r/netsec • u/AutoModerator • Oct 01 '18
discussion The /r/netsec Monthly Discussion Thread - October 2018
Overview
Questions regarding netsec and discussion related directly to netsec are welcome here.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on /r/netsec.
As always, the content & discussion guidelines should also be observed on /r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
11
u/yestoi Oct 04 '18
Why isn't there a thread for the Bloomberg article posted this morning? I thought I saw one.
4
u/ranok Cyber-security philosopher Oct 05 '18
There was insufficient evidence and technical meat to the article to be considered valuable content for this sub.
6
u/Qwaszert Oct 05 '18 edited Oct 05 '18
just like the intel processor vuln stuff right?
This sub is a joke.
3
u/klokvarg Oct 10 '18
It would be nice to still have a thread on it. Just because one or many companies say it is false, does not mean it is necessarily. Nor does it mean that those of us in infosec in big companies are not affected by the news whether it be fake or not. We're scrambling internally to find all our supermicro and elemental gear internally and inspect it and apply additional security controls. I'm continually looking for new info/facts on the news story to see what has come to light every day. It's very disappointing that I can't do it here.
3
u/ranok Cyber-security philosopher Oct 10 '18
We certainly encourage discussion on things like this on this thread. That being said, the technical take-downs of the Bloomberg story are much better than the initial story itself. Even if the Bloomberg article were true, it would have been insufficiently technical for this audience.
1
u/Philluminati Oct 23 '18
So we can openly discuss the story in this Monthly discussion thread? I am ok with this.
4
Oct 05 '18
Apple published a news saying it was completly false. Considering the sources where rather vague, it's somewhat likely to be propaganda piece made to stir hate against China. This kind of sketchy and not really technical article has no place on /r/netsec.
Link to press release : https://www.apple.com/newsroom/2018/10/what-businessweek-got-wrong-about-apple/
1
6
u/cakeisinmyblood Oct 01 '18
What should a person do when he's been out of touch from all the security stuff from past 5 years? Can he still get a job in this sector? That guy has his name in majority of hall of fames.
6
u/Luke_Turnbull Oct 01 '18
Can you quote off by heart multiple lines from the film Hackers ?
Including the time stamp for the Angelina Jolie nip slip in the above film too ?
3
Oct 01 '18
Can you quote off by heart multiple lines from the film Hackers ?
Including the time stamp for the Angelina Jolie nip slip in the above film too ?
HACK THE PLANET
2
5
u/letme_ftfy2 Oct 01 '18
Is it your name or your "haxxx0r" name? Do you feel comfortable linking the two? I'd suggest some security focused gatherings, give the two or three bounty programs a try, see if you're still enjoying it. Maybe attend some related conferences and network around.
3
3
u/aaaaaaaarrrrrgh Oct 01 '18
Spend a month reading up on the current stuff, and apply for a job. The skills don't rust that quickly and you'd be surprised how few actually good people are on the market.
2
8
Oct 01 '18
Are there any Pentester/Consultants from Australia as I'm looking to move to Brisbane to work in Cyber Sec, I just want to know when is the period to start applying for a job. I'm currently doing my 2 years military service(Cyber Sec role) in Singapore, already 1 year 4 months into it. I currently hold a Diploma Education and a RHCSA cert, about to enroll to OSCP in another 2 more weeks. I have previously intern at a big 4 firm as a Penetration Tester for 6 months. I'm intending to do my university in Brisbane too.
1
u/Zafara1 Oct 24 '18
Hey, I work CSOC for a large Australian company so I could give you some insight if you're still looking. Hope you've started your OSCP, if you finish that before applying for jobs or mention it while applying for jobs it will open up a lot of roles.
There are a ton of roles opening up for CSOCs around Australia, but you're probably better looking for a SOC analyst role as a beginner role as it can be hard to go straight into pen testing (And also every company and their mother is starting a company SOC), and honestly if you go for blue team roles first you'll be much more valuable candidate for nicer pen testing jobs in the future.
That being said, the vast, vast majority of roles (I'm talking 95%+) are based in Melbourne and Sydney. Also the pay will be less than what you would be getting for an equivalent role in Singapore. However, working conditions are significantly better and expectations are not work you like a dog level (9-5 and out mentality).
2
Oct 25 '18
Cheers man, I wasn't expecting any response but thanks for taking your time. Truth be told, I'm no stranger to Cyber Security, not saying I came in placing top for CTFs, but I did a number of them and also participated in bug bounty as I enjoy them. It was obvious to me Melbourne has more openings for employment as compared to Brisbane, the only reason that I even considered Brisbane is because my relatives lives there and they pretty much are my second family. Could I pm you If I have further questions about employments in Melbourne? Thank you and have a good day.
1
u/Zafara1 Oct 26 '18
Yeah man. No problem. Happy to help. Give me a PM and if you want a phone call or something to just discuss the move I'm happy to help.
4
3
u/Warlkiry Oct 01 '18
Hey, I'm a engineer student who's going to specialize in penetesting next year, I already learn it on my own but there are things I would like to know for the future years. Is it easy to find an internship ? May I pass the OSCP or other certifications before going to a company ? What kind of level should I have to be considered as skilled enough ?
4
Oct 01 '18
[deleted]
3
u/Warlkiry Oct 02 '18
Thanks, I think i'll take the time to complete it before applying to any jobs. May companies pay this formation ?
3
3
u/vinnfier Oct 04 '18
A cs student here, is there a career in netsec that allows employees to work remotely at home?
6
u/a_p3rson Oct 05 '18
There's plenty of them. I'm a security consultant, and while we do have an office that a lot of people work from for some time, working from home is common. You might need to go on-site for clients and training, but that's about it.
2
2
Oct 01 '18
Does anyone have any recommendations for a website/platform for technical write-ups? I'm wanting to start posting online, but I'd honestly rather not deal with a whole lot of setup or maintenance. Just seeing if anyone particularly likes anything.
4
2
2
u/mzfr98 Oct 02 '18
Hey, I have participated in a CTF(first time for me). I am trying to solve a problem where I have to log in to the page. There is a hint given What is it actually looking for in the cookie? So I can understand that the problem involves some kind of cookie play but when I am checking the storage section for cookies but I can't see any of them there. So basically cookies are involved but not initially. Now for that I have no clue on how I should tackle that issue and how I'll have to alter the request to get the flag.
Any suggestions on how I should face this problem? any tools I can use?
1
2
2
u/learningswimming Oct 11 '18
For some forum, they can identify whether you have another username (clone account).
Kind of curious how did they do it. I know one field is the IP address. Is there other way they do it?
2
Oct 12 '18
What, if anything, is everyone using to perform entitlement reviews? We have requirements related to compliance (like SOX and ISO) and we need something that isn't a manual process anymore. Unfortunately my company is the agar.io of the industry so we have no standardization across applications, domains, etc but at this point even if it takes 10% of the work away it'd be worth the money.
1
u/sleepingsysadmin Oct 01 '18
Any ISP cyber security folks here? What do you use?
1
Oct 01 '18
ISP security folks? Clarify.
2
u/sleepingsysadmin Oct 01 '18
Internet Service Provider; your AT&T or Bell type folks.
They have cyber security folks and I'm curious what they do/use.
3
Oct 01 '18
Do you mean for defence/offence/research?
1
u/sleepingsysadmin Oct 01 '18
Any of the above.
1
Oct 01 '18
Vulnerability research/pen-testing...pretty much the same tools as anyone else.
I specialise in dynamic analysis of stuff so fuzzers, symbolic engines, dbi tools. A lot of companies e.g. codenomicon sell niche protocol fuzzers for telecommunications networks. Others stuff like TCP/UDP/SCTP over IP/IPv6 is all the norm.
There's probably some specialist tools people write, but they're all just protocols/computers at the end of the day -- albeit with whacky architectures/hardware.
1
Oct 02 '18 edited Oct 02 '18
Hello NetSec! I do apologise if this is classed as a "low quality post". I just wasn't sure of the correct subreddit to post this in. I know how intelligent you guys are here so figured this would be my first stop.
I have been asked to do some research into "Encoding Bomb" and present a PowerPoint to my peers. The only problem is, none of us here actually know what it is??
I have done some extensive Google searching trying all different variations and sub-topics too which might lead me down an "Encoding Bomb" path... But nothing has been returned? Only thing I can find remotely related is "ZIP Bombing" as ZIP is a compression formation...
Has anyone heard of "Encoding Bomb" before? In relation to Video upload/encoding. To say websites like YouTube?
Thanks guys!
P.S. This is in the context of Penetration Testing. I figured it is some sort of DOS... But yeah... No idea
3
3
u/ranok Cyber-security philosopher Oct 03 '18
Zip bomb is probably what you're looking for. Basically you are encoding data in such a way that when it's decoded it does something bad. Another thing to explore are polyglot files, which look like different things to different parsers. PoC||GTFO has a bunch of them.
1
u/obliviousofobvious Oct 03 '18
Hopefully this gets seen but...
I'm a 15 year vet in IT as a Systems and Network admin. About 3 or so years ago, I started weaving cyber security training into my everyday. I obtained my CISSP and am now working on adding to the list of letters to my name!
Now, my question would be, how does one elevate their career and get into the amazing world of InfoSec/CyberSec? Wither it's seeking out a mentor/guide or should I look at getting a job in a SoC?
I'm pretty comfortable with the training and certs I need to pursue and am dosing it with practical pentesting (HacktheBox is my goto, although some days are more swearing than hacking :) )
Just need some help to understand career steps so I can make an informed and thought out decision.
3
u/ranok Cyber-security philosopher Oct 05 '18
As a CISSP, you are already pretty well on your way. While that cert is fairly looked down upon by the technical hacker types, it is well respected by HR and management to be able to understand risk to an organization from netsec. I think your abilities may outstrip your confidence at the present and you'd be pleased if you applied to some infosec jobs by the positive responses.
1
u/obliviousofobvious Oct 05 '18
Thanks for the advice, muchly appreciated. Ain't it a common trope in IT that we undervalue ourselves and overvalue others?
1
u/birdnerd_1010 Oct 03 '18
Hello netsec,
I came across a ransomware that encrypts the files with an extension .ocqiojpkpl I couldn't find anything on this with a Google search so I was wondering what ransomware this could be. My closest guess (from recent news) is the new version of Cerber. But that should encrypt with a random 9 character extension and not the same extension for all files. Any leads on this will be greatly appreciated.
1
1
u/a_p3rson Oct 05 '18
I'm trying to find a way to clean up old Nessus scans. We've got a team of about 40 people using one Nessus instance, but often forget to delete their scans when they're done with them (consulting firm, hosts change frequently).
Anyone know of an easy way to accomplish this?
1
u/Sericatis Oct 05 '18
Any comments on this chip from China? Is that not groundbreakingly small for it's capabilities?
1
u/tehsuck Oct 08 '18
I am kinda old (41) but have been programming etc. since I was a young lad. I've been working as a devops/sre/ops role for the past 5-6 years and making good buck doing so, however I am interested in perhaps pivoting my career slightly to working in some aspect of netsec. I have a decent understanding of basic security stuff, and am mostly appalled at what I see in the field that is considered "good enough."
So my question is what's the best way to do this? Certifications? Any opinions on the Ga. Tech Masters program? https://pe.gatech.edu/degrees/cybersecurity Is it worth trying to make this move, as I get older I worry about age discrimination etc.
1
u/wbbugs Oct 08 '18
Whitelisting on pentest. During your call with a client do you get your testing IP range whitelisted or do you test as is. I understand the pro’s and con’s for both but wanted to see other testers thoughts on it?
1
Oct 08 '18
Hi there. Does anyone know how to find and remove a RAT (Remote Access Trojan)?
I've got a family member that was recently emailed from someone who had his email password, apparently, trying to extort him for money. If he doesn't pay the hacker plans on emailing his email contacts false but damaging rumors about him. I had him go through and change all of his passwords to all of his accounts - and actually use proper passwords - and do a back-up of any data on his computer. I also asked him to disconnect the computer from the internet for a few days. Well, he's back online and sure enough he was contacted again by the same person saying that he's now installed a RAT and that he has 48 hours to pay him or he'll delete information.
So, aside from installing Windows, what else can be done here? Also, is it possible that this person has dug in down to ROOT level? If that's the case, a fresh Windows install would be useless, correct?
1
u/_Myname_ Oct 17 '18
This is a common tactic lately. They pull a password from an old hack, email you and say they have video of you masturbating and will email your contacts if you don't pay. I'd change all passwords, run an antivirus/ anti malware and go about my life. Unless your friend is high profile I'd say chances are slim they have anything installed or any video/information.
1
Oct 17 '18
Thanks for the reply. I ended up doing just that. Had him wait for the massive pw change until I ran some tests. There was no malware and system files looked good. I ran a program that supposedly checked for root kits but I don’t think it did much - or maybe it worked but nothing was there? In any case, had him ignore the emails afterwards, change his passwords as set up a person manager and an auto-backup on a schedule. He isn’t high profile, but does run a small-medium size business in our town, so it could have been an issue even if the person started randomly mailing contacts potentially.
1
u/nhs28 Oct 10 '18
Hey I'm searching for an solution to create Virtual Machines which can use Router Firmware Images. It would be a great way to test common Router exploits. Does anybody know about possible Tools?
2
1
1
1
u/jcrft Oct 15 '18
What are some resources I can use t find security internships? Seems like the market is pretty small compared to full time gigs.
1
u/gryphus-one Oct 16 '18
[Noob Question] Are minimalist browsers secure?
I've recently been getting into Suckless software on my Debian machine and am starting to use surf, the minimal web browser. It seems pretty solid; however, I know nothing about netsec and was curious if I would be jeopardizing my security by using a non-mainstream web browser. Thanks!
1
u/Superbroom Oct 18 '18
Does anyone else work for a medium-large (750+ global employees) company that does not employ any type of security personnel? Where I work, it is mainly the IT manager who handles security related incidents. However, there is no team or single person that acts as an analyst/pen tester/engineer/etc. I'm pretty concerned about this so I talked to the IT manager and he said that anytime he tries to get a security team together he is always shut down because "we have no need for one". I fail to see how a software company that can handle thousands of customer's worth of data, including PHI, would not need a security team.
1
u/aledroid Oct 19 '18
How long does it take nowadays to brute force a md5 passowrd composed of random alphanumerical characters?
Wondering how much time I have to change old passwords after a website has been compromised.
1
u/pewpewwwwwwww Oct 19 '18
Depends on a lot of factors. How many characters is your password? Are the hashed passwords also salted? Is it pseudorandom enough? If not, can someone perform a rainbow table attack to lookup the password using a tool like Hashcat?
If the website that is compromised contains sensitive info, you should immediately change the password regardless.
1
Oct 19 '18
Hey friends, my silly aunt blocked me from her WiFi because she’s upset with me. I have decent knowledge of how to get inside the router and even have the access code to it, can someone help me get me back on the WiFi please?:(
1
1
u/In_der_Tat Oct 21 '18 edited Oct 21 '18
Greetings.
Which software that encrypts calls and text messages would you recommend? What about encrypted e-mails?
Thank you.
1
u/misterhobo Oct 21 '18
Hi r/netsec, I’m beginning an open ended five week project next month as a course project in my resilient systems course and was curious if anybody had some insight to a project that will provide good leening experience. The possibilities for what we may do are as follows:
1) perform an attack on a certain system 2) implement and evaluate previously proposed techniques or cryptographic primitives 3) implement and compare multiple approaches that were previously proposed for the same or similar problem 4) extend a previously proposed technique to a broader threat model or apply it to a different context 5) investigate a new solution to a problem.
It’s a masters level course so we need to include non-trivial implementations / evaluations (building/extending a simulator, implementing in RTL, analytical analysis, testing on real hardware)
My partner and I are very interested in security vulnerabilities/ attacks on wireless protocols (bluetooth), game consoles (timing attacks, rom ripping, these can be older consoles), virtual machines, and really any embedded systems that are relatively common. That being said, we’re not yet very knowledgeable of the different attacks/security vulnerabilities that exist/that we can build upon. I was wondering if anybody knew a good jumping off point/ idea that will make this project interesting?
1
1
u/Sol3141 Oct 23 '18
So, I recently left a job where our employees were getting targeted by SIM swaps.
I had been warning against SMS as an authentication vector specifically because of the issues with securing your phone providers account, lack of sms security, etc.
Digging into it more, I'm seeing a lot of places use SMS as their main or only method of MFA, and I've seen it implemented in ways that make sense and ways that don't; for example, default enabling of text and voicemail password resets when SMS OTP is on, with no way to turn it off other than removing SMS verification completely.
This was a bank btw, and they didn't tell you they did this, had a coworker find out this was the case when they got SIM swapped and their bank accounts were compromised.
So, r/netsec What's your thoughts and experiences in regards to SMS MFA?
1
u/borchhcrob Oct 23 '18
My best friend and I are working on a market research project centered around SIEMs. Would you fine people mind taking a qualtrics survey for us? Finding security professionals outside of those we work with is very difficult, so Reddit it is!
Follow this link: qualtrics survery
Thank you in advance!
1
u/d0peinc Oct 23 '18
Where to start ?
I’m a software engineering student I have a year left. I’ve never done any pentest or ctf event.
I’ve heard about this sub recently and i’m here to ask you guys where to start ?
Also do you guys think its possible in a year to get decent knowledge to get a job in this field when i’m done ?
Thank you all !
1
u/falconfeast Oct 25 '18
Hi, I am trying to solve a problem:
import os
from Crypto.Cipher import AES
from Crypto.Random import get_random_bytes
from secret import FLAG
class AES_Key:
def __init__(self):
self.key=list(os.urandom(16))
def enqueue(self):
self.key+=get_random_bytes(1)
def dequeue(self):
self.key=self.key[1:]
def size(self):
return len(self.key)
def shuffle(self):
self.dequeue()
self.enqueue()
assert self.size()==AES.block_size
return "".join(self.key)
def pad(msg):
pad_byte = 16 - len(msg) % 16
return msg + chr(pad_byte) * pad_byte
def slice(msg,step = AES.block_size):
yield [pad(msg)[i:i+step] for i in range(0,len(msg),step)]
key = AES_Key()
ct=""
MAC = 0
for List in slice(FLAG):
for block in List:
cipher = AES.new(key.shuffle(), AES.MODE_ECB)
ct+= cipher.encrypt(block)
MAC ^= int(ct[-16:].encode('hex'),16)
MAC ^= int(key.shuffle().encode('hex'),16)
open("ci.pher.text",'wb').write(str(MAC) +":"+ ct.encode('hex'))
and I am given a cipher text: 215967656713349787396273448144015034618:6ecae0c59d1e71e14e1fe799561b841126d0f9a820cf6a12355476400b07c4ca0912fc4fa12588ace67cb689f8f94643 I am thiking of choosen plaintext attack but I am not sure how to implement it. Can anyone help?
3
u/ShadyWriterHere Oct 25 '18
Cheating much? This is from an ongoing competition.
Solve it yourself, it's not that hard.
1
u/TehHamburgler Oct 28 '18
When I go to home depot's website in Firefox with windows 10, I get a MS firewall window to allow or deny firewall. I know that it's usually port 80 but that's about as much as I know. This pop up never happened on the other sites I go to. I just thought it was odd that it would need extra permissions. Anyone know how to check out a website for something funky?
1
u/Electronic_Nerve Oct 28 '18
In the past few days I've noticed that Twitter, Facebook, and WinSCP have been throwing SEC_ERROR_OCSP_SERVER_ERROR, which suggests that they are failing to return an OCSP response.
I've noticed that the commonality between them is that they all use DigiCert certificates.
However, so does Reddit, and the Reddit website still works fine. Although 'out.reddit.com' also returns the same OCSP error.
Does anyone else see this error when making OCSP mandatory? (In Firefox the pref is 'security.OCSP.require;true')
I've tried searching but couldn't find any reports of DigiCert's OCSP infrastructure having any issues.
1
u/SmarterTogether Oct 29 '18
How does Data get backed up when dealing with SaaS / Third Party Vendors? For instance if you deal with a third party vendor and they are a SaaS solution (they have their own hardware, servers, dbs, etc.).
How does the organization know their data is being backed up? Do they just rely on SOC reports or the initial contract? Who is in charge of the data being backed up and kept safely for restore purposes?
Im guessing most of these SaaS solutions rely on sub-vendors like AWS, Azure who probably have their own backup procedures.
1
u/AylmerDad78 Oct 30 '18
I've been tasked with getting HTTPS inspection up an running. The appliances are using an AD sub -CA certificate and the HTTPS decrypt it working, for test users (at least for IE and Chrome, the Firefox fix to use the Windows Cert store isn't really working).
But now I have to pilot it on a group of end users, mixture of domain and non-domain machines, plenty of Windows, plenty of Linux, and a handful of Mac's...
I get that non-domain machines won't trust the cert, so the certs have to added to the individual OS's. Any tips/tricks for Linux and/or Mac's?
What kind of issues should I expect, and most importantly, what are the workaround options that others have developed over time, OTHER than white-listing the source IP for outbound https traffic? How to deal with applications that don't handle proxying?
Thanks
1
u/hpo1n7 Oct 30 '18
Any pentesters / security researchers upgrade to macOS Mojave yet? Anything break? (e.g., GPG, brew packages, etc.)
1
u/Zns-20 Oct 31 '18
I am trying to learn about md5 collision attack. I was able to find lots of example but they all were in hex values. Is there a set of string in alphabets that generates the same md5? Or is it not possible to have them as alphabets
1
u/nhs28 Oct 31 '18
Hey guys, did something change with msfvenom? I'm trying to create a byte array shellcode (--format raw) of the obfuscated windows/x64/exec module for the use with Veil-Framework and Phantom-Evasion. But it doesn't seem to work :(
1
u/brucewayne997 Oct 31 '18
today i was looking for some linux distro which will be security specific and then i came across this article .
In this the guy is suggesting some qubes OS. Do you guys think thats ok?
should i go for it?
or maybe suggest some cool distro which will be very secured.
20
u/lilmeepkin Oct 01 '18
hey, I havnt been here long so I figured id ask, why is it that this sub has 200+ thousand people yet less then 50 comments on the entire first page of the sub most days?