Saturday, February 2, 2013

All your VMs are belong to us


It goes without saying that a server hosting a bunch of virtual machines is a juicy target.  But it's always nice to see that principle demonstrated in a very concrete and simple form.  VMInjector is such a tool.


To quote a bit from the Readme:

VMInjector injects a DLL library into the VMWare process to gain access to the mapped resources. The DLL library works by parsing memory space owned by the VMware process and locating the memory-mapped RAM file, which corresponds to the guest's RAM image. By manipulating the allocated RAM file and patching the function in charge of the authentication, an attacker gains unauthorised access to the underlying virtual host.
VMInjector can currently bypass locked Windows, Ubuntu and Mac OS X operation systems.


http://www.sectechno.com/2013/02/02/vminjector-tool-to-unlock-guest-vms/

It's available at:

https://github.com/batistam/VMInjector



Simple and elegant.

Wednesday, January 30, 2013

what could possibly go rong?

It appears that Facebook is expanding their use of requiring users to send them a picture of a Government issued ID in order to unlock their accounts.

In other words, anybody with Photoshop (probably just Paint) can convince Facebook that they're who they say that are.

Really?

http://idealab.talkingpointsmemo.com/2013/01/instagram-asking-for-users-government-issued-photo-ids-now-too.php

If you can't authenticate a user - just admit so and move on.  Don't engage in security theater and force legitimate users to place their own PII at risk (cause you know that some users will not sanitize the picture before emailing it in.)


Sunday, January 27, 2013

SQL Slammer

Here's a neat little post describing how David Litchfield discovered the bug which was eventually exploited by SQL Slammer.

It's all about curiosity, and picking at the edges when you find a crack in the veneer.

http://threatpost.com/en_us/blogs/inside-story-sql-slammer-102010


Thursday, January 24, 2013

Sendmail all over again

OMG!  I actually have troubles believing this - except the source is Krebs and the vendor has essentially admitted to it via a Tech Alert.

Barracuda Networks has been shipping firewalls, spam filters and VPN devices with undocumented back-door accounts. Allegedly, the back-door accounts include a password-free account with write access to the MySQL database that provides authentication information.

The only access control to these accounts is that they try to limit access to ssh connections from Barracuda owned IP addresses.  Apparently they failed in this endeavor since other, unrelated, companies also have addresses in the permitted address blocks.


http://krebsonsecurity.com/2013/01/backdoors-found-in-barracuda-networks-gear/#more-18612


How on earth can a security device vendor ship a device with an open back-door account in today's environment?  

Let me repeat that question:

How, in today's security environment, when truly serious and damaging attacks are the order of the day, could any provider of security devices knowingly ship security devices with open back-door accounts?

Back in the 90's we all learned not to do this thanks to the Sendmail WIZ account.  Just to provide context, those were the days when you could still find Unix systems with guest accounts ... and yet we still understood that back-door accounts were a bad idea.

This is exactly the sort of thing we accuse the Chinese of doing as we drag them to congressional hearings and reject their equipment; and it turns out that a California based company has been doing it in a most egregious way for years.  I'd be willing to bet the government, including the DoD, has lots of this equipment.

If I owned any Barracuda gear - today's project would be to confirm if this report is really true (it's so incredible, I still have trouble believing it.).  If it did turn out to be true, I would immediately begin the process of removing all Barracuda equipment from my site.  

Why such a dramatic response?  It's not so much that this is a big gaping security hole, everybody has bugs.  But any company that knowingly permits this sort of thing to ship, in 2013, must have a corporate culture that's totally devoid of any reasonable concern about protecting their customer. As they say, there's no fixing stupid.

This, BTW, is a terrific example of why Defense in Depth is so critical.  The only defense against this vulnerability is to block all incoming ssh connections.  Of course, for some unlucky individuals, the natural way to block these connections would be via their Barracuda firewall (!)


Tuesday, January 22, 2013

Backtrack moving forward


The folks who have brought us Backtrack are preparing to release the new version.  Instead of just putting out another static distribution, they've gone to a fully upgradable version that will allow them to maintain current versions of their tools.  A hugely bigger task, and way more useful for us - the users.

It's going to be renamed to Kali.  I can't wait to play with it.

Cool video teaser follows.




Saturday, January 19, 2013

Is DDOS free speach?


So I finally got around to poking at the "We The People" petitions that you can submit to the White House;  and guess what I found?

A petition to equate DDOS attacks with a protest march.  In other words, DDOS is just a form of free speech!

https://petitions.whitehouse.gov/petition/make-distributed-denial-service-ddos-legal-form-protesting/X3drjwZY

I think the big flaw with the petition is that individuals hitting reload on a web site is very different than pointing a botnet at a web site, or sending a hundred ping-of-death packets to a web site.

For better or worse, it looks like the petition is not getting much support.

Goodbye Passwords, Don't Let The Door Hit You ...


Google already provides a version of two-factor authentication for gmail - via sending you a one-time password via  SMS when you login.  But now they're looking to take it all the way and be done with the password.

http://www.wired.com/wiredenterprise/2013/01/google-password/

I've been toying with trying the Yubico authentication token.  Maybe it's time ...