Amazon

17.2.11

The Song Remains the Same


So Stuxnet was a "game changer" because we saw a private separated network get JACKED! Let me share some of the responses I have heard:

"They shouldn't have been using Windows"
"Stuxnet was no big deal if you weren't the target"
"There are enough other people that are vulnerable, they probably won't come after us"
"We have firewalls, IDS, and AV."


These comments come from vendors, CISOs, and security architects. Hi, you are missing the point. If you focus on the specifics of the attack these are somewhat accurate statements. If you look at the framework of the attack it should make you aware that you are at risk. Some components of Stuxnet were very generic and can provide a framework for future attacks. Check out this page by Ralph Langner: http://www.controlglobal.com/articles/2011/IndustrialControllers1101.html
 Here's a question to ask your CISO or security team lead or whoever you have entrusted your security to.:

"How can our firewall (also include AV, IDS, etc) be defeated?"
"How can an attacker exfiltrate data once they are inside?"
"Can you (security d00d) exfiltrate data without anyone knowing?"

If you saw the report on Night Dragon, you saw another example of energy being targeted. The target was compromised via SQLi and the attack progressed using fairly standard simplistic techniques. No ofeense to the target is meant here, I am targeting the mentality mentioned above. These folks had firewalls, AV, proxies, and policies. Their controls were overcome at every step with what the incident responders called "simple" techniques. Simple is a relative term and the timeframe of the attack is not discussed. If this attack took place over a span of weeks it is relatively easy to recreate. If this attack was done in a matter of days or less, it was well-planned and executed. 

7.2.11

Critical Infrastructure Hacking FUD


Let's take a minute and talk about some of the FUD being slammed all around regarding critical systems hacking.  We are talking about the electric power system, water, and other utilities or critical infrastructure. This article came out last week: http://www.wired.com/threatlevel/2011/02/hoover/ Stating that hackers can't do weird stuff to Hoover Dam. That article is accurate. Twitter exploded the same day with infosec and pen testers screaming "yes we can!" This is also accurate. We have to temper some of the almost outlandish claims we attackers make with the "you can't touch us" claims of infrastructure. 
Why is the wired article true:
1. Separated networks - The Hoover Dam (critical infrastructure sites) are not web apps that you can just stick in a web browser.

2. Infrastructure stuff breaks all the time - These people are trained to respond to outages a lot better than the IT in some organizations.

3. Hackers aren't breaking news - Infosec incidents get published all the time and, sometimes, utilities take notice and plan for these things.

Why what the hackers are saying is true:
1. Remember Stuxnet? - Those targets were air-gapped and didn't touch the Internet.

2. Resiliency != Security - Infrastructure people will say "when was the last time your lights went out?" when the question really is "When was the last time someone wanted to make your lights go out?"

3. Hackers evolve - When people start figuring out patching, web apps and client side attacks shift to the front. When people get leery of those techniques bring on insider threats and social engineering.

You have to get both sides of the story to understand the problem. If you are using computers, networks, and software you have risks. Reducing your attack surface by using air-gapped and private networks is an effective layer of defense. That said, security is never "done." It is an ongoing issue and it must be tested continuously. Insiders cannot be trusted, sometimes this is because of bad intentions, and sometimes it is because people make mistakes. We also have instances where you have say a SCADA operator granting remote sessions and connections for service or maintenance on the system, or they figure out some way to surf the web from their console. In case you have the world's best workers who never look for a way to goof off, we have the removable media attack vectors. I will leave a nasty USB drive in your parking lot or Starbucks and watch who picks it up etc.

Does your blue team tell you they can't be breached? If so, go find a red team and let a real-world scenario play out with them, you might learn that your team is as great as they say they are. You might find that they are unaware of certain vectors into your systems. For example, let's pretend you are performing a test of a "closed system" and everything initially seems to indicate that this is true. Then you notice you can resolve DNS names like Google, but you cannot not get to the Internet via a web browser, the system isn't touching the Internet right? WRONG! Your assigned DNS servers, initially RFC 1918 addresses,  become public IP addresses when you reboot while connected to the "private" network. Out of curiosity, you try to touch those servers from your home ISP and you can. This is news to your client since they had been assured otherwise by the provider. Maybe it even said that in their SLA.

If you read the link regarding the Hoover Dam, someone who appears to be from the public affairs office is posting comments about how that cannot happen. You will see other folks asking how employees communicate and are part of the electric smart grid if they are so isolated. You cannot have it both ways. There's an example of someone touring a power generation facility and asking about security and the operator saying "We aren't connected to the Internet." The person touring asks how they receive communications and directives from their main facility which is several miles away. The operator points out that they receive e-mail on the control system machine. Now this is where perspectives will really diverge. For me, it's not the same to say you don't touch or use the Internet when you are, hopefully, using some sort of VPN tunnel. I view separate as not touching, tunneling, sharing a switch/router, or even the same network rack. SEPARATE. Don't get me wrong, I understand how extremely cost prohibitive it would be to build out your own personal WAN but it can be done. For the govie "cyber" security architects, there are a lot of good models to look at. Companies who have customers and dollars to lose take security pretty seriously.  

So can hackers open the gates of the Hoover Dam? No one has let me test it so all I can say is "maybe." The attack probably won't be attempted from some kid's basement but that doesn't mean it cannot be done. A lot of people say they aren't connected to Internet when they really are. All systems have vulnerabilities but not all vulnerabilities can be exploited with the same level of ease. Be a critical thinker and get both sides of every story.

1.2.11

Logging, Monitoring, and Defending (IDS/IPS)


Yesterday one of the email lists I monitor was debating the best IDS/IPS for large-scale implementation and the Einstein project managed to surface. I followed the topic for awhile but there wasn't much debate however it did bring up some of the more interesting points I have noticed over the past decade in infosec. Some places still don't want IPS, they are content with IDS and just want to reduce their response time and have forensic evidence available when attacks occur. The biggest debate I see is how to choose a product to defend with. This used to be a private vs. open-source argument, and sometimes still is. Lots of people decide to implement SNORT so they only have to buy some hardware, other buy SNORT via SouceFire and get some support. Other folks like to get a pure commercial solution which can be capable of much higher detection speed depending on how fast you need to go. The current rulers in IPS for the commercial world are Juniper and Tipping Point. McAfee is coming on strong after purchasing a competitor, re-branding and getting up to speed. What I found most interesting was that someone brought up using a government-made system. Historically, the government doesn't have a great track record for keeping things secure. Not all government entities are created equally since different personnel work at different sites and agencies so we will have to wait and see how this group does. Personally, I like COTS solutions when you are defending large-scale implementations for the speed and support. That isn't to say your people aren't capable of deploying something different and being secure.

Whatever way you choose to go, don't end up like the diver in the picture. They have on all the necessary gear yet are unaware of the clear and present danger(picture is fake). You will NOT implement an IDS/IPS and be secure simply because of its existence. You absolutely must log what happens and figure out a way to monitor your traffic. There are aggregation and correlation products out there that can take your vulnerability scans and/or customized input so that you don't have to be alerted when a Linux exploit is headed towards a Windows platform and vice versa. The goal for your implementation is to help your security posture. The ability to log is critical but logging doesn't mean monitoring, and monitoring isn't always effective if it isn't actually human readable. Without a, in my experience, significant amount of customization and tweaking an IDS will be spewing way too many alerts for an analyst to track. You may be doing your parsing with custom scripts, vendor filters, or a combination of the two.

I am anxiously waiting to see which way the smart grid will choose to go. It seems like the current feeling is that nothing would be able to monitor the massive amount of traffic and nodes (millions) that might be generated on some of these networks. Hey IPS vendors, we are looking at you.

27.1.11

Wiping hard drives to stop wasting money


I saw this post today and can't believe this myth is still out there. Here's the scoop, go ask an IT person "How many times do I have to wipe a drive to completely erase it?" You will hear many answers and the most popular will likely be 3 times, 7 times, it can never be erased. Let's clear it up. If you make one pass correctly your mission is accomplished. This is how magnetic media works, feel free to test it yourself with the forensic/data recovery tool of choice. How does wasting money come into play?

I was once part of a project testing multiple web proxy vendors. A work policy stated that hard drives could not be returned to vendors and all drives had to be degaussed then shredded. This was for non-classified material that would be tough to even call sensitive. One vendor was set to charge around 16k for the drives in their product. In order to avoid this charge I began asking if there was a waiver process, how it worked, and if the policy was in-house or from a more "legal" entity. Sure enough, there was a waiver process. I filled out the (un) necessary forms and also attempted to explain why this may not be required in the future in order to save my company and the vendor money. No amount of demonstration or discussion seemed to convince people that seven passes, degaussing, and shredding were the only way to maybe prevent our data from falling into the hands of the empire. This was a two-week process with regular chastisement received by me for even attempting to return a drive. At the culmination of the project I erased the drives manually using dd and then handed them to our other forensic examiner to ensure he could not retrieve data. The data was gone, the drives returned and we managed to save thousands of dollars. As I gave the final status report one of the managers stated "We probably could have saved $16,000 if we had just followed the policy." Feeling offended by that I retorted "If the policy is technically inaccurate or wrong, we should fix the policy because it makes us look stupid." Not my most humble moment.

As far as I know that company continues to destroy drives in the name of security that could be recycled, reused, or returned . This effort likely costs millions of dollars annually and provides landfills with many tiny shards of metal that will never break down. Policies are good things when they are accurate.

24.1.11

Acceptable Risk (What's it going to take for security to be important?)

It was an interesting weekend in the cyber-security world to say the least. Some guy who goes by"srblche srblchez" began selling .gov, .edu, and .mil websites or more accurately control to those sites. For attribution I am pulling information from multiple sources such as:
Rafal Los' interview with the dude:
http://h30501.www3.hp.com/t5/Following-the-White-Rabbit-A/Exclusive-Q-amp-A-with-hacker-quot-srblche-srblchez-quot/ba-p/18361

Brian Krebs blog:
http://krebsonsecurity.com/2011/01/ready-for-cyberwar/

Martin Bos (purehate_) found the real site here:
http://www.srblche.com/

Some of the , excellent, points from information security pros are the hair-pullingingly frustrating "I told you so when I tested your environment." I think every pen tester and blue teamer out there has felt this at one point or another. Several talks I saw online last year focused on the fact that we haven't adequately communicated to the decision makers how security impacts their mission or their bottom line. This is completely true. I have seen pen-testing reports that are purely technical and not readable by management executives. Rafal asked "What will it take?" Based on the way we teach economics, and the gazillions of people getting their MBA, it will take a direct tie to putting dollars into the company's pocket. CFO/CEOs want you to be able to answer this question:
"If I invest dollars how much will I earn?" or "If I don't address vulnerability how many dollars will I lose?"

These are not easy questions to answer and a penetration test only brings part of the answer. The larger answer comes from business case analysis and understanding a failure scenario surrounding the vulnerabilities discovered. Until security equals dollars in a pocket then it will be tough. We will continue to fight the "acceptable risk"

This line of thinking comes from my experiences attempting to align security with business mission. I once wrote a five year strategic plan for an organization aligning the mission of security with the mission of the organization and it was completely disregarded. The point is not that my work was not used, the point is that it didn't even generate discussion. No talk, no action. In fact they put someone in charge of security that clearly stated there were almost no problems with their current mode of operations despite test results to the contrary. Even moving beyond that, the group had little funding despite security being "important" to this organization. Sadly, this was not a unique situation. The companies I have seen do security the best were those that know their reputation is on the line and understand that a breach would lose them customers(dollars). Sadly, this would exclude the types of sites that were compromised.

Here are the points for people in charge:

  1. Hire the right people - People who are seeking to learn perpetually and understand that security yesterday is being pwned tomorrow. A project manager or policy maker should not be making technical decisions they do not understand.
  2. Fund these people - Security should be 15-20 % of your IT budget every year. If you haven't seen an equipment upgrade or product requisition for a few years, something is wrong.
  3. Yesterday's technology (firewalling, IPS, DMZ, A/V) needs help - Anti-virus programs are necessary but don't rely on them If you think updated definitions protect you, look up Shikata Ga Nai.
  4. The "help" is your people - Talented infosec people are your only defense. No device you buy is a silver bullet and salespeople will say anything to get a sale. If you don't believe me get a DLP solution and winzip and see for yourself
  5. Test your environment with real scenarios - Don't prescribe the environment to the testing entity. Make it as real as possible or you will never know where you actually stand and be lulled into a false sense of security.
  6. Policy without a technical control is faith - Don't just tell people what not to do, actually prevent it. "We don't allow portable media." is a lot different than "We really hope people aren't using portable media and we will fire them if they do."
  7. Policies and controls must line up - Don't tell your people to have and 8 character password with mixed case and special characters then make them have a password with six characters, single case, and no special characters. (yeah, I have seen this)
  8. Security policies should be written by security people, not HR - If you don't understand the policy, more specifically how to break it, you probably shouldn't write it.
  9. There are more but I 'm tired.

18.1.11

Stuxnet is a US-Israeli joint operation


The NY Times published an article which does not cite named sources. This is normal and acceptable in journalism, I won't beat that horse. I would like to point out that it is all speculation at this point.

The buzz about this started over the weekend and the “confidential sources” part is what’s keeping it interesting. It is worth noting that the source could be Iran itself. The clues in the code, dates and “Myrtus”, could just as easily be a smokescreen. Some speculate those clues were planted to throw investigators from the actual trail. Here’s Iran saying we did it:
http://www.msnbc.msn.com/id/41121090/ns/world_news-mideastn_africa/
Interesting points I observed about the video.
1. No Iranian is shown, scientist or not, in footage with the reactor
2. All signs on walls and doors are in English.
3. Everything in Persian or Farsi or showing Islamic symbols is just paper taped to the walls

"Cyber Warfare"


This term has been thrown around a little and yesterday the Organization for Economic Cooperation and Development (OECD) released a report saying that "true cyberwar is unlikely." Here's an excerpt that was sent to me for comment:


“There is nothing new in what the hacktivists are doing,” Mr. Sommer said. “It really should not be exaggerated. It’s really more like the kind of thing Greenpeace does.”

“We have to get used to the fact that popular protests, as well as skirmishes between nations, are going to have a cyber dimension,” he added. “Some people say cyberespionage is just a few clicks away from cyberwar. It’s not; it’s just another way of spying.”

Report challenges cyberwar doomsday scenarios
New York Times January 17, 2011
https://www.nytimes.com/2011/01/17/technology/17cache.html?_r=2&ref=global

A new study commissioned by the Organization for Economic Cooperation and Development says a true cyberwar is unlikely, and that -- unlike scenarios painted by many recent books and articles on the topic -- advanced countries could recover from such a conflict within days, even hours. "You have this sort of competition between writers to say, 'I have a scarier story than you do,'" said co-author Peter Sommer of the London School of Economics.

I agree that sometimes infosec folks can get into the habit of telling the scarier story. If that scarier story is true though shouldn't we take heed? I responded with the following:

This is an interesting take and really just seems to be a language issue. I suppose it all depends on how you define "war" and "warfare." Mr. Sommer's quote "... skirmishes between nations, are going to have a cyber dimension,” is war in some people's eyes. Also, if it's "..just another way of spying" do wars ever start because of more traditional espionage? I also don't really understand the Greenpeace reference since they don't really attempt government-level espionage. As for the statement that "... advanced countries could recover from such a conflict within days, even hours." That's a great point, cyber-based attack would only be devastating if followed by a tactical operational attack to take advantage of the service disruption. The ability to disrupt, or intercept, communications to and from your target would give you a significant advantage. This ability has brought about encrypted communications by default for the military while critical infrastructure has not yet seen the need for this. One of the issues we discuss with our customers when penetration testing is to assess the impact of the operational decisions made based on information received from a field-connected device. Can I get a human, or machine, to initiate an action if I provide false data?

In 2008 Russia attacked Georgia and used cyber attacks as part of their campaign. I wonder if that would be considered cyber warfare by the authors or just a skirmish? Then, to be fair, I wonder how Georgia would define it.
http://www.zdnet.com/blog/security/coordinated-russia-vs-georgia-cyber-attack-in-progress/1670

I believe cyber "war" is a reality and will be used as a component of real large-scale attacks in the future. What do you think?