Monday, February 6, 2017

Welcome to OSINT: Fun with Open Source Intelligence!

Hi Everyone,

2016 and 2017 so far have both been insanely busy years for me and consequently I have not been able to post much at all.

I am very excited to announce that my course OSINT: Fun with Open Source Intelligence is going live soon on Pentester Academy http://www.pentesteracademy.com/course?id=29

Enjoy!

Jamal

Friday, January 1, 2016

Happy 2016!

Hi Everyone,

2015 has been an insanely, insanely busy year for me and I simply haven't been able to post anything. The custom search engines continue to be updated with new sites and I have some interesting news; I am in the early stages of developing a mini course on OSINT (Open Source Intelligence), stay tuned for more information. Here is to an exciting 2016!

Thursday, April 17, 2014

Heartbleed

As of now, everyone has heard about the Heartbleed bug (vulnerability CVE-2014-0160). There are a number of articles, postings and blogs about the bug and its implications. I have listed below some of the most useful links and articles relating to this vulnerability and managing this situation.


Recommended reading:

The Hacker news has a list of FAQs on this vulnerability, it also includes links to PoC code and sites/ services that check whether a server is vulnerable
http://thehackernews.com/2014/04/heartbleed-bug-explained-10-most.html#

Bruce Schneier has a very interesting post on Heartbleed and its implications
https://www.schneier.com/blog/archives/2014/04/heartbleed.html

Pentura Labs has a very good writeup and includes instructions for testing if your version of openssl is impacted even if you are offline
http://penturalabs.wordpress.com/2014/04/08/yet-another-heartbleed/

the SANS Diary has some very good posts on this evolving situation
https://isc.sans.edu/diary/The+Other+Side+of+Heartbleed+-+Client+Vulnerabilities/17945
http://digital-forensics.sans.org/blog/2014/04/10/heartbleed-links-simulcast-etc

A large number of servers and devices are impacted, some of the vendor notifications are listed below
http://www.symantec.com/connect/blogs/detect-heartbleed-vulnerability-remediate-and-harden-your-infrastructure-control-compliance-su
http://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10623
http://kb.bluecoat.com/index?page=content&id=SA79
https://isc.sans.edu/diary/Heartbleed+vendor+notifications/17929




Even if your main business servers are not impacted, it is possible that a web appliance, phone or networked device on your infrastructure is at risk.

Happy Patching!

Tuesday, December 24, 2013

Merry Christmas and Happy Holidays to All!

Merry Christmas and Happy Holidays to All!

It's been a very busy year overall and unfortunately I haven't been able to post as often as I would have liked to.

I recently had the great pleasure of speaking at the TASK Oct 2013 event (Toronto Area Security Klatch).
The presentation was very well received and there was plenty of quality discussion. I had a great time, made some new friends and got some excellent feedback. It was very special to speak at an event at home-base.

TASK is a very interesting group that holds monthly events with various speakers from the security community. These talks are free and also qualify for CISSP credits. The organizers of this event are also responsible for bringing the well known Sector Security conference to Toronto each year. More information on TASK and upcoming TASK events can be found at  http://www.task.to/


Interesting course from SANS:

SANS has a new course offering by Benjamin Wright called LEG523: Law of Data Security and Investigations, if you are an investigator, law enforcement, deal with legal counsel or are called as an expert witness this is definetly soemthing to think about.

Ben has some very interesting insights from a legal point of view; I am a big fan of his ideas on using a screencast or video capture to complement or  replace an investigator or incident handler's notes:
http://computer-forensics.sans.org/blog/2011/01/26/preserve-cyber-investigation-evidence-screencast-tool#comments

You can find more of Ben's insights and Blog posts at:
https://plus.google.com/+BenjaminWright1/posts
https://twitter.com/benjaminwright


Updates:

I have added a number of new sites to the OSINT engine. If you use this Google Custom Search, it is worth checking out.

Saturday, February 2, 2013

Updates - new sites added to various engines

I have added new sites to the
Open Source Intelligence Deep Web Search

(http://www.google.com/cse/home?cx=013791148858571516042:eygbr9xc-ys),

the Social Networking Intel/ Footprint web search
(http://www.google.com/cse/home?cx=013791148858571516042:ntbykhk-kus )

and the Pastebin and collaborative tools intelligence deep web search
(http://www.google.com/cse/home?cx=013791148858571516042:gqsws13ehog&hl=en ).

Enjoy!

Saturday, October 27, 2012

Malware and domains search

I've put together a custom google search for malicious software, known bad sites and dangerous ip addresses, it can be found here:

http://www.google.com/cse/home?cx=013791148858571516042:mkgwsgd9da8

Examples of the sites on the list include:

https://atlas.arbor.net/summary
http://www.blade-defender.org/
http://mtc.sri.com/

I will be constantly updating the search engine.

Monday, September 3, 2012

Attacks on the stock market: some thoughts

I have recently been thinking about stock markets and possible attacks on them; Die Hard 4 (http://en.wikipedia.org/wiki/Live_Free_or_Die_Hard), Hackers and any number of hacker movies have some very complicated looking system with great looking Angelia Jolie lookalikes or other attractive people who have these super elite skills and can hack the Gibson or do some increasingly complex attack to bring the main system down etc.

These attacks are certainly entertaining and also complex, and have a greater likelihood of being detected and also failing. What if there was a simpler way to launch attacks without directly attacking the market itself?

Let's look at day-traders as an example:

  • When launching trades, you need to use trade execution software
  • Most of these pieces of software are proprietary in nature and supplied either by brokerages or independent software houses
  • Since these pieces of software have a smaller market share, I began to think about how many people actually check to see whether the software they are downloading is really what it is supposed to be. How many people actually check the md5/sha-1 hash to see if there is a match?

An attacker could conceivably put a link on a legitimate vendor page that re-directs clients to a malicious piece of software (for a temporary period of time) or offer a 'free' version that works just as well. 

Another plausible scenario could have an attacker flooding various message boards and other locations that he/she is leaking a great new algorithm that is similar to or used by traders at a large firm like Goldman and watch to see how many people download this just to get an edge in their trading strategies. 

This malicious code could behave in a manner similar to which the the user expects or remains dormant until several trades have gone through and when the traders funds are in their account, execute its own trades and transfer an amount to a another brokerage or western union account.

If these transfers are randomized or if the malicious code monitors the traders' behavior and carries out transactions that appear similar to the traders own activity,  or deletes itself after x number of successful trades or transfers, this can make things much more difficult to detect.

Saturday, April 14, 2012

IIT Guwahati and the Market Intelligence Search

In February, I had the privilege of speaking at the Indian Institute of Guwahati as part of the ISEA 2012 workshop and conference. I had a wonderful time, enjoyed amazing hospitality, got some very encouraging and positive feedback and made some great new friends.

I have put together a custom search for stocks, bonds and related securities. While there are a number of different sites and blogs that provide market intelligence this engine leverages various sources to bring a large amount of relevant information in one place with the ease of a simple Google search.

The engine can be found here:

http://www.google.com/cse/home?cx=013791148858571516042:lse_tm-ugfq&hl=en

Monday, January 30, 2012

i2p, and onion/ tor search

I have put together a custom search for the hidden web. This search goes through various sources to leverage and scour through various i2p and onion/ tor sites. The advantage here is that even if you do not have tor installed, or do not want it installed you can still search for the information you need and then using your results either dig deeper by installing tor or take any actions you need to. I do not link directly to any of the sites in question.

http://www.google.com/cse/home?cx=013791148858571516042:adxvhgecf4m&hl=en

Sunday, January 29, 2012

Black Hat Abu Dhabi - Amazing

I was at Black Hat Abu Dhabi 2011 last month and had an amazing time. I got to listen to some very interesting research, had the pleasure of meeting some very cool people, made great new friends and got some excellent feedback on my presentation.

I just came across the following article from the Wharton school of business, which briefly mentioned me and some of my work, which I thought was really nice.

http://knowledge.wharton.upenn.edu/arabic/article.cfm?articleid=2774

I have also updated all three searches with new sites.

Enjoy!

Monday, August 1, 2011

Social Networking Intel/ Footprint web search

I've put together a custom google search for social networking related searches, it can be found here:

http://www.google.com/cse/home?cx=013791148858571516042:ntbykhk-kus

This can provide an idea of what an individual's social networking footprint looks like.

Examples of the sites on the list include:

facebook.com
flickr.com
plus.google.com

I will be constantly updating the search engine.

Sunday, July 3, 2011

Pastebin and collaborative tools intelligence web search

I've put together a custom google search for Intelligence/ information posted to pastebin and other online collaborative service and information portals, it can be found here:

http://www.google.com/cse/home?cx=013791148858571516042:gqsws13ehog&hl=en

Examples of the sites on the list include:

http://pastebin.ca/
http://nopaste.info/
http://paste.pocoo.org/

I will be adding more sources as I come across them.

Thursday, May 5, 2011

Open Source Intelligence Deep Web Search- updates

I have updated the OSINT custom google search.

http://www.google.com/cse/home?cx=013791148858571516042:eygbr9xc-ys

The following sites have been added:

http://www.isn.ethz.ch/
http://isnblog.ethz.ch/
http://theosintjournal.blogspot.com/
http://www.robtex.com
http://serversniff.net
http://www.peekyou.com
http://com.lullar.com/
http://www.checkusernames.com/
http://knowem.com
http://www.isearch.com
http://www.pipl.com
http://www.123people.com
http://www.spokeo.com
http://webmii.com/
http://www.zoominfo.com
http://samy.pl/androidmap
http://www.bing.com/maps/
http://twittermap.appspot.com/
http://tineye.com
http://youropenbook.org/
http://picfog.com
http://www.whitepages.com/find_neighbors
http://www.archive.org/web/web.php
http://boardreader.com
http://omgili.com
http://www.onstrat.com/osint/
http://www.onlinenewspapers.com/
https://wits.nctc.gov/FederalDiscoverWITS/index.do?N=0
https://www.cia.gov/library/publications/the-world-factbook/index.html

Tuesday, April 12, 2011

Open Source Intelligence Deep Web Search

I've put together a custom google search for Open Source Intelligence related topics, it can be found here:

http://www.google.com/cse/home?cx=013791148858571516042:eygbr9xc-ys

It currently searches the following sites:

http://www.turbo10.com/
http://www.deepdyve.com/
http://infomine.ucr.edu/
http://vlib.org/
http://www.intute.ac.uk/
http://aip.completeplanet.com/aip-engines/browse?thisPage=%2Fbrowse%2Fbrowse.jsp&successPage=%2Fbrowse%2Fbrowse.jsp&errorFlag=&errorMsg=&event=loadPageEvent&directPage=&directSection=4&treeQueryExpr=&treeQueryType=phrase&treeQueryTarget=tree
http://www.infoplease.com/index.html
http://www.deeppeep.org/
http://www.incywincy.com/
http://www.deepwebtech.com/
http://www.scirus.com/srsapp/
http://www.techxtra.ac.uk/index.html
http://www.osint.org.uk/
http://www.phibetaiota.net/
http://www.onstrat.com/osint/
http://extremesearcher.com/handbooklinks.html#chap1
http://rr.reuser.biz/
http://osintdaily.blogspot.com/
http://www.reversenumberdatabase.com/416-524

I will be adding more sources as I come across them.

Monday, February 14, 2011

A possible security bug in plenty of fish

I think I may have found a security related bug in plenty of fish...

It looks like your session can remain active even if you have attempted to clear out your cookies and cache (provided you have multiple windows open).

Here is the scenario:

I was logged into plenty of fish, and had multiple (plenty of fish) windows open; I was looking at different profiles and am in a habit of opening new windows when browsing.

After surfing for a while I decided to clear out my cache; I was using the latest stable build of firefox and went to tools clear recent history (everything) and hit ok.

After clearing everything (which includes cookies and active sessions), I got the impression that this would mean my session would be killed and that if I attempted to click on a new profile or send a message I would be asked to re-authenticate. This is not the case.

After my session being "killed", I was still able to view new profiles and even email members I was interested in and was able to authenticate that these messages had successfully gone through.

What if you were on a public computer and thought that by clearing your cache and cookies, your session would be killed and that no one else would be able to use your profile?

Something to think about...

Friday, January 28, 2011

new security hole in facebook

I was logged into facebook and just saw the craziest thing; you can have your apps activated and doing things while you aren't signed into facebook.

I am sure you must be thinking, that doesn't make any sense.

Let me describe my steps below:

I was logged into two sessions of facebook (two windows open) and they were both on my home page.

I was using firefox and on one of the sessions went into the mafia wars game application; I then clicked on the second session and signed out of facebook. One would think that by signing out of this session, it would have deactivated my other session as well; it did this to a certain extent. I carried out a few actions in my game, ie. deposited some money etc and was able to do this successfully. I then clicked on the home link and it asked me to sign into facebook.

When I saw this, I re-signed into facebook and re-entered my application and checked to make sure the applications I had carried out in my game had been successful; they had, I was able to recreate this scenario without any problems.

This is significant, if I can do this in mafiawars, can you picture the implications with other applications? What if other applications go further and connect to things like your location, or private pictures? What if you were logged into facebook, on a public computer like in the library?

Something to think about...

Saturday, January 8, 2011

Some thoughts on malware analysis and vmware

There are a number of different ways to examine malware, from using automated sites like threatexpert and virustotal to running your own sandbox locally (either on a physical machine or by using virtualization software like vmware). There are some in the malware analysis community who advocate using real hardware, as some pieces of malware have virtualization detection mechanisms built into them. Others point out that virtualization provides a greater level of flexibility and you can actually put measures in place for dealing with malware that tries to behave differently in a virtualized environment. I recently began to think a lot about this, since many companies are now using virtualization to a greater extent internally on things like webservers, as this can lead to lower costs and flexibility. It makes one wonder, does this mean that we are going to see a new trend in malware that ignores whether a machine is virtualized or not and just behaves the same anyway? If this does not appear to be the case, then does it mean that increased virtualization of both servers and desktops can actually reduce the likelihood of an organization being as heavily impacted by malware?

Thursday, January 6, 2011

Interesting information leak from facebook

The other day I signed into facebook and came across something very interesting. I noticed an update on my newsfeed from someone I had sent a friend request to. Having seen this I was under the impression that they had accepted my friend request, consequently I clicked on their profile and saw that it said awaiting friend confirmation. This is significant and may have some forensic/ investigative value because it seems to tell us that depending on what privacy settings a person has, if they don't act on a friend request, you can still get regular updates on some of their information on your newsfeed. This could potentially be used to track when a person changes, or updates their pictures, posts status updates or other information, without actually having to go to their profile page on a regular basis and without being part of their friendship group on facebook.

Monday, October 4, 2010

Guessing ATM PIN's using publically available information via social media

I was looking at the information a lot of us have publicly available and began to think about ATM PIN security.

The ATM's I am familiar with have a 4 digit (all numerals) pin code, this suggests that your pin is probably going to be a year. If you look at facebook, linkedin, myspace, flickr and any number of other sources you can build a profile of a person which can greatly help to reduce the number of possible ATM pin combinations they are likely to be using. Once you have a profile of your target, asking the right questions can reduce the ATM pin possibilities to a substantially more manageable number.

As an example:

If you are looking at a single guy, building a profile can determine the questions you need to answer for this person:

If this is a young unmarried single guy, you should find out:

Year of his birth
Does he have a new job?
Did he get a promotion recently?
Does he have his own car?
What year model is his car?
What year did he buy his car?
Does he have his own place?
What year did he buy his own place?
Does he have a dog?
What year did he get his dog?
Does he have any hobbies he is extremely passionate about?
Do any of them have specific years tied to them?
For instance maybe he likes guitars; maybe he has a favorite guitar. Is that a vintage 1965 Fender Strat?

This means you are looking at 6-9 likely possibilities for his ATM pin, given that you usually get about 3 attempts before being locked out the odds of getting the right combination are fairly high.

If the individual is married and has kids, you may need to add a few more questions

What year did he have his first kid?
What year did he get married?
The Date of Birth of his wife or significant other?

The more complex the profile, the more you need to fine tune your questions. While we might recommend that people create a number only they know and that sort of thing, a lot of us are more likely to go with something that we are familiar with and likely to easily remember. I am just scratching the surface here, the better you build the profile the better you get to know the person and this improves the likelihood of you getting back improved information.

Tuesday, July 27, 2010

Blackberries being viewed as a Security threat by various Middle Eastern governments

The Toronto Star had an interesting article on how Blackberries are seen as a potential security threat by various countries in the Middle East and Asia.

http://www.thestar.com/business/companies/rim/article/840150#article

From the article:
The UAE’s Telecommunications Regulatory Authority said Sunday that as a result of how BlackBerry data is managed and stored that “certain Blackberry applications allow people to misuse the service, causing serious social, judicial and national security repercussions.”

This is certainly interesting information and raises the question of what specific applications are of concern to the government. I can imagine Blackberry messenger being one of the applications that causes some concerns from a privacy perspective but I am curious as to what some of the other applications of concern might be.

Just thinking of some possibilities:
Youtube
Twitter
Facebook
Worldmate Live
Maximizer
Cellcrypt - possibly determining who is using this
various news portal applications
viigo
Wi-Fi Proxy FTP HTTP Servers (app)
SSH apps (PaderSyncSSH and Rove Mobile SSH) - possibly determining which non corporate individuals are using apps of this nature?