Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

24 April, 2018

Need for security-professionals in Norway

Yes, it's been an often-discussed topic in Norwegian media in later years:

"Lack of security-professionals."

Well, as commented in this (Norwegian) article, BY a security-professional; there seems to be a lack of security-oriented IT professionals, but, not because they aren't there at all. They are. What is seriously lacking in this scenario, is competence in recruiting firms looking for this kind of competence. Always has been.

Computer-security is not a fixed-set field, AT ALL. Even though a lot of so-called "professionals" seem to be stuck on the idea that it is.

Serious professionals wanting to work in this field on the other hand, are (often) painfully aware of what it actually entails to do so:

  • constant refreshing on networking- / computing- / vulnerability-security in IT
  • vulnerability-monitoring of often-used software in the company
  • a simple awareness of the fact that: nobody is ever 100% secure
Computer-security is a weight-battle; does the securing of something vulnerable affect normal operations? Or, is the fix / security-measure absolutely needed for normal operations? These are everyday obstacles a security-professional has to deal with on a regular basis, so they have to be quite flexible on expanding their knowledge-base, and often.

These points are often completely missed by recruiters. They don't look for ability / knowledge / flexibility, they often tend to only look at academic degrees (preferably multiple(!)), gender, published articles / blog-posts and other non-related (and often quite unrealistic) demands for the position(s) in question.

Then, they complain about not finding any candidates for their outrageous requirements.

Seriously, re-define your demands / requirements to a more realistic degree, maybe you'll find a competent person to do the job. But you most certainly will NOT find the dream-candidate with the kind of demands currently set as standard.

10 March, 2015

Fail2Ban

Fail2Ban works by scanning through log files and reacting to offending actions such as repeated failed login attempts, by using iptables to generate blocking-rules for any defined (listening) protocols / services, aimed at specific offending IP-addresses.

I used to utilize DenyHosts, but as the project was discontinued I had to adapt. And so I also had to retract all my recommendations of DenyHosts and update them all to endorse Fail2Ban instead.

If using Ubuntu or Linux Mint, setting up and using Fail2Ban is easy.

It comes pre-configured (on Ubuntu) to detect malicious SSH-activity with basic notification action,

Firstly, you just have to apt-get it:

sudo apt-get install fail2ban
Then, you just copy over the standard (Ubuntu) "skeleton"-config:
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
 Then stop and (re-)start Fail2Ban to load and run the config:
sudo service fail2ban stop && \
sudo service fail2ban start
It can be customized to send e-mail alerts to designated addresses, and various other "actions_".

Protocols and / or services are easily added to the config-file if they aren't already present. Fail2Bans config-file uses an easy syntax (layout-format) for somebody with basic networking- and logging-knowledge.

I tend to also enable the "ssh-ddos" detection, since these days we're seeing more and more distributed attacks. There are more SSH-specific detection's, but they're not necessary.

24 October, 2013

Digital Attack Map

A real-time overview of world-wide DDoS attacks :P

Digital Attack Map screencap, taken @ thursday Oct. 24 2013 - 2:48pm


Link:
http://www.digitalattackmap.com/#anim=1&color=0&country=ALL&time=16002&view=map

24 April, 2013

Funny comment :-P

This was a response to "Correct me if I'm wrong" posted by an irrate Linux FUD-er. ( http://www.zdnet.com/six-open-source-security-myths-debunked-and-eight-real-challenges-to-consider-7000014225/ )


You're wrong and probably never worked for a software company.

I've been through this a couple times before, but I'll describe it again.

Software versions are charactized by version numbers, in my case, when I worked for Bentley Systems, a version was designated by numbers like 05.07.01.22.

Software, like Firefox makes versions for Windows and Linux among others. Basically the core parts of the program operate in the same manner and the API is different to work on Linux and adjustments are made for libraries, directories, etc.

The dirty little secret here at ZDNet and among the shills is that they blame an application for allowing an intrinsic problem or vulnerability with the OS to be accessed. Shills, Ed, and ZDNet are great at blaming the application, such as Chrome or Firefox for the problem and not addressing the core Windows vulnerability. Then, they read documentation and without knowing anything about how things are done, blame the Linux counterparts, because they are listed.

The problem is that items present in the application allow the core Windows vulnerability to be used to infect Windows. The application issue may also be present in the Linux version, but because Linux is so much more secure than Windows, there is no problem or infection with Linux. The only way Linux could be infected is if the malware could read the mind of the user and get his password.

Developers review the Windows version issue and make adjustments so it does not allow the Windows vulnerability to be addressed and also make the change across the board to all sister versions to maintain consistency. Because you are naive and see Ubuntu listed as affected, it does not mean Ubuntu ever had a security issue at all, the Ubuntu version is just having the code changed for consistency. In other words, no application for Windows is ever going to fully prevent all the Windows critical flaws from being accessed. Those application characteristics causing the Windows issues may be present the Linux version, but can't be used to attack Linux, but are being changed anyway. In most cases, the change may be an operating improvement and be more efficient.

It's so silly to ZDNet pull the same BS over and over again, year after year. If you want to believe it, you are only following the ZDNet propaganda trail, Do yourself a favor, pour yourself a strong one, and install Ubuntu or Mint on a second machine, run it as a Live DVD, or install it as a dual boot and your primary computer. Then, install, Chrome, Opera or any other open source program you like and try to get infected. Then come back here and post the Website and how you got infected. That's something that no one, in all these years of accusations has ever been able to do. Once you see that you don't get infected you;ll begin to see how ZDNet twists information and is just a stooge for Microsoft.

As far as you referencing Linux Torvalds and the linux.com issue it was related to stolen passwords. Anyone who gets poorly secured passwords an attacks a system can't be stopped. Most times the admins are storing their login information on a Windows box, that gets easily hacked by a zero-day or a crafted emai that allows access. Remember the big ZDNet push for articles about Google, which runs 100% Linux getting hacked? Well, two Chinese employees were storing data on a Windows notebook and it easily got hacked. Since then, Google forbids employees from using Windows or work. you don't hear about that anymore here, do you? Forbidding employees to do company work on Windows is the single most important any manager can make.

If you dig deeply into these articles against open source and Linux, you will find, as I have, that the core problem is Windows and you will see a critical update down the road, at a later time to silently correct the Windows problem. But that is never brought up here.
anonymous
  • Prove that Linux gets hacked. It's something never done here.

    If you feel that strongly about it, post how and where you got hacked. I'm waiting.
    anonymous

    Test the theory yourself

    Get a box and harden Windows, use ANY anti-malware you like.
    Get a box and install any Linux distro, any of them, pick the weakest one you can think of.

    Go look at any web site you like with Firefox, Opera or Chrome on both ... NO IE (not supported on Linux).

    (hint: adult content and gaming sites that are 2nd or 3rd tier are reportedly famous for infections), try google searching "most dangerous web sites".

    The rules of the game are:

    * only following links or using the back button icon of the browser are allowed
    * if windows pop up you are not allowed to touch them anywhere (including the X to close).
    * if the back button is not usable or the browser is non-responsive, close the browser with task manager.

    The object is to visit infected sites and return without touching anything.

    See which system is left running after 1 hour.

    Please report your results HONESTLY.


    * ( ... no clicking (X)
    * If the browser locks up ... use the "task manager" to kill it.

    BrentRBrian

03 November, 2009

Android vs iPhone OS patching

I just finished reading the changelog for iPhone OS 3.0 on the Apple support-pages, and after reading the Google Android changelog from my recent Magic-update, Apple does not impress me that much anymore.


iPhone OS 3.0 (rls. june'09) had 38(!) vulnerabilities, many of them quite critical, whilst Android had a grand total of 2 vulnerabilities (critical announced ones that I can find online), which were even spread across 2 update-intervals 3 months apart...

1 of the vulnerabilities in Android involved applications having CAMERA-privileges without the user explicitly allowing it, and the other one involved maliciously crafted sms-messages that could reboot the device.

Most of the 38 counted vulnerabilities on the iPhone were critical. Involving post-actions ranging from a device-reset, to arbitrary code execution. What made me re-act was where in the system the bugs resided, which was just about everywhere!

The following sub-systems on iPhone OS 3.0 had vulnerabilities announced on the changelog: CoreGraphics, WebKit, ImageIO, IC for Unicode, IPSec, libxml, Mail, MPEG-4 Codec, Profile, Safari, Telephony, Exchange.

I'm really, REALLY glad I chose a device running an independantly developed open platform :) instead of a closed-source license-hog of a proprietary mobile overkill-system :P

Link:

12 October, 2009

Apple Inc.: "you're safe with us"


Herregud, seriøst? Det er nå avdekket en kritisk(!) feil i Mac OS X, som visstnok har vært der lenge. Apple har ikke kommet med hverken kommentarer, eller gitt noen klare svar på om det kommer noen fiks for problemet i nærmeste fremtid.

Slike feil hadde jeg ikke forventet av Microsoft engang, heller ikke at det skulle gå dagevis siden feilen ble avdekket til den ble lappet over...

Feilen ligger i det å logge seg inn på gjeste-kontoen i Mac OS X. Når en da logger seg inn på sin egen vanlige bruker i ettertid, skal mappen (/Users/"ditt-brukernavn") fortsatt være der, men er skåltom...

Det er liksom ikke helt uten grunn at jeg sier til folk at de må ta sikkerhetskopi av dataene deres tidt og ofte...

Så, Mac-folk, FFS:
TA BACKUP FOR DATAENES SKYLD!

Denne forhåndsregelen bør håndheves av ALLE databrukere, uavhengig av hvilket operativ system eller maskinvare som brukes!

21 August, 2009

NULL pointer dereference in Linux kernel

Lately there has been a lot of talk about the newly discovered (but 8 years old) bug in the 2.x Linux kernel series.

Personally, I always research such claims before going into an admin-panic, and surely enough, it paid off this time as well as before. Seems the exploits have to be executed in full user-space with at least standard shell-access. To me, local exploits are not that worrysome, because I'm the only one really using my Linux-machines physically, and the few users that DO have shell-access on them, are mostly friendly superusers with no ill intent what-so-ever.

One server is connected directly to my ISP-protected NAT access-ring, and configured with a reasonably (but strictly) secured firewall, it provides public web-services. This machine has not posed any problems, not with implementation nor security. It runs all-vanilla software and configurations.

My other server is placed in an internal LAN, 2 firewall-rings further in from the public machine, protected by a linux-based router-gateway with no public shell-access (so, no severe security risks so far). This internal LAN sever provides a webapp-database only reachable by the public machine for web-serving purposes, Windows file-sharing only accessible by the internal LAN and a mediaserver only accessible by my PlayStation3 system.

I'm not in a hurry to patch/upgrade any of them right off the bat, I'll do it when I have time...

Links:

29 April, 2009

Alle får!




Bra, lille Ballmer! Endelig litt fornuft fra Microsoft's side, vel, dette var allerede annonsert tidligere, men da ble det ikke sagt sort-på-hvitt at "alle får", men det ser ut som det er nettopp det som skjer nå.
Alle får!
Hvem får sikkerhetsoppdateringer? Det er et spørsmål Microsoft får oftere enn de hadde regnet med. Kanskje grunnet piratkopierings-sperrene i Windows XP og Vista.
Skal nettsikkerheten ivaretas for alle, må også alle være sikret. Dette er i alle fall et steg i riktig retning.

Levner ingen tvil
«Det ser ut til å være en myte at Microsoft holder tilbake Windows sikkerhetsoppdateringer og leverer dem kun til de som er eiere av ekte Windows. La meg være klar: alle sikkerhetsoppdateringer leveres til alle brukere» skriver selskapet på The Windows Blog.
Får håpe det fortsetter.

Men bare for å legge alles oppmerksomhet litt opp på G, så sies det i "The Windows Blog"-innlegget hvor dette legges frem, at ikke ALLE oppdateringer fra Windows Update sendes ut til alle brukere (uavhengig om de er genuine brukere eller pirater, noe jeg mener er lite trolig allikevel med tanke på hvem vi snakker om her) "fordi det kan dreie seg om ekstra-produkter innenfor Microsofts varesortiment" (les: pirat-kopierte enkelt-programmer).

System-oppdateringer sendes allikevel ut til alle, men det mener jeg er mer fordi pirat-maskiner ikke skal knele genuine brukeres nett-opplevelser, enn at "alle skal sikres best mulig".

Microsoft ser seg nok tvunget til å gi alle system-oppdateringer, men ikke å bevare bruker-opplevelsen til ikke-genuine brukere fordi "de ikke har bruker-rettigheter på gjeldende produkt" (sett ut ifra et juridisk standpunkt), så det er rett og slett mer en "fiks" for å garantere genuine brukeres rettigheter enn at pirat-brukere også skal ivaretas sikkerhetsmessig.


N.B.! Dette innlegget er IKKE ment som hets mot Microsoft. Jeg er en åpen tilhenger av OSS (Open Source Software), men jeg jobber til daglig med Microsoft-teknologi, og har årevis med erfaring med deres produkter, faktisk helt siden MS-DOS v4.

21 April, 2009

Computer illiterates are dangerous!


On Friday, EFF and the law firm of Fish and Richardson filed an emergency motion to quash and for the return of seized property on behalf of a Boston College computer science student whose computers, cell phone, and other property were seized as part of an investigation into who sent an e-mail to a school mailing list identifying another student as gay. The problem? Not only is there no indication that any crime was committed, the investigating officer argued that the computer expertise of the student itself supported a finding of probable cause to seize the student's property.

The whole problem started because the computer science student was using a command-line interface, of which the arresting officer did not understand. Quotes from the arresting officer's report say:
"Mr.Carlixte uses two different operating systems to hide his illegal activities. One is the regular B.C. operating system and the other is a black screen with white font which he uses prompts on"

I mean.., c'mon! Seriously!? Are all computer hobbyists to be considered "crackers" until proven otherwise? FFS!!!

OS X utsatt for botnet-orm



Nå er det i hvert fall ikke trygt å bruke Mac lenger...

Mac / Apple har siden 70-tallet vært trendsetter på data-markedet, så det var ikke et spørsmål om "hvordan" eller "hvis", men "når". Visste det bare var et tidsspørsmål. Og det har jeg sagt lenge, så lenge det finnes en merkbar markedsandel med folk som bruker visse typer systemer, vil disse da bli mål for cyber-kriminelle (crackere).

Botnets har lenge vært et problem med Windows-maskiner. Mac-folket har lenge ment at noe tilsvarende ikke kan skje med deres maskiner. Dels fordi de er en minoritet få virusmakere gidder å bry seg med, og dels på grunn av at Apples operativsystem OS X er bygget på Unix - en plattform som av mange regnes som sikrere enn Microsofts.


En nedlastbar fiks fra Apple, kalt "iWorksServices Trojan Removal Tool", kan hentes ned herfra.

For å videre beskytte Mac- / Apple-maskiner fra slike trusler, bør en installere anti-virus og evt. anti-spionvare programmer (og her gjelder KISS-prinsippet, mer enn ETT anti-virus eller anti-spionvare program på samme maskin byr på mer problemer enn nytte).

14 April, 2009

"GhostNet" linked to the "Waledac" botnet

Conficker.C-infected computers have shown activity recently, according to security analysts and software/network engineers, so it seems the threat is not over...yet.

It's main activities (identified activities, that is), are:
  • downloading (malware from other botnets, mainly the spammer-botnet "Waledac", better known as the re-animated Storm DeadNet "Valentines e-mail spammer botnet")
  • linking (assumably to other malicious botnets)
  • communicating (assumably with it's creators).

It is also reported to flash rogue anti-viral software ads directed at users of these infected machines.

Darknet.co.uk had this article to explain (excerpt from article below):

“Fear is used, universally, as a means to control people,” said Sendio CTO Tal Golan. “Governments use it. Large businesses use it. So it should come as no surprise to anyone that ‘cyber-bad guys’ use it.”

At the moment, the rogue anti-virus software comes from sites located in the Ukraine (131-3.elaninet.com.78.26.179.107) although the worm is downloading it from other sites, according to Kaspersky Lab.



Hmm. No, not surprising at all if you ask me.

31 March, 2009

The "Conficker.C"-hype

I've read like tenfolds of articles both international and national about the suspected D-day, April 1st 2009. It is rumored that over 10 million computers will release a tidal-wave of DDoS-attacks on a global scale...

However, if you secured your home-setup earlier/today (like I have), you SHOULD be safe, for the time being...

Time will show.

But... to give you an idea about HOW malicious this worm is, Microsoft has promised a $250.000 reward for anyone able to provide information about it's creator(s). So, it's a serious issue.
Or...is it? ;P (April 1st 2009?? C'mon...)





For mine norske lesere, her er en ganske detaljert artikkel om "problemet": http://www.dagbladet.no/2009/03/31/kultur/tekno/internett/virus/5549841/

For å utfylle litt mer ut ifra det engelske innlegget ovenfor:
Er du sikret mot Botnets, som f.eks. ved å bruke OpenDNS istedenfor en lokal navnetjener (router, gateway, e.l. som cacher navnespørringer lokalt, utgjør en sikkerhetsrisiko på IP addressering mot Internett), så er du rimelig sikret i tilfelle noe av dette finner sted. Lite trolig, siden det dreier seg om 1. april...


30 March, 2009

E-warfare

The time has come...


Fellow IT crowd: electronic espionage and malicious takeovers are upon us.

The following article-link takes up the subject about cyber espionage on a global scale: http://www.scribd.com/doc/13731776/Tracking-GhostNet-Investigating-a-Cyber-Espionage-Network
A 10-month investigation uncovered what seems to be a Chinese cyber-spy network crossing the globe. Further investigation through fieldwork, technical scouting and laboratory testing uncovered that the "GhostNet" can consist of as many as 1.295 individual computers residing in 103 countries. At least 30% of these can be considered high-value political, diplomatic, economic and military targets.
Some malicious crackers are surely having fun harvesting quite the bot-farm I must say...

And if the technical advisors are right, the Chinese can do ALOT more damage than just steal sensitive information.

We are now living the nightmare a lot of sci-fi literature predicted years ago...

Ph34r!

I'm not saying this affects everyday people at the moment.., but it's a wake-up call to remind us that we're not totally 100% secure online, what-so-ever...

16 March, 2009

På tide ordensmakten tar steget...



Vekk med Windows! - digi.no : Kommentarer
Diskusjonen går høyt om Mac OS og Linux er tryggere enn Windows, teknisk sett. Konklusjonen synes å være at ja, begge de to alternative operativsystemene er mer robust konstruert enn Microsofts markedsledende system. Men selv om det kan stilles spørsmålstegn ved dette (og det gjør Microsoft, selvsagt), så er det et faktum at systemer som få bruker ikke er så utsatt for virusmakerne som systemer som brukes av en minoritet.

13 March, 2009

SERIØST...!?



Herregud folkens, dette er for dårlig når vi har de ressursene og mulighetene vi råder over i vårt fagre land!
>;/

Først Kripos, så Politiet, tollen... Hva skjer videre? Skal nasjonsviktige institusjoner bare falle som fluer i grusen?

"Hvordan skal normale individer kunne beskytte seg på nett når store offentlige organisasjoner ikke klarer dette?"

Vel, for det første hadde det kanskje vært lurt å sende ansatte på IT-kurs, evt. personverns-veiledning og sist men ikke minst; grunnleggende anti-virus og spionvare opplæring...

Eller.., hva med å FAKTISK BRUKE FINANSIERING PÅ DATASIKKERHET!? Rutiner er IKKE alfa-omega, men hjelper på med godt uttenkte retningslinjer og verktøy.

http://www.digi.no/807565/conficker-skapte-kaos-for-politiet

http://www.digi.no/807455/politiet-er-lammet-av-virus

19 February, 2009

ARCFOUR (RC4)

RC4 is a stream cipher designed in RSA laboratories by Ron Rivest in 1987. This cipher is widely used in commercial applications including Oracle SQL, Microsoft Windows and the SSL. The algorithm was kept as a trade secret until the mid-1990's.

The external analysis of RC4 was invoked by the leakage of its source code in 1994 to cypherpunks mailing list.

The key stream generated by RC4 is a stream of pseudo-random bytes.

This is the first in a series of posts about cryptography/security.
I won't delve far too deep into details, but I'm very interested in the specific protocol algorithms used.

P.S.: RC4 is reputedly an acronym for "Ron's Code 4"

28 January, 2009

Var jo bare et tidsspørsmål...



"IT-eksperter går til nettverkskrig"


"Klart for 'offisielle' ID-kort"
'Er vi villig til å betale 340 kroner for et kort som skal hjelpe det offentlige til mindre tap og mer effektive tjenester?'

26 August, 2008

Finally, a decent HIDS for Win32!

OSSEC has finally been aqcuired by a software-company with enough resources to boost development towards a windows-client as well as a linux-client.

I installed the win32-client on my office workstation, and it is working like a charm. Active Responses are working, I'm getting the notifications I set-up manually and the agent-manager made administration quite easy.

So I can say I'm very pleased that Canada-based software-company ThirdBrigade aqcuisitioned OSSEC HIDS as a security product
. And even more so because they promised to continue with the open-source development and distribution of it under the GPL.

http://www.ossec.net/

15 March, 2008

Security focus: Securing Linux

Security focus published two articles on securing Linux systems. But the cool bit, is that they refer a lot to my favourite distribution, coincidence? ;P (Got Slack?)



(Originally written in 2000, these articles sadly address quite a lot of deprecated security issues, but a few are still applicable.) But still, after several years, the biggest real threat seems to be brute-forcing techniques. It just changes modus operandi, and counter-measures are following quickly. To be more specific, de-centralized criminal hacker behaviour is beginning to be a major issue online, mainly because of the many homes that have 24/7 broadband connections, giving the blackhats more reliable inter-connected botnets to 'play' with...

09 March, 2008

SSH, domains, crypto...

Finally, I've acquired a location to set up a desktop computer as a domain-gateway for my personal LAN/WAN/WiFi-connections! Sw33t! My earlier conclusion to carry an USB memory dongle was a good idea. I got so many notifications about brute-force attack-attempts running SSH-blockage rules on my firewall, so I decided to drop them all together.


Using private-key authentication with a passphrase, proved to be MUCH better. Nearly any excessive bandwidth-overhead, nor serious lagging (which was the main problems when running SSH firewall rules for brute-force attack tracking and blocking. It was basically too CPU intensive to be useful).

Regarding the key-authentication, both the generation of keys, and re-configuring of the SSH server to accept the keys was pretty straightforward. So now I'm enjoying fully secured SSHv2 sessions.

But again, I decided against utilizing some parts of my plans, like using 256bit
AES cipher, instead of the intended 448bit Blowfish cipher, as it would be overkill with regards to the processing power available on the desktop machine I'm going to use ;P (Pentium-III 1st gen. 800Mhz). From what I know, Norwegian government-sections use 256bit AES, so it will more than suffice for my uses. Less is more.

I also set up a basic, free static hostname (with wildcards) to reach my public gateway-machine, and a secondary hostname for dynamic http-forwarding to the web-server hosted on the domain.

Good luck to the ones wanting to crack these streams! ;D