Showing posts with label Articles. Show all posts
Showing posts with label Articles. Show all posts

Wednesday, April 6, 2011

The 10 Commandments of Internet Safety

Must draw a distinction between two types of hackers, the firstaims to do something bad, and the second aimed to create digital solutions more secure and in this sense we will give you a number of tips to avoid falling into the trap of bad hacking,


Use Strong Passwords

In general, the strongest passwords are sufficiently long (Experts recommend using 12 characters minimum according tothe latest studies), randomly generated and contain no words in any language. Most others are weak because of the cracking methods programmed into password cracking tools. The three main methods used are:
weak password attackCommon password weaknesses are exploited, such as blank passwords, the word password, the users' lognames or any other information the cracker may know about the user.
dictionary attack Word lists from various sources, including foreign language and slang, are encrypted and compared to the encrypted password.
brute-force attack Every possible character combination is encrypted and compared to the encrypted password until a match is found.

Have an operating system and software updates: browser,antivirus, office, personal firewall, etc..

Most attacks attempting to use a computer fault (faults of theoperating system or software). In general, attackers are looking forcomputers whose software has not been updated to use the faultis not corrected and thus manage to get inside. Therefore it isessential to update all of its software to correct these flaws.

Perform regular backups

One of the first principles of defense is to keep a copy of his datain order to respond:
  • Hardware failure. Disk failure is rare but it does happen.
  • Accidental file deletion.
  • Theft and natural disaster.
  • Catastrophic virus or spyware infections, if you have to erase your hard disk and reinstall everything.
Backing up your data is a requirement of the continuity of your business.

Disable default ActiveX components and JavaScript

Les composants ActiveX ou JavaScript permettent des fonctionnalités intéressantes mais ils présentent aussi des risques de sécurité pouvant aller jusqu’à la prise de contrôle par un intrus d’une machine vulnérable. En dépit de la gêne que cela peut occasionner, il est conseillé de désactiver leur interprétation par défaut et de choisir de ne les activer que lorsque cela est nécessaire et si l’on estime être sur un site de confiance.

Do not click on links too fast

One of the typical attacks to mislead Internet users to stealpersonal information, is to encourage them to click a link in a message. This link may be misleading and malicious. Rather thanclicking on it, it is better to grasp oneself site address in theaddress bar of your browser. Many problems will be avoided.

Never use an administrator account to surf

The computer user has privileges or rights on it. These rightsallow or not to conduct certain activities and access to certain files from a computer. A distinction is usually called administrator rightsand the rights of so-called simple user. In most cases, a simpleuser rights are sufficient to send messages or surf the Internet. Bylimiting the rights of a user are also limits the risk of infection orcompromise of the computer.

Control of Private Information

The Internet is not the place of anonymity and the information thatwe keep it there instantly escape! In this context, good practice isto never leave personal information in forums, to never enterpersonal data and sensitive (such as bank details) on sites that do not offer the necessary guarantees. When in doubt, better to do nothing ...

Never pass on hoaxes

A hoax is a message or warning that is not true. Computer virus hoaxes can cause a lot of confusion and wasted time amoung ordinary computer users, and sometimes quite technical people. Computer virus hoaxes are quite common and they usually warn about a new computer virus that no anti-virus software detects and which can do a lot of damage to files or computers. The biggest give-away is that they ask people to pass on the warning to everyone they know - this is how the hoax spreads.

In general, ordinary users should NEVER pass on warnings, and you should only expect to get warnings from a trusted source: your company's data security officer, or your ISP's technical support. The information in a real warning will be verifiable: if it says the information was released by Microsoft, there will be a link or reference to a Microsoft web page or press release.

If you receive a warning that you do not know whether to believe, contact your data security office, helpdesk, or us to check - we would rather answer your question once than questions from the hundreds or thousands of panicing people you might pass the message on to.

Be careful: the Internet is a street populated by strangers!

We must remain vigilant! If for example a corresponding wellknown and with whom you regularly exchange of letters in French, send a message with a title in English (or any other language)should not open it. If in doubt, it is always possible to confirm themessage by phone. In general, do not rely mechanically on behalfof the sender appears in the message and never meet a strangerwithout a minimum of care.

Use caution when opening attachments to e-mail

One of the most effective methods to distribute malicious code isto use email attachments. To protect yourself, never openattachments with the following extensions:. pif (such as anattachment called "photos.pif). com,. bat,. exe,. vbs,. lnk. AtConversely, when you send files as attachments to emails prefersending attachments in the most "inert"possible, such as RTF or PDF for example. This limits the risk of information leaks


References:

Thursday, March 3, 2011

Network intrusion methodology

The goal of this article is to explain the methodology that pirates generally use to infiltrate a computer system. Its purpose is not to explain how to compromise a system but to help you understand how the process works so you can better protect yourself. The best way to protect your system is to use the same approach pirates do in order to map the system's vulnerabilities. As such, this article does not provide specific information about how flaws are exploited, but rather it explains how to detect and correct them.




General methodology

Hackers intending to hack into computer systems firstly look for flaws, that is, vulnerabilities that can harm the system's security, in protocols, operating systems, applications or even an organization's employees! The terms vulnerability, breach and the more informal security hole are also used to refer to security flaws.
To be able to implement an exploit (the technical term that means to exploit a vulnerability), the hacker firstly has to retrieve a maximum amount of information about the network's architecture and about the operating systems and applications running on this network. Most attacks are the work of script kiddies foolishing trying out exploits found on the internet, with no knowledge of the system or of their related risks.
Once the hacker has established a map of the system, he is capable of applying exploits related to the versions of the applications he has indexed. Initial access to a machine will let him extend his action to retrieve other information and possibly escalate his privileges on the machine.
When administrator access (the term root access is generally used) is obtained, we say that the machine has been compromised (or more precisely, that a root compromise has occurred), since system files may have been modified. At this point the hacker has maximum rights on the machine.
If the intruding party is a pirate, he finishes by erasing his tracks, to avoid suspicion on the part of the compromised network's administrator and to be able to retain control over the compromised machines for as long as possible.
The following outline summarizes the full methodology: 


Retrieval of system information

Information about the targeted network's addressing, generally referred to as fingerprinting, must be obtained before an attack can be launched. This involves gathering a maximum amount of information about the target network's communication infrastructures:
  • IP addressing,
  • Domain names,
  • Network protocols,
  • Activated services,
  • Server architecture,
  • etc. 

Consultation of public bases

By obtaining the public IP address of one of the network's machines or simply the organization's domain name, a pirate is potentially capable of knowing the addressing of the entire network, that is, the range of public IP addresses belonging to the targeted organization and its breakdown into sub-networks. To do so, all he needs to do is consult the public bases that attribute IP addresses and domain names:
Consultation of search engines


The simple consultation of search engines sometimes makes it possible to gather information about a company's structure, the names of its main products and even the names of some of its employees. 

Network scanning

When the network's topology is known by the pirate, he can scan it, that is, use a software tool (called a scanner ) to determine the IP addresses active on the network, the open ports corresponding to accessible services and the operating system used by its servers.
One of the most widely known network scanning tools is Nmap, which many network administrators recognize as an essential tool for securing networks. This tool acts by sending TCP and/or UDP packets to a group of machines on a network (determined by a network address and a mask) and then analyzing the responses. Depending on the speed of the received TCP packets, it can determine the remote operating system for each scanned machine.
There is another type of scanner, called a passive mapper (one of the most well-known is Siphon), that makes it possible to find out the network topology of the physical thread on which the mapper analyzes packets. Unlike the previous scanners, this tool does not send packets over the network and therefore cannot be detected by intrusion detection systems.
In addition, some tools make it possible to receive X connections (an X server is a server that manages the display of UNIX type machines). This system is designed to be able to use the display of stations present on the network to study what is posted on the screens and to possibly intercept the keys entered by users of vulnerable machines.


Banner grabbing

When the network scan is finished, the pirate simply needs to examine the log file of tools used to find out the IP addresses of the machines connected to the network and the open ports on the network.
The numbers of open ports on the machines can provide information about the type of open service and invite him to interrogate the service to obtain additional information about the server version in the so-called "banner" information.
As such, to find out the version of an HTTP server, a pirate can just Telnet to the web server on port 80:
telnet www.commentcamarche.net 80
then request the welcome page:
GET / HTTP/1.0
The server then responds with the following header:
HTTP/1.1 200 OK
Date: Thu, 21 Mar 2002 18:22:57 GMT
Server: Apache/1.3.20 (Unix) Debian/GNU
The operating system, server and its version are then known.

Social engineering

Social engineering involves manipulating human beings, that is, taking advantage of the naivety and excessive kindness of network users, to obtain information about the network. This process involves making contact with a network user, usually by impersonating someone else, so as to obtain information about the information system and possibly to directly obtain a password. Similarly, a security flaw can be created in the remote system by sending a Trojan horse to some of the network's users. All it takes is for one of the users to open the attachment for internal network access to be given to the external attacker.
This is why security policies should be comprehensive and incorporate human factors (for example, raising user awareness about security problems), since a system's security level is characterised by its weakest link.


Spotting flaws

After drawing up an inventory of the software and possibly the hardware present, the hacker needs to determine whether or not there are flaws.
Vulnerability scanners are available that let administrators subject their networks to intrusion tests to find out whether certain applications have security flaws. The two main vulnerability scanners are:
Network administrators are also advised to regularly visit websites that keep a vulnerability database up to date:
In addition, some associations, particularly CERTs (Computer Emergency Response Teams), are in charge of capitalising on vulnerabilities and gathering together information concerning security problems.
  • CERT IST dedicated to the French Industry, Services and Tertiary community,
  • CERT IST dedicated to the French administration,
  • CERT Renater dedicated to the community of GIP RENATER members (Réseau National de télécommunications pour la Technologie, l'Enseignement et la Recherche). 

Intrusion

When the pirate has drawn up a map of resources and machines present on the network, he is ready to prepare his intrusion.
To be able to infiltrate the network, the pirate needs to access valid accounts on the machines he has indexed. To do so, pirates use several methods:
  • Social engineering, that is, by directly contacting certain network users (by email or telephone) in order to squeeze out information concerning their user ID or password. This is generally implemented by impersonating the network administrator.
  • Consultation of the directory or of messaging or file sharing services making it possible to find valid user names
  • Exploitation of vulnerabilities in Berkeley R* commands.
  • Brute force cracking, which involves automatically trying out various passwords on an account list (for example, the ID possibly followed by a number, or the password password or passwd, etc). 

Privilege escalation

When the pirate has obtained one or more accesses to the network by working off of one or more accounts with low protection levels, he will look to increase his privileges by obtaining root access; this is called privilege escalation.
As soon as root access has been obtained on a machine, the attacker can examine the network to look for additional information.
He can then install a sniffer, that is, a software program capable of monitoring (the term sniffing is also used) network traffic coming from or directed at machines located on the same thread. Thanks to this technique, the pirate can hope to retrieve ID/password pairs giving him access to accounts with privileges extended to other network machines (for example, access to an administrator's account) in order to be able to control a majority of the network.
NIS servers present on a network are also preferred targets of pirates since they are packed with information about the network and its users.


Compromise

Thanks to the previous steps, the pirate has been able to draw up a complete map of the network, of its machines and of their flaws and has root access to at least one of them. He can now extend his action even further by exploiting the trust relationships that exist among the various machines.
This identity spoofing technique lets the pirate penetrate privileged networks the compromised machine has access to.


Backdoor

When a pirate has successfully infiltrated a company network and compromised a machine, he may want to be able to come back. To do so, he will install an application in order to artificially create a security flaw. This referred to as a backdoor; the term trapdoor is also sometimes used.

Covering tracks

When the intruder has obtained sufficient control over the network, he needs to erase evidence of his visit by deleting the files he created and by clearing the log files of the machines he intruded, that is, by deleting activity lines relating to his actions.
There are also software programs, called "rootkits", that make it possible to replace the system's administration tools with modified versions in order to hide the pirate's presence on the system. If the administrator connects at the same time as the pirate, he is likely to notice the services the pirate has launched or simply see that someone else is connected simultaneously. The goal of a rootkit is therefore to fool the administrator by hiding the reality.


Conclusion

All managers of networks connected to the internet are responsible for the network's security and should test its flaws.
This is why a network administrator should keep informed of vulnerabilities in the software programs he uses by "putting himself in the shoes of a pirate" in order to try to infiltrate his own system and continuously operate in a context of paranoia.
When the company's own skills are not adequate to carry out this operation, an audit can be performed by a company specialized in computer security.

More

Article written by Jean-François PILLOU, based on an article by GomoR.

Tuesday, March 1, 2011

The different types of attacks

The computer is a very wide area, the number of vulnerabilities on system may be important. Thus, attacks against these vulnerabilities may be the both very diverse and very dangerous. Therefore we will initially analyze what we call "the anatomy of an attack, then a second time, we characterize these attacks and observe their progress.



Network attacks

This type of attack is based mainly on faults related to the protocols or their implementation.
Observe some well-known attacks.
  
Scan techniques

Port scans are not attacks itself. The purpose of the scans is determine which ports are open, and thus deduce the services are performed on the target machine (eg port 80/TCP for an HTTP service). Therefore, most attacks are preceded by a port scan at the Probe phase which is as we have seen, the first phase of the 5P's, in the course of an attack.
 
There are a large number of scan techniques. Ideally, the best scan technique is one that is more stealth so as not to alert the suspicions of the future victim.

IP Spoofing

Target: To spoof the IP address of another machine.
Purpose: to impersonate another machine faking IP packets. This technique
may be useful in the case of authentication based on IP address (such as services
rlogin or ssh for example).
Finality: to impersonate another machine faking IP packets. This technique
may be useful in the case of authentication based on IP address (such as services
rlogin or ssh for example).
Stages: There are utilities to change the IP packets or create their
own packages (eg hping2). With these utilities, you can specify an address
IP different from what one has, and so pretending to be another "machine ".
However, this poses a problem by specifying a different IP address for our machine,
we will not receive responses from the remote machine, since it will answer
spoofed address.

ARP Spoofing (ou ARP Redirect)

Target: To redirect traffic from one machine to another.
Purpose: Through this redirection, an attacker can impersonate
another. In addition, the attacker can reroute the packets it receives to the real consignee, so the user does usurped will realize nothing. The purpose is the same as IP spoofing but it works here at the data link layer.
Finality:: To perform this usurpation must corrupt the ARP cache of the victim. This which means that we must send ARP frames, stating that the IP address of another machine is his. ARP caches are regularly emptied, care must be taken to maintain usurpation.

DNS Spoofing 

Target: to provide false answers to DNS queries, that is to say, indicate a false address IP for a domain name.
Finaly: redirect unwitting surfers to sites of pirates. With this false
redirect, the user can send his credentials in confidence for example.
 

Fragments attacks

Object: The purpose of this attack is to bypass the protections of filtering equipment IP.
Purpose: In bypassing protections, such as a hacker can penetrate a
network to carry out attacks or retrieve confidential information.
 

TCP Session Hijacking

Object: The purpose of this attack is to redirect a TCP stream in order to override a password protection.
Purpose: control of authentication taking place only at the opening of the session, a pirate attack that successfully manages to take possession of the connection throughout the duration of the session.
Process: firstly, the attacker must monitor the network, then when it considers
that authentication has occurred (time of n seconds for example), it's out of sync
session between the user and the server. To do this, it constructs a packet having
source IP address, that of the user's machine and the TCP acknowledgment number expected by the server. In addition to synch the TCP connection, this package allows the attacker inject a command through the previously established session.
 

Application attacks

Application attacks rely on flaws in the programs used, or still misconfigurations. However, as before, it is possible classify these attacks according to their origin.

Configuration problems

It is very rare for network administrators configure correctly program.
In general, they simply use the default settings. These are often unsafe to facilitate the operation of the software (eg login / password of a default server database).
 
In addition, errors can occur when configuring software. A a server misconfiguration can lead to access important files, or involving the integrity of the operating system. It is therefore important to read documentation provided by developers to avoid creating faults.

Bugs 

Related to a problem in the source code, they can lead to exploitation of vulnerabilities. It is not uncommon to see the operation of a machine following a simple error programming. It may not do anything against such problems, except wait a patch from the developer.

Buffer overflows

Buffer overflows or stack overflow, are a special category of bug.
Coming from a programming error, they can operate a remote shellcode3.
This shellcode will allow an attacker to execute commands on the
remote system, up to its destruction.
 
The programming error is often the same: the size of an entry is not
Entry is checked and copied directly into a buffer whose size is smaller than the sizethe entrance. 
We find ourselves in a situation of overflow, and the operator can access memory.

 Scripts

Mainly web (eg Perl, PHP, ASP), they are running on a server and returns a
result to the client. However, when dynamic (ie they use inputs entered by a user), faults can occur if the inputs are not properly controlled.
The classic example is the use of remote file, such as displaying the file
password system, up the tree from the web directory.

SQL Injection

Like scripting attacks, SQL injections benefit of input parameters unaudited. 
As their name suggests, the purpose of SQL injection is to inject SQL code
in a query database. Thus, it is possible to retrieve information is
found in the database (eg passwords) or destroy data.
 
  
Man in the middle
 
Less known but equally effective, this attack can divert traffic
between two stations. Suppose a client C communicates with a server S. A hacker can divert traffic from the client by passing queries from C to S P by his machine, then forwarding requests from P to S. And vice versa for responses from S to C.
 
Completely transparent to the client machine P plays the role of proxy. It accesses
and to all communications and can obtain information without the user noticing.
 

Denial of service 

Mentioned above, denial of service attack is to make unavailable service. 
This can be done in several ways: through a network overload, making the machine totally unreachable, or so in application crashing
the application remotely.
 
The use of a buffer overflow may allow remote crash the application.
Thanks to some malicious instructions and following a programming error, a
someone could make available a service (web server, server messaging, ... etc.) or even a complete system.
 

Why is this post important ? 

This story displays the attacks adopted a more streamlined for a previous topic as well as the importance of where we will explain one of these attacks in more detail in future.
  
Reference
Les systèmes de détection d'intrusions,
David Burgermeister, Jonathan Krier