Saturday, July 23, 2011

Orion 0.4 Squirrel Edition Released

The Orion Live CD is an Ubuntu-based environment for computer security analysts and incident responders to acquire and analyze data, track case information, and collaborate securely over SSH tunnels.

I started Orion as the last project for my Masters of Information Security Engineering degree with the SANS Technology Institute. The Orion project team is small right now (there are three of us), but we're always on the lookout for the right new members to add.

Please check out version 0.4 (AKA the “Squirrel Edition”) at the sourceforge site:

http://orionlivecd.sourceforge.net

Friday, April 01, 2011

SANS Community Albuquerque: Come learn current hacker techniques!

I keep having this conversation with former students: "Hey John, remember that thing we talked about in class? It's just like what was in the news the other day!"

Exactly.

The SANS Hacker Techniques, Exploits, and Incident Handling class (SEC 504) has one goal: Teach defenders how attackers are breaking into systems and how to defend against those attacks.

I am pleased to announce that I will be teaching SEC 504 at SANS Community Albuquerque April 25-30. We'll cover the material written by the visionary Ed Skoudis and his co-authors. We'll also discuss current news and what's going on behind the scenes. And, we'll end the week with a rockin' cool Capture the Flag contest to test your new and existing skillz.

Come join me! I guarantee a fun and informative week. :-)

Sunday, January 09, 2011

Lector, si monumentum requiris, circumspice

When Christopher Wren died in 1723, this epitaph was inscribed on his tombstone at St. Paul's Cathedral in London: Reader, if you seek his memorial, look around you.

As one of the most noted English architects, and founder of the Royal Society, the monument to his memory was wrought by his own hands over many years before his mortal end.

It is telling that part of Wren's material legacy included the rebuilding of 50 churches and St. Paul's Cathedral after the Great Fire of London in 1666. From chaos, order. Now, just in case I have piqued the interest of freemasons and occultists -- I really mean this in the most literal sense: the destruction wrought by nature (or even not by nature) has always become an opportunity for creative minds to build something from the ashes.

This cycle of destruction and rebirth is the true human condition, but the detail we often forget is that we create the order and the chaos.

Every day, look around and ask what your monument will be.

Tuesday, November 30, 2010

You keep using that word...

A few weeks ago I found myself at a vendor presentation by a well-known physical security vendor. I was looking forward to the discussion on "advanced video analytics" and other cutting edge developments. Unfortunately, this was a pure sales pitch... and the "advanced technology" was primarily focused on how this vendor could help scale the customers' security camera video storage by placing it on a "secure server in the cloud."

I was quiet up to this point in the presentation. But, I had to ask: "What do you mean by, a 'secure server' in the cloud?" The room got a little quieter. The sales guy, his pace interrupted, looked at me with complete sincerity and said: "I mean we secure it for you."

I didn't think he meant that he, himself, was hardening the OS and running assessments against it. Even so, with security cameras and alarms as their forte, I couldn't understand how it made sense for anyone at his company to provide such a service.

The morale of this story is: Question everything.

I would never trust my security camera video data to a company storing it in the cloud -- at least not until I had a chance to check it thoroughly (yes, myself). Believe me, I've recently checked other products thoroughly and found them -- let's just say -- not quite meeting expectations.

Saturday, June 12, 2010

Orion Lucid 0.1 RELEASED!


The Orion Incident Response LiveCD (okay, LiveDVD) has been released at:

http://sourceforge.net/projects/orionlivecd/

This is the first public release, and is based on Ubuntu Lucid Lynx. The original alpha version was based on BackTrack 4, but we decided to switch for a variety of reasons. Because of this, there are a few bugs that need working out.

To read the paper that goes with it, see:

http://bit.ly/cFWFSQ

--john

SANS Technical Institute Masters Graduation

Last night I received my Master of Science in Information Security Engineering degree from the SANS Technology Institute (STI) at the SANSFIRE 2010 conference in Balitmore. I was also asked to give a speech. A few people have asked for a copy, so I am posting it here:

Good evening, and thank you for attending.

If I seem a bit nervous, it's because I don't normally read speeches -- I prefer "winging it." But I won't waste your time today with extemporaneous rambling. Besides, I have a few important things I want to say.


I especially want to thank the families and friends of the graduates who were able to make it today. My own family traveled from California, Texas, and New Mexico to be with us. I am very thankful that you could all be here today, and I deeply appreciate the support and sacrifices of my wife and two daughters over the last few years while I was working nights and weekends toward this goal. I know I share this sentiment with my fellow graduates.


Thank you also to the SANS Community. Without you, none of this would be possible. From the excellent instructors and gifted students to the SANS Forensics blog team and active SANS mailing lists, you continue to create the most productive and inquisitive organization of network security experts in the world.


The SANS Technical Institute leaders and staff also deserve a huge Thank You today. Stephen Northcutt, Alan Paller, Eric Cole, Johannes Ullrich, Ed Skoudis, and others have put forth a vision, and have applied all their formidable talents to turn it into a reality. STI, if you haven't heard, has achieved candidacy status -- an impressive accomplishment in such a short time. And Dean Debbie Svoboda, perhaps more than anyone else, deserves our appreciation -- as the rudder (and sometimes even the sails) to make this ship go.

I also want to congratulate my fellow graduates: John, Rob, Rodney, and Tim.
As graduates, our work on our masters degree programs is now complete. However, the real work has only just begun.

Recently I re-read my student outcome statement. In it I wrote I was inspired by the sci-fi/cyberpunk author William Gibson, who coined the term Cyberspace in the 1980's.

Gibson painted a fascinating, but dark, picture of the future where technology leads to black market cybernetic augmentation, pervasive surveillance, Console Cowboys controlling cyberspace, the blurring of government and mega-corporations, and blended military operations of electronic and conventional warfare.

Here is a passage:


"You're a console cowboy. The prototypes of the programs you use to crack industrial banks were developed for Screaming Fist. For the assault on the Kirensk computer nexus. Basic module was a Nightwing microlight, a pilot, a matrix deck, a jockey. We were running a virus called Mole. The Mole series was the first generation of real intrusion programs."


Now, just as in the real world, a lot of that sounds simultaneously scary and exciting. But, our goal, as leaders, should be to guide us to the brighter, rather than the darker, aspects of that future. As you know, cyberspace has already become the New Arms Race. As SANS graduates, instructors, and students... we each have a larger role to play. In Randy Marchany's recent blog posting ("Building Skynet -- The Beginning"), he states that we are the Builders in this arms race, but we are not the Controllers. We understand things, and think we have a handle on them, but we are not always making the decisions. Randy concludes with two "Ugly Secrets" that most of us here know very well: ONE) We know we are becoming a surveillance society, because we are helping to build it, and TWO) The Controllers trump the Builders. Some of these controllers are the management and government officials who might, say, turn things we build into weapons of mass destruction, BUT ... more insidiously ... sometimes we hand Control over to automation. You know this is true if you simply recall the last time you were told, with a shrug of resignation:


"I'm sorry, there is nothing I can do, it's the computer."


So, this is my challenge to you: While you are building -- build integrity and checks-and-balances into your creations. Make sure, to the best of your abilities, that you are not enabling the leverage for oppression or creating the surveillance state. And, be very, very careful about ceding the Controller position to automated software. We write the software, and we know it can make mistakes, because WE make mistakes. Bake this thinking in to what you do, who you know, and what you teach. You are leaders, and this is your... And my... Responsibility. This is the challenge I issue to you: the graduates of STI -- and the entire SANS community. And... I am heartened, as I look around the room, because I know we have the right people to do the job. It's not an easy job, but I am still inspired by the words of a certain dead president, that we do these things:


"not because they are easy, but because they are hard, because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one which we intend to win."


Thank you.

Tuesday, May 18, 2010

You ate... what?

Tonight a friend and I shared a dessert that is positively the strangest one I've ever had. We went to Layang Layang, a Malaysian restaurant in Cupertino. Our food was excellent -- and exactly what I was craving.

But, the star of the meal was this dessert, the Ice Kacang (aka, "A.B.C."). I saw a picture in the menu and read a description before we ordered it. It didn't matter. I still wasn't prepared for the mountain of shaved ice mixed with a bizarre (yet, excellent) combination of ingredients. It arrived to at our table looking like an icy volcano drizzled with caramel. Digging into the center brought more surprises in the form of sweet corn kernels, palm seeds, and little green jelly cubes. Two of us could not finish it, but it had a fascinating array of flavors -- including some that our palettes had absolutely no reference for.

I'm definitely glad we decided to be adventurous. I recommend trying it if you find yourself in the Cupertino area.

Thursday, June 18, 2009

Juicy, juicy mangoes!

I used to like mangoes okay.  They were good, but a little over-sweet and a little stringy.

It turns out... I really, really like mangoes.  It's just that I hadn't had a very good one until this week.

My wife orders a box of organic produce every other week, and we got two slender, yellow mangoes.  These are from Mexico, are organic (obviously), but I don't know the name.  They are INCREDIBLE.  Juicy, smooth-as-silk, and sweet with a little bit of limey tartness.

I just cut one up for lunches tomorrow, and I'm already obsessing over how to get more.

If you have any recommendations, please send them to me! 

Recreating XML files from fragments

I'm working on an interesting problem right now.  Occasionally I acquire fragments of files that I would like to re-create as much as possible.  Many of these are Microsoft Word 2007 files.  MS Word 2007 uses an XML format, so it would seem possible to parse the file to detect tags that were ended, but don't have a matching opening (because the beginning was cut off).

I figured that I'm probably not the first one to think about this problem, so I went trolling the intertubes for ready-made solutions.  Since perl is my glueware language of choice, I searched until I found the following handy snippet from prlmnks.org:
use XML::LibXML;
my $parser = XML::LibXML->new();
$parser->recover(1);
my $doc = $parser->parse_file($ARGV[0]);
print $doc->toString(1);
Very, very nice!  Now I am part of the way there.  Next, I took a pre-existing MS Word document of similar make and model, and prepended it.  With a little manual massaging, I got the script above to parse it, and even pretty-print it (a nice bonus).  Unfortunately, Microsoft Word still doesn't like the resultant "document."

I'm still working on this problem, but that's decent progress for an hour of work.

Thursday, April 30, 2009

Ubiquity

At first I was stunned at just how much I liked my iPod Touch. I just wanted a replacement for my 5th gen iPod, that stopped working when it mysteriously acquired a dent in its formerly pristine stainless steel back.

It didn't take long for it to turn into my most indispensible tool. Place to eat? UrbanSpoon. Reservation? OpenTable. And the list goes on: calculators, converters, levels, action games, puzzles, wikipedia apps, ebook readers, and even a way to read books from my Safari account.

If the kid is bored... a bit of Shrek. Long flight?A pithy podcast is the trick. Can't sleep? Ambient noise generator FTW!

In short, this little glass and steel box has become utterly indispensible.

This post, of course... composed, in bed, one thumb at a time.

Saturday, March 28, 2009

Securing Our Medical Infrastucture

On Friday, April 17th, InfraGard New Mexico is holding it's annual conference in Albuquerque, NM at the Hilton Garden Inn in Uptown.

The conference is titled:  Securing Our Medical Infrastructure

At $175 ($125 for current InfraGard members), the all-day conference is steal!!

The speakers include Larry Pesce (from PaulDotCom), Bill Tydeman (computer crime investigator for Health and Human Services), and others.

Visit the conference site for more details on registration and sponsorship.  Hope to see you there!!!

--john

Wednesday, March 25, 2009

Get ready for Conficker - No April Fools Day Joke

Good news: The patch for this issue came out from Microsoft in October last year. If you had automatic updates enabled at that time, you were probably already not vulnerable.

Not so good news: I can confirm that it is set to become more active again on April 1st. On that day, if you are infected, you may notice your machine is very slow for the first six hours or so.

Worse news: Conficker is suspected to be building the largest "botnet" of computers to date. These computers are typically used to perform massive spam campaigns, launder money, host illegal or thieving web sites, or even take down computer systems of nation states (such as Estonia).

What you can do now:
1) Read the Wikipedia article on Conficker, which provides a lot of good information,
2) Download the BitDefender Conficker removal tool from http://bdtools.net/ and check/clean your computer.

Monday, March 09, 2009

Darn it, they got me doing Karaoke again!

I met some incredibly talented folks at SANS 2009 this year.  Ryan, Jason, Don, Zoher and I hung out with Ed Skoudis, Mike Poor, Larry Pesce, and others.

Ryan truly has an evil mind (this is a good thing, in our field), and I was impressed with Don's massive cahones for his efforts over at EthicalHacker.net (and also for owning a bar while owning a software company!).

One evening we spent some time chatting with Ed Skoudis after one of his talks at the local Sushi bar.  I didn't have Sushi since I'd just eaten, but somehow (it must have been the mojito), Mike Poor convinced a few of us to join him on stage for a dead-on (umm, not) rendition of Bohemian Rhapsody.  It was fun, but not to be attempted without some liquid courage (at least not with my singing voice).

By the way, Jason, thanks for posting the tamer pictures.

That'll Do, Donkey, That'll Do

[Update 2009-03-13: Our team received notification yesterday that we Passed this project.]

I completed my Group Discussion and Written Project for my SANS Masters program while at SANS 2009 last week. I'm pretty sure the grade will be good, but I won't know for another week or so.

Seth Misenar and Tim Proffitt were my tiger teammates for an assignment that involved researching detective and preventive measures for Downadup/Conficker. We had 24 hours to do the work and present to the ficticious CIO (played by Stephen Northcutt) of GIAC Enterprises. Seth did an excellent job of presenting, but in the end we were "fired" by the CIO because we commented that he had gotten "too excited" about the possibility of his email being infected.

Later in the week we were asked to present again. It was suggested that we should rotate the role of presenter, so I volunteered. We presented a 2nd time on March 7th, and after we were done, Stephen Northcutt didn't say anything.

I got a little nervous at that point and asked, "Do you have any questions? Or any feedback?"

Stephen's response was a simple: "No."

After a little more prodding he added, "I don't even have any recommendations. You nailed it."

Ah.... sweet success. :-)

SANS 2009: MGT 525

I'm just back from SANS 2009 in Orlando (#SANS2009).  I took MGT525 -- yes, the project management class -- with Jeff Frisk.  I signed up for the class because it is a required component of the degree I am working on.  I had actually heard some negative things about the class, so I was dreading it just a little (sorry Jeff).  But, I'm pleased to report that I found it incredibly useful.  I have been running large projects (large information security projects) for awhile, but I haven't really ever had any formal PM training.  We have a Project Management Office, and they provide guidelines and templates, and I know what a WBS and Gantt chart are for, but I didn't really know the "proper" way to go from one step to the next.

My eyes were opened when we worked through labs on taking the WBS and producing a precedence diagram to figure out the actual critical path -- including identifying what activities had how much float time.

Now project management seems much less like art and more like science.  This makes me happy.

Thanks Jeff!

Wednesday, December 31, 2008

MD5 Considered Harmful Today or Don't Put Too Much Faith in PKI

A group of 7 security researchers from the United States, Switzerland, and the Netherlands has released details of an exploitation ("MD5 considered harmful today") in the now well-known MD5 Hash Collision vulnerability that would allow a rogue web site to issue a rogue SSL certificate... as well as a rogue signing certificate that is trusted by a valid root Certificate Authority.

Putting that all into English (or at least non-geekspeak):

"Secure" web sites can be impersonated by evildoers, even with the cute little lock icon and a completely "valid" certificate as far as your browser is concerned. This web site could be your bank.

The paper discusses countermeasures, mostly aimed at Certificate Authorities (CAs) and browser vendors. One thing you can do is look at your certificate chain for critical sites to see if MD5 is used by the CA's signing certificate.

The Mozilla developers are already working on a patch for Firefox, et al.:
https://bugzilla.mozilla.org/show_bug.cgi?id=471539


--john

Sunday, October 05, 2008

We cannot let this man be elected as President

I am appalled. If John McCain has done even one tenth of the things listed in this Rolling Stone article, we cannot let him take the office of the Commander in Chief:

http://tinyurl.com/3oje6n

Update:
Scary. Someone actually went to the trouble of breaking the above URL. Here is the new one:

http://tinyurl.com/mcmaverick

Or, just google for "mccain maverick rolling stone".

Sunday, September 14, 2008

strip=1 ftw

I use lots of browser flame-retardant suit layers these days... NoScript, AdBlock, etc. I even tend to NoScript google.com by default. If you only go to "normal" web sites this might seem extreme, but if you are poking around the seedy back streets of the intertubes, you probably know what I mean.

Here is another good pair of tips for safer browsing:

1. Use the cache, Luke, and
2. Always use strip=1

You can use the google cache to search for your topic of interest, and the oracle will return some hits (e.g., "100th monkey"):

  1. Hundredth Monkey Effect - Wikipedia, the free encyclopedia

    The “Hundredth Monkey Effect” is a supposed phenomenon in which a learned behaviour spreads instantaneously from one group of monkeys to all related monkeys ...
    en.wikipedia.org/wiki/Hundredth_Monkey - 32k - Cached - Similar pages - Note this
    gqqw9kMHZRoFt8OyvG9JlHlDgwW5sgV299RIBg3DVr8DolLpJiLqsJelqosQMCWJe3ghxm2XTUvAtSU1k0AvRYTKu3ZWsO88HHco
  2. The 100th Monkey Studio

    An open art studio using art therapy and creativity in Portland Oregon.
    www.the100thmonkeystudio.com/ - 14k - Cached - Similar pages - Note this
Then, click on the "Cached" link to view the page from the Google servers -- and avoid nastiness that might be found and the listed web sites themselves.

However...

That little trick doesn't completely protect you. Don't believe me? Just start up your favorite network sniffer (tcpdump, wireshark, etc.). You will see, if the page has certain types of content -- such as images, they will still come from the original web site. Oops! You have been identified, and hopefully not served.

The way to avoid this is to Right Click on that "Cached" link, past it into a browser's URL bar and add "&strip=1" to the end of it, such as...

http://www.google.com/search?q=cache:en.wikipedia.org\
/wiki/Hundredth_Monkey+100th+monkey&strip=1


Now your sniffer will happily report that all information comes only from Google.

Happy browsing!

Thursday, August 28, 2008

SANS Forensics Blog is up!

Okay, you heard it here first!  

SANS has created a new blog on digital forensics, and yours truly is the first poster.

SANS has chosen a team of about 25 contributors to provide the latest news, tips, and techniques on the topic of forensics.  There are some great posts on the way, so enjoy!

Tuesday, August 26, 2008

PenTest at the Alamo!

Last year I took my kids to San Antonio for some fall heat, killer whales, and our first visit to The Alamo. I eventually had to be dragged away from the Bowie knife collection (note to wives: it's a guy thing).

Now I'm ready to go back. Not because I need more time with whales or knives, but because SANS San Antonio (Nov 8-13), will be featuring the new SEC560 Network Penetration and Ethical Hacking class.

I have heard fantastic things about this new class. The courseware author, Ed Skoudis, apparently pulled out all the stops putting this one together. And, for Ed, that's really saying something.

The class is being taught by Jim Shewmaker. Shew is a great instructor, and it should be a rockin' fun time. Also on site will be Tanya Baccam (Oracle-security-guru-extraordinaire) and Jonathan Ham. I assisted Jonathan with the Google Hacking class in San Diego last year, and it was an excellent class... with attendees from the NSA to keep things extra interesting.

Think about it... when it's cold in November, you could be eating chips and salsa, drinking margaritas, and honing your pen testing skills-- what could be better than that!