Minggu, 16 Mei 2010

Review of Cyberpunk Posted

Amazon.com just posted my four star review of Cyberpunk by Katie Hafner and John Markoff. From the review:

Cyberpunk is a unique exploration of three distinct digital security stories. Authors Katie Hafner and John Markoff describe the histories of Kevin Mitnick and friends, Hans Heinrich Hübner and the Hannover hackers, and Robert T Morris and family. This approach is interesting because all three tales are told independently, yet key events occur within a few years of each other and some overlap...

I don't usually include material beyond the first paragraph from my review announcements, but I loved these excerpts:

I'd like to conclude by citing some of my favorite excerpts. First, when describing Digital's Palo Alto security, the authors write:

"[I]n recognition of the open-mindedness back at corporate headquarters, the computer scientists in Palo Alto took great care to operate their precious gateway responsibly. To give the best possible oversight both for maintenance and security, Ph.D's in computer science took turns poring over daily log files... So it was only a matter of hours after the intrusions into the Palo Alto computers began that the gateway watchers there noticed something amiss." (emphasis added) p 118

Second, when expressing frustration with Digital's inability to counter the intruders, the authors quote "one irate Digital employee":

"We seem to be totally defenseless against these people. We have repeatedly rebuilt system after system and finally management has told the system support group to ignore the problem... I want to make sure someone at network security knows that we are being ***** (censored) in broad daylight. These people freely walk into our systems and are taking restricted, confidential, and proprietary information." (emphasis added) p 120

Third, nothing changes:

"Digital might be reluctant to press charges... [F]ew of the computer crimes detected were ever reported to the police and still fewer were made public through criminal charges... [C]ompanies worried about having their vulnerabilities publicized." p 125

Though nearly 20 years old, Cyberpunk still shares many traits with the modern digital security world.

Review of The Hacker Crackdown Posted

Amazon.com just posted my five star review of The Hacker Crackdown by Bruce Sterling. From the review:

Bruce Sterling's book The Hacker Crackdown (THC) captures the spirit and history of the "hacker scene" in the late 1980s and early 1990s. Having lived through that period with my C-64 and first 386 PC, I thought the author accurately describes what it was like for computer users during that era. THC is one of my favorite books on hacker activity because it combines a narrative with the author's accounts of interactions with key individuals. THC expertly tells several stories from multiple perspectives -- hacker, law enforcement, security professional, telecom operator, even homeless man-on-the-street! The author also manages to not offend technically-minded readers while describing material for non-technical audiences.

Sabtu, 08 Mei 2010

Everything I Need to Know About Leadership I Learned as a Patrol Leader


This post is outside the digital security realm, but I know a lot of my readers are team members and team leaders in their technical shops. I thought it might be useful to share a few thoughts on leadership. I don't claim to be the world's best leader but I've been thinking about the topic recently.

I've participated in a lot of "leadership training" over the years, in and out of classrooms. A few examples: I've attended classes at GE's Crotonville, earned a master's degree from Harvard Kennedy School (supposed home to future political leaders), led a flight in the AFCERT, served as a cadet flight commander at USAFA, and captained my high school track team. As the years have progressed I find fewer of these experiences, especially formal training, to be novel or particularly helpful. For example, I believe the approaches I brought to my USAFA experience had less to do with USAFA and more to do with what I already knew. Tonight I decided to think back to where I first learned my "leadership style."

I realized that everything I needed to know about leadership I learned as a Patrol Leader, as a Boy Scout. Patrols are the core unit of the troop; they are the unit within a troop that can conduct independent activities, although they collaborate with other patrols during troop-wide events. I spent about 10 years as a Scout (starting as a Cub) and finished (barely) with my Eagle award a few months before I turned 18. My troop first nominated me to become a Patrol Leader when I was about 12.

I distinctly remember being a Patrol Leader twice. I led one patrol for my normal troop when I was younger, and then I was nominated to be a Patrol Leader for a regional troop from Massachusetts that attended the 1989 Scout Jamboree when I was 17. I cherished this second experience, because I was basically inactive during the ages of 15 and 16, due to high school. In both cases my patrol probably consisted of no more than 12 kids, usually younger but not always.

So what did I learn as a Patrol Leader? Check out these Ten Tips for Being a Patrol Leader from Scouting.org:

  1. Keep Your Word. Don't make promises you can't keep.

  2. Be Fair to All. A good leader shows no favorites. Don't allow friendships to keep you from being fair to all members of your patrol. Know who likes to do what, and assign duties to patrol members by what they like to do.

  3. Be a Good Communicator. You don't need a commanding voice to be a good leader, but you must be willing to step out front with an effective "Let's go." A good leader knows how to get and give information so that everyone understands what's going on.

  4. Be Flexible. Everything doesn't always go as planned. Be prepared to shift to "plan B" when "plan A" doesn't work.

  5. Be Organized. The time you spend planning will be repaid many times over. At patrol meetings, record who agrees to do each task, and fill out the duty roster before going camping.

  6. Delegate. Some leaders assume that the job will not get done unless they do it themselves. Most people like to be challenged with a task. Empower your patrol members to do things they have never tried.

  7. Set an Example. The most important thing you can do is lead by example. Whatever you do, your patrol members are likely to do the same. A cheerful attitude can keep everyone's spirits up.

  8. Be Consistent. Nothing is more confusing than a leader who is one way one moment and another way a short time later. If your patrol knows what to expect from you, they will more likely respond positively to your leadership.

  9. Give Praise. The best way to get credit is to give it away. Often a "Nice job" is all the praise necessary to make a Scout feel he is contributing to the efforts of the patrol.

  10. Ask for Help. Don't be embarrassed to ask for help. You have many resources at your disposal. When confronted with a situation you don't know how to handle, ask someone with more experience for some advice and direction.


You don't need a MBA now, aside from some classes on financial statements. I'd also venture that many MBA classes don't cover these 10 points.

I remember being particularly keen on patrol spirit:

Patrol spirit is the glue that holds the patrol together and keeps it going. Building patrol spirit takes time, because it is shaped by a patrol's experiences—good and bad. Often misadventures such as enduring a thunderstorm or getting lost in the woods will contribute much in pulling a patrol together. Many other elements also will help build patrol spirit. Creating a patrol identity and traditions will help build each patrol member's sense of belonging.

I remember working on our patrol flag and being proud of our new identity. Never mind that we were "Wolverines" (yes, straight out of Red Dawn) but our flag had a panther or cougar on it. (Blame the T-shirt shop for not having a "wolverine" transfer.) We put our patches and name on that thing and that's all that mattered.

When I was about 14 my troop nominated me to become Senior Patrol Leader, which is the top boy leader. Unfortunately, it's like a management position, because while you lead the troop most of the activities happen at the patrol level. You end up being more of an intermediary between the adult leaders and the Patrol Leaders. It's an important job but I remember missing having my own patrol. That's one reason I was glad to get a Patrol Leader job with the regional troop attending the Jamboree in 1989.

My take-away from this post is to remember the 10 points outlined above when I work with my current team. It's been over 20 years since I left Scouting, but the lessons I learned there have proven to be timeless and enduring.

Papers Not PowerPoint, Plus Tips for Improvement

Recently I railed against PowerPoint. In this post I'd like to congratulate Black Hat and some of their Briefings speakers for submitting white papers, not just PowerPoint presentations.

This evening while cleaning out a tmp directory I noticed a copy of a white paper by IBM's Tom Cross from Black Hat DC 2010 titled Exploiting Lawful Intercept to Wiretap the Internet. The paper describes Tom's analysis of Cisco's implementation of CALEA for law enforcement-directed wiretaps. The paper is 18 pages, but the last 3 are basically citations. It's a great piece of work which I wish I had read earlier.

For me, this paper emphasized how much of a failure it is to try to deliver complicated information in PowerPoint form. I got more out of taking 20 minutes to read Tom's 15 pages of material than I could have trying to make sense out of his 41 slides. Tom is a good writer whose paper delivers solid arguments. Rather than just praise the paper and slam the PowerPoint, I'd like to show how Tom did use PowerPoint well so that I keep these ideas in mind when I need to brief audiences.

A speaker I listened to earlier this week said you can't expect an audience to take away more than one point from any slide, so why bother? In fact, if you adapt the ideas of the great Tufte, you should use PowerPoint only as a delivery mechanism for charts, diagrams, and other visuals.

Using this approach, the figure at right which appears in Tom's PowerPoint deck for Black Hat is just the kind of material that should appear in a PowerPoint presentation. You could imagine this diagram being in a handout given to the audience, but during the briefing Tom would no doubt want to point towards specific elements of the diagram while the audience watched. This justifies displaying the figure via PowerPoint, because it is the most effective medium for communicating the information.

I think the SNMP MIB extract displayed at left, also from Tom's PowerPoint, is justified as appearing in a slide. Tom isn't asking the audience to pay attention to every line on the slide, like someone might expect an audience to do with a slide full of bullets. Rather, Tom has highlighted two important excerpts, showing them as proof that within this MIB there are two elements which expose information to attackers. This information could also appear on a handout given to the audience. However, here I like seeing the information to prove Tom's point. It's almost like a "technical figure" for me.

On a related point, I did not see any PowerPoint posted for HD Moore's talk Metasploit and Money. However, HD posted a great 9 page white paper, which is archived. I think I already mentioned via Twitter that I enjoyed this paper, and I wonder if no slides were presented?

To summarize, if you're presenting complicated material, slides are generally not an effective delivery mechanism. At best they can supplement a briefing by being a vehicle for displaying figures or other visuals, but bullets are generally a waste of time. For details why, please see my posts on PowerPoint.

Jumat, 07 Mei 2010

Bejtlich to Speak at SANS Forensics and Incident Response 2010

I am pleased to announce that I will return for the third SANS WhatWorks Summit in Forensics and Incident Response in DC, 8-9 July 2010. Rob Lee sent an email stating I would be on the Advanced Persistent Threat Panel with Chris Glyer and Mike Cloppert, so I'm looking forward to participating. I might also have a solo presentation, but I haven't seen the agenda yet. This IR event is a great precursor to my next SANS WhatWorks Summit in Incident Detection and Log Management in DC, 8-9 December 2010.

Update: Agenda is posted. I will participate in two panels (Network Forensics, APT) and provide one briefing (CIRT-level Response to Advanced Persistent Threat).

The Face of Information Warfare

When information warfare happens, it's possible the victims will not recognize it as "warfare." I was reminded of this yesterday during the market selloff, which may have been caused by an error in trading. I'm not saying that the market selloff was an information attack. Rather, what we saw yesterday (an example appears in the screen shot -- Proctor and Gamble down 32% in the blink of an eye) reminded me of what an information attack might look like.

The NASDAQ is "recovering" by cancelling trades. However, how sustainable is that incident response? Are those who placed trades going to accept that response? In the future, what happens when traders can't trust what their systems display?

I'm looking forward to seeing the outputs of any investigation into this incident.

lsof for Windows subsitute

5/10/2010 update to this post (see below)
I've created a couple of Vista cmd files that pump netstat output to tasklist to help substitute for the missing`lsof -Ts` in Linux (see below). The TCP/TCPv6 output logs the time, IP address (foreign endpoint), application information. The (stateless) UDP/UDPv6 output just logs time and application information.  (See output below). The value of logging network endpoints and their process information is incalculable in security. Mark Russinovich's procmon (when run with the network filter) does this quite thoroughly.  Microsoft's Netmon 3.3 correlates endpoint data packets to most applications. However, I was interesting in developing something cmd line, perhaps not so heavy, using all native Vista commands. The crux of the scripts are:

:: pipe appropriate netstat output to tasklist
for /f "tokens=1-5" %%a in ('@netstat -%netstat_option% -p %connection_type% ^| findstr /V Active ^| findstr /V Proto') do set EP=%%c& set PID=%%e& call :loop
..
::log Endpoint and network process PID
@echo "%timestamp%","%EP%", | findstr /V "ECHO"
@tasklist /FO CSV /V /FI "PID eq %PID%" /NH


 With an automated check of network %PID% in place, you can add options to check/log the open files of each network application with the (very slow) 'openfiles' command:
[The 'openfiles' cmd works once global flags are enabled.]

for /f "tokens=1-5" %a in ('openfiles /query /FO TABLE /NH /V') do @if %c==%PID% echo %e >> temp
...
C:\Users\Admin\AppData\Local\Google\Chrome\Application\4.1.249.1064
...
Adding Mark Russinovich's accesschk will show the security permissions on those files:

for /f %i in ('more temp') do @accesschk -qv %i | more
....
C:\Users\Admin\AppData\Local\Google\Chrome\Application\4.1.249.1064\avcodec-52.dll
Medium Mandatory Level (Default) [No-Write-Up]
RW RMFVista\Admin
FILE_ALL_ACCESS
RW NT AUTHORITY\SYSTEM
FILE_ALL_ACCESS
RW BUILTIN\Administrators
FILE_ALL_ACCESS

....
The cmd files can be found here: 

http://www.rmfdevelopment.com/PowerShell_Scripts/ano_TCP.cmd
http://www.rmfdevelopment.com/PowerShell_Scripts/ano_UDP.cmd


5/10/2010 update:
An update which takes any of four arguments (TCP,TCPv6,UDP, UDPv6) and logs to a CSV file output as below can be found at http://www.rmfdevelopment.com/PowerShell_Scripts/ano_all.cmd
ano_all.cmd output for TCP
"05.10.2010_11.35.21.34","LISTENING","0.0.0.0:1029","0.0.0.0:0","services.exe","740","Services","0","9,532"
"05.10.2010_11.35.21.82","LISTENING","0.0.0.0:9000","0.0.0.0:0","System","4","Services","0","21,204"
"05.10.2010_11.35.22.34","LISTENING","192.168.0.3:139","0.0.0.0:0","System","4","Services","0","21,204"
"05.10.2010_11.35.22.84","CLOSE_WAIT","192.168.0.3:1059","174.133.89.198:80","pctsSvc.exe","856","Services","0","195,660"
"05.10.2010_11.35.23.33","ESTABLISHED","192.168.0.3:1072","85.13.200.108:21","ftp.exe","2568","Console","1","6,388"
"05.10.2010_11.35.23.82","ESTABLISHED","192.168.0.3:1080","74.125.155.139:80","chrome.exe","4404","Console","1","62,576"
"05.10.2010_11.35.24.31","ESTABLISHED","192.168.0.3:1082","72.14.213.191:80","chrome.exe","4404","Console","1","62,576"


ano_TCP.cmd output for TCP
(note: It would be trivial to add the connection state as well. I did in ano_all.cmd as remarked above -RMF)

"05.06.2010_21.30.31.74","174.133.89.198:80",
"pctsSvc.exe","3368","Services","0","24,588 K","Unknown","NT AUTHORITY\SYSTEM","0:15:51","N/A"
"05.06.2010_21.30.32.20","72.14.213.99:80",
"Picasa3.exe","4248","Console","1","128,588 K","Running","RMFVista\Admin","0:02:16","Picasa 3"
"05.06.2010_21.30.32.69","72.14.213.101:80",
"chrome.exe","4232","Console","1","79,432 K","Running","RMFVista\Admin","0:01:49","Network Security - Google Chrome"
"05.06.2010_21.30.33.15","74.125.127.191:80",
"chrome.exe","4232","Console","1","79,432 K","Running","RMFVista\Admin","0:01:49","Network Security - Google Chrome"
"05.06.2010_21.30.33.60","74.125.127.105:443",
"chrome.exe","4232","Console","1","79,432 K","Running","RMFVista\Admin","0:01:49","Network Security - Google Chrome"
"05.06.2010_21.30.34.12","74.125.127.139:80",
"chrome.exe","4232","Console","1","79,432 K","Running","RMFVista\Admin","0:01:49","Network Security - Google Chrome"


ano_UDP.cmd output for UDP   

(note: No foreign IP addresses ever shows up in Microsoft's netstat for protocol UDP...as far as I can tell.)

"05.06.2010_21.29.42.51","*:*",
"nc.exe","4120","Console","1","572 K","Unknown","RMFVista\Admin","0:00:00","N/A"
"05.06.2010_21.29.44.07","*:*",
"svchost.exe","1196","Services","0","3,400 K","Unknown","NT AUTHORITY\LOCAL SERVICE","0:00:01","N/A"
"05.06.2010_21.29.44.50","*:*",
"svchost.exe","636","Services","0","52,188 K","Unknown","NT AUTHORITY\SYSTEM","0:07:36","N/A"
"05.06.2010_21.29.44.99","*:*",
"svchost.exe","636","Services","0","52,188 K","Unknown","NT AUTHORITY\SYSTEM","0:07:36","N/A"
"05.06.2010_21.29.45.42","*:*",
"svchost.exe","1288","Services","0","17,136 K","Unknown","NT AUTHORITY\NETWORK SERVICE","0:00:03","N/A"
"05.06.2010_21.29.45.87","*:*",
"VCSW.exe","5644","Services","0","3,540 K","Unknown","NT AUTHORITY\SYSTEM","0:00:04","N/A"


lsof (Linux 4.78) sample output
lsof -Ts | grep -i Firefox | grep IPv4
firefox 5756 root 5lu IPv4 22403 TCP 192.168.0.5:40814->nuq04s01-in-f113.le100.net:www (ESTABLISHED)