B La C K H a T B R Ie Fin
Total Page:16
File Type:pdf, Size:1020Kb
SensePost b l Automation - Deus ex Machina or Rube Goldberg Machine? a How far can automation be taken? How much intelligence can be c embodied in code? How generic can automated IT security assessment tools really be? This presentation will attempt to show which areas of attacks lend themselves to automation and which k aspects should best be left for manual human inspection and analyses. SensePost will provide the audience a glimpse of BiDiBLAH - an h attempt to automate a focussed yet comprehensive assessment. The tool provides automation for: a • Finding networks and targets • Fingerprinting targets • Discovering known vulnerabilities on the targets t • Exploiting the vulnerabilities found • Reporting Roelof Temmingh is the Technical Director of SensePost where his primary function is that of external penetration b specialist. Roelof is internationally recognized for his skills in the assessment of web servers. He has written various pieces of PERL code as proof of concept for known r vulnerabilities, and coded the world-first anti-IDS web proxy “Pudding”. He has spoken at many International Conferences and in the past year alone has been a keynote speaker at SummerCon (Holland) and a speaker at The i Black Hat Briefings. Roelof drinks tea and smokes Camels. Haroon Meer is currently SensePost’s Director of e Development (and coffee drinking). He specializes in the research and development of new tools and techniques for network penetration and has released several tools, f utilities and white-papers to the security community. He has been a guest speaker at many Security forums including the Black Hat Briefings. Haroon doesnt drink tea or smoke camels. i Charl van der Walt is a founder member of SensePost. He n studied Computer Science at UNISA, Mathematics at the University of Heidelberg in Germany and has a Diploma in Information Security from the Rand Afrikaans University. He is an accredited BS7799 Lead Auditor with the British g Institute of Standards in London. Charl has a number of years experience in Information Security and has been involved in a number of prestigious security projects in Africa, Asia and Europe. He is a regular speaker at seminars s and conferences nationwide and is regularly published on internationally recognized forums like SecurityFocus. Charl has a dog called Fish. b l a c k h Assessment automation: Deux ex Machina || Rube Goldberg a Machine? 2005 t LAS VEGAS b r Introduction i SensePost has done hundreds of external assessment e Tried and trusted methodology So…in search of an automated assessment tool f This talk is about: • What is this methodology? • Can it be automated? i • Where does automation really work well? n • Where does it simply sucks? • Why does it fail? (and can it be corrected?) • Implications for penetration testers g s digital self defense b l Principles of automation a To have an automatic process we need to code it To code it we need to have an algorithm or flow In order to have an algorithm or flow it we need to c understand the process To understand the process we need to have done it many times k If you cannot write the process down on paper you probably don’t understand it completely h Exceptions on the rule – the root of all evil Tradeoffs – if it will work in 99.99% of cases and a will take me 2 months to code support for the 0.01% of cases…is it worth it? t b r Weird perceptions i e Unix good….Windows baaaad! (meeaaaaa) ‘Hard core’ hackers will tell you that Windows sucks. f GUI apps limit you to do complex things Problem is not the OS – it’s the implementation of the GUI People think that, because it’s a GUI app, it needs to be “dumbed down” i People think that, because it’s a GUI app, it needs to user friendly n People think that, because it’s a GUI app, stupid people will use it Unix tools are mostly “fire and forget” Unix tools have difficulty showing progress g Unix makes it hard to write X11 interfaces – so ppl stick to text based interfaces BiDiBLAH uses “hot” text boxes – you can copy and paste & grep and s awk and sed all you wish digital self defense b l The demos you are about to see… a BiDiBLAH is a tool for doing attacks/assessments Its built for large networks c …we don’t have a large network …but our clients do …but we don’t want to show their network k …no...we don’t…really… SO: h Passive: IBM,Playboy Active: SensePost/VMWare a There’s just too much risk in doing this live …but everything you see is real t (some time lapse in places – I’ll tell you where) b r SensePost external methodology i e f i Vulnerability Penetration Footprinting Finger printing Targeting discovery testing n g s digital self defense b l Methodology: Footprinting a c k Find Find forward Find netblocks/ Find reverse Perform vitality Find domains sub domains DNS entries Define netblocks DNS entries testing h a t b r Methodology:Footprint:Find domains i Initial domain e f TLD expansion Name expansion Related domains i Content n matching Network (MX/NS/IP) g matching Meta data Final domain s matching list digital self defense black hat briefings Fu Google Google keywords Domain Contains Subdomains main domain? digital self defense digital Methodology: Footprinting: Find subdomains Methodology: Footprinting:Find Video Video – BiDiBLAH’s footprinting : Sub domains Hit lists possible? ll forwards Domain / T subdomain A Z MX/NS records Perform forward digital self defense digital yes Video Video – BiDiBLAH’s footprinting Forwards : Methodology: Footprinting: Forward DNS entries black hat briefings b l Methodology: Footprint: Netblocks a Trim forwards to c class C Whois k Find the AS Find other Clean routes netblocks Additional in the same AS blocks: ARIN h RIPE APNIC LACNIC AFRINIC Inspect reverse a entries t b r Video – BiDiBLAH footprinting : NetBlocks i e f i n g s digital self defense b l Methodology: Footprint: Reverse DNS a Netblocks c To netblocks Perform reverse for each IP in block k Filters Unmatched no Match filter? entries h yes Extract domain Matched Extract domain entries a More More related Do we have name no domains the domain? expanded domains t b r Demo – BiDiBLAH’s footprinting : Reverse DNS i e f i n g s digital self defense b l Methodology: Footprint: Vitality a Netblocks c Port hitlist k TCP scans UDP scans ICMP scans h a IP list t b r Vitality : Async scanning i e Sniffer f Send SYNs SYN ACK Flags & SRC RST port i n Open ports Closed ports g Send FIN s digital self defense b l Video - BiDiBLAH – Vitality (SensePost network) a c k h a t b r Final domain Initial domain Google list keywords Name Related TLD expansion expansion domains Google Fu i Contains main domain? Content matching MX/NS records e Network (MX/NS/IP) Subdomains matching ZT possible? Meta data Hit lists matching yes f Perform forward Trim forwards to All forwards class C i Whois Find the AS Clean Find other routes netblocks in the same AS Additional blocks: ARIN n RIPE APNIC Inspect reverse LACNIC entries AFRINIC Port hitlist Perform reverse for each IP in g block TCP scans UDP scans ICMP scans Unmatched no Match filter? entries IP list Filters yes s Extract domain Matched Extract domain entries More related domains Do we have More no the domain? name expanded domains digital self defense b l a w c e i v t n e r k e f f i d a – h g n i t n i r p a t o o F t b r Automation of footprint i Pheeww…glad that’s over! e Which steps are difficult to automate & why? • Domain finding f • works semi OK, but never complete [not implemented] • currently, you can learn a lot from reverse entries • Sub domain finding – easy - [DONE] i • Forwards – easy - [DONE] • Netblocks – difficult… n • AS expansion is not always good for smaller (hosted) blocks. • Whois info on these blocks are pretty unless. • No standard interface to registrars g • [Currently set to manual] • Reverse scans – easy - [DONE] • Vitality – easy [DONE (tcp only)] s digital self defense b l SensePost external methodology a c So, where are we now? k Vulnerability Penetration Footprinting Finger printing Targeting discovery testing h a t b r Methodology: Fingerprinting i e OS detection from the Internet to a firewalled host is difficult…Not just technically, but conceptually : f An Apache box protected by a FireWall-1 running on Win32 and 1:1NAT will report itself as a Windows machines on a network level…but as a Unix machine on app level..so what will it be?? i BiDiBLAH does not try to do OS detection, but rather just do banner grabbing n Using Async banner grabbing for 21,22,25,80,110,143 Multithreaded 443 (SSL) g Any banner/version can be grabbed asynchronously but it gets increasingly tricky.. s digital self defense b l Async banner grabbing – the process a Right SRC Sniffer port? c Send SYN Is FIN? Is SYN ACK? Is ACK? k Send FIN/ACK Send ACK Port 80? 0 Extract banner h 1 Extract banner Port 80? from HTTP header a Send GET / HTTP/1.0 t b r Video - BiDiBLAH: Async banner grabbing i e f i n g s digital self defense b l SensePost external methodology a c So, where are we now? k Vulnerability Penetration Footprinting Finger printing Targeting discovery testing h a t b r Methodology: targeting i With a great deal of potential targets, we want to be able to select e only those that really interests us.