Wednesday, March 19, 2008

Спасибо тебе, Google!

Анализируя события HTTP_Post систем обнаружения, я поймал ряд POST-ов на gmail. Сохранение пакетов событий было настроено, таким образом, мне были доступны пакеты примерно следующего вида:

Возникла идея на удачу попробовать ретранслировать пойманный пакет. Я был полон уверенности, что такая простая атака не пройдет с Google, тем не менее, любопытство взяло свое, и я решил все-таки попробовать.

Для ретрансляции я использовал Tamper Data, поместив в строке запроса Firefox то, что было в строке POST, запустил перехват:

Согласившился с запросом вмешаться:

В появившемся списке заголовков я добавил/отредактировал Cookie и Referer, взяв их из пойманного пакета:

Я продолжал соглашаться с вмешательством и подставлять Cookie до тех пор, пока промптеры о необходимости вмешаться престали появляться. Я отключил перехват. Примечательно то, что в окне браузера я все же не увидел Inbox другого пользователя (жертвы, чей пакет был пойман), чего, собственно, я и ожидал. Тем не менее, снова, так просто, на всякий случай, я набрал в строке браузера http://mail.google.com/mail/ и, к своему удивлению, провалился в Inbox жертвы.

Описанное выше происходило в пятницу 14 Марта, вечером. Тогда я решил, что возможно, Cookie еще не успели протухнуть, хотя, то, что эти Cookie можно повторно использовать – уже уязвимость, которую необходимо исправлять.

17 Марта, утром я повторил ту же самую, описанную выше процедуру, взяв за основу тот же самый пакет. К своему ужасу я снова попал в тот же ящик, сделав вывод, что пойманные мной Cookie не протухают никогда.

Далее, я решил выйти из ящика жертвы, сказав “Sign out”. Примечательно, что после этого действия фокус перестал работать: сколько я не пытался повторно послать пакет, я не попадал в Inbox жертвы.

Поскольку я сам являюсь фанатом и активным пользователем сервисов Google, я описал все свои дознания в службу поддержки Google (в раздел советов по улучшению http://mail.google.com/support/bin/request.py?contact_type=suggest )

На мой взгляд (я не считаю себя глубоким специалистом в безопасности Web), на тот момент были возможны следующие «улучшения»:

· Сделать Cookie одноразовыми или как-то шифровать их – это сделает невозможным их повторное использование;

· По окончании работы с GMAIL принудительно завершать сессию пользователя (принудительный Sign out), чтобы никакие Cookie не воспринимались вообще.

Никакой обратной связи о том, что мое «улучшение» принято/отклонено/в таком-то статусе, не было, тем не менее, на следующий день, 18 Марта я решил попробовать работает ли фокус (конечно, я взял другую жертву, не ту, которой я сказал “Sign out”) и, внимание, фокус не работал: как бы я не пытался повторно переслать пойманные пакеты, я постоянно попадал в приглашение ввести логин/пароль. Мне остается только гадать о том, была ли эта простейшая уязвимость изначально и потом исправлена после получения моего «улучшения», или уязвимость проявилась как побочный эффект каких-то работ, которые проводились на Google. Важно, что проблема исчезла, к тому же так быстро!

Friday, February 22, 2008

Sweet, sweet audit.

From osiris maillist:
"We are currently using Osiris to monitor Linux and Windows servers. We have an auditor that is stating that our 'File integrity monitoring is not appropriately configured'. However, we believe that we are 'appropriately' monitoring the correct files. He means that he doesn't believe that we are monitoring all of the proper files on our servers, that we are leaving important files unmonitored"

Unfortunately security auditors work usually based on "expert opinion", which have no fundamental base. So audit report is only opinion of one person without enough experience.

Thursday, February 14, 2008

Virtualization Project

Monday, January 28, 2008

Trend With Web Site Attacks

Web site attacks are going the same route as malware. In early days computer viruses mostly did something fun or just destructed some or all of your data (mostly without any obvious reason). Now they are used to earn money - spam, cyber extortions etc. Most of modern malware is staying stealth to not interfere with normal computer operation and avoid detection.

Same is true for latest web site breaches - attackers just slightly modify legitimate web sites to spread malware to their audience.

SecurityFocus: Attackers favor compromise over creation
SecurityFocus: Legitimate sites serving up stealthy attacks
PCWorld: 10,000 Web Sites Rigged with Advanced Hack Attack

Wednesday, January 16, 2008

New Banking Trojan

This is really awesome. Latest piece of technology from trojan makers. Please note the ability to defeat best practice of "authenticate transactions, not just sessions". This once again underlines importance of endpoint security - you cannot be safe if your computer is compromised.

http://www.symantec.com/enterprise/security_response/weblog/2008/01/banking_in_silence.html

The ability of this Trojan to perform man-in-the-middle attacks on valid transactions is what is most worrying. The Trojan can intercept transactions that require two-factor authentication. It can then silently change the user-entered destination bank account details to the attacker's account details instead. Of course the Trojan ensures that the user does not notice this change by presenting the user with the details they expect to see, while all the time sending the bank the attacker's details instead. Since the user doesn’t notice anything wrong with the transaction, they will enter the second authentication password, in effect handing over their money to the attackers. The Trojan intercepts all of this traffic before it is encrypted, so even if the transaction takes place over SSL the attack is still valid. Unfortunately, we were unable to reproduce exactly such a transaction in the lab. However, through analysis of the Trojan's code it can be seen that this feature is available to the attackers.

Tuesday, January 15, 2008

SANS: Top Ten Cyber Security Menaces for 2008

SANS has posted Top Ten Cyber Security Menaces for 2008.
To my mind this can be a good argument against low attention to securing employee Internet access and mobile devices.

New Boeing Vulnerable To Computer Attacks?

I wonder who makes such rubbish decisions? Isn't this in the school programme? :)

The computer network in the Dreamliner's passenger compartment, designed to give passengers in-flight internet access, is connected to the plane's control, navigation and communication systems, an FAA report reveals.
Wired: "FAA: Boeing's New 787 May Be Vulnerable to Hacker Attack"