Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Saturday, May 6, 2023

BSides Austin 2023

After a Covid hiatus, the BSides Austin computer security conference returned as an in-person event. We enjoyed meeting people we had not seen in two-and-a-half years. The conference ran three parallel tracks and I blocked out some talks to attend but I spent the day near Laurel’s table supporting Kids First Uganda. It was time well invested, visiting vendors and watching attendees. I even met a recruiter who gave me a QR code to upload my resume. 

Three tracks with 24 sessions included cloud-focused phishing,
containing smishing incidents, attacking Microsoft Cloud,
mitigating malvertising, and "Don't Let Your Roomba
Sell Your Bank Login."


There was a BSides Austin virtual meeting on 2 December 2022 that I did not attend. In the past 30 months, I have been in several virtual conference chatrooms and they are a poor substitute. It is much easier and more comfortable to stand in an open hall just watching and waiting than it is to be in a chatroom by yourself. 



The conference featured a day of training on Thursday. (Laurel attended; I did not.) In fact, this year's theme was "Never Stop Learning." 


Organizer Janice Daquila-Pardo told me that they had 600 sign-ups and about 500 in attendance. The last full-scale event in 2019 tallied 700 attendees. We signed up late but got t-shirts nevertheless because of the no-shows. 



Locksporting (above) had two tables this time.
In addition to a wide range of key locks, there were combination
locks and even ziplocks to try your skills on (bottom right).
Next to them were the hardware hackers (bottom left). 
IT managers worry about clouds as services and they
seldom see the more obvious weaknesses.

History of BSides Austin

“The very first BSides in Austin was organized in 2010 by Jack Daniel and Ben Tomhave. This was the fourth BSides ever to be held, and it had about 30 attendees. In 2011, Michael Gough stepped up and took over organization of our local event. Even as he continued to manage the BSides Austin events through 2015, Michael also helped kick off BSides Texas in 2012, and was heavily involved in BSides throughout Texas (including Dallas, San Antonio and Houston). 

“Matt [Pardo; @ultraslogger] and Janice [Daquila Pardo; @bsidesaustin] have been running BSides Austin since 2016. BSides Austin has grown in that short time into a two-day event with around 750 participants. Our goal is to continue providing a fantastic event with great content and training for the information security community.” -- https://bsidesaustin.com/about/

Security Innovation sponsored this year's capture the flag contest. 
The website of this fictional bank had 30 vulnerabilities
and prizes went to those who found the most.
The overarching comment was: "It was harder this year
and the scores were lower."


Laurel and I have volunteered at BSides Austin and LASCON, the Lonestar Application Security Conference, both created and maintained largely by members of the local OWASP chapter. Laurel worked registration and I monitored the presentation rooms, taking head counts and thanking the speaker with a Starbucks gift card. We also presented. Laurel delivered on securing your home network with a Raspberry Pi and I spoke on physical security for data centers. 

For their conference swag, Blackhills Information Security
brought several games including interactive comics
and a complex card game (three decks). 

Our first computer security conference in Austin was BSides 2013 and then the benefit outreach was Hackers for Charity delivering to Uganda. Just about every white hat hacker gathering has some social engagements supporting local or international communities not usually served well by others. Laurel met Kids First Uganda through a cousin. She had quilts made from t-shirts from previous computer security conferences and those were offered for donated sale at BSides.

Friday, September 9, 2016

Hackers Heart Small Talk

Social engineering is the gathering of computer system information by other means.

T-Shirt from Defcon 24
It is common for Internet companies to rely on standard software. Even when provided by competing firms, the forms and formats of presentation are necessarily similar.  

What was your childhood pet's name?
What street did you grow up on?
What was the make of your first car?
What is your mother's maiden name?

The last line on the t-shirt is hard to read because it is on the midriff:  Is your voice your passport?  is a reference to Sneakers, the hacker film with Robert Redford, River Phoenix, Dan Aykroyd, James Earl Jones, Sidney Poitier, Mary McDonnell, and Ben Kingsley.     

Other popular keys to your files include
Who was your favorite teacher?
In what city did your parents meet?
What city did you grow up in?
What high school did you attend?
What was your favorite subject in school?

It is not so much that you cannot trust your co-workers (though there is that), but that you cannot know who else is listening when you are out in public socializing with your colleagues.

ALSO ON NECESSARY FACTS
Hacking
Passwords
BSides 2016
Securing Your Viper from Cylons
When Old Technologies Were New

Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Saturday, January 23, 2016

Passwords

Are your passwords strong enough to resist a brute force attack? Passwords are just about dead. Many systems now offer “two factor identification.” You give them your cell phone number and you have to use both a password and a code number sent to  the phone for your log in.  But passwords continue. They are easy for administrators. They are part of the common culture.

Steve Gibson has the engineer’s “knack.” (See the Dilbert video here.His company, Gibson Research Corporation (here)sells a wide range of computer security products and services. He also offers many for free. Among the freebies is Haystack: How Big is Your Haystack – and how well is your needle hidden? (here)  This utility provides a metric for measuring password security.

It is pretty easy to do yourself, if you like arithmetic. 26 upper case letters, 26 lower case, 10 digits, 33 characters (with the space) for 95 printable ASCII characters in the common set.  So, if you have an 8-character password that is 95 to the 8th power possible combinations: 6.634 times 10 to the 15th power or over 6-and-a-half quadrillion. If you could try a million guesses a second, it would take 6.5 billion seconds or just over 200 years. (60 seconds/minute * 60 minutes/hour * 24 hours/day * 365.25 days / year* 200 years =6.3 billion .)

Gibson Research makes all of that automatic. Just key in your password, and it tells you how long it would take to crack.

Cracking passwords is a routine activity for a hacker. They have tools.  At one meet-up for hackers, the speaker told us, “If you have to use brute force, you are not thinking.”  They do not type in a million guesses per second, of course. They have programs to do that. Also, most websites just do not allow that kind of traffic: you cannot do a million guesses per second. What the hackers do is break in to a site, such as Target, Home Depot, LinkedIn, or eHarmony, download all of the log files, and then, on their own time, let their software attack the data offline.

Also, hackers do not use the same computers that you and I do. They start with gaming machines because the processors in those are built for high-speed calculation. They then gang those multiple processors to create massively parallel computers.  The calculators from GRC show the likely outcome for brute force by both a “regular” computer and a “massive cracking array.”

If someone got hired today at a typical midrange American corporation, their password might just be January2016. If, like most of us, they think that are really clever, it ends with an exclamation point: January2016!  Hackers have databases of these. They start with standard dictionaries, and add to them all of the known passwords that they discover.

One common recommendation is to take the first letters of a phrase known only to you and personal only to you. My mother had naturally red hair for most of her life. She was born in 1929 and passed in 2012. So, “My mother’s red hair came from a bottle” becomes mmrhcfab19292012. According to Gibson Research, brute force guessing with a massive cracking array would take over 26 centuries.

Gioachino Rossini premiered his opera, William Tell, in 1829. “William & Tell = 1829” would take a massive parallel cracking machine about 1 million trillion centuries to guess.  However, Five + One = 27 could be done in under 1.5 million centuries.

Remember, however, that a dictionary attack will crack any common phrase.  With over 1.7 million veterans of the United States Marine Corp, someone—probably several hundred someones—has “Semper Fi” for a password. Don’t let that be you. A brute force attack would need only 39 minutes, but that is not necessary: a cracker's dictionary should have "Semper Fi" in it already.

(Above, I said that cracking passwords is a “routine activity” for a hacker. “Routine activities” is the name of theory of crime.  Attributed to sociologists Marcus Felson and Lawrence E. Cohen, routine activities theory says that crime is what criminals do, independent of such “social causes” as poverty. See Routine Activity Theory on Wikipedia here: )

PREVIOUSLY ON NECESSARY FACTS


Sunday, October 11, 2015

InnoTech 2015

On Thursday, October 8, I spent the morning at the 13th annual InnoTech computer security conference. Seventy-nine vendors filled the floor. I only had time to meet a fraction of them. My tour was facilitated by a "passport" sheet that listed ten sponsors. Track them down, get them to sign their square, and drop the completed form in a box for a drawing.  It was "must be present to win" but I did not stay for that. I met some friends, colleagues from OWASP, and recruiters who sponsor our happy hours.

"Technology Navigators is a technical staffing firm,
specialized in recruiting skilled individuals
for project-oriented consulting and contract positions.
We’ve been firmly rooted in the Austin technology community since 1999,
and have been providing companies that
develop, build, and use technology
with the people they need to grow their business for over 15 years."
"Knight Security Systems has built its reputation over three decades
as one of the country’s leading providers of security system solutions.
With over 4,000 systems since 1983, Knight Security Systems has assisted
our customers in reducing internal and external, loss, legal liability,
employee liability, increasing productivity, safety compliance,
customer satisfaction and bottom line profits."
"Headspring is much more than a provider of
enterprise software strategy and development ...
We are motivated by our daily opportunity
to create a real impact in the world,
and to enable our employees, our clients
and our community
to achieve beyond their perceived potential."
"Bridgepoint Consulting provides
management consulting services
that help organizations optimize financial operations
and information technology
while mitigating organizational risks.
Whether a company needs assistance with strategy,
process improvement,
technology or regulatory compliance—
or simply has resource gaps,
our team of professionals deliver measurable results."
"By partnering with our customers,
Future Com [www.myfuturecom.com]
can give them a competitive advantage
in terms of everything from implementation times
and resources required during deployments
to lowering the total cost of ownership
of technology and solutions as a whole."
PC Magazine Best Antivirus Software 2015.
Available for Macintosh.
Enterprise solutions also available.
"Bitdefender protects its users’ privacy,
as well as the as their devices.
Our award-winning security technologies protect against
all cyber-threats today,
from annoying adware
to dangerous malware
that infiltrates to steal data, intercept online payments,
spy, or hold your information for ransom."
"M-Files is document management the way it should be:
simple to install and learn, reliable, powerful and secure –
without breaking your budget.
Improve workflow, increase information reuse, eliminate redundancy,
securely control content, and avoid conflicts and data loss –
all in a single document management solution
that integrates with Windows Explorer."


"Everything transacts on the wire: 
from raw packets to the payloads of all application transactions. 
Wire data is a deep and rich source that contains 
every conversation occurring on the network. 
Wire data provides an objective, "outside-looking-in" view 
across the entire application delivery chain. 
It serves as the most unbiased source of truth about 
the performance, effectiveness, and security 
of enterprise IT environments." -- Extrahop Networks
"For thirty years,
New Horizons Computer Learning Centers
has provided practical and innovative
corporate training solutions
to help organizations overcome operational challenges
and take advantage of emerging opportunities."
"Advanced communications and cloud solutions
from Time Warner Cable Business Class
can enable your Enterprise to be more successful
in today’s market. ... 
Time Warner Cable Business Class
delivers reliable and scalable voice and data solutions
over our advanced, fiber-rich IP network."
"...Veeam has pioneered a new market of Availability for the Modern Data Center
by helping organizations meet
recovery time and point objectives (RTPO™)
of less than 15 minutes for all applications and data,
through a fundamentally new kind of solution
that delivers high-speed recovery, data loss avoidance,
verified protection, leveraged data and complete visibility."
"Keep your home connected
with powerful High-Speed Internet, Digital TV, Phone Service.
Services designed for business ranging from
home/small offices up to 50 employees,
including Internet Solutions, Phone Services,
and 24/7 Technical Support.
Enterprise-class data, voice, network and cloud solutions
designed to meet the unique needs of your business."
PREVIOUSLY ON NECESSARY FACTS
Available on Slideshare

Sunday, January 25, 2015

Your Cell Phone is Not Safe

Your cell phone can be taken over by hackers who will view through your camera and watch you enter your passwords and other information.  Here in Austin at the IEEE “Globecom” conference on global communication last December, I attended a presentation from Temple University researchers who compromised an Android cell phone. (For the exposed risk of someone else taking control of your car while you are driving it, see “Securing Your Viper Against Cylons” here on NecessaryFacts.) 


Doctoral candidate Longfei Wu and five colleagues from Temple University, the University of Massachusetts, and Beijing University exploited vulnerabilities in the Android cell phone to seize control of the camera.  

Having done that – and having reduced their footprint to one pixel – they then watched finger touches to the keyboard in order to guess passwords.  Some sequences were more secure than others.  1459 and 1479 were easy to identify.  1359 and 1471 were harder to guess.  The fundamental fact remains: They took control of the camera without the cell phone owner being aware of it.

Moreover, the Android operating system does not provide you with a log file of usage.  There is no way for you to review what your phone has been doing.  However, the researchers fixed that. 
“We make changes to the CheckPermission() function of ActicityManagerService, and write a lightweight defense app such that whenever the camera is being called by apps with CAMERA permission, the defense app will be informed along with the caller’s Application Package Name.[…]There are three parts of warnings in our defense scheme. First, an alert dialog including the name of the suspicious app is displayed. In case the warning message cannot be seen immediately by the user (e.g., the user is not using the phone), the defense app will also make sound and vibration to warn the user of spy camera attacks. Besides, the detailed activity pattern of suspected apps are logged so that the user can check back.” -- from "Security Threats to Mobile Multimedia Applications: Camera-based Attacks on Mobile Phones", IEEE Communications Magazine, March 2014."
iPhones also are at risk
If you want to protect your phone, you have to figure out how for yourself.  Very few ready-made defense apps exist for Android, or iPhone.  You could join a local hacker club such as DefCon.  (For Ann Arbor, it is DefCon 734; for Minneapolis it is DC612.)  That brings up the problem of trust.  When I go to computer security conferences, I never take a computer; and I do not answer my phone.  I do trust the organizers of our local groups, LASCON, ISSA, OWASP,  and B-Sides; but I do not trust everyone who comes to every meeting.  If you want someone to “jailbreak” your phone, and program something on it for you, then you really need strong trust.  It is best to do it for yourself. 

“Unfortunately, it's not uploaded online. To support the defense scheme, I modified the Android system and generate new image files. This means if someone want to use the defense function, he/she must flash the phone. As a result, all the installed stuff may get lost. I think people wouldn't like that to happen. Besides, the Android version I used for testing is 4.1-4.3, while the most recent release is 5.0.” – Longfei Wu, reply to email.
As "the Internet of Things" connects your washing machine and your car to your home thermostat and puts them all online along with your coffee-maker and alarm clock, all of them connected to the television box that never shuts off and always listens, you will be increasingly exposed to harm.  

PREVIOUSLY ON NECESSARY FACTS
Hacking
Biohackers
When Old Technologies Were New
LASCON 2014

Tuesday, November 25, 2014

Brian Krebs’ Spam Nation

Computer security journalist Brian Krebs ("Krebs on Security" here) signed books at Barnes & Noble in Austin on November 24.  Spam Nation is really about two nations: Russia and the United States.  Two criminal organizations dedicated to online spam and botnets, perhaps the largest in the world, work(ed) from Russia, targeting Americans. 


Brian Krebs started his presentation by acknowledging the four years he spent on the project.  He then thanked his publisher, editor, and associated researchers, and the cyber-crooks.  Both of them denied that they were engaged in criminal activity; and both have threatened to sue. 

It starts with spam, offers for Viagra, Gucci, and other big name products, especially pharmaceuticals and designer fashions.  The offers themselves are real enough, in that, apparently, millions of people are taking fake drugs and carrying fake handbags. 

About fifty security professionals attended.
However, attached to the offer is malicious software that takes control of your computer. Your computer becomes a zombie following their orders to infect more computers.  These networks of robots (“botnets”) flood the Internet with new viruses.  According to Krebs, the typical life cycle is 12 to 24 hours. As new creations, the programs successfully challenge anti-virus software such as Kaspersky and McAfee.

Eventually, the two criminals turned on each other.  They provided Russian law enforcement (and Krebs) with millions of stolen records.  One of them, Pavel Vreblevsky even got himself appointed to a commission to investigate computer crime.  (I note that in that, he was like William Chaloner and John J. Ford, who also played both sides of the game.)
When asked about security tools, Krebs replied that good procedures are the best protection.  Rather than trying to keep people out of your network, you need to focus on finding them once they get in.  Rather than spending money, sometimes millions of dollars, on tools that no one actually uses, it is better to hire good people to really use the tools your company now has. 

Krebs said to keep your personal and professional lives separate.  He recommended partitioning your operations with different computers on different services for different tasks. Have different VPNs (virtual private networks). Use layers of security.


Asked about the threat of a catastrophic attack on our information infrastructure, Krebs said that it is not in the interests of these criminals to harm our economy.  They want us to buy from them.  Disrupting commerce is unproductive.  Krebs suggested that a catastrophic event will come from a Wargames scenario where “some kid in his mom’s basement who will see a big red button and has no social understanding.”

PREVIOUSLY ON NECESSARY FACTS

Friday, October 24, 2014

LASCON 2014

OWASP (the Open Web Application Security Project) sponsors LASCON, the Lonestar Application Security Conference.  This year's two-day assembly brought together cutting edge vendors, theoreticians, and developers.  It was my privilege to be the introductory speaker serving KUNAL ANAND of Prevoty and KSENIA DMITRIEVA of Cigital.  The general session guest speakers included Martin Hellman, co-inventor of Public Key Cryptography, and Kelley Misata, formerly of Tor, now with Suricata.
Martin Hellman (right)
"The Open Web Application Security Project (OWASP) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks." - www.OWASP.org



Ksenia Dmitrieva of Cigital answers questions
after her presentation
"Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. You'll find everything about OWASP here on or linked from our wiki and current information on our OWASP Blog. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide. We ask that the community look out for inappropriate uses of the OWASP brand including use of our name, logos, project names and other trademark issues." -- OWASP.


Keynote Speaker Kelley Misata spoke on behalf of Tor.
Misata is now working with the CERIAS project of Purdue
and Suricata, an Open Source Foundation partner
.
Martin Hellman worked directly with Whitfield Diffie to realize public key cryptography. They then discovered that Ralph Merkle had independently submitted papers some months earlier.  Merkle's work was rejected for openly running contrary to the mainstream of cryptographic theory. ("Secure Communications over Insecure Channels" on his website here.) They published congruent ideas but under a less contrarian article title, "New Directions in Cryptography." (On his own pages here and archived widely, including here.).  Also,  Hellman was a professor. (Diffie was his doctoral student). On the other hand, Merkle was working on his doctorate; and he had no support for his theories from his own mentors.  So Hellman brought more social status to the supposedly impartial peer-review process.  He also brought Merkle to Stanford from Berkeley.

Kelley Misata had been cyber-stalked for eight years. She watched while her computer was taken over and worked remotely. Trashy emails were posted in her name from cuts and pastes from her own Facebook pages. She could not apply for a job without her stalker knowing it and intruding.  She figured out who he was.  However, the FBI said that they were powerless, and a judge refused to issue a restraining order, both because the stalker hid behind Tor and could not be identified.  So, she took her MBA and her experience in marketing to Tor where she advocated for privacy and security. She now helps the Center for Education and Research in Information Assurance and Security (CERIAS) while working on her doctorate at Purdue.

Appropriately, the front of the vendor's hall was held by White Hat Security of Santa Clara.  All of the sellers were satisfied to have made good contacts. While setting up his talk, Kunal Anand underscored for me the importance of qualified leads to a start-up looking to scale its services. 


OWASP co-founder and Contrast Security CTO Jeff Williams 
Among the fifteen sponsors set up in the vendor hall were HP (both local and national sales offices), Contrast Security of Palo Alto, Trustwave, F5 Networks (headquartered in Seattle), Checkmarx from Chicago, Qualys (Redwood City), and K2Share from College Station. Texas.
Wade Williamson from Shape Security of Mountainview. 
OWASP conventions always include several security challenges, such as "capture the flag" and locksporting.  The convention name tags were puzzles with imbedded clues.  (Decipher the Roman numerals into an IP address and go from there.)  Winners received a challenge coin. "Capture the flag" lets would-be hackers attack knowledgeable defenders of a target computer.  Of course, all the firewalls do you no good if someone can pop the lock on your server cage. 


Jgor taught me how to pick a four-wheel combination lock.
After I felt successfully for the solution, he showed a slide
with a cutaway view of the internals . 
Over 40 different breakout sessions provided expert presentations on application security, rugged development, agile development, cryptography, IoT and mobile platforms, and an array of special case studies.  The two-day conference ended with giveaways and drawings. The top prize was a Pwn Phone from Pwnie Express.


We enjoyed great guitar work from Chris Devore
at both lunches and the Thursday evening social.
ALSO ON NECESSARY FACTS
B-Sides 2013
Open Secrets
Fortune Cookie in Hex Code
The Eurion Project
Securing Your Viper Against Cylons