<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Kirk Jackson's Page of Words</title>
    <link>http://pageofwords.com/blog/</link>
    <description>Run the ink across this page of words</description>
    <language>en-us</language>
    <copyright>Kirk Jackson</copyright>
    <lastBuildDate>Thu, 14 Jul 2011 01:52:31 GMT</lastBuildDate>
    <generator>newtelligence dasBlog 1.9.6264.0</generator>
    <managingEditor>kirkj@paradise.net.nz</managingEditor>
    <webMaster>kirkj@paradise.net.nz</webMaster>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/pageofwords" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="pageofwords" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Today I'm presenting at the awesome <a href="http://www.wdcnz.com">WDCNZ</a> conference,
organised by <a href="http://bgeek.net">Owen</a> and the fine folks at <a href="http://www.xero.com">Xero</a>.
</p>
        <p>
The talk discusses some of the new browser features that will help to protect you
from XSS, man-in-the-middle and other attacks. 
</p>
        <p>
Please download, and send through any feedback or questions: <a href="http://pageofwords.com/blog/content/binary/KirkJackson-WDCNZ-GetAHeader-online.pdf">KirkJackson-WDCNZ-GetAHeader-online.pdf
(1.35 MB)</a></p>
        <img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce" />
      <xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/DwLLtsWcUwk" height="1" width="1" /></body>
      <title>WDCNZ Conference - Web Security: Get a Head(er)</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce.aspx</guid>
      <link>http://pageofwords.com/blog/2011/07/14/WDCNZConferenceWebSecurityGetAHeader.aspx</link>
      <pubDate>Thu, 14 Jul 2011 01:52:31 GMT</pubDate>
      <description>&lt;p&gt;
Today I'm presenting at the awesome &lt;a href="http://www.wdcnz.com"&gt;WDCNZ&lt;/a&gt; conference,
organised by &lt;a href="http://bgeek.net"&gt;Owen&lt;/a&gt; and the fine folks at &lt;a href="http://www.xero.com"&gt;Xero&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The talk discusses some of the new browser features that will help to protect you
from XSS, man-in-the-middle and other attacks. 
&lt;/p&gt;
&lt;p&gt;
Please download, and send through any feedback or questions: &lt;a href="http://pageofwords.com/blog/content/binary/KirkJackson-WDCNZ-GetAHeader-online.pdf"&gt;KirkJackson-WDCNZ-GetAHeader-online.pdf
(1.35 MB)&lt;/a&gt; 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,51bfff43-2cd1-49c9-a63a-5a6a95c8b7ce.aspx</comments>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=4c768f4f-f09b-4037-b8e7-38f05758f2b6</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,4c768f4f-f09b-4037-b8e7-38f05758f2b6.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,4c768f4f-f09b-4037-b8e7-38f05758f2b6.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=4c768f4f-f09b-4037-b8e7-38f05758f2b6</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">Andy and I presented at the first <a href="http://www.nzalm.co.nz">NZ
ALM conference</a> today -- a conference covering all aspects of the application lifecycle,
and use of the Visual Studio ALM suite of tools.<br /><br />
Our talk covered the Security Development Lifecycle, and gave some 'motivating examples'
of different recent hacks, exploits, or just plain quirks that demonstrated how thinking
about security at each stage of the lifecycle can help protect the security and privacy
of your users, businesses and their data.<br /><br />
Here's the presentation, including links to useful web references:<br /><br /><a href="http://pageofwords.com/blog/content/binary/2011-04-06-NZALM-KirkJackson-AndyProw.pdf">2011-04-06-NZALM-KirkJackson-AndyProw.pdf</a> (4.4mb)<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=4c768f4f-f09b-4037-b8e7-38f05758f2b6" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/6H8NfFqMug4" height="1" width="1" /></body>
      <title>New Zealand ALM Conference - Thinking Securely from life to cycle</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,4c768f4f-f09b-4037-b8e7-38f05758f2b6.aspx</guid>
      <link>http://pageofwords.com/blog/2011/04/06/NewZealandALMConferenceThinkingSecurelyFromLifeToCycle.aspx</link>
      <pubDate>Wed, 06 Apr 2011 10:40:13 GMT</pubDate>
      <description>Andy and I presented at the first &lt;a href="http://www.nzalm.co.nz"&gt;NZ ALM conference&lt;/a&gt; today
-- a conference covering all aspects of the application lifecycle, and use of the
Visual Studio ALM suite of tools.&lt;br&gt;
&lt;br&gt;
Our talk covered the Security Development Lifecycle, and gave some 'motivating examples'
of different recent hacks, exploits, or just plain quirks that demonstrated how thinking
about security at each stage of the lifecycle can help protect the security and privacy
of your users, businesses and their data.&lt;br&gt;
&lt;br&gt;
Here's the presentation, including links to useful web references:&lt;br&gt;
&lt;br&gt;
&lt;a href="http://pageofwords.com/blog/content/binary/2011-04-06-NZALM-KirkJackson-AndyProw.pdf"&gt;2011-04-06-NZALM-KirkJackson-AndyProw.pdf&lt;/a&gt; (4.4mb)&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=4c768f4f-f09b-4037-b8e7-38f05758f2b6" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,4c768f4f-f09b-4037-b8e7-38f05758f2b6.aspx</comments>
      <category>Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=71a380b8-fcef-4f01-afa5-5ea542948c18</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=71a380b8-fcef-4f01-afa5-5ea542948c18</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">I presented at the <a href="http://www.sharepointconference.co.nz/nz2011/">NZ
SharePoint conference</a> yesterday. It was a pretty impressive event - kudos to Debbie
and the organising team.<br /><br />
My talk was split into two parts: what are some of the risks in running a SharePoint
site; and how can you protect against them.<br /><br />
The risks I covered were cross-site scripting and malicious file uploads - MIME sniffing
in IE, the recent MHTML attack and the ever-present risk of malicious PDF documents.
The key takeaway is that any file uploaded could be malicious, and to think of how
to mitigate those risks.<br /><br />
In the 'protection' section, I covered some SharePoint development best practices
and stepped through SharePoint specifics on how to protect against XSS and CSRF. SharePoint
has some pretty good protections built in the box, but if we're building our own web-parts
we need to be vigilant.<br /><br />
The presentation should shortly be available from the conference website, with a video
in a month or so. If you've got any questions please feel free to email me or get
in touch.<br /><p /><a href="http://pageofwords.com/blog/content/binary/2011-03-17-NZSPC-KirkJackson.pdf">2011-03-17-NZSPC-KirkJackson.pdf
(2.9 MB)</a><br /><br />
Cheers,<br /><br />
Kirk<br /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=71a380b8-fcef-4f01-afa5-5ea542948c18" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/4-aKcoQl4cs" height="1" width="1" /></body>
      <title>SharePoint Conference NZ - Is your SharePoint under threat?</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</guid>
      <link>http://pageofwords.com/blog/2011/03/17/SharePointConferenceNZIsYourSharePointUnderThreat.aspx</link>
      <pubDate>Thu, 17 Mar 2011 22:42:33 GMT</pubDate>
      <description>I presented at the &lt;a href="http://www.sharepointconference.co.nz/nz2011/"&gt;NZ SharePoint
conference&lt;/a&gt; yesterday. It was a pretty impressive event - kudos to Debbie and the
organising team.&lt;br&gt;
&lt;br&gt;
My talk was split into two parts: what are some of the risks in running a SharePoint
site; and how can you protect against them.&lt;br&gt;
&lt;br&gt;
The risks I covered were cross-site scripting and malicious file uploads - MIME sniffing
in IE, the recent MHTML attack and the ever-present risk of malicious PDF documents.
The key takeaway is that any file uploaded could be malicious, and to think of how
to mitigate those risks.&lt;br&gt;
&lt;br&gt;
In the 'protection' section, I covered some SharePoint development best practices
and stepped through SharePoint specifics on how to protect against XSS and CSRF. SharePoint
has some pretty good protections built in the box, but if we're building our own web-parts
we need to be vigilant.&lt;br&gt;
&lt;br&gt;
The presentation should shortly be available from the conference website, with a video
in a month or so. If you've got any questions please feel free to email me or get
in touch.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;a href="http://pageofwords.com/blog/content/binary/2011-03-17-NZSPC-KirkJackson.pdf"&gt;2011-03-17-NZSPC-KirkJackson.pdf
(2.9 MB)&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
&lt;br&gt;
Kirk&lt;br&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=71a380b8-fcef-4f01-afa5-5ea542948c18" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,71a380b8-fcef-4f01-afa5-5ea542948c18.aspx</comments>
      <category>Security;SharePoint</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=b0f679e5-80bd-4186-a11e-7f32648766ff</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,b0f679e5-80bd-4186-a11e-7f32648766ff.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,b0f679e5-80bd-4186-a11e-7f32648766ff.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=b0f679e5-80bd-4186-a11e-7f32648766ff</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">This month I gave a similar talk to two
user groups. The <a href="http://www.owasp.org/index.php/New_Zealand">OWASP Wellington</a> (and
Auckland over video conference), and the <a href="http://www.dot.net.nz/UserGroupPages/WellingtonNET.aspx">Wellington
.NET user group</a> both invited me to speak on: "I know what you did last summer;
The latest from the world of web hacks".<br /><br />
This was a fun talk to deliver. The focus was on recent web 'hacks' that had occurred
in the past few months (I used a pretty general definition of 'hack'), but the main
discussion was around the lessons that we could learn from these issues and what we
could draw back into our own projects.<br /><br />
I think this talk had the most amount of interaction out of any of my previous talks.
There was lively discussion about what the root cause of the problem was, whether
it was even fixable at all, and we lamented the effects of 'users' :)<br /><br />
Since the .NET talk was a superset of the OWASP one (it was longer), I've included
those slides below:<br /><p /><a href="http://pageofwords.com/blog/content/binary/2011-03-09-WellingtonNet.pdf">2011-03-09-WellingtonNet.pdf
(2.07 MB)</a><br /><br />
Thanks for coming!<br /><br />
Kirk<br /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=b0f679e5-80bd-4186-a11e-7f32648766ff" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/o5XTW6angHs" height="1" width="1" /></body>
      <title>Recent talks - I know what you did last summer</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,b0f679e5-80bd-4186-a11e-7f32648766ff.aspx</guid>
      <link>http://pageofwords.com/blog/2011/03/09/RecentTalksIKnowWhatYouDidLastSummer.aspx</link>
      <pubDate>Wed, 09 Mar 2011 08:17:00 GMT</pubDate>
      <description>This month I gave a similar talk to two user groups. The &lt;a href="http://www.owasp.org/index.php/New_Zealand"&gt;OWASP
Wellington&lt;/a&gt; (and Auckland over video conference), and the &lt;a href="http://www.dot.net.nz/UserGroupPages/WellingtonNET.aspx"&gt;Wellington
.NET user group&lt;/a&gt; both invited me to speak on: "I know what you did last summer;
The latest from the world of web hacks".&lt;br&gt;
&lt;br&gt;
This was a fun talk to deliver. The focus was on recent web 'hacks' that had occurred
in the past few months (I used a pretty general definition of 'hack'), but the main
discussion was around the lessons that we could learn from these issues and what we
could draw back into our own projects.&lt;br&gt;
&lt;br&gt;
I think this talk had the most amount of interaction out of any of my previous talks.
There was lively discussion about what the root cause of the problem was, whether
it was even fixable at all, and we lamented the effects of 'users' :)&lt;br&gt;
&lt;br&gt;
Since the .NET talk was a superset of the OWASP one (it was longer), I've included
those slides below:&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;a href="http://pageofwords.com/blog/content/binary/2011-03-09-WellingtonNet.pdf"&gt;2011-03-09-WellingtonNet.pdf
(2.07 MB)&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
Thanks for coming!&lt;br&gt;
&lt;br&gt;
Kirk&lt;br&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=b0f679e5-80bd-4186-a11e-7f32648766ff" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,b0f679e5-80bd-4186-a11e-7f32648766ff.aspx</comments>
      <category>.NET;OWASP;Security;UserGroup;Web</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=81025a86-8442-4a79-97f7-b25ddef3c72e</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,81025a86-8442-4a79-97f7-b25ddef3c72e.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,81025a86-8442-4a79-97f7-b25ddef3c72e.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=81025a86-8442-4a79-97f7-b25ddef3c72e</wfw:commentRss>
      <slash:comments>1</slash:comments>
      <body xmlns="http://www.w3.org/1999/xhtml">Last month I started in a new role at <a href="http://www.aurasoftwaresecurity.co.nz">Aura
Software Security</a>, where I am a security consultant. I'm excited about all the
fun stuff I'll be doing, getting involved with security advice, training and testing
at all stages of the development lifecycle.<br /><br />
However, starting a new job means leaving another, and I'm sad to leave <a href="http://www.xero.com">Xero</a>.
It has been a blast working at Xero, and I have made some great friends, had a lot
of laughs, and been a part of building something pretty special.<br /><br />
In terms of this blog, I predict that nothing much will change -- I will continue
to post infrequently, usually triggered by a promise to post some event slides or
other online. If you're subscribed, you've probably noticed that most of my posts
tend to be around web security, and I doubt that will change!<br /><br />
Kirk<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=81025a86-8442-4a79-97f7-b25ddef3c72e" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/ieHIb2s8bdI" height="1" width="1" /></body>
      <title>New job</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,81025a86-8442-4a79-97f7-b25ddef3c72e.aspx</guid>
      <link>http://pageofwords.com/blog/2011/03/09/NewJob.aspx</link>
      <pubDate>Wed, 09 Mar 2011 08:09:04 GMT</pubDate>
      <description>Last month I started in a new role at &lt;a href="http://www.aurasoftwaresecurity.co.nz"&gt;Aura
Software Security&lt;/a&gt;, where I am a security consultant. I'm excited about all the
fun stuff I'll be doing, getting involved with security advice, training and testing
at all stages of the development lifecycle.&lt;br&gt;
&lt;br&gt;
However, starting a new job means leaving another, and I'm sad to leave &lt;a href="http://www.xero.com"&gt;Xero&lt;/a&gt;.
It has been a blast working at Xero, and I have made some great friends, had a lot
of laughs, and been a part of building something pretty special.&lt;br&gt;
&lt;br&gt;
In terms of this blog, I predict that nothing much will change -- I will continue
to post infrequently, usually triggered by a promise to post some event slides or
other online. If you're subscribed, you've probably noticed that most of my posts
tend to be around web security, and I doubt that will change!&lt;br&gt;
&lt;br&gt;
Kirk&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=81025a86-8442-4a79-97f7-b25ddef3c72e" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,81025a86-8442-4a79-97f7-b25ddef3c72e.aspx</comments>
      <category>Xero;Aura</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=47180a1e-aa67-416a-9e0e-ab0b0584c010</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,47180a1e-aa67-416a-9e0e-ab0b0584c010.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,47180a1e-aa67-416a-9e0e-ab0b0584c010.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=47180a1e-aa67-416a-9e0e-ab0b0584c010</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Thanks to those user group members and Xero partners that came along to our talk today.
</p>
        <p>
We covered the two vulnerabilities released last week, the workarounds, and the patches
that were released this morning.
</p>
        <p>
Here are the slides: <a href="http://pageofwords.com/blog/content/binary/KirkJackson-PaddingOracle.pdf">KirkJackson-PaddingOracle.pdf
(641.14 KB)</a></p>
        <p>
All ASP.NET applications are affected. The best thing to do is <a href="http://blogs.technet.com/b/msrc/archive/2010/09/28/ms10-070-released-out-of-band-today.aspx">install
the patches released this morning</a>. 
</p>
        <p>
          <b>
            <br />
          </b>
        </p>
        <p>
          <b>Problem &amp; bulletins:</b>
        </p>
        <p>
          <a href="http://www.microsoft.com/technet/security/bulletin/ms10-070.mspx">Security
bulletin MS10-070</a>
        </p>
        <p>
          <a href="http://weblogs.asp.net/scottgu/archive/tags/Security/default.aspx"> Useful
info on ScottGu's blog<br /></a>
        </p>
        <p>
          <a href="http://forums.asp.net/1233.aspx">Forum about the security vulnerability</a>
        </p>
        <p>
          <a href="http://www.youtube.com/watch?v=mP6mKLh1FBw">Video of a site exploit</a>,
even with the workarounds applied 
</p>
        <p>
          <b> Patch: </b>
        </p>
        <p>
          <a href="http://weblogs.asp.net/scottgu/archive/2010/09/28/asp-net-security-update-now-available.aspx">Scott
Gu's writeup of the patch</a>
        </p>
        <p>
          <a href="http://musingmarc.blogspot.com/2010/09/ms10-070-post-mortem-analysis-of-patch.html">Post-mortem
of the patch - Marc Brooks</a>
        </p>
        <p>
How to <a href="http://support.microsoft.com/kb/2425938"> configure the new patched
features</a></p>
        <p>
          <b>Research:</b>
        </p>
        <p>
          <a href="http://twitter.com/julianor">Juliano Rizzo</a> and <a href="http://twitter.com/thaidn">Thai
Duong</a> and their <a href="http://netifera.com/research/">POET tool</a></p>
        <p>
          <a href="http://www.gdssecurity.com/l/b/2010/09/28/new-version-of-padbuster-available-for-download/"> Padbuster
tool</a> (including a <a href="http://www.gdssecurity.com/l/b/2010/09/14/automated-padding-oracle-attacks-with-padbuster/">great
writeup of Padding Oracles)</a></p>
        <img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=47180a1e-aa67-416a-9e0e-ab0b0584c010" />
      <xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/fxgW9xwAfFw" height="1" width="1" /></body>
      <title>ASP.NET Vulnerability - Slides</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,47180a1e-aa67-416a-9e0e-ab0b0584c010.aspx</guid>
      <link>http://pageofwords.com/blog/2010/09/29/ASPNETVulnerabilitySlides.aspx</link>
      <pubDate>Wed, 29 Sep 2010 08:25:39 GMT</pubDate>
      <description>&lt;p&gt;
Thanks to those user group members and Xero partners that came along to our talk today.
&lt;/p&gt;
&lt;p&gt;
We covered the two vulnerabilities released last week, the workarounds, and the patches
that were released this morning.
&lt;/p&gt;
&lt;p&gt;
Here are the slides: &lt;a href="http://pageofwords.com/blog/content/binary/KirkJackson-PaddingOracle.pdf"&gt;KirkJackson-PaddingOracle.pdf
(641.14 KB)&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
All ASP.NET applications are affected. The best thing to do is &lt;a href="http://blogs.technet.com/b/msrc/archive/2010/09/28/ms10-070-released-out-of-band-today.aspx"&gt;install
the patches released this morning&lt;/a&gt;. 
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt; 
&lt;br&gt;
&lt;/b&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt;Problem &amp;amp; bulletins:&lt;/b&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms10-070.mspx"&gt;Security
bulletin MS10-070&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://weblogs.asp.net/scottgu/archive/tags/Security/default.aspx"&gt; Useful
info on ScottGu's blog&lt;br&gt;
&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://forums.asp.net/1233.aspx"&gt;Forum about the security vulnerability&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.youtube.com/watch?v=mP6mKLh1FBw"&gt;Video of a site exploit&lt;/a&gt;,
even with the workarounds applied 
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt; Patch: &lt;/b&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://weblogs.asp.net/scottgu/archive/2010/09/28/asp-net-security-update-now-available.aspx"&gt;Scott
Gu's writeup of the patch&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://musingmarc.blogspot.com/2010/09/ms10-070-post-mortem-analysis-of-patch.html"&gt;Post-mortem
of the patch - Marc Brooks&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
How to &lt;a href="http://support.microsoft.com/kb/2425938"&gt; configure the new patched
features&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;b&gt;Research:&lt;/b&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://twitter.com/julianor"&gt;Juliano Rizzo&lt;/a&gt; and &lt;a href="http://twitter.com/thaidn"&gt;Thai
Duong&lt;/a&gt; and their &lt;a href="http://netifera.com/research/"&gt;POET tool&lt;/a&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;a href="http://www.gdssecurity.com/l/b/2010/09/28/new-version-of-padbuster-available-for-download/"&gt; Padbuster
tool&lt;/a&gt; (including a &lt;a href="http://www.gdssecurity.com/l/b/2010/09/14/automated-padding-oracle-attacks-with-padbuster/"&gt;great
writeup of Padding Oracles)&lt;/a&gt; 
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=47180a1e-aa67-416a-9e0e-ab0b0584c010" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,47180a1e-aa67-416a-9e0e-ab0b0584c010.aspx</comments>
      <category>.NET;Security;Xero</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=54b58629-7704-4ddb-b39a-8e12e283631e</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,54b58629-7704-4ddb-b39a-8e12e283631e.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,54b58629-7704-4ddb-b39a-8e12e283631e.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=54b58629-7704-4ddb-b39a-8e12e283631e</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">If you're in Wellington this Wednesday
and you develop, maintain, manage or host ASP.NET or SharePoint websites, please do
come along to hear about the security vulnerability disclosed a week ago:<br /><br /><a href="http://www.dot.net.nz/Lists/Events%20Calendar/DispForm.aspx?ID=321">http://www.dot.net.nz/Lists/Events%20Calendar/DispForm.aspx?ID=321</a><br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=54b58629-7704-4ddb-b39a-8e12e283631e" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/pEMhrTxa5iY" height="1" width="1" /></body>
      <title>ASP.NET vulnerability - briefing in Wellington this Wednesday</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,54b58629-7704-4ddb-b39a-8e12e283631e.aspx</guid>
      <link>http://pageofwords.com/blog/2010/09/27/ASPNETVulnerabilityBriefingInWellingtonThisWednesday.aspx</link>
      <pubDate>Mon, 27 Sep 2010 09:08:47 GMT</pubDate>
      <description>If you're in Wellington this Wednesday and you develop, maintain, manage or host ASP.NET or SharePoint websites, please do come along to hear about the security vulnerability disclosed a week ago:&lt;br&gt;
&lt;br&gt;
&lt;a href="http://www.dot.net.nz/Lists/Events%20Calendar/DispForm.aspx?ID=321"&gt;http://www.dot.net.nz/Lists/Events%20Calendar/DispForm.aspx?ID=321&lt;/a&gt;
&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=54b58629-7704-4ddb-b39a-8e12e283631e" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,54b58629-7704-4ddb-b39a-8e12e283631e.aspx</comments>
      <category>.NET;Security;UserGroup</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=611df22f-c847-4422-9ecb-131982b93a14</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,611df22f-c847-4422-9ecb-131982b93a14.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,611df22f-c847-4422-9ecb-131982b93a14.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=611df22f-c847-4422-9ecb-131982b93a14</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
Here's the presentation I delivered at the Auckland Code Camp 2010. It covers 10 things
that I found when surveying attendees websites :)
</p>
        <div class="prezi-player">
          <style type="text/css" media="screen">.prezi-player { width: 550px; } .prezi-player-links { text-align: center; }</style>
          <object id="prezi_g6qwyes_oik_" name="prezi_g6qwyes_oik_" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" height="400" width="550">
            <param name="movie" value="http://prezi.com/bin/preziloader.swf" />
            <param name="allowfullscreen" value="true" />
            <param name="allowscriptaccess" value="always" />
            <param name="bgcolor" value="#ffffff" />
            <param name="flashvars" value="prezi_id=g6qwyes_oik_&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0" />
            <embed id="preziEmbed_g6qwyes_oik_" name="preziEmbed_g6qwyes_oik_" src="http://prezi.com/bin/preziloader.swf" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" bgcolor="#ffffff" flashvars="prezi_id=g6qwyes_oik_&amp;lock_to_path=0&amp;color=ffffff&amp;autoplay=no&amp;autohide_ctrls=0" height="400" width="550">
            </embed>
          </object>
          <div class="prezi-player-links">
            <p>
              <a title="Presentation to the Code Camp 2010 in Auckland, New Zealand. &#xD;&#xA;&#xD;&#xA;Presented by Kirk Jackson" href="http://prezi.com/g6qwyes_oik_/10-things-you-are-doing-wrong/">10
things YOU are doing wrong!</a> on <a href="http://prezi.com">Prezi</a></p>
          </div>
        </div>
        <img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=611df22f-c847-4422-9ecb-131982b93a14" />
      <xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/Dz7RcxbjtB8" height="1" width="1" /></body>
      <title>10 things YOU are doing wrong!</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,611df22f-c847-4422-9ecb-131982b93a14.aspx</guid>
      <link>http://pageofwords.com/blog/2010/09/01/10ThingsYOUAreDoingWrong.aspx</link>
      <pubDate>Wed, 01 Sep 2010 04:18:01 GMT</pubDate>
      <description>&lt;p&gt;
Here's the presentation I delivered at the Auckland Code Camp 2010. It covers 10 things
that I found when surveying attendees websites :)
&lt;/p&gt;
&lt;div class="prezi-player"&gt;&lt;style type="text/css" media="screen"&gt;.prezi-player { width: 550px; } .prezi-player-links { text-align: center; }&lt;/style&gt;
&lt;object id="prezi_g6qwyes_oik_" name="prezi_g6qwyes_oik_" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" height="400" width="550"&gt;
&lt;param name="movie" value="http://prezi.com/bin/preziloader.swf"&gt;
&lt;param name="allowfullscreen" value="true"&gt;
&lt;param name="allowscriptaccess" value="always"&gt;
&lt;param name="bgcolor" value="#ffffff"&gt;
&lt;param name="flashvars" value="prezi_id=g6qwyes_oik_&amp;amp;lock_to_path=0&amp;amp;color=ffffff&amp;amp;autoplay=no&amp;amp;autohide_ctrls=0"&gt;&lt;embed id="preziEmbed_g6qwyes_oik_" name="preziEmbed_g6qwyes_oik_" src="http://prezi.com/bin/preziloader.swf" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" bgcolor="#ffffff" flashvars="prezi_id=g6qwyes_oik_&amp;amp;lock_to_path=0&amp;amp;color=ffffff&amp;amp;autoplay=no&amp;amp;autohide_ctrls=0" height="400" width="550"&gt;
&lt;/object&gt;
&lt;div class="prezi-player-links"&gt;
&lt;p&gt;
&lt;a title="Presentation to the Code Camp 2010 in Auckland, New Zealand. 

Presented by Kirk Jackson" href="http://prezi.com/g6qwyes_oik_/10-things-you-are-doing-wrong/"&gt;10
things YOU are doing wrong!&lt;/a&gt; on &lt;a href="http://prezi.com"&gt;Prezi&lt;/a&gt;
&lt;/p&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=611df22f-c847-4422-9ecb-131982b93a14" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,611df22f-c847-4422-9ecb-131982b93a14.aspx</comments>
      <category>CodeCamp;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <p>
If you're in Auckland this Sunday, come along and check out the latest Microsoft technologies
from MS Communities<img style="border-bottom: 0px; border-left: 0px; margin: 10px; border-top: 0px; border-right: 0px" title="msc-logo" border="0" alt="msc-logo" align="left" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-09-metablogapi/4762.msc_2D00_logo_5F00_3.png" width="358" height="88" />.
</p>
        <p>
 
</p>
        <p>
It's happening Sunday 29 August from 930am till 530PM at the University of Auckland
Business School. This is a free event so please <a href="http://mscommunities.net.nz/summit/">Register
and attend</a></p>
        <p>
 
</p>
        <p>
 
</p>
        <p>
The MS Communities website is at <a href="http://mscommunities.net.nz/summit/">http://mscommunities.net.nz/summit/</a> with
the days agenda
</p>
        <img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68" />
      <xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/DU73QRsdwxY" height="1" width="1" /></body>
      <title>MS Communities Code Camp/Summit This Sunday (29/AUG) in Auckland</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68.aspx</guid>
      <link>http://pageofwords.com/blog/2010/08/25/MSCommunitiesCodeCampSummitThisSunday29AUGInAuckland.aspx</link>
      <pubDate>Wed, 25 Aug 2010 13:07:55 GMT</pubDate>
      <description>&lt;p&gt;
If you're in Auckland this Sunday, come along and check out the latest Microsoft technologies
from MS Communities&lt;img style="border-bottom: 0px; border-left: 0px; margin: 10px; border-top: 0px; border-right: 0px" title="msc-logo" border="0" alt="msc-logo" align="left" src="http://blogs.technet.com/cfs-file.ashx/__key/CommunityServer-Blogs-Components-WeblogFiles/00-00-00-45-09-metablogapi/4762.msc_2D00_logo_5F00_3.png" width="358" height="88" /&gt;.
&lt;/p&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
It's happening Sunday 29 August from 930am till 530PM at the University of Auckland
Business School. This is a free event so please &lt;a href="http://mscommunities.net.nz/summit/"&gt;Register
and attend&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
&amp;#160;
&lt;/p&gt;
&lt;p&gt;
The MS Communities website is at &lt;a href="http://mscommunities.net.nz/summit/"&gt;http://mscommunities.net.nz/summit/&lt;/a&gt; with
the days agenda
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,ee2dad9f-5bb8-49cc-9fd2-b82af9a11c68.aspx</comments>
      <category>CodeCamp;UserGroup</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/images/dean.jpg" alt="dean.jpg" align="right" border="0" height="334" width="200" />Used
to be a QSA (Qualified Security Assessor). There are now 8 in NZ.<br /><br />
The QSA wears the risk and signs you off for PCI compliance.<br /><br />
There are no silver bullets for PCI stuff.<br /><br />
"It's a hell of a roller-coaster ride"<br /><br />
He has seen 2.5 million credit card numbers in NZ, in the clear, in many website databases.<br /><br />
One guy Albert Gonzalez compromised 170 million credit cards across many large corporations.<br /><br /><b>PCI requirements:</b><br /><br />
"Protect stored data": 79% of orgs fail on this.<br /><br />
PAN (account data) must be unreadable when stored.<br /><br />
You can never store mag stripe data.<br /><br />
"Track and monitor all access to network resources and cardholder data"<br /><br />
"Develop and maintain secure systems and applications" - 56% of organisations fail
on this<br /><br /><b>Rant:</b><br /><br />
1. Card holder data gets everywhere<br /><br />
2. Keep test and development environments out of scope. Don't use real live data in
them.<br /><br />
3. The good: payment gateways and companies that handle cards - they do a good job.
They outsource to experts.<br /><br />
The bad: small merchants with a few transactions. Cheap website with cheap hosting.
Easily compromised.<br /><br />
The ugly: corporates. Great staff but don't make any progress.<br /><br />
If you're a merchant: find a compliant service provider.<br /><br />
4. If your a service provider: code well, make a noise about it. Make your solutions
easy to assess for compliance. Keep in touch with your acquiring bank.<br /><br />
5. You need to evolve your security to address risks. You are allowed to exceed PCI
standards.<br /><br /><br />
6. New VISA best practices: you don't need to store the PAN any more, rely on your
service provider to do it.<br /><br /><br />
7. Do it properly, or don't use credit cards. Support your developers and give them
training.<br /><br />
8. Storage of card data: Challenge it - why does the business need it? Get rid of
old cards if you don't need them.<br /><br />
9. Checkbox security - don't just check the boxes. Exceed them.<br /><br />
10. OWASP top 10 - adopted by PCI DSS.<br /><br />
Two most useful links:<br /><br /><a href="https://www.pcisecuritystandards.org/">www.pcisecuritystandards.org</a><br /><br />
www.owasp.org<br /><br /><b>Parting thoughts:</b><br /><br />
- Use OWASP as a tool<br /><br />
- Don't confuse compliance and standards with security<br /><br />
- Chop up your credit cards!<br /><br /><b>Questions:</b><br /><br />
Why did you give up being a QSA?<br /><br />
It was really stressful<br /><br />
When collecting info and passing it on to a payment gateway, do you require an audit?<br /><br />
Different QSAs treat it differently. He believes the webserver is in scope if it's
taking the card data. New version of standard coming out in October that may address
in-memory stuff.<br /><br />
Why stop using credit cards? At least you get protection, unlike if you use debit
cards?<br /><br />
Dean uses a low-value debit card.<br /><br />
How does PCI deal with it if you're using third-party libraries?<br /><br />
Payment application DSS will kick in if you're using it to resell.<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/igrS7j8cUr8" height="1" width="1" /></body>
      <title>Dean Carter: Ramblings of an ex-QSA</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/15/DeanCarterRamblingsOfAnExQSA.aspx</link>
      <pubDate>Thu, 15 Jul 2010 04:47:41 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/images/dean.jpg" alt="dean.jpg" align="right" border="0" height="334" width="200"&gt;Used
to be a QSA (Qualified Security Assessor). There are now 8 in NZ.&lt;br&gt;
&lt;br&gt;
The QSA wears the risk and signs you off for PCI compliance.&lt;br&gt;
&lt;br&gt;
There are no silver bullets for PCI stuff.&lt;br&gt;
&lt;br&gt;
"It's a hell of a roller-coaster ride"&lt;br&gt;
&lt;br&gt;
He has seen 2.5 million credit card numbers in NZ, in the clear, in many website databases.&lt;br&gt;
&lt;br&gt;
One guy Albert Gonzalez compromised 170 million credit cards across many large corporations.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;PCI requirements:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
"Protect stored data": 79% of orgs fail on this.&lt;br&gt;
&lt;br&gt;
PAN (account data) must be unreadable when stored.&lt;br&gt;
&lt;br&gt;
You can never store mag stripe data.&lt;br&gt;
&lt;br&gt;
"Track and monitor all access to network resources and cardholder data"&lt;br&gt;
&lt;br&gt;
"Develop and maintain secure systems and applications" - 56% of organisations fail
on this&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Rant:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
1. Card holder data gets everywhere&lt;br&gt;
&lt;br&gt;
2. Keep test and development environments out of scope. Don't use real live data in
them.&lt;br&gt;
&lt;br&gt;
3. The good: payment gateways and companies that handle cards - they do a good job.
They outsource to experts.&lt;br&gt;
&lt;br&gt;
The bad: small merchants with a few transactions. Cheap website with cheap hosting.
Easily compromised.&lt;br&gt;
&lt;br&gt;
The ugly: corporates. Great staff but don't make any progress.&lt;br&gt;
&lt;br&gt;
If you're a merchant: find a compliant service provider.&lt;br&gt;
&lt;br&gt;
4. If your a service provider: code well, make a noise about it. Make your solutions
easy to assess for compliance. Keep in touch with your acquiring bank.&lt;br&gt;
&lt;br&gt;
5. You need to evolve your security to address risks. You are allowed to exceed PCI
standards.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
6. New VISA best practices: you don't need to store the PAN any more, rely on your
service provider to do it.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
7. Do it properly, or don't use credit cards. Support your developers and give them
training.&lt;br&gt;
&lt;br&gt;
8. Storage of card data: Challenge it - why does the business need it? Get rid of
old cards if you don't need them.&lt;br&gt;
&lt;br&gt;
9. Checkbox security - don't just check the boxes. Exceed them.&lt;br&gt;
&lt;br&gt;
10. OWASP top 10 - adopted by PCI DSS.&lt;br&gt;
&lt;br&gt;
Two most useful links:&lt;br&gt;
&lt;br&gt;
&lt;a href="https://www.pcisecuritystandards.org/"&gt;www.pcisecuritystandards.org&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
www.owasp.org&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Parting thoughts:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Use OWASP as a tool&lt;br&gt;
&lt;br&gt;
- Don't confuse compliance and standards with security&lt;br&gt;
&lt;br&gt;
- Chop up your credit cards!&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Questions:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Why did you give up being a QSA?&lt;br&gt;
&lt;br&gt;
It was really stressful&lt;br&gt;
&lt;br&gt;
When collecting info and passing it on to a payment gateway, do you require an audit?&lt;br&gt;
&lt;br&gt;
Different QSAs treat it differently. He believes the webserver is in scope if it's
taking the card data. New version of standard coming out in October that may address
in-memory stuff.&lt;br&gt;
&lt;br&gt;
Why stop using credit cards? At least you get protection, unlike if you use debit
cards?&lt;br&gt;
&lt;br&gt;
Dean uses a low-value debit card.&lt;br&gt;
&lt;br&gt;
How does PCI deal with it if you're using third-party libraries?&lt;br&gt;
&lt;br&gt;
Payment application DSS will kick in if you're using it to resell.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,9aad5abd-b8eb-43ea-89b0-8d9c36ca5df0.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=a25db50d-cf87-4743-a32e-277d70acebfb</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,a25db50d-cf87-4743-a32e-277d70acebfb.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,a25db50d-cf87-4743-a32e-277d70acebfb.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=a25db50d-cf87-4743-a32e-277d70acebfb</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/images/hosting.jpg" alt="hosting.jpg" align="right" border="0" height="286" width="200" />Hosting
and Web Apps<br />
The Obscurity of Security<br /><br />
Quintin from SiteHost and Mike from Web Drive cover horror stories they've uncovered
in website code when they've been rung up to fix something.<br /><br /><br />
Security used to be the domain of systems admins and hosters, but developers have
added more fancy features.<br /><br />
Website owners and developer blame their hosters when their sites are defaced.<br /><br /><b>What if security isn't part of the spec?</b><br /><br />
Make it part of the spec.<br /><br />
(Shift jobs if management won't let you make it part of the spec.)<br /><br />
Security starts early: Planning and design phase<br /><br />
- Research, talk to security people<br />
- Get your team some security experience<br />
- Reduce the attack surface<br />
- Keep it simple: Don't build a CMS for a 5 page site<br />
- Don't have an admin area, or use defense in depth to protect it<br /><br /><b>Not all apps are equal:</b><br /><br />
- Sometimes buying is better than building<br />
- Everything has security holes<br />
- Pick something good<br />
 - How does vendor approach security?<br />
 - Check the apps security history:<br />
   - If there are no holes, beware. If there are silly problems, beware.<br /><br /><b>RTFM:</b><br /><br />
- Read the OWASP top 10<br />
- Read the OWASP books<br />
- Read the install documentation and follow the "After installation" docs.<br />
- e.g. Think about what you do when you unserialise stuff; don't trust untrusted user
data<br /><br /><b>Development:</b><br /><br />
- Attack surface reduction<br />
- Validate all your input<br />
- Use source control, and know how it works.<br />
- Watch out for rolling .svn, .git, .cvs directories: might show directory lists,
source code, usernames<br />
- svn checkout is an invalid installation method<br />
- Look at all the files that are there! Especially free / open source apps you download<br /><br /><b>Data management:</b><br /><br />
- If you don't need it, don't store it<br />
- If you need to keep it, how do you need to access it?<br />
- Hash (with a salt), don't encrypt<br />
- Keep production and development seperate<br />
- Keep tabs on your data - size, growth rates, is data used by the code? Get rid of
it.<br /><br /><b>Password strategy:</b><br /><br />
- Don't reuse credentials<br />
- Weak usernames and passwords for db - common to see dbname = username = password<br />
- Watch out for old staff members and old passwords<br /><br /><b>Filesystem security:</b><br /><br />
- Watch out for apps that use /tmp and friends, or require special directory permissions<br />
- Learn how to chmod correctly. x is good enough for directory traversal.<br />
- Watch out for log files in web root<br />
- Beware test files eg phpinfo<br />
- Don't leave old crap on your filesystem: Session files, template caches, zip files<br /><br /><b>Deployment:</b><br /><br />
- Automate as much as possible<br />
- Don't blindly follow installation instructions<br />
  - Read them when you select the software, and understand what it's doing<br />
- Don't use hosting control panels if you don't need them - they have high level access
to the underlying system, and greatly increase your attack surface<br />
- Use SSL for the content not just for the login pages<br />
- Keep your websites separate - different trust level = different credentials<br /><br /><b>Backups:</b><br /><br />
- Keep your own backups - don't trust the providers ones. They protect from a catastrophic
failure, and you could lose 12-24 hours of data<br />
- Test them before you need to use them<br /><br /><b>Clouds:</b><br /><br />
- Don't ever use remote includes - including some third party code in your app!<br />
- Minimise remote resource usage:<br />
  - How does your site react if the remote resource is gone?<br />
  - Take your own copy of AJAX libraries<br />
- Do you need third party analytics for everything?<br />
- Outsourcing data storage: What data are you uploading? Where is it hosted? Is it
safe? Who has access to it? How are backups stored, and how long are they retained?<br /><br /><b>Software lifecycle management:</b><br /><br />
- Have a process for decommissioning, make sure you delete data and files that aren't
used<br />
- Make sure software is up to date<br />
- Who monitors upstream releases? How quickly do you make patches? Who makes the call?<br /><br /><b>Monitoring:</b><br /><br />
- Monitor changes to your website content and uptime<br />
- Check external access. Has your whitelist stopped working?<br />
- DNS: Remember that DNS is an external dependancy. Has your domain been hijacked?<br /><br /><b>Politics:</b><br /><br />
- Make security a part of job description - managers and developers need to make security
a priority and make it part of KPIs<br />
- Get buy-in from non-technical staff<br /><br /><b>Talk to your hosting providers:</b><br /><br />
Talk to their security guys well in advance. Make sure your specific requirements
are getting through to the technician who is doing the work (don't trust the salesperson).<br /><br />
Remember: It's your job to make sure it's working<br /><br /><b>Questions:</b><br /><br />
Including KPIs is a good thing, but you need to give developers the time to learn.<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=a25db50d-cf87-4743-a32e-277d70acebfb" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/QA_B6eW47mU" height="1" width="1" /></body>
      <title>Quintin Russ / Mike Jager - Hosting and Security</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,a25db50d-cf87-4743-a32e-277d70acebfb.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/15/QuintinRussMikeJagerHostingAndSecurity.aspx</link>
      <pubDate>Thu, 15 Jul 2010 04:24:29 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/images/hosting.jpg" alt="hosting.jpg" align="right" border="0" height="286" width="200"&gt;Hosting
and Web Apps&lt;br&gt;
The Obscurity of Security&lt;br&gt;
&lt;br&gt;
Quintin from SiteHost and Mike from Web Drive cover horror stories they've uncovered
in website code when they've been rung up to fix something.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Security used to be the domain of systems admins and hosters, but developers have
added more fancy features.&lt;br&gt;
&lt;br&gt;
Website owners and developer blame their hosters when their sites are defaced.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;What if security isn't part of the spec?&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Make it part of the spec.&lt;br&gt;
&lt;br&gt;
(Shift jobs if management won't let you make it part of the spec.)&lt;br&gt;
&lt;br&gt;
Security starts early: Planning and design phase&lt;br&gt;
&lt;br&gt;
- Research, talk to security people&lt;br&gt;
- Get your team some security experience&lt;br&gt;
- Reduce the attack surface&lt;br&gt;
- Keep it simple: Don't build a CMS for a 5 page site&lt;br&gt;
- Don't have an admin area, or use defense in depth to protect it&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Not all apps are equal:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Sometimes buying is better than building&lt;br&gt;
- Everything has security holes&lt;br&gt;
- Pick something good&lt;br&gt;
&amp;nbsp;- How does vendor approach security?&lt;br&gt;
&amp;nbsp;- Check the apps security history:&lt;br&gt;
&amp;nbsp;&amp;nbsp; - If there are no holes, beware. If there are silly problems, beware.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;RTFM:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Read the OWASP top 10&lt;br&gt;
- Read the OWASP books&lt;br&gt;
- Read the install documentation and follow the "After installation" docs.&lt;br&gt;
- e.g. Think about what you do when you unserialise stuff; don't trust untrusted user
data&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Development:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Attack surface reduction&lt;br&gt;
- Validate all your input&lt;br&gt;
- Use source control, and know how it works.&lt;br&gt;
- Watch out for rolling .svn, .git, .cvs directories: might show directory lists,
source code, usernames&lt;br&gt;
- svn checkout is an invalid installation method&lt;br&gt;
- Look at all the files that are there! Especially free / open source apps you download&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Data management:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- If you don't need it, don't store it&lt;br&gt;
- If you need to keep it, how do you need to access it?&lt;br&gt;
- Hash (with a salt), don't encrypt&lt;br&gt;
- Keep production and development seperate&lt;br&gt;
- Keep tabs on your data - size, growth rates, is data used by the code? Get rid of
it.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Password strategy:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Don't reuse credentials&lt;br&gt;
- Weak usernames and passwords for db - common to see dbname = username = password&lt;br&gt;
- Watch out for old staff members and old passwords&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Filesystem security:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Watch out for apps that use /tmp and friends, or require special directory permissions&lt;br&gt;
- Learn how to chmod correctly. x is good enough for directory traversal.&lt;br&gt;
- Watch out for log files in web root&lt;br&gt;
- Beware test files eg phpinfo&lt;br&gt;
- Don't leave old crap on your filesystem: Session files, template caches, zip files&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Deployment:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Automate as much as possible&lt;br&gt;
- Don't blindly follow installation instructions&lt;br&gt;
&amp;nbsp; - Read them when you select the software, and understand what it's doing&lt;br&gt;
- Don't use hosting control panels if you don't need them - they have high level access
to the underlying system, and greatly increase your attack surface&lt;br&gt;
- Use SSL for the content not just for the login pages&lt;br&gt;
- Keep your websites separate - different trust level = different credentials&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Backups:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Keep your own backups - don't trust the providers ones. They protect from a catastrophic
failure, and you could lose 12-24 hours of data&lt;br&gt;
- Test them before you need to use them&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Clouds:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Don't ever use remote includes - including some third party code in your app!&lt;br&gt;
- Minimise remote resource usage:&lt;br&gt;
&amp;nbsp; - How does your site react if the remote resource is gone?&lt;br&gt;
&amp;nbsp; - Take your own copy of AJAX libraries&lt;br&gt;
- Do you need third party analytics for everything?&lt;br&gt;
- Outsourcing data storage: What data are you uploading? Where is it hosted? Is it
safe? Who has access to it? How are backups stored, and how long are they retained?&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Software lifecycle management:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Have a process for decommissioning, make sure you delete data and files that aren't
used&lt;br&gt;
- Make sure software is up to date&lt;br&gt;
- Who monitors upstream releases? How quickly do you make patches? Who makes the call?&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Monitoring:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Monitor changes to your website content and uptime&lt;br&gt;
- Check external access. Has your whitelist stopped working?&lt;br&gt;
- DNS: Remember that DNS is an external dependancy. Has your domain been hijacked?&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Politics:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
- Make security a part of job description - managers and developers need to make security
a priority and make it part of KPIs&lt;br&gt;
- Get buy-in from non-technical staff&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Talk to your hosting providers:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Talk to their security guys well in advance. Make sure your specific requirements
are getting through to the technician who is doing the work (don't trust the salesperson).&lt;br&gt;
&lt;br&gt;
Remember: It's your job to make sure it's working&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Questions:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Including KPIs is a good thing, but you need to give developers the time to learn.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=a25db50d-cf87-4743-a32e-277d70acebfb" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,a25db50d-cf87-4743-a32e-277d70acebfb.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=74cac478-54fc-455b-b3b4-f73fe88a7816</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,74cac478-54fc-455b-b3b4-f73fe88a7816.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,74cac478-54fc-455b-b3b4-f73fe88a7816.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=74cac478-54fc-455b-b3b4-f73fe88a7816</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/content/binary/tales.jpg" align="right" border="0" />
        <p>
Thanks to everyone who came along to our talk at <a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010">OWASP
NZ Day 2010</a> today. 
<br /></p>
        <p>
Also, a big thanks to the <a href="http://www.dot.net.nz">Wellington .NET user group</a> crowd
that came last night to listen to our practice run -- you'll be pleased to know that
we dropped the discussion of hash extension attacks :)
</p>
Here are the slides for your downloading pleasure: <a href="http://pageofwords.com/blog/content/binary/tales-of-the-crypto.ppt">tales-of-the-crypto.ppt
(3.79 MB)</a><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=74cac478-54fc-455b-b3b4-f73fe88a7816" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/2S6sxW6yJI0" height="1" width="1" /></body>
      <title>Graeme Neilson / Kirk Jackson: Tales from the Crypt0</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,74cac478-54fc-455b-b3b4-f73fe88a7816.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/15/GraemeNeilsonKirkJacksonTalesFromTheCrypt0.aspx</link>
      <pubDate>Thu, 15 Jul 2010 03:25:18 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/content/binary/tales.jpg" align="right" border="0"&gt; 
&lt;p&gt;
Thanks to everyone who came along to our talk at &lt;a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010"&gt;OWASP
NZ Day 2010&lt;/a&gt; today. 
&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;
Also, a big thanks to the &lt;a href="http://www.dot.net.nz"&gt;Wellington .NET user group&lt;/a&gt; crowd
that came last night to listen to our practice run -- you'll be pleased to know that
we dropped the discussion of hash extension attacks :)
&lt;/p&gt;
Here are the slides for your downloading pleasure: &lt;a href="http://pageofwords.com/blog/content/binary/tales-of-the-crypto.ppt"&gt;tales-of-the-crypto.ppt
(3.79 MB)&lt;/a&gt;&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=74cac478-54fc-455b-b3b4-f73fe88a7816" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,74cac478-54fc-455b-b3b4-f73fe88a7816.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=cefb12f7-1c1c-456d-a535-fdaea7c8e73d</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,cefb12f7-1c1c-456d-a535-fdaea7c8e73d.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,cefb12f7-1c1c-456d-a535-fdaea7c8e73d.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=cefb12f7-1c1c-456d-a535-fdaea7c8e73d</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/content/binary/metlstorm.jpg" align="right" border="0" /> Adam
is one of the organisers of <a href="https://kiwicon.org/">Kiwicon</a>, and has presented
on this topic in Singapore.<br /><br />
Using tools to capture / probe network traffic.<br /><br />
If you compare to app/data recon tools like Maltego, network recon tools aren't as
start of the art.<br /><br />
But... if you own the networks under this new fangled cloud stuff, then you own the
whole environment.<br /><br />
It's hard to map out, search and investigate &gt;= Class A<br /><br />
At the moment, only big countries can do that sort of investigation. Apparently countries
are gearing up for 'Cyber Wars'.<br /><br />
But, individuals and corporates can get involved in the same activities of cyber-war
or cyber-terrorism.<br /><br />
Scanning, pinging and trying exploits doesn't scale well - you have to do a lot of
work and get lots of false hits.<br /><br />
You might get owned randomly - it's cheap to own more targets, and then figure out
what to do with it later.<br /><br /><b>Targeting:</b><br /><br />
It's hard to target large numbers of IP addresses. The current tools can't scale to
those kinds of numbers (and the pay services will get really expensive).<br /><br /><b><a href="http://lowscuttlingchillicrab.com">lowscuttlingchillicrab.com</a></b><br /><br />
So he built a geo-targeted network recon data acquisition system with a web interface,
and scanned all of NZ and Singapore for conferences.<br /><br />
An interface to search over data.<br /><br />
"This is a highly secure router, stay away" - the open telnet port tells us so.<br /><br />
Cool things it does:<br /><ul><li>
Searches over certificates</li><li>
Screen captures remote desktop screens</li><li>
Good for targeting: finding particular applications / devices / protocols</li><li>
Good at finding other assets owned by a company outside of their own netblock</li><li>
Helps us understand how many vulnerable things are sitting out there</li></ul><b>The internals of the tool:</b><br /><br />
Version 1 was just to see how plausible it was to scan large chunks of the internet.
Used lots of glued together tools like nmap etc.<br /><br />
Version 2 is now a simple python script that has been optimised for acquiring the
data by scanning a whole country block over certain ports.<br /><br />
A few billion rows of data - use MongoDB to store data. Erlang, RabbitMQ, Python,
Celery MQ, Python / Django frontend, GridFS distributed filestore.<br /><br /><b>Target selection:</b><br /><br />
How do you define what a country is? Is it domain names ending in .nz? Netblocks announced
at peering exchanges? Address registry allocations? GeoIP?<br /><br />
He chose GeoIP as it simplified things - but misses out on .nz stuff hosted overseas.<br /><br /><b>Acquiring data:</b><br /><br />
Custom-tuned protocols to limit rates, fire up application to capture details for
different protocols.<br /><br />
About 1.4B rows per complete scan of NZ and Singapore.<br /><br />
Need to optimise for search / retrieval as that's the primary use once the data is
acquired.<br /><br /><b>Data mining:</b><br /><br />
Look for old boxes, boxes with self-signed certs, certain switches, domains etc.<br /><br />
Singapore: 377k boxes that talk HTTP - more than the number of live systems. 14k cisco
boxes. 12k open RDP (one with background of Commonwealth Bank of Australia :))<br /><br /><b>IDS Avoidance:</b><br /><br />
He's not actually carrying out any intrusions. Only collecting banners, and complying
with what they say.<br /><br />
IDSs don't necessarily detect them - only 7 complaints to ISP in NZ, and one funny
one in Singapore.<br /><br />
People <i>are </i>watching - DNS PTR backscatter gives an idea of people watching
and resolving domain names for IP address.<br /><br />
Portscans aren't very interesting these days. People notice, but don't do anything.<br /><br /><b>But not good for:</b><br /><br />
If you notice mis-configured systems, it's hard to do anything about it.<br /><br />
Giving it as public / bad guy access would be difficult and cause problems. 
<br /><br /><b>What about Shodan?</b><br /><br />
Scan whole world for 4 ports (21, 22, 23, 80), but not as many hosts or depth of coverage
in NZ.<br /><br />
Sells commercial access to exported data.<br /><br /><b>What does it mean?</b><br /><br />
A search engine over this data makes it very powerful.<br /><br />
It's not that hard to do this sort of thing. It's probably already being done by military
or crime industries. Cheap compared to a drug submarine :)<br /><br /><br /><b>Questions:</b><br /><br />
What did the abuse mails say?<br /><br />
One from a Uni, two or three from an ISP and they noticed scanning of the SIP voice
customers. A few of ZoneAlarm type people noticing.<br /><br />
Scanning boxes: Where were they hosted? Bandwidth out?<br /><br />
Domestically peered, gigabit to APE. It's not really bandwidth constrained, it's constrained
by politeness. Turned off state tracking for outbound connections. Could probably
do the whole country in 2 hours if you cranked it up, but would cause problems for
people.<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=cefb12f7-1c1c-456d-a535-fdaea7c8e73d" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/jMk3kJsfu8s" height="1" width="1" /></body>
      <title>Metlstorm: Low Scuttling Chillicrab</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,cefb12f7-1c1c-456d-a535-fdaea7c8e73d.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/15/MetlstormLowScuttlingChillicrab.aspx</link>
      <pubDate>Thu, 15 Jul 2010 01:48:11 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/content/binary/metlstorm.jpg" align="right" border="0"&gt; Adam
is one of the organisers of &lt;a href="https://kiwicon.org/"&gt;Kiwicon&lt;/a&gt;, and has presented
on this topic in Singapore.&lt;br&gt;
&lt;br&gt;
Using tools to capture / probe network traffic.&lt;br&gt;
&lt;br&gt;
If you compare to app/data recon tools like Maltego, network recon tools aren't as
start of the art.&lt;br&gt;
&lt;br&gt;
But... if you own the networks under this new fangled cloud stuff, then you own the
whole environment.&lt;br&gt;
&lt;br&gt;
It's hard to map out, search and investigate &amp;gt;= Class A&lt;br&gt;
&lt;br&gt;
At the moment, only big countries can do that sort of investigation. Apparently countries
are gearing up for 'Cyber Wars'.&lt;br&gt;
&lt;br&gt;
But, individuals and corporates can get involved in the same activities of cyber-war
or cyber-terrorism.&lt;br&gt;
&lt;br&gt;
Scanning, pinging and trying exploits doesn't scale well - you have to do a lot of
work and get lots of false hits.&lt;br&gt;
&lt;br&gt;
You might get owned randomly - it's cheap to own more targets, and then figure out
what to do with it later.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Targeting:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
It's hard to target large numbers of IP addresses. The current tools can't scale to
those kinds of numbers (and the pay services will get really expensive).&lt;br&gt;
&lt;br&gt;
&lt;b&gt;&lt;a href="http://lowscuttlingchillicrab.com"&gt;lowscuttlingchillicrab.com&lt;/a&gt;&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
So he built a geo-targeted network recon data acquisition system with a web interface,
and scanned all of NZ and Singapore for conferences.&lt;br&gt;
&lt;br&gt;
An interface to search over data.&lt;br&gt;
&lt;br&gt;
"This is a highly secure router, stay away" - the open telnet port tells us so.&lt;br&gt;
&lt;br&gt;
Cool things it does:&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;
Searches over certificates&lt;/li&gt;
&lt;li&gt;
Screen captures remote desktop screens&lt;/li&gt;
&lt;li&gt;
Good for targeting: finding particular applications / devices / protocols&lt;/li&gt;
&lt;li&gt;
Good at finding other assets owned by a company outside of their own netblock&lt;/li&gt;
&lt;li&gt;
Helps us understand how many vulnerable things are sitting out there&lt;/li&gt;
&lt;/ul&gt;
&lt;b&gt;The internals of the tool:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Version 1 was just to see how plausible it was to scan large chunks of the internet.
Used lots of glued together tools like nmap etc.&lt;br&gt;
&lt;br&gt;
Version 2 is now a simple python script that has been optimised for acquiring the
data by scanning a whole country block over certain ports.&lt;br&gt;
&lt;br&gt;
A few billion rows of data - use MongoDB to store data. Erlang, RabbitMQ, Python,
Celery MQ, Python / Django frontend, GridFS distributed filestore.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Target selection:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
How do you define what a country is? Is it domain names ending in .nz? Netblocks announced
at peering exchanges? Address registry allocations? GeoIP?&lt;br&gt;
&lt;br&gt;
He chose GeoIP as it simplified things - but misses out on .nz stuff hosted overseas.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Acquiring data:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Custom-tuned protocols to limit rates, fire up application to capture details for
different protocols.&lt;br&gt;
&lt;br&gt;
About 1.4B rows per complete scan of NZ and Singapore.&lt;br&gt;
&lt;br&gt;
Need to optimise for search / retrieval as that's the primary use once the data is
acquired.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Data mining:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Look for old boxes, boxes with self-signed certs, certain switches, domains etc.&lt;br&gt;
&lt;br&gt;
Singapore: 377k boxes that talk HTTP - more than the number of live systems. 14k cisco
boxes. 12k open RDP (one with background of Commonwealth Bank of Australia :))&lt;br&gt;
&lt;br&gt;
&lt;b&gt;IDS Avoidance:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
He's not actually carrying out any intrusions. Only collecting banners, and complying
with what they say.&lt;br&gt;
&lt;br&gt;
IDSs don't necessarily detect them - only 7 complaints to ISP in NZ, and one funny
one in Singapore.&lt;br&gt;
&lt;br&gt;
People &lt;i&gt;are &lt;/i&gt;watching - DNS PTR backscatter gives an idea of people watching
and resolving domain names for IP address.&lt;br&gt;
&lt;br&gt;
Portscans aren't very interesting these days. People notice, but don't do anything.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;But not good for:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
If you notice mis-configured systems, it's hard to do anything about it.&lt;br&gt;
&lt;br&gt;
Giving it as public / bad guy access would be difficult and cause problems. 
&lt;br&gt;
&lt;br&gt;
&lt;b&gt;What about Shodan?&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Scan whole world for 4 ports (21, 22, 23, 80), but not as many hosts or depth of coverage
in NZ.&lt;br&gt;
&lt;br&gt;
Sells commercial access to exported data.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;What does it mean?&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
A search engine over this data makes it very powerful.&lt;br&gt;
&lt;br&gt;
It's not that hard to do this sort of thing. It's probably already being done by military
or crime industries. Cheap compared to a drug submarine :)&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Questions:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
What did the abuse mails say?&lt;br&gt;
&lt;br&gt;
One from a Uni, two or three from an ISP and they noticed scanning of the SIP voice
customers. A few of ZoneAlarm type people noticing.&lt;br&gt;
&lt;br&gt;
Scanning boxes: Where were they hosted? Bandwidth out?&lt;br&gt;
&lt;br&gt;
Domestically peered, gigabit to APE. It's not really bandwidth constrained, it's constrained
by politeness. Turned off state tracking for outbound connections. Could probably
do the whole country in 2 hours if you cranked it up, but would cause problems for
people.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=cefb12f7-1c1c-456d-a535-fdaea7c8e73d" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,cefb12f7-1c1c-456d-a535-fdaea7c8e73d.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=0428b4c3-fb5a-4368-8643-2d069a95aab2</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,0428b4c3-fb5a-4368-8643-2d069a95aab2.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,0428b4c3-fb5a-4368-8643-2d069a95aab2.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=0428b4c3-fb5a-4368-8643-2d069a95aab2</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/images/paul.jpg" alt="paul.jpg" align="right" border="0" height="370" width="200" />Paul
Craig works at security-assessment.com as a forensic investigator.<br /><br />
Forensic investigation: <i>Fact</i>-based investigation - must be reproducible and
not based on anything subjective.<br /><br />
If you're going to get hacked, it will start at your web app. Firewalls generally
stop all other traffic.<br /><br />
Treat all results as possible legal evidence - could be used for murder etc cases.
Evidence could be used to allow police to arrest a suspect.<br /><br />
Most computer crimes in NZ will be tried under property law with a judge and jury.<br /><br />
All evidence may need to be provided to defendant to cast doubt on the evidence. How
was it collected or analysed?<br /><br />
Common things customers say:<br /><br />
- Assumptions<br />
- They only compromised one server - assume it has happened more than once<br />
- We already dealt with it - probably destroyed all forensic evidence (could come
back to bite in the future)<br />
- It's too hard / not my problem<br /><br /><b>What to do when there's an incident:</b><br /><br />
How you act makes all the difference. Smooth engagements and do things as fast as
possible.<br /><br />
Need a single point of contact for all security incidents within an organisation.<br /><br />
Appoint an incident response team - includng someone with internal clout, legal support.<br /><br />
Find a forensics supplier in advance. Don't leave it till when there's an incident.<br /><br />
It's a specialised industry, and you shouldn't do it yourself.<br /><br /><b>Media:</b><br /><br />
Media love a hacking story. This makes things stressful.<br /><br />
You need a bottom draw letter pre-written that you can give to the media. Get it signed
by the CEO now.<br /><br /><b>Technical incident response:</b><br /><br />
Treat with urgency, gather incident team together in a secure location.<br /><br />
Get incident responder into the system as soon as possible to get current connections,
arp caches etc.<br /><br />
- Disable scheduled patches, updates, restarts<br />
- Unplug from internet / firewall it<br />
- Leave the server powered on<br />
- Put a big sign "Do not touch"<br /><br />
Within a day or less if possible.<br /><br /><b>Police reports:</b><br /><br />
If you have evidence that a crime has been committed, or something could be committed
(e.g. fraud), file an incident report with police. As much evidence as possible.<br /><br /><b>Will you catch them?</b><br /><br />
If NZ / AU - likely.<br /><br />
If UN / NATO, possible but involved IPTF task force.<br /><br />
Other country: very slim chance of catching them.<br /><br /><b>When don't you have to file a report:</b><br /><br />
No loss of finances, no increase in fraud risk, no chance of repurcussions / fines.<br /><br /><br /><b>How to do forensics:</b><br /><br />
Paul then talked about how security-assessment.com do forensics testing. Take-away:
it's hard, and in order to provide evidence in court you won't actually be able to
do it yourself.<br /><br /><b>Examples:</b><br /><br />
Paul gave examples of when they'd be engaged with customers. Problems encountered:<br /><br />
- They knew they had been hacked, but hadn't told each other<br />
- Meeting in insecure places<br />
- Taking too long to figure out what to do<br />
- Companies that don't know how to respond<br />
- Assuming evidence has been destroyed already<br /><br />
Without senior executive support, nothing will happen. Forensic and technical response
isn't a technical problem: it is an entire business problem.<br /><br /><b>Take-home:</b><br /><br />
Sooner or later, you'll get hacked. When it happens, take it seriously.<br /><br />
Prepare for that incident straight away. Figure out what you'd do?<br /><br />
Stay cool when it happens, follow the game plan.<br /><br />
Never assume anything!<br /><br /><b>Questions:</b><br /><br />
How do you deal with situations where the hacked website needs to be back up in 10
minutes? So you don't have time to do forensics?<br /><br />
- Bring up a DR server if you have a safe backup.<br />
- If it's compromised, you have to take it off immediately if someone is on that server
at that time<br /><br />
How do you deal with virtualisation? When you don't have physical access to a machine?<br /><br />
- Can get all active memory and disk onto a disk<br />
- Can take the entire VM snapshot and rebuild into a real computer again<br /><br />
What about if it's a cloud provider?<br /><br />
- Probably have no access to get an image. Comes down to whether we can get that access.<br /><br />
Does a live image impact the integrity of the evidence?<br /><br />
- Hash the evidence as soon as it is taken, so we can prove the image is unaltered.<br /><br />
If hacker uses anonymity services like tor / proxies?<br /><br />
- Often there's one request where they connect back directly.<br />
- Often there's still some fragments of evidence remaining.<br />
- Might be able to find out what they did, but not necessarily who did it.<br />
  - "Your credit cards have not been touched"<br /><br /><br /><br /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=0428b4c3-fb5a-4368-8643-2d069a95aab2" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/tGMPDtB3IPw" height="1" width="1" /></body>
      <title>Paul Craig: What to do when you get pwned?</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,0428b4c3-fb5a-4368-8643-2d069a95aab2.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/15/PaulCraigWhatToDoWhenYouGetPwned.aspx</link>
      <pubDate>Thu, 15 Jul 2010 00:00:10 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/images/paul.jpg" alt="paul.jpg" align="right" border="0" height="370" width="200"&gt;Paul
Craig works at security-assessment.com as a forensic investigator.&lt;br&gt;
&lt;br&gt;
Forensic investigation: &lt;i&gt;Fact&lt;/i&gt;-based investigation - must be reproducible and
not based on anything subjective.&lt;br&gt;
&lt;br&gt;
If you're going to get hacked, it will start at your web app. Firewalls generally
stop all other traffic.&lt;br&gt;
&lt;br&gt;
Treat all results as possible legal evidence - could be used for murder etc cases.
Evidence could be used to allow police to arrest a suspect.&lt;br&gt;
&lt;br&gt;
Most computer crimes in NZ will be tried under property law with a judge and jury.&lt;br&gt;
&lt;br&gt;
All evidence may need to be provided to defendant to cast doubt on the evidence. How
was it collected or analysed?&lt;br&gt;
&lt;br&gt;
Common things customers say:&lt;br&gt;
&lt;br&gt;
- Assumptions&lt;br&gt;
- They only compromised one server - assume it has happened more than once&lt;br&gt;
- We already dealt with it - probably destroyed all forensic evidence (could come
back to bite in the future)&lt;br&gt;
- It's too hard / not my problem&lt;br&gt;
&lt;br&gt;
&lt;b&gt;What to do when there's an incident:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
How you act makes all the difference. Smooth engagements and do things as fast as
possible.&lt;br&gt;
&lt;br&gt;
Need a single point of contact for all security incidents within an organisation.&lt;br&gt;
&lt;br&gt;
Appoint an incident response team - includng someone with internal clout, legal support.&lt;br&gt;
&lt;br&gt;
Find a forensics supplier in advance. Don't leave it till when there's an incident.&lt;br&gt;
&lt;br&gt;
It's a specialised industry, and you shouldn't do it yourself.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Media:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Media love a hacking story. This makes things stressful.&lt;br&gt;
&lt;br&gt;
You need a bottom draw letter pre-written that you can give to the media. Get it signed
by the CEO now.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Technical incident response:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Treat with urgency, gather incident team together in a secure location.&lt;br&gt;
&lt;br&gt;
Get incident responder into the system as soon as possible to get current connections,
arp caches etc.&lt;br&gt;
&lt;br&gt;
- Disable scheduled patches, updates, restarts&lt;br&gt;
- Unplug from internet / firewall it&lt;br&gt;
- Leave the server powered on&lt;br&gt;
- Put a big sign "Do not touch"&lt;br&gt;
&lt;br&gt;
Within a day or less if possible.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Police reports:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
If you have evidence that a crime has been committed, or something could be committed
(e.g. fraud), file an incident report with police. As much evidence as possible.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Will you catch them?&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
If NZ / AU - likely.&lt;br&gt;
&lt;br&gt;
If UN / NATO, possible but involved IPTF task force.&lt;br&gt;
&lt;br&gt;
Other country: very slim chance of catching them.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;When don't you have to file a report:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
No loss of finances, no increase in fraud risk, no chance of repurcussions / fines.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;b&gt;How to do forensics:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Paul then talked about how security-assessment.com do forensics testing. Take-away:
it's hard, and in order to provide evidence in court you won't actually be able to
do it yourself.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Examples:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Paul gave examples of when they'd be engaged with customers. Problems encountered:&lt;br&gt;
&lt;br&gt;
- They knew they had been hacked, but hadn't told each other&lt;br&gt;
- Meeting in insecure places&lt;br&gt;
- Taking too long to figure out what to do&lt;br&gt;
- Companies that don't know how to respond&lt;br&gt;
- Assuming evidence has been destroyed already&lt;br&gt;
&lt;br&gt;
Without senior executive support, nothing will happen. Forensic and technical response
isn't a technical problem: it is an entire business problem.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Take-home:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Sooner or later, you'll get hacked. When it happens, take it seriously.&lt;br&gt;
&lt;br&gt;
Prepare for that incident straight away. Figure out what you'd do?&lt;br&gt;
&lt;br&gt;
Stay cool when it happens, follow the game plan.&lt;br&gt;
&lt;br&gt;
Never assume anything!&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Questions:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
How do you deal with situations where the hacked website needs to be back up in 10
minutes? So you don't have time to do forensics?&lt;br&gt;
&lt;br&gt;
- Bring up a DR server if you have a safe backup.&lt;br&gt;
- If it's compromised, you have to take it off immediately if someone is on that server
at that time&lt;br&gt;
&lt;br&gt;
How do you deal with virtualisation? When you don't have physical access to a machine?&lt;br&gt;
&lt;br&gt;
- Can get all active memory and disk onto a disk&lt;br&gt;
- Can take the entire VM snapshot and rebuild into a real computer again&lt;br&gt;
&lt;br&gt;
What about if it's a cloud provider?&lt;br&gt;
&lt;br&gt;
- Probably have no access to get an image. Comes down to whether we can get that access.&lt;br&gt;
&lt;br&gt;
Does a live image impact the integrity of the evidence?&lt;br&gt;
&lt;br&gt;
- Hash the evidence as soon as it is taken, so we can prove the image is unaltered.&lt;br&gt;
&lt;br&gt;
If hacker uses anonymity services like tor / proxies?&lt;br&gt;
&lt;br&gt;
- Often there's one request where they connect back directly.&lt;br&gt;
- Often there's still some fragments of evidence remaining.&lt;br&gt;
- Might be able to find out what they did, but not necessarily who did it.&lt;br&gt;
&amp;nbsp; - "Your credit cards have not been touched"&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=0428b4c3-fb5a-4368-8643-2d069a95aab2" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,0428b4c3-fb5a-4368-8643-2d069a95aab2.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=04c4734b-4fb2-423e-b951-47d645fd352f</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,04c4734b-4fb2-423e-b951-47d645fd352f.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,04c4734b-4fb2-423e-b951-47d645fd352f.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=04c4734b-4fb2-423e-b951-47d645fd352f</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/images/roberto.jpg" alt="roberto.jpg" align="right" border="0" height="292" width="200" />Roberto's
talk covered application-level vulnerabilities, and gave some ideas on how to plan
for them, how to react when they happen, and how to recover from them.<br /><br />
Most denial of service attacks have traditionally covered the layer 3 or 4 (i.e. the
transport or network stack), but Roberto has seen attacks against applications and
web service layers.<br /><br />
Can lead to increased use of resources like CPU, network<br /><br />
Root causes:<br /><br />
- bug<br />
- application logic open to abuse<br />
- session level attacks<br /><br />
Examples:<br /><br />
PHP: Can create an unbounded size object in code<br /><br />
Failure to release resource: DB exception doesn't close connection. Attacker can cause
app to open up lots of DB connections and deny service.<br /><br />
Sesion related: storing lots of session objects that consume resources, so attacker
can target this to exhaust server resources.<br /><br />
User input as a loop counter: If the user can control how many times an expensive
operation is performed, it can cause the app to do lots of demanding work.<br /><br />
=&gt; Put in some limits, don't allow the user to set in their code.<br /><br />
Regular expressions: Certain input may cause lots of passes through a regular expression,
causing lots of CPU to be used.<br /><br />
Other web problems can amplify DOS effects (XSS, XSRF, SQL injection, large file input)<br /><br />
Recommendations:<br /><br />
- Input strict validation and filtering<br />
- Handle exceptions and properly release resources<br />
- Set limits for:<br />
  - Session related objects<br />
  - Token expiration<br />
  - Object allocation<br />
  - Loop counters<br />
  - User registration - captcha<br />
  - Concurrent session tokens per IP address<br /><br />
- Testing your web app<br />
  - Test Regex, database queries<br />
  - DoS and stress testing<br />
  - Security testing<br /><br /><b>XML attacks:</b><br /><br />
There are lots of attacks against XML or web services.<br /><br />
Recommendations: don't use customised XML parser, input validation, use an XML firewall,
limit the sizes of input messages, disable external DTDs.<br /><br /><b>Webserver attacks:</b><br /><br />
Attacks to use up all the threads on a webserver, or slow down the processing so the
server can't process other requests.<br /><br />
Recommendations: Apache and IS have modules or configuration settings. Make sure you
test the changes.<br /><br /><b>Database attacks:</b><br /><br />
Make the DB do more work than they should. E.g. cause a slow scan over a whole table,
or avoid caching layers.<br /><br />
Recommendations: Input validation, captcha or user limits, only let authenticated
users perform slow queries, use caching layers.<br /><br /><b>If you are under attack:</b><br /><br />
Be prepared, have a plan, simulate it often.<br /><br /><b>When under attack:</b><br /><br />
Is it real? What is the target? Is the target critical?<br /><br /><b>Reacting:</b><br /><br />
Several methods: slow down the attack, deflect it, drop connections, escalate to authorities
or other nefarious ways to stop botnets.<br /><br /><b>Recovering:</b><br /><br />
Meet up to debrief as soon as possible afterwards. What lessons were learnt? Update
incident plan.<br /><br />
What was the root cause? What if it happens again? Provide all data to law enforcement.<br /><br /><b>Conclusion:</b><br /><br />
No generic solution to DOS.<br /><br />
If offered a DOS solution product, look carefully before committing.<br /><br />
Start networking with people that can help you.<br /><br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=04c4734b-4fb2-423e-b951-47d645fd352f" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/7mIUW1_5fgk" height="1" width="1" /></body>
      <title>Roberto Suggi Liverani - Defending Against Application Level DoS Attacks</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,04c4734b-4fb2-423e-b951-47d645fd352f.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/14/RobertoSuggiLiveraniDefendingAgainstApplicationLevelDoSAttacks.aspx</link>
      <pubDate>Wed, 14 Jul 2010 23:37:58 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/images/roberto.jpg" alt="roberto.jpg" align="right" border="0" height="292" width="200"&gt;Roberto's
talk covered application-level vulnerabilities, and gave some ideas on how to plan
for them, how to react when they happen, and how to recover from them.&lt;br&gt;
&lt;br&gt;
Most denial of service attacks have traditionally covered the layer 3 or 4 (i.e. the
transport or network stack), but Roberto has seen attacks against applications and
web service layers.&lt;br&gt;
&lt;br&gt;
Can lead to increased use of resources like CPU, network&lt;br&gt;
&lt;br&gt;
Root causes:&lt;br&gt;
&lt;br&gt;
- bug&lt;br&gt;
- application logic open to abuse&lt;br&gt;
- session level attacks&lt;br&gt;
&lt;br&gt;
Examples:&lt;br&gt;
&lt;br&gt;
PHP: Can create an unbounded size object in code&lt;br&gt;
&lt;br&gt;
Failure to release resource: DB exception doesn't close connection. Attacker can cause
app to open up lots of DB connections and deny service.&lt;br&gt;
&lt;br&gt;
Sesion related: storing lots of session objects that consume resources, so attacker
can target this to exhaust server resources.&lt;br&gt;
&lt;br&gt;
User input as a loop counter: If the user can control how many times an expensive
operation is performed, it can cause the app to do lots of demanding work.&lt;br&gt;
&lt;br&gt;
=&amp;gt; Put in some limits, don't allow the user to set in their code.&lt;br&gt;
&lt;br&gt;
Regular expressions: Certain input may cause lots of passes through a regular expression,
causing lots of CPU to be used.&lt;br&gt;
&lt;br&gt;
Other web problems can amplify DOS effects (XSS, XSRF, SQL injection, large file input)&lt;br&gt;
&lt;br&gt;
Recommendations:&lt;br&gt;
&lt;br&gt;
- Input strict validation and filtering&lt;br&gt;
- Handle exceptions and properly release resources&lt;br&gt;
- Set limits for:&lt;br&gt;
&amp;nbsp; - Session related objects&lt;br&gt;
&amp;nbsp; - Token expiration&lt;br&gt;
&amp;nbsp; - Object allocation&lt;br&gt;
&amp;nbsp; - Loop counters&lt;br&gt;
&amp;nbsp; - User registration - captcha&lt;br&gt;
&amp;nbsp; - Concurrent session tokens per IP address&lt;br&gt;
&lt;br&gt;
- Testing your web app&lt;br&gt;
&amp;nbsp; - Test Regex, database queries&lt;br&gt;
&amp;nbsp; - DoS and stress testing&lt;br&gt;
&amp;nbsp; - Security testing&lt;br&gt;
&lt;br&gt;
&lt;b&gt;XML attacks:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
There are lots of attacks against XML or web services.&lt;br&gt;
&lt;br&gt;
Recommendations: don't use customised XML parser, input validation, use an XML firewall,
limit the sizes of input messages, disable external DTDs.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Webserver attacks:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Attacks to use up all the threads on a webserver, or slow down the processing so the
server can't process other requests.&lt;br&gt;
&lt;br&gt;
Recommendations: Apache and IS have modules or configuration settings. Make sure you
test the changes.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Database attacks:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Make the DB do more work than they should. E.g. cause a slow scan over a whole table,
or avoid caching layers.&lt;br&gt;
&lt;br&gt;
Recommendations: Input validation, captcha or user limits, only let authenticated
users perform slow queries, use caching layers.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;If you are under attack:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Be prepared, have a plan, simulate it often.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;When under attack:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Is it real? What is the target? Is the target critical?&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Reacting:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Several methods: slow down the attack, deflect it, drop connections, escalate to authorities
or other nefarious ways to stop botnets.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Recovering:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
Meet up to debrief as soon as possible afterwards. What lessons were learnt? Update
incident plan.&lt;br&gt;
&lt;br&gt;
What was the root cause? What if it happens again? Provide all data to law enforcement.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Conclusion:&lt;/b&gt;
&lt;br&gt;
&lt;br&gt;
No generic solution to DOS.&lt;br&gt;
&lt;br&gt;
If offered a DOS solution product, look carefully before committing.&lt;br&gt;
&lt;br&gt;
Start networking with people that can help you.&lt;br&gt;
&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=04c4734b-4fb2-423e-b951-47d645fd352f" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,04c4734b-4fb2-423e-b951-47d645fd352f.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=5e6df742-ff74-4a98-acc1-87e71eb694e2</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,5e6df742-ff74-4a98-acc1-87e71eb694e2.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,5e6df742-ff74-4a98-acc1-87e71eb694e2.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=5e6df742-ff74-4a98-acc1-87e71eb694e2</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">
        <img src="http://pageofwords.com/blog/images/brett.jpg" alt="brett.jpg" align="right" border="0" height="415" width="300" />Brett
presented a talk on some of the "Not so common code vulnerabilities".<br /><br />
The theme of his talk was that we shouldn't trust user input.<br /><br />
My notes:<br /><br />
A security vulnerability in an app - a weakness that allows a user to perform an action
that was unintended.<br /><br />
AppTrends graph (<a href="http://www.cenzic.com/">cenzic.com</a>) - input validation
is the cause of everything (XSS, SQL injection, etc)<br /><br /><br />
Frameworks won't protect you (e.g. .NET, PHP, Java frameworks). 
<br /><br />
Frameworks can promote bad practices, or have bugs in them themselves.<br /><br />
- Spring Framework http://blog.o0o.nu/ - override class loaded<br />
- Struts2 - execute arbitrary java code<br /><br />
Examples of problems:<br /><br />
Trusting filenames / urls from the user<br /><br />
Using 302 Redirects as a security measure - returning secure 
<br /><br />
content below the redirect by mistake<br /><br />
Captchas: Tell whether it's a human or computer. Bad implementations where people
have rolled their own and make it easy for computer to answer<br /><br />
Online shopping: Response from DPS comes in a browser redirect, so you can intercept
it, and add extra stuff to the shopping cart after paying, but before the website
thinks the order is finished.<br /><br />
Flash: Parameters for a flash movie can be entered in the url as well. Movie hosted
on our site can end up displaying images or other content from our attack website.<br /><br />
Forgotten password: Stored proc truncates email address to 100 characters when looking
up the user, but application uses the whole string. This can lead to an attacker receiving
the forgotten password email.<br /><br />
Java object serialisation: Object is serialised into a cookie using Base64 encoding.
Ooops: It contains something sensitive like a password.<br /><br />
PHP app in a security appliance used by a .mil: Shell out to a system command using
a url parameter passed via an unauthenticated user.<br /><br />
Cookies: storing security data in a cookie - example of LoginAttempts - an attacker
can modify the cookie to their hearts content.<br /><br />
Cookie: remember me functionality - store random token in the database and send it
to the user as a cookie, so they can log in automatically. Vulnerability: flawed if
null was stored in both the db and the cookie.<br /><br /><br />
Lesson:<br /><br />
Never trust the users input<br /><br />
Input validation is the key. 
<br /><br /><br />
You can use hidden form fields or cookies, as long as the backend input validation
is secure. You can't trust that the frontend is doing things correctly.<br /><br />
Backend should:<br />
- Validate the data<br />
- Ensure the user is authorised to access the data<br /><br />
Data comes in many forms (upper / lower case, encoded etc)<br /><br />
- Decode the data, or reject it if a normal user wouldn't send it<br /><br />
Ensure data conforms to the correct format<br />
- Check length, type, min / max values<br />
- Alphanumeric / valid date only<br /><br />
Reject invalid data, rather than attempting to fix it up.<br /><br />
Beware writing your own data sanitisation functions - needs to be well tested and
document. Use OWASP or language features if possible.<br /><br />
- Easy to write bad sanitisation. Examples of bad url testing, 
<br /><br />
XSS works without script<br /><br /><br />
Takeaways:<br /><br />
- Review your code. Have "Code Review Parties"<br />
- Have peer reviews<br />
- Have standards, and stick to them<br /><br />
Questions to Brett:<br /><br />
Should we still trust CAPTCHA?<br /><br />
Still effective at the moment, but can be broken.<br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=5e6df742-ff74-4a98-acc1-87e71eb694e2" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/jdyb45_JNoY" height="1" width="1" /></body>
      <title>Brett Moore: Don't try this at home</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,5e6df742-ff74-4a98-acc1-87e71eb694e2.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/14/BrettMooreDontTryThisAtHome.aspx</link>
      <pubDate>Wed, 14 Jul 2010 21:59:45 GMT</pubDate>
      <description>&lt;img src="http://pageofwords.com/blog/images/brett.jpg" alt="brett.jpg" align="right" border="0" height="415" width="300"&gt;Brett
presented a talk on some of the "Not so common code vulnerabilities".&lt;br&gt;
&lt;br&gt;
The theme of his talk was that we shouldn't trust user input.&lt;br&gt;
&lt;br&gt;
My notes:&lt;br&gt;
&lt;br&gt;
A security vulnerability in an app - a weakness that allows a user to perform an action
that was unintended.&lt;br&gt;
&lt;br&gt;
AppTrends graph (&lt;a href="http://www.cenzic.com/"&gt;cenzic.com&lt;/a&gt;) - input validation
is the cause of everything (XSS, SQL injection, etc)&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Frameworks won't protect you (e.g. .NET, PHP, Java frameworks). 
&lt;br&gt;
&lt;br&gt;
Frameworks can promote bad practices, or have bugs in them themselves.&lt;br&gt;
&lt;br&gt;
- Spring Framework http://blog.o0o.nu/ - override class loaded&lt;br&gt;
- Struts2 - execute arbitrary java code&lt;br&gt;
&lt;br&gt;
Examples of problems:&lt;br&gt;
&lt;br&gt;
Trusting filenames / urls from the user&lt;br&gt;
&lt;br&gt;
Using 302 Redirects as a security measure - returning secure 
&lt;br&gt;
&lt;br&gt;
content below the redirect by mistake&lt;br&gt;
&lt;br&gt;
Captchas: Tell whether it's a human or computer. Bad implementations where people
have rolled their own and make it easy for computer to answer&lt;br&gt;
&lt;br&gt;
Online shopping: Response from DPS comes in a browser redirect, so you can intercept
it, and add extra stuff to the shopping cart after paying, but before the website
thinks the order is finished.&lt;br&gt;
&lt;br&gt;
Flash: Parameters for a flash movie can be entered in the url as well. Movie hosted
on our site can end up displaying images or other content from our attack website.&lt;br&gt;
&lt;br&gt;
Forgotten password: Stored proc truncates email address to 100 characters when looking
up the user, but application uses the whole string. This can lead to an attacker receiving
the forgotten password email.&lt;br&gt;
&lt;br&gt;
Java object serialisation: Object is serialised into a cookie using Base64 encoding.
Ooops: It contains something sensitive like a password.&lt;br&gt;
&lt;br&gt;
PHP app in a security appliance used by a .mil: Shell out to a system command using
a url parameter passed via an unauthenticated user.&lt;br&gt;
&lt;br&gt;
Cookies: storing security data in a cookie - example of LoginAttempts - an attacker
can modify the cookie to their hearts content.&lt;br&gt;
&lt;br&gt;
Cookie: remember me functionality - store random token in the database and send it
to the user as a cookie, so they can log in automatically. Vulnerability: flawed if
null was stored in both the db and the cookie.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Lesson:&lt;br&gt;
&lt;br&gt;
Never trust the users input&lt;br&gt;
&lt;br&gt;
Input validation is the key. 
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
You can use hidden form fields or cookies, as long as the backend input validation
is secure. You can't trust that the frontend is doing things correctly.&lt;br&gt;
&lt;br&gt;
Backend should:&lt;br&gt;
- Validate the data&lt;br&gt;
- Ensure the user is authorised to access the data&lt;br&gt;
&lt;br&gt;
Data comes in many forms (upper / lower case, encoded etc)&lt;br&gt;
&lt;br&gt;
- Decode the data, or reject it if a normal user wouldn't send it&lt;br&gt;
&lt;br&gt;
Ensure data conforms to the correct format&lt;br&gt;
- Check length, type, min / max values&lt;br&gt;
- Alphanumeric / valid date only&lt;br&gt;
&lt;br&gt;
Reject invalid data, rather than attempting to fix it up.&lt;br&gt;
&lt;br&gt;
Beware writing your own data sanitisation functions - needs to be well tested and
document. Use OWASP or language features if possible.&lt;br&gt;
&lt;br&gt;
- Easy to write bad sanitisation. Examples of bad url testing, 
&lt;br&gt;
&lt;br&gt;
XSS works without script&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Takeaways:&lt;br&gt;
&lt;br&gt;
- Review your code. Have "Code Review Parties"&lt;br&gt;
- Have peer reviews&lt;br&gt;
- Have standards, and stick to them&lt;br&gt;
&lt;br&gt;
Questions to Brett:&lt;br&gt;
&lt;br&gt;
Should we still trust CAPTCHA?&lt;br&gt;
&lt;br&gt;
Still effective at the moment, but can be broken.&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=5e6df742-ff74-4a98-acc1-87e71eb694e2" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,5e6df742-ff74-4a98-acc1-87e71eb694e2.aspx</comments>
      <category>OWASP;Security</category>
    </item>
    <item>
      <trackback:ping>http://pageofwords.com/blog/Trackback.aspx?guid=ec0e1324-3840-43c9-854f-d0d49822d4e9</trackback:ping>
      <pingback:server>http://pageofwords.com/blog/pingback.aspx</pingback:server>
      <pingback:target>http://pageofwords.com/blog/PermaLink,guid,ec0e1324-3840-43c9-854f-d0d49822d4e9.aspx</pingback:target>
      <dc:creator>Kirk Jackson</dc:creator>
      <wfw:comment>http://pageofwords.com/blog/CommentView,guid,ec0e1324-3840-43c9-854f-d0d49822d4e9.aspx</wfw:comment>
      <wfw:commentRss>http://pageofwords.com/blog/SyndicationService.asmx/GetEntryCommentsRss?guid=ec0e1324-3840-43c9-854f-d0d49822d4e9</wfw:commentRss>
      <body xmlns="http://www.w3.org/1999/xhtml">I had fun attending <a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010">OWASP
NZ Day 2010</a>.<br /><br />
There were 6 great sessions - plus Graeme and I presented a talk on encryption, and
how to develop applications using encryption:<br /><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/14/BrettMooreDontTryThisAtHome.aspx">Brett
Moore: Don't try this at home</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/14/RobertoSuggiLiveraniDefendingAgainstApplicationLevelDoSAttacks.aspx">Roberto
Suggi Liverani - Defending Against Application Level DoS Attacks</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/PaulCraigWhatToDoWhenYouGetPwned.aspx">Paul
Craig: What to do when you get pwned?</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/MetlstormLowScuttlingChillicrab.aspx">Metlstorm:
Low Scuttling Chillicrab</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/GraemeNeilsonKirkJacksonTalesFromTheCrypt0.aspx">Graeme
Neilson / Kirk Jackson: Tales from the Crypt0</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/QuintinRussMikeJagerHostingAndSecurity.aspx">Quintin
Russ / Mike Jager - Hosting and Security</a><br /><a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/DeanCarterRamblingsOfAnExQSA.aspx">Dean
Carter: Ramblings of an ex-QSA</a><br /><br />
I came away with that feeling of satisfaction where you know you've learnt lots, but
haven't had time to digest and process it all yet. Some of my immediate takeaways
are:<br /><br /><ul><li>
Input validation is still a big area of problems in most apps<br /></li><li>
Application bugs and inefficiencies can be vectors for denial of service attacks</li><li>
If you get pwned, hacked or DOS'd, you need to have a plan of what you're going to
do to recover, and if there's a chance that you need law enforcement involved, you
need to get a forensic analyst involved very early on (preferably in advance)</li><li>
There are lots of computers on the internet in NZ, and lots of them have obvious vulnerabilities.
No-one is doing anything about this (at least, no-one <i>good</i> is doing anything
about this!)</li><li>
Bad development practices lead to problems in the hosting environment. App and deployment
security problems live on</li><li>
Credit cards are the devil, and should be treated as such :)</li></ul>
Thanks Roberto and Lech for organising, I'm looking forward to next year!<br /><br />
Kirk<br /><br /><p /><img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=ec0e1324-3840-43c9-854f-d0d49822d4e9" /><xhtml:img xmlns:xhtml="http://www.w3.org/1999/xhtml" src="http://feeds.feedburner.com/~r/pageofwords/~4/pilo-x4IAUc" height="1" width="1" /></body>
      <title>OWASP NZ Day 2010</title>
      <guid isPermaLink="false">http://pageofwords.com/blog/PermaLink,guid,ec0e1324-3840-43c9-854f-d0d49822d4e9.aspx</guid>
      <link>http://pageofwords.com/blog/2010/07/14/OWASPNZDay2010.aspx</link>
      <pubDate>Wed, 14 Jul 2010 21:54:01 GMT</pubDate>
      <description>I had fun attending &lt;a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010"&gt;OWASP
NZ Day 2010&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
There were 6 great sessions - plus Graeme and I presented a talk on encryption, and
how to develop applications using encryption:&lt;br&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/14/BrettMooreDontTryThisAtHome.aspx"&gt;Brett
Moore: Don't try this at home&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/14/RobertoSuggiLiveraniDefendingAgainstApplicationLevelDoSAttacks.aspx"&gt;Roberto
Suggi Liverani - Defending Against Application Level DoS Attacks&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/PaulCraigWhatToDoWhenYouGetPwned.aspx"&gt;Paul
Craig: What to do when you get pwned?&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/MetlstormLowScuttlingChillicrab.aspx"&gt;Metlstorm:
Low Scuttling Chillicrab&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/GraemeNeilsonKirkJacksonTalesFromTheCrypt0.aspx"&gt;Graeme
Neilson / Kirk Jackson: Tales from the Crypt0&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/QuintinRussMikeJagerHostingAndSecurity.aspx"&gt;Quintin
Russ / Mike Jager - Hosting and Security&lt;/a&gt;
&lt;br&gt;
&lt;a class="TitleLinkStyle" rel="bookmark" href="2010/07/15/DeanCarterRamblingsOfAnExQSA.aspx"&gt;Dean
Carter: Ramblings of an ex-QSA&lt;/a&gt;
&lt;br&gt;
&lt;br&gt;
I came away with that feeling of satisfaction where you know you've learnt lots, but
haven't had time to digest and process it all yet. Some of my immediate takeaways
are:&lt;br&gt;
&lt;br&gt;
&lt;ul&gt;
&lt;li&gt;
Input validation is still a big area of problems in most apps&lt;br&gt;
&lt;/li&gt;
&lt;li&gt;
Application bugs and inefficiencies can be vectors for denial of service attacks&lt;/li&gt;
&lt;li&gt;
If you get pwned, hacked or DOS'd, you need to have a plan of what you're going to
do to recover, and if there's a chance that you need law enforcement involved, you
need to get a forensic analyst involved very early on (preferably in advance)&lt;/li&gt;
&lt;li&gt;
There are lots of computers on the internet in NZ, and lots of them have obvious vulnerabilities.
No-one is doing anything about this (at least, no-one &lt;i&gt;good&lt;/i&gt; is doing anything
about this!)&lt;/li&gt;
&lt;li&gt;
Bad development practices lead to problems in the hosting environment. App and deployment
security problems live on&lt;/li&gt;
&lt;li&gt;
Credit cards are the devil, and should be treated as such :)&lt;/li&gt;
&lt;/ul&gt;
Thanks Roberto and Lech for organising, I'm looking forward to next year!&lt;br&gt;
&lt;br&gt;
Kirk&lt;br&gt;
&lt;br&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;img width="0" height="0" src="http://pageofwords.com/blog/aggbug.ashx?id=ec0e1324-3840-43c9-854f-d0d49822d4e9" /&gt;</description>
      <comments>http://pageofwords.com/blog/CommentView,guid,ec0e1324-3840-43c9-854f-d0d49822d4e9.aspx</comments>
      <category>Security</category>
    </item>
  </channel>
</rss>

