When I was a kid in Florida, I remember trees down and people taking boats down the "roads" in hurricane Ingrid. Did not feel afraid. Many other hurricanes, no problem.
We lived on barrier island in Boca Raton. Hurricanes have a problem getting to us because of the Bahamas. Evacuated twice, both times we just went to brother-in-law's house and it was fine, just loss of power. Hurricane Wilma 2005 - different story.
For Wilma, we were not evacuated. It ended up terrifying.
Wilma was deemed not a risk. After evacuating twice in the past couple years, we were pretty happy.
Here's what happened. We were in our billiards room playing pool and noticed my car getting pounded by debris. It was parked out front. I ran out to pull it into garage, and a 70 pound palm frond narrowly missed me going 80 MPH. Ran back inside, screw the Infiniti.
We went to sleep. Middle of the night, wind was howling, transformers were popping, trees were falling, hitting the house.
In the family room, the sliding glass doors were arcing due to wind. We watched our screened porch over the pool fall - and parts of it were swinging violently toward the sliding glass doors.
Walked from window to window, watching fences fall, trees fall. Didn't see the neighbor's roof land in our backyard - saw that in the morning.
My ears popped. It was life-threatening bad. We went to the most reinforced bathroom to wait it out.
It was bad. Remembered seeing Andrew tragedy, which we missed by being in Boca Raton.
So, we got through it. Took in a professional chef who had his roof destroyed. Best move ever - he was master of grill. We didn't have power for 2 weeks. No internet for 6 weeks. No food in grocery stores for 2 weeks.
We ate MRE's. They aren't bad. Best source of food was the neighbors' freezers though. With a chef and propane, we fed the neighborhood & family for many days with the goodies from their freezers.
You can't be prepared for the smells, we took people into the house who didn't bathe for - literally weeks. No fans, no A/C - oh and the dogs, they smell too.
Anyway, on the bright side, we made it through, and made some good friends.
Friday, August 25, 2017
Monday, August 21, 2017
Mandiant “Breach”: A High-Level Case Analysis & Understanding the Data Leak
Post is from my friend https://twitter.com/CryptoCypher
What is Mandiant?
On July 31st, nameless attackers released a
document claiming they breached the security of Mandiant, an American cyber
security firm. In this document, attackers claimed that they had
penetrated the Mandiant network infrastructure with remote access and monitoring
capabilities to their analysts’ systems.
What happened?
On August 7th, FireEye, the parent company of
Mandiant, released a statement denying the alleged breach
within their network infrastructure. FireEye claims that the attackers had
accessed one threat intelligence analyst’s online accounts through external
pre-existing data leaks that included account credentials, specifically
passwords. Through an internal investigation at Mandiant, the employee’s
credentials were found in 8 external database breaches, many of which likely
had the same login credentials as other online accounts where company data was
stored. Presumably, the analyst’s accounts were accessed with stolen
credentials, and the limited company data affecting two customers was stolen.
Mandiant nor FireEye are at fault at all, it is a flaw of an employee’s account
credential usage, which could happen anywhere.
Why do these breaches happen? Targeted attack,
tarnishing brand name reputation, personal attack, etc.
I suspect this attack was executed for three likely reasons:
- Brand
reputation: damage the companies’ reputation
- Personal
vendetta: damage the analyst’s reputation through a dox-oriented
effort
- Publicity:
advertise the #LeakTheAnalyst hacking campaign
Brand reputation is easily tarnished through the
media. Even if allegations are false, it will not look good on any company’s
reputation. FireEye and Mandiant handled this particular situation well by
offering public transparency in their investigations, explaining that their
network infrastructure and customer data is safe.
Personal vendetta’s often lead to people being
digitally attacked with the intent of negatively impacting the victim’s life
through exposure of information via doxing or other tactics. The goal of a
targeted attack like this could be to cause internal politics with a victim’s
employer, future employer’s who search for their name on Google or even to
simply just bother the victim.
Publicity for the attacker’s #LeakTheAnalyst campaign
could have also been the goal of this targeted attack. By claiming
responsibility for the attack through the hacking campaign, the media will do
the rest of the work for them by spreading their message.
Regardless of the reason, we need to look at how these
targeted attacks are happening. The answer is loud, clear and nothing new to
the security industry: people are re-using passwords, and as a result, personal
accounts are being accessed for data exfiltration.
What data is included?
It is important that we understand how exactly data is
stored in databases. Every field included during the account registration
process will also be included as a field in a database entry. Here is an
example of what the database entries look like to hackers and administrators
behind the scenes:
hackforums.net.sql:
,(37337, 'Cypher', '7274ed7f77a35fc8b090a36df4e8535c',
'7NSymPAH', 'j7fFx7OGpz1F69mPi1NV8c65kCKi4mXrqVvOsbfd2ygZNWnypY', 'crypto@cypher.ca',
0, 0, 0.00, NULL, NULL, NULL, 2, NULL, 0, NULL, 1296257475, 1296314097,
1296314097, 0, NULL, 0, NULL, NULL, NULL, '1-1-1992', 'all', NULL, NULL,
1, 0, 0, 0, 1, 2, 0, 'linear', 1, 1, 1, 1, 0, 0, 0, NULL, NULL, -8, 0, 0, NULL,
NULL, 0, 0, 0, 0, NULL, NULL, NULL, 1, 0, 0, '75.46.83.65', '99.138.48.174',
1670000814, 1261327169, NULL, 2555, 1, 1, 1, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 1,
0, NULL)
In this fabricated sample using the HackForums.net SQL data
format, we can see multiple things:
- User
ID: 37337
- Username:
Cypher
- Password
(MD5 hash): 7274ed7f77a35fc8b090a36df4e8535c (Decrypted: @cryptocypher)
- Email:
crypto@cypher.ca
- Date
of birth: January 1st, 1992 (1-1-1992)
- Past
IP addresses: 75.46.83.65,
99.138.48.174
- Other
random data
Naturally, people use the same passwords on multiple
accounts. Once that hashed password that we obtained from a third-party
database is cracked, that is when unauthorized access to social media, cloud
storage, email accounts, government documentation, and whatever more could be
accessed with similar account credentials.
There is a lot of information contained in these accounts;
private messages, personally identifiable information, corporate documents,
project source code, and more. As a result, doxes are created (ie. Mandiant
employee), companies are attacked (ie. Mandiant), identities are stolen,
competitors can steal project ideas, and reputation is tarnished all-around for
all parties included upon attacks being carried out.
How can this data be obtained? LeakedSource, HIBP,
etc.
Public services like HaveIBeenPwned (HIBP) are freely available to
check to see if any of our information is in any known public data leaks. As of
this time of writing, HIBP currently has data including:
·
228 hacked websites
·
3,999,249,352 account entries from leaked
databases
·
53,121 pastes containing personally identifiable
information
·
50,181,662 pastes containing account information
Among these breaches, data is included from LinkedIn, VK,
DailyMotion, Brazzers, and even websites as old as Neopets. For an extensive
list of websites who have experienced data leaks, you can either check this
page on HIBP or visit “The Breached Database Directory” hosted by
Vigilante.pw.

The Vigilante.pw
breached database directory data statistics.
There are also paid data search engine services that
frequently come-and-go due to legality issues. These services operate similarly
to HIBP, but they actually show the parsed data, based on account entries like
the HackForums SQL entry example displayed above. A popular example would be LeakedSource,
who sell data for any of their 3,109,103,084 accounts on record. There are also
data trading rings where cyber criminals trade data among themselves.
How can I prevent an attack like this from happening?
Do not use the same password. But really, take
advantage of two-factor authentication where possible, try to use different
passwords if you can remember them, and use a password manager like KeePassX
for the passwords that you cannot remember.
Inevitably, companies will be vulnerable to these types of
attacks for as long as passwords are used to authenticate account ownership.
Respective to this, the fault lays in human error. Tech folks should raise
awareness in their offices by using examples like the Mandiant case to explain
to directors and co-workers the dangers of poor password management hygiene.
Penetration tests including phishing attempts on employees could also be
considered.
Companies could also consider using these public data
services to their advantage if they are legally capable of doing so. I propose
that security departments start scanning these third-party database leaks to
find information tied to their own domain and employees. This will ensure that
our employees and clients are aware of the leaked data prior to an adversary
having the chance to take advantage of this information. LeakedSource offers
API services for this, but a lot could be done in-house if the data can be
found in a public
archive.
We can also setup Google Alerts to alert us whenever content is
archived by Google containing specified pieces of personally identifiable
information. There is also a HIBP email list that we can subscribe to so that
we are alerted whenever our email is discovered in future data breaches. These
are all preemptive steps that we can take to ensure our personal information’s
security.
Conclusion
People everywhere are gaining unauthorized access to places
that they should not be accessed due to the poor practice of password storage.
We need to educate our users, actively test our own companies security, and
search for company emails that are included in third-party data breaches.
People are constantly accessing company and political data that they should not
be accessing, and it is all preventable.
Monday, May 15, 2017
How Snake People Can Have Wealth, Not Money
OK first thing, you will not like this advice if you're a fun-loving millenial. You will get older though, and what really sucks is being a poor old person. We do not want this, as much fun as you're having now, that outcome needs to be avoided. Caveat, like everything, pick and choose what you are willing to do of these ideas. Here goes if you're still listening:
- When you sell a house, if you've lived in it 2 of past 5 years, those gains are basically tax free in US. Had to place this high because we have made big bucks this way. See below on buying houses. BTW I freaking love houses as assets.
- Don't take on any debt. If you don't have enough $ on hand, do not buy it. Save up, and when you buy what you really want, it will mean all the more.
- Pay off student loans and any other (aside from mortgage on house) as soon as you can. Attempt to get family members to help you pay this "hangsman's noose" off - it's choking for young people!
- - SPEND LESS THAN YOU MAKE (golden rule)
- Cook at home. Eat snacks at work. Avoid restaurants (yes this includes Starbucks), Enjoy avocados and other healthy foods, at home. Eat lavishly at home - enjoy life. I recently spent $500 on a fancy doctor to get this advice: eat whole foods you prepare at home. See, you've already saved $500, and made it more likely you'll live to be a rich old fart, should you do this :)
- If you do eat at a restaurant, take home leftovers and eat them dammit
- Try to get rid of your car, If you don't live by public transportation, you may have to temporarily drive a very unimpressive car. No worries, the best people you will know will like you for you, not your stuff.
- Buy energy-efficient minimally-polluting stuff. Even if a bit more expensive. So far, we just have this one earth.
- If work offers 401K max it. Nevah walk away from matching funds too. After tax it's pretty good.
- No pets - too expensive when you're young. If you need a fix, help a friend out by petsitting :)
- Any roommate must pay rent. Exception being a roommate who cooks and stuff, maybe in school. Just avoid people who take advantage of you :( Later in life, when you can afford it, help such people out.
- Don't f-up a windfall (co goes public or inheritance, etc) - bank most of it and party / splurge with 5- 10% maximum.
- At your age, equities are the play. Find a fund with research and don't necessarily trust financial advisors. Always diversify and don't put all of your eggs in one basket. Buy equities and other investments over time, not all at once. Things change, and plunking down a lot of dough at one time has always failed for me.
- Negotiate for more when taking a job. Don't be afraid to ask for a raise.
- No expensive hobbies - the idea is to have money and time for that when you're old and rich.
- Don't buy watercraft. Find friends who have boats and buy the beer. They are holes in the water the owner pours money in.
- Children are expensive. Maybe just have one - people say you should wait, but it's OK to have one or even two when you're young. Kids will make you tougher (and softer).
- Furniture is not an asset. It's an expense. Same with jewelry. Don't get me started on expensive knick-naks. Ugh.
- Buy clothes at a Goodwill or summat in a great neighborhood. That stuff rocks. If you are leery of used clothing, just go to conferences and collect that swag - which tends to include clothing :)
- Anything called a "loan" you make must be considered a donation. Loaning money to friends is a super bad idea :(
- Home buying tips:
- Think about being self-employed (contractor) Self employed upside - write off all the stuff you shouldn't be doing (see aforementioned). Downside - complicated and no bennies. Upside is you are young and unlikely to have huge healthcare expenses. Get a good tax guy if you do self-employed option.
- Don't be a douche - if you go to dinner or drinks, pay your fair share and a little plus. These are friends. Getting to wealth over money entails loyalty and being a good person. If it's a work event - don't pass it up if the exec to pays because they can likely expense.
- New cars: don't do it. You will pay a premium. I did that once, never got satisfaction. Now I buy 2 -3 YO cars from CarMax. Cars are an expense, not an asset. Kind of people think well of you for having a new car, well - suboptimal because they might not be very smart :(
- If you do have debt, consider this https://en.wikipedia.org/wiki/Debt-snowball_method - Kk but try to avoid this debt situation :)
Money does not relate directly to the fun you will have. Remember that. Stupid purchases will ultimately make you feel stupid. Some of these ideas seem no-funl at this time. But think of the older you, and how bad it would suck to be old AND poor someday. Having said that, travel, enjoy life, but think about that older person you will be, and be smart about your finances.
- When you sell a house, if you've lived in it 2 of past 5 years, those gains are basically tax free in US. Had to place this high because we have made big bucks this way. See below on buying houses. BTW I freaking love houses as assets.
- Don't take on any debt. If you don't have enough $ on hand, do not buy it. Save up, and when you buy what you really want, it will mean all the more.
- Pay off student loans and any other (aside from mortgage on house) as soon as you can. Attempt to get family members to help you pay this "hangsman's noose" off - it's choking for young people!
- - SPEND LESS THAN YOU MAKE (golden rule)
- Cook at home. Eat snacks at work. Avoid restaurants (yes this includes Starbucks), Enjoy avocados and other healthy foods, at home. Eat lavishly at home - enjoy life. I recently spent $500 on a fancy doctor to get this advice: eat whole foods you prepare at home. See, you've already saved $500, and made it more likely you'll live to be a rich old fart, should you do this :)
- If you do eat at a restaurant, take home leftovers and eat them dammit
- Try to get rid of your car, If you don't live by public transportation, you may have to temporarily drive a very unimpressive car. No worries, the best people you will know will like you for you, not your stuff.
- Buy energy-efficient minimally-polluting stuff. Even if a bit more expensive. So far, we just have this one earth.
- If work offers 401K max it. Nevah walk away from matching funds too. After tax it's pretty good.
- No pets - too expensive when you're young. If you need a fix, help a friend out by petsitting :)
- Any roommate must pay rent. Exception being a roommate who cooks and stuff, maybe in school. Just avoid people who take advantage of you :( Later in life, when you can afford it, help such people out.
- Don't f-up a windfall (co goes public or inheritance, etc) - bank most of it and party / splurge with 5- 10% maximum.
- At your age, equities are the play. Find a fund with research and don't necessarily trust financial advisors. Always diversify and don't put all of your eggs in one basket. Buy equities and other investments over time, not all at once. Things change, and plunking down a lot of dough at one time has always failed for me.
- Negotiate for more when taking a job. Don't be afraid to ask for a raise.
- No expensive hobbies - the idea is to have money and time for that when you're old and rich.
- Don't buy watercraft. Find friends who have boats and buy the beer. They are holes in the water the owner pours money in.
- Children are expensive. Maybe just have one - people say you should wait, but it's OK to have one or even two when you're young. Kids will make you tougher (and softer).
- Furniture is not an asset. It's an expense. Same with jewelry. Don't get me started on expensive knick-naks. Ugh.
- Buy clothes at a Goodwill or summat in a great neighborhood. That stuff rocks. If you are leery of used clothing, just go to conferences and collect that swag - which tends to include clothing :)
- Anything called a "loan" you make must be considered a donation. Loaning money to friends is a super bad idea :(
- Home buying tips:
- Location. Buy where people will want to live when you sell. Buy worst house with good bones in great neighborhood. Way to figure out bones on house is looking at attic and basement. That's the part fancy realtors won't get seller to fix. Look for watermarks in garage.
- If you're up to fixing up, do it.Weigh data on the investment on home improvement vs. return. A great neighborhood weighs in.
- Consider privacy - land is king
- Watch those HOAs and arrangement where you can be arbitrarily "assessed" for big money.
- Look for property that comes with land you can subdivide and sell later (never have done that, but way population is increasing, might be a good idea).
- If you get a bad vibe on neighborhood - listen to it
- Even if a house is worth $500K one day, no guarantee it will be that way a year from now. If you're way up, do like in Vegas and pull your chips off the table. Real estate bubbles suck.
- First home likely not the one you stay in for life. I've owned 14 houses so far. Then again, I *like* houses! Property is an asset, not an expense.
- If you've made a bad investment suck it up and move on. I've stuck with bad investments before - it doesn't work. Chalk it up to experience. Hesitate to make investments "friends" prod you to do. Take care.
- Don't smoke cigarettes, drink or do drugs. If you must, these expenses are in the "Exception - Cheating Allowance" category. Feel guilt for this and do what you must to make it up to the older you who wants to be wealthy.
- Think about being self-employed (contractor) Self employed upside - write off all the stuff you shouldn't be doing (see aforementioned). Downside - complicated and no bennies. Upside is you are young and unlikely to have huge healthcare expenses. Get a good tax guy if you do self-employed option.
- Don't be a douche - if you go to dinner or drinks, pay your fair share and a little plus. These are friends. Getting to wealth over money entails loyalty and being a good person. If it's a work event - don't pass it up if the exec to pays because they can likely expense.
- New cars: don't do it. You will pay a premium. I did that once, never got satisfaction. Now I buy 2 -3 YO cars from CarMax. Cars are an expense, not an asset. Kind of people think well of you for having a new car, well - suboptimal because they might not be very smart :(
- If you do have debt, consider this https://en.wikipedia.org/wiki/Debt-snowball_method - Kk but try to avoid this debt situation :)
Money does not relate directly to the fun you will have. Remember that. Stupid purchases will ultimately make you feel stupid. Some of these ideas seem no-funl at this time. But think of the older you, and how bad it would suck to be old AND poor someday. Having said that, travel, enjoy life, but think about that older person you will be, and be smart about your finances.
Saturday, December 26, 2015
The First Annual Cyber Santa!
And it's not just because Tony Robinson featured AlienVault and me. https://blindseeker.com/blahg/?p=668?utm_medium=Social&utm_source=Twitter
This is an amazing way to help turn infosec more positive, by recognizing the folks doing positive things for the infosec community. It is kick ass. Enough said, it's the holidays :)
Wednesday, October 14, 2015
Samy Kamkar presents at InnoTech Austin ISSA Security Summit
I really enjoyed the talk
by Samy Kamkar last week at Innotech Austin, where the ISSA Capital of Texas
chapter put on their Security Summit. If you don’t know of Samy, he’s the security
researcher best known for creating The MySpace worm, one of the fastest
spreading malware of all time. His talk, Covert Attack Vectors, was lighthearted and fun.
Here’s one of his
slides:
Samy discussed several
exploits – some of them done by him as a teenager. The final analysis was that
the only way to really protect your privacy might be this approach:
A great crowd was on-hand, and everyone seemed to have a
great time!
Wednesday, August 26, 2015
Security Practitioners: Eat Your Own Dogfood!
Josh Sokol presented at the Austin OWASP chapter meeting in
August. His talk was about how we should
set a better example for colleagues as security practitioners by using a
security-sensitive thought process in our day-to-day lives.
A recording of his talk is here: https://vimeo.com/channels/owaspaustin We had a good turnout for the talk, and the
audience interaction was great!
Here are some of his key points:
In the Car
- Don’t indulge in bumper stickers that give away too much information. There are a lot of bad guys running around that can use it for evil purposes.
- Don’t leave valuables in your car. It gets the interest of the wrong element.
- Keep an eye on neighborhoods you travel through, and observe when you need to get out of bad neighborhoods.
- Don’t leave your garage door opener in the car. It’s a simple matter for bad guys to get your codes from it and possibly break into your house via the garage
- Get a CarSafety Hammer, Window Breaker and Seatbelt Cutter.
House – think about deterrents
- Have an escape plan in case of an emergency
- Even if you don’t have an alarm system like ADT, be sure to get some of their signs/stickers
- If you have an alarm system, make sure you set up a panic code. That’s a code you use if the bad guy forces you to disable the alarm, and it sends a distress call while appearing to simply disable.
- Get good door locks! Guys like Jgor can get through the cheap ones in 30 seconds.
- Get motion lights
- Get a camera surveillance system. They are cheap now.
- Get a “Beware of Dog” sign, even if you happen to be a cat person.
- Consider getting a device to separate your cable modem from your router like the PA-200. That way, you don’t have to trust your ISP and you can allow guest access to wifi in your house without worries
- Backup the Backup of your Backups
- Use WPA2 encryption
- Have a Fireproof Safe
- Have a week’s worth of home rations
- Have a “bug out” bag and location decided
At Work
- Keep your desk clean
- If in doubt, take your computer with you wherever you go
- Shred sensitive documents
- Don’t leave valuables unattended
- Don’t expect police to help you with a stolen cell phone – even if you can track it they will not help . Get set up for remote wipe instead.
Your Computer
- Check before clicking
- Check to make sure it’s HTTPS
- Know what you’re running
- Cover your camera
- Disable JavaScript
- Use 2-step verification
- Use KeePass – it’s free and open source
- Don’t use a bank debit card – all the liability is on you
- Use one card for in-person transactions; consider a card with a Virtual Account Number
Wednesday, May 27, 2015
Bug Bounty Programs: “Asking for it”
At Austin OWASP Charles Valentine, VP of Technical Services
at Indeed, presented on “Case
Study: Key Takeaways from Indeed’s Crowdsourced Security Testing Program." Here's a recording of his talk: https://vimeo.com/channels/owaspaustin
Indeed, with a slogan of “We help people all over the world
hire and get hired”, prides itself on having a secure environment for both job
seekers and job providers to interact. They also have a rapid rate of change in
their application and data. For these reasons, they’re highly motivated to deal
with bugs, especially related to security, very proactively.
Indeed is careful to avoid “toxic assets” like credit cards –
they keep any financial transactions between individuals and banks, keeping
only a token for credit cards, rather than actual information. They also
acknowledge that with their rate of change, they need a way to find bugs
quickly. Charles emphasized what we all know is true: the faster you find a bug, the less cost to fix.
Of course, it’s possible to hire legions of testers and
penetration testers. It’s also possible to crowd-source this testing and enlist
bug bounty hunters to find the bugs.
Indeed chose to set up a bug bounty program using Bugcrowd. They pay between $50 - $1500 for
each bug that hunters find. So far, they’ve paid for 228 bugs, with an average
payment of $162.50. They typically respond within 7 days. They figure using Bugcrowd technology is
saving them about 80% of the administrative costs for the program.
Subscribe to:
Posts (Atom)







