<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-887492972197912983</id><updated>2011-11-30T10:34:01.591-08:00</updated><category term='hackerhafe hacker'/><category term='PCI DSS requirement 6.6'/><category term='packing backdoors'/><category term='automated xss'/><category term='hackersafe website hacked'/><category term='application security testing tools'/><category term='UK government data breach'/><category term='virgin media data breach'/><category term='hackersafe'/><category term='PCI 1.2'/><category term='IWTC'/><category term='elitewrap'/><category term='Cross Site Scripting'/><category term='IWTC 2008'/><category term='compliance with requirement 6.6'/><category term='PCI DSS compliance'/><category term='PCI DSS 1.2'/><category term='virgin media security breach'/><category term='stealth backdoor'/><category term='bypass antivirus'/><category term='Top Secret documents on train'/><category term='PCI DSS'/><category term='tini.exe hex editing'/><category term='elitewrap tutorial'/><category term='automated sql injection'/><category term='virgin media security'/><category term='backtrack live cd'/><category term='Cotton Traders breach'/><category term='UK Top Secret documents'/><category term='modify backdoor'/><category term='backtrack'/><category term='OWASP Ireland'/><category term='David Rook'/><category term='PCI Standard version 1.2'/><category term='data breach'/><category term='backtrack pauldotcom'/><category term='Preventing XSS'/><category term='PCI compliance'/><category term='automated security testing'/><category term='modify tini.exe'/><category term='virgin security'/><category term='XSS'/><category term='PCI requirement 6.6'/><category term='Preventing Cross Site Scripting'/><title type='text'>Security ninja</title><subtitle type='html'>My ramblings about information security</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>34</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-6017881960043818768</id><published>2008-10-07T13:17:00.000-07:00</published><updated>2008-10-07T13:22:26.316-07:00</updated><title type='text'>The security ninja has left the building</title><content type='html'>Well as usual things have happened much sooner than I had planned!&lt;br /&gt;&lt;br /&gt;The new blog and forum went live over the weekend and now the new Security Ninja website is live. I'm happy with the way it looks at the moment and work is ongoing but from today onwards I will not be posting to this blog anymore.&lt;br /&gt;&lt;br /&gt;The Security Ninja website can be found &lt;a href="http://securityninja.co.uk"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I look forward to seeing everyone on the new site!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-6017881960043818768?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/6017881960043818768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=6017881960043818768' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6017881960043818768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6017881960043818768'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/10/security-ninja-has-left-building.html' title='The security ninja has left the building'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-791818339666323023</id><published>2008-10-03T14:07:00.000-07:00</published><updated>2008-10-03T14:25:12.626-07:00</updated><title type='text'>News from the ninja</title><content type='html'>Hi everyone,&lt;br /&gt;&lt;br /&gt;I just wanted to keep everyone up to date with what is going on with Security Ninja. I've been crazy busy with my company being close to our annual PCI audit but of more interest to you guys is the changes coming to Security Ninja.&lt;br /&gt;&lt;br /&gt;As I have been working away on the various tutorials I'm writing I think the blog format isn't quite right to host everything I plan to produce. I love my blog and its going to stay around but Security Ninja is expanding to provide more than just a blog! &lt;br /&gt;&lt;br /&gt;I have a few ideas which I plan to put on the new site, for example I would like a wiki for application security, a security forum, a whitepapers section and a tutorial section. On top of that lot I will of course be keeping the blog going!&lt;br /&gt;&lt;br /&gt;The new blog can be found &lt;a href="http://securityninja.co.uk/blog/"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I plan on bringing the forum online over the weekend and the rest of the site over the next month.&lt;br /&gt;&lt;br /&gt;If anyone has ideas for the new site then give me a shout on the blog or my cool new email address - securityninja at securityninja.co.uk :-)&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-791818339666323023?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/791818339666323023/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=791818339666323023' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/791818339666323023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/791818339666323023'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/10/news-from-ninja.html' title='News from the ninja'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-7892682534551752086</id><published>2008-10-02T13:27:00.000-07:00</published><updated>2008-10-02T13:47:30.769-07:00</updated><title type='text'>PCI version 1.2 released</title><content type='html'>Everyone who reads my blog and has spoken to me knows my feelings on the lack of real changes in the new version of the PCI DSS standard, those feelings aside I feel people should read the new version of the standard available &lt;a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For those of you who feel the standard is sufficient or don't understand my issues with the standard I have listed three examples below that I feel the standard should address:&lt;br /&gt;&lt;br /&gt;Virtualisation&lt;br /&gt;&lt;br /&gt;Almost every company seems to be implementing virtualisation technologies within their infrastructure without understanding the new security issues this potentially raises. More and more researchers are attacking virtualisation technologies which means more and more vulnerabilities will be found (for example, Blackhat USA07 had 2 presentations of virtualisation security issues compared to 20 at Blackhat USA08).&lt;br /&gt;&lt;br /&gt;I think the standard needed to include specific requirements for this technology.&lt;br /&gt;&lt;br /&gt;Cloud Computing&lt;br /&gt;&lt;br /&gt;Maybe not such a hot technology right now but it will continue to rise in popularity because of the low cost of ownership this technology can deliver. Cloud computing makes even virtualisation look expensive!&lt;br /&gt;&lt;br /&gt;In the current economic climate companies will aim to save as much money as possible and cloud computing will deliver serious savings. So what is my problem? With cloud computing you don't actually know where your data is, well you know its in the cloud......&lt;br /&gt;&lt;br /&gt;I can't see how cloud computing can be PCI DSS compliant but companies who need to be complaint may just go down this route. I get the feeling that before the next version of the standard is released this may become an issue the council needs to address.&lt;br /&gt;&lt;br /&gt;Secure Application Development&lt;br /&gt;&lt;br /&gt;Considering secure application development is my niche I will always look for more on this particular topic. I have always had a problem with requirement 6.6 and I still do. I'm not really keen on the idea of using only a WAF (Web Application Firewall) instead of a really good secure development process. I don't care what the marketing departments of the WAF vendors say you cannot prevent attacks such as CSRF (Cross Site Request Forgery) with these devices.&lt;br /&gt;&lt;br /&gt;Let me know what you think!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-7892682534551752086?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/7892682534551752086/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=7892682534551752086' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7892682534551752086'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7892682534551752086'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/10/pci-version-12-released.html' title='PCI version 1.2 released'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-8493846253696273824</id><published>2008-09-25T11:20:00.000-07:00</published><updated>2008-09-25T11:23:29.368-07:00</updated><title type='text'>My (IN)SECURE Magazine Article</title><content type='html'>Hi everybody,&lt;br /&gt;&lt;br /&gt;The September edition of (IN)SECURE Magazine has been published and contains my article on Secure Web Application Development.&lt;br /&gt;&lt;br /&gt;You can download the magazine &lt;a href="http://www.net-security.org/insecuremag.php"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As always feedback is more than welcome!&lt;br /&gt;&lt;br /&gt;My Burp Suite tutorial is still work in progress, I have had a few requests to include more content than I originally planned so hold tight everyone!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-8493846253696273824?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/8493846253696273824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=8493846253696273824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8493846253696273824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8493846253696273824'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/09/my-insecure-magazine-article.html' title='My (IN)SECURE Magazine Article'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-8078057146306046395</id><published>2008-09-13T02:04:00.000-07:00</published><updated>2008-09-13T02:24:15.525-07:00</updated><title type='text'>Burp Suite Tutorial</title><content type='html'>Just a quick note to say the tutorial for Burp Suite is in progress. &lt;br /&gt;&lt;br /&gt;I have been in contact with Portswigger who is the developer behind the Burp Suite so the tutorial will have his input as well as mine.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-8078057146306046395?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/8078057146306046395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=8078057146306046395' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8078057146306046395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8078057146306046395'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/09/burp-suite-tutorial.html' title='Burp Suite Tutorial'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-3117372307945253629</id><published>2008-09-09T13:11:00.000-07:00</published><updated>2008-09-09T13:29:21.918-07:00</updated><title type='text'>SCADA system vulnerability and exploit code</title><content type='html'>For those of you who don't know what a SCADA system is think core backbone systems for a country or countries. Power grids, water systems and defense systems to name just a few. A brief overview can be found &lt;a href="http://en.wikipedia.org/wiki/SCADA"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Often these systems have operated on very old (Win 3.x and OS2) systems which people are to scared to update. The defense has always been "oh we don't connect this core systems to the internet so we are fine". That isn't always the case anymore, more and more SCADA systems are getting internet access whether it is authorised or not. A penetration tester friend of mine recently told me how he was auditing a SCADA infrastructure that had 5 connections to the internet that had never been authorised. Normally I wouldn't have paid much attention but these are systems which control almost everything we use and rely upon delay, cyber warfare anyone?&lt;br /&gt;&lt;br /&gt;So why should I write this post now? Well a recent vulnerability discovered by &lt;a href="http://www.theregister.co.uk/2008/09/08/scada_exploit_released/"&gt;Core Technologies&lt;/a&gt; has had exploit code written for it. This exploit code has been made available as a module for Metasploit for anyone to download. I do not encourage any kind of unlawful hacking but surely someone will take advantage of this and take something very important down?&lt;br /&gt;&lt;br /&gt;I won't reproduce someone else's work so &lt;a href="http://www.milw0rm.com/papers/221"&gt;here&lt;/a&gt; is the paper written by the exploit writer Kevin Finisterre. &lt;br /&gt;&lt;br /&gt;As always if you have any questions or comments then fire away.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-3117372307945253629?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/3117372307945253629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=3117372307945253629' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3117372307945253629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3117372307945253629'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/09/scada-system-vulnerability-and-exploit.html' title='SCADA system vulnerability and exploit code'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-5903905613903318839</id><published>2008-09-09T12:41:00.000-07:00</published><updated>2008-09-09T13:11:08.578-07:00</updated><title type='text'>A few updates....</title><content type='html'>A bit apology for the amount time that has elapsed since my last post. Moving house took up more of my time than I had planned!!&lt;br /&gt;&lt;br /&gt;I'm moved and settled so back to business as usual from today on.&lt;br /&gt;&lt;br /&gt;Whilst I have been away I have agreed to become a columnist with &lt;a href="http://www.bloginfosec.com/"&gt;bloginfosec&lt;/a&gt; and my first article should be posted in the next couple of weeks. I recommend anyone who reads this blog to also take a look at the content over at &lt;a href="http://www.bloginfosec.com/"&gt;bloginfosec&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Secondly my article I have written for (in)secure magazine which discusses secure web application development and integrating security into a dvelopment lifecycle will be published this month. You can subscribe to the magazine for free at &lt;a href="http://www.net-security.org/insecuremag.php"&gt;net-security.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Last but not least on the updates. OWASP have announced that an EU Summit will be held in Portugal this November and will be discussing many important issues! More information can be found &lt;a href="http://www.owasp.org/index.php/OWASP_EU_Summit_2008"&gt;here.&lt;/a&gt; I will be going along to the summit so if any readers on going along then drop me a line and we can hook up.&lt;br /&gt;&lt;br /&gt;I thought I would let you all know what content I plan to add to the blog in the coming weeks. Some of it is based on my own interests and some of it is based on the search queries that people are using to land of my little corner of the web!&lt;br /&gt;&lt;br /&gt;Burp Suite Tutorial&lt;br /&gt;&lt;br /&gt;Grendel Scan Tutorial&lt;br /&gt;&lt;br /&gt;Metasploit Tutorial&lt;br /&gt;&lt;br /&gt;Samurai Live CD Review&lt;br /&gt;&lt;br /&gt;Backtrack 3 Review&lt;br /&gt;&lt;br /&gt;SQL Ninja Tutorial&lt;br /&gt;&lt;br /&gt;Those will be the more technical posts that are coming up in the short term. I will be posting my usual comments on the news and security vulnerabilities.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-5903905613903318839?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/5903905613903318839/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=5903905613903318839' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5903905613903318839'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5903905613903318839'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/09/few-updates.html' title='A few updates....'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1682131175784867750</id><published>2008-08-25T10:49:00.001-07:00</published><updated>2008-08-25T10:50:55.253-07:00</updated><title type='text'>Blackhat USA 08</title><content type='html'>The presentation materials are now available for the Blackhat USA 2008 conference, go and read them &lt;a href="https://www.blackhat.com/html/bh-usa-08/bh-usa-08-archive.html"&gt;all&lt;/a&gt; :-)&lt;br /&gt;&lt;br /&gt;Sorry for the lack of posts, I'm moving house in 2 days so its all very hectic at the moment!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1682131175784867750?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1682131175784867750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1682131175784867750' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1682131175784867750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1682131175784867750'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/08/blackhat-usa-08.html' title='Blackhat USA 08'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-4027185094891163638</id><published>2008-08-19T11:56:00.000-07:00</published><updated>2008-08-19T14:06:30.192-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI Standard version 1.2'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI 1.2'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS 1.2'/><title type='text'>PCI DSS version 1.2</title><content type='html'>I have come across a document from the &lt;a href="https://www.pcisecuritystandards.org/security_standards/supporting_documents.shtml"&gt;PCI DSS Council&lt;/a&gt; today which has a summary of the changes that will be included in the next version of the standard.&lt;br /&gt;&lt;br /&gt;I will reserve my full opinion on the changes until I see the final version of the standard. I will say I'm a bit disappointed if the document lists all of the changes to the standard as it doesn't even update requirement 6.5 to the latest OWASP top ten...&lt;br /&gt;&lt;br /&gt;I will post more when the final version of the standard is released.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-4027185094891163638?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/4027185094891163638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=4027185094891163638' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4027185094891163638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4027185094891163638'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/08/pci-dss-version-12.html' title='PCI DSS version 1.2'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-2498488316051209471</id><published>2008-08-14T12:04:00.000-07:00</published><updated>2008-08-19T14:02:47.497-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='application security testing tools'/><title type='text'>Application Security Testing Tools</title><content type='html'>I have been asked a few times recently to tell people what tools I use when I'm testing web applications for security issues.&lt;br /&gt;&lt;br /&gt;I always find that a mixture of tools can be used to find potential security issues in applications but to exploit these issues it always seems to be a manual effort. I don't mind that, I get a good feeling when I hack things!&lt;br /&gt;&lt;br /&gt;I will list the tools I use along with a short description, I'm not writing this post as a tutorial - if anyone wants tutorials then let me know and I will see what I can do.&lt;br /&gt;&lt;br /&gt;My favourite tool would be the &lt;a href="http://portswigger.net/suite/"&gt;Burp Suite&lt;/a&gt; from Portswigger. We have recently purchased a site license at work - I think that says a lot for this tool. Burp Suite offers many different modules that can help you test application security. I like the intruder module the most, this allows me to input the strings I would use in manual tests very quickly and in a few different ways. My test inputs file is nearly 400 different inputs so the intruder module is a lifesaver. The Burp Suite is available as a free or commercial tool, I recommend that anyone interested in web application security testing grabs a copy and has a play with it.&lt;br /&gt;&lt;br /&gt;The Burp Suite can also be extended using the IBurpExtender, if any developers reading this want to collaborate on a project then drop me a line. I have a few ideas that I would love to implement using the Burp Extender.&lt;br /&gt;&lt;br /&gt;I have recently started playing with the &lt;a href="http://www.securitycompass.com/exploitme.shtml"&gt;Exploit Me&lt;/a&gt; Firefox plugins and I have been impressed by them. I have put SQL Inject me and XSS me into my testing tool box. The plugins allow you to "point and click" test web applications for XSS and SQL Injection issues. They are quick and efficient and I would recommend them to anyone wanting to test for these issues.&lt;br /&gt;&lt;br /&gt;I have recently started to try some fuzz testing tools when I have been testing web applications. This approach has found a lot of bugs in high profile software in the past so I felt it was worth a try. &lt;br /&gt;&lt;br /&gt;I had started using &lt;a href="http://www.immunitysec.com/resources-freesoftware.shtml"&gt;Spike Proxy&lt;/a&gt; for fuzzing but if I'm honest I'm not that impressed with the tool. I felt the initial character set that is hardcoded into the tool wasn't as big as I would like. I extended this significantly but I'm still not likely to stick with this tool. I wanted the fuzzer to put random data into fields with random lengths and this tool didn't deliver that for me. Perhaps I'm using it incorrectly, if so drop me a line and enlighten me :-)&lt;br /&gt;&lt;br /&gt;So to fulfill my desire for a fuzzing tool I have begun playing with Jmeter for this purpose. I think if I write some Java which has a predefined character set (could even pull from a "random" source - /dev/random?) and an upper and lower length for the input I can use &lt;a href="http://jakarta.apache.org/jmeter/usermanual/component_reference.html"&gt;BeanShell&lt;/a&gt; with Jmeter and input this fuzz type data into fields which I submit to the web application. I can't take all of the credit for that idea, if the person who helped with this idea is reading this now then thank you very much! That idea is still very much in the "does it actually work?" stage so I will let you all know how it goes.&lt;br /&gt;&lt;br /&gt;Thats my main set of testing tools at the moment but I'm always playing with new things. I have a few tools listed below that I think are going to be squeezing into my testing tool box soon (not all of these are new tools):&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.grendel-scan.com/index.htm"&gt;Grendel-Scan&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cirt.net/nikto2"&gt;Nikto&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.sensepost.com/research/wikto/"&gt;Wikto&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Try them and find out what works for you.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-2498488316051209471?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/2498488316051209471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=2498488316051209471' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/2498488316051209471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/2498488316051209471'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/08/application-security-testing-tools.html' title='Application Security Testing Tools'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-3147356899137116373</id><published>2008-08-14T11:59:00.000-07:00</published><updated>2008-08-14T12:03:22.498-07:00</updated><title type='text'>Up in the clouds......</title><content type='html'>With all the discussion of cloud computing recently I have decided to give it a go. I'm going to sign up with the &lt;a href="http://www.amazon.com/gp/browse.html?node=201590011"&gt;Amazon&lt;/a&gt; cloud service.&lt;br /&gt;&lt;br /&gt;Since I created this blog I'm finding I need bigger and better labs to test out things like the Dan Kaminsky DNS flaw, Evilgrade and a multitude of reverse engineering tasks. I have decided that doing all of this up in the Amazon cloud gives me a huge amount of computing power for a very small price.&lt;br /&gt;&lt;br /&gt;I'm going to get myself set up in the next few days - expect some good lab work to appear on the blog in the coming months!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-3147356899137116373?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/3147356899137116373/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=3147356899137116373' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3147356899137116373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3147356899137116373'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/08/up-in-clouds.html' title='Up in the clouds......'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1356277432712078574</id><published>2008-08-11T13:29:00.000-07:00</published><updated>2008-08-11T13:40:46.327-07:00</updated><title type='text'>Security/Hacking conferences</title><content type='html'>With all the talk of Blackhat USA and Defcon at the moment it makes me wish I would have gone along! I have a lot of friends over in Las Vegas at the moment telling me about the fun they are having. I look forward to reading the presentations from the conferences. &lt;br /&gt;&lt;br /&gt;Next year I will be going! I will also being making my usual journey to Blackhat Europe in 2009. It seems like a long way off but Blackhat Europe will be hosted in Amsterdam as usual. It will run from April 14th through to the 17th next year. Details will be posted on &lt;a href="http://www.blackhat.com/"&gt;this&lt;/a&gt; page.&lt;br /&gt;&lt;br /&gt;I also plan on visiting the Chaos Communication Congress in December this year, the Chaos Congress will be held on the traditional days of 27th - 30th December. I think I really need to pick my time carefully when I tell my girlfriend I plan on going! More details can be found &lt;a href="http://events.ccc.de/congress/2008/"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I will post more about Blackhat nearer the time but if anyone else is planning on going to CCC give me a shout.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1356277432712078574?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1356277432712078574/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1356277432712078574' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1356277432712078574'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1356277432712078574'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/08/securityhacking-conferences.html' title='Security/Hacking conferences'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-7884318757084103891</id><published>2008-07-28T12:56:00.000-07:00</published><updated>2008-07-28T14:59:10.000-07:00</updated><title type='text'>An apple a day.......</title><content type='html'>Should keep the doctor away. Useless its an OS X install acting as a DNS server, in which case this apple a day will get you owned.&lt;br /&gt;&lt;br /&gt;Incase you have been living on the moon and have missed the huge amounts of news stories about the serious issue discovered in every DNS implementation please read &lt;a href="http://www.securityfocus.com/brief/779"&gt;this.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It appears that Apple are one of the few major vendors who have not released a patch and according to &lt;a href="http://www.heise-online.co.uk/security/DNS-hole-no-patch-yet-from-Apple--/news/111187"&gt;Heise Security&lt;/a&gt; they haven't even issued any security alerts. I'm not an anti Apple person, I own a Macbook and an Ipod Touch but over the years they haven't been great at security and patching. Steve Jobs might be right about Microsoft lacking taste and design ideas but they sure do kick Apple's ass when it comes to patching and patch scheduling.  &lt;br /&gt;&lt;br /&gt;This DNS issue has been bubbling for a couple of weeks now until Halvar Flake figured out the problem. DYOR (Do Your Own Research) on the whole story but the issue has got much worse with the release of a metasploit module and Evilgrade which exploits this issue.&lt;br /&gt;&lt;br /&gt;As soon as I get the chance I will give a demo of either the metasploit modules or Evilgrade, probably Evilgrade as I like the look of that!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-7884318757084103891?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/7884318757084103891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=7884318757084103891' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7884318757084103891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7884318757084103891'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/apple-day.html' title='An apple a day.......'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1571141372206187323</id><published>2008-07-28T12:41:00.000-07:00</published><updated>2008-07-28T12:52:55.693-07:00</updated><title type='text'>76% of US Banking websites insecure</title><content type='html'>I came across a study today written by Laura Falk, Atul Prakash and Kevin Borders from the University of Michigan which explains that of the 214 US banking sites reviewed 76% have security holes.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://cups.cs.cmu.edu/soups/2008/proceedings/p117Falk.pdf"&gt;report&lt;/a&gt; focuses on security issues that have occurred because of poor design decisions in the development of the banking sites. I like this approach because it demonstrates that security compromises don't just occur through obscure or fancy attacks.&lt;br /&gt;&lt;br /&gt;Some of the issues highlighted are things that I would suggest are obvious design flaws such as beginning a logon session from an HTTP page. &lt;br /&gt;&lt;br /&gt;I would suggest that anyone with an interest in secure web application development should have a read of this report. My article in the next edition of Insecure Magazine will give you tips on how to avoid these types of design issues.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1571141372206187323?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1571141372206187323/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1571141372206187323' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1571141372206187323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1571141372206187323'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/76-of-us-banking-websites-insecure.html' title='76% of US Banking websites insecure'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-818862441188881550</id><published>2008-07-15T13:51:00.001-07:00</published><updated>2008-07-15T14:22:26.067-07:00</updated><title type='text'>Views on the news</title><content type='html'>I have come across a few news stories I wanted to share with you all today, so instead of having multiple posts I thought I would address them all here.&lt;br /&gt;&lt;br /&gt;The first news story I nearly didn't read but I'm glad I did. Moodle is a course management portal used by universities and the like across the world. The &lt;a href="http://www.darkreading.com/document.asp?doc_id=158901&amp;WT.svl=news1_2"&gt;story&lt;/a&gt; explained how the portal has two vulnerabilities, XSS (Cross Site Scripting,not really a "wow") but also a CSRF (Cross Site Request Forgery). The CSRF really interested me and I now have something to point my colleagues to who have listened to me talking about this issue for a while now.&lt;br /&gt;&lt;br /&gt;I won't explain CSRF here (details can be found &lt;a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery"&gt;here&lt;/a&gt;) but the attack itself tricked users into clicking on a link which sent an edit profile request on their behalf. This leads to a compromise of the users account.&lt;br /&gt;&lt;br /&gt;The second story explains how 3/4 UK companies have banned IM within their infrastructure. In the &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9110159&amp;source=rss_topic85"&gt;story&lt;/a&gt; it  states that only 88% of the IT directors surveyed felt IM posed a security risk, oh dear. Personally I would ban public IM (MSN, Yahoo etc) for all users, in fact I would go one step further and remove web access completely for certain business units. If a business unit has access to sensitive data then, in my opinion, the systems in that business unit should not have web access. The sensitive data could be credit card data, Intellectual Property such as source code - anything sensitive and of high value to the business really.&lt;br /&gt;&lt;br /&gt;I'd like to hear the opinions of other people on this.&lt;br /&gt;&lt;br /&gt;Just one more to go, a more technical story. &lt;br /&gt;&lt;br /&gt;The last one is from &lt;a href="http://isc.sans.org/diary.html?storyid=4724"&gt;Sans ISC&lt;/a&gt;, have a read and let me know what you think.&lt;br /&gt; &lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-818862441188881550?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/818862441188881550/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=818862441188881550' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/818862441188881550'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/818862441188881550'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/views-on-news.html' title='Views on the news'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-6173305603790930294</id><published>2008-07-15T13:46:00.000-07:00</published><updated>2008-07-15T13:50:51.709-07:00</updated><title type='text'>The dataloss database</title><content type='html'>I often struggled to find the statistics I required for presentations on data breaches until I found attrition.org&lt;br /&gt;&lt;br /&gt;I liked attrition, but I love what it has evolved into! I got an email on full disclosure mailing list today announcing its change to the dataloss database. The Open Security Foundation will be running the &lt;a href="http://datalossdb.org/"&gt;datalossDB&lt;/a&gt; and I for one look forward to using it going forward!&lt;br /&gt;&lt;br /&gt;Basically it is a central DB for all public data breaches for the past 8 years there are many ways to search the data and monthly and annual reports can can be viewed by any one.&lt;br /&gt;&lt;br /&gt;I have to say the guys at OSF have done a great job with this!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-6173305603790930294?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/6173305603790930294/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=6173305603790930294' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6173305603790930294'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6173305603790930294'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/dataloss-database.html' title='The dataloss database'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-3075372641252257255</id><published>2008-07-10T11:27:00.000-07:00</published><updated>2008-07-10T11:36:16.850-07:00</updated><title type='text'>2600, first the magazine now the book!</title><content type='html'>2600 magazine has been around since 1984 and I always look forward to my copy being delivered. I was happy to read that they are releasing a book with all of the best bits from 1984 through to 2008.&lt;br /&gt;&lt;br /&gt;I think it will be a great read, I bet the articles in the early editions still talked about topics such as blueboxing through to the early/mid nineties when the internet exploded into the beast we know today. I can't wait!&lt;br /&gt;&lt;br /&gt;More details can be found here: &lt;a href="http://www.amazon.co.uk/Best-2600-Hacker-Odyssey/dp/0470294191/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1215714356&amp;sr=8-1"&gt;2600 book&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And yes, I have pre-ordered mine ;-)&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-3075372641252257255?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/3075372641252257255/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=3075372641252257255' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3075372641252257255'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/3075372641252257255'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/2600-first-magazine-now-book.html' title='2600, first the magazine now the book!'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-4410629563707705437</id><published>2008-07-08T12:32:00.000-07:00</published><updated>2008-07-08T14:39:04.095-07:00</updated><title type='text'>Part 3 - using the wrapped ProRat Trojan</title><content type='html'>Well finally I have managed to get part 3 written. My initial intention was to use the modified tini.exe that we installed in part two but I changed my mind. Part one and two are still fully relevant, you need to have read part two to understand part 3 fully.&lt;br /&gt;&lt;br /&gt;I decided to use a a trojan that has far more "eye candy" than tini and netcat. I'm using a trojan called prorat which I used to tinker about with in the past. I think it will really highlight why part one and part two were important to know.&lt;br /&gt;&lt;br /&gt;First, as usual, the actors: &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SHPT6HXlmsI/AAAAAAAAAC0/-UFsmwkpKOU/s1600-h/The+Actors.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SHPT6HXlmsI/AAAAAAAAAC0/-UFsmwkpKOU/s400/The+Actors.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220749388416391874" /&gt;&lt;/a&gt;&lt;br /&gt;I have used two Windows XP virtual machines (safety first kids) for this demonstration, both the victim and attack hosts are shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SHPT6GGX9wI/AAAAAAAAAC8/iPgCJ9CHGSw/s1600-h/victimhost.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SHPT6GGX9wI/AAAAAAAAAC8/iPgCJ9CHGSw/s400/victimhost.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220749388075759362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPT6ZNJooI/AAAAAAAAADE/BFsQahDGANs/s1600-h/attackhost.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPT6ZNJooI/AAAAAAAAADE/BFsQahDGANs/s400/attackhost.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220749393204454018" /&gt;&lt;/a&gt;&lt;br /&gt;I have downloaded and openend the prorat command software on the attacker machine as shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_R1s5-AeiKEs/SHPT6uu-yAI/AAAAAAAAADM/qzgmQoUqo1Y/s1600-h/prorat.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp1.blogger.com/_R1s5-AeiKEs/SHPT6uu-yAI/AAAAAAAAADM/qzgmQoUqo1Y/s400/prorat.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220749398983493634" /&gt;&lt;/a&gt;&lt;br /&gt;The first thing I need to do is to create the server. The server in prorat is actually the piece of software you wish to install on the victims machine. I chose a random port for my server, port 8668. I have included a few screenshots below showing the wide range of options available to the attacker when he is creating the server:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SHPT61xS2gI/AAAAAAAAADU/dhSxnj5Pl6Q/s1600-h/createserver.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SHPT61xS2gI/AAAAAAAAADU/dhSxnj5Pl6Q/s400/createserver.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220749400872245762" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPaQAKmU3I/AAAAAAAAADc/fp3NsSxUHYY/s1600-h/servercreaterconfig.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPaQAKmU3I/AAAAAAAAADc/fp3NsSxUHYY/s400/servercreaterconfig.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220756361509753714" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQf8eslI/AAAAAAAAADk/p5fhIEDUKe0/s1600-h/servercreaterconfig2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQf8eslI/AAAAAAAAADk/p5fhIEDUKe0/s400/servercreaterconfig2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220756370040468050" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQb5-ZQI/AAAAAAAAADs/N8u-DeIE_oY/s1600-h/servercreaterconfig3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQb5-ZQI/AAAAAAAAADs/N8u-DeIE_oY/s400/servercreaterconfig3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220756368956220674" /&gt;&lt;/a&gt;&lt;br /&gt;Some of those options, more so in the first image are pretty serious attacker options. For example disable the firewall and anti virus......&lt;br /&gt;&lt;br /&gt;I wrapped the prorat server up with the firefox installer (see part two of this series for more information) and installed this on the victims machine. I have included before and after netstat -na outputs below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SHPaQuI3pEI/AAAAAAAAAD0/JLkaz3YR5zI/s1600-h/netstat+before.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SHPaQuI3pEI/AAAAAAAAAD0/JLkaz3YR5zI/s400/netstat+before.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220756373850530882" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQ5Cw0zI/AAAAAAAAAD8/gTgODOe9KjE/s1600-h/netstat+after.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SHPaQ5Cw0zI/AAAAAAAAAD8/gTgODOe9KjE/s400/netstat+after.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220756376777708338" /&gt;&lt;/a&gt;&lt;br /&gt;I connect to the server through the prorat command console:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SHPcSTlSfJI/AAAAAAAAAEE/7wLbAf5oKcs/s1600-h/prorat+connected.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SHPcSTlSfJI/AAAAAAAAAEE/7wLbAf5oKcs/s400/prorat+connected.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220758600104967314" /&gt;&lt;/a&gt;&lt;br /&gt;I think its time for some fun, lets have a play with some of the tools available to us. As you can see the command console offers me lots of tools to extract information or even do more damage to the victim. I have just selected a few of these to demonstrate in this post.&lt;br /&gt;&lt;br /&gt;I have included screen shots of a view of these tools in action, firstly taking screenshots of the victims desktop:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcSj78bhI/AAAAAAAAAEM/8CwYIbWH57M/s1600-h/screenshot.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcSj78bhI/AAAAAAAAAEM/8CwYIbWH57M/s400/screenshot.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220758604494958098" /&gt;&lt;/a&gt;&lt;br /&gt;Viewing the applications the victim is running:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcS9_78xI/AAAAAAAAAEU/AIR-XG5Tpdg/s1600-h/viewing+open+apps.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcS9_78xI/AAAAAAAAAEU/AIR-XG5Tpdg/s400/viewing+open+apps.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220758611491025682" /&gt;&lt;/a&gt;&lt;br /&gt;Viewing the web history:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcS-sTZTI/AAAAAAAAAEc/W2PnmUiwL4Y/s1600-h/proratvistedsites.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcS-sTZTI/AAAAAAAAAEc/W2PnmUiwL4Y/s400/proratvistedsites.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220758611677111602" /&gt;&lt;/a&gt;&lt;br /&gt;I just have three more examples I would like to show to you in this post. Firstly copying the victims clipboard. I have entered some text in notepad on the victims computers:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcTEES8DI/AAAAAAAAAEk/_O8klXxbogw/s1600-h/clipboard1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPcTEES8DI/AAAAAAAAAEk/_O8klXxbogw/s400/clipboard1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220758613119922226" /&gt;&lt;/a&gt;&lt;br /&gt;And I have accessed this through the command console:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPd9uZgKqI/AAAAAAAAAEs/5JEQ-VC2YoI/s1600-h/clipboard2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPd9uZgKqI/AAAAAAAAAEs/5JEQ-VC2YoI/s400/clipboard2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220760445549292194" /&gt;&lt;/a&gt;&lt;br /&gt;Second, stealing files from the victims machine. The victim has a file called mypasswordsfile.txt:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SHPd932XGvI/AAAAAAAAAE0/or-lcFNgues/s1600-h/filesonvictim.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SHPd932XGvI/AAAAAAAAAE0/or-lcFNgues/s400/filesonvictim.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220760448086252274" /&gt;&lt;/a&gt;&lt;br /&gt;and I have copied this to the command console:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SHPd-AKdzLI/AAAAAAAAAE8/VKDHIjre8WU/s1600-h/filesstolen.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SHPd-AKdzLI/AAAAAAAAAE8/VKDHIjre8WU/s400/filesstolen.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220760450318060722" /&gt;&lt;/a&gt;&lt;br /&gt;Just one more to show, the keylogger. Without needing any prompting from me the prorat server has been sending all of keystrokes back to the command console as shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SHPd-XYwJpI/AAAAAAAAAFE/ZGfYgvhV3e4/s1600-h/keylogger.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SHPd-XYwJpI/AAAAAAAAAFE/ZGfYgvhV3e4/s400/keylogger.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5220760456551999122" /&gt;&lt;/a&gt;&lt;br /&gt;Well that is all really, I think we all can now see how easy it can be to get malicious and powerful software onto an unsuspecting victims machine.&lt;br /&gt;&lt;br /&gt;Don't have nightmares, the next technical post will be explaining how to steal data and hiding it covertly with tcp packets.&lt;br /&gt;&lt;br /&gt;Dave&lt;br /&gt;&lt;br /&gt;PS - all stunts are performed by highly trained security ninjas, do not attempt to perform these stunts in your own home.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-4410629563707705437?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/4410629563707705437/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=4410629563707705437' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4410629563707705437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4410629563707705437'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/part-3-using-wrapped-prorat-trojan.html' title='Part 3 - using the wrapped ProRat Trojan'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp2.blogger.com/_R1s5-AeiKEs/SHPT6HXlmsI/AAAAAAAAAC0/-UFsmwkpKOU/s72-c/The+Actors.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-5113289486503752405</id><published>2008-07-07T07:32:00.001-07:00</published><updated>2008-07-07T08:10:42.261-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='automated security testing'/><category scheme='http://www.blogger.com/atom/ns#' term='automated sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='automated xss'/><title type='text'>Exploit-me tools</title><content type='html'>I have been using a few new tools recently to help automate my XSS and SQL injection testing and I thought I would share them with you.&lt;br /&gt;&lt;br /&gt;My normal approach involved manual work along with the Burp Suite (using the intruder function) with a list of inputs loaded in. I came across the &lt;a href="http://www.securitycompass.com/exploitme.shtml"&gt;Exploit-me&lt;/a&gt; tools from Security Compass and I thought I would tell you guys about them.&lt;br /&gt;&lt;br /&gt;I won't talk to much about how to use the tools, I think installing them and having a play will tell you all you need to know. The link above to the Security Compass website does have some FAQ's/usage guides along with a presentation given at the SecTor conference. XSS-Me comes pre-loaded with RSnake's XSS cheat sheet inputs, these can be expanded with strings from your own brain or from many web sources. SQL inject ME is similar in that it comes pre-loaded with some strings, again this list can be extended. Lastly the Access-Me tool aims to exploit access control flaws within an application.&lt;br /&gt;&lt;br /&gt;Have a play with the tools and let me know what you think.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-5113289486503752405?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/5113289486503752405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=5113289486503752405' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5113289486503752405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5113289486503752405'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/exploit-me-tools.html' title='Exploit-me tools'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-5959612764109497660</id><published>2008-07-07T07:26:00.000-07:00</published><updated>2008-07-07T07:31:58.619-07:00</updated><title type='text'>(in)secure magazine article</title><content type='html'>Hi everyone,&lt;br /&gt;&lt;br /&gt;I will be writing an article for the next edition of &lt;a href="http://www.net-security.org/insecuremag.php"&gt;(in)secure magazine&lt;/a&gt; on secure web application development. &lt;br /&gt;&lt;br /&gt;I plan on explaining why we need to develop securely, what kind of approaches to development can be taken to ensure secure development takes place and then general tips based on my own experience.&lt;br /&gt;&lt;br /&gt;When the next edition is released I will post a link to it here.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-5959612764109497660?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/5959612764109497660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=5959612764109497660' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5959612764109497660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5959612764109497660'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/insecure-magazine-article.html' title='(in)secure magazine article'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-6226925529015036126</id><published>2008-07-07T07:21:00.001-07:00</published><updated>2008-07-07T07:25:52.261-07:00</updated><title type='text'>I'm back!</title><content type='html'>I flew back to Ireland this morning from the British Grand Prix, as a fan of Ferrari it turned out to be a disappointing race for me. Arguably we haven't been as poor from a team perspective since the pre Schumacher days in the 80's and early 90's. Hopefully things will be better when I fly to the home of Ferrari F1 racing in September.&lt;br /&gt;&lt;br /&gt;I will be working on post 3 in the series over the next day or two so watch out for that. Because of the comment by Niall last week about Anti Virus products I want to take a different approach to the one I had originally planned so stay tuned!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-6226925529015036126?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/6226925529015036126/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=6226925529015036126' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6226925529015036126'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6226925529015036126'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/im-back.html' title='I&apos;m back!'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-7634534190469031824</id><published>2008-07-02T11:58:00.000-07:00</published><updated>2008-07-02T12:14:17.552-07:00</updated><title type='text'>Citibank ATM's hacked</title><content type='html'>I came across an interesting story today which explain how the Citbank ATM's in over 5,000 7Eleven stores have been hacked. &lt;br /&gt;&lt;br /&gt;It is estimated that the hackers have stolen around $2million from this hack. That is of course no small amount of cash but thats not what caught my attention. All that's known is the hackers broke into the ATM network through a server at a third-party processor, which means they probably didn't have to touch the ATMs at all to steal the pin numbers. The pin numbers were passed in the clear from the ATM machine through to the backend system. This is about all the information that has been made public so far, as soon I hear anymore I will post it here.&lt;br /&gt;&lt;br /&gt;This is clearly a new way to steal the pin numbers and would show absolutely no signs to the ATM user. Previously security professionals would inform users not to enter their pin into links followed through phishing emails. We would also tell people about false fronts on ATM's designed to steal your data but this is completely different. The end user would have had no idea that this was going on.&lt;br /&gt;&lt;br /&gt;More and more ATM's are running on the Windows Operating system and this appears to be a range of versions from Windows 98 through to Windows XP. I have an example on an ATM running Windows NT below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp1.blogger.com/_R1s5-AeiKEs/SGvTNnKGXvI/AAAAAAAAACk/f40PmvyZg0Q/s1600-h/NT+ATM.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp1.blogger.com/_R1s5-AeiKEs/SGvTNnKGXvI/AAAAAAAAACk/f40PmvyZg0Q/s400/NT+ATM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218496824041955058" /&gt;&lt;/a&gt;&lt;br /&gt;And a second image I like is shown below, its a Russian ATM running a pirated version of Windows XP:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SGvTN6zHuSI/AAAAAAAAACs/5ak69-IQ-68/s1600-h/pirateATM.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SGvTN6zHuSI/AAAAAAAAACs/5ak69-IQ-68/s400/pirateATM.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218496829314283810" /&gt;&lt;/a&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-7634534190469031824?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/7634534190469031824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=7634534190469031824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7634534190469031824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7634534190469031824'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/citibank-atms-hacked.html' title='Citibank ATM&apos;s hacked'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp1.blogger.com/_R1s5-AeiKEs/SGvTNnKGXvI/AAAAAAAAACk/f40PmvyZg0Q/s72-c/NT+ATM.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-8677595754234705959</id><published>2008-07-01T14:19:00.000-07:00</published><updated>2008-07-02T11:08:22.579-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='elitewrap tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='packing backdoors'/><category scheme='http://www.blogger.com/atom/ns#' term='elitewrap'/><category scheme='http://www.blogger.com/atom/ns#' term='stealth backdoor'/><title type='text'>Wrapping a backdoor with a genuine installer</title><content type='html'>Well I have been able to get this posted much quicker than I thought. In short I will be using dave.exe from post 1 to wrap it up with the genuine installer for Firefox 3.0.&lt;br /&gt;&lt;br /&gt;This will install Firefox and also my backdoor silently on the machine.&lt;br /&gt;&lt;br /&gt;Here we go, the actors:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqgIqVO6TI/AAAAAAAAABM/Y6XYWO9nQm0/s1600-h/The+actors.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqgIqVO6TI/AAAAAAAAABM/Y6XYWO9nQm0/s400/The+actors.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218159188924885298" /&gt;&lt;/a&gt;&lt;br /&gt;Once I have launched Elitewrap I have to define the output filename. This is the name of the wrapped .exe&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqgheznWSI/AAAAAAAAABU/pQk5lWSOY3c/s1600-h/output+filename.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqgheznWSI/AAAAAAAAABU/pQk5lWSOY3c/s400/output+filename.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218159615327820066" /&gt;&lt;/a&gt;&lt;br /&gt;Once this has been defined you have to select the operation you want Elitewrap to perform. &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqg8MuEzfI/AAAAAAAAABc/hh5WXXJnrWI/s1600-h/operations.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqg8MuEzfI/AAAAAAAAABc/hh5WXXJnrWI/s400/operations.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218160074329214450" /&gt;&lt;/a&gt;&lt;br /&gt;The readme file lists all the options with explanations but I will be using operation 3. This will install my backdoor silently whilst the Firefox installer runs in the foreground.&lt;br /&gt;&lt;br /&gt;And so to wrap the exes, nothing really complicated to it as you can see below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqhXFkoE_I/AAAAAAAAABk/INGlFSQewsU/s1600-h/wrap+the+exes.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqhXFkoE_I/AAAAAAAAABk/INGlFSQewsU/s400/wrap+the+exes.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218160536267002866" /&gt;&lt;/a&gt;&lt;br /&gt;And here is the output:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqjy4kZtQI/AAAAAAAAABs/vMqL_6fyEis/s1600-h/wrapped+FF.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqjy4kZtQI/AAAAAAAAABs/vMqL_6fyEis/s400/wrapped+FF.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218163212835992834" /&gt;&lt;/a&gt;&lt;br /&gt;Before I run this executable I have run the netstat -na command to show the backdoor isn't already running (it will be on port 39846):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp0.blogger.com/_R1s5-AeiKEs/SGqkN0J1uCI/AAAAAAAAAB0/cCH_Cqazq3c/s1600-h/netcat+before.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp0.blogger.com/_R1s5-AeiKEs/SGqkN0J1uCI/AAAAAAAAAB0/cCH_Cqazq3c/s400/netcat+before.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218163675507308578" /&gt;&lt;/a&gt;&lt;br /&gt;So I double click the exe and here is the output (including an update netstat):&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp3.blogger.com/_R1s5-AeiKEs/SGqkj6NMHrI/AAAAAAAAAB8/WLtbc9AvIQQ/s1600-h/FF+start.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp3.blogger.com/_R1s5-AeiKEs/SGqkj6NMHrI/AAAAAAAAAB8/WLtbc9AvIQQ/s400/FF+start.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218164055089094322" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SGqkkElabGI/AAAAAAAAACE/wNEXhNqxYmk/s1600-h/dave+listening.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SGqkkElabGI/AAAAAAAAACE/wNEXhNqxYmk/s400/dave+listening.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218164057875049570" /&gt;&lt;/a&gt;&lt;br /&gt;So we can see already that the backdoor is listening and we haven't even installed Firefox. So even if we were to cancel the installation its too late.&lt;br /&gt;&lt;br /&gt;We continued the installation and allowed it to finish:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SGqlJdmR5nI/AAAAAAAAACM/wy8gAtNaqmk/s1600-h/FF+finish.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SGqlJdmR5nI/AAAAAAAAACM/wy8gAtNaqmk/s400/FF+finish.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218164700244731506" /&gt;&lt;/a&gt;&lt;br /&gt;And the final result is shown below: &lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SGqlJSE91jI/AAAAAAAAACU/zoSE6Wv0PhY/s1600-h/end+result.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SGqlJSE91jI/AAAAAAAAACU/zoSE6Wv0PhY/s400/end+result.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218164697152214578" /&gt;&lt;/a&gt;&lt;br /&gt;Firefox installed without any hint of a problem and my backdoor is waiting for me to connect.&lt;br /&gt;&lt;br /&gt;I hope that this post has been informative, contact me or leave a comment if you have any questions.&lt;br /&gt;&lt;br /&gt;Update: based on Niall's comment I have uploaded the wrapped firefox.exe to Virus Total and the results are shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://bp2.blogger.com/_R1s5-AeiKEs/SGvD2o8LiqI/AAAAAAAAACc/5tlsCos-uzU/s1600-h/virustotal.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://bp2.blogger.com/_R1s5-AeiKEs/SGvD2o8LiqI/AAAAAAAAACc/5tlsCos-uzU/s400/virustotal.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5218479936709036706" /&gt;&lt;/a&gt;&lt;br /&gt;For part three of this post I will be using some a bit more industrial that dave.exe. All will be revealed soon!&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-8677595754234705959?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/8677595754234705959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=8677595754234705959' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8677595754234705959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8677595754234705959'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/07/wrapping-backdoor-with-genuine.html' title='Wrapping a backdoor with a genuine installer'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://bp0.blogger.com/_R1s5-AeiKEs/SGqgIqVO6TI/AAAAAAAAABM/Y6XYWO9nQm0/s72-c/The+actors.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1005355788193838014</id><published>2008-06-30T12:06:00.000-07:00</published><updated>2008-07-01T13:46:34.211-07:00</updated><title type='text'>Part two nearly here.....</title><content type='html'>With a bit of my OWASP work complete I thought I would put part two of this post up. I decided to video the whole thing, it was my first time and I have had nothing but trouble with it. The video was nearly 100mb so it took ages to upload and when it finally did the quality was terrible, it looked great locally.&lt;br /&gt;&lt;br /&gt;I will just post up screenshots tomorrow like I did for the first bit of the post. I will sort this out tomorrow night, so only one more day to wait. If I get the video uploaded and looking good I will add that in.&lt;br /&gt;&lt;br /&gt;If I had more time I'd get it sorted properly but I fly out to the British Grand Prix on Thursday morning and I'd like to get it posted before I depart.&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1005355788193838014?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1005355788193838014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1005355788193838014' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1005355788193838014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1005355788193838014'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/part-two-nearly-here.html' title='Part two nearly here.....'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1240340607156932650</id><published>2008-06-27T12:36:00.000-07:00</published><updated>2008-06-27T14:24:00.738-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tini.exe hex editing'/><category scheme='http://www.blogger.com/atom/ns#' term='modify tini.exe'/><category scheme='http://www.blogger.com/atom/ns#' term='bypass antivirus'/><category scheme='http://www.blogger.com/atom/ns#' term='modify backdoor'/><title type='text'>Bypass modern anti virus with an 8 year old backdoor</title><content type='html'>This is the first of a 3 part blog entry, well blog entry/warning/tutorial - pick which you think fits this best. As soon as people find out I work in IT Security normally the first question I'm asked is which is the best Anti Virus product to use? Normally I just say one of the big providers, F-Secure, Symantec etc but I do also state that they aren't a silver bullet.&lt;br /&gt;&lt;br /&gt;What I'm going to do in this 3 part blog is first download tini.exe which is a backdoor roughly 8 years old and submit it to Virus Total. This will be scanned by 33 different anti virus products and I will show the results. Then the fun bit, I will modify just the port that tini.exe listens on and its name then see how many report it as a backdoor!&lt;br /&gt;&lt;br /&gt;Secondly I will show you how to wrap this backdoor into any application you want and have it install silently along with the real application. The third step will be a demonstration of a second machine connecting to this backdoor.&lt;br /&gt;&lt;br /&gt;First download the tini installer. I will submit the default Tini.exe backdoor to virus total and see how many of the modern anti virus companies will detect this old backdoor.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_R1s5-AeiKEs/SGVE7ZbU2dI/AAAAAAAAAAM/1cL6h7_zcic/s1600-h/tini+scan+1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_R1s5-AeiKEs/SGVE7ZbU2dI/AAAAAAAAAAM/1cL6h7_zcic/s400/tini+scan+1.jpg" alt="" id="BLOGGER_PHOTO_ID_5216651530607057362" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_R1s5-AeiKEs/SGVE7pdDwuI/AAAAAAAAAAU/WO-dkU79fvM/s1600-h/tini+scan+2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_R1s5-AeiKEs/SGVE7pdDwuI/AAAAAAAAAAU/WO-dkU79fvM/s400/tini+scan+2.jpg" alt="" id="BLOGGER_PHOTO_ID_5216651534909293282" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;All of the products have figured out that it is some kind of backdoor/trojan.&lt;br /&gt;&lt;br /&gt;So now to crack tini open with a hex editor and find the default port value, 7777 in this case:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFirj2HrI/AAAAAAAAAAc/h5wzqCZ3Yps/s1600-h/hex+edit1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFirj2HrI/AAAAAAAAAAc/h5wzqCZ3Yps/s400/hex+edit1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5216652205489528498" /&gt;&lt;/a&gt;&lt;br /&gt;Now I have picked a random port of 39846 (9ba6) and I will edit the backdoor as shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFivkSvkI/AAAAAAAAAAk/K8vUb9aFQxU/s1600-h/hex+edit2.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFivkSvkI/AAAAAAAAAAk/K8vUb9aFQxU/s400/hex+edit2.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5216652206565146178" /&gt;&lt;/a&gt;&lt;br /&gt;I saved the modified version as dave.exe and I will re-submit this Virus Total. The results are shown below:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_R1s5-AeiKEs/SGVFi9xnstI/AAAAAAAAAAs/qahck_CA504/s1600-h/tini+scan+3.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_R1s5-AeiKEs/SGVFi9xnstI/AAAAAAAAAAs/qahck_CA504/s400/tini+scan+3.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5216652210379141842" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFjJIcHwI/AAAAAAAAAA0/d0dcUFv34Rw/s1600-h/tini+scan+4.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_R1s5-AeiKEs/SGVFjJIcHwI/AAAAAAAAAA0/d0dcUFv34Rw/s400/tini+scan+4.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5216652213427642114" /&gt;&lt;/a&gt;&lt;br /&gt;You can see that only 21 of the products now reported this file as being malicious. So by just changing the listening port and the name of the backdoor 21/33 products detected this 8 year old backdoor (first scan was 32/33). It is hardly inspiring reading is it?&lt;br /&gt;&lt;br /&gt;Part two of this post will show you how to wrap this modified backdoor with a genuine application to install it in stealth on the victims machine.&lt;br /&gt;&lt;br /&gt;Please be patient for post two, I have commitments to meet for the OWASP Code Review guide for the next few days before I can put part two up.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1240340607156932650?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1240340607156932650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1240340607156932650' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1240340607156932650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1240340607156932650'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/bypass-modern-anti-virus-with-8-year.html' title='Bypass modern anti virus with an 8 year old backdoor'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_R1s5-AeiKEs/SGVE7ZbU2dI/AAAAAAAAAAM/1cL6h7_zcic/s72-c/tini+scan+1.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1339806322166233062</id><published>2008-06-22T13:06:00.000-07:00</published><updated>2008-06-22T13:17:58.979-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='backtrack live cd'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack pauldotcom'/><title type='text'>Interview with the developers of Backtrack</title><content type='html'>I have been listening to episode 112 of the PaulDotCom podcast (&lt;a href="http://www.pauldotcom.com/"&gt;PaulDotCom&lt;/a&gt;) and it contains a fantastic interview with the guys behind the BackTrack distribution.&lt;br /&gt;&lt;br /&gt;I highly recommend this podcast to existing and new BackTrack users alike. &lt;br /&gt;&lt;br /&gt;The guys talk about where the distribution came from, some of the problems they have faced, some of the tools in the latest version and plans for the future.&lt;br /&gt;&lt;br /&gt;The BackTrack distribution can be found here: &lt;a href="http://www.remote-exploit.org/backtrack.html"&gt;BackTrack&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1339806322166233062?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1339806322166233062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1339806322166233062' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1339806322166233062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1339806322166233062'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/interview-with-developers-of-backtrack.html' title='Interview with the developers of Backtrack'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-7449890914498640483</id><published>2008-06-20T11:46:00.000-07:00</published><updated>2008-06-22T13:18:58.738-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virgin media data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='virgin media security breach'/><category scheme='http://www.blogger.com/atom/ns#' term='virgin media security'/><category scheme='http://www.blogger.com/atom/ns#' term='virgin security'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><title type='text'>Virgin Media data breach</title><content type='html'>What is it with 2008 and companies losing data on CD's?&lt;br /&gt;&lt;br /&gt;The latest company to lose data this way is Virgin Media, they have lost a CD which was un-encrypted and contained the bank account details, names and addresses of 3000 customers.&lt;br /&gt;&lt;br /&gt;More information can be found here: &lt;a href="http://www.theregister.co.uk/2008/06/20/virgin_media_banking_loss/"&gt;Virgin Media data loss&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;What more can I say, its Friday night - maybe I will come back and add a rant to this post tomorrow :-)&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-7449890914498640483?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/7449890914498640483/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=7449890914498640483' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7449890914498640483'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7449890914498640483'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/virgin-media-data-breach.html' title='Virgin Media data breach'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-6637244235540532279</id><published>2008-06-16T11:25:00.000-07:00</published><updated>2008-06-16T12:49:50.119-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Preventing Cross Site Scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='Cross Site Scripting'/><category scheme='http://www.blogger.com/atom/ns#' term='Preventing XSS'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>Secure Development - preventing Cross Site Scripting</title><content type='html'>Hi everyone, I have included a Google Docs reader below for a paper I have written on Cross Site Scripting. The paper discusses the three types of Cross Site Scripting attacks as well as code examples and the associated fix.&lt;br /&gt;&lt;br /&gt;The paper can be viewed here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://docs.google.com/Doc?docid=dcd4c73_278b5mgkf7&amp;hl=en"&gt;Preventing Cross Site Scripting&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The formatting has been messed up a bit by Google Docs but I hope it makes sense to everyone.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-6637244235540532279?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/6637244235540532279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=6637244235540532279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6637244235540532279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/6637244235540532279'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/secure-development-preventing-cross_16.html' title='Secure Development - preventing Cross Site Scripting'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-1296785699611342610</id><published>2008-06-15T07:42:00.000-07:00</published><updated>2008-06-15T13:32:59.583-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS requirement 6.6'/><category scheme='http://www.blogger.com/atom/ns#' term='compliance with requirement 6.6'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI requirement 6.6'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI compliance'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS compliance'/><title type='text'>PCI 6.6 mandatory compliance date looming</title><content type='html'>When I first read PCI DSS v1.1 requirement 6.6 caught my eye for two reasons. I could see the potential security benefits but also the extra work I would have to do!&lt;br /&gt;&lt;br /&gt;Requirement 6.6 is shown below:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Ensure that all web-facing applications are protected against known attacks by applying either of the following methods:  &lt;br /&gt;&lt;br /&gt;• Having all custom application code reviewed for common vulnerabilities by an organization that specializes in application security &lt;br /&gt;• Installing an application layer firewall in front of web-facing applications. &lt;br /&gt;&lt;br /&gt;Note: This method is considered a best practice until June 30, 2008, after which it becomes a requirement. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Wow, all custom code externally reviewed - time to save up the pennies to pay for that!  A lot of the community were scratching their heads trying to figure out whether this actually means having every line of custom code reviewed, even for a relatively small company we were a bit worried about the cost. Fortunately the PCI Council released a clarification document earlier this year detailing that a company could meet 6.6 by one of the following approaches:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;br /&gt;"The application code review option does not necessarily require a manual review of source code. &lt;br /&gt;&lt;br /&gt;Keeping in mind that the objective of Requirement 6.6 is to prevent exploitation of common vulnerabilities (such as those listed in Requirement 6.5), several possible solutions may be considered. &lt;br /&gt;&lt;br /&gt;They are dynamic and pro-active, requiring the specific initiation of a manual or automated process. Properly implemented, one or more of these four alternatives could meet the intent of Option 1 and provide the minimum level of protection against common web application threats:&lt;br /&gt; &lt;br /&gt;1. Manual review of application source code &lt;br /&gt;2. Proper use of automated application source code analyzer (scanning) tools &lt;br /&gt;3. Manual web application security vulnerability assessment &lt;br /&gt;4. Proper use of automated web application security vulnerability assessment (scanning) tools" &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;We felt that our current approach towards secure application development and code reviews met the intent of the first option in requirement 6.6. We have had an external company who are specialist in auditing and application security to review (and produce a report on) our process.&lt;br /&gt;&lt;br /&gt;I would love to know what kind of approach others have taken to satisfy requirement 6.6. &lt;br /&gt;&lt;br /&gt;Remember folks, it becomes mandatory in 15 days so act fast!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-1296785699611342610?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/1296785699611342610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=1296785699611342610' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1296785699611342610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/1296785699611342610'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/pci-66-mandatory-compliance-date.html' title='PCI 6.6 mandatory compliance date looming'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-7797172663885801054</id><published>2008-06-15T07:16:00.000-07:00</published><updated>2008-06-15T08:12:50.353-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='UK government data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Top Secret documents on train'/><category scheme='http://www.blogger.com/atom/ns#' term='UK Top Secret documents'/><title type='text'>Even more documents lost....</title><content type='html'>Following on from my post last week which discussed the loss of Top Secret government documents a second breach has been hitting the headlines.&lt;br /&gt;&lt;br /&gt;I was amazed that these kind of documents were left on a train once but to happen twice is beyond belief. Several of the statements made by government officials/in news reports did grab my attention, firstly:&lt;br /&gt;&lt;br /&gt;"His work reportedly involves writing and contributing to intelligence and security assessments, and he has the authority to take secret documents out of the Cabinet Office - so long as strict procedures are observed."&lt;br /&gt;&lt;br /&gt;So the government actually allows Top Secret (National Security documents) to be printed and taken off its premises. As a Security professional my first reaction was one of surprise until you consider the major security blunders by the UK government in the past 12 months. &lt;br /&gt;&lt;br /&gt;Secondly, a comment made by Keith Vaz, Chairman of the Home Affairs Select Committee:&lt;br /&gt;&lt;br /&gt;"no official no matter how senior, should be allowed to take classified or confidential documents outside their offices for whatever reason."&lt;br /&gt;&lt;br /&gt;That seems a good enough start in my opinion. But this really does come back to very last point I made in my original post last week about printed data. &lt;br /&gt;&lt;br /&gt;It is one of my biggest professional fears, how do I know people aren't printing sensitive data off and stuffing it into their pockets? As a financial services company we get emails every week from individuals and banks (yes, banks) which contain un-encrypted sensitive data. Fortunately we have well defined procedures and skilled staff to respond correctly to these emails. But what if we didn't?&lt;br /&gt;&lt;br /&gt;In terms of technical controls we can control the risk of theft around this data but if it were printed then all bets are off. A user could just print the email, if we prevent printing then could do a screen print, they could even write it down and away they go. In this day and age of mobile phones with high resolution cameras what is to stop people just taking a picture of the data and taking it that way?&lt;br /&gt;&lt;br /&gt;When you think of it like this you may feel a bit of sympathy for the government, but they have the budgets and the ability to hire the top talent to prevent these breaches.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-7797172663885801054?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/7797172663885801054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=7797172663885801054' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7797172663885801054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/7797172663885801054'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/even-more-documents-lost.html' title='Even more documents lost....'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-5500951169418507014</id><published>2008-06-11T11:55:00.000-07:00</published><updated>2008-06-15T08:12:17.727-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cotton Traders breach'/><category scheme='http://www.blogger.com/atom/ns#' term='UK government data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='Top Secret documents on train'/><category scheme='http://www.blogger.com/atom/ns#' term='UK Top Secret documents'/><title type='text'>Security, is it really that hard?</title><content type='html'>I read and hear about security breaches almost everyday and I always ask myself the same question, "is security really that hard?".&lt;br /&gt;&lt;br /&gt;Today I have read two articles on the BBC website, one (&lt;a href="http://news.bbc.co.uk/2/hi/technology/7446871.stm"&gt;BBC Article 1&lt;/a&gt;) is even more credit card numbers lost and the second (&lt;a href="http://news.bbc.co.uk/2/hi/uk_news/7449255.stm"&gt;BBC Article 2&lt;/a&gt;) is more UK government confidential documents lost.&lt;br /&gt;&lt;br /&gt;Cotton Traders have lost 38,000 credit card numbers through their website. No technical details of the breach have been given but its likely to be a SQL Injection attack. The article on the BBC doesn't give much information away. What it does give away is false information about the TK Maxx data breach in 2007. The article falsely stated the TK Maxx breach occured through their website.&lt;br /&gt;&lt;br /&gt;TK Maxx (more precisely TJX) didn't loose their card numbers through their website. The breach occurred because of someone noticing that the TK Maxx stores used WEP to protect their internal POS networks. Through war driving they cracked the WEP (not a highly technical hack) and went onto take close to 100 million card numbers over 18 months. For such a big news company I would have expected a more accurate report from the BBC.&lt;br /&gt;&lt;br /&gt;Back to the original point, the Cotton Traders breach. Many sites are vulnerable to (again this is based on my assumption) SQL Injection so only half a scowl for them on that. But cleartext card data, thats not really forgivable. If I were investigating the breach my two main questions would be 1) Did you need to store that data and 2) Why didn't you securely store it (i.e. encryption)? I'm sure we will never publicly know these answers.&lt;br /&gt;&lt;br /&gt;My last point on Cotton Traders is the breach occurred in January, 6 months ago. The sooner we see more laws like California's SB 1386 the better! The public should be made aware sooner of such breaches, just think how many are probably going un-reported.&lt;br /&gt;&lt;br /&gt;The second article focuses on the fact that the UK government has lost more information. This time a government official has left printed copies of Top Secret documents on Al Qaeda and the war in Iraq on a train. A police investigation is being conducted and I'd suggest that some poor employee that may not have known better will be receiving their P45 soon. I could write all night about the potential problems that have occurred to cause this loss of data but I won't!&lt;br /&gt;&lt;br /&gt;At a recent Data Privacy seminar we were all unanimous in our fear of printed data. We can have all the latest and greatest firewalls, IPS/IDS, encryption etc but once its on paper what can you do?&lt;br /&gt;&lt;br /&gt;Dave&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-5500951169418507014?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/5500951169418507014/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=5500951169418507014' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5500951169418507014'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/5500951169418507014'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/security-is-it-really-that-hard.html' title='Security, is it really that hard?'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-4612194465736032880</id><published>2008-06-09T03:07:00.000-07:00</published><updated>2008-06-15T08:11:21.703-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hackerhafe hacker'/><category scheme='http://www.blogger.com/atom/ns#' term='hackersafe'/><category scheme='http://www.blogger.com/atom/ns#' term='hackersafe website hacked'/><title type='text'>How safe is hackersafe?</title><content type='html'>A lot of websites now have the hackersafe logo displayed on their website. I've always wondered what this actually means for a website, what do they check etc.....&lt;br /&gt;&lt;br /&gt;Well today I got a phishing email, I followed the link to see who had been exploited this time. The phishing site was being hosted a few directories deep on the webserver so I backed up to the homepage (away from the Phishing site to the "real" site) to be greeted by the lovely hackersafe logo. The hackersafe logo proudly proclaimed that the site was hackersafe, certified today!&lt;br /&gt;&lt;br /&gt;Obviously the site isn't hackersafe. So what does this mean, is this a security company providing an inferior service spreading FUD and providing no real security? My opinion would be maybe, potentially there is a need for this kind of service but in my opinion hackersafe does not provide what its clients believe it does.&lt;br /&gt;&lt;br /&gt;It is worth noting that in October 2007 McAfee payed $51M (potentially rising to $75M) for hackersafe. The service being provided and those figures remind me of one thing, "This time next year, we'll be millionaires!" (Delboy, Only Fools and Horses).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-4612194465736032880?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/4612194465736032880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=4612194465736032880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4612194465736032880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/4612194465736032880'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/how-safe-is-hackersafe.html' title='How safe is hackersafe?'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-2059825173755580222</id><published>2008-06-06T14:04:00.000-07:00</published><updated>2008-06-15T08:10:47.186-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='David Rook'/><category scheme='http://www.blogger.com/atom/ns#' term='OWASP Ireland'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI DSS'/><category scheme='http://www.blogger.com/atom/ns#' term='IWTC 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='IWTC'/><title type='text'>My public security talks</title><content type='html'>This year has been good for me so far for public talking. I have been lucky enough to be invited to speak at the Irish Web Technology Conference (IWTC 2008) and an OWASP Ireland Chapter Meeting.&lt;br /&gt;&lt;br /&gt;I had a lot of fun doing these talks, IWTC was based in the Cineworld cinema in Dublin. It was a very strange feeling to actually be presenting my work on the big cinema screen where only weeks earlier I was watching Shrek!&lt;br /&gt;&lt;br /&gt;The IWTC talk was focused on a high level discussion of the current threats application developers need to protect against in 2008. I also discussed how to write code to protect against these threats. I finished off the talk with an explanation of the application security processes I have implemented at Realex Payments.&lt;br /&gt;&lt;br /&gt;The talk can be viewed here (Google Docs has broke some of it, contact me for the original): &lt;br /&gt;&lt;br /&gt;&lt;iframe src='http://docs.google.com/EmbedSlideshow?docid=dcd4c73_14djcqh9c5' frameborder='0' width='410' height='342'&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;In April Eoin Keary (OWASP Ireland Chapter Lead) invited me to talk about Application Security and the PCI DSS. The talk focused on how PCI DSS would affect an application developer along with an overall opinion on PCI DSS and how it applies to application security. I presented this talk at Ernst and Young in Dublin.&lt;br /&gt;&lt;br /&gt;The talk can be viewed here: &lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;iframe src='http://docs.google.com/EmbedSlideshow?docid=dcd4c73_3f4rwcwcz' frameborder='0' width='410' height='342'&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;All feedback, good or bad, is welcome!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-2059825173755580222?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/2059825173755580222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=2059825173755580222' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/2059825173755580222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/2059825173755580222'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/my-public-security-talks.html' title='My public security talks'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-887492972197912983.post-8272178582037229777</id><published>2008-06-06T13:51:00.000-07:00</published><updated>2008-06-06T13:57:39.038-07:00</updated><title type='text'>My first blog!</title><content type='html'>After reading so much about blogging I thought it was about time I started!&lt;br /&gt;&lt;br /&gt;I was inspired to start my blog after my friend Martin mentioned me on his blog (http://brigomp.blogspot.com/). As the blog is in Spanish all I understood was my own name, fortunately it was all good.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/887492972197912983-8272178582037229777?l=securityninja.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityninja.blogspot.com/feeds/8272178582037229777/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=887492972197912983&amp;postID=8272178582037229777' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8272178582037229777'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/887492972197912983/posts/default/8272178582037229777'/><link rel='alternate' type='text/html' href='http://securityninja.blogspot.com/2008/06/my-first-blog.html' title='My first blog!'/><author><name>David Rook</name><uri>http://www.blogger.com/profile/17825866700317798112</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
