Friday, January 15, 2010

Off of Security for a few

I just wanted to start a small series of posts that are off the security topic a little. I will intersperse these with the same good 'ol security posts as well, but I wanted to mention a few things as well.

A lot of people like me, some call them geeks I suppose, have desk jobs and type all day long. When you work long hours in such an environment, some of us tend to get out of shape. I have certainly gotten out of shape over the years and decided to do something about it. An old colleague of mine tried this workout system called P90x. He said "it's not for the faint of heart", but he posted some pictures of his progress and it was enough for me to think "I can do this".

It's an action/pain packed 90 days, but if you do it, you will see results. Now, I just started today and let me tell you, it is painful! I feel much better now after a shower, but I'm sure I'll be in more pain as the day goes on and even more tomorrow.

This plan is no joke! It's 7 days a week for 90 days. There are "rest" weeks, but don't think relax when you read rest. It is just a little lighter. So I wanted to say I will continue to post my comments on how it is going and any tips I can give from someone that is in probably the worst shape of their life but doing this.

So first thing is first. They have a pre workout test. A few moves that you can do to see if you are ready. I passed 90% of it. I'm the kind of person that goes for a challenge and feel that 10% wasn't bad enough to halt progress in my goal. If you get anything less than that, they recommend, as do I, that you don't do it. The workouts are much worse, not easier. If you want to know what this is before you buy it, let me know and I can give you some examples. If you can't do them, don't even think about it! Your well being is more important than meeting a goal. They do have other workouts which can bring you up to speed before you do this. Take that heed!

Tips on the first day. All I can say is be realistic if you are in as bad of shape as me. Endurance is important so you can finish the workout. Keep that in mind when you are counting reps. Make a goal for each set and try to get it. Don't risk form for reps, it's not worth it. The people on the video were knocking out huge numbers of push ups and pull ups. Don't put yourself on that level, just know that is where you want to be. I averaged probably half of what they were doing. This is not a bad thing, just keep in mind, these people did this program already, and I guarantee some of them were in a similar boat.

Just be consistent and know when you need to stop. Drink, drink, drink! Keep hydrated it is huge! If you are working with a partner, they may be able to push you a bit. If you are by yourself you need to be true to yourself, know your goals and try your best. Don't quit because "it's too hard" unless it really is. Case in point is that on the next to last set of pushups, I went down and could not get back up. I'm OK with that. That was really all I can do. My body said no, my mind didn't! I think that is key.

I'll post more as time progresses. I can only stress to make goals. My first goal is to be doing the reps they are doing on the video by then end of the first phase of 30 days. I think that's respectable and if I can't, then I can't, but that's what I'm shooting for.

Monday, January 4, 2010

Top 10 Home Anti Virus Applications

I stumbled on this top 10 list of home paid for anti virus applications. I tend to get the question of which AV I recommend from friends and family. Generally I have been a fan of the Symantec product. This is all relative as you may have seen in a previous post where I showed generally how easy it was to pass a virus though current AV techniques. With all of this in mind Symantec showed up as #2 on this list by PC world. Not a bad standing. G Data was number one which I have personally never heard of. The article does say that it was a close race between the two.

So was this post to say "I told you so"? No! It was just to show the top 10. You can make your decision. What I wanted to get across, as I have mentioned before, the freebies are good but it really adds serious protection to pay for your subscription. All AV subscriptions end up around the same ball park of $25-$50 bucks per year. That is a small price to pay for the protection of your system and data. PC techs tend to charge $75-$100/hour to do clean up after the fact so you can do the math! Even if you have a good friend or family member that will do the work for you, your gonna pay the same price at minimum of what you could have paid to have good protection in the first place.

It can seem like insurance, but like insurance, it's worth it if it does happen! Remember AV isn't the silver bullet for a secure system but it should definitely be a part of your armor!

Sunday, December 27, 2009

Posting slow down

So I think I have fallen into the same pit that many do with keeping up on a blog. Too many things going on and not enough time in the day. I wanted to post an update and hopefully resolve to update more often :)

So I have been reading a bunch on malware analysis. I have found myself doing this more and more at work. I really enjoy the process, which has lead me to dissect the topic. The last book which I just finished was "Malware Forensics: Investigating and Analyzing Malicious Code". The book was written well. The idea of it was that you had two incidents that you were investigating. One was on a Windows machine and the other was on a Linux machine. It then took you step by step into each.

The one thing I would probably offer in the way of criticism of the book would be to finish the Windows portion, then do the Linux portion. I found it difficult to keep my mind focused when it would switch from chapter to chapter. I would find myself wanting to skip to the next Windows or Linux section to see what happens next.

Now I am reading The Art of Computer Virus Reasarch and Defense. This book is a little dated but contains great material about how viri work. The most interesting thing I see is probably that Peter Szor was talking about the need to protect Javascript in Adobe applications, or types of worms called Octopus in which multiple systems communicate together to perform an action. These are things that are current and in some cases current of the past month or two and yet here they are written about in full detail years ago.

If I learned anything about this topic so far in this book, it is that virus writers are so far ahead, it's no wonder Anti Virus programs are so easy to beat. The techniques of the good virus writers (good as in ability, not in motive) are light years ahead of the people that probably defend these systems every day. I don't mean to say this to take away from any system, network or security admin out there, but they seem to have a large leg up.

We talk a lot about education being the key to winning this battle. I agree with this, however, I feel that the real education needs to come from the people protecting these systems, more than end user education. Now before I get flamed, I'm not saying that end user education isn't important as well; I'm just saying that if the people that know and understand these systems don't understand the vectors of attack, how can we expect end users who just expect things to work to understand the techniques?

In closing, the plan to meet every Saturday starting on the 16th of January to go over the Metasploit framework course offered by Offensive Security is still on. It will be at the Bowie, MD library. If you haven't received the dates please just contact me at nospamcshaffer which is at the gmail.com mail service. Of course remove nospam for the real address.

Sunday, October 18, 2009

Security for Small Businesses

Most small businesses see IT security as a threat that doesn't really target them. I was over at the NIST website today and stumbled on some information they released for Cyber Security Awareness Month, which is this month if you didn't know :) The video was decent and brought up some good stats that I think any small business should listen to. A large percentage of small businesses experience laptop theft, insider abuse, virus infection and bot infection.

The page brings out that although as a one off, small businesses are small targets. However, when you take into account that small businesses make up what they are stating 95% of businesses in America and 50% of the nations gross national product, that isn't so small is it? Control of that could be quite devastating to the whole country.

They have released a 20 page guide outlining common things small businesses can do to help secure their networks. If you want a copy of this, or just want to watch the video, you can find them at the following links:

Article

Video

Security Document

SMB Security Page at NIST

Saturday, October 10, 2009

Security Group Study

Calling anyone interested in security in the Washington DC area! I am trying to get a group together to have a group study effort to sharpen our general security and pentesting skills. I plan on finding a place where we can meet and go through the Offensive Security Metasploit Unleashed course. I think it will be a good way to get an introduction into general security as well as pentesting, but it will also help some who may know this already sharpen or help keep their skills sharp. I have not decided on a place to have this yet. I would like it to be as central as possible to the metro area so its as convenient as possible for everyone interested. If you have ideas for meeting places let me know.

The fee for this group effort will be $4 donation to Jonny Long's Hackers for Charity per the request of Offensive Security. Depending on the venue we may need to purchase drinks/food or some other customer item for the example of a Starbucks. If we can find a free place, that's great. I would like to have Internet available if possible, but hey, we're hackers I'm sure we can figure that one out :)

What do I need to participate?

Technically nothing. If you want to get the most out of it, being that this will be a meeting where a desktop will probably not be available, you should have a laptop that can run some virtual machines. The Offensive Security group has the requirements for the class here:

Lab Requirements

With that said, I have my laptop and one other I can bring. If anyone has extra laptops they can bring to the group meeting for people to use while they are there, that would be great. It will be more than just the lab as discussions will be a majority of the time. Thus, even if you don't have the gear, you will still learn a ton.

I will post again when more details are available. If you are interested please let me know by emailing me at pleasedontspam-cshaffergmailcom (remove the pleasedontspam- and of course add the @ and the . in their respective places :P)

Also if you are part of mailing lists or groups in the area, pass the info around.

New Blog

I have created a new blog. A new blog you say? We barely read this one :). This new one is more professional in nature. It is the beginning of a new open source community creating custom IPS signatures for Symantec Endpoint Protection. So the good news is, unless this is something you are interested in you can still get my normal great content here :). If it is something you are or may be interested in check it out!

Open Source SEP Signatures

Sunday, October 4, 2009

My Anti Virus will keep me safe and warm! Won't it?

There is always questions being asked to me as to what the best Anti Virus is. This is a difficult question. The truth of it is, they can all be beaten. I know that might come as a shock to you, maybe not, but it's very true. I decided to take this post and try to explain why this is difficult.

What I have done is created a simple backdoor trojan using our favorite Metasploit shell_reverse_tcp. I encoded it with Shikata_ga_nai. Loosely translated this is Japanese for "nothing can be done about it". This method basically utilized a polymorphic XOR additive feedback encoder. (for those of you unacclimated to this is means it has the ability to change things in what appears to be a random fashion.)

This is a simple shell code. It has a specific purpose to connect back to any system I tell it to. This should be caught by any normal means. I encoded one version with Shikata_ga_nai and built one version with no encoding. I uploaded both to VirusTotal. This site scans your files that you upload with 41 (at this time) different virus scanners and lets you know which ones found it malicious. Both versions were said to contain no malicious code. Now this could be an unfair test as it was simple code, so I decided to encode Netcat both ways and run that through. For those of you that are not familiar with Netcat; it is a back door program that can be used for good or bad but is definitely seen by major vendors as malicious. I again ran this through Virus Total and the unencoded version was caught 25 of the 41 vendors easily. The version I encoded was not recognized at all.

So what does it all mean Basil? It means that even all of those old viri can get past your anti virus. What you really need is an endpoint protection from companies such as Symantec, McAfee or Sophos. Why are they better? Because they are created to look for "odd" behavior rather than just a signature of the file. This is becoming more and more important as attacks and attackers are getting more complex.

For those of you that will still use the free anti virus programs out there, do what you can to keep them up to date, scan your systems often. Microsoft has released a free version of Anti Virus. You can get it here Microsoft Security Esstentials. Make sure you are downloading this from the Microsoft web site! There are many fakes out there already. I have not tested it fully, but the little I have tested it shows that it is pretty decent for free. It would be nice to run multiple anti virus programs but usually they fight with each other. I am testing this one with AVG on my wife's PC and will report back if they work well together or not. I also recommend running Malwarebytes as often as possible. Especially if you are a constant Facebook or Myspace user. Running it nightly might be a good choice.

As always, if you have any questions, let me know.