Monday, February 8, 2010

Phishers steal CO2-emission certificates

When I was looking through my RSS feeds this morning I came across an article from WebWereld where they talked about the fact that phishing is also used for stealing CO2-emmision certificates.

These certificates are issued for free by the EU and companies trade them between each other, just to be able to pollute more. The day price at the moment they where stolen was 2,5 EUR a piece.

It makes makes no sense to me at all. If I understood the article correctly the certificate does not impose CO2-emission limitations to companies. So basically it is normal that the EU would ask nothing for this certificate, because it does not give you any privileges.

Isn't it kind of weird then that a company is ready to pay 2,5 EUR for something that actually doesn't do anything for your company? The funny part is then that people start stealing these things. It kind of remind me when I was at school and saw kids fight over little plastic disks called flippo's.

Saturday, January 16, 2010

OpenVPN workshop

Today there was an OpenVPN workshop at the Hackerspace Brussels. The workshop was given by Christophe Vandeplas. The first part of the workshop was the theoretical part. The nice thing about the setup was that you did not need any knowledge about networking or VPN.

Christophe took us all through the basics, starting with "how 2 systems talk over a switch" over "how to machines talk over a router" and then going to firewalls, NAT and of course VPN and everything that goes with it.

The second part of the workshop was actually setting up an OpenVPN system. It was really a step by step walktrough.

It was was a great afternoon where I learned a lot. The presentation can be found here. Christophe has also a how-to about the Belgian eID and OpenVPN.

Saturday, December 26, 2009

Airport security, you are kidding, right?

I have not posted anything in a while because I was sometimes not inspired to write anything, sometimes too busy or sometimes just on holiday. My latest holidays were in Spain and while going trough airport security here in Charleroi Airport (a.k.a Brussels South) I declined the metal detector alarm. I was absolutely sure that I had removed any of the non-permitted objects and had no clue what declined the alarm.

The classic procedure then started ... please step through Sir. The security staff member asked me if I had anything on me that could have triggered the alarm. I replied no and than I assumed the position for a check. The guy did it reasonably correct but he forgot to check the lower part of the abdomen. I know most people would not be comfortable about this.

Since the procedure had no result, a hand detector was the next procedure. Funny because the only thing it found was the metal parts that every jeans has so with some logic everybody wearing jeans would have triggered the alarm. This was not the case so in my mind that was not what triggered it but I was cleared and off to catch my flight.

When I had my flight home I was dressed exactly the same way but I made sure that my clothes did absolutely not have any metal parts. You guess it ... I triggered the alarm again :). Yes I was very happy because I was consistent.

The guy started his search, he didn't find anything so I had to put each foot in some kind of sniffer machine (too bad I forgot to look at the brand) . When I got cleared it suddenly became clear to me the only thing I had on me and was made of metal is the frame of my glasses.

If I was really up to no good I would not have made such a 'mistake' but it is clear to me that those security people have no procedure in place for the cases that don't fit the procedure and actually I personally think that is scary.

Thursday, October 22, 2009

Belgian national infrastructure client

The last couple of days I was on site at a customer that is one of the big players in the Belgian national infrastructure. I am just there to help out roll out some systems, not as a DBA or a security guy but ... I had my little fun.

The first thing I noticed when I got in was that with just a name drop and telling that I am an IT guy the friendly guy at the front desk opened the doors. No calling to verify my story, just walked on the site to the other buildings. Always be polite and ask for directions smiling :).

Then I got to the building of the IT department and first thing I noticed where all the print outs on the walls, one of them was a procedure with a password on it ... sweeeet.

Later that day I got an email with my login credentials. Yes my dear reader, plain text passwords emailed over the dhcp network. I was asking my new colleagues if I was the only one thinking that it shouldn't be that way but apparently they did not understand the problem.

Now I have access badges and can come in through the employee entrance. At the entry point there is a security guard to open the gate for the cars and verify the people walking in. The only problem is, the guy is about 6 meters from you when you show your badge. The badge is a classic (white) RFID card with the company logo and your name printed on it. Just by curiosity I showed the guy a membership card of something else that is red and blue and got in smiling.

But the customer is security-aware ... they are doing an audit of their email system at the moment, they have firewalls, anti-virus and VPNs.

Sunday, September 27, 2009

Python workshop at HSB

Yesterday I went to a python workshop organized at the hackerspace Brussels. We gathered at the void*pointer around 14 hours. fs111 gave us a very nice introduction to python.

There where programmers and people who who had not programmed in ages but it was ok. You could ask any question you had and there were some exercises, classics like the number guessing games, to get you up and programming.

We have a home work assignment, writing a very simple port scanner :). Have a look at the hackerspace website if you want to join for the follow up.

My conclusion is simple python is a very powerful language, easy to learn (that is the credit of the instructor) and it is worth to sit down an afternoon and learn it. It will be certainly become a weapon of choice to handle some of my day-to-day admin problems.

Monday, August 31, 2009

Getting to know your target: find a job

Introduction
There are 2 ways of gathering information. You can go for passive reconnaissance or active reconnaissance. Recon can be done online but there is no reason that it can't be done offline.

During passive recon you go after the information that is out there? It is either out there intentionally or leaked. You do not engage any contact with the other party. You try to discover information about the organization, the employees, the third parties, the systems, naming conventions, ... anything that you can lay your hands on.

The active form of information gathering is the part where you engage a limited form of contact. Nothing intrusive but just enough to get a better view on the other party.

I don't know who you are and if the knowledge in this article can get you in trouble with the law but I suggest you only try these techniques on your own infrastructure or one for which you have the necessary (written) permissions.

The idea behind this articles is to get feedback, so give me your side on the story. If you think I am wrong, tell me and if you agree or want to add something let me know too.

Relations
Organizations do not exist on their own. In the real world you got suppliers, customers, users, ... you get the idea. One of the ways to reveal this is just visit the website of your target and look for company info.

To look for an example I got on one of the large ISP's in Belgium their website and found this out:
- The members of the different boards: names and functions
- The have a daughter that is a hosting company
- Locations of different company locations
- Their logos and for what they are used
- Customer service, communication department info
- Phone numbers
- The use of webeventservices.com for communication
- The email address of the VP Corporate Counsel is firstname.lastname@staff.companyname.be
- The list of the different analysts in all major financial institions that follow the company and conviently their email addresses
- subdomains
- department names
- Jobs and these contain information about the systems they use

They use:
Cognos (7, Series 8, Powerplay, BCM), BO, SPSS, SAS, MS Outlook, MS Office, Salesforce.com (CRM), IBM Ascential Datastage, Oracle databases, Java, J2EE, MS Sharepoint 2007, Windows 2000 Server & Advanced Server, Windows 2000 Professional, Windows 2003 Server, Windows Vista, VMWare, Juniper & Alcatel backbone routers, linux, solarix, AIX, DNS, DHCP, POP3, SMTP, http, LDAP, IBM & Sun application servers (java), ...

This information was gathered just by looking around on their website, but the next step I use is by looking at jobsites if I can find anything on that company. For this example I used one of the most popular job sites in Belgium called vacature.com and it returned 12 job openings. On another jobsite called monster.be I found other information and stuff like what the interim offices they use.

To manage all the information I gather I use mind-mapping software. Since I like open source I looked for a good open source one and personally I like Freemind.

Next post will be about BiLE from Sensepost. A nice tool suite to get more info about relations between websites.

Monday, August 17, 2009

HAR2009

I've been to HAR2009 and it was the first security conference I've ever been to. It was great, it was on a camping site and there where 2000 tickets sold. I met a lot of interesting people and went to quite some cool presentations. Not all topics where technical infosec topics, but that was okay. Next conference will be BruCon and I'm looking forward to it.

I've your in the neighborhood of Brussels and want to meet nice people at a hackerspace make sure to drop by the Hackerspace Brussels (HSB). For those who don't know what a hackerspace is, just come. The people you'll meet are not the ones who'll break into your bank.