Category: Security Awareness

  • 6 Dumbest Ideas in Computer Security – Revisited

    Markus Ranum’s popular “6 Dumbest Ideas in Computer Security” is apparently accepted by many. I agree with a couple of his points, but have serious issues on the others.

    Here is what Mark had to say in a nutshell:

    1) Default Permit –

    Allow everything except bad processes and/or users.

    I Agree.

    There is a lot of this going around and it is dumb. And I say its dumb in total humility, we all do dumb things from time to time. With Windows XP service pack 2, which is basically a firewall implemented on top of the OS and though it is not perfect, I believe that more people are beginning to see the importance of DENY ALL.

    2) Enumerating Badness

    Listing a concentrating on the thousands of malware as opposed to concentrating on accounting for the legitimate software and getting rid of the rest. It’s a ploy by the man to keep security corporations afloat.

    I Agree and Disagree with this.

    I agree that it is important to have accountability for what is going great on your system and running as it should. You should know and maintain your “known good” baseline configuration. But it is like protecting your home. Shouldn’t you know what recent rash of crimes are going on in your neighborhood?

    Shouldn’t you keep note of those crimes and have a method or practice of protecting yourself. Although it is impractical to seek out every possible type of attack a criminal will use against your home, you should at least have protection against the MOST LIKELY methods that might be used against your home. I believe that being aware of some of the most possible known threats to your system and taking action is like personal insurance.

    3) Penetrate and Patch –

    Systems should be designed better so they don’t have to be patched.

    WTF (What the f*#@!!)

    Of course systems should be designed better… and humans should be designed so that we don’t go to war! And there shouldn’t be hunger anywhere on planet earth. Could have, Should have, would have. In a perfect world, I.E. WOULD HAVE been ABORTED. But Internet Explorer was released to all and controlled 95% of the browser for years. Mark, there are systems that need patches. Security isn’t just proactive its reactive. I understand and agree with what you are saying but in the real world millions of people by millions of badly designed and even hazardous products.

    4) Hacking is Cool

    Mark insists that saying “hacking is cool” or having popular series of “hack” books (i.e. Google Hacks, Mind Hacks) is glorifying criminals.

    I Strongly Disagree.

    This is yet another example of someone ignorant of what hacking actually is.

    I’ve had numerous arguments about this. I don’t care what you say Mark (or anyone else) hacking is and always will be cool. NO!… I don’t believe CRIME is not cool. Hackers are not always criminals. You would have to go to the Defcon to realize this. But Mark seems like the type that would look down his nose at Defcon and everyone there. Many of the vulnerabilities that are discovered before criminals exploit them are discovered by gray hats, hackers who actively or accidentally discover security holes. Many times these gray hats actually warn the companies and are told to sit down and shut.

    Even if you did believe that every hacker is a criminal and ALL hacking is a crime, would it not make sense to know your enemy and what he/she does? Criminal Profilers must not only know the tactics of criminals they have to UNDERSTAND them. I was a cop for five years. In my experience, the best cops & investigators understood not only how and why people commit crimes but also how they try and get out of it.

    Mark calls hacking “social problem.”

    Even TLC (the learning channels) does not take this stance on hacking. Check out their list of the famous & Infamous hackers.

    Hackers included on the TLC page:

    Steve Wozniak (co-founder of Apple)

    Richard Stallman (creator of GNU)

    Dennis Ritchie/Ken Thompson (created UNIX)

    TSutomu Shimomura (caught Kevin Mitnick)

    Linus Torvalds (creator of Linux)

     

    This is a good definition of what a hacker is:

    http://en.wikipedia.org/wiki/Hacker#History

    Most Information Security professionals (or those claiming to be) either completely understand what “hacking” is or do not understand it at all.

    5) Educating Users

    Users should be kept dumb.

    I disagree.

    Social Engineering is the best example of what happens when your users are blind. The biggest threat to any system is the people using them. Kevin Mitnick said, “There is no patch for stupidity.” Really funny, but I disagree the patch is Security Awareness. Check out what the folks at Security Awareness for MA PA and the Corporate clueless blog had to say. 

              6) Action is Better Than Inaction

    It really is easier to not do something dumb than it is to do something smart.

    I agree. Very well put.

     

    I would also add a seventh, brought up by Par Kris Buytaert at x-tend.be:

    7) Security Can be sold in a Box

             Everyone wants a push button solution to all their security issues.  The truth is that it does not exist.  The only way to beat the game is stay ahead of it.  That is not to say everyone should be security geeks, but they should have some understanding of spyware, malware and other filth (that is if they value there accounts, privacy and data).

     

    Over all, I feel that article has a lot to give to computer security community.  Its great that there are professionals that put that much thought on what they feel  is right.

     

     

  • First potential virus risk for Windows Vista found

    “Virus writers are targeting a new Microsoft tool that will be part
    of Windows and is set to ship as part of the next Exchange e-mail
    server release.” – C|Net

    F-Secure has already found a possible flaw in the Windows Vista
    (code named Longhorn) command Shell called Monad also know as MSH.

    Representatives of F-Secure stated that if Microsoft released Windows
    Vista with MSH enabled, it could cause and outbreak of scripting
    viruses.  Examples of Scripting viruses include Macrovirues, the
    ILOVEYou VB scripting virus and the Melissa virus.

    The exploit aiming at MSH is discussed here.

    Microsoft my chose to disable MSH by default or simply add it as a plugin. 

  • The ISSEP: Information System Security Engineering Professional (ISSEP) certification

     

    I've been thinking of taking the Information System Security Engineering Professional (ISSEP) certification.  Since the CISSP info is still fresh in my mind and much of the ISSEP are things I do or have to deal with daily it seems like a good idea. 

    What is the ISSEP?
    The ISSEP was developed by the International Information System Security Certification Consortium (ISC)2 in conjuction with the National Security Agency/IAD. Where as the CISSP is an all encompassing general look at security, the ISSEP is a concentration on system security engineering process.  System security engineering has to do with ensuring that selected solutions
    meet the mission or business security needs.  It is defined as “the art of and science of discovering users security needs, and designing and making with economy and elegance information
    systems so that they can safely resist the forces they might be subjected to.”

    System Security Engineers tasks:
      Discover Information Protection Needs
      Define system Security Requirements
      Design System Security Architectures
      Develop Detailed Security Design
      Implement System Security
      Assess Information Protection Effectiveness

    Instead of ten Domains the ISSEP has four:
      System Security Engineering
      Certification and Accreditation
      Technical Managment
      U.S. Government Information Assurance Regulations 

    Most of of the ISSEP's material comes from the Information Assurance Technical Framework (IATF). 

    My co-worker recently took the test and he said it was more difficult than the CISSP.  The CISSP is easily THE most difficult test I've every done.  Although, since most of the information comes from the IATF, I'm not sure how it could be more difficult.
    The CISSP is so broad that you could not possibly get all the information from a single source.

    http://www.acsac.org/2003/case/thu-c-1530-Oren.pdf
    www.nsa.gov
    www.isc2.org

     

  • CISCO LEAP (lightweight Extensible Authentication Protocol) Weak?

    Light weight EAP is Cisco's proprietary version of Extensible Authentication Protocol (EAP, used mainly for wireless LANs).  Cisco graciously allowed vendors to support LEAP using Cisco Certified Extenstion (CCX). 

    Cisco owns about 60% of the wireless market with 46% of those using Light Weight Extensible Authentication Protocol according to the research group nemertes. 

    HAZZAAA!! Cisco is secure…

    (except against Dictionary Attacks)

    With such a large piece of the wireless market using LEAP, Cisco had sucessfully advertised LEAP as a secure protocol.  Unfortunately, LEAP is weak against Dictionary Attacks (Brewin).

    At DEFCON 11, on August 1, 2003, Joshua Wright did a presentation on the weakness of LEAP

     

    Here is Cisco's response to Leap Dictionary attacks:

    To help our customers respond to the possibility of dictionary attacks, Cisco strongly recommends that all of our customers to review their security policies and institute the previously published best practices that are outlined below and in the Cisco SAFE White Papers.

    Use a strong password policy (as detailed below) and periodically expire user passwords (recommended at least every three months) giving users advanced warning to change passwords before they expire.

    If unable to implement a strong password policy, consider migrating to another EAP type like EAP-FAST, PEAP or EAP-TLS whose authentication methods are not susceptible to dictionary attacks:

    EAP-FAST is an authentication protocol that creates a secure tunnel without using certificates.

    PEAP is a hybrid authentication protocol that creates a secured TLS tunnel between the WLAN user and the RADIUS server to authenticate the user to the network.

    EAP-TLS uses pre-issued digital certificates to authenticate a user to the network.

     

    FINAL NOTE:

    “1 month of audits by l33t security companies: No vulnerabilities
    1 month of architecture research by CCIE's: No vulnerabilities
    2 days of hacking by DaBubble, Bishop, and Evol: Root.
    There's some things that fackers should audit (WEBAPPS) for everything else, get a real hacker.” — SecurityFocus

    Why doesn't Cisco become more hacker friendly.  They pissed off the Security Profesionals and Hackers alike with that CiscoGate fiasco, don't have any cool hacker parties at the Defcon.. I mean what is the deal, John Chambers?! 

    John, I doubt you will ever read this blog, but here goes anyway, I think that Cisco has great products.  I believe in Cisco's amazing engineering, but if you guys don't aggressively attack security issues PROACTIVELY, you will drop from first class to third class quickly.  I'm not trying to tell you how to run cisco, I'm just saying, why not use hackers and their finding to your advantage. 

    Take the IE browser as an example: they used to own 95% of the market, consumners got so fed up with its lack of security that now Firefox (co-created by Blake Ross Intern/Hacker) is doing something not even Netscape could do.  

     

    Reference:

    EAP. RFC 2284. Extensible Authentication Protocol.

    EAP, Extensible Authentication Protocol Wiki. Wikipedia.org

    George C. Ou. Leap: A looming disaster in Enterprise Wireless LANs.  Lanarchitecture.net

    nemertes, Cisco Warns its WLAN Security can be Cracked. nemertes.com

    Brewin, Bob. Cisco Warn its WLAN Security can be Cracked. computerworld.com

    Cisco, Abusing 802.11: Weaknesses in LEAP Challenge/Response. Defcon 11/2003

    Cisco. Cisco Response to Dictionary Attacks on Cisco Leap.

  • Good Password Tips and Password Management

    These days a single computer user may have dozens of passwords. If you use computers at your job you may need to access secured databases, local workstations and numerous accounts online and each is supposed to have its own unique password. Though many people don't require a logon for their home PC, they will definitely have one for email or websites that they manage. Here is a guide to assist you in strengthening your passwords and password techniques.

    After reading this article you will know the following:
    -How to make good passwords
    -Good password practices
    -Techniques to manage all of your passwords

    How to Make Good Passwords

    Choose a password with the following criteria:
    -At least 8 characters in length
    -At least 1 number
    -At least 1 special character
    -Upper and lowercase.

    Passwords with difficult combinations make it harder for tools like L0phtcrack, Brutus, John the Ripper, Cain and Able and other password crackers to decipher your password.

    When creating a password, don't use personal information such as birthdays, children names, or first and last names. Avoid using words or phrases that can be easily guess or cracked with a “dictionary attack.” Do not use the same password on the different systems. If you work in a classified environment, passwords should be treated at the same level of classification as the systems they protect.

    Good password practices

    Never share your password with ANYONE including your Administrators, Help Desk personnel or System Administrators. IT professionals at your job or Internet Service Provider (ISP) will not normally ask you for your password. If they do need it then you should give it to them in person and ensure you change it as soon as they are done with their task. A common “Social Engineering” tactic used by malicious hackers consists of calling up unsuspecting users and pretending to be from the computer support staff. Another tactic is to have trusting users email the password or type it into what looks like a legitimate site; this is known as “phishing.”

    Be aware of your surrounding when you are typing your password. Watch for “shoulder Surfing” or people watching what you type as you are entering your password. If you use the web to access critical information (such as online banking, or medical information) ensure that the site uses some type of secured method of encryption. You will know this if the site's URL begins with an “https.” SSL and Secure HTTP are sometimes indicated by a tiny lock in a corner of the page. If there is no encryption then it maybe possible for unauthorized users to view and/or capture the data you enter and later access the account using a “sniffer.” A sniffer is a tool that captures all “clear text” or unencrypted data. SSL and Secure HTTP encrypts data so that it looks like gibberish to tools like sniffers.

    Techniques to manage all of your passwords

    It is best to memorize your passwords however if you have literally scores of passwords from work, home, online business ventures and the bank and you do not have a photographic memory, you may want to write them down and put it in your wallet. This simple and practical task is what author of Beyond Fear, and system security phenomenon, Bruce Schneier, recommends as does Senior Programmer for Security Policy at Microsoft, Jesper Johannson.

    Using Password Management applications such as Password Safe, a free Microsoft application for storing passwords, and Password Vault (also free) can help you to effectively manage your passwords.

    Another management technique is to allow Windows (and other Operating Systems) to automatically fill in the data. This is great for trusted SECURE environments such as home systems in which you don not need to hide any account information from anyone, but not such a good idea for the work environment. It should also be noted that systems without a high level of Internet security (protected with firewalls, updated patches, NAT enabled, etc) should not use the auto fill features as the passwords are many times stored on the system in clear text making it easy for malicious code such as spyware, trojans and worms to steal your passwords and account information.

    The greatest thing you can do to protect your password is to be aware that at every moment someone somewhere would love to access some or all of your accounts. It is not always cyber criminals looking for you banking information, sometimes it is just curious people who happen upon your username & password. It may even be someone you know. Be aware.

     

    Other ways to protect your passwords:

    .htaccess

    PasswordSafe

    Online Password Generators:

    http://www.winguides.com/security/password.php

    http://www.goodpassword.com/

     

     

  • Defcon's Infamous Wall of Sheep

    One of my favorite traditions at the Defcon is the “Wall of
    Sheep.”  It displays all the “sheeple” that have not secured there
    systems yet feel compelled to get on the Defcons Wi-Fi. 
    During Defcon 11 one guy was there doing his
    taxes!!  Needless to say he was tripped naked and paraded
    around the conference like an apple stuffed Luau Pig.  At least
    they didn't display his Tax ID.       

    Take K. Rose's advice… If you're going to Defcon, don't turn on your laptop.

    read more | digg story

  • Security Awareness Toolbox

    The Information Warfare Site (IWar) is a great resource for Security Awareness. Iwar's Security Awareness Toolbox is an excellent page packed with enough Security Awareness content to make you sick of it.

    read more | digg story

  • ISO 27001: Information Security Management

    WHAT IS ISO 27001?

    The ISO 27001 is the replacement for BS7799. It supplements the ISO 17799.

    The BS7799 is the requirements for an Information Security Management System. The BS7799 is a framework for
    the management of information security.  It is used to for the controls described within ISO 17799 may be selected. 

    Management standards such as ISO 9001 is streamlined with the new 27001 and the PDCA model (Plan-Do-Check-Act) as well as 17799 which will eventually be renumbers to 27002.

    More on the 27002: http://www.standards-online.net/InformationSecurityStandard.htm

    More on 17799:http://www.17799.com

    http://17799-news.the-hamster.com

    More on 27001: http://www.27001-online.com

  • Network Vulnerability tool: AutoScan is a utility for network exploration

    AutoScan is a utility for network exploration.

    I used AutoScan on my home network and found out that my Router has Linux on it.  For my customer's enclave I used Autoscan to quickly locate vulnerabilities.

    Although the network is small the scan was usefull since it has given me a good idea what affect AutoScan will have on my customers larger newtork with more valuable assets and a potentially larger number of risks.

    AutoScan did not alter my customers work as it instantly picked up workstations, internetworking devices and printers.  The built in nmap scripts adds a very nice touch. 

    If you're a mobile White Hat on the go like me, autoscan within the WHAX live CD is a great security tool to add to your “batbelt.”

    The objective of the program is to post the list of all equipment connected to the network. A list of ports preset is scanned for each equipment. You can find many more vulnerability tools with tags at Technorati & Del.icio.us:
    http://del.icio.us/tag/vulnerability+assessment

    read more | digg story

  • "Spies Among Us", Ira Winkler (Rob Slade book review)

    The following is a review by Robert Slade.  Robert Slade is a data communications and security specialist and author of Robert Slade's Guide to Computer Viruses: How to Avoid Them, How to Get Rid of Them, and How to Get Help

    REVIEW: “Spies Among Us”, Ira Winkler  

    by Rob Slade

    “Spies Among Us”, Ira Winkler 2005, 0-7645-8468-5, U$27.50/C$38.99/UK#16.99 Ira Winkler www.irawinkler.com
    5353 Dundas Street West, 4th Floor, Etobicoke, ON   M9B 6H8  2005 0-7645-8468-5
    John Wiley & Sons, Inc.
    416-236-4433 fax: 416-236-4448

      http://www.amazon.com/exec/obidos/ASIN/0764584685/robsladesinterne
      http://www.amazon.co.uk/exec/obidos/ASIN/0764584685/robsladesinte-21
    http://www.amazon.ca/exec/obidos/ASIN/0764584685/robsladesin03-20
    Audience n+ Tech 1 Writing 3 (see revfaq.htm for explanation) 326 p.  “Spies Among Us”

    In the introduction, Winkler admits that the title is slightly
    misleading: most surveillance is not done by international spies, but by common or garden thieves, competitors, and so forth.  The point that he is trying to make is that non-terrorists can hurt you, although he raises the issue with illustrations that are not completely clear.

    Part one deals with espionage concepts.  Chapter one reviews spying terminology, but makes points about the process by explaining the jargon and distinctions.  Risk analysis is introduced in chapter two, but the calculations used may not be clear to all readers.  An attempt to assess the value of information is made in chapter three.  Chapter
    four outlines threats (entities that might harm you) and five covers vulnerabilities–the way your own operations can make you subject to attack.

    Part two describes some case studies of spying.  The content is interesting, although the value is rather concentrated in the short “vulnerabilities exploited” section at the end of each chapter.  I must say that I've read all manner of similar stories and case studies in various security books, and Winkler's are more interesting than most.

    Part three deals with protection.  Chapter twelve lists a number of countermeasures.  These are described in a level of detail that is appropriate for non-specialists (in security), although the content related to technical safety might be a bit thin.  How to plan and implement an overall security program is outlined in chapter thirteen, which includes a very interesting section on how the Department of Homeland Security has taught us valuable lessons about how *not* to execute safeguards.

    While not structured in a formal manner that would make for easier reference, this book nonetheless has some excellent content.  Like Schneier's “Beyond Fear” (cf. BKBYNDFR.RVW ), it is easy enough, and engaging enough, for those outside of the security profession to read.
    Busy managers may find the work a bit wordy and disorganized, but it makes useful points, and has constructive suggestions.  Home users and amateurs will find the style most suited to them, although the recommended controls are aimed at businesses.  Security professionals will not (or should not) find anything new here, but may appreciate the “war stories” and explanations that can be employed in security awareness training.

    copyright Robert M. Slade, 2005   BKSPAMUS.RVW   20050531

    http://victoria.tc.ca/techrev         

    Slade's book reviews — http://sun.soci.niu.edu/~rslade/mnbk.htm

    Slade's Bio — http://sun.soci.niu.edu/~rslade/bkoigtce.rvw

    ======================
    rslade@vcn.bc.ca      slade@victoria.tc.ca      rslade@sun.soci.niu.edu