October 26, 2016

CompTIA Security+ certification review


Overview

   I will start my certification story with Security+. At the beginning of 2015 my wife and I decided to relocate from Russia somewhere in Europe, because technical security jobs in my city are at low demand with pretty shit salaries by the way. So one of the first steps for us was to convert my knowledge in something more recognizable all around the world. I read some reviews regarding different certifications and decided to start with CompTIA Security+. I knew that this certification is an entry level one for security, so I it didn't take much time to prepare. Another important reason was that English is not my native language, so I wanted to get a feel of enterprise security terms and approaches.
   I have quite weird thoughts about certification process itself. It is not rare that certification is used not for proving skills, just to move up for career ladder regardless what you know and your abilities. That is why I am a big fan of Offensive Security guys, their approach and frustration. Obviously for Security+ you can easily google dumps, but if you don't understand the actual material you will struggle a lot in feature. By the way price around 300$ is quite challenging in Russia I decided to pass exam myself as I did before in school and University. I was always bad in "copy-paste" way.
   I examined CompTIA site and found more details about themes:
  • Network Security - 21%
  • Compliance and Operational Security - 18%
  • Threats and Vulnerabilities - 21%
  • Application, Data and Host Security - 16%
  • Access Control and Identity Management - 13%
  • Cryptography - 11%
All questions were divided on these categories. 90 questions/90 minutes to complete exam. 900 points maximum, 750 to pass. Let's prepare.

Preparation

There were 2 books for Security+ preparation:

Both books were excellent preparation guide. Let's dig a bit in. Topics were quite similar, so I will speak about both books in general.
  1. Network Security. Here you will find all variety of topics about firewalls, IPS/IDS, VLAN, DMZ, NAT, protocols from different layers of TCP/IP stack and etc. In exam most of the questions in these domain would be about port numbers and associated protocols, effective security measures to lock down security on network level, wireless security.
  2. Compliance and Operational Security. This part is quite boring and annoying, but I can't but mention the fact that these topics would be very helpful for you when you will decide to ask security budget increase or buy new fancy useless security toy=) Disaster recovery, backup plans, incident response, risk management - understanding all these topics would be handy to speak with business. More interesting to read about physical security and security administration. Remember all abbreviations, what they mean and how technical stuff influence them.
  3. Threats and Vulnerabilities. I think most interesting topic in both books. You will dive in malware classification, application and general attacks, social engineering. Most questions from this category would be about choosing best way to mitigate some threat or to distinct one threat from another.
  4. Access Control and Identity Management. Here you will deal with authentication/authorization (802.1x, port security, RADIUS and etc), host-based security software, ways to improve security on endpoints. Most questions would be about how to implement these features to address specific threat in most effective way.
  5. Cryptography. Key concepts of symmetric and public key cryptography, hashing, most common protocols, limitations and recommended parameters to use. Also network protocols which use cryptography heavily would be described: IPSec, TLS, HTTPS and etc.

Exam

   My review would not be really full without my impression about exam. Actually it was not too bad. CompTIA gave you various number of situations and asked for best solution in this situation. 2 out of 4 answers were quite stupid, but to choose right one you will probably need to think a bit. It was all about choosing best variant. You need to remember 2 parameters from situation in your head to do right  choice. Also you can find performance-based questions, which were far away from practice. In one question you will probably found parts from different domains. For question examples-have a look at samples in books above.
   I spent 2 weeks to prepare for this exam. I did it in PearsonVue center. I used about 60 minutes to achieve 880/900, probably I missed 1 or 2 questions. My first step towards relocation was made.

Conclusion

This exam can prove your entry level of understanding security. It is not hard technical exam, more situation based. Obviously, good university would provide all necessary background to pass this exam quickly. If you are looking for Level 1 position or your first infosec job it is a good choice. With my current level of experience and knowledge I would not bother to recertify after expiration.

October 17, 2016

Share is fun!

   A lot of things happened since my last blog post. During last 2 years I could not find time to write a blog post=) Lie! However, now my wife and I raise 2 beautiful kids and we teach them that "share is fun". As you know, in order to show best example for kids you need to follow your own words. Let's get it started!

   I have a lot of material to share in my blog. I will try to write frequently, at least 2 times a week. I am going to cover different things:

  • my experience of passing Security+, CEH, OSCP, OSWP, OSCE, SANS GXPN. Also I hope to achieve SANS GREM and SLAE this year, so probably I will cover them too.
  • talk about Info Sec books, blogs and other resource I use to broad my knowledge. Unfortunately, there is not too much really good resources and books, so I will try to cover them.
  • describe interesting stuff that I face during my way in Info Sec. I am not going to copy/paste excellent materials from Corelan, fuzzy security and etc, but I am going to explain moments that was not clear for me during reading and I spent some time to research it.
  • create series of articles regarding Linux exploitation and some other things that is not clearly described in the Internet. Before starting something like this I will examine carefully available resources in order not to reinvent a wheel.

My main goal for this blog is to make it unique, interesting to read and valuable for different folks in Info Sec field.
   

February 20, 2015

NIST 800-61. Computer Security Incident Handling Guide

   I can call this standard as «CISO Time!» As far as computer security incidents are corncerned enough companies act in a reactive way. We have an incident, let's do something to reduce damage. Sometimes they thought how to patch vulnerabilities, which leads to some kind of remediation. And then wait for another incident.
   Also there is another way to deal with incidents — proactive way. In this standard you can find some useful steps how to implement incident response activities in company's every day life. Almost all recommendations are obvious, but they are placed together. If you are going to write incident response plan, you can follow instructions in this standard and you'll get sufficient plan.
   Standard consists of 3 parts. First part is devoted to organizing a Computer Incident Response (CIR) Capability. In this chapter you can find useful information about policy and plan elements, also with obvious advantages of developing CIR plan. Some pages describe how to effectively communicate within organization and what departments should participate in incident response activities.
   Second chapter was about how to handle an Incident. This activity consists of 4 steps: Preparation → Detection and Analysis → Containment, Eradiction, Recovery → Post-Incident Activity.
   As far as preparation step is is concerned I can't but mention 3 main activities:
  •  get all necessary contacts from people with whom you are going to work while CIR; 
  • all incident analysis hardware and software should be up to date and easy to use; 
  • incident analysis resources are also important, because using them you have all information about infrastructure in one place.
   Detection and analysis is one of the most important part of the plan. First of all, you should determine attack vectors, indicators and profile activity in your infrastructure. When you understand normal behaviour and create correlation and log retention policies you will be able to prioritize incidents. It is better to make such decision with colleagues and top-manager, such as CISO. Generally, you can try to divide incidents by functional or informational impact and recoverability, but every company can find their own criteria about how to prioritize incidents.
   Containment and eradication also as a recovery can be much different because of your organization internal policies. Containment depends on many factors as impact on SLA, potential damage and so on. Eradiction should be carefully done, because of possible information lost. Effectiveness on this step is fully depends on how good detection analysis was performed. Almost all recovery procedures are held by IT staff. It is their part.
   Post-Incident Activities include lesson learned meetings after incident. On this meetings your CIR team should update CIR policies and procedures, create chronology and monetary estimate of the amount of damage. Based on this lessons you can justify fundings, help your IA department to find incident trends and systemic security weaknesses. Also measures of success can be renewed. It is always important to understand when incident is localized and eliminated.
   In this chapter you can find CIR handling checklist. It is very brief, but also helpful to start from. The last part is devoted to coordination and information sharing. It is also a good start to from your list whom to call and what to say. Special attention in this standard is paid to granular information sharing because of business impact. It is better to speak with law and PR departments before presenting information to some unauthorized people.
   In conclusion, I would like to say that this standard is not a full guide about CIR. It is only a brief review. Almost every topic should be expanded with different technical and administrative measures. But if you don't know where to start or even you know — it is a good review to check your key positions. Great job, NIST!

February 2, 2015

Review on Software Security Course by Maryland University on coursera.org

   This course was my second course in Cybersecurity specialization. Syllabus you can find here. In brief this course gave me a lot of fun. From my point of view there was a good start, but at the end it became a little bit boring, brief and easy.
    There were 6 weeks, 6 quizzes and 3 labs. First lecture was about low-level memory-based attacks. Stack smashing and format string attacks were well described, there were clear examples, so if you are not familiar with this attacks you can find here useful information. I can't but mention references at the end of the week. There were a lot of links, which provided detailed and deep description of these attacks. Well done, professor! As for me, ROP description was not clearly explained and there were not enough examples to understand it without addtional reading.
   Week 2 was devoted to defense mechanisms against memory attacks. Key technics, such as stack canaries, DEP, ASLR, memory-safety enforcement, control-flow integrity (CFI) were described in details. During these 2 weeks students had time to finish lab 1. It was a vulnerable software with source in VirtualBox image. Professor also provided this lab with step-by-step instructions. It was great pleasure to find flaws, to write exploits and using gdb. I appreciate such tasks because in educational programms there is lack of practice, especially in practical information security.
    Nowadays everything migrates to web. Professor devoted week 3 and lab 2 to web flaws. In brief there were descriptions and examples of SQLi, XSS, CSRF and Session hijacking. Some defensive mechanisms were presented too. In order to create lab BadStore distib was chosen. It is damn vulnerable web app with lots of flaws. Unfortunately, tasks in lab was very easy. As for me it will be more useful and tough to use XSS or SQLi to get access, than find out some cookies info.
   Secure design in week 4 was pretty easy to understand. It was great, that principles of designing was introduced in course. In this week you can find basic definitions? Such as authentication, authorization and etc. Also there were criteria of a good model, key principles of secure design. They are obvious, but very hard to follow.
   Week 5 was a nightmare. I suffered and struggled with static code analysis. From my point of view this technology is efficient, but also it needs much more experience in software development than an average student has. As for me, quizz after the lecture was incredibly difficult, some ways of static analysis procedure was not fully described in lectures, but they were in quizz. Additional reading was Brian Chess and his book - «Secure Programming with Static Analysis». Great book, but without enough coding experience and time for understanding for me it was rocket science. Symbolic execution theme was fair, good examples and clear description of principles gave me an opportunity to solve quizz questions.
    Lab 3 was connected with fuzzing. In brief we fuzzed app from Lab 1. It was very easy and I didn't spend much time on thinking about it.
   Week 6 was greatly titled «Penetration testing». But I was confused, because Professor in brief told us several well-known tricks and software without going deeper. Some words was about fuzzing, but not enough to understand underlying algorythms.
   Course was pretty good at the beginning. 3 weeks was great, 2 good labs. I thought it would be better and better. But at the end themes became a little bit boring and unclear. May be they were in a hurry. If this course would be expanded with heap overflow and ROP examples, more information about XSS and CSRF, more practice and entire week or two about pentest it would be great and unbelievable. I think professor can do it!

January 11, 2015

Thoughts about electronic authentication after NIST 800-63-1 review

   This guideline is devoted to the problem of electronic authentication in federal IT system. For my current job this recommendations are not obligatory, but I found some tricky details in this standard. I also use it to structure information connected with this vital infosec problem.
   The standard consists of 6 major sections. The first one is called "E-Authentication Model", where you can find detailed description of  authentication process and architectural model. This scheme is used almost in all authentication protocols such as Kerberos, 802.1x and etc. Additionally you can find some words about who participate in authentication process, what types of tokens and credentials are widely used. Below all these topics will be described and explained.
   The next sections is about registration and issuance processes. After short introduction there are threats and mitigation strategies. As for me I find these two parts of every section valuable, because I can use it in security policy or as a part of threat modeling.Every section finishes with tables about assurance level and what should be done to fulfill the requirements.
   Section about tokens is a good place to find out some unusual authentication schemes with single and multi-factor tokens. Threats, mitigation strategies and tables with assurance level are at the end of the section.
   In token and credential management section I find good enumeration of CSP responsibilities. This list is written in general words, but you can implement these responsibilities in every system where token and credential management are presented. Can you guess what information you can find at the end of the section? Right, threats, mitigation activities and tables...
   Section about authentication process mainly focuses on defense against man-in-the-middle attacks. Almost all mitigation activities are based on using TLS and strong cryptography.
   Nowadays SSO is very popular because of convenience and security (of course, it should be properly developed and implemented). Without assertion process this technology will be useless. Assertion section in standard is well written, 2 models are described (direct and indirect), also there are examples of assertion types. You know what you can find at the end of the section...
   In conclusion, from my point of view, this guideline has lack of technical information and may be authors next time will try to give more practical recommendations about mitigation strategies. But nevertheless this standard is a good sources to systematize your knowledge.

January 5, 2015

Review on Usable Security Course by Maryland University on coursera.org

   During one of the autumn evenings I found an email from Coursera about  Specialization program. For me I found interesting specialization in Cybersecurity. If I'm not mistaken in Maryland University there is one of the biggest Security Operation Centers in US. The specialization contains 4 courses: Usable Security, Software Security, Cryptography, Hardware Security. All courses have their own dates to start, so you can enter a course. If you want verified certificate or you'd like to finish Cybersecurity specialization you should follow signature track and pay 49$ for each course. 
   Signature Track is a way that you can confirm your identity. You should type some text, so they can verify you. Also they took your photo and asked to send your government id with photo. This scheme is implemented in such way: you complete quizz and then they took your typo and photo. Of course, this is not the way to clearly identify you, there are a lot of ways to overcome it. But as for me, the main reason is to get knowledge, not to achieve certificates.
   Let's come back to our courses. I started with Usable Secuity. When I first read the syllabus, I thought: "Oh, piece of cake... What is the reason to give such kind of material?" I worked in the field of security for almost 4 years, not so much, but enough to understand some key principles. You assess risks, find suitable security measures, implement them and also include this in your information security policy. Of course, your users are a part of this process, but you educate them and control what they are doing. But this course gave me some info to think about...
   Course included 5 key themes: design principles, measuring and evaluating usability, authentication, web browsing and privacy. The material was not technical, so you could not find any descriptions of secure authentication schemes and etc. During week 1 human computer interaction and ways of measuring usability was described in details. Week 2 was about design and ways how to perform it. Week 3 gave key concepts how to evaluate system design (controlled experiments, A\B testing and etc). Week 4 provided me with solid guidelines for usable security. Week 5 revealed usable authentication theme. I was surprised when professor started to check current browser https certificate validation on professor of biology, who was not so familiar with computer security at all. He was a little bit shocked when he saw warning. When she became to show him how to accept risk and got access to site... For him it was a rocket science... As for me, he is smart person, but he is not living in the field of computer security, so all these things and tricks are not convenient for him.
Week 6 was about usable privacy. Professor gave good list about how to make terms and agreements clear to users. Then final exam and course was finished.
I got certificate with verification link on it.
   For me this course was very useful. Now I tried to think and act like a user or ask user to do something, because the only way to develop a secure system by design is to develop it convenient and clear for users and administrators.

December 15, 2014

Another two annoying admin quests

   Today I will share problem decisions connected with Visio Viewer and WinDjvu.

   Let's start with Visio. I had to install Visio Viewer on client computers, and one of them while opening visio schemes showed blank IE tab with red cross. After googling I found that register key (HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{279D6C9A-652E-4833-BEFC-312CA8887857}) removal gave sufficient result.

   Another problem happened while right-click on file took place. First of all I thought that AV check took a long time, but after using procmon I understood that there was no check after first time. Some time I spent on russian forums and found out a good piece of advice. If you know russian you can check this.
In brief I made several steps to achieve my goal:
1. I found register key HKEY_CLASSES_ROOT\ Applications.
2. I opened each key with "name_programm.dll" and "name_programm.exe".
3. If nothing was encapsulated in these keys I searched for empty string parameter "NoOpenWith". If parameter was absent, I created it manually.
4.  If something was encapsulated, I went down till "command" subkey was found. I checked the path which was written in default key.
5. I found that WinDjvu tried to find something on server, which was replaced a year ago. I deleted this key from the beginning "WinDjvu.exe".
6. Happy users - calm admin!

December 9, 2014

Ntfrs failure

   Three days ago I found a warning in Ntfrs log of domain controller based on Windows Server 2008 R2 SP1. I had two domain controllers - one virtual and one physical. Event ID was 13508 and its' description was:
"The File Replication Service is having trouble enabling replication from <server 1 name> to <server 2 name> for c:\winnt\sysvol\domain; retrying".
   I found several decisions here. Editing register from the most popular advice gave no result, because BurFlags Value Name after restarting became 0 again. I read this on Microsoft web site in knowledge base. So I created on DC with PDC in c:\sysvol\domain folder a file NTFRS_CMD_FILE_MOVE_ROOT without extension. Then restarted ntfrs. After that I restarted ntfrs on another DC.
   Everything became fine in frs replication, but on PDC I found NETLOGON error 5706 with description: "The Netlogon service could not create server share. The following error occurred: The filename, directory name, or volume label syntax is incorrect". I went to eventid and found a link to MS knowledge base. I stopped netlogon service and added 2 register keys, one was already created (SysVol), after creation another (DBFlag) I started netlogon and error went away.

October 26, 2014

Microsoft Word "problematic feature".

   Today I'm going to tell some words about interesting bug, which I found in MS Word. After googling I found a post in social technet which described my situation and explanation that this was a feature not a bug since Office 2003.

   Situation is quite simple, I tried to open a document which was created using a template from a folder on server. Opening took about 30 seconds. So it was not good. I found out that if I switched off a network connection, this document had opened immediately.

   Well, I started a search and found a path to template in a folder on old server. I marked this field by red oval.



   I changed it on a current template in actual folder on new server and got rid of this problem for this particular file. Luckly, this problem was on one computer and unfortunately there were a lot of files to change.

   I decided to follow MS advice and created a full path on this computer with every folder as it was on old server. But the problem with server name left unresolved. First, I decided to create an entry in hosts file but it didn't work. Then I understood that I need to create a CNAME in DNS with association between old server name and name of this machine. Finally, the problem has gone!

June 27, 2014

NIST 800-188

   Today I'm going to say some words about NIST 800-188 "Guide to enterprise password management". Before this I read about Firewall and secure virtualization.  Well, I found these standards quite useful, because of their ability to systematize information connected with specific information security theme. Unfortunately, in these standards I didn't find any new information. Maybe, the reason is  that a lot of corporate security instruments use in their methodology NIST basics.
   Let's come back to NIST about password management. Shortly, this standard consists of intro, chapter about threats against passwords and password management. As always in intro you can find all necessary definitions and brief description of further chapters.
   Threats centered around capturing, transmission and cracking. Speaking about capturing I would like to mention interesting thing about caching passwords in swap and while hibernation. I don't hear about special utilities which can clean memory swap and hibernation file. Also there were a lot of researches connected with recovering passwords from such places (eForensics magazine, for example). 
   Transmission attacks are divided in two groups: sniffing and replay attacks. From my point of view, nowadays only one authentication protocol can be widely used in corporate networks "ou-of-box" - Kerberos. It has a lot of advantages, such as ticket granting system, strong crypto protocols. Authors of NIST also give their preferencesto this authentication protocol, because you can use it in your Windows environment, also with Heimdal Kerberos. Thank you, MIT))
   Cracking part is devoted to different well-known techniques, such as brute force, dictionary attack and rainbow tables. Nowadays, from my point of view, password cracking fully depends on computing power. Good salted passwords can make this type of attack ineffective. 
   As far as passwords are mentioned, we can find in NIST information about, what a good password is. From my point of view, you should find happy medium between strength and employee's ability to remember such passwords. The main rule is that length is much more vital than complexity. That's why password phrases are quite useful.
   Management recommendations give a piece of advice about using SSO (Single Sign On) where it is possible. Using of master passwords also has disadvantages, but it is transparent to user and easy to remember.
   In conclusion, I can advice to read this standard only to check your corporate password policy or if you are new to password protection theme.