For those of you in the Seattle area or willing to travel who are interested in digital forensics there is a great opportunity to learn and socialize coming up in March.
The CTIN Digital Forensics Conference will be March 13 though 15, 2013 at the Hilton Seattle Airport & Conference Center. CTIN, the Computer Technology Investigators Network, is non-profit, free membership organization comprised of public and private sector computer forensic examiners and investigators focused on the areas of high-tech security, investigation, and prosecution of high-tech crimes for both private and public sector.
Topics slated for the conference agenda are many, with great speakers to discuss them in depth:
Windows Time Stamp Forensics, Incident Response Procedures, Tracking USB Devices, Timeline Analysis with Encase, Internet Forensics, Placing the Suspect Behind the Keyboard, Social Network Investigations, Triage, Live CDs (WinFE & Linux)
F-Response and Intella, Lab - Hard drive repair, Mobile Device Forensics, Windows 7/8 Forensics
Child Pornography, Legal Update, Counter-forensics, Linux Forensics, X-Ways Forensics
Expert Testimony, ProDiscover, Live Memory Forensics, Encase, Open Source Forensic Tools
Cell Phone Tower Analysis, Mac Forensics, Registry Forensics, Malware Analysis, iPhone/iPad/other Apple products, Imaging Workshop, Paraben Forensics, Virtualization Forensics
Register before 1 DEC 2012 for $295, and $350 thereafter.
While you don't have to be a CTIN member to attend I strongly advocate your joining and supporting CTIN.
Sunday, November 11, 2012
Friday, November 02, 2012
toolsmith: Arachni - Web Application Security Scanner
Part 1 of 2 - Web Application Security
Flaw Discovery and Prevention
Prerequisites/dependencies
Ruby 1.9.2 or higher in any *nix environment
Introduction
This month’s issue kicks off a two part series on web
application security flaw discovery and prevention, beginning with Arachni. As
this month’s topic is another case of mailing lists facilitating great
toolsmith topics, I’ll begin this month by recommending a few you should join
if you haven’t already. The Web Application Security Consortium mailing list is a
must, as are the SecurityFocus lists. I favor
their Penetration Testing and Web Application Security lists but they have many
others as well. As you can imagine, these two make sense for me given focuses
on web application security and penetration testing, and it was via
SecurityFocus that I received news of the latest release of Arachni. Arachni is
a high-performance, modular, open source web application security scanning
framework written in Ruby. It was refreshing to discover a web app scanner I
had not yet tested. I spend a lot of time with the likes of Burp, ZAP, and
Watobo but strongly advocate expanding the arsenal.
Arachni’s developer/creator is Tasos "Zapotek"
Laskos, who kindly provided details on this rapidly maturing tool and project.
Via email, Tasos indicated that to date, Arachni's role has
been that of an experiment/learning-exercise hybrid, mainly focused on doing
things a little bit differently. He’s glad to say that the fundamental project
goals have been achieved; Arachni is fast, relatively simple, quite accurate, open
source and quite flexible in the ways which it can be deployed. In addition, as
of late, stability and testing have been given top priority in order to ensure
that the framework won't exhibit performance degradation as the code-base
expands.
With a strong foundation laid and a clear road map,
future plans for Arachni include pushing the envelope where version 0.4.2 include
improved distributed, high-performance scan features such as the new,
distributed crawler
(under current development), and a new, cleaner, more stable and attractive Web
User Interface, as well as general code clean-up.
Version 0.5 is where a lot of interesting work will take
place as the Arachni team will be attempting to break some new ground with
native DOM and JavaScript support, with the intent of allowing a depth/level of
analysis beyond what's generally possible today, from either open source or
commercial systems. According to Tasos, most, if not all, current scanners rely
on external browser engines to perform their duties bringing with them a few
penalties (performance hits, loss of control, limited inspection capabilities, design
compromises, etc.), which Arachni will be able to avoid. This kind of
functionality, especially from an open and flexible system, will be greatly
beneficial to web application testing in general, and not just in a security-related
context.
Arachni success stories include incredibly cool features
such as WAF Realtime Virtual Patching. At
OWASP AppSec DC 2012,
Trustwave Spider Lab’s Ryan Barnett discussed the concept of dynamic
application scanning testing (DAST) exporting data that is then imported into a
web application firewall (WAF) for targeted remediation. In addition to stating
that the Arachni scanner is an “absolutely awesome web application scanner
framework” Ryan describes how to integrate export data from Arachni with
ModSecurity, the WAF for which he is OWASP ModSecurity Core Rule Set (CRS)
project leader. Take note here as next month in toolsmith we’re going to
discuss ModSecurity for IIS as part two of this series and will follow Ryan’s
principles for DAST to WAF.
Other Arachni successes include highly-customized
scripted audits and easy incorporation into testing platforms (by virtue of its
distributed features). Tasos has
received a lot of positive feedback and has been pleasantly surprised there has
not been one unsatisfied user, even in the Arachni's early, immature phases.
Many Arachni users end up doing so out of frustration with the currently
available tools and are quite happy with the results after giving Arachni a try
given that Arachni gives users a decent alternative while simplifying web application
security assessment tasks.
Arachni benefits from excellent documentation and support
via its wiki,
be sure to give a good once over before beginning installation and use.
Installing Arachni
On an Ubuntu 12.10 instance,
I first made sure I had all dependencies met via sudo
apt-get install build-essential libxml2-dev libxslt1-dev libcurl4-openssl-dev
libsqlite3-dev libyaml-dev zlib1g-dev ruby1.9.1-dev ruby1.9.1.
For developer’s sake, this
includes Gem support so thereafter one need only issue sudo gem install arachni to install Arachni. However, the
preferred method is use of the appropriate system packages from the latest
downloads page.
While Arachni features robust
CLI use, for
presentation’s sake we’ll describe Arachni use with the Web UI. Start
it via arachni_web_autostart
which will initiate a Dispatcher and the UI server. The last step is to point
your browser to http://localhost:4567,
accept the default settings and begin use.
Arachni in use
Of interest as you begin
Arachni use is the dispatcher which spawns RPC instances and allows you to attach
to, pause, resume, and shutdown Arachni instances. This is extremely important
for users who wish to configure Arachni instances in a high performance grid (think
a web application security scanning cluster with a master and slave
configuration). Per the wiki, “this allows scan-time to be severely decreased,
by as much as n times less under ideal circumstances, where n
equals the number of running instances.”
You can configure Arachni’s
web UI to run under SSL and provide HTTP Basic authentication if you wish to
lock use down. Refer to the wiki entry for the web user interface for more
details.
Before beginning a simple
scan (one Dispatcher), let’s quickly review Arachni’s modules and plugins. Each
has a tab in Arachni’s primary UI view. The 45 modules are divided into Audit (22) and
Recon (23) options where the audit modules actively test the web application
via inputs such as parameters, forms, cookies and headers while the recon
modules passively test the web application, focusing on server configuration,
responses and specific directories and files. I particularly like the
additional SSN and credit card number disclosure modules as they are helpful for
OSINT, as well as the Backdoor module, which looks to determine if the web
application you’re assessing is already owned. Of note from the Audit options
is the Trainer module that probes all inputs of a given page in order to
uncover new input vectors and trains Arachni by analyzing the server responses.
Arachni modules are all enabled by default. Arachni plugins offer preconfigured
auto-logins (great when spidering), proxy settings, and notification options
along with some pending plugins supported in the CLI version but not yet ready
for the Web UI as of v.0.4.1.1
To start a scan, navigate to
the Start a scan tab and confirm
that a Dispatcher is running. You should see the likes of @localhost:7331 (host
and port) along with number of running scans, as well as RAM and CPU usage.
Then paste a URL into the URL form, and select Launch Scan as seen in Figure 1.
![]() |
| Figure 1: Launching an Arachni scan |
While the scan is running you
can monitor the Dispatcher status via the Dispatchers tab as seen in Figure 2.
![]() |
| Figure 2: Arachni Dispatcher status |
From the Dispatchers view you can choose to Attach
to the running Instance (there will be multiples if you’ve configured a high
performance grid) which will give a real-time view to the scan statistics,
percentage of completion for the running instance, scanner output, and results
for findings discovered as seen in Figure 3. Dispatchers provide Instances,
Instances perform the scans.
![]() |
| Figure 3: Arachni scan status |
Once the scan is complete, as
you might imagine, the completed results report will be available to you in the
Reports tab. As an example I
chose the HTML output but realize that you can also select JSON, text, YAML,
and XML as well as binary output such as Metareport, Marshal report, and even
Arachni Framework Reporting. Figure 4 represents the HTML-based results of a
scan against NOWASP Mutillidae.
![]() |
| Figure 4: HTML Arachni results |
The results are accurate too;
in my preliminary testing I found very few false positives. When Arachni isn’t
definitive about results, it even goes so far as to label the result “untrusted
(and may in fact be false positives) because at the time they were identified
the server was exhibiting some kind of anomalous behavior or there was 3rd part
interference (like network latency for example).” Nice, I love truth and
transparency in my test results.
I am really excited to see
Arachni work at scale. I intend to test it very broadly on large applications
using a high performance grid. This is definitely one project I’ll keep
squarely on my radar screen as it matures through its 0.4.2 and 0.5 releases.
In Conclusion
Join us again next month as we resume this discussion
when take Arachni results and leverage them for Realtime Virtual Patching with
ModSecurity for IIS. By then I will have tested Arachni’s clustering
capabilities as well so we should have some real benefit to look forward to
next month. Please feel free to seek support via the
support portal, file a bug report via the issue tracker, or to
reach out to Tasos via Twitter or email as he looks forward to feedback and
feature requests.
Ping me via email if you have questions (russ at
holisticinfosec dot org).
Cheers…until next month.
Acknowledgements
Tasos "Zapotek"
Laskos, Arachni project lead
Monday, October 01, 2012
toolsmith: Network Security Toolkit (NST) - Packet Analysis Personified
Prerequisites
Virtualization software if you don’t wish to run NST as a
LiveCD or install to dedicated hardware.
Introduction
As I write this I’m on the way back from SANS Network
Security in Las Vegas where I’d spent two days deeply entrenched analyzing packet
captures during the lab portion of the GSE exam. During preparation for this
exam I’d used a variety of VM-based LiveCD distributions to study and practice,
amongst them Security Onion. There are three distributions I run as VMs that
are always on immediate standby in my toolkit. They are, in no particular
order, Doug Burk’s brilliant Security Onion, Kevin Johnson’s SamuraiWTF, and
Back Track 5 R3. Security Onion and
SamuraiWTF have
both been toolsmith topics for good reason; I’ve not covered Back Track only
because it would seem so cliché. I will tell you that I am extremely fond of
Security Onion and consider it indispensable. As such, I hesitated to cover the
Network Security Toolkit (NST) when I first learned of it while preparing for
the lab, feeling as if it might violate some code of loyalty I felt to Doug and
Security Onion. Weird I know, and the truth is Doug would be one of the first
to tell you that the more tools made available to defenders the better. NST
represents a number of core principles inherent to toolsmith and the likes of
Security Onion. NST is comprehensive and convenient and allows the analyst
almost immediate and useful results. NST is an excellent learning tool and allows beginners and experts much
success in discovering more about their network environments. NST is also an
inclusive, open project that grows with help from an interested and engaged
community. The simple truth is Security Onion and NST represent different
approaches to complex problems. We all have a community to serve and the same
goals at heart, so I got over my hesitation and reached out to the NST project
leads.
The Network Security Toolkit is the brainchild of Paul
Blankenbaker and Ron Henderson and is a Linux distribution that includes a vast
collection of best-of-breed open source network security applications useful to
the network security professional. In the early days of NST Paul and Ron found
that they needed a common user interface and unified methodology for ease of access
and efficiency in automating the configuration process. Ron’s background
in network computing and Paul’s in software development lead to what is now referred
to as the NST WUI (Web User Interface). Given the wide range of open source
networking tools with corresponding command line interface that differ from one
application to the next, this was no small feat. The NST WUI now provides a
means to allow easy access and a common look-and-feel for many popular network
security tools, giving the novice the ability to point and click while also
providing advanced users (security analysts, ethical hackers) options to work
directly with command line console output.
According to Ron, one of the most beneficial tool enhancements that NST has to offer for the network and security administrator is the Single-Tap and Multi-Tap Network Packet Capture interface. Essentially, adding a web-based front-end to Wireshark, Tcpdump, and Snort for packet capture analysis and decode has made it easy to perform these tasks using a web browser. With the new NST v2.16.0-4104 release they took it a step forward and integrated CloudShark technology into the NST WUI for collaborative packet capture analysis, sharing and management.
Ron is also fond of the Network Interface Bandwidth monitor. This tool is an interactive dynamic SVG/AJAX enabled application integrated into the NST WUI for monitoring Network Bandwidth
usage on each configured network interface in pseudo real-time. He designed this application with the controls of a standard digital oscilloscope in mind.
Ron is also proud of NST’s ability to Geolocate network entities. We’ll further explore using NST’s current repertoire of available network entities that can geolocated with their associated application, as well as Ron’s other favorites mentioned above.
According to Ron, one of the most beneficial tool enhancements that NST has to offer for the network and security administrator is the Single-Tap and Multi-Tap Network Packet Capture interface. Essentially, adding a web-based front-end to Wireshark, Tcpdump, and Snort for packet capture analysis and decode has made it easy to perform these tasks using a web browser. With the new NST v2.16.0-4104 release they took it a step forward and integrated CloudShark technology into the NST WUI for collaborative packet capture analysis, sharing and management.
Ron is also fond of the Network Interface Bandwidth monitor. This tool is an interactive dynamic SVG/AJAX enabled application integrated into the NST WUI for monitoring Network Bandwidth
usage on each configured network interface in pseudo real-time. He designed this application with the controls of a standard digital oscilloscope in mind.
Ron is also proud of NST’s ability to Geolocate network entities. We’ll further explore using NST’s current repertoire of available network entities that can geolocated with their associated application, as well as Ron’s other favorites mentioned above.
Paul also shared something I enjoyed as acronyms are so
common in our trade. He mentioned that the NST distribution can be used in many
situations. One of his personal favorites is related to the FIRST Robotics
Competition (FRC) which occurs each year. FIRST for Paul is For Inspiration and Recognition
of Science and Technology where I am more accustomed to its use as Forum for Incident Response and Security Teams. Paul mentors FIRST team 868, the TechHounds at the Carmel
high school in Indiana, where in FRC competitions, teams have used NST (or
could use) during a hectic FRC build season:
· Quickly identity which network components
involved with operating the robot are "alive"
o From
the WUI menu: Security -> Active Scanners -> ARP Scan (arp-scan)
·
Observe how much network traffic increases or
decreases as we adjust the IP based robot camera settings
o From
the WUI menu: Network -> Monitors -> Network Interface Bandwidth Monitor
·
Capture packets between the robot and the
controlling computer
·
Scan the area for WIFI traffic and use this
information to pick frequencies for robot communications that are not heavily
used
·
Set up a Subversion and Trac server for managing
source code through the build season.
o From
the WUI menu: System -> File System Management -> Subversion Manager
·
Teach the benefits of scripting and automating
tasks
·
Provide an environment that can be expanded and
customized
While Paul and team have used NST for robotics, it’s
quite clear how their use case bullet list applies to the incident responder
and network security analyst.
Installing NST
NST, as an ISO, can be run as
LiveCD, installed to dedicated hardware, and also as a virtual machine. If you intend to take advantage of the
Multi-Tap Network Packet Capture interface feature with your NST installation set
up as a centralized, aggregating sensor then you’ll definitely want to utilize
dedicated hardware with multiple network interfaces. As an example, Figure 1
displays using NST to capture network and port address translation traffic across
a firewall boundary.
![]() |
| Figure 1: Multi-Tap Network Packet Capture Across A Firewall Boundary - NAT/PAT Traffic |
Once booted into NST you can
navigate from Applications to System Tools to Install NST to Hard Drive in order to
execute a dedicated installation.
Keep in mind that when
virtualizing you could enable multiple NICs to leverage multi-tap, but your
performance will be limited as you’d likely do so on a host system with one
NIC.
Using NST
NST use centers around the
WUI; access it via Firefox on the NST installation at http://127.0.0.1/nstwui/main.cgi.
The first time you login,
you’ll be immediately reminded to change the default password (nst2003). After
doing so, log back in and select Tools
-> Network Widgets -> IPv4 Address. Once you know what the
IP address is you can opt to use NST WUI from another browser. My session as an
example: https://192.168.153.132/nstwui/index.cgi.
Per Ron’s above mentioned
tool enhancements, let’s explore
Single-Tap Network Packet Capture (I’m running NST as a VM). Click
Network -> Protocol Analyzers -> Single-Tap Network Packet Capture
where you’ll be presented with a number of options regarding how you’d like to
configure the capture. You can choose define the likes of duration, file size,
and packet count or select predefined short or long capture sessions as seen in
Figure 2.
![]() |
| Figure 2: Configure a Single-Tap capture with NST |
If you accepted defaults for
capture storage location you can click Browse
and find the results of your efforts in /var/nst/wuiout/wireshark.
Now here’s where the cool comes in. CloudShark (yep, Wireshark in the cloud)
allows you to “secure, share, and analyze capture files anywhere, on any device”
via either cloudshark.org or a CloudShark appliance. Please note that capture files
uploaded to cloudshark.org are not secured by default and can be viewed by
anyone who knows the correct URL. You’ll need an appliance or CloudShark
Enterprise to secure and manage captures. That aside the premise of CloudShark
is appealing and NST integrates CloudShark directly. From the Tools menu select Network Widgets then CloudShark Upload Manager. I’d already
upload malicious.pcap as seen in
Figure 3.
![]() |
| Figure 3: CloudShark tightly integrated with NST |
Users need only click on View Network Packet Captures in the
upload manager and they’ll be directed right to the CloudShark instance of
their uploaded capture as seen in Figure 4.
![]() |
| Figure 4: Capture results displayed via CloudShark |
Many of the features you’d
expect from a local instance of Wireshark are available to the analyst,
including graphs, conversations, protocol decodes, and follow stream.
NST also includes the Network
Interface Bandwidth Monitor. Select Network
-> Monitors -> Network Interface Bandwidth Monitor. A
bandwidth monitor for any interface present on your NST instance will be
available to you (eth0 and lo on my VM) as seen in Figure 5.
![]() |
| Figure 5: NST’s Network Interface Bandwidth Monitor |
You can see the +100 kbps
spikes I generated against eth0 with a quick NMAP scan as an example.
NST’s geolocation
capabilities are many, but be sure to setup the NST system to geolocate data
first. I uploaded
a multiple host PCAP (P2P traffic) via Network Packet Capture Manager, clicked
the A (attach) button under Action and was them redirected back to
Network -> Protocol Analyzers -> Single-Tap Network Packet Capture.
I then chose to use the Text-Based Protocol Analyzer Decode option as described
on the NST Wiki
and clicked the Hosts – Google Maps
button. This particular capture gave NST a lot of work to do as it includes
thousands of IPs but the resulting geolocated visualization as seen in Figure 6
is well worth it.
![]() |
| Figure 6: P2P bot visually geolocated via NST |
If we had page space
available to show you the whole world you’d see that the entire globe is
represented by this bot, but I’m only showing you North America and Europe.
As discussed in recent
OSINT-related toolsmiths, there’s even an NST OSINT feature called theHarvester
found under Security -> Information Search -> theHarvester. Information gathering
with theHarvester includes e-mail accounts, user names, hostnames, and domains
from different public internet sources.
So many features, so little
time. Pick an item from the menu and drill in. There’s a ton of documentation
under the Docs menu too, including the NST Wiki, so you have no excuses not to
jump in head first.
In Conclusion
NST is one of those offerings where the few pages
dedicated to it in toolsmith don’t do it justice. NST is incredibly feature
rich, and literally invites the user to explore while the hours sneak by
unnoticed. The NST WUI has created a learning environment I will be
incorporating into my network security analysis teaching regimens. New to
network security analysis or a salty old hand, NST is a worthy addition to your
tool collection.
Ping me via email if you have questions (russ at
holisticinfosec dot org).
Cheers…until next month.
Acknowledgements
Paul Blankenbaker and Ron
Henderson, NST project leads
Thursday, September 27, 2012
The replacement security analyst's Top 10
I'm a huge football fan so the depth of my joy at the return of the "real" NFL referees cannot be measured. Given the replacement ref debacle I felt compelled to share a replacement security analyst's Top 10.
Note: at one time or another in my career I have truly heard all of these.
In no particular order...
Welcome back, NFL refs. :-)
Cheers.
Note: at one time or another in my career I have truly heard all of these.
In no particular order...
- Disable AV altogether, its inconvenient when moving malware samples around.
- Passwords longer than eight characters make it hard to do your job.
- Don't worry about chain of custody or evidence integrity, cases rarely go to court anyway.
- When a concerned user calls about a potentially compromised system, tell them to just run McAfee Stinger.
- Why would you want to keep DNS logs?
- Go ahead and give developers the ability to deploy code to straight to production from their desktops. It helps them be agile and creates efficiency.
- Proxying egress web traffic is an invasion of privacy and makes users mad, so don't do it.
- Your vulnerability scanner is causing my service to crash! Turn it off!
- We don't need to fix XSS. You can't hack a server with it.
- But it is encrypted. We used MD5 hashing to store the credit cards in the database.
Welcome back, NFL refs. :-)
Cheers.
Tuesday, September 04, 2012
toolsmith: SearchDiggity - Dig Before They Do
Prerequisites
Windows .NET Framework
Introduction
I’ve been conducting quite a bit of open source
intelligence gathering (OSINT) recently as part of a variety of engagements and
realized I hadn’t discussed the subject since we last reviewed FOCA in March
2011 or Search Engine Security Auditing in June
2007. I’d recently had a few hits on my feed reader, and at least via one
mailing lists, regarding SearchDiggity from Fran Brown and Rob Ragan of Stach
& Liu. They’d recently presented Pulp Google Hacking at the 4th
Annual InfoSec Summit at ISSA Los Angeles as well as Tenacious Diggity at
DEFCON 20 and the content certainly piqued my interest. One quick look at the framework
and all its features and I was immediately intrigued. At first glance you note similarities
to Wikto and FOCA given Search Diggity’s use of the Google Hacking Database and
Shodan. This is no small irony as this team has taken point on rejuvenating the
art of the search engine hack. In Fran’s InformationWeek report, Using Google to Find Vulnerabilities In YourIT Environment,
he discusses toolsmith favorites FOCA, Maltego, and Shodan amongst others. I’ll
paraphrase Fran from this March 2012 whitepaper to frame why using tools such
as SearchDiggity and others in the Diggity arsenal is so important. Use these
same methods to find flaws before the bad guys do; these methods use search
engines such as Google and Bing to identify vulnerabilities in your applications,
systems and services allowing you to fix them before they can be exploited. Fran
and Rob’s work has even hit mainstream media with the likes of NotInMyBackyard
(included in SearchDiggity) achieving coverage in USA Today.
Suffice it to say that downloads from the Google Hacking Diggity Project pages
jumped by 45,000 almost immediately, fueled largely by non-security consumers looking
to discover any sensitive data leaks related to themselves or their
organizations. A nice problem to have for the pair from Stach & Liu and one
Fran addressed with a blogpost to provide a quick intro to NotInMyBackYardDiggity, to be
discussed in more detail later in this article.
I reached out to Fran and Rob rather late in this month’s
writing process and am indebted to them as they kindly accommodated me with a
number of resources as well a few minutes for questions via telephone. There
are Diggity-related videos and tool screenshots as
well as all the presentations the
team has given in the last few years. The SearchDiggity team is most proud of
their latest additions to the toolset, including NotInMyBackyard and PortScan.
Keep in mind that, like so many tools discussed in toolsmith, SeachDiggity and
its various elements were written to accommodate the needs of the developers
during their own penetration tests and assessments. No cached data is safe from
the Diggity Duo’s next generation search engine hacking arsenal and all their
tools are free for download and use.
Installing Search Diggity
SearchDiggity installation is
point-and-click simple after downloading the installation package, but there
are few recommendations for your consideration. The default installation path
is C:\Program Files (x86)
\SearchDiggity, but consider using a non-system drive as an installation
target to ensure no permissions anomalies; I installed in D:\tools\SearchDiggity. SearchDiggity
writes results files to DiggityDownloads
(I set D:\tools\DiggityDownloads
under Options à Settings à General) and will need permission to
its root in order to Update Query
Definitions (search strings, Google/Bing Dorks).
Using SearchDiggity
I started my review of SearchDiggity
capabilities with the Bing Hacking Database (BHDB) under the Bing tab and utilizing the menu
referred to as BHDBv2NEW as seen in Figure 1.
![]() |
| Figure 1: A BHDB analysis of HolisticInfosec.org |
As with any tool,
optimization of your scan settings for your target before you start the scan
run is highly recommended. Given that my site is not an Adobe Coldfusion
offering there’s really no need to look for CFIDE references, right? Ditto for
Outlook Web Access or SharePoint, but CMS Config Files with XSS and SQL
injection instreamset options
are definitely in order. Good news, no significant findings were noted using my
domain as the target.
NotInMyBackyard is a recent
addition to SearchDiggity for which the team has garnered a lot of deserved
attention and as such we’ll explore it here. I used my name as my primary
search parameter and configured Methods
to include Quotes, and set Locations to include:
1)
Cloud
Storage (Dropbox, Google Docs, Microsoft Skydrive, Amazon AWS)
2)
Document
Sharing (scribd.com, 4shared.com, issuu.com, docstoc.com, wepapers.com)
3)
Pastebin
(pastebin.com, snipt.org, drupalbin.com, paste.ubuntu.com, tinypaste.com,
paste2.org, codepad.org, dpaste.com, pastie.org, pastebin.mozilla.org)
4)
Social
(Facebook, Twitter, YouTube, LinkedIn)
5)
Forums
(groups.google.com)
6)
Public
presentations charts graphs videos (Slideshare, Prezi, present.me,
Gliffy, Vimeo, Dailymotion, Metacafe)
You can opt to set additional
parameters such as Extensions
for document types including all versions of Microsoft Office, PDF,CSV, TXT,
database types including MS-SQL and Access, backup, logs, and config files, as
well as test and script files. My favorites (utilized in a separate run) are
the financial file options including Quicken and QuickBooks data files and
QuickBooks backup files. Finally, there are a number of granular keyword
selections to narrow your query results that might include your patient
records, places of birth, or your name in a data dump. This is extremely useful
when trying to determine if your email address, as associated with one of your
primary accounts, has been accumulated in a data dump posted to a Pastebin-like
offering. Just keep in mind, the more options you select the longer your query
run will take. I typically carve my searches up in specific categories then
export the results to a file named for the category.
As seen in Figure 2,
NotInMyBackyard reveals all available query results in a clean, legible manner
that includes hyperlinks to the referenced results, allowing you to validate
the findings.
![]() |
| Figure 2: NotInMyBackyard flushes out results |
I found that my search, as
configured, was more enlightening specific to all the copies of my material
posted to other sites without my permission. It was also interesting to see
where articles and presentation material were cited in academic material.
Imagine using your organizational domain name, and specific keywords and
accounts to discover what’s exposed to the evildoers conducting the same
activity.
You can focus similar
activity with more attention to the enterprise mindset utilizing
SearchDiggity’s DLP offerings. First conduct a Google or Bing run against a
domain of interest using the DLPDiggity
Initial selection. Once the query run is complete, highlight all the
files (CTRL-A works well), and click the download button. This will download
all the files to the download directory you configured, populating it with
files discovered using DLPDiggity
Initial, against which you
can then apply the full DLP menu. I did as described against a target
that shall remain unnamed and found either valid findings or sample/example
data that matched the search regex explicitly as seen in Figure 3.
![]() |
| Figure 3: Data Leak Prevention with SearchDiggity |
I only used the Quick Checks
set here too. When you contemplate the likes of database connection strings,
bank account numbers, and encryption-related findings, coupled with the
requisite credit cards, SSNs, and other PII, it becomes immediately apparent
how powerful this tool is for both prevention and discovery during the
reconnaissance phase of a penetration test.
I’ll cover one more
SearchDiggity component but as is usually the case with toolsmith topics there
is much about the tool du jour that remains unsaid. Be sure to check out the
SearchDiggity Shodan and PortScan offerings on your own. I’m always particularly
interested in Flash-related FAIL findings and SearchDiggity won’t disappoint
here either. Start with a Google or Bing search against a target domain with FlashDiggity Initial enabled. Much as
noted with the DLP feature, after discovery, SearchDiggity will download the
SWF files it identifies with FlashDiggity
Initial. As an example I ran this configuration without a domain
specified. By default, for a Google search, 70 results per query will be
returned. Suffice it to say that with the three specific queries defined in FlashDiggity Initial searches, I was
quickly treated to 210 results which I then opted to download. I switched over
the Flash menu and for real s’s
and g’s (work that one out on your own :-)) enabled all
options. Figure 4 exemplifies (anonymously) just how concerning certain Flash
implementations may be, particularly when utilized for administrative functions
and authentication.
![]() |
| Figure 4: Find bad Flash with SearchDiggity |
FlashDiggity decompiles the
downloaded SWF files with Flare and stores the resulting .flr file in the
download directory for your review. It should go without saying that flaw
enumeration becomes all that much easier. As an example, FlashDiggity’s getURL
XSS detection discovered the following using geturl\(.*(_root\.|_level0\.|_global\.).*\)
as its regex logic:
this.getURL('mailto:' +
_global.escape(this.decodeEmailAddr(v2.emladdr)) + '?subject=' +
_global.escape(v2.emlsubj) + '&body=' +
_global.escape(this.getEmailContent()));
This snippet makes for
interesting analysis. Risks associated with getURL
are well documented but the global escape may mitigate the issue. That said,
the Flash file was created with Techsmith Camtasia in January 2009, and an XSS
vulnerability was reported in October 2009 regarding SWF files created with
Camtasia Studio. Yet, SWF files hosted on TechSmith’s Screencast service were
not vulnerable and more than one reference to Screencast was noted in the
decompiled .flr file. With one FlashDiggity search, we were able to learn a
great deal about potentially flawed Flash files subject to possible exploit.
And we didn’t even touch SearchDiggity’s
malware analysis feature set.
In Conclusion
As always I’ll remind you, please use SearchDiggity for
good, not evil. Incorporating its use as part of your organizational defensive
tactics is a worthy effort. Keep in mind that you can also leverage this logic
as part of Google Hacking Diggity Defense Tools including Alert and Monitoring
RSS feeds.
Configure them with your specific and desired organizational parameters and
enjoy real time alerting and monitoring via your RSS feed reader. For those of
you defending Internet-facing SharePoint implementations you’ll definitely want
to check out the SharePoint Diggity Hacking Project too.
Enjoy this tool arsenal from Stach & Liu’s Dynamic
Duo; they’d love to hear from you with kudos, constructive criticism, and
feature requests via diggity at stachliu.com.
Ping me via email if you have questions (russ at
holisticinfosec dot org).
Cheers…until next month.
Acknowledgements
Subscribe to:
Posts (Atom)
Moving blog to HolisticInfoSec.io
toolsmith and HolisticInfoSec have moved. I've decided to consolidate all content on one platform, namely an R markdown blogdown sit...
-
Continuing where we left off in The HELK vs APTSimulator - Part 1 , I will focus our attention on additional, useful HELK features to ...
-
Ladies and gentlemen, for our main attraction, I give you...The HELK vs APTSimulator, in a Death Battle! The late, great Randy "Macho...
-
First off, Happy New Year! I hope you have a productive and successful 2018. I thought I'd kick off the new year with another explorat...
















