Archive for September, 2009

null Meet Bhopal 30 September

// September 29th, 2009 // 3 Comments » // Meets

Its now time to boost the phreakiness of null by adding up more
security phreaks who are really willing to contribute for the cause.

First Official null Meets in Bhopal.

Agenda:

Introduction of null members, their profile and background. Where to go from here.

Date & Time: 30th Sept 2009 05:00 PM

Venue: Plot no.C-7, Income Tax Housing Society, E-8 Gulmohar, Bhopal -462039

————————————————————————————————————–

Minutes of  Meeting:

People Present:

1. Yogesh pandit

2. Pranav Nemade

3.  Lokesh Ghure

4. Yogendra Kirar

5. Akanksha Suneri

6. Vivek Singh Parihar

7. Aisha Gandhi

8. Akshat Mishra

9. Pram Mohit

Talks/Discussion:

————————-

1.  Introduction about null By Yogesh Pandit.

2.  Discussion about current happenings  in security and cyber crime world.

3.  Safeguard against identity theft and  password hacking while surfing through internet cafe By Lokesh Gujre.

Following topic will covered in upcoming meets.

1.  Voice communication routers By Pranav Namade.

2.  Phishing  By Yogesh Pandit.

3.  Secure Socket Layer (SSL) By Akanksha Suneri.

null Bangalore Meeting on 19th September 2009 – An Update

// September 24th, 2009 // No Comments » // Meets

First of all we are getting a fantastic response for the NULL meets. On an average we are getting about 15 people in the room.

TALKS

We had one amazing talk + demo + code
1. SSL Cipher Enumeration by Gursev

Gursev started his talk with basics of SSL handshake and then explained why certain tools being used for enumeration are not sufficient. Tools such as SSLDigger, Nessus and OpenSSL just connect and get the version of SSL being used. Sometimes SSLv2 is allowed only to inform users about using SSLv3. This implies that we are bound to get some false positives by just relying on the tools.

Among reasons on why we should do an audit of SSL being used we mentioned that as part of most compliance requirements minimum SSL version should be 3 and minimum cipher strength should be 128 bit.

His tools of choice for the talk+demo were Wireshark, Ruby specifically the interactive ruby prompt. He also covered a typical real world scenario of using these tools behind two types of proxies. He used Fiddler and Paros to demo this.

The most informative part for me personally was they way he built his ruby script to first just connect to a web server on port 443. Then wrote code to show all the supported versions on the server and how we can use the program to force the server to send only a certain combination for our testing. Also any doubts I had about the differences in SSLv3 and TLSv1 were clarified.

He was awesome to put all this up on his blog. Please read the full text here.

http://gursevkalra.blogspot.com/2009/09/ruby-and-openssl-based-ssl-cipher.html

MISC

1. KV Prashant and Shashidhar have taken the initiative to bring something similar to COPTECH to Bangalore.
2. People discussed about attending certain conferences and the value in doing so. Also the online security conference on SecurityTube was discussed as well.
3. Due to popular demand Gursev has agreed to do a more comprehensive talk on cryptography in the near future.
4. The next talk is on Web 2.0 Security by KV Prashanth on 3rd October. I still need to co-ordinate with Sundar of OWASP to send a reminder for that.
5. We need to discuss about trying out ISACA office as a venue once we have more number of people turning up for the meets.

Lastly I would like to apologise for the delay in posting the update about the meeting. First a holiday and then fever contributed to the delay. Ideally a couple more people along with me who don’t mind spending an hour or so would ensure that the updates/reminders don’t get delayed. Please send me an email off-list.

CopTech … (Ajit Hatti)

// September 21st, 2009 // 3 Comments » // Blog

Event : CopTech
Date : 16th September
Venue : Commissioner Office, Pune

Introduction to CopTech :

Pune Police along with Nasscom and Data Security Council of India (DSCI) on 30 June, established the Cop Tech forum to increase sharing of ideas & knowledge on cyber security between the Cops and the IT Industry. In presence of many CXO of reknowned IT Industry and top brass cops Commissioner of police Satya Pal Singh signed a memorandum of understanding (MoU) with Nasscom.

< IT compnies see CopTech as a great business oportunity. Some how we didnt find any one from IBM who were there in last inaugural meet>

The Event :

Presence :  60+ members, mostly from IT, BPO, Security Consultants and NULL. <around 14 NULL Members, Majority :) >
Anchored by : DCP Rajendra Dahale.
Headed by : Comissioner of Police Dr.  Satya Pal Singh

<He has huge  popularity among the youth, probably the only tech savy commissioner who blogs, inaugurate Hacker Summits and Promotes Cyber Security at such a great level>

Other dignities :

Mr. Pratap Reddy (IPS, Security Advisor to NASSCOM)

<Guys, we were impressed by his knowledge & great visibility in the operations of IT and Police Department.> ,

Anant Shinde (Add. Comm. of Police Crime Branch)

Deepak Shikarpur (President Computer Society Of India)

<Pune’s IT Icon, he is very popular in Pune, writes columns, I have read some of his sci-fi type tech columns :) >.

Anand Deshpande (MD Persistent Systems)

<Persistent is higly respected organization in Pune. Its  Devang Methat auditorium is home to many technical conferences and community driven activities>

Opening Speach : Mr. Dahale
Breifed on the coptech initiative and the challanges in front of cyber crime department.
Few intresting points he maidjottings out of his speach

1. Cyber Crime Cell Pune – Formed on first 1st July 2003 and 5 cases were registered in the same year.
2. 207 casese were registered in 2008
3. 182 cases have been reported till 31 Aug 2009
4. The major cyber crime complain comprises of
1. Defacing on orkut and other social sites (67)
2. Nigerian Frauds (12)
3. Mobile Hacking (52)
4. Email account hacking (11)
5. Others.

The Highlight of CopTech : Mr. Pratap Reddy

Mr. Reddy took on the discussion further and enumurated the challanges the Police department has in fron of them

1. Modernising Police Control Room : Drawing an anlogy between Police Control room and BPO industry, Mr. Reddy said that theres a lot department can learn from BPO industry to better manage the operations. He gave 3 points of focus :
a. People : to be trained for soft skills and working with more efficiency.
b. Process : Redifine process to better manage the control romm operations &
c. Technology : to facilitalte the People to execute porcesses and operations more effectively and efficiently.

2. Effectively chanellising the information gathered from Control room to the task forces which work on the actual sight of incidents.
a. Improvements in Response time
b. Exploit the information effectively
c. Use of digital gadgets like GPS, digital Maps etc.

3. Data Mining. Department has huge data and it is ever increasing. Finding relevant information is the biggest challange. Departments is in need of appropriate technology/tools to improve their data mining capabilities.

4. Use of CCTV and Video Analytics in real time to proactively controll the incidnets and improve response time.
He said currently CCTV is used in responsive manner. Department needs technology which can analyse the videos and generate alerts/inform control room in real time.

5. Modern Cyberforensic Lab, tools and Expertise. With the current state, Cyber crime cell takes good amount of time to solve the cases. With enhanced tools and expetise there is good scope to minimize the turn around time.

6. Citizen Advisory : Stressing on Prevention, Mr. Reddy said its higly improtant to make citizens aware of threats on net. Awareness is a good way to fight cyber crime.

The IT Icon of Pune – Depak Shikarpur:

Deepak Shikarpur had mentioned said

“In my child hood I saw two films back 2 back Pandu Havaldar and James Bond. and had thought when will our Pandu Havaldar will become James Bond? And Im pleased to tell that with the modernisition, technology and the new outlook of these dedicated cops, Yes we feel that our cops are no less then James Bond”.

<Yes Sir!!! we all agree with you on that>.

The Chief – Dr. Satya Pal Singh :

Addressing the COPTech Forum Dr. Satya Pal Singh read out another lottery mail which he recieved on his black berry and challanged the corporates to come up with better SPAM filters.

“Its like a marriage of Police Department and Technology. And the relation is dominated by the stronger party. The technology is stronger party and hence department has taken up this challange to make better use of technology and work in smart, effective and efficient manner.”

He also made an early announcement of a new modern Forensic lab in Pune which will be probably best in the country

<Tentative date of official inauguration is 7th Oct. but department is yet to find some chief guest to inaugurate it>

Vote of Thanks :
Mr. Tungar thanked the Corporates, Dignities and NULL members present for the Meet.

We null members had a good long discussions with Mr.Tungar on their day today challanges, non-cooperation, loose operations of IT and Telecom industry etc.  He also discussed a famous case where a person was victim of digital evidences which were against him and how they solved the case based on their experience with humans and not with machine. We had a great time with him.

With sips of coffe, crackles of wafers and sweetness of Gulabjaumns, we were indulged in networking with many other eminent IT personalities present at Cop-Tech.

It was a great event. We were amazed by the humbleness of Police department and there drive to achieve technical excellence right from operations to dealing politely with tax payers.

Dr. Satyapal Singh told

“Control room daily recieves thousands of calls. 75% of which are irrevelent, miss guiding or just to ask some lame address. But still would like our force to work under cool and improve on their soft skills.”

Obviously this event has increased my respect for Police force and has motivited me (rather all nulls) to contribute in this drive called COP-Tech…

Enjoy,

~Ajit

Hughly popular among the youth, probaly the only tech savy commissioner who writes blog, innogrates Hackers Summits and Promotes Cyber Security at such a great leve

Bangalore Meetup on 19th September 2009 at Praxeva India starting at 10 AM

// September 16th, 2009 // No Comments » // Meets

There is a slight change in the talks being covered due to unforeseen circumstances.

The following talks are scheduled

1. SSL Cipher Ennumeration by Gursev

This is what he will be covering

# Aim: Enumerate all ciphers suites supported by the web server.

# Application: Auditing of cipher suites supported by web server. Testing ciphers supported by web servers is mandatory for various activities like PCI tests, Penetration testing and possibly other compliance issues.

# Discuss about SSL basics (very basics)

# Then we dig down and write a quick script using OpenSSL and Ruby to help achieve the same.

2. Demonstration of a tool – Amit Parekh

3. Demo of the GIFAR attack – Amit Gupta

4. Discussion on security incidents in the past – Led by Gursev // This may or mayn’t happen depending on the time we have

The talk Practical Aspects of Taking your Application to the Cloud by Simran Gambhir is postponed till after he recovers from a broken foot. Get well soon dude!

VENUE DETAILS

Praxeva India Services Pvt. Ltd, Atrium Business Center, 66/1 2nd Floor, Coles Road, Frazer Town, Bangalore-560005 Praxeva India Office Location on Google Map

* End of mosque road there is a CCD, from there, if you look diagonally opposite (onto coles road), you will see a pizza hut (approx 100 meters). The office is on the 3rd floor of the pizza hut building.

null Pune meet on Sat 12th Sept 2009

// September 7th, 2009 // No Comments » // Meets

Agenda:

1. Lessons learnt while deploying security devices on Corporate Network – By Murtuja Bharmal

2. nullcon Goa 2010 – Where are we?

Date & Time: 12th Sept 2009 04:30 PM

Venue: Securematrix, 2nd Floor, Trident Towers, Pashan Road, Bavdhan, Pune

null@Bangalore

// September 7th, 2009 // No Comments » // @Bangalore

City: Bangalore

State: Karnataka

Country: India

Moderator(s): Akash Mahajan (aka _at_ null.co.in),
Prashant KV (bug _at_ null.co.in),
Riyaz Walikar (karniv0re _at_ null.co.in)

Website: http://null.co.in
Mailing List: http://groups.google.com/group/null-co-in

null@Pune

// September 7th, 2009 // No Comments » // @Pune

A bunch of really really crazy, like minded security phreaks.

City: Pune

State: Maharashtra

Country: India

Moderator(s): Murtuja Bharmal (void _at_ null.co.in),
Aseem Jakhar (null _at_ null.co.in),
Prashant Mahajan (corrupt _at_ null.co.in),
Pushkar Pashupat (ppush _at_ null.co.in)

Website: http://null.co.in
Mailing List: http://groups.google.com/group/null-co-in

Null Bangalore Meeting on 5th September 2009 – An Update

// September 7th, 2009 // 1 Comment » // Meets

We had a combined NULL + OWASP meeting this time. The response was very encouraging with over 20 people showing up.

TALKS

We had two informative talks

  1. Cookie Replay Attacks by Ravi Gopal
  2. Cloud Security by Shashidhar

In the cookie replay attacks talk and demo Ravi demonstrated how trivial it is to sniff an ethernet network to find google cookies and then replay them to gain access to the gmail accounts. His research has indicated that only the GX cookie value is enough to do this. The attack is mitigated by using secure HTTP for your entire gmail session. He has made a blog post about this as well Cookie Replay Attacks

In the the Cloud Security talk Shashidhar explained from the basics of what is the historical background for cloud computing and took it all the way to explain 15 domains people should be aware of before taking their apps/businesses to the cloud. Interesting arguments were put forth in support of and against what he presented. This also led to Simran proposing the next meeting’s topic.

One of the members was concerned that if all the sysadmin/security related functions move to the cloud what will happen to his job. Shashidhar assured him that there will be plenty of work going around in the 15 domains he spoke about.

Due to paucity of time he wasn’t able to cover all the points in the presentation he will surely respond to any questions you might have after going through the presentation.

MISC

  1. We had a lucky draw to giveaway one NULL t-shirt. Gursev was the one who won that.
  2. Shashidhar suggested that in case the number of attendees becomes more than 40 we can use the ISACA office for holding our meetings.
  3. The pictures were taken by Gursev.

NEXT MEETING on 19th SEPTEMBER 2009 – 10 AM

The following talks are scheduled

1. Practical Aspects of Taking your Application to the Cloud – Simran Gambhir

2. Discussion on security incidents in the past – Led by Gursev

3. Demonstration of a tool – Amit Parekh

VENUE DETAILS

Praxeva India Services Pvt. Ltd, Atrium Business Center, 66/1 2nd Floor, Coles Road, Frazer Town, Bangalore-560005

Praxeva India Office Location on Google Map

* End of mosque road there is a CCD, from there, if you look diagonally opposite (onto coles road), you will see a pizza hut (approx 100 meters). The office is on the 3rd floor of the pizza hut building.

Introduction to vulnerability research

// September 2nd, 2009 // 1 Comment » // Blog

I often get asked by many people on how we discover new vulnerabilities or code exploits. So, finally I decided to spend some time and make a small tutorial on what vulnerability research is all about. Well, it’s not a tutorial as such, more of an introduction. But I have covered all aspects of it – right from discovery to exploit creation process. I have made this three part series on discovering ActiveX vulnerability using fuzzing. This tutorial could serve as good “jump start” to all the folks looking to get into Fuzzing and vulnerability research.

Discovering ActiveX Vulnerabilities — Part 1 [ Introduction ]
Discovering ActiveX Vulnerabilities — Part 2 [ Fuzzing ]
Discovering ActiveX Vulnerabilities — Part 3 [ The Exploit ]

njoy,

~DaH4ckeR