
Happy enchantment!

Jack Dorsey: Running a business idea - applicable to IT security?

What does this post have to do with security? Well, we will soon see it. Stanford University's entrepreneurship corner is one of those reasons why Internet is, even just for this, a great invention. From your screen at home or from our smartphone or mp3 player, we have access to lectures given my current entrepreneurs.

One of the latest lectures is the one given by Jack Dorsey, creator of  twitter and square. I took note of some learning points, maybe subjective, out of his talk.

They are brilliant points to consider when creating a start-up within the IT security world. Do not forget them!
  • "Instrument" your company from day 1. The first thing he did in square (and not in twitter) is writing an admin control panel for their servers.
  • Be a story teller. You need to inspire your team and your customers with a story, your idea.
  • In the company, you act as the editor, composing the stories.
  • The team you build is not permanent, different players will need to enter and exit according to their profiles, the current story and the "required edition".
  • Internal communication: Everyone in the company will have the same priorities.
  • External communication: You communicate with the product, your product is "your story for your customers".
  • Money in the bank: The company needs it, firstly from investors and secondly, and more critical, from revenue.
  • Limit the number of details. Those details that stay need to be perfect.
  • A last sentence from his side:"expect the unexpected and, whenever possible, be the unexpected".
If you see value in these points, then listen to the entire podcast or watch the lecture.

Happy listening!

ps Thanks to the Stanford's Entrepreneurial Thought Leaders Seminar crew!


Social-engineer.org crew interviews communication expert Joe Navarro

The episode number 14 of the Social Engineer podcast features an interview with the author and expert in non-verbal communications, Joe Navarro. This is a post with learning points extracted from listening to his interview.

Disclaimer: These lines do not substitute the listening of the interview. The statements mentioned are close to literal or slightly summarised or just a subjective interpretation. Kudos to the social-engineer.org crew!

Minute 17: Inmigrants in a country using a different language than their mother tongue need to be sensitive to body language and observe carefully.

Minute 18: Babies mimic gestures since their third week of life.

Minute 19: Babies with eleven months look for mood clues coming from their mothers.

Minute 20: Blue is a smoothing colour. Blue is predominant on TV.

Minute 22: When we see something beautiful, our pupils dilate. When we see something ugly, ours pupils contract. Our limbic system controls this.

Minute 31: A good observer focuses not only on the face but on the entire body. It is more difficult to lie when there is space among our fingers and we show our thumb.

Minute 36 and 37: People talking while looking at the same direction are more relaxed than people talking facing each other. Facing people create tension when talking.

Minute 41: You can calm someone down just by exhaling in front of them (they will mirror you).

Minute 47: A biographer of Kennedy mentioned that you can get anyone anywhere anywhen talk to you, you just have to tell them that you treasure their opinion.

Minute 55: The meaning of words: People in their fifties like to talk about problems, people in their thirties talk about issues. People like to talk with people like them.

Minute 66: When performing social engineering, assess whether the person does look comfortable to you.

Minute 66: In the US, the amount of time one should look someone else at their eyes is 1.8 seconds.

Minute 68: Arch your eyebrows when you greet someone. When arching the eyebrows, we burn sugar. We only burn sugar when we care. Babies respond to this action already when they are a week's old.

Minute 70: If you show space between your fingers, you are confident of what you are saying.

Minute 72: Some tips on using body language with your children.

Happy interview listening!

Pauldotcom crew interview Brian Krebs - They talk about digital fraud

The pauldotcom crew interviews Brian Krebs in episode 219 (part 1) of their podcast. This is a post with learning points extracted from the interview.

Disclaimer: These lines do not substitute the listening of the interview. The statements mentioned are close to literal or slightly summarised or just a subjective interpretation. Kudos to the pauldotcom crew!

Minute 8: Brian's IT network was taken over by the lion worm.

Minute 10: People start in security because either they were hacked or they were hacking and decided to change sides and go to the more difficult defence.

Minute 14: He writes about topics that are news to him. This way, they will also be news to everybody else.

Minute 18: A lot of the bad guys have multiple identities in different fora. Most of them specialise on a specific topic and they outsource the rest. [...] They are somehow open since they need to be reachable by their clientele.

Minute 21: Outsourcing in cybercrime is a constant. Even testing services to assess outsourced tasks are outsourced.

Minute 24-26: Ukraine is one of the main sources of attacks, even more than Russia: very technically savvy individuals with very low payslips in legal jobs.

Minute 32: A lot of people buy spam-announced pharmaceutical products.

Minute 34: Their prescription runs out, suddenly they see those announcements and they buy them. The medicine seems to work and it is a third of the real price. However, there is no guarantee that the medicine has the same quality every time [also from minute 44].

Minute 36: Some of those cheap medicines are made in China or India.

Minute 37: Usually those sites ship a pack of "Viasgra" for free with any other order medicine requested. 

Minute 39-40: Rogue pharmacy is the driver of fraud on Internet nowadays. Although it is probably not the most lucrative business.

Minute 41: The most lucrative business in cybercrime is stealing from a corporate bank account through a piece of malware sent to someone in the organisation.

Minute 41: Changing your online banking credentials regularly is hardly done nowadays. This is why stolen credentials are still valid months after.

Minute 48: The gas station card skimmers is currently over the top as a real business. 

Minute 50: ATM skimming figures - average skimmer scam takes around USD 60000 (not confirmed figure).

Minute 52: Gift card fraud is huge. However, given the high margins gift cards have, sellers tolerate it.

Minute 66: We need to clearly explain to people the consequences of not caring about security.

Minute 67: (Unfortunately) Only life-threatening factors will make people security conscientious.

Minute 73: Brian Krebs is reachable for any anonymous security news anyone would like to share with the public.

Happy reading/listening!
Happy new year 2011!






Gray hat hacking: The ethical hacker's handbook - Book review

The following is a brief [and biased] review of the pages of Grey Hat Hacking (2nd edition - 2007). In one sentence, I would borrow the book from a library to read it. Alternatively, I would buy it, read it and sell it afterwards. 

Disclaimer: These lines do not substitute the reading of the book. They are meant to provide a global overview of what the reader can find in the book. My kudos to the authors, writing a book is always a big effort. And even a greater effort if the books talks about a changing target as IT security / software analysis. 


The book: Gray hat hacking: The ethical hacker's handbook.
The authors: Shon Harris, Allen Harper, Chris Eagle, Jonathan Ness .
Publication year:  2007 - Second edition.
Publisher: McGraw-Hill.



chapter 1 ethics of ethical hacking
A very generic chapter, useful to read across and set the global scene. If you need to justify work in IT security - well structured and referenced such for example page 10 - the origin of the word hacker and ethical hacker. Clear statements such as security does not like complexity [however, I would add, we live in a complex world].

chapter 2 ethical hacking and the legal system
A summary of US laws related to IT security, for example the US Federal computer crime statutes and some acts like:
18 USC 1029, 18 USC 1030, 18 USC 2510, 18 USC 2701, Digital Milenium Copyright Act and Cyber Security Enhancement Act.

chapter 3 proper and ethical disclosure
A helicopter overview about ethical disclosure. They mention the month of the PHP/Browser bugs, the story of Michael Lynn and CISCO and refer to the CERT/CC vulnerability disclosure process of 45 days. The Organisation for Internet Safety and the Zero Day Initiative (by Tipping Point, owned by 3Com).

chapter 4 metasploit
It is a nice approach to launch and to own a box by learning how to use metasploit. They provide a thorough description of the use of the console and auxiliary modules. They start with a simple example, an unpatched XP Service Pack 1 machine missing the RRAS security update, mentioning first the basic use of basic commands to start with:

show
info
use
help
show options
set RHOST ipaddress
show payloads
set PAYLOAD payload-name
show options
show targets
set TARGET 1
exploit
info
show auxiliary
use option
show options
sessions -l
sessions -i number

and - second, exploiting client-side (browsers, email apps, media players, client sw in general) vulnerabilities with metasploit

A useful hint, to return to the metasploit console prompt we can use ctrl-z.
I would also highlight a curious comment: they mention that this way you can attack workstations protected by a firewall

I find very interesting the description they provide of meterpreter, a command interpreter to inject payload into the memory of the exploited process.
Meterpreter has core commands, file system commands, networking commands, system commands, user interface commands, making ven possible to migrate from one process to another.

They conclude this chapter with the use of metasploit as a man in the middle password stealer, configuring metasploit as a malicious SMB server. They also touch briefly cain (the password stealing tool) and finally they briefly refer to the link with nmap or nessus with db_autopwn and provide a brief description of what is inside a metasploit module.

chapter 5 - using backtrack
They talk about backtrack2. This chapter shows us how quickly things happen in the security arena. Their point on the usefulness of isorecorder and how to make changes in the distribution and make them persistent is somehow now outdated.

Part 2 of the book is called pen testing and tools - This name is a little bit misleading.

chapter 6 programming survival skills
I took with me: the year 1972, when Dennis Ritchie invented C, that Intel processors are little endian and Motorola are big endian. And some memorty related concepts:

- bss section is the below the stack section - to store global non initialised variables - the size is fixed at runtime
- heap section - to store dynamically allocated variables, it grows from lower addressed memory to higher addressed memory allocation of memory is controlled through malloc() and free() functions
- stack - used to keep track of function calls and grows from higher addressed memory to lower addressed memory - local variables exist in stack section

[ I think there is a typo, a 5 should be an index variable in page 131]

I also read the ATT assembly is normally used in linux and NASM is used by many windows assemblers and debuggers.

The chapter ends with assembly and python. Python objects are data types such as strings, numbers, lists, dictionaries and files dictionaries are similar to lists but their objects are referenced by a key. I like the python part - easy and to the point

chapter 7 basic linux exploits
You can read that a stack is FILO and some points on the importance of address space layout randomisation. I also took with me that perl is interpreted [e.g. perl -e 'print "A" x 600'] and that python is an interpreted object oriented language.

They mention sticky bits and the fact that shell code is actually binary. They keep providing valuable input regarding the memory:

- environment and arguments are stored in an area above the stack
- eip poins to the next instruction to be executed
- in metasploit we can find locations of opcodes with msfelfscan

chapter 8 advanced linux exploits
This chapter shows how to calculate the locations to overwrite the heap with buffer overflow exploits. They show how these techniques require time and effort. They explore the Windows debugger - from page 250 - and some point in OllyDbg on page 255. Important point, OllyDBg only works in userspace. For kernel space, we need to use another debugger like WinDbg. The end briefly mentioning the metasploit opcode database.

chapter 9 shellcode strategies
This is a very verbose and theoretical chapter. They include the use of gdb (debugger) and gcc (compiler) and mention the important role of objdump to get the shellcode.

chapter 10 writing linux shellcode
Interesting tips, the use of nasm -f elf, ld -0 and I think there is a typo on page 231.

chapter 11 basic windows exploits
This chapter states that Linux and Windows are driven by the same assembly language. The Microsoft C/C++ optimizing compiler and linker is touched upon,
cl.exe, together with cdb, ntsd and windbg.

chapter 12 basic passive analysis
The text turns now to present source code audit tools such as ITS4, rats, flowfinder and plint and a decompiler for Java named Jreversepro, stressing the importance of checking all user supplied data.

Code analysis tools mentioned in this chapter are:

- IDA pro as a powerful disassembler
- hex-ray (an IDA pro plug-in) as a decompiler
- binnavi - a graph-based analysis and debugging tool- binary code reverse engineering tool that was built to assist vulnerability researchers who look for vulnerabilities in disassembled code

and some other tools like:
- bugspam (an IDA plugin)
- chevarista (a static analyser)
- bindiff (useful to compare binaries and patched binaries)

chapter 13 advanced static analysis with IDA Pro
This chapter shows us that stripping a binary means removing all symbol information. We can also read that to learn what dynamic libraries an executable depends on, we can use dumpbin in WIndows, ldd in Linux and otool in Mac OS X. Additionally, this chapter also mentions:
- the fast library acquisition for identification and recognition (flair)
- the use of pelf and sigmake
- how to perform a manual load of program headers
- IDA's scripting language, IDC
- IDA plug-ins
- and finally, a brief reference to pro loaders and processor modules

chapter 14 advanced reverse engineering
This chapter starts with a nice statement: stress testing for SW developers is what vulnerability researchers call fuzzing. The tools they propose to use are:
- debuggers like gdb
- code coverage tools like process stalker
- profiling tools
- flow analysis tools
- menory use monitoring tools like valgrind, a memory debugging and profiling system
- and finally, fuzzers like SPIKE

chapter 15 client side browser exploits
This chapter mentions the concept of spear phishing (APT or targeted attacks are now the trendy name). As fuzzing tools, they propose:
- mangleme from freshmeat.net
- axfuzz and axenum - to check appearances of install, writeregval, runcmd, gethostname, rebootmachine
- AxMan and Internetexploiter
As a little detail, they use something called the "mark of the web" to make Internet Explorer behave as if we would be browsing external Internet zones.

chapter 16 exploiting Windows access control model for local elevation of privileges
These pages talk about SIDs and Access Tokens, Access Control Entries, SYstem ACLs and discretionary ACL while using some of the not so popular sysinternals tools.

chapter 17 Intelligent fuzzing with Scully
This chapter refers to the importance of protocol analysis in effective fuzzing. For that, they porpose the use of the Sulley fuzzing framework.

chapter 18 from vulnerability to exploit
As the title indicates, this chapter refers to the steps necessary to construct payloads (and the need to find the eip, the instruction pointer).

chapter 19 closing the holes: mitigation
Three concepts are described and discussed in this chapter: patching, binary mutation and third party patching.

chapter 20 collecting malware and initial analysis
They talk about malware and honeypots, the possibilities to avoid VM detection and the usefulness of honeyd and nepenthest. Names of tools proposed in this chapter for malware analysis are PEiD, UPX, strings, regshot, filemon, process explorer, process monitor (they don't mention this one but I do, together with capturebat log viewer), norman sandbox and map (malcode analysis software tool) from idefense.

chapter 21 hacking malware
More content yet on unpacking using PEiD, LordPE, IDA and Olly plugins and additional content on malware analysis.

Happy grey hacking reading!