<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sekiur My Thoughts &#187; hack</title>
	<atom:link href="http://blog.sekiur.com/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.sekiur.com</link>
	<description>VoIP, Mobility, Security, Open Source, Science, Politics, and Technology.</description>
	<lastBuildDate>Wed, 24 Aug 2011 19:46:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Conficker Gets Ready To Strike</title>
		<link>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/</link>
		<comments>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 19:37:25 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downandup]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=758</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg"></a>Without a doubt the whole security professional community have their eyes on the Conficker.C variant which is designed to do something on April 1st.</p> <p>So what is that something? We&#8217;ll find out within 24 hours.</p> <p>What we do know is that this variant of Conficker has become better at preventing removal and others from [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg"><img class="alignleft size-full wp-image-759" title="24hours_day0" src="http://blog.sekiur.com/wp-content/uploads/2009/03/24hours_day0.jpg" alt="" width="120" height="107" /></a>Without a doubt the whole security professional community have their eyes on the Conficker.C variant which is designed to do something on April 1st.</p>
<p>So what is that something? We&#8217;ll find out within 24 hours.</p>
<p>What we do know is that this variant of Conficker has become better at preventing removal and others from taking control of the network of worm infected computers.</p>
<p>The Conficker worm will begin to poll 500 different domain names every day looking for updates to download doubling its current rate.</p>
<p>Interestingly enough one of my most popular posts is on the removal of the Conficker worm from a network environment <a href="http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/" target="_self">here</a> and over the last couple of days visitors have exploded exponentially.</p>
<p>In my two other posts in which I talk about the <a href="http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/" target="_self">Microsoft flaw</a> and the <a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self">Social Engineering</a> components of the worm, I take a rather passive approach to the problem which is based on having contingency plans to prevent, contain and remove the worm from infected computers.</p>
<p>A more pro-active approach would be to look for infected machines without waiting for the symptons to appear by actively scanning the network for computers which have been infected.</p>
<p>Locating computers which have been infected with Conficker using a network scan has kept me up multiple nights, until the guys at <a href="http://honeynet.org/" target="_self">Honeynet.org</a> came up with the <a href="http://honeynet.org/node/388" target="_self">tool here</a>. Thanks to <a href="http://www.dshield.org/" target="_self">DShield.org</a> for linking to it in their article on <a href="http://www.dshield.org/diary.html?storyid=6097" target="_self">locating Conficker</a>.<a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self"><br />
</a></p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p><a href="http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/" target="_self">http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/</a><br />
<a href="http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/" target="_self">http://blog.sekiur.com/2008/10/worm-takes-advantage-of-microsoft-flaw/</a><br />
<a href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_self">http://blog.sekiur.com/2009/01/worm-uses-social-engineering/</a></p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.shankrila.com/tech-stuff/how-to-remove-conficker-worm/">Your Quick Guide to the Conficker Worm</a> (shankrila.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/article/09/02/13/With_global_effort_a_new_type_of_worm_is_slowed_1.html&amp;a=3158865&amp;rid=54f79576-6273-4d40-8fb9-001ff817cc48&amp;e=3bc0e6cf396bcb6a07b7981582904fa2">With global effort, a new type of worm is slowed</a> (infoworld.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.idiomag.com/peek/72863/crap">My Top Security and Maintenance Tools</a> (idiomag.com)</li>
<li class="zemanta-article-ul-li"><a href="http://blogs.technet.com/msrc/archive/2009/02/06/new-information-pages-on-conficker.aspx">New Information Pages on Conficker</a> (blogs.technet.com)</li>
<li class="zemanta-article-ul-li"><a href="http://littlegreenfootballs.com/article/33216_Windows_PC_Worm_Set_to_Activate_on_April_1st">Windows PC Worm Set to Activate on April 1st</a> (littlegreenfootballs.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/54f79576-6273-4d40-8fb9-001ff817cc48/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=54f79576-6273-4d40-8fb9-001ff817cc48" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/03/conficker-gets-ready-to-strike/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safeguard Against Random Password Hacks</title>
		<link>http://blog.sekiur.com/2009/02/safeguard-against-random-password-hacks/</link>
		<comments>http://blog.sekiur.com/2009/02/safeguard-against-random-password-hacks/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 21:08:55 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[fail2ban]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[Intrusion Prevention System]]></category>
		<category><![CDATA[ips]]></category>
		<category><![CDATA[linux]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=735</guid>
		<description><![CDATA[<a href="http://commons.wikipedia.org/wiki/Image:Internet_map_1024.jpg"></a> Image via <a href="http://commons.wikipedia.org/wiki/Image:Internet_map_1024.jpg">Wikipedia</a> <p>A great tool I ran across to protect your server from random password attacks which I have been receiving recently from China.</p> <p><a class="zem_slink" title="Fail2ban" rel="homepage" href="http://www.fail2ban.org/">Fail2ban</a> scans log files and bans IP addresses that make repeated, unsuccessful attempts to access the server and then it updates the IPtables [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignleft" style="width: 212px;">
<dt class="wp-caption-dt"><a href="http://commons.wikipedia.org/wiki/Image:Internet_map_1024.jpg"><img title="Partial map of the Internet based on the Janua..." src="http://upload.wikimedia.org/wikipedia/commons/thumb/d/d2/Internet_map_1024.jpg/202px-Internet_map_1024.jpg" alt="Partial map of the Internet based on the Janua..." height="202" width="202"></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:Internet_map_1024.jpg">Wikipedia</a></dd>
</dl>
</div>
</div>
<p>A great tool I ran across to protect your server from random password attacks which I have been receiving recently from China.</p>
<p><a class="zem_slink" title="Fail2ban" rel="homepage" href="http://www.fail2ban.org/">Fail2ban</a> scans log files and bans IP addresses that make repeated, unsuccessful attempts to access the server and then it updates the IPtables rules to reject those IP addresses for a period of time which is defined by you. It can also be configured to notify you if once these events occur.</p>
<p>Its no high-end <a class="zem_slink" title="Intrusion-prevention system" rel="wikipedia" href="http://en.wikipedia.org/wiki/Intrusion-prevention_system">Intrusion Prevention System</a>, but it does the job.</p>
<p>Fail2ban comes preconfigured to detect and block attacks to ports 22 (ssh), 25 (SMTP) and 80 (http). Instructions on installing on <a class="zem_slink" title="CentOS" rel="homepage" href="http://www.centos.org/">CentOS</a> are detailed below as well as adding functionality for ProFTPD.</p>
<p>I love package management as opposed to compiling because its clean and easy to maintain, so we will need to subscribe to repositories to install Fail2ban.</p>
<p><strong>* </strong><strong>Update the system </strong></p>
<p>yum update</p>
<p><strong>* </strong><strong>Install DAG’s GPG key </strong></p>
<p>rpm –import http://dag.wieers.com/rpm/packages/RPM-GPG-KEY.dag.txt</p>
<p><strong>* </strong><strong>Verify the package you have downloaded</strong></p>
<p>rpm -K rpmforge-release-0.3.6-1.el5.rf.*.rpm</p>
<p>Security warning: The rpmforge-release package imports GPG keys into your RPM database. As long as you have verified the package and trust Dag then it should be safe.</p>
<p><strong>* </strong><strong>Download and Install the package </strong></p>
<p>wget http://packages.sw.be/rpmforge-release/rpmforge-release-0.3.6-1.el5.rf.i386.rpm<br />
rpm -ivh rpmforge-release-0.3.6-1.el5.rf.*.rpm</p>
<p>This will add a yum repository config file and import the appropriate GPG keys. At this point, you can set the priority of the RPMForge repository, and also of the CentOS repositories if you have not done so yet.</p>
<p><strong>* </strong><strong>Test with this command: </strong></p>
<p>yum check-update</p>
<p><strong>* </strong><strong>Update the system </strong></p>
<p>yum update</p>
<p><strong>* Install Fail2ban</strong></p>
<p>yum install fail2ban</p>
<p><strong>* Configure Fail2ban</strong> by editing and adding to /etc/fail2ban.conf</p>
<p>maxfailures = 3 (the default is 5)</p>
<p>ignoreip = 127.0.0.1 &lt;the_server_IP&gt; &lt;network_you_want_excluded/24&gt;</p>
<p><strong>* Enable E-Mail Notification</strong></p>
<p>[MAIL]<br />
# Option:&nbsp; enabled<br />
# Notes.:&nbsp; enable mail notification when banning an IP address.<br />
# Values:&nbsp; [true | false]&nbsp; Default:&nbsp; false<br />
#<br />
enabled = true</p>
<p>to = &lt;your_email_address&gt;</p>
<p><strong>* Add ProFTPD functionality</strong></p>
<p>[proftpd]<br />
enabled = true<br />
logfile = /var/log/secure<br />
fwstart = <a class="zem_slink" title="Iptables" rel="homepage" href="http://www.netfilter.org/">iptables</a> -N fail2ban-proftpd<br />
iptables -I INPUT -p tcp &#8211;dport ftp -j fail2ban-proftpd<br />
iptables -A fail2ban-proftpd -j RETURN<br />
fwend = iptables -D INPUT -p tcp &#8211;dport ftp -j fail2ban-proftpd<br />
iptables -F fail2ban-proftpd<br />
iptables -X fail2ban-proftpd<br />
fwcheck = iptables -L INPUT | grep -q fail2ban-proftpd<br />
fwban = iptables -I fail2ban-proftpd 1 -s &lt;ip&gt; -j DROP<br />
fwunban = iptables -D fail2ban-proftpd -s &lt;ip&gt; -j DROP<br />
timeregex = \S{3}\s{1,2}\d{1,2} \d{2}:\d{2}:\d{2}<br />
timepattern = %%b %%d %%H:%%M:%%S<br />
failregex = Maximum login attempts|no such user found|Failed password</p>
<p><strong>* Set it to startup automatically with the system</strong></p>
<p>chkconfig &#8211;levels 235 fail2ban on</p>
<p><strong>* Start Fail2ban and walk away</strong></p>
<p>/etc/init.d/fail2ban start</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://www.linux.com/feature/149492">Security scans with OpenVAS</a> (linux.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.linux.com/feature/149491">Monitor your network with GroundWork Monitor Community Edition</a> (linux.com)</li>
<li class="zemanta-article-ul-li"><a href="http://arnoldit.com/wordpress/2008/12/17/logrhythm-analysis-and-search-of-log-files/">LogRhythm: Analysis and Search of Log Files</a> (arnoldit.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.channelweb.co.uk/crn/news/2231802/security-market-growing">IT security market still growing</a> (channelweb.co.uk)</li>
<li class="zemanta-article-ul-li"><a href="http://www.linux.com/feature/152460">Access remote network services with SSH tools</a> (linux.com)</li>
<li class="zemanta-article-ul-li"><a href="http://britg.com/2008/10/23/getting-rid-of-ssh-or-sftp-delay/">Getting Rid of SSH or SFTP Delay</a> (britg.com)</li>
</ul>
<div style="margin-top: 10px; height: 15px;" class="zemanta-pixie"><a class="zemanta-pixie-a" href="http://reblog.zemanta.com/zemified/028ed8ed-982f-489c-91c0-83d91bf007f3/" title="Zemified by Zemanta"><img style="border: medium none ; float: right;" class="zemanta-pixie-img" src="http://img.zemanta.com/reblog_e.png?x-id=028ed8ed-982f-489c-91c0-83d91bf007f3" alt="Reblog this post [with Zemanta]"></a><span class="zem-script more-related"><script type="text/javascript" src="http://static.zemanta.com/readside/loader.js" defer="defer"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/02/safeguard-against-random-password-hacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Step by Step In Dealing With Conficker</title>
		<link>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/</link>
		<comments>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/#comments</comments>
		<pubDate>Tue, 03 Feb 2009 23:03:35 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[downandup]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[trojan]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=722</guid>
		<description><![CDATA[<p>This will turn out to be a &#8220;trojan horse&#8221; literally if actions are not taken to prevent it from spreading within the corporate network.</p> <p>Below are step by step instructions on mitigating the risk of the threat that &#8220;Conficker&#8221;/&#8221;Downandup&#8221; poses.</p> <p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/binary.jpg"></a></p> <p>Symptoms</p> <p>============</p> <p>Symptoms to help you determine if you are infected</p> Account lockout [...]]]></description>
			<content:encoded><![CDATA[<p>This will turn out to be a &#8220;trojan horse&#8221; literally if actions are not taken to prevent it from spreading within the corporate network.</p>
<p>Below are step by step instructions on mitigating the risk of the threat that &#8220;Conficker&#8221;/&#8221;Downandup&#8221; poses.</p>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/02/binary.jpg"><img class="aligncenter size-medium wp-image-724" title="binary" src="http://blog.sekiur.com/wp-content/uploads/2009/02/binary-300x225.jpg" alt="" width="300" height="225" /></a></p>
<p><strong>Symptoms</strong></p>
<p>============</p>
<p>Symptoms to help you determine if you are infected</p>
<ul>
<li>Account lockout policies are being tripped</li>
<li>Automatic Updates, Background Intelligent Transfer Service, Windows Defender and Error Reporting Server Services are disabled</li>
<li>Errors related to SVCHOST</li>
<li>Domain Controllers are slow to respond to client requests</li>
<li> Network congestion</li>
<li> Various security related websites are not accessible including Windows Update.</li>
</ul>
<p><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'; color: #000000;">For  further details see the Microsoft Malware Protection Center write up for <a href="http://www.microsoft.com/security/portal/Entry.aspx?Name=Worm%3aWin32%2fConficker.B">Win32/Conficker.b</a>. or the Sekiur writeup </span><a title="Sekiur" href="http://blog.sekiur.com/2009/01/worm-uses-social-engineering/" target="_blank">here</a>.</p>
<p><strong>Solution</strong></p>
<p>=========</p>
<p>Ideally you want to not only automate the removal of the &#8220;Conficker&#8221;/&#8221;Downandup&#8221; worm from a large number of computers but also take steps to minimize the risk of them being infected again.</p>
<p>The following script will attempt to remove the &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  worm and prevent further infection by taking the following steps:</p>
<ol>
<li>Install patch <a href="http://support.microsoft.com/kb/958644" target="_blank">KB958644</a> for <a href="http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx" target="_blank">MS08-067</a> if not installed</li>
<li>Attempt to remove the &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  worm</li>
<li>Enable Hidden Setting</li>
<li>Delete all scheduled tasks</li>
<li>Stop and disable services. (lanmanserver, schedule)</li>
<li>Run MSRT &#8211; Malicious Software Removal Tool</li>
<li>Install Autorun hotfix if not installed</li>
<li>Install <a href="http://support.microsoft.com/kb/950582" target="_blank">KB950582</a> for vulnerability <a href="http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx" target="_blank">MS08-038</a></li>
<li>Re-enable TCP Receive Window Auto-tuning on Windows Vista and Windows Server 2008</li>
<li>Remove Hidden Setting</li>
<li>Enable Automatic Updates, Background Intelligent Transfer and Error Reporting Services</li>
<li>Restart</li>
<li>Install patch <a href="http://support.microsoft.com/kb/958644" target="_blank">KB958644</a> for <a href="http://www.microsoft.com/technet/security/bulletin/MS08-067.mspx" target="_blank">MS08-067</a> and restart</li>
</ol>
<p>You will need to download the following files and batch script and drop them into the NetLogon share.</p>
<ul>
<li> Getver.exe &#8211; contained in ConfickerClean-v10.3.zip here ==> [Download not found] and script to remove &#8220;Conficker&#8221;/&#8221;Downandup&#8221;  locally here ==> [Download not found].</li>
<li>SC.EXE &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>REG.exe &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>windows-kb890830-v2.6.exe &#8211; x86 version of MSRT, available <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&amp;displaylang=en" target="_blank">here</a>.</li>
<li>windows-kb890830-x64-v2.6.exe &#8211; x64 version of MSRT, available <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=585D2BDE-367F-495E-94E7-6349F4EFFC74&amp;displaylang=en" target="_blank">here</a>.</li>
<li> sleep.exe &#8211; contained in ConfickerClean-v10.3.zip</li>
<li>Hotfix update for Windows 2000, Windows XP and Windows 2003, download all updates listed in <a href="http://support.microsoft.com/kb/953252" target="_blank">http://support.microsoft.com/kb/953252</a>, except the Itanium update as this script does not support Itanium.</li>
<li>Place all 3 updates in the Netlogon directory.</li>
<li>Security update MS08-038 for Windows Vista and Windows Server 2008 &#8211; <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx" target="_blank">http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx</a><br />
This vulnerability is not being exploited, however, to disable Autorun properly this needs to be applied as it contains a fix related to autorun, same as the one listed above in <a href="http://support.microsoft.com/kb/953252" target="_blank">KB953252</a>.</li>
</ul>
<p>Now you will proceed to create and push a Group Policy to the domain.</p>
<ol>
<li>Edit the &lt;domain.com&gt; values in the script.</li>
<li>Rename it to .BAT and drop it in the \\%windir%\sysvol\sysvol\\scriptsfolder (aka, Netlogon share).</li>
<li> Create a Startup Script policy and reference this batch file.  This needs to be a Startup Script and not a Logon script, so that the script runs under the machine account.</li>
<li>Link the GPO with the Startup Script to the OU and Groups where you want it to apply.</li>
</ol>
<p><strong>Note:</strong></p>
<p><strong>Its not recommend you use this on DC&#8217;s or critical servers, those should be cleaned manually so that the services disabled below do not need to be left disabled for an extended period of time.</strong></p>
<p><strong>FAQ:</strong></p>
<p><strong>Why disable the Server service? </strong></p>
<p>This is due to Weak Passwords which the malware attempts to exploit. The password change will need to be accomplished via password policy for the domain, resetting any local and domain admin password to a complex password which includes at least 10 characters and contains, alpha-numeric characters and extended characters such as a question mark or exclamation point.</p>
<p><strong>Why disable the Task Scheduler service? </strong></p>
<p>This is because the malware creates several AT jobs that run every hour to reinfect the system.</p>
<p><strong>Why install MS08-067?</strong></p>
<p>This is the main attack vector of the malware.</p>
<p><strong>Why disable Autorun?</strong></p>
<p>This is because the malware drops a binary file called Autorun.inf on all removable drives.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
<p>Sources:</p>
<p>All credit to Microsoft Support Engineering</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/02/step-by-step-in-dealing-with-conficker/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Worm Uses Social Engineering</title>
		<link>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/</link>
		<comments>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/#comments</comments>
		<pubDate>Thu, 22 Jan 2009 19:27:27 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[ms08-067]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[vulnera]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=704</guid>
		<description><![CDATA[<p>A new worm has hit the Internet and its taking its toll on computers worldwide. It has been reported that over 9 million computers have already been infected.</p> <p>The worm called &#8220;Downandup&#8221;, &#8220;Conficker&#8221; or &#8220;Kido&#8221; by different anti-virus vendors uses the Microsoft vulnerability which I blogged about here (<a rel="bookmark" href="../2008/10/worm-takes-advantage-of-microsoft-flaw/">Worm Takes Advantage Of Microsoft [...]]]></description>
			<content:encoded><![CDATA[<p>A new worm has hit the Internet and its taking its toll on computers worldwide. It has been reported that over 9 million computers have already been infected.</p>
<p>The worm called &#8220;Downandup&#8221;, &#8220;Conficker&#8221; or &#8220;Kido&#8221; by different anti-virus vendors uses the Microsoft vulnerability which I blogged about here (<a rel="bookmark" href="../2008/10/worm-takes-advantage-of-microsoft-flaw/">Worm Takes Advantage Of Microsoft Flaw</a>) and here (<a rel="bookmark" href="../2008/10/microsoft-releases-emergency-patch/">Microsoft Releases Emergency Patch</a>).</p>
<p>The worm mostly spreads across networks, turning off the system restore and deleting the restore points, blocks access to security website, download additional malware from the author, attempts to infect other computers by scanning network shares and scheduled a task to re-infect the computer if removed.</p>
<p>What is interesting is that it can also spread by USB memory keys or devices making use of <a href="http://en.wikipedia.org/wiki/Social_engineering_(security)" target="_blank">social engineering</a> which makes it more dangerous to the untrained eye. When a USB drive is inserted it shows a modified AutoPlay screen seen below which will install the worm when the users inadvertently clicks on it.</p>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/windows_vista_open_folder_to_view_files.png"><img class="aligncenter size-full wp-image-705" title="windows_vista_open_folder_to_view_files" src="http://blog.sekiur.com/wp-content/uploads/2009/01/windows_vista_open_folder_to_view_files.png" alt="" width="400" height="550" /></a></p>
<p>According to <a title="SANS ISC" href="http://isc.sans.org/" target="_blank">SANS Internet Storm Center</a>, one of the reasons the worm is infecting so many machines is that &#8220;Conficker&#8221; uses multiple infection vectors:</p>
<ol>
<li>It exploits the MS08-067 vulnerability,</li>
<li>It brute forces Administrator passwords on local networks and spreads through ADMIN$ shares and finally</li>
<li>It infects removable devices and network shares by creating a special autorun.inf file and dropping its own DLL on the device.</li>
</ol>
<h4 class="tabsection-title">Characteristics -</h4>
<p>When executed, the worm copies itself using a random name to the %Sysdir% folder.</p>
<p><em>(Where %Sysdir% is the Windows system folder; e.g. C:\Windows\System32)</em></p>
<p>It modifies the following registry key to create a randomly-named service on the affected syetem:</p>
<ul>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\&#8221;ServiceDll&#8221; = &#8220;Path to worm&#8221;</li>
<li>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\&#8221;ImagePath&#8221; = %SystemRoot%\system32\svchost.exe -k netsvcs</li>
</ul>
<p>Attempts connections to one or more of the following websites to obtain the public ip address of the affected computer.</p>
<ul>
<li>hxxp://www.getmyip.org</li>
<li>hxxp://getmyip.co.uk</li>
<li>hxxp://checkip.dyndns.org</li>
<li>hxxp://whatsmyipaddress.com</li>
</ul>
<p>Attempts to download a malware file from the remote website: (Rogue Russian site is up but not serving file anymore)</p>
<ul>
<li> hxxp://trafficconverter.biz/[Removed]antispyware/[Removed].exe</li>
</ul>
<p>Starts a HTTP server on a random port on the infected machine to host a copy of the worm.</p>
<p>Continuously scans the subnet of the infected host for vulnerable machines and executes the exploit. If the exploit is successful, the remote computer will then connect back to the http server and download a copy of the worm.</p>
<p>Later variants of w32/Conficker.worm are using scheduled tasks and Autorun.inf file to replicate on to non vulnerable systems or to reinfect previously infected systems after they have been cleaned.</p>
<h4 class="tabsection-title">Suggestions -</h4>
<ol>
<li>Disable AutoPlay in your environment.</li>
<li>Run a good security suite.</li>
<li>Keep your computer updated with the latest patches.</li>
<li>Be <strong>PROACTIVE</strong> and look for the worm in your environment.</li>
</ol>
<p>Sources:</p>
<p>http://www.nai.com</p>
<p>http://www.symantec.com</p>
<p>http://www.f-secure.com</p>
<p>http://isc.sans.org</p>
<ul></ul>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/01/worm-uses-social-engineering/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Locking Down The Blackberry Network</title>
		<link>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/</link>
		<comments>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/#comments</comments>
		<pubDate>Sun, 11 Jan 2009 09:02:08 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[bes]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[rim]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[smartphone]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=683</guid>
		<description><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown.jpg"></a>Early last year India threatened to discontinue Blackberry service if Research In Motion (RIM), the company behind the Blackberry did not allow the Indian Government to monitor the Blackberry network traffic raising serious security concerns. Here are a few articles from <a href="http://www.pcworld.com/article/143351/india_scrutinizes_blackberry_security.html" target="_blank">PCWorld</a>, <a href="http://www.infoworld.com/article/08/03/12/BlackBerry-under-security-scrutiny-in-India_1.html" target="_blank">InfoWorld</a>, and <a href="http://news.cnet.com/8301-10784_3-9953395-7.html" target="_blank">CNet</a>.</p> <p>Now president-elect Barack [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown.jpg"><img class="alignleft size-medium wp-image-689" title="lockdown" src="http://blog.sekiur.com/wp-content/uploads/2009/01/lockdown-300x190.jpg" alt="" width="300" height="190" /></a>Early last year India threatened to discontinue Blackberry service if Research In Motion (RIM), the company behind the Blackberry did not allow the Indian Government to monitor the Blackberry network traffic raising serious security concerns. Here are a few articles from <a href="http://www.pcworld.com/article/143351/india_scrutinizes_blackberry_security.html" target="_blank">PCWorld</a>, <a href="http://www.infoworld.com/article/08/03/12/BlackBerry-under-security-scrutiny-in-India_1.html" target="_blank">InfoWorld</a>, and <a href="http://news.cnet.com/8301-10784_3-9953395-7.html" target="_blank">CNet</a>.</p>
<p>Now president-elect Barack Obama <a href="http://www.telegraph.co.uk/news/worldnews/northamerica/usa/barackobama/4174298/Barack-Obama-vows-to-keep-Blackberry-despite-hacking-fears.html" target="_blank">vows to keep his Blackberry</a> despite hacking fears and concerns by the Secret Service.</p>
<p>This will not only be a headache for the Secret Service but its pretty likely that hacking attempts towards the RIM network will increase exponentially.</p>
<p>Generally people just don&#8217;t think about the risk that a smart-phone poses, specially if its connected to a Blackberry Enterprise Server. How could my phone be a risk to anyone? Well a smartphone is not just a phone, but rather a miniature computer that is not just capable of making calls but it also an un-metered gateway into the corporate network.</p>
<p>In order to understand what actions to take to protect a smart-phone, in particular the Blackberry you have to understand how it works and how it interacts with the Blackberry Enterprise Server.</p>
<p><strong>Vulnerabilities:</strong></p>
<ul>
<li>Lack of authentication</li>
<li>Lack of encryption</li>
<li>Lack of mobile code execution controls</li>
<li>Difficult to enforce controls</li>
<li>Peripheral devices introduce additional vulnerabilities</li>
<li>Infrastructure vulnerabilities service specific operating systems, platforms, applications, etc.</li>
<li>Small size is prone to theft and loss</li>
<li>All devices may not be corporate owned</li>
<li>Multiple configurations of the Blackberry Enterprise Server (BES) architecture</li>
<li>Limited centralized update mechanisms</li>
<li>Limited IT/CIO Control</li>
</ul>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2009/01/bes.png"><img class="aligncenter size-full wp-image-684" title="bes" src="http://blog.sekiur.com/wp-content/uploads/2009/01/bes.png" alt="" width="466" height="257" /></a></p>
<p><strong>Sources of Recommended Controls and Security Guidelines:</strong></p>
<ul>
<li>The Vendor  (Microsoft, Treo, RIM, etc.)</li>
<li>SANS (www.sans.org)</li>
<li>NIST has a great publication</li>
<li>Other existing guidelines</li>
<li>3rd Party Solutions often fill the gaps</li>
</ul>
<p>Once the vulnerabilities have been identified we proceed to implement controls and audits.</p>
<p><strong>Controls:</strong></p>
<p>Controls will include policies, standards, practices, procedures, guidelines, awareness, authentication, encryption, and asset management.</p>
<p><strong>Audits:</strong></p>
<p>Once the scope has been defined, allow to review the implementation of policies between the BES, servers, Blackberry devices, and Blackberry desktop agents. Audits also allow the review of configuration and options to ensure that security is not just available but implemented. Additionally configurations pushed down to end devices need to be audited as well.</p>
<p>The infrastructure design and configuration of network components (firewalls, routers, switches, VLANs, etc.) will need to be audited as they play an intricate part of the overall security of the system.</p>
<p><strong>Risk Assessment:</strong></p>
<p>Although this requires additional resources and expertise, its a must in certain environments like corporate or government. A risk assessment will identity security vulnerabilities and provide a 2nd chance to identify all &#8220;assets&#8221;.</p>
<p>Once this has been completed, validating the risk by performing an &#8220;ethical hack&#8221; will remove any uncertainty by proving the vulnerabilities identified actually exist.</p>
<p><strong>Conclusion:</strong></p>
<p>Providing documentation on the findings is vital. The documentation required will contain an executive summary, action items and details for system administrators, and a clear and concise report with both the good and the bad findings.</p>
<p>A couple of things that should not fall through the cracks are ensuring that the corrective actions are implementable within the organization and the next audit scheduled.</p>
<p><strong>Sample Policy:</strong></p>
<p><a rel="bookmark" href="../2009/01/sample-blackberry-enterprise-server-policy/">Sample Blackberry Enterprise Server Policy</a></p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2009/01/locking-down-the-blackberry-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Its the FMI&#8217;s Turn at Being Hacked</title>
		<link>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/</link>
		<comments>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/#comments</comments>
		<pubDate>Sun, 23 Nov 2008 05:41:58 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[fox news]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[imf]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=562</guid>
		<description><![CDATA[<p>Within weeks of the World Bank&#8217;s story breaking about its computer systems being breached by hackers, Fox News has reported here that Cyber-Hackers have broken into the IMF computer system.</p> <p>The International Monetary Fund (IMF) is an <a title="International organization" href="http://en.wikipedia.org/wiki/International_organization">international organization</a> that oversees the <a title="Global financial system" href="http://en.wikipedia.org/wiki/Global_financial_system">global financial system</a> by following the [...]]]></description>
			<content:encoded><![CDATA[<p>Within weeks of the World Bank&#8217;s story breaking about its computer systems being breached by hackers, Fox News has reported here that Cyber-Hackers have broken into the IMF computer system.</p>
<blockquote><p>The <strong>International Monetary Fund</strong> (<strong>IMF</strong>) is an <a title="International organization" href="http://en.wikipedia.org/wiki/International_organization">international organization</a> that oversees the <a title="Global financial system" href="http://en.wikipedia.org/wiki/Global_financial_system">global financial system</a> by following the <a class="mw-redirect" title="Macroeconomic policies" href="http://en.wikipedia.org/wiki/Macroeconomic_policies">macroeconomic policies</a> of its member countries, in particular those with an impact on <a title="Exchange rate" href="http://en.wikipedia.org/wiki/Exchange_rate">exchange rates</a> and the <a title="Balance of payments" href="http://en.wikipedia.org/wiki/Balance_of_payments">balance of payments</a>. It also offers financial and technical assistance to its members, making it an international <a title="Lender of last resort" href="http://en.wikipedia.org/wiki/Lender_of_last_resort">lender of last resort</a>. Its headquarters are located in <a title="Washington, D.C." href="http://en.wikipedia.org/wiki/Washington,_D.C.">Washington, D.C.</a>, <a title="United States" href="http://en.wikipedia.org/wiki/United_States">USA</a>.</p></blockquote>
<p>The IMF of course absolutely denies that the event took place. <span id="intelliTXT">The spyware discoveries came at a particularly sensitive time for the international bailout institution, which along with the World Bank is expected to play a central role in trying to combat global financial turmoil.</span></p>
<p>This is too much of a coincidence in my opinion. Any information taken by the attackers will likely be used as leverage to blackmail the institutions rather than being made public to embarass them.</p>
<blockquote><p><span id="intelliTXT">In fact, the computer assaults on the World Bank and the IMF are only part of a rash of sensitive cyber-burglaries that even reached into the U.S. presidential campaign. Both London&#8217;s Financial Times and Newsweek recently reported that the computer network of the White House, and the Obama and McCain campaigns, were seriously breached.</span></p>
<p>The Pentagon claims the Chinese army has established units to develop viruses to attack enemy computer systems. Chinese hackers penetrated the Pentagon last year, in an attack that obtained e-mails from the system serving Defense Secretary Robert Gates.</p>
<p>Despite vigorous Chinese denials, &#8220;everyone in the intelligence community knows that China is the biggest player in cyber espionage,&#8221; says John Tkacik, a former head of China intelligence for the U.S. State Department. Tkacik told FOX News that later this month, President-elect Obama will be presented with a new top-secret National Intelligence Estimate (NIE) report that &#8220;will cause the scales to drop from his eyes&#8221; regarding Chinese cyber-espionage.</p>
<p>&#8220;What the Chinese are particularly interested in at the IMF is what loans the IMF is likely to give to other countries,&#8221; says Nick Day, a former British intelligence officer who runs Diligence, a private investigative firm that does extensive work for many international corporations and institutions.</p>
<p>&#8220;The geopolitics of this is that essentially you&#8217;ve got a few countries in the world that are stacked on huge foreign capital reserves — Russia, China, Japan, the Middle East — and the rest of us are pretty much borrowers to those lenders.</p></blockquote>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/11/its-the-fmis-turn-at-being-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>World Bank Hacked</title>
		<link>http://blog.sekiur.com/2008/11/world-bank-hacked/</link>
		<comments>http://blog.sekiur.com/2008/11/world-bank-hacked/#comments</comments>
		<pubDate>Sat, 15 Nov 2008 01:58:57 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Guy De Poerck]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[incident]]></category>
		<category><![CDATA[intrusion]]></category>
		<category><![CDATA[jack conde]]></category>
		<category><![CDATA[kenneth lay]]></category>
		<category><![CDATA[Robert Zoellick]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[sap]]></category>
		<category><![CDATA[SecurID]]></category>
		<category><![CDATA[world bank]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=373</guid>
		<description><![CDATA[<p>Earlier this year, the World Bank suffered a server security breach in which hackers were able to compromise critical servers.</p> <p>In what Fox News characterized as an &#8220;<a href="http://www.foxnews.com/story/0,2933,435681,00.html" target="_self">Unprecedented Crisis</a>&#8220;, were one of the largest repositories of sensitive data about the economies of every nation, had been raided repeatedly for more than a year.</p> [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this year, the World Bank suffered a server security breach in which hackers were able to compromise critical servers.</p>
<p>In what Fox News characterized as an &#8220;<a href="http://www.foxnews.com/story/0,2933,435681,00.html" target="_self">Unprecedented Crisis</a>&#8220;, were one of the largest repositories of sensitive data about the economies of every nation, had been raided repeatedly for more than a year.</p>
<p><a href="http://blog.sekiur.com/wp-content/uploads/2008/11/hacker_d70focus_1.jpg"><img class="aligncenter size-medium wp-image-550" title="hacker_d70focus_1" src="http://blog.sekiur.com/wp-content/uploads/2008/11/hacker_d70focus_1-300x200.jpg" alt="" width="300" height="200" /></a></p>
<blockquote><p><span id="intelliTXT">It is still not known how much information was stolen. But sources inside the bank confirm that servers in the institution&#8217;s highly-restricted treasury unit were deeply penetrated with spy software last April. Invaders also had full access to the rest of the bank&#8217;s network for nearly a month in June and July.</span></p>
<p>In total, at least six major intrusions — two of them using the same group of IP addresses originating from China — have been detected at the World Bank since the summer of 2007, with the most recent breach occurring just last month.</p>
<p>In a frantic midnight e-mail to colleagues, the bank&#8217;s senior technology manager referred to the situation as an &#8220;unprecedented crisis.&#8221; In fact, it may be the worst security breach ever at a global financial institution. And it has left bank officials scrambling to try to understand the nature of the year-long cyber-assault, while also trying to keep the news from leaking to the public.</p>
<p><a href="http://www.foxnews.com/projects/pdf/UnprecedentedCrisisEmail.pdf" target="_blank">• Click here to see the e-mail.</a></p></blockquote>
<blockquote><p><span id="intelliTXT">The crisis comes at an awkward moment for World Bank president Robert Zoellick, who runs the world&#8217;s largest and most influential anti-poverty agency, which doles out $25 billion a year, and whose board represents 185 member nations. This weekend, the bank holds its annual series of meetings in Washington — and just in advance of those sessions, Zoellick called for a radical revamping of multilateral organizations in light of the global economic meltdown.</span></p></blockquote>
<blockquote><p><span id="intelliTXT">The bank&#8217;s chief information officer, Guy De Poerck, has engaged Price Waterhouse Coopers to do a confidential million-dollar assessment that is expected to tell him what&#8217;s going on in his own department.</span></p></blockquote>
<p>What is very peculiar about this story is that no other news agency has reported the event and that Fox News was able to acquire internal e-mails and memos regarding the attack.<br />
Jack Conde, Senior Enterprise Risk Management Officer at World Bank shared with executives on July,10, the extent of the breach <a href="http://www.foxnews.com/projects/pdf/WorldBankDoc1.pdf" target="_blank">here</a>. According to the memo at least 17 servers were breached and were slowly being taken offline to perform forensics.</p>
<p>The memo goes on to say what steps they will take in the future to prevent information leaving the network, like implementing an outgoing firewall rule preventing communications being initiated from within the network.</p>
<blockquote><p>A major effort is underway to implement a firewall rule that will bar all outbound traffic from server networks to the internet with exceptions made for servers with a legitimate reason to make such connections. To this end, ISG staff is creating a daily report of traffic which will be vetted by ISG service managers and OIS to insure that all exceptions are explained and justified. The rule will be implemented on Friday. This effort will curtail any data lost from production servers in the future.</p></blockquote>
<p>This a normal reaction to a breach, were measures that should have been in place were not, but any such action should always be considered carefully to determine if it will actually prevent data loss or provide a false sense of security.</p>
<p>In the age of spyware, malware, keyloggers and hamachi, the biggest threat to corporate data comes from within.</p>
<p>What would be achieved by a firewall rule restricting Internet access? Well, absolutely nothing when the servers have access to every PC on the internal network and subsequently these PC&#8217;s have inherent access to the Internet.</p>
<p>In this particular situation were the attacker was able to compromise in excess of 17 servers and go undetected for so long, can only lead to 2 conclusions. Either the security guys are clueless or the attacker or attackers knew what they were doing.</p>
<blockquote><p><span id="intelliTXT">In plainspeak: &#8220;They had access to everything,&#8221; says the source. &#8220;They had the keys to every room at the bank. And we can&#8217;t say whether they still do or don&#8217;t until we fully and openly address what&#8217;s happening here.&#8221;</span></p></blockquote>
<p>Now this is not a small business, a law firm, or a retail chain. This is the World Bank, so I am inclined to believe that the keepers of the data are professionals and subsequently it would be wise to think that the attacker is not stupid.</p>
<p>Having access to the servers that were compromised and knowing that sooner or later someone was going to discover the breach, it wouldn&#8217;t be far fetched that the attacker would create false accounts and personnel records to back them up in the SAP (ERP), HR and Secure ID systems of the 10,000 plus employee organization.</p>
<p>This would give an attacker the capability to restore access once the breach was discovered triggering the containment plan. Additionally the attacker had gained system administrator access providing access throughout the corporation, providing the potential of creating backdoor&#8217;s into virtually any desktop computer in the network.</p>
<p><span id="intelliTXT">After FOX News published its story, a World Bank spokesman issued the following statement:</span></p>
<p><span id="intelliTXT">&#8220;The Fox News story is wrong and is riddled with falsehoods and errors. The story cites misinformation from unattributed sources and leaked emails that are taken out of context.</span></p>
<blockquote><p>&#8220;Like other public and private institutions, the World Bank has repeatedly experienced hacking attacks on its computer systems and is constantly updating its security to defeat these. But at no point has a hacking attack accessed sensitive information in the World Bank&#8217;s Treasury, procurement, anti-corruption or human resources departments.&#8221;</p></blockquote>
<p>In the security field, you have to be paranoid and levelheaded, specially if you are working in an outfit like this.</p>
<p>Hey World Bank&#8230;. if you need a hand&#8230; drop be a line.</p>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/11/world-bank-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox Extensions For Penetration Testing</title>
		<link>http://blog.sekiur.com/2008/11/firefox-extensions-for-penetration-testing/</link>
		<comments>http://blog.sekiur.com/2008/11/firefox-extensions-for-penetration-testing/#comments</comments>
		<pubDate>Mon, 10 Nov 2008 13:30:27 +0000</pubDate>
		<dc:creator>Jose Vicente Ortega</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[open source]]></category>
		<category><![CDATA[penetration testing]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://blog.sekiur.com/?p=510</guid>
		<description><![CDATA[<p>This year at the SecTor security conference in Toronto, Canada, Security Compass introduced a series of open source firefox extensions aiding in penetration testing exercises.</p> <p>Illuminating the Black Art of Security. SecTor brings the world&#8217;s brightest (and darkest) minds together to identify, discuss, dissect and debate the latest digital threats facing corporations today. Unique to [...]]]></description>
			<content:encoded><![CDATA[<p>This year at the SecTor security conference in Toronto, Canada, Security Compass introduced a series of open source firefox extensions aiding in penetration testing exercises.</p>
<blockquote><p><span class="Content">Illuminating the Black Art of Security. SecTor brings the world&#8217;s brightest (and darkest) minds together to identify, discuss, dissect and debate the latest digital threats facing corporations today. Unique to central Canada, SecTor provides an unmatched opportunity for IT Professionals to collaborate with their peers and learn from their mentors. Held at the Metro Toronto Convention Centre in downtown Toronto, SecTor runs two full days, October 7th and 8th. The event features Keynotes from North America&#8217;s most respected and trusted experts. Speakers are true security professionals with depth of understanding on topics that matter. SecTor is a must attend event for every IT Professional.</span></p></blockquote>
<p>This suite of web application security testing tools is named Exploit-Me and its designed to be lightweight and easy to use.</p>
<p>The suite is compromised of <strong>XSS-Me</strong> allowing Cross-Site Scripting, which is a common flaw found in web applications, <strong>SQL Inject-Me</strong> used to check for SQL Injection vulnerabilities which would allow malicious users to view, delete and modify records and finally <strong>Access-Me</strong> which test for access vulnerabilities by trying to access resources without being authenticated.</p>
<p class="section_header">XSS-Me</p>
<p><a href="http://securitycompass.com/exploit_me/xssme/xssme_faq.shtml"><img class="small" src="http://securitycompass.com/img/xssme_img.jpg" alt="" /></a></p>
<p class="section_body">Cross-Site Scripting (XSS) is a common flaw found   in today&#8217;s web applications. XSS flaws can cause serious damage to a web   application. Detecting XSS vulnerabilities early in the development   process will help protect a web application from unnecessary flaws. XSS-Me is the    Exploit-Me tool used to test for reflected XSS vulnerabilities.</p>
<ul class="arrows">
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/7598">Download XSS-Me Now!</a></li>
<li><a href="http://securitycompass.com/exploit_me/xssme/xssme-0.4.0.shtml">XSS-Me 0.4 release notes</a></li>
<li><a href="http://securitycompass.com/exploit_me/xssme/xssme_source-0.4.0.zip">Get the source</a></li>
<li><a href="http://securitycompass.com/exploit_me/xssme/xssme_faq.shtml">Read the FAQ to find out more</a></li>
<li><a href="http://securitycompass.com/exploit_me/xssme/xssme_extended_strings.shtml">Extended XSS string set</a></li>
<li><a href="http://securitycompass.com/exploit_me/exploitme_issues.shtml">Known issues</a></li>
</ul>
<p class="section_header">SQL Inject-Me</p>
<p><a href="http://securitycompass.com/exploit_me/sqlime/sqlime_faq.shtml"><img class="small" src="http://securitycompass.com/img/sqlinjectme_img.jpg" alt="" /></a></p>
<p class="section_body">SQL Injection vulnerabilities can cause a lot of damage to a   web application. A malicious user can possibly view records, delete   records, drop tables or gain access to your server. SQL Inject-Me is the Exploit-Me tool used    to test for SQL Injection vulnerabilities.</p>
<ul class="arrows">
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/7597">Download SQL Inject-Me Now!</a></li>
<li><a href="http://securitycompass.com/exploit_me/sqlime/sqlime-0.4.0.shtml">SQL Inject-Me 0.4 release notes</a></li>
<li><a href="http://securitycompass.com/exploit_me/sqlime/sqlime_source.zip">Get the source</a></li>
<li><a href="http://securitycompass.com/exploit_me/sqlime/sqlime_faq.shtml">Read the FAQ to find out more</a></li>
<li><a href="http://securitycompass.com/exploit_me/exploitme_issues.shtml">Known issues</a></li>
</ul>
<p class="section_header">Access-Me</p>
<p><a href="http://securitycompass.com/exploit_me/accessme/accessme_faq.shtml"><img class="small" src="http://securitycompass.com/img/app_train_img.jpg" alt="" /></a></p>
<p class="section_body">Access vulnerabilities in an application can allow an attacker   to access resources without being authenticated.  Access-Me is the Exploit-Me tool used    to test for Access vulnerabilities.</p>
<ul class="arrows">
<li><a href="https://addons.mozilla.org/en-US/firefox/addon/7595">Download Access-Me Now!</a></li>
<li><a href="http://securitycompass.com/exploit_me/accessme/accessme-0.2.shtml">Access-Me 0.2 release notes</a></li>
<li><a href="http://securitycompass.com/exploit_me/accessme/accessme_source-0.2.zip">Get the source</a></li>
<li><a href="http://securitycompass.com/exploit_me/accessme/hacking_accessme.shtml">Learn to Hack Access Me to add evaluation code</a></li>
<li><a href="http://securitycompass.com/exploit_me/accessme/accessme_faq.shtml">Read the FAQ to find out more</a></li>
<li><a href="http://securitycompass.com/exploit_me/exploitme_issues.shtml">Known issues</a></li>
</ul>
<p style="text-align: center;"><script type="text/javascript"><!--
google_ad_client = "pub-3340920433757461";
google_ui_features = "rc:10";
google_ad_width = 468;
google_ad_height = 60;
google_ad_format = "468x60_as";
google_ad_type = "text_image";
google_color_border = "FFFFFF";
google_color_bg = "FFFFFF";
google_color_link = "0000FF";
google_color_text = "000000";
google_color_url = "008000";

//--></script>
<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.sekiur.com/2008/11/firefox-extensions-for-penetration-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

