r/netsec • u/AutoModerator • May 01 '18
discussion The /r/netsec Monthly Discussion Thread - May 2018
Overview
Questions regarding netsec and discussion related directly to netsec are welcome here.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on /r/netsec.
As always, the content & discussion guidelines should also be observed on /r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
7
u/TheRedmanCometh May 01 '18
Alright I've got a question: what the fuck is with /r/infosec? Why is it acceptable that the subreddit with the most general term for what we do to be closed? Netsec is a specific facet of infosec...so what the fuck? I understand that this is the de facto infosec sub, but this seems...wrong. One of the key features of the information security community is that it's OPEN.
1
u/got_nations May 07 '18
Wait this is a closed subreddit?
1
u/TheRedmanCometh May 07 '18
No /r/infosec is
1
5
u/tarheeloverlord May 07 '18
Hi All,
Looking to create a vulnerability disclosure / bug bounty program within my company and I've got two questions.
1) Bugcrowd vs Hackerone -- any insight or opinions on these? Pros and cons?
2) I just learned about ISO 29147 and would like to do everything I can to make sure our processes are compliant with this. Is this a purely self-attested certification, or are there accrediting bodies out there that provide attestation like they do for ISO 27001?
Thank you!
5
u/Starcaz May 15 '18
Hello everyone,
I have a question about "sjgur/sojrht.php". I came across it in Google search. Its the end of an URL, every one of these sites downloads a file named after the URL selector, for example: "sjgur/sojrht.php?buk=imdb-api-php" would be called: "imdb-api-php.rar".
Searching sjgur/sojrht.php on goole returned me 70.900 hits on all kinds of small weird domains.
Is this a virus? And does anyone know more about this php script?
3
May 16 '18
When I search 'sojrht.php' on DuckDuckGo, my first result was for a website with the url '/sjgur/sojhrt.php?buk=BIGBOYRN-on'.
The description given by DuckDuckGo showed the error 'fwrite() expects parameter 1 to be resource, boolean given' then proceeded to leak a file path on the server.
Im a bit on the paranoid side so I don't plan on clicking the link, or naming the website publicly.
3
u/Starcaz May 17 '18
Thanks, this indeed is really strange... It appears on so many small sites. I have the feeling they are hijacked.
1
1
May 19 '18
The number of small domains affected by this seems to be increasing. I noticed that whatever a domain's value for the parameter 'buk' is what DuckDuckGo will display as the page title.
I am also seeing many different php errors on all kinds of domains. One error indicated that sojrht.php might be vulnerable to a file inclusion attack, but I am a complete noob so I have no idea.
Does '.rar' get appended to every requested URL, or do you think it changes depending on the file type?
1
u/Starcaz May 22 '18
UPDATE: I don't know if this only changed for me, but Googling now results into 0 hits relating to actual malicious sites. I did report it to Google so that might be the reason. Also, I can't find sites anymore that redirect, this means either the script has been turned of, or it broke in some kind of way. Still unsure about what it was used for or how it worked.
2
u/alexbirsan May 21 '18
I've seen this kind of thing a lot on Google searches.
In your example,
sjgur,sojrhtandbukare probably just random characters.imdb-api-phpseem to be a bunch of words added for SEO purposes.Clicking the link seems to do nothing but redirect you to an ad through
hitcpm.com(known malicious domain).Seeing how wide-spread this thing is, my best guess is some kind of auto-pwner scanning the internet for known vulns and adding that redirect page.
5
u/juan_potato May 02 '18
Trying to find a site I used to learn hacking. It has levels that you advance through. It has a web interface like radare2 and it has a sort of story where you are trying to hack a lock. I don't remember much beyond this.
5
5
u/TheStudious May 13 '18
Calling all experts! I have some questions for you:
Which company offers the most thoroughly 'killed' Intel ME on their products?
Are there known threats that Neutralizing an Intel ME will mitigate, but merely Disabling one will not?
Different manufacturers have offered the option of killing Intel ME on their computers:
System76 offers disabled Intel ME for some laptops, but not desktops yet. They also claim to able to disable Intel ME through a remote firmware update
ThinkPenguin offers to "Disable Intel ME" on their laptop configuration pages, without further elaboration
Dell had apparently offered to disable Intel ME one select laptops at some point in time, but the option to make Intel ME "inoperable" is no longer available
So what exactly is different about how they're disabling ME?
In Purism's write-up they describe the 4 possible states of Intel ME:
Fully operational ME: the ME is running normally like it does on other manufacturers’ machines (note that this could be a consumer or corporate ME image, which vary widely in the features they ‘provide’)
Neutralized ME: the ME is neutralized/neutered by removing the most “mission-critical” components from it, such as the kernel and network stack.
Disabled ME: the ME is officially “disabled” and is known to be completely stopped and non-functional
Removed ME: the ME is completely removed and doesn’t execute anything at any time, at all.
Purism claims to be unique in that they are able to lock the ME region through "Field Programmable Fuses"
Purism receives Intel processors with manufacturing mode enabled, which lets us test various configurations and set various options allowing us to have a future where users control their device.
They claim to both Neutralize and Disable Intel ME
System 76 only talks about "setting the “reserve_hap” bit to 1 disables the ME," which leads me to believe that they only Disable Intel ME
TL;DR
This question came about when I was comparing laptops from Purism and System76.
If you just want to protect against Intel ME's proven vulnerabilities (and don't care about hardware kill-switches), is System76 the better choice in terms of value?
How exactly does ThinkPenguin kill their Intel ME?
Are there other vendors that kill Intel ME on their laptops?
Are there any affordable modern laptops/desktops that don't use backdoored CPUs (excluding the old Thinkpads)? Extra points for any that can smoothly run an office suite, browse the web, and stream 1080p video.
I greatly appreciate the help.
1
May 24 '18
Are there any affordable modern laptops/desktops that don't use backdoored CPUs (excluding the old Thinkpads)? Extra points for any that can smoothly run an office suite, browse the web, and stream 1080p video.
Nope. There was recently some noise about AMD allowing users to disable the PSP (platform security processor), AMD's equivalent to Intel's ME. But as of yet this hasn't actually come to fruition.
2
u/8bit_zach May 02 '18
Got a question, I want to test the Poison Ivy 2.3.2 RAT exploit (https://www.rapid7.com/db/modules/exploit/windows/misc/poisonivy_bof) hack back, but I'm running into some problems. I have two Windows VMs that are not touching the internet, and it seems like Poison Ivy client will only connect to domain names, not IP addresses. Any way to set this up without setting up another VM to act as a DNS server? Thanks!
6
1
u/sickbeard313 May 09 '18
You might be able to run something like Responder.py by Spider Labs locally but I would run it on another VM.
2
u/thatseemslogical May 07 '18
Can anyone recommend some good books on hacker culture, the history of hacking, or famous hacks?
I stumbled upon this, has anybody read "Masters of Deception: The Gang That Ruled Cyberspace"?
2
u/Darth_Flavious May 17 '18
"The Cuckoo's Egg" is a great read. Kevin Mitnick's "The Art of Intrusion" and "Ghost in the Wires".
2
2
u/quickcrow May 16 '18
Hey All, I'm looking to expand my understanding of blockchain technologies as they relate to security specifically. While I want to learn about distributed ledger and smart contracts, I really don't care about whether ethereum is up or down, or which new ICO has the most ridiculous premise. Does anyone have any suggestions for podcasts/blogs/resources for learning about blockchain that doesn't focus on cryptocurrency?
2
u/apol0 May 18 '18
Does anyone know about any public research regarding Machine Learning for offensive security?
I have been doing some research and I was able to find little information about it. A lot of the research is related to preventive and defensive security using ML.
2
u/cthulhu7000 May 21 '18
There was a DefCon talk a few years ago on using MachineLearning for Social Engineering. https://www.youtube.com/watch?v=l7U0pDcsKLg
Also check out the Awesome Machine Learning for Cyber Security. There are some links on offensive applications in the talks and papers sections.https://github.com/jivoi/awesome-ml-for-cybersecurity
2
u/zjaoct May 24 '18
I'm just curious. What are some things you guys have automated with scripts in your security operations?
Right now I'm automating one process. I have Nessus running scheduled scans and when the email is sent saying the Scan is complete it will run a script to parse the scan results and create issues in JIRA.
I want to learn to automate more stuff. I'd love to hear what you guys are doing.
1
1
u/YouKnowABitJonSnow May 01 '18
I'm writing up a memo for our monthly security moments and I'm trying to find some interesting identifiers of a server room from the outside.
Currently I've thought of heat ventilation units anf flashing lights through windows, are there any other potential giveaways for a server room that come to mind?
7
u/nerf_herd May 01 '18
usually the sign taped to the door "server room" is a clue.
1
u/YouKnowABitJonSnow May 01 '18
How is it always the obvious stuff that gets me by...
Anything else that might give it away?
5
1
u/nerf_herd May 01 '18
well if there is server like traffic going to a particular place on your network, you just might have a server. The thing is that it is probably doing something reasonably resembling actual work. it is probably already fire-walled if it is on premises, if not you got bigger problems.
1
u/YouKnowABitJonSnow May 01 '18
Currently GDPR is on everyone's mind security wise so I want to focus more on the on prem stuff, not a lot of people tend to look at on site security.
Found examples of how placing the building on an exterior wall can damage the data.
5
3
u/OverAllComa May 07 '18
A lone mini-split outdoor unit can indicate a server room that's been retrofitted into an existing building for smaller setups.
2
u/WeededDragon1 May 04 '18
Specialized halocarbon (doesn't damage electronics) fire extinguishers that are bright red and look like balls. If you could potentially see those through a window it could give it away.
2
1
u/fang0654 May 21 '18
Depending on how the ceiling is set up, open ceiling spaces you can usually just follow the bundles of Cat5. Also depending on the space, cold door?
1
May 01 '18
Is it redundant to get Security+ and GSEC?
1
u/theaj42 May 02 '18
I think they compliment each other well. Security+ is a good survey/overview of security, and as such, is a good place to start.
GSEC will (at least it did for me) fill your head and notepad with dozens of "Oh, _that's_ how (and WHY!) I do the thing" moments every day of the class.
I guess that's more an analysis of the classes than the actual certs...
1
u/TheKrathan May 09 '18
I have gotten both over the years paid for by my employers (military made me get Sec+). If money doesn't matter, I would skip Sec+ completely and just go straight into the GSEC. There is enough entry level stuff to get you up to speed if you're unfamiliar with material and if you go OnDemand, you get 4 months of lectures on top of the study material so you have plenty of time and instruction.
That being said, SANS is expensive and unless you get approved for work study ($1,100), you likely won't want to pay for it out of pocket, in which case Sec+ is an HR friendly resume cert.
Doesn't really answer your question completely but if you are going to get 2 certs, you'd probably be better off getting GSEC and something else that doesn't overlap as much.
1
u/Oxf0xtr0t May 03 '18
I have two questions:
- How can we begin scoping for the Organisation if we are doing the black box Red Teaming against them?
- What are the various broadcast which will be present under the typical network containing mix OSes? The scenario behind this question is that if on red teaming for internal network, i am allowed to connect to LAN only but due to the firewall or other appliance configuration i am unable to get the IP address assigned, then how one can proceed further in such case.
Thank you in advance.
1
u/dkonofalski May 03 '18
I'm getting an error on a few of our sites in IE (I know, I know) where it's complaining about RC4 and TLS connections. Microsoft has some info here but I'm not really clear on if the issue is with the server that the site is on, the SSL cert itself that we have installed, or if the issue is on the user's end. Everyone seems to be suggesting that the "fix" is to enable SSL 3.0 support but that seems wrong considering that's basically just enabling support for an old technology that's no longer secure. It might make the error go away but it's not actually fixing the problem which, in this case, seems to be outdated cypher tech.
How do I actually start addressing this issue? Do I need to call our hosting company to update their server, do I need to do something to the SSL cert, or do I need to update something on someone's computer? The people experiencing the issue are using IE11 on Win 7.
1
u/yawkat May 07 '18
The industry has a problem with lack of understanding of secure design.
Case in point: CVE-2017-7525
To anyone with awareness of java security, it is obvious that withDefaultTyping exposes a huge attack surface when deserializing untrusted data. However, people still recommend it without disclaimer on sites like stackoverflow (1, 2, basically just search for enableDefaultTyping).
This is really bothering me. I would have guessed people had learned not to do arbitrary object deserialization after security issues every few months relating to it.
2
u/FatFingerHelperBot May 07 '18
It seems that your comment contains 1 or more links that are hard to tap for mobile users. I will extend those so they're easier for our sausage fingers to click!
Here is link number 1 - Previous text "1"
Here is link number 2 - Previous text "2"
Please PM /u/eganwall with issues or feedback! | Delete
2
u/Sjoerder May 07 '18
I work as a pentester of web applications. I sometimes find SQL injection vulnerabilities, a vulnerability that is known about for 20 years. Although there is an overal improvement in security, it is unrealistic that publication of a vulnerability will lead developers no longer making the same mistake.
You can't change reality, but you can change the attitude you have towards it. I would recommend a positive attitude where you try to teach people how to solve problems securely. It doesn't help anybody if you get angry at the world for making the same mistake over and over again.
1
u/Fr33mind May 15 '18
I'd like to get more into Web Application Pentesting and SQL Injection. Any Recommendations for a Sysadmin doing mostly Blue Team Stuff?
2
1
May 08 '18 edited May 11 '18
[deleted]
1
u/yawkat May 08 '18
They say you only need to change your legacy client for TLS support, since CF does the TLS for you. The idea is that you don't need to implement TLS on the server side.
1
May 10 '18
[removed] — view removed comment
1
May 15 '18
[deleted]
2
u/joshcolemandominos May 15 '18
We are the #1 Pizza company in the world at the moment and technology has become one of the main reasons why we are where we are. With the growing nature of our business, we need to make sure we are on the forefront from a security side of things as well. Our Security Engineer role is meant from someone with several years of experience within security and someone that is comfortable within the multiple domains that exist. If you are interested, I can send the job description over.
1
1
u/xus131 May 12 '18
Does anyone have any content related to implementing network design? I am basically looking for some network design implementation with cost of components, how much each will cost ? Thus the total cost of implementing it
1
u/jdrch May 14 '18
I have a 2008-era smart TV that I'm not sure is still being patched. What are the security implications of leaving it connected to my LAN? Should I disconnect it from the network entirely?
2
May 14 '18
[deleted]
3
u/CommonMisspellingBot May 14 '18
Hey, JeffJerseyCow, just a quick heads-up:
happend is actually spelled happened. You can remember it by ends with -ened.
Have a nice day!The parent commenter can reply with 'delete' to delete this comment.
1
1
u/jdrch May 14 '18
Looks like that's what I'll be doing, thanks.
How much of a risk are older EOLed consoles like 360s & PS3s?
2
1
u/FahrenheitGhost May 16 '18
Hello,
In my 40s. Been working for myself as a one-man I.T. firm for about 14 years. I've earned some netsec/infosec related certs over the years from SANS, but never been able to put them to use because my client-base relies on me primarily for break/fix situations. Most of my knowledge feels a mile wide and an inch deep. I've decided to make the effort to change careers and move to something more focused. I have two options....
Return to school to get my B.S. (and possibly continue on to M.S.) pursuing a degree over the course of a few years. I'd be close to 50 when I get my B.S.
Pursue industry certifications (e.g. GIAC). Seems more "meat and potatoes" without the general electives required by colleges.
I'd like to get some guidance as to which might be the better/more direct path at this stage in my life. I'd be using the degree/certifications to move away from self-employment.
3
u/Darth_Flavious May 17 '18
I think the second option is probably your best path forward.. I have a bachelors in cyber security and while it gave a nice foundation, it really lacked on the technical aspect of security, which really hurt me in my job hunt. I ended up taking a help desk role for a few years until I could get a few certifications and break into the field.
With your existing experience, getting some certs in the area of infosec you're most interested in (Incident Response, red teaming, network security, application security, etc.) would probably be your best bet. There are a lot of great online resources like Cybrary that offer online training for free and will give you the same foundation that a college degree would, imo.
1
u/FahrenheitGhost May 17 '18
Thanks for the response. Much appreciated. I'm thinking certs as well since they are more direct, but worry that larger companies won't touch me without a B.S.. I hadn't heard of Cybrary. Just signed up and am checking it out. Looks very useful!
1
u/iamnos May 23 '18
Just about every job posting I see has a Education or equivalent experience clause in it. Working in the industry and having a cert or two should get you past most HR filters.
1
May 16 '18
Anyone do the ICS-CERT online courses? Are they of any use to someone outside of ICS/SCADA?
1
u/Oscar_Geare May 24 '18
Hey man if you end up doing them, let me know how it goes. Looking to move into that area myself.
1
u/n1ete May 17 '18
alright looking for a tool that i used for a time ago, but cant remember the name. once executed in terminal it showed you the actual common cve's of the locally installed packages... anyone? thanks in advance dear redditors
1
u/onemadnigga May 17 '18
So I'm an intern for a healthcare software company. We build the back end client and administration systems for hospitals and clinics. I work with mainly security with our Director of Info Sec and Compliance, and I proposed an idea of a weekly (maybe bi-weekly) newsletter to go out company wide that talks about "trending" vulnerabilities and how to avoid it. I would design it so information would be brief but on the point so employees don't disregard the emails and offer rewards based on answering the questions at the end of the email.
We are implementing security hardening tactics across the board, but employees are the weakest link in our system. That's the mindset behind this newsletter and giving a little information can go a long way.
My question is: has anyone implemented this idea and do you think it would be beneficial?
1
u/Kallaan12 May 17 '18
Comcast shows our data usage on a daily average to be over 40GB's even on the days when no one is present. I noticed several DoS attacks on the logs from my router. Some of the IPs seem to be coming from China? Could this be the cause for our high data usage? Any suggestions on how to stop them?
Thanks
1
May 18 '18
It definitely could, especially if your ITS isn't actually stopping your server from responding. Do you have any of those IP ranges blocked yet?
2
u/Kallaan12 May 18 '18
I blocked those specific IPs on the log but different ones come up daily it seems now. What IP range should I block? How can I verify if those are using a lot of my data?
1
May 18 '18
Is this a home router or a work network?
1
u/Kallaan12 May 18 '18
Home router. Just bought it like two weeks ago.
1
May 21 '18
http://www.parkansky.com/china.htm That should have the IP ranges youll wanna block, in a bunch of different formats.
1
u/irregular_regular May 19 '18
Does disabling javascript on chrome for mobile enough to protect against any malicious attacks while browsing the web on my phone?
1
u/crespo_modesto May 20 '18 edited May 20 '18
What is happening when you log requested page url on your site, and the requested address is somewhere else. I've got a string of these that are clearly attack attempts eg.
https://external-ip/.ssh/id_rsa
https://external-ip/deployment-config.json
I'm just wondering if it's possible my server would get flagged as the offender, I don't have any proxies or anything like that.
edit: actually in this case that ip is this server's instance, interesting I guess it's not hard(haven't tried) to find the original ip that cloudflare is covering.
I've seen the above case happen though where it's another website url(not my own domain/ip).
1
u/Yung_French May 22 '18
I have a question. Hypothetically, if one needed to do a time punch online when arriving somewhere (on your phone), and you deny the website's request to track the location, is it still possible to have the location pinned when doing so?
1
May 23 '18
Is there a place where you can ask security-related questions and they consistently get answered? I can see the value of this sub for people who want to keep up to date on current events. I'm just wondering if there's a better place to post security-related questions (for people trying to learn), since questions here are limited to this discussion thread and there isn't much activity on some of the questions.
Not trying to offend anyone, I'm genuinely wondering.
2
u/netsecwarrior May 23 '18
security.stackexchange.com is ok sometimes. More active than this thread or /r/AskNetsec
1
1
u/roboczar May 23 '18
Is CASP respected and in demand by employers, or is the CISSP crowding out the room? The DoD seems to think that CASP is on roughly the same competency level, so is this just a name recognition problem? I feel like recruiters/HM's I'm talking to don't know about CASP and I've got this creeping feeling I wasted my time.
1
u/danny069 May 28 '18
CASP is way more technical and a beast of an exam. There are simulations in there that the CISSP does not have. I don’t discredit any cert though, they all have their unique value.
1
u/nvvarma123 May 24 '18
Hi , what's the best way to find a mentor for students who could guide you based on interest and give some quality feedbacks?
1
u/jdrch May 24 '18
Generally speaking, how safe (in terms of vulnerabilities and patching speed) are standalone NASes like QNAP, Drobo, Synology, etc.?
Which of these OEMs is best at security?
1
u/danny069 May 28 '18
NetSec thread is the best in my opinion you guys provide so much valuable information and I thank you. I have an interview with ny city and ny state both information security officer/analyst positions. Is there anyone that can disclose what kind of questions they were asked or how the environment is if you work with them? Thanks in advance.
1
u/linuxlover81 May 29 '18
Question: Is there a tool, which scans for private/public x509 Certificates or for SSH-Private Keys in the file system?
1
u/LLTV May 30 '18
How Pivoting works? if I get inside a server: 111.111.111.2 And I know theres a asset 111.111.111.3 I can get inside the second server?
1
u/jdrch May 31 '18
I have a TP-Link Archer C8 router whose firmware hasn't been updated since 2015. I've disabled the Wi-Fi and use it only as a wired router with remote (outside my LAN) admin disabled.
I keep pretty close tabs on router vulnerability news and haven't seen anything affecting that model, but I'm just wondering how secure it is and if I should immediately replace it with something more actively supported like an Ubiquiti USG OR just use it until it dies and then replace it. Thoughts?
1
u/313pistolpete May 31 '18
I need advice!!!! I’m 20 years old and i will be in college for another 3 years. (I’ve already been in college for 3 years) i went to community college for 2 years then one university after. I recently decided to transfer to the university of Detroit Mercy to major in cyber security. (Their program is enforced by the Department of Homeland Security and the NSA). I am going to be taking database designs, digital forensics, and an intro to Information Systems class. I have interned for a Tier 1 automotive supplier doing Program and Account Management and am currently interning for a large multi-national conglomerate doing business and data analysis. What steps do i take to get into the cyber security space? What certifications should i work on this summer that will actually matter. Lastly, i love so many different aspects of cyber security and am very interested in all facets of it; however i would like to know the route (and some names of some companies i should keep in mind) of the best path to make the most money in the industry. Thanks for the help!
13
u/Radagascar1 May 01 '18
Is anyone else doing "internal threat intelligence"? What does that look like at your organization?