Saturday, 7 May 2016

Red Team Case Study

A red team exercise involves completely reimagining the traditional penetration test and vulnerability analysis. Rather than examining individual components of the security model in isolation, red teaming simulates a real criminal attack under controlled conditions. These tests mimic the real-world targeted attacks that businesses face on a daily basis, using a goal-based engagement that delivers the true business impact of a breach.

Our client engagement started with a threat and risk analysis, personalised to the business, to identify real-world attackers, their motivation, their skills and likely avenues of attack. Once the most likely and damaging threats had been identified, scenarios were created that the staff of the organisation would recognise as real and pertinent to their company.

Each scenario began with an information gathering and reconnaissance phase to identify potential weaknesses in physical premises, staff members and Internet-facing technology. Premises were located and reviewed online to produce a short-list for further examination in person. On-site reconnaissance of selected buildings was used to plan a more detailed, multi-staged operation.

The organisation’s registered domains, address ranges and Internet hosts were examined, exposing the software in use, and finding public-facing systems such as Outlook Web Access. Internet searches harvested email addresses and associated employee information from sites such as LinkedIn. Emails were sent to elicit responses containing the company’s official style and layout.

A spear phishing campaign was mounted, using email addresses discovered in the information gathering phase, with fake domain names and cloned sites facilitating password theft.

The stolen credentials were then deployed in an on-premises attack against a branch office. Physical access to premises was facilitated through a combination of impersonation and telephone pretexting. Subsequent network access using the phished passwords permitted theft of information from a variety of servers and also demonstrated persistent remote access through technical exploits.

More sophisticated on-premises attacks were then designed to test visitor controls and desktop security at head office. Scenarios were developed with team members having fully-developed ‘legends’ (back stories) for each engagement. The stories selected entailed impersonation of a potential customer requiring a tour of a facility, and another masquerading as a member of the press researching the charitable activities of the business. Carefully planned emails and phone calls resulted in a legitimate appointment at head office. Once on site, one team member kept staff occupied in a business meeting while another excused themselves for a ‘comfort break’ and took the opportunity to look for unprotected computers and to plant a remote control device on the network. That team member was never challenged during their excursion and found unlocked offices containing unattended and logged-on computers.

This threat-based approach highlighted vulnerabilities that otherwise would have been missed or perhaps not even considered during a typical ‘due diligence’ exercise. It delivered critical results for a modest outlay in time and expenditure. Red teaming is not an alternative to traditional testing, but it is a very valuable additional activity.

There was also the opportunity to use the results of the red team exercise as the basis for world-wide security awareness training. Presentations based on these simulated criminal attacks engaged people in a fashion completely unlike traditional training. Because the audience was following a story, and because that story was genuinely relevant to their organisation, it was possible to raise the bar on that most difficult of security controls - the human firewall. Security awareness at all levels was increased significantly and staff members became security evangelists in their own right.

Further red team exercises will build on this exciting precedent and provide more engaging stories to continue the education of everyone in the organisation.

Tuesday, 26 January 2016

Windows Password Issues

How Long is Strong?
You might imagine that a seven character password is very difficult to crack. However, if we were to try guessing every possible seven character password using an automated tool, it would take just two days to work through all the permutations on a typical desktop PC.
Even worse, most people choose simple passwords - perhaps using the name of their partner with a number appended, or some other word commonly found in a dictionary. An attacker with the right software can try most words and proper nouns, each with one or two numbers appended, in just a few minutes.
It Gets Worse ... 
There is another threat to Windows passwords: rainbow tables. Putting it simply, these are lists of passwords with their encrypted equivalents, making the process of finding a password very fast indeed. Since the tables contain both the encrypted password and its corresponding plain text, you are effectively looking up the password rather than needing to guess it.
The only restriction for rainbow tables is size - the longer the password you are trying to guess, the larger the tables need to be.
What About 'Complex' Passwords?
The traditional response to the problem of weak passwords is to encourage users to use a combination of random letters, numbers and symbols.
Unfortunately, such passwords are impossible for the average person to remember, resulting in other serious problems such as passwords being written on post-it notes or hidden under the keyboard where even inexperienced attackers can find them.
If you decide to make a complex password memorable,  
What's the Answer?
The maximum length of a Windows password was increased to a massive 127 characters many years ago. Although the 'change password' dialogue box limits you to 32 characters, this still makes long, secure passwords possible.
So, instead of trying to memorise a complicated string of numbers, letters and symbols, envisage the password as a passphrase.
A phrase such as “I.love.green.tomatoes” is very easy to remember, yet all but impossible to crack using any automated tools.
Isn't it time you considered switching to passphrases?
More Info
Get your copy of the full Windows passwords white paper

Monday, 11 June 2012

Peru Trek

Caroline, our intrepid Office and Accounts Manager, has decided to support a worthwhile cause by trekking the Inca Trail to Machu Picchu on behalf of Wave 105 Cash for Kids (Registered charity number: 1122062)

This is a great charity, committed to supporting local children under the age of 18, who are financially, socially, emotionally or physically disadvantaged. They encourage children to participate in activities outside of school that can engage, spark their imaginations, and help increase their self confidence through art, music or any sport they are passionate about.

To support Caroline, follow the link to her donations page:
http://everydayhero.co.uk/caroline_mathieson

Tuesday, 17 April 2012

After a year of blogging apathy, I decided it's time to write a new entry. What prompted me is an interview I did for Infosecurity Europe about social engineering and blended attacks just recently. It's now up on YouTube, so take a peek and let me know what you think!

Tuesday, 29 March 2011

Cloud Security Alliance UK & Ireland

I am delighted to have been appointed to the executive board of the new UK & Ireland chapter of the Cloud Security Alliance. I'm Chair of the Advisory Board which will give me plenty to work on over the next few months! I gave the keynote at our inaugural chapter meeting last week and really enjoyed the feedback and audience participation. Our next event is on Thursday 21 April when we are hosting a summit in London, inside Infosecurity Europe 2011.

Thursday, 3 March 2011

Cyber Security In Real-Time Systems and CNI

I'm going to be speaking at an event focused on cyber security threats and protection strategies for real time and critical national infrastructure (CNI) systems in Reading on 18 March. This subject area is finally getting some attention since the Stuxnet worm and I'm keen to help give some pragmatic advice.

09:30 - Coffee reception
10:00 - Welcome address
10:15 - CSIRS Threat Analysis and Actions
11:00 - Security Testing in Critical Systems
12:00 - Q&A Panel discussion
12:30 - Closing remarks
13:00 – Lunch

For more information contact David Spinks, Chairman of CSIRS at dspinks41@gmail.com

Saturday, 12 February 2011

Cloud Security Alliance UK and Ireland

Good news for those of us involved in cloud security in this part of the world: the UK & Ireland Chapter of the CSA is now up and running. As an executive board member I'm keen to spread the word of course. If you are interested in cloud security, follow this link to the LinkedIn group - it's free to join. Go on - you know you want to :-)

Tuesday, 18 January 2011

A Software Engineer, a Hardware Engineer and a Departmental Manager ...

A Software Engineer, a Hardware Engineer and a Departmental Manager were on their way to a meeting in Switzerland. They were driving down a steep mountain road when suddenly the brakes on their car failed.

The car careered almost out of control down the road, bouncing off the crash barriers, until it miraculously ground to a halt scraping along the mountainside. The car's occupants, shaken but unhurt, now had a problem: they were stuck halfway down a mountain in a car with no brakes. What were they to do?

"I know", said the Departmental Manager, "Let's have a meeting, propose a Vision, formulate a Mission Statement, define some Goals, and by a process of Continuous Improvement find a solution to the Critical Problems, and we can be on our way."

"No, no", said the Hardware Engineer, "That will take far too long, and besides, that method has never worked before. I've got my Swiss Army knife with me, and in no time at all I can strip down the car's braking system, isolate the fault, fix it, and we can be on our way."

"Well", said the Software Engineer, "before we do anything, I think we should push the car back up the road and see if it happens again."

(With thanks to John Mitchell)

Saturday, 1 January 2011

Festive Greetings

Season's greetings dear readers - it been a while, thanks to a combination of overwork and illness, but here at last is a new posting from FPWS. I'll make it simple and festive:
http://www.youtube.com/watch?v=CDTjXjQJ75o

Happy New Year to everyone!

Tuesday, 26 October 2010

Fighting malware in your browser

I've mentioned Team Cymru before. Now I want to draw your attention to their Malware Hash Registry (MHR) project and in particular their add on for Firefox. This must be the simplest and most effective way of ensuring your downloads are free of malware - and it's free. Just check it out

Friday, 27 August 2010

Vote for us!

Exciting news for First Base Technologies - we've made the final in the "Security Service Provider of the Year" category of the Computing Security Awards based on volume of on-line nominations.  Voting is now underway.

Please consider voting for us at www.computingsecurityawards.co.uk - use the drop down menu under Security Service Provider of the Year and cast your vote!

Thanks!

Thursday, 5 August 2010

Personal mobile devices

I was recently invited to a roundtable event to discuss the results of some research sponsored by Sourcefire. Part of the survey results concerned the use of personal mobile devices, which seems to be a hot topic with many of our clients. Here's a summary of the findings:
  • 69 percent of UK employees use their own personal devices for work-related purposes, and 71 percent move data on and off the corporate network via these devices, and almost all carry out activities that could put company data at risk. 96 percent of senior managers and directors use personal devices for work tasks.
  • 83 percent of employees admit such actions pose a risk to their organisation’s IT security, but if banned, 1 in 3 would just carry on using them regardless. In fact, 27 percent believe the company should be grateful that they are so conscientious.
  • 63 percent of senior managers / directors use their personal devices to move information off the corporate network and 95 percent of people use their personal devices to carry out activities that could put data at risk – such as Internet shopping and social networking.
  • 98 percent of employees also have a personal email account and during the last 12 months, 1 in 4 employees have used it to achieve work-related tasks. The most common being to send urgent emails when the corporate email has been down (18 percent) whilst 12 percent have used it to receive legitimate work documents that were being blocked by the company firewall.
It looks like we'll all be in the security business for a long time to come!


Tuesday, 1 June 2010

May 2010 ramblings

I see it's been almost two months since my last blog entry. What poor discipline - sorry. Things have been really hectic here at First Base Technologies, which is my only excuse.

This year's Infosecurity Europe was the best for many years - we invested in a new and larger stand and more staff and the results speak for themselves. Lots of visitors with a better appreciation of what penetration testing is all about and how it fits into PCI-DSS. Better informed discussions about penetration testing as part of Governance, Risk and Compliance too.

Today I had an excellent meeting with Claranet who provide secure hosting in a private cloud. Just what we need - a guarantee of where our data resides for compliance with Data Protection coupled with a cast-iron SLA. And they provide secure networking too. Great stuff.

Thursday, 4 March 2010

Hot topics for 2010 - discuss!

I've just been asked for my "hot topics" in infosecurity for 2010, so I thought it would be interesting to throw these out at you and see what you think, so here goes:

1. Security awareness
It's increasingly obvious that technical controls alone are not providing organisations with the security they need. Staff education and awareness, delivered in a creative and imaginative way, is critical to managing information security in 2010.

2. Cloud computing
Few organisations are giving serious consideration to the security risks inherent in the cloud computing model. Whilst day-to-day operations can be outsourced in this way, the responsibility for security cannot. A combination of technical, legal and audit skills are required to ensure the security of data in the cloud.

3. Defense against cybercrime
Organisations continue to underestimate the devious nature of cyber criminals and have little or no commitment to "thinking like a hacker". This mind set is critical in order to apply budget and resources to the areas where criminals are most likely to attack and to counter their methods effectively.

Opinions anyone?

Monday, 18 January 2010

A Happy New Year for data protection?

UK readers may have noticed that the Information Commissioner’s Office (ICO)­ will have new powers to fine organisations responsible for security breaches from 6 April 2010. Fines of up to £500,000 can be imposed for serious breaches of the Data Protection Act. The ICO press release is here.

Jonathan Armstrong of Duane Morris, with whom I've shared several conference platforms, thinks this will make CEOs and other senior people take more notice and should make some IT security budgets less prone to cuts. As he says, "If the ICO can levy some decent fines early on, people may take more notice." His article is here.

We can only hope that tougher UK legislation will start to make a difference to the lackadaisical attitude of some senior people towards security!

Friday, 27 November 2009

BCS ELITE annual dinner

Last night I attended the BCS ELITE annual dinner - the first for several years, but well worth the wait. It was a black tie event at the Landsdowne Club, where the food and wine was excellent, and the latter flowed in quantity (hence feeling rather fragile today). I was really pleased to find that I was sharing a table with the always entertaining Lord Renwick and his lovely Lady, as well as several other intelligent and erudite folk. What a good start to the festive season :-) This post isn't really much to do with security, but I would recommend ELITE to anyone interested in good conversation and networking with IT people.