March 15, 2012

We Didn't Start the Fire(wall)



Well, hello there, boys and girls, it's time for another sing-song, sing-along!


Previously, we destroyed paid homage to a Bob Dylan song in the guise of a BSides security conference tribute http://shpantzer.blogspot.com/2011/07/cons-they-are-changin.html and that seemed to go over like a lead balloon, so let's try this again...  Once more, with FEEEEEEELing.


Today, we point our favorite secure (ahem) browser to http://www.youtube.com/watch?v=eFTLKWw542g (open in another tab), support the original artist by watching the official video with a 30 second commercial, then follow along with our very own mangled, er, um, I mean ShpanTazered (TM) version of this Billy Joel classic!  


The original song was difficult to follow, with so many vague references to historical events and figures.  I left some of the original references in there, just to be confusing, but switched up the rest for an infosec audience (who else reads this ridiculous blog...)  


Security types will certainly be more familiar with Operation Bot Roast than Santayana (who's THAT?) and with the infamous and historically significant Paris Hilton Sidekick hack than with any 'trouble in the Suez' nonsense (where's that again...?)


We usually look at the world through the hazy filters of geek rock star practitioners and analysts, malware outbreaks, advances in hacking tools, networking breakthroughs and disruptive technologies.  Not actual rock stars and you know, shooting wars, and whatever else people pay attention to... We're special little infosec snowflakes!  Cuz I said so.


It's been a long, wild ride, intertubes, so have a drink of water, warm up your vocal chords, strap in and try to sing this techie tongue-twister to the Billy beat!


Good luck, 


gAli G AKA Gal Shpantzer



We Didn't Start the Fire(wall)

Hacktivism, PGP, Red China, Entropy
BlackBerry, Neuromancer, PageRank SEO

Dan Kaminsky, Richard Nixon, Studebaker, Max Vision
Red Pill, Blue Pill, CISSP

RADIUS, Logic Bomb, Pain Ray, Johnny Long
Gene Schultz, The King And I, when do we stop SQLi ?

Robert Morris, Vaccine, England's got the same queen
DVD Jon, Liberace, Operation Bot Roast

We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it

Pirate Party, Rybolov, Nimda and CSRF
Blaster LoveBug, John The Ripper, Communist Bloc

SRI, BBN, PDF bugs round the bend,
D-N-S Fails, Synchronize the Clocks

Stuxnet, LASER Beam, BSides’ got a winning team
Hoffacino, Xerox PARC, Kristin Paget, Bletchley Park

Lycos, LulzSec, Altavista, Cuckoo’s Egg
Freedom Frisk, Howard Schmidt, Paris Hilton’s Sidekick

We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it

Cyber Storm, AirCrack, Mickey Mantle, ENIAC
Mitnick, System High, It’s the year of PKI

Keyloggers, Stacheldracht, Operation ShadyRAT
BitLocker, SecuTwits, Sony-BMG Rootkit

SE Linux, @Beaker, EFF, Mafia
SIPRNET, Lamo, Ripco is a no-go

U2, WikiLeaks, IANA and IRC
Securosis, RAND Corp, Hacker’s Manifesto

We didn't start the firewall
It was always burning
Since the URL's been turning
We didn't start the fire
No we didn't light it
But we tried to fight it

Zimmerman, LANMan, Stranger in a Strange LAN
Webcam, KLM, APT invasion

(David) Bell-Lapadula, Foursquare check-in mania
Vint Cerf, Trojans, GPUs make BitCoins

JavaScript, Active X, British Politician sex
RSA: Blown away! What else do I have to say?!?

We didn't start the firewall
It was always burning
Since the URLs been turning
We didn't start the firewall
No we didn't light it
But we tried to fight it

451, brute forcing, Kerberos is back again
Pick locks, teraflops, Captain Crunch, DevOps
Begin, Reagan, Cross Domain, hackers bringing Titan Rain
Ayatollas in Iran, US in Afghanistan

9/11, Sally Ride, Biba Model, suicide
Foreign debts, homeless vets, AIDE, Crack, iOS
Got collisions in the SHA, China's under martial law
BYOD, browser wars, I can't take it anymore!

We didn't start the firewall
It was always burning
Since the URL’s been turning
We didn't start the fire
No we didn't light it
But we tried to fight it
 

March 13, 2012

FUDSec post. Oldie but goodie...

Back in the Spring of 2010 I was given the rare opportunity to contribute to the FUDSec Blog.  I thought long and hard about what I could add to the site, then sat down for a whole 30 minutes of uninterruped, squirrel-less focus and created the Shpantzer Coma Scale of Vendor Lameness and FUD, AKA SCSoVLF.  Kinda has a ring to it, doesn't it...  It was in response to the overhyped marketing and ridiculous bandwagon-jumping by vendors who, due to the economy, were struggling to get a piece of the security spending pie.  When the economy shrinks, the vendors can get desperate to make their numbers and sometimes the sales and marketing machines get ahead of delivery and, you know, real software/hardware/services that actually do anything.

I've spent years as a specialty security VAR/Integrator and still consult to a couple of niche vendors so I understand that it's rough all over...  Still, I'm somewhat old school when it comes to the integrity of the sales process.  Everybody's selling something, whether their consulting services (Ohai 0-day ninjas!) or basic antivirus products trying to stay relevant in an increasingly difficult market.  Regardless, it's never a bad idea to present your wares in a way that will bring you a fanatically loyal following of qualified buyers and the referrals to friends of said qualified buyers.

Be the professional who can legitimately say "You know, I can't do that myself but I know someone who can."

This is a very small industry.  People talk and ask around.  Don't be that one clown who tries to make a quick buck by overdoing it.

I'll be updating the post right here on this site since it's been almost two years and I want to drive some more nails into the FUD coffin as best I can...

For now, here's the original, uncensored, unadulterated and unfiltered version 1.0 of the Shpantzer Coma Scale of Vendor Lameness and FUD...

http://fudsec.com/scsovlf-aka-the-shpantzer-coma-scale-of-vendo
In the previous post, leading up to RSA 2012, I mentioned the CyberWolves and the fear they instill in the hearts of infosec professionals.  Now it's time for a quick post RSA 2012 update:  High-speed photography of my CyberOwls unleashing their CyberWolf-shredding, Anti-Threat Talons during an intense table-top training exercise! 

Exclusive footage here:  http://www.youtube.com/watch?v=37MNE8tOBG4&feature=player_detailpage#t=10s

February 24, 2012

#RSAC is RBAC(K)!

Well, well, well... It's that time of the year again:  RSA Conference, the infosec class reunion!

As with my ongoing #TSASongs lampooning of the TSA, I like to drip, drip, drip or death-by-comedy my fellow tweeple with some infosec snark, for the weeks before the RSA Conference, when the vendor-PR spin machines start roaring past oughtta-be-illegal decibels.  I use the main conference hashtag #RSAC to sneak in a few sarcastic, overwrought fake vendor pitches, replete with the latest and greatest buzzwords used (and abused) by infosec vendors, analysts and press. 

Self-employed consultants like myself can do no wrong, of course, so I don't include that essential category in this ribbing ;-)

This is in many ways poking fun at what's going on in the infosec industry on any given day, not just at RSA Conference.  When the tough economy meets daily train wreck headlines of massive breaches... the vendor who shouts the loudest and scariest often gets the most leads:  http://t.co/SZDxchFO

Monty Python really gets it!

Note I didn't say the best quality leads, just the most leads...



Below please find a few of the better #RSAC tweets I dropped into the conference buzz machine. 

Enjoy!

(In)Securely,

Gal Shpantzer

-My Evening Iguana can beat up ur Night Dragon and my CC-EAL7 CyberOwls use their Anti-Threat Talons (ATT) to eat ShadyRATs 

-CyberWolves on the prowl? Swarm the threat w nocturnal CyberOwls, they target cyberwolves w Anti-Threat Talonswhere they hate it most!

-Holistically distributed, FIPS-approved, exascale, EO12333-compliant self-defending active-hackback web proxy honeypot in the cloudz

-Plz allow me2 introduce myself, I'm a con of wealth and taste, I've been round for a long long year, stole many a man's soul and faith

-So, you have problems with HIPAA SOX HITECH DITSCAP APT GLBA NIST FIPS-140 CC-EAL7 OASIS TCG NSA EO12333? My appliance does that!   (For a good laugh, search EO 12333)

-0day detecting DEP/ASLR-enabled TCG KMIP SED for over-the-horizon threats 2 NFC micropayment due Wikileaks LadyGaga DVD threat vectors  (referring to State Dep't cables leak)

-Hacktivist-aware, Privacy-enhancing, SinglePaneOfGlass SituationalAwareness of Console Management Distributed Denial of FIPS-140 DDoS


PersistentAdversarialThreatHostileEntityToilingIncessantlyCounterMeasuringAgainstReasonableKineticExigencyTrollingINventiveGroups 


(Translation: PATHETICMARKETING)

-Virtualized BYOD active-defense of API orchestration through self-healing private cloud to holistically protect from CyberWolf attack

-Wirespeed (100G) CC-EAL4+ BigData Securing, Privacy-Aware, DataLeakagePreventing, TCL-enabled iOS/Android BYONOSQL 

FYI the whole CyberWolves thing is, sadly, not my idea.  It's from a real article. :-/ http://www.dcvelocity.com/articles/20111219supply_chain_info_networks_internet_security_threat/

#CantMakeThisUp














February 22, 2012

Verification of claims made in Security Domination via Hard Drive Isolation!

Since late 2009, I've been on a roadshow called Security Domination via Hard Drive Isolation, discussing the emerging Desktop-on-a-stick, PC-in-your-pocket and other USB-based mobility and security approaches.  The niche emerged before the iThings craze really came to a full roar and is still today actively pursued as a valid approach for many use cases, including secure telework and remote access, disaster recovery and more.

There are several players in the USB hardware space that claim high-security encryption, some with a FIPS 140-2 level 3 validation from NIST.  I would generally trust these USB sticks to carry files around, as a sort of secure briefcase, from one trusted machine to another, or as a backup media that's pre-encrypted. 

Once the vendors in question start making claims that move past the secure briefcase use case, I start getting a bit concerned as to the nature of security they can provide. 

There are two schools of thought in this niche: Bootable (boot to a clean OS) vs. Bubble.  The bubble variety (by far the most common) is inherently less secure than the bootable for defeating software malware, since the bubble relies on various mechanisms that claim to defeat malware on the spinning disk of the host OS on the host machine (usually Windows).  In my mind, this is a losing proposition, considering the sophistication of the malware we're seeing out there and the pace of evolution that the 'authors' have demonstrated. 

While I've always been in awe of some of the mil-spec sticks' resistance to physical destruction, there are some claims that they make regarding the security of their extended product lines that I've challenged in the Security Domination talk.  I specifically called out the issue of untrusted host OS keystroke-logging and screenshot-grabbing (yes, that's a term..) as a problem in the bubble space.  Furthermore, I called out the inevitable destruction of the claim that the virtual (on-screen) keyboard was a solution to the problem.

Turns out that sick, er, great minds think alike!  I just found this youtube video from April 2010 that challenges the virtual keyboard security claims via a demonstration of keystroke logging of USB key unlock passwords, including input from the virtual (on-screen) keyboard. 

Here you go, virtual keyboard security is not as secure as we'd like it to be.

http://www.youtube.com/watch?v=B5mJEhg1HtU

This type of malware is (to be uncharacteristically mild) problematic for the high-security USB vendors who claim to solve several malware-related security problems without booting to a clean OS. 

Not to put too fine a point on it, please understand this:  If you're inserting a USB key into a USB port on an untrusted machine and you're not booting into a clean alternative OS, but rather piggybacking onto the untrusted, pre-pwned OS on the host machine... well then, you're putting the unlock password (and any other work you perform from the USB key's virtual OS) at risk from software keystroke loggers and screenshot grabbers, etc.  



PS Hardware keystroke loggers are a related but different issue and are not in the scope of this discussion.


January 06, 2012

Personnel Security: A Musical Journey, guided by Warren Zevon

(previously published elsewhere, now back home)


Warren Zevon: An Infosec Musical Journey

One analogy I learned early in my career is that Information security is a three-legged stool, consisting of Computer Security, Physical Security and Personnel Security.  Compromise one of these legs and the stool falls over.

In some cases involving access to highly sensitive information, personnel security involves plumbing the depths of people's personal histories, up to and including very intrusive interviews and polygraphs.  This part of information security is something that most practitioners and managers don't have to deal with, other than interfacing with HR or the personnel security office during the hiring process.

Where is the nexus between personal conduct and being trustworthy to protect sensitive information?  That depends, amongst other factors, on the level of sensitivity of the information and the type of organization granting access to the information.

Let's take a musical journey through personnel security and rediscover an old classic, Lawyers, Guns and Money, by Warren Zevon.

According to Zevon, he wrote the lyrics to Lawyers, Guns and Money on wet cocktail napkins, while on vacation in Kauai, "after a long day of improbable and grotesque mischief."

http://www.youtube.com/watch?v=S5puAN1PGQw (mostly safe for work, has one four letter word that starts with S).

Let's analyze what we can learn from Zevon's lyrics as practitioners of information security, assuming that the subject of the song has sensitive information in his head and is being targeted for exploitation:

I went home with the waitress, the way I always do
How was I to know she was with the Russians too?

This is a classic honeypot situation, where an adversary uses an attractive person to get the target into a compromising position, in quite the literal sense, after which the target may be coerced to betray his country or captured for interrogation, or just killed.

Honeypots are fixtures of spy movie plots, from the James Bond franchise to Munich to The Good Shepherd.

One real life case of 'she was with the Russians' is that of Clayton Lonetree, who was in a sensitive US embassy security position in Moscow... http://www.hanford.gov/c.cfm/oci/ci_spy.cfm?dossier=72

A more recent example, more on point to information security, is the case of the missing Blackberry belonging to the aide to the British Prime Minister during a visit to China.
http://council.smallwarsjournal.com/archive/index.php/t-5775.html

More lyrics:

I was gambling in Havana
I took a little risk
Send lawyers, guns and money
Dad, get me outta this

This is another classic weakness that can result in becoming a more exploitable target, since gambling can become an addiction and result in grave financial hardship. Eventually someone with bad intentions may notice the weakness and may attempt to recruit the subject by using coercion or quid pro quo services demanded by people seeking cooperation from the target.  "We give you money to take care of the gambling debts, the loan sharks won't break your bones and hey, no big deal, it's just some information, not like it's gonna hurt anybody..."

Next, we hear Zevon's character denying responsibility for his situation, declaring himself a victim of circumstance and bad luck:

I'm the innocent bystander
and somehow I got stuck
between a rock and a hard place
and I'm down on my luck

This denial of responsibility displays a lack of maturity and ability to recognize and correct personal flaws, which we all have to some degree.  This is perhaps the worst offense committed by the subject of the song.

The US State Department website has a listing of the elements of the Whole Person concept that may be relevant to the adjudication of a background investigation for a security clearance.  (Note that different parts of the US Government have different security-related priorities and bureacratic mechanisms, so there is not one place for a federal clearance).

http://www.state.gov/m/ds/clearances/60321.htm

If you read through the webpage, you'll find that Zevon's lyrics included behavior that would fall under several areas of concern in the Adjudicative Guidelines for Determining Eligibility to Classified Information:

Guideline D on Sexual Behavior, referring to "sexual behavior that causes an individual to be vulnerable to coercion, exploitation, or duress" as one of the specific concerns in the guideline.

Guideline F on Financial Considerations (explicitly mentioning compulsive gambling), and

Guideline E on Personal Conduct, which includes lack of full and open cooperation with investigators who are charged with determining if the subject of the investigation is trustworthy enough to obtain and keep a clearance. Specifically,  "Refusal to provide full, frank and truthful answers to lawful questions of investigators, security officials, or other official representatives in connection with a personnel security or trustworthiness determination."

One good site for more specific examples of personnel security decisions is the Defense Office of Hearings and Appeals (DOHA), you can read about actual situations where people were denied clearances or lost them and appealed their cases to DOHA.  These cases illustrate the balancing act involved in deciding whether to grant or deny a clearance and the legal underpinnings of the clearance adjudication process.

Many years of actual cases, including the latest ones from December 2011:
http://www.dod.gov/dodgc/doha/industrial/2011.html

The Adjudicative Desk Reference may be used as a guide by administrative judges and others in determining the outcome of personnel security matters.  http://www.dhra.mil/perserec/products.html#ADR   The reference was created by the Defense Department's Personnel Security Research Center (PERSEREC) as a tool to assist in making difficult decisions regarding suitability for cleared work.

Other products from PERSEREC may be of interest to those involved in HR, Insider Threat and Workplace Violence and other areas of research: Use with caution, this is not an exact science...  The first link includes a pointer to a 2011 "Ethnographic Analysis of Second Life."  http://www.dhra.mil/perserec/reports.html and  http://www.dhra.mil/perserec/products.html

July 21, 2011

The Cons They Are a Changin'

I took some time off of #TSASongs to bring you this tribute to BSides security conferences.

http://www.securitybsides.com/


Please sing along with me, to the tune of Bob Dylan's The Times They Are a Changin'

A Parody with a message...


Come gather round Tweeple wherever you roam
and admit that the BSides around you have grown
and accept it that soon you'll need skillz that are honed
if your time to you is worth savin
then you better start learnin or you’ll sink like a stone

for the times they are a changin


come PR flacks and keynotes who dominate with your spend
and keep your eyes wide the chance won’t come again
and don’t hype too soon for the FUD’s still in spin
there’s no tellin who that its shamin'
for the loser now will be later to win

for the times they are a changin

come vendors and pitchmen, please heed the call
don’t sell in the doorway don’t flog up the hall
for he that gets hurt will be he who cold called
the battle outside ragin
will soon shake your Windows, bypass your firewalls

for the times they are a changin

come conference planners throughout the land
and don’t criticize what you can’t understand
our cons and our parties are beyond your command
your old road is rapidly aging
please get outta the new one if you can’t lend your hand

for the times they are a changin

the line it is drawn, the curse it is cast
the expensive cons now will lose people fast
as the closed cons now will later be past
the order is rapidly fadin
but the BSides con is a guaranteed blast

for the times they are a changin

---------------------------------------------------------------


Dedicated to the BSides crew and volunteers.

All my (g)love,


@Shpantzer