Thursday, January 9, 2014

Exercises for CSIRTs

Good training materials from ENISA for developing incident response skills.

Wednesday, December 11, 2013

Joining OWASP

I've decided to support it's mission and I have joined OWASP.

You can reach me via following email adress: mzet [at] owasp [dot] org.

Use my PGP key when sending sensitive information (you are encouraged to verify the fingerprint of this key before using it - use public keyserver for that):

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.14 (GNU/Linux)

mQINBFKnSIcBEAC2fElJJxy+OHDIQ1hyAgxf02N52nyzxTWc63rhDxhGfFsrfgZt
LrXLssuvXyzLx7qmCjIWPVY2KiM4znppwctJYoUwBysnunzFX7/Hviv8sNaTf9ve
NDfDBx/6ByTX1Jvn8opeSGYFnRFMMipTVtegweKng3Pc/L4D43bo1QEiDeJR0sI5
cSNd36kXehIgU/NfBxUMYfKwxIFRT5oNOZMO0Vu0Etbgt7E3MztzffzKzW2iK4mk
qXQ/YkH1I0FT+DLaNa4rv5vSrzQB4aW5s0/ioyXb0Eyr8Vi3/uxEnVgROZWTYSf1
rdbApKwY8HREBIwczUuoWaCalu56OXHHMVU5bLdgly7EpscitRncXUxevB9gHekG
u/CPvxFGv33UiDeuebDGxRlF6qZqzcfFFGwdc8D1XTIPk2cVrKvdcqw6xTN5M0wg
Cm2GJ6YBZE+Dz1jy5qfldJAC1DZSGrZzcsGIbwDAq6Qt0UAYeXQEbIjLCGU3xLBt
yaVn0gK9B8BxLgVfnrdVHlopLNo7pS7Z9rtw9roHxrNeMg6302MIsZ/bXqwk7zC6
vUabxW64NCo2nfHpryLOEhw5hHcPg0PJ79YF5yq4PP7q9u7Jorlui8tN47iJmIvE
rNuM4ywmG5IhdLEsv0xYJVzy2N6db37oZw7opGKV9yCjXz1Sl3wEjuCVHQARAQAB
tB9NYXJpdXN6IFppdWxlayA8bXpldEBvd2FzcC5vcmc+iQI+BBMBAgAoBQJSp0iH
AhsDBQkDwmcABgsJCAcDAgYVCAIJCgsEFgIDAQIeAQIXgAAKCRAJqYwipRPWc+Oz
EACM1pzEbV1iRl6vbHpK1zncg4Eg+v65A3XDqYQs5FO36kCs8l+D15qzItqmHATJ
ZRNtdkSgzNEz5iu/RQ0/Zl278wS87U8zztqM/4v7REH9FwfyOV0KQ5kjOs+QdbvX
4jYPQvT7kdPICRp5hWJ//WVrFERmKBfACoQyz3UzfBygS8L+Cvph0TtsWovLdMCa
Ks2rxAh7wzHw550VZhGRW+9WeLcTDc1niFPTw1oFQ2OooHR5HMoOHvGCZKEBhbkr
Wp9Y78PxEaT+BAcZnRPEqzqdJ7qRdskWAw/3d2On5fjRNZyaKhcJ5+UdMcLKp1eH
pr0WOdPjQBDrYIFv5RGWWs2Bm8OitpCx907QzDnL8gnaOGSUw/X4zrOf+6YgSyMj
oA19aWgjqK8K09lUZsEI+ESYj5jWIJQg8MomLocvvOr7BcOeGpRATly4lE0+9Un8
t+eaGiHZQ8Bcz5Zga864APPgpJzqhWfUVnVCAWua/dXfvl3T7UPIn2Py4N0DyC29
qORaF7eo/RDOGernHWtR/yJATRnguaxmrxUcfG7tM5vaKkbVF3U8hmsgk5xZkShp
WRX324IwN5PnUfPo9sE7bdog95omL0HhnzhjGG6uAbfM5o2rGr5X1cXHQFovExoo
2tzwk2N4oGuSk3MpbvS55n8LHSZaEpxnnlmRh+ft9kAB3LkCDQRSp0iHARAAw2Zr
CmXDK56N+x3enjsqUqbZ0+MnHFx8rx3IEHGR9WDrPbUFC23XdN1rGMDmiaTVyYpd
+Mg5EWWKPQ66EFgVMg8OybVxYfdkc/0/xBNUH65p/hIRBjlIVTQR6v1P22lRtTO8
UoAkZ+jeyXxXn4ezEKlSv4DQg4DQ/ljFSDLE9AZitoshE9fg+GJ8h5RfctRCW/8z
ONjNaYWMyYSV7uoyQBDWebEcNnBLoKt004AHr+xY0sBgLyN1y7fs3qXnZvgy2gxx
WG5LsLHtT7AXzkPbMUHal/b2AXSke+YT2CoqQjEHgTUytfaf+9Kb1/rHI5wwEpNu
YYWkBkFOeOC0hzo4xwsD5GjzP1Niw9ACQKhFF8ZLDooZbs2v/mq+I4+lucbeRDNV
UBfZ1i1es+F5JEL2clNaPKnJrfX5RQ0+2QpV6yKlEF2pYIRhzMc+oNLCtAD0uOMT
CoRUJBRxFk24fYEhvom9WsG8lMN7rvoh8Y9RcsM9kRjsfcPZWz70GoUVTLDDNuz3
g7NAv6H/yP4Uys0uAetQNrvTZ52oaBK65XrrwEekC8GqAjJnuRlyAAqMz4jIrtIn
C9gC4yjD99QSlLn7EFIcXc3l3BltpWCcTGQoKMptfwF1T+Nfv1UCK4tzhHeHZwyS
BSHcDtbkUuxgb3EcTCzYvf4m9UQppqSfQBAADokAEQEAAYkCJQQYAQIADwUCUqdI
hwIbDAUJA8JnAAAKCRAJqYwipRPWcw/HD/90WgsPDv/AJSU7ajxXAd5Pv5ouj9QT
l9z1MeYyxiUX9e8wmhZgOzeQouBjhdbWV8M31Mz0QSxYImsPTspzEVqx9c5GgUU1
olYSEkt8xapp21K+3lbi+NXPOaOF4PFff0RUpCtxuECuxXOx8X/q6BlshfKASrzM
V7suSQt1i+d4EZKq/S99Q5IYtWmWAypyPp+xaGlqbjxxpedzfux4qxYjsvF4g7Wm
TwO4d5Dr6eYlaR5vJiGZv43C637Sq0w4y1VD06SnqqR57QKTbWFn2K7laUdK4yQB
sghHQRde+czx3FeHXBWKGJ+EQG7QzN2Y5qexTtBL8kdYamkwOgUyaPCAPSzDiepK
ACATVT8rg6pckWp5rlUGoBP3bWtj2B+WI5KWbwGwizia++XLrJd0kdXAKrzzF7vg
Eadst0cz7f90gMz/PKHW8iw4qqCm3jjR37uUUlh0xI0da4c0/6vzPqaKK6Udgb2I
5Z44mObhbF4r+NER4P2SmgnI/Y1ztNUoT1W53IACblibjMa5kQy0Db0jnE49nWBM
Gg1E+XjscXFzI3T1Hzgf4eA1FIDdumT/1gPflfMU+1QQWJn8lPCqiG1nwG223Uwf
7kE7tUaG1wkmcgfy2/voy7xbevc6Aa58wsPs9aA9FO+kV8jSAvMdkZ4d/U/aecQl
PYWjMy0tteEVFw==
=nusV
-----END PGP PUBLIC KEY BLOCK-----

Key fingerprint = 4DA1 6296 AD30 5875 7F36 EC9A 09A9 8C22 A513 D673

Sunday, November 24, 2013

OWASP Appsec Tutorial Series

Good videos by OWASP. Be sure that developers in your team have watched it.

Friday, November 22, 2013

BKMs #0: Setting Up air gapped machine


Here's how I've setup and maintain Linux-based (Debian) air gapped computer.

Getting Debian

1) From trusted environment (I used computer and network at my work) I've downloaded debian.iso:

 $ wget http://cdimage.debian.org/debian-cd/7.2.0/i386/iso-dvd/debian\ 
-7.2.0-i386-DVD-1.iso

2) I've downloaded SHA1 sum and it's signature:

 $ wget http://cdimage.debian.org/debian-cd/7.2.0/i386/iso-dvd/SHA1SUMS.sign

3) To verify signature I needed Debian's cd/dvd signing key:

I googled exactly what I needed: "debian cd signing key", first match looked very promising: http://www.debian.org/CD/verify

I found (there was also second key with uid "Debian CD signing key" but with older date) what I was looking for:

pub   4096R/6294BE9B 2011-01-05
Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B
uid Debian CD signing key
sub 4096R/11CD9819 2011-01-05

To be sure that http://www.debian.org/CD/verify site wasn't compromised at a time I was viewing it - I visited Google Cache of this site and compared key of interest:

pub   4096R/6294BE9B 2011-01-05
Key fingerprint = DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B
uid Debian CD signing key
sub 4096R/11CD9819 2011-01-05

Good - exactly the same. One have to bear in mind that best practice is to check keyid/fingerprint of given cryptographic key from at least two sources (it's more difficult to compromise two sources at once). I used official Debian website as a first source and Google Cache of this site as second source. It's somewhat simpler approach (I don't need to look for second source which is sometimes tedious) but it's crucial to check date of generating cache by the Google. In this situtation older cache is better, for example if cache was generated ten days ago (and keys are identical on both current and cached versions) it means that site wasn't compromised OR it was compromised but nobody spotted it for 10 days (which is highly unlikely because many Debian developers see and use this site and would notice that keys listed there are forged).

4) Now that I identified valid key and verified that the source of it wasn't compromised, I could fetch key from public keyserver (using key id from above listings) and verify it's fingerpint:

 $ gpg --keyserver pgp.mit.edu --recv-keys 0x6294BE9B
$ gpg --fingerprint 0x6294BE9B

Key fingerprint = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

Good - it's the same as advertised by key owner.

5) Now I can validate (by validating the key I confirm that I trust the owner of the key):

 $ gpg --edit-key 0x6294BE9B (in prompt choose: trust,3,quit)

6) Finally with valid key I can verify signature of downloaded iso image:

 $ gpg --verify SHA1SUMS.sign

7) I burned downloaded iso to DVD disc.

Installation

1) I used my legacy PC machine that I haven't used anymore (even better is to use completely new computer). I used magnetic (as opposed to SSD) disk (it much more difficult to securely erase SSD disks).

2) First I wiped out all the data from the disk (to do that I had to download Debian's liveCD and burn it to CD disc - I've made it from my trusted computer. I followed steps above when downloading livecd), then I boot it on my computer and I run:

 # shred /dev/sda

3) I've double checked that computer isn't connected to network and that it doesn't have wifi card installed (from this point on it will never be connected to network again). Now I could start installing OS.

4) I used following guide to do whole-disk encryption (I skipped part with setting up recovery system). I used Blowfish as an encryption algorithm (I do not trust AES anymore). I used this advice for choosing strong password that I could remember.

Usage

1) I bought new pendirve for moving files on and off my air-gapped machine (by the way I called it vault :) and I shredded it and created FAT16 partition:

 # shred /dev/sdb
# fdisk /dev/sdb (n,t,w)
# mkdosfs -F 16 /dev/sdb1

2) I generated gpg key pair on the vault and copied public key to pendrive:

 $ gpg --gen-key
$ gpg --armor --output vault-key.asc --export

Assumption is that private key will never leave vault machine. I copied public part (vault-key.asc) to my pendirve and I will share it with persons I need to communicate securely (of course I will also need their public keys for secure 2-way communication).

3) Also pendrive's whole-disk encryption is worth considering but I wanted to be able to use this pendrive both on Linux and Windows machines so I skipped this step for now (when I will transfer something sensitive I can always encrypt it with vault's public key).

4) I have now reasonably secure, air gapped computer. It's by no mean perfect: the way how files are transfered back and forth vault is obviously it's weakest point. Trusted "converters" or "verifiers" as mentioned here would help, but someone would have to write it first which isn't trivial.

5) Some typical maintenance issues and the way I deal with it:
- In case I will need more software I can always repeat steps "Getting Debian" to download second (or third) Debian's DVD.
- Keeping software up to date can be achieved by downloading Debian's update iso images.
- One more thing that I leave for now is maintaining secure backups of vault's disk - but it's doable.

Monday, November 18, 2013

Autumn hiking in Owl Mountains

(in Polish)

Jesienny wypad w Góry Sowie i okolice Wałbrzycha, zaowocował trzema kolejnymi "zdobyczami" z listy Korony Gór Polski: Wielka Sowa, Waligóra oraz CHełmiec. Poniżej kilka zdjęć z wyprawy:







Góry Sowie, Wielka Sowa - 1015 m n.p.m.


Góry Kamienne, widok z Waligóry (936 m n.p.m.)


Góry Wałbrzyskie, Chełmiec - 851 m n.p.m.


Saturday, October 19, 2013

Setting Up a Metasploit Development Environment for CentOS/Fedora

Here are steps to quickly set up development environment for Metasploit Project on rpm-based (CentOS & Fedora Core) Linux distros. The following is shortened version of official Metasploit tutorial (which describes whole process for Debian/Ubuntu distros). Idea is to prepare basic environment to start development quickly.

Install required packages:
 # yum -y install postgresql-devel libpcap-devel git
Install Ruby environment:
 $ curl -L https://get.rvm.io | bash -s stable --autolibs=enabled \
     --ruby=1.9.3
I got complaints about checksum verification, so I had to run:
 $ ~/.rvm/bin/rvm get stable
and now rerun:
 $ curl -L https://get.rvm.io | bash -s stable --autolibs=enabled \
     --ruby=1.9.3
Source rvm environment for current Bash session (also remember to add it to your ~/.bashrc):
 $ source ~/.rvm/scripts/rvm
Set your default ruby and gemset:
 $ rvm use --create --default 1.9.3-p448@msf
On CentOS when I tried to run from my metasploit-framework checkout:
 $ gem install bundle && bundle install
I got following error message:
 ERROR:  While executing gem ... (Gem::FilePermissionError)
 You don't have write permissions into the
 ~/.rvm/gems/ruby-1.9.3-p448@msf/bin directory.
It turned out that ~/.rvm/gems/ruby-1.9.3-p448@msf/bin directory doesn't exist - creating it solved the problem:
 $ cd ~/.rvm/gems/ruby-1.9.3-p448@msf
 $ mkdir bin
Ater rerun:
 $ gem install bundle && bundle install
I got similar error message (on CentOS):
 ERROR:  While executing gem ... (Gem::FilePermissionError)
 You don't have write permissions into the
 ~/.rvm/gems/ruby-1.9.3-p448@metasploit-framework/bin directory.
As previously, creating bin/ directory solved the issue:
 $ cd ~/.rvm/gems/ruby-1.9.3-p448@metasploit-framework
 $ mkdir bin
From now on bundle installation went smoothly and soon I was able to start msfconsole from my metasploit-framework directory:
 $ ./msfconsole -L
It's all that is required to start hacking on Metasploit codebase. I've ommited some optional steps listed in official tutorial - most notably step with forking official Metasploit repo, but because it is only required to perform pull requests, one can postpone it for now and do it when his new feature/module will be initially implemented.

Monday, September 30, 2013

Patch to Nmap: adding APT1 malware fingerprints

Mandiant company released fingerprints of SSL certificates used by APT1 malware, it's valuable threat intelligence data so I thought it's worth to add it to Nmap.

With this simple patch Nmap gained capability to warn you when it finds a HTTPS server which supposedly belongs to APT1's attack infrastructure. Simply run:
 $ nmap -n -P0 -p 443 --script ssl-known-key <YOUR-NETWORK-IP-RANGE>
to discover signs of APT1 in your network.