Conducting a Security Audit: An Introductory Overview
The word "audit" can send shivers down the spine of the most battle-hardened executive. It means that an outside organization is going to conduct a formal written examination of one or more crucial components of the organization. Financial audits are the most common examinations a business manager encounters. This is a familiar area for most executives: they know that financial auditors are going to examine the financial records and how those records are used. They may even be familiar with physical security audits. However, they are unlikely to be acquainted with information security audits; that is, an audit of how the confidentiality, availability and integrity of an organization's information is assured. They should be. An information security audit is one of the best ways to determine the security of an organization's information without incurring the cost and other associated damages of a security incident.
Tuesday, May 27, 2003
ISECOM - Institute for Security and Open Methodologies
Security Testing
OSSTMM - Open Source Security Testing Methodology Manual
OSSTMM Shortcuts
Internal Security Testing
BSTA Workbook - Business Security Testing and Analysis Workbook
Application Security
SPSMM - Secure Programming Standards Methodology Manual
Theses
Security Tools
Operational Tools
Development
Open Protocol Resource
Security Training
JACK - Jack of all Trades Security Testing Training Supplement
OPST - OSSTMM Professional Security Tester Certification
OPSA - OSSTMM Professional Security Analyst Certification
OPSS - OSSTMM Professional Security Series
Hacker High School
Incident Handling
SIPES - Security Incident Pollicy Enforcement System
Business Integrity Testing
Software Quality Testing
STICK - Software Testing Checklist
Security Testing
OSSTMM - Open Source Security Testing Methodology Manual
OSSTMM Shortcuts
Internal Security Testing
BSTA Workbook - Business Security Testing and Analysis Workbook
Application Security
SPSMM - Secure Programming Standards Methodology Manual
Theses
Security Tools
Operational Tools
Development
Open Protocol Resource
Security Training
JACK - Jack of all Trades Security Testing Training Supplement
OPST - OSSTMM Professional Security Tester Certification
OPSA - OSSTMM Professional Security Analyst Certification
OPSS - OSSTMM Professional Security Series
Hacker High School
Incident Handling
SIPES - Security Incident Pollicy Enforcement System
Business Integrity Testing
Software Quality Testing
STICK - Software Testing Checklist
Thursday, May 22, 2003
Passive Network Traffic Analysis
Network IDS devices use passive network monitoring extensively to detect possible threats. Through passive monitoring, a security admin can gain a thorough understanding of the network's topology: what services are available, what operating systems are in use, and what vulnerabilities may be exposed on the network. Much of this data can be gathered in an automated, non-intrusive manner through the use of standard tools, which will be discussed later in this article. While the concepts presented here are not difficult to understand, the reader should have at least an intermediate understanding of IP and a base-level familiarity with the operation of network sniffers.
Network IDS devices use passive network monitoring extensively to detect possible threats. Through passive monitoring, a security admin can gain a thorough understanding of the network's topology: what services are available, what operating systems are in use, and what vulnerabilities may be exposed on the network. Much of this data can be gathered in an automated, non-intrusive manner through the use of standard tools, which will be discussed later in this article. While the concepts presented here are not difficult to understand, the reader should have at least an intermediate understanding of IP and a base-level familiarity with the operation of network sniffers.
Tuesday, May 20, 2003
Securing Apache: Step-by-Step
This article shows in a step-by-step fashion, how to install and configure the Apache 1.3.x Web server in order to mitigate or avoid successful break-in when new vulnerabilities in this software are found.
This article shows in a step-by-step fashion, how to install and configure the Apache 1.3.x Web server in order to mitigate or avoid successful break-in when new vulnerabilities in this software are found.
Friday, May 16, 2003
Cain & Abel is a password recovery tool for Microsoft Operating Systems. It allows easy recovery of various kind of passwords by sniffing the network, cracking encrypted passwords using Dictionary & Brute-Force attacks, decoding scrambled passwords, revealing password boxes and analyzing routing protocols.
IRS scans for IP restrictions set for a particular service on a Host. It combines "ARP Poisoning" and 'Half-Scan' techniques and tries totally spoofed TCP connections to the selected port of the Target. IRS is not a port Scanner but a 'valid source IP address' Scanner for a given service.
sTerm is a Telnet client with a unique feature. It can establish an entire bi-directional Telnet session to a target host never sending your real IP and MAC addresses in any packet. By using "ARP Poisoning", "MAC Spoofing" and "IP Spoofing" techniques sTerm can effectively bypass ACLs, Firewall rules and IP restrictions on servers and network devices. the connection will be done impersonating a Trusted Host.
cPfPc (Cisco PIX Firewall Password Calculator) produces the encrypted form of Cisco PIX enable mode passwords without the need to access the device.
ArpWorks is an utility for sending customized 'ARP announce' packets over the network. All ARP parameters, including the Ethernet Source MAC address (the phisical address of your network card) can be changed as you like. Other features are: IP to MAC resolver, subnet MAC discovery, host isolation, packets redirection, general IP confict.
IRS scans for IP restrictions set for a particular service on a Host. It combines "ARP Poisoning" and 'Half-Scan' techniques and tries totally spoofed TCP connections to the selected port of the Target. IRS is not a port Scanner but a 'valid source IP address' Scanner for a given service.
sTerm is a Telnet client with a unique feature. It can establish an entire bi-directional Telnet session to a target host never sending your real IP and MAC addresses in any packet. By using "ARP Poisoning", "MAC Spoofing" and "IP Spoofing" techniques sTerm can effectively bypass ACLs, Firewall rules and IP restrictions on servers and network devices. the connection will be done impersonating a Trusted Host.
cPfPc (Cisco PIX Firewall Password Calculator) produces the encrypted form of Cisco PIX enable mode passwords without the need to access the device.
ArpWorks is an utility for sending customized 'ARP announce' packets over the network. All ARP parameters, including the Ethernet Source MAC address (the phisical address of your network card) can be changed as you like. Other features are: IP to MAC resolver, subnet MAC discovery, host isolation, packets redirection, general IP confict.
Saturday, May 10, 2003
Top 75 Network Security Tools
In May of 2003, I conducted a survey of Nmap users from the nmap-hackers mailing list to determine their favorite security tools. Each respondent could list up to 8. This was a followup to the highly successful June 2000 Top 50 list. An astounding 1854 people responded in '03, and their recommendations were so impressive that I have expanded the list to 75 tools! Anyone in the security field would be well advised to go over the list and investigate tools they are unfamiliar with. I discovered several powerful new tools this way. I also plan to point newbies to this page whenever they write me saying "I do not know where to start".
In May of 2003, I conducted a survey of Nmap users from the nmap-hackers mailing list to determine their favorite security tools. Each respondent could list up to 8. This was a followup to the highly successful June 2000 Top 50 list. An astounding 1854 people responded in '03, and their recommendations were so impressive that I have expanded the list to 75 tools! Anyone in the security field would be well advised to go over the list and investigate tools they are unfamiliar with. I discovered several powerful new tools this way. I also plan to point newbies to this page whenever they write me saying "I do not know where to start".
Wednesday, May 07, 2003
Wellenreiter v1.8 - scanning for dummies
Perl Wellenreiter-1.8 has been released right now. Get it at our downloadsection. Wellenreiter is the first and only Linux Wireless scanner that does not need configurations by the user. It detects its environment automaticly. As long as the needed modules and drivers are present, Wellenreiter find its settings. As i said in the topic,scanning for dummies.
Perl Wellenreiter-1.8 has been released right now. Get it at our downloadsection. Wellenreiter is the first and only Linux Wireless scanner that does not need configurations by the user. It detects its environment automaticly. As long as the needed modules and drivers are present, Wellenreiter find its settings. As i said in the topic,scanning for dummies.
Practical examples for establishing Web service security in .NET
Instead of abstract theories, here are some examples to provide an easy and quick way to accomplish a rather complex task
Because security is one of the most fundamental aspects in the development and deployment of a Web service, there are a myriad of articles, documentation, and samples of how to make it secure. Yet the majority of this information is conveyed as abstract theory, as opposed to practical, real-world implementation.
Here, I'll share some practical examples on Web service security in .NET, not just abstract theories. These examples provide an easy and fast way to accomplish a rather complex task.
Let's explore programmatic Web service security using Visual Studio .NET to implement a custom, stateful SOAP Header to authenticate a consumer before allowing a method to execute. I will also show you how to remove public access to your Web service, how to prevent anonymous users from obtaining your WSDL file, and how to implement your Web service in an unauthorised manner. I will then explain how you can wrap your entire Web service implementation in a highly secure, encrypted format.
Instead of abstract theories, here are some examples to provide an easy and quick way to accomplish a rather complex task
Because security is one of the most fundamental aspects in the development and deployment of a Web service, there are a myriad of articles, documentation, and samples of how to make it secure. Yet the majority of this information is conveyed as abstract theory, as opposed to practical, real-world implementation.
Here, I'll share some practical examples on Web service security in .NET, not just abstract theories. These examples provide an easy and fast way to accomplish a rather complex task.
Let's explore programmatic Web service security using Visual Studio .NET to implement a custom, stateful SOAP Header to authenticate a consumer before allowing a method to execute. I will also show you how to remove public access to your Web service, how to prevent anonymous users from obtaining your WSDL file, and how to implement your Web service in an unauthorised manner. I will then explain how you can wrap your entire Web service implementation in a highly secure, encrypted format.
Tuesday, May 06, 2003
MUSC Computer Use Policy
The University recognizes its legal and social obligations to respect the privacy of the authorized users of its computing and network resources. However, users must recognize that the confidentiality of their electronic communications cannot be guaranteed by the University. Moreover, the University reserves the right to audit or monitor any uses of its computing and network resources when necessary to ensure compliance with University policy, and with federal, state and local law.
The University network provides its authorized users with access to many classes of privileged information. Users must maintain the confidentiality and integrity of the information they access, and must not use privileged information for any purpose not explicitly authorized.
The University's computing and network resources exist to support the University's missions of teaching, research, patient care and public service. Incidental personal use of these resources by authorized users is permitted only to the extent that such use is lawful and ethical, does not conflict with the University's missions, does not interfere with other authorized users, and does not cause additional expense to the University.
The University recognizes its legal and social obligations to respect the privacy of the authorized users of its computing and network resources. However, users must recognize that the confidentiality of their electronic communications cannot be guaranteed by the University. Moreover, the University reserves the right to audit or monitor any uses of its computing and network resources when necessary to ensure compliance with University policy, and with federal, state and local law.
The University network provides its authorized users with access to many classes of privileged information. Users must maintain the confidentiality and integrity of the information they access, and must not use privileged information for any purpose not explicitly authorized.
The University's computing and network resources exist to support the University's missions of teaching, research, patient care and public service. Incidental personal use of these resources by authorized users is permitted only to the extent that such use is lawful and ethical, does not conflict with the University's missions, does not interfere with other authorized users, and does not cause additional expense to the University.
Scapy
Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery, packet sniffer, etc. It can for the moment replace hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, tethereal, p0f
Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery, packet sniffer, etc. It can for the moment replace hping, 85% of nmap, arpspoof, arp-sk, arping, tcpdump, tethereal, p0f
Projects of Syn Ack Labs
stegtunnel hides data in the IPID and initial sequence numbers of TCP connections.
lsrtunnel will spoof connections to a host that reverses source routed packets as an arbitrary IP address.
lsrscan is a tool to determine what remote hosts do with loose source routed IP datagrams.
crypt-ml attempts to extend OpenPGP encryption to mailing lists.
is a Linux-based stealthy LKM detector, useful for honeypots and the like.
stegtunnel hides data in the IPID and initial sequence numbers of TCP connections.
lsrtunnel will spoof connections to a host that reverses source routed packets as an arbitrary IP address.
lsrscan is a tool to determine what remote hosts do with loose source routed IP datagrams.
crypt-ml attempts to extend OpenPGP encryption to mailing lists.
Tuesday, April 29, 2003
The NoCat Community Wireless Network Project
Connect to the network using DHCP, you bring up a web browser, type in any url and you'll get an authentication screen. Authenticate first then you can use the network etc.
Connect to the network using DHCP, you bring up a web browser, type in any url and you'll get an authentication screen. Authenticate first then you can use the network etc.
Saturday, April 26, 2003
OpenBSD IPsec clients
This page is for people who wants to use IPsec clients with OpenBSD as an IPsec gateway.
This page is for people who wants to use IPsec clients with OpenBSD as an IPsec gateway.
Thursday, April 24, 2003
Detecting NAT Devices using sFlow
Unauthorized NAT (Network Address Translation) devices can be a significant security problem. Typically the NAT device will appear to the network administrator as an end host and it will authenticate itself onto the network. However, the NAT device provides unrestricted access to any number of hosts connecting to it directly, or more troublingly via wireless (Wi-Fi 802.11). Wi-Fi is a particular problem since it allows access to the network from a considerable distance, allowing unauthorized access without even entering the building.
Reliably detecting NAT devices is difficult since they are virtually indistinguishable from legitimate hosts. This paper describes how the detailed, pervasive, traffic monitoring capabilities of sFlow (RFC 3176) can be used to identify NAT devices on a network.
Unauthorized NAT (Network Address Translation) devices can be a significant security problem. Typically the NAT device will appear to the network administrator as an end host and it will authenticate itself onto the network. However, the NAT device provides unrestricted access to any number of hosts connecting to it directly, or more troublingly via wireless (Wi-Fi 802.11). Wi-Fi is a particular problem since it allows access to the network from a considerable distance, allowing unauthorized access without even entering the building.
Reliably detecting NAT devices is difficult since they are virtually indistinguishable from legitimate hosts. This paper describes how the detailed, pervasive, traffic monitoring capabilities of sFlow (RFC 3176) can be used to identify NAT devices on a network.
Thursday, April 17, 2003
Cisco Support for Lawful Intercept In IP Networks
Service providers are being asked to meet lawful intercept requirements of IP networks for voice as well as data in a variety of countries worldwide. Service Provider requirements vary from country to country but some requirements remain common even though details such as delivery formats may differ. The objective of this document is to describe how a Service Provider can support lawful intercept with a general solution that has a minimum set of common interfaces. This document does not deal with legal requirements or obligations.
Service providers are being asked to meet lawful intercept requirements of IP networks for voice as well as data in a variety of countries worldwide. Service Provider requirements vary from country to country but some requirements remain common even though details such as delivery formats may differ. The objective of this document is to describe how a Service Provider can support lawful intercept with a general solution that has a minimum set of common interfaces. This document does not deal with legal requirements or obligations.
Tuesday, April 15, 2003
PKI... Why Go Through the Hassle?
As e-mail increasingly substitutes the use of letters and faxes (also to governmental bodies) and as commercial transactions on the web get more and more important to organisations, the need for secure communications equally grows, especially with spoof attacks, interception of transmissions and other hacking methods becoming more widespread and getting more “intelligent” every day. So, if the web is to achieve its true (commercial) potential, it is important that the right technological infrastructure is in place. Public Key Infrastructure (PKI) enabled by cryptography provides a secure basis. Digital signatures use public key infrastructure.
As e-mail increasingly substitutes the use of letters and faxes (also to governmental bodies) and as commercial transactions on the web get more and more important to organisations, the need for secure communications equally grows, especially with spoof attacks, interception of transmissions and other hacking methods becoming more widespread and getting more “intelligent” every day. So, if the web is to achieve its true (commercial) potential, it is important that the right technological infrastructure is in place. Public Key Infrastructure (PKI) enabled by cryptography provides a secure basis. Digital signatures use public key infrastructure.
Digital Forensics Lesson Learned Repository
The use of computers to store evidence by criminals has become more prevalent as our society has become increasingly computerized. It is now routine to find calendars, e-mails among co-conspirators, financial account information, detailed plans of crimes, telephone numbers and other artifacts that can be used as evidence in a criminal case stored on a hard drive, PDA or cell phone. However, every new computerized device or new software upgrade poses additional challenges to computer forensics experts who are already thinly stretched as case loads mount. There is little opportunity for innovation and research, and no slack to allow the luxury of reinventing the wheel for similar cases.
A "Lesson Learned" is defined as: "A good work practice or innovative approach that is captured and shared to promote repeat application, or an adverse work practice or experience that is captured and shared to avoid recurrence[1]." In order to facilitate sharing information on computer forensics, we are developing a web-based Lessons-Learned Repository (LLR) to facilitate both the contribution and retrieval of Lessons.
The LLR will initially be populated through contributions from a set of selected computer forensics specialists from the Law Enforcement community, the results of an analysis of the transcripts of past court cases involving electronic evidence and standardized procedures for collecting the data from a device in a legally admissible manner [2]. Once the Repository is on-line, it is anticipated additional Lessons will continue to be contributed from the global computer forensics community, as well as being augmented by manufacturers willing to post contact information for product-specific inquiries.
The use of computers to store evidence by criminals has become more prevalent as our society has become increasingly computerized. It is now routine to find calendars, e-mails among co-conspirators, financial account information, detailed plans of crimes, telephone numbers and other artifacts that can be used as evidence in a criminal case stored on a hard drive, PDA or cell phone. However, every new computerized device or new software upgrade poses additional challenges to computer forensics experts who are already thinly stretched as case loads mount. There is little opportunity for innovation and research, and no slack to allow the luxury of reinventing the wheel for similar cases.
A "Lesson Learned" is defined as: "A good work practice or innovative approach that is captured and shared to promote repeat application, or an adverse work practice or experience that is captured and shared to avoid recurrence[1]." In order to facilitate sharing information on computer forensics, we are developing a web-based Lessons-Learned Repository (LLR) to facilitate both the contribution and retrieval of Lessons.
The LLR will initially be populated through contributions from a set of selected computer forensics specialists from the Law Enforcement community, the results of an analysis of the transcripts of past court cases involving electronic evidence and standardized procedures for collecting the data from a device in a legally admissible manner [2]. Once the Repository is on-line, it is anticipated additional Lessons will continue to be contributed from the global computer forensics community, as well as being augmented by manufacturers willing to post contact information for product-specific inquiries.
Warren Harrison
Warren's research interests are focused on the areas of software engineering, computer forensics and mobile wireless applications. He is currently Editor-in-Chief of IEEE Software Magazine, whose mission is "building the community of leading software practitioners." He is also past-Editor-in-Chief of Empirical Software Engineering and the Software Quality Journal.
Warren's research interests are focused on the areas of software engineering, computer forensics and mobile wireless applications. He is currently Editor-in-Chief of IEEE Software Magazine, whose mission is "building the community of leading software practitioners." He is also past-Editor-in-Chief of Empirical Software Engineering and the Software Quality Journal.
Subscribe to:
Posts (Atom)
