Latest Security News

How To Find the right GPO

כלי WEB מועיל לחיפוש הגדרות  Group Policy  - מחולק לפי נושאים ומכיל הסברים רחבים.-http://gps.cloudapp.net/
ניתן לפלטר לפי מערכות הפעלה או מוצרים נלוים ( OFFICE ETC)

גזור ושמור...

links to malware sites for testing your geers

אתר מעולה המציג אוסף לינקים לאתרים נגועים בכל רושעה שנחפוץ - מעולה לבדיקת תוכנות AV PROXY IPS וכל שימוש נוסף  שאפשר לחשוב עליו .
האתר מעודכן ע"י הקהילה ואינו מסחרי
לשימושכם.
http://www.malwaredomainlist.com/mdl.php

מודול metasploit בדיקת סיסמאות בדומיין (smb)


לצורך בדיקת סיסמאות בדומיין (כניסה לתחנות- SMB) ,אני משתמש במודול   של :metasploit

הפעלה:

$ msfconsole



msf > use auxiliary/scanner/smb/smb_login
msf auxiliary(smb_login) > set RHOSTS [TARGET HOST RANGE]
msf auxiliary(smb_login); run

Module Options

BLANK_PASSWORDSTry blank passwords for all users (default: true)
BRUTEFORCE_SPEEDHow fast to bruteforce, from 0 to 5 (default: 5)
PASS_FILEFile containing passwords, one per line
PRESERVE_DOMAINSRespect a username that contains a domain name. (default: true)
RHOSTSThe target address range or CIDR identifier
RPORTSet the SMB service port (default: 445)
SMBDomainSMB Domain (default: WORKGROUP)
SMBPassSMB Password
SMBUserSMB Username
STOP_ON_SUCCESSStop guessing when a credential works for a host
THREADSThe number of concurrent threads (default: 1)
USERPASS_FILEFile containing users and passwords separated by space, one pair per line
USER_AS_PASSTry the username as the password for all users (default: true)
USER_FILEFile containing usernames, one per line
VERBOSEWhether to print output for all attempts (default: true)
CHOSTThe local client address
CPORTThe local client port
ConnectTimeoutMaximum number of seconds to establish a TCP connection
DCERPC::ReadTimeoutThe number of seconds to wait for DCERPC responses
MaxGuessesPerServiceMaximum number of credentials to try per service instance. If set to zero or a non-number, this option will not be used.
MaxGuessesPerUserMaximum guesses for a particular username for the service instance. Note that users are considered unique among different services, so a user at 10.1.1.1:22 is different from one at 10.2.2.2:22, and both will be tried up to the MaxGuessesPerUser limit. If set to zero or a non-number, this option will not be used.
MaxMinutesPerServiceMaximum time in minutes to bruteforce the service instance. If set to zero or a non-number, this option will not be used.
NTLM::SendLMAlways send the LANMAN response (except when NTLMv2_session is specified)
NTLM::SendNTLMActivate the 'Negotiate NTLM key' flag, indicating the use of NTLM responses
NTLM::SendSPNSend an avp of type SPN in the ntlmv2 client Blob, this allow authentification on windows Seven/2008r2 when SPN is required
NTLM::UseLMKeyActivate the 'Negotiate Lan Manager Key' flag, using the LM key when the LM response is sent
NTLM::UseNTLM2_sessionActivate the 'Negotiate NTLM2 key' flag, forcing the use of a NTLMv2_session
NTLM::UseNTLMv2Use NTLMv2 instead of NTLM2_session when 'Negotiate NTLM2' key is true
ProxiesUse a proxy chain
REMOVE_PASS_FILEAutomatically delete the PASS_FILE on module completion
REMOVE_USERPASS_FILEAutomatically delete the USERPASS_FILE on module completion
REMOVE_USER_FILEAutomatically delete the USER_FILE on module completion
SMB::ChunkSizeThe chunk size for SMB segments, bigger values will increase speed but break NT 4.0 and SMB signing
SMB::Native_LMThe Native LM to send during authentication
SMB::Native_OSThe Native OS to send during authentication
SMB::VerifySignatureEnforces client-side verification of server response signatures
SMBDirectThe target port is a raw SMB service (not NetBIOS)
SMBNameThe NetBIOS hostname (required for port 139 connections)
SSLNegotiate SSL for outgoing connections
SSLVersionSpecify the version of SSL that should be used (accepted: SSL2, SSL3, TLS1)
ShowProgressDisplay progress messages during a scan
ShowProgressPercentThe interval in percent that progress should be shown
WORKSPACESpecify the workspace for this module
DCERPC::fake_bind_multiUse multi-context bind calls
DCERPC::fake_bind_multi_appendSet the number of UUIDs to append the target
DCERPC::fake_bind_multi_prependSet the number of UUIDs to prepend before the target
DCERPC::max_frag_sizeSet the DCERPC packet fragmentation size
DCERPC::smb_pipeioUse a different delivery method for accessing named pipes (accepted: rw, trans)
SMB::obscure_trans_pipe_levelObscure PIPE string in TransNamedPipe (level 0-3)
SMB::pad_data_levelPlace extra padding between headers and data (level 0-3)
SMB::pad_file_levelObscure path names used in open/create (level 0-3)
SMB::pipe_evasionEnable segmented read/writes for SMB Pipes
SMB::pipe_read_max_sizeMaximum buffer size for pipe reads
SMB::pipe_read_min_sizeMinimum buffer size for pipe reads
SMB::pipe_write_max_sizeMaximum buffer size for pipe writes
SMB::pipe_write_min_sizeMinimum buffer size for pipe writes
TCP::max_send_sizeMaxiumum tcp segment size. (0 = disable)
TCP::send_delayDelays inserted before every send. (0 = disable)


GEO IP - שימוש ב PERL לזיהוי מקורות שמות אתרים וכתובות IP



לא אחת אני נזקק לזיהוי מקור עולמי של כתובות IP המתקיפות את הארגון או זיהוי מידע הנשלח מהארגון .
נכון להיום אין לי כלי מסחרי היודע לנתח את נתוני ה FW ,PROXY וכו ולהראות מיפוי עולמי של גישות אלו.

קיימות מספר חבילות PERL שדרכם ניתן לפרסר כתובות IP ושמות DOMAIN ולזהות את ארץ המקור
אני אתמקד בחבילה: Geo::IPfree
את החבילה ניתן להוריד בקלות דרך ה PACKEGE MANAGER של ה ACTIVE PERL ,החבילה כוללת מספר יכולות אשר ניתן ללמוד עליהם כאן:
http://search.cpan.org/~bricas/Geo-IPfree-1.101650/lib/Geo/IPfree.pm
בנוסף החבילה מגיעה עם קובץ DAT המהווה למעשה את ה DB המקומי של הרשתות בעולם .
את הקובץ רצוי לשדרגאחת לשבוע עד חודש  כאן:
http://software77.net/geo-ip/?DL=4&x=Download
יש למקם אותו בספרית ה PERL במקום הקובץ המקורי המגיע עם החבילה:












 סקריפט לדוגמא הקורא מקובץ CSV את העמודה הראשונה - בודק אותה מול ה GEOIP ומחזיר קובץ CSV חדש בתוספת העמודה הגאוגרפית:

ניתן לשנות ולשהתמש בחלקים בהערה במקום הקיים

להורדת הסקריפט:
https://docs.google.com/leaf?id=0B2RudizokeYDMzhjMjQ4NTQtM2RlMi00YzBlLTkwMGUtNGVmYWY4NWE1YThh&sort=name&layout=list&num=50



















Stuxnet - וירוס חדש +ZERO DAY חדש



רימה חדשה נחתה ביולי 2010 .בכינויים:stuxnetStuxnet (McAfee) , RTKT_STUXNET.A (Trend Micro) , Win32/Stuxnet.A (CA)  .
שני דברים מעניינים בתולעת הזאת ושעבורם הגוף שהזמין את התולעת שילם ה ר ב ה  כסף  להאקר:
  1. התולעת מתקינה שני דרייברים (עבור הROOTKIT) הנראים חתומים בחיתום חוקי של חברת  Realtek ,מעניין איך זה קרה...
  2. שימוש ב ZERODAY חדש הפועל על כל סוגי מערכות ההפעלה חלונות :CVE-2010-2568 המנצל פגיעות בקיצור דרך ,קבצי .LNK.
התולעת מתרבה דרך התקני USB ושיתופים ברשת וזאת ללא שימוש במנגנון ה AUTORUN הידוע לשימצה ונחסם ברוב הארגונים.

לבדיקת ה ZERODAY מול מערכות ההגנה הארגוניות :

מידע נוסף:





התקפה טורקית על אתרים ישראליים באמצעות DNS cache poisoning


ביום חמישי ה 10.6.2010 התבצעה התקפת DNS cache poisoning על מספר אתרים ישראליים ע"י קבוצת ההאקרים הטורקית TurkGuvenligi Tayfa  .החברות מיהרו לעדכן ולתקן את הרשומות ב DNS אך עבור משתמשים רבים מאחורי אמצעי CACHEING ארגוניים ( ISA ודומיו)  התופעה נמשכה לאורך כל אותו היום.
הדף שהופנו אליו המשתמשים ממוקם בשיקגו.
FYI





windows update ISO DVD


מיקרוסופט מאפשרת הורדה של דיסקים(ISO) המכילים את עדכוני האבטחה החודשיים .
זאת אופציה טובה עבור איזורים מאובטחים ומנותקים ברשת המצריכים גישה פיזית בלבד להרצת עדכונים וכן עבור ארגונים המיישמים מספר שפות בסניפים ברחבי העולם ולא משתמש באפליקציות כגון WSUS
הדיסקים מכילים את כל השפות וכל מערכות ההפעלה כולל בx64
לקריאה נוספת:

http://support.microsoft.com/kb/913086