Monday, May 26, 2008

SEC520W2L2

PAM Today

AAA Friday,

Next week hardening Linux, he will rejig Lab5 and Lab5b


Tuesday next week is a lab day

He moved the test from this week to the 27 till the end of week3 the test is up to


ChaPTER 5 and the intrusion discovery, n Hardening Linux

Put off the take home tank lab,

Finish up to lab 4 by Friday,


When he says its due, he is going to take the open boodle, PDF file report and upload it to open

And He will mark it online, and you must upload it by the due date


NO distatory recovery,

Test is on exploits and the text the stuff we do on labs,



PAM a lot of the labs are about

This week Access Control,

Linux comes with a lot of services working independently,

Till Pam came alone in the terms of Authorization and Authentication you would have to do everything independly

PAM is basically a system you can set all the authentication parameters through one program and have it affect all the services,


Theirs a directory PAM.d their use to be PAM.conf one file with the services, PAM is the same as xinet.d what ever you want to control with pam you put the config in the directory theirs another file called other and is the default that will handle the services, it comes in modules. Modules use permission and passwords,

Is the password strong enough, you can determine is the auth is going to fail or a warning you might say they have a weak password and go in or password weak you cannot go through you can do this all through PAM,


If you look at pam it carriers a lot of files and you can also see all the services that have configuration files, the default is other,

Looking at the files we can see …the login one… we can see four interface types, theirs AUTH this is called stacking modules, the login process uses 11 modules, and each modules everyone uses login the modules are executed one at a time, the first thing is authentication auth , after that required means this must succeed or the login field, more then 4 required mean both requisite means this this failed then the login failsso if 4 fail it will fail in the end, if it says requisite it will stop.

Option will give a warning,


Sufficient that means if there are all sufficient then some will pass,

So you have interface the parameter how it will work then the module, to find out how they work you gotta do research on the module, some commonly and some aren’t

System.auth is used often, after the module theirs parameters that are sent to the module

You can find out on the net how these works, if you look at the links on the course notes you can look at everything and see what it says,

Going through the lab do backup reading and see what it does, no ignorance!

We will look at password checking and setting criteria for authentication for the needs at the time, we are looking at the basic of using one thing you always do , is so ssh does not allow root login, people will try to brute force password for root login, never login as root through ssh or login as all if exposed to the net ,

Pam solves the previous problem.

Wednesday, May 21, 2008

SEC520 Types To Regard As Security Personnel

You always need to access something pretend you want to print you must switch to partial system administration your software uses the network, its controlled but parts are making use of kernel states that have admin control,

Hackers will break the software right when that’s happening if they do that they can break the shell and have access control of the tat process, and that’s one of escalating privileges and that’s where the loop holes are, its like the cgi programs, it does things that a user cannot do that an escalation of privileges, implementing is really hard because its so hard its always going to flawed the trick is not to have it prefect but now be the low hanging side , the bigger the value of the prize the more stringent you have to be, if they can make 10million they will spend 1 mil,

You come up with policy rationale three things to think of ,


One thing is

1. Due Diligence – your legal obligations, protect it

2. Risk Analysis – Cost of Benefit “How much will it cost and how much am I going to lose” Intelligent guessing

3. Exceed the Standards - Why? Bear chase phenomenon if you in a party of campers you try to be faster then the other people,

History:

In the beginning of computers, their were no passwords wasent an issue originally first computers were batch operators, they do one job at a time, so a computer center, it would be in a basement where the banks of memory the size of a huge cabnit and you would do your punch card, so one job at a time controlled by an operator, one job at a time you couldn’t cross boundaries, “think” MIT came up with the concept of time sharing that not all process is busy all the time, theirs I/O, its split into chunks and they all had a dumb terminal, except for a big centralized machine, what happen that some people were getting access to things they weren’t suppose to, and some errors and data would overwrite because their were not access control stuff, because in the early days they didn’t know so they came with access and password, they didn’t like the idea the machine control what they could do, suddenly the system would dictate to them and was a huge loss of freedom, Richard Stallman, Their was quite a resisted against password, then they broke into the password file and tried to live in access one famous incident, one was setting the login procedure and he look at the login and a password file would come up.

Someone would have a password file like the /etc/passwd in linux when you login program must have access to the file to see if ur their it use to be user name and password what they came up with is a
one way hash(cryptography technique) user puts into a password and given to a hashing algorithm MD5, if you give this the same input it will come out with the same output, so they store the hash of the pass except the password itself whats stored is not the same what is put in,
2 characteristics

1. It cannot be reversed,
if I have this I cant figure out this,

2. Given input always produces same output,
2a. any change to input how ever small produces completely different output

If I change 1 letter the output will be completely different,

Have a good logging system, everything being keyed were being cached in the buffer and waiting to be given to the hash,

Other thing realize in login you shouldn’t log password, which means also logging user names with failed attempts

You want to store them from successful ones, you want ot know who they were and where they came from, something simple become complex,

You remember the CIA if you kick ur users off the system cause their making mistakes you are failing accessibility, once they solved that stuff, what’s the weakest link, the first element the employee, social engineering, they will use passwords that are easy, or they can use social engineering, have educations and user friendly policy easy to understand and educate the user why the policy is important, you can do this well, sec625 is human side of the security,

Issue of sniffing,

Don’t use telnet use ssh, make sure you have ssl happening, any password in the wire should be encrypted before going in the wire

ShoulderSurfing, someone watching u type,
They can be grayed the Astrix

Other types of sniffing, one of the links, think geek, it’s a key sniffer, if going on a pc keyboard it’s a key logger,

Monitor Radiation, Vantek, if you invest something monitoring e


Key board timing attacks – you can decrypt them

Cost benefit analysis

The Trojan login, thinking when you login you see a prompt user name and password, its not hard to duplicate that, here what you can do if you have access, you leave th screen on so write a program so ur program runs inside of the login then you present a error then it passes it to the system,

Ettercap, is an evil program, it makes it easy for man in the middle attacks insert urself in the browser and server, it makes arp poisoning easy, knowing this if your on a lan with strangers you should not do anything that private,

Authentication factors, three factors of authentication,
1. Something you know the most common example is a password
2. Something you have – token key
3. Something you are – bio metrics

First password, they are easy to implement , no need to buy hardware or software, weakness choose weak password, we all know this,

Strangth if someone has it,

Weakness it can be forgotten come to work without ur token you cannot login, stolen, required extra hardware, you have to install a token reader on every machine, if you use a special card or device it can be expensive

4. Bio-metrics – easy to fool, you cant get 100% of the percent the higher percent the more it costs, if I gets easy if can interfere with it you need a huge database something the gnarl public is using it needs a huge database, if you their checking ur finger at the boarder what kinda pipe line would you need, so yo need to think about things like this they can take photos of your eyes,

ATM strategy

Well in today’s world everything is moving fast we are all learning and re-learning new things over and over. Before I start I wanted to ask the class why do they think emerging communication technologies are here? Basically why do we need to communicate them?

Well Uyless Black, a lecturer on communications technologies says

Today emerging technologies are here to overcome the deficiencies of the current technologies. Each new technology must meet the needs of applications

What he’s basically saying is we don’t need faster computers, we don’t need faster applications WE HAVE THEM and they are advancing in a millisecond rate, we need better communications between systems to be more accurate between Wide and Local area networks.

We choose Asynchronous Transfer Mode not because it’s a any protocol it’s the mother of all protocols and you will learn why in just a few minutes.

Just to define some how some of the information is handled before it actually transmits data, PMD synchronizes the transmission and reception of the connection and maintains continuous flow and TC allows devices to locate cells within a stream of bits.

Now I know what you guys are all thinking, How then this information directed…well first in front of the information you want to send there is header which contains all specifications about the load that will come after it, this is similar to an envelope, What do you need for an envelop? A Stamp, Mail Address and an optional Return address, you might even need two stamps!

So when your first going to send out your letter you put the right information on the top then drop it off to the closest mail box, after the header there is the pay load and we can see this similar to the mail carrier that carriers all ur letters and delivers them to the right destination, and like your envelope when they reach their destination the Name on the envelope is the person you want to be reading your message. That is similar to what the payload incorporates.

Now your thinking I got the envelop I wrote the letter but then who’s going to carrier my letter to my friend! Well actually you don’t care, but for ATM and as a Technician you must know which device you’re going to hook up

You basically use Switches/Bridges, they are two devices but are usually now embedded into one and perform functions what is inside the header and payload. Now we know how its directed and how its carried, now how is it handled?

Well inside each header there are bits called the VC and VP each of these are similar to telephone numbers but only regarded to each switch/bridge/router locally and no significance when transmitted except during the process of the switch where it translates that number to the right path in the opposing network.

Sunday, May 18, 2008

INT525 Compile Process

Just some stuff I've been working on.....you know this one actually is good instructions.....Apache Installation

Creating symbolic links to start up Apache, S__ and K__ in init

We download the source tarbal

Untar it with tar –xzvf

Make sure no one can log in if you do this to their account /bin/false

7 fields per user etc passwd

Everydeamon /bin/false

When installing we user

Do not do this as root,

Make
Make test

Make a dedicated directory to deal with your source code

/exp/src

Your configuration needs,

Document Root
Server Root
Extract Binaries
Change Executable Directory
Configuration Files












All command line switches, and easier more quickly with config.layout

# SuSE 6.x layout

prefix: /usr
exec_prefix: ${prefix}
bindir: ${prefix}/bin
sbindir: ${prefix}/sbin
libdir: ${prefix}/lib
libexecdir: ${prefix}/lib/apr
mandir: ${prefix}/share/man
sysconfdir: /etc/httpd
datadir: /usr/local/httpd
installbuilddir: ${datadir}/build
includedir: ${prefix}/include/apr
localstatedir: /var/lib/httpd
runtimedir: /var/run


Buildconf (first time system inspection and change system tree appropriately)
./configure (command line switches –withlayout)
Make
Make Test
Make Install (Don’t Do)
Make Clean

We are done unless we want to statically compile some modules, modify the build dso capabilities, we must compile the mod_so

Run shell script to automate this and make modifications to it and run it

Tuesday, May 13, 2008

INT525W2L2

Modules you can add them dynamically or statically

Statically – part of the binary

Mod.so is required if you want the rest of the modules linked dynamically,

Dso vs Static


Mod.speling in the url simple module that makes you make one typographic submission in the resource you are going, cgi-bin without the - that will be an error mod.spelling will correct.

Mod.alias, gives you ability to alias directory,

Script.alias, like alias with executable power, don’t use it, does not give you the control of flexibility alias does with a directory container,

Talk about basic directive in apache we know, and some modules that supply them,

When you come to a website you are virtually hosting, the main thing that must be set, you have a principal one that you might call default or main,

If you ask for a IP it doesn’t know or a Name VH they don’t know, they have to have a default way for the request, one of the metrics it must be rebout and must be forgiving for arrant behaviour a forgiving behaviour

When it does not know the deafualt behaviour will give to the main server,

WE need to learn the simple procedure this is the default place to go and you come in for a name server, this is the place to go if we are not servicing that IP,

What things need to go into the virtual host container for the main or default server

ServerRoot parent of the apache binary trees,




LockFile /var/log/apache2/accept.lock



IfModule directive all supplied by modules, nested tree of a fork, the later one will hold true, the last declaration has more authority, precedence

Which one has higher precedence, the example is not particularly authoritative but they actually fork the decision tree, not at run time, the service is running, we are either going to go around it or go through it

So binary executable for the binary,

.c static linked component of the kernel,

This says IfModule, if you move the config to a machine and you recompile it wont blow simply trying to start so it will not do these things



This is the global configuration file httpd.conf

Reaps the child processes,

MaxSpare initiates repeaing responses,

MaxClients = Maximum requests

Worker.c

443 ssl’

Directory < “/export/srv/www/vhosts/main/htdocs”>

Main => ALL FQDN
Perl

AllowOverride None


Worker.c
A typical configuration of the process-thread controls in the worker MPM could look as follows:
ServerLimit 16
StartServers 2
MaxClients 150
MinSpareThreads 25
MaxSpareThreads 75
ThreadsPerChild 25

Server limit identifies what will initially launch when the server is started it must be greater or equal MaxClients / ThreadsPerChild

MinSpareThreads and MaxSpareThreads identify the the idle threads in all processes and forks or kills processes to keep this number within the declaration

MaxClients the maximum total number of threads in all processes.

MaxClients / ThreadsPerChild = Max Child Processes

150 / 25 = 6

ThreadLimit must be greater or equal to ThreadsPerChild

While the processes are started as root under Unix intorder to bind processes and threads binding them to port 80 Apache will use less-privileged users.



#
# If you wish httpd to run as a different user or group, you must run
# httpd as root initially and it will switch.
#
# User/Group: The name (or #number) of the user/group to run httpd as.
# It is usually good practice to create a dedicated user and group for
# running httpd, as with most system services.
#
User daemon
Group daemon



MaxRequestsPerChild controls how frequently the server recycles processes by killing old ones and launching new ones.
Description:Multi-Processing Module implementing a hybrid multi-threaded multi-process web server
worker.c
it retains much of the stability of a process-based server by keeping multiple processes available, each with many threads.
Or
Prefork.c
It is also the best MPM for isolating each request, so that a problem with a single request will not affect any other.
Directive and Declorations

Declarations = Server Name

Directive = alias this directory their

Directive that configure this to the relation to mother child

\

ONE PARENT


worker.c has a different parent the child process then prefork.c
worker.c uses ThreadsPerChild that controls the number of threads deployed by each child prcess and Max Clients right
while prefork.c uses MinServer and MaxServer that spawns childprocesses that are indepent from the kernel
threads works as a stream as prefork words as a dependent entity


First thing that your going run out of when your worker.c is cpu and prefork.c is memory

Remember to check
http://httpd.apache.org/docs/2.2/mod/prefork.html
http://httpd.apache.org/docs/2.2/mod/worker.html

SEC520W2L1

Exploits - things that can go wrong


5 years script kiddies, now its criminal activity and has really changed, over the next few
Years it’s going to change again.


The change from operating attacks to application attacks, when you have applicatios you have a lot more variables then with dealing with the os many more applications and all doing different things, OS are straight forward applicationts are dynamic.


You still have the same things the attackers will do,

What is a DoS

CIA

Confidentiality,

Keep it secret

Integrity

Information from the data is what it should be, for instance you look at your bank account and you want to know the numbers are really their.

What it should be when it should be.

Lot of do who changed it who can change it.

Identity how do you prove someone is who they are.

Accessibility


Avaliable when its needed in a timely fashion.

DoS denies accessibility

DDoS – Distributed Denial of service

One way is to break the software this is one way another common one its not through breaking the software but overloading or clogging the piped to it.

Thisi is where DDoS, BogNets one central system which controls many computers so no one can access the service

DoS the basic, it has been mostly preformed for kids in basements or unhappy employees, They have been used for extortion, if you shut down your site it can cost you 30000 dollars it can be a real problem and it has in some palces ,


Why is the web to vulnerable to risk,

When it first came out everything was open and a kind of utopian world,

John Morris, the son of a internet pioneer the son wrote a program to find how mayn users are on the internet, thousands of the them, it used the finger deamon and it would move itself on the machine and do finger searches, he forgot to do make it see if its their, it was a naïve thing, he wrote a program that invaded other peoples computers,

Firewalls – controls what gets in and out, a firewall originally, first basic fire wall did packet filtering, looks at each packet and looks at the ports what ports is it asking for suppose you have telnet inside which is port23 and you have ssh 22 and http 80 and so , suppose you want telnet internally but not externally lets say it gets stop at the fire wall if you wna the public to have access to your web server then you make them go through that only port, may port for 25 but you restrict it to the ports you want to get through,


What happened when it was in place, everyone started having a webserver, webservers would give you some documents, well the people that wrote webservers what if it can expand to dynamic content or video they made more expansive webserver and create dynamic content.

Dynamic more accessible to the public, then they explanded the firewall they had web services goes through mysql, and come up more complex and they have holes to powerful complex software, the attacks change what they do and start aiming at the dynamic attributes of the server not just HTTP, but HTTP are common cause they do so many things and because theya re complex they are perfect targets for running exploits the exploits have gotten more and more toward webbrowsers.


Embed macros, it’s a program in a program web applications become a good target

Email targets are great bc of spam

Media players complexity, YouTube.com vector to get into the system passed the firewall.


On the server side service os the OS security software becomes a target for attackers, get a couruppted version. File management servers and database software.


Also things aimed at people, user rights unauthed devices,

Phishing, your account is over due give ur password, got all the right graphics but its false,

Spear phishing when you target people, or you lap top of usb keys, wireless if a grate vector

Instant messaging, easy for all the dumbasses.



Zero Day Attack, an attack where the attackers know it can mount it before the vendors know its their, it usually happens with hacks someone finds the weakness posts it then it the software vendors will patch it.

Because we have sophisticated criminals before they use


Storm Worm,


Recognize trends

Talking about DoS

Another privileged escalation – its like a user getting root access, some users on a a system but you want to get higher.


Trying to get from out in the cloud through a couple of a server, if they see outside traffic doing into system they have logs or IDS, they can call your service, or police come knocking

They will break in further away to get closer to the machine, trying to get machines to do the work for them, this is slow so they can get privileged escalation.






Common things, two things you will see a lot of,

XSS - Cross Site Scripting

SQL Injection



Everyone is blogging, websites allow users to put stuff in, cross site scripting when you put data in a blog that will effect the behaviour of a server, thing about it like this someone goes to a site, and look at someone’s blog the big thing now is java script, Java script embeds some code in your webpage, when the browser gets the webpage it runs that code, it allows the code to run on the clients machine however evil stuff can get in it, in cross site scription when you look at a wikipage or a blog, that will not be visible by you that will be executed by ur browser.


A lot of sites and wikis check this, but if its sophisticated it will always get through,


SQL injection when a web server is sending queires to a database databases by nature have a lot of data, its in a hackers intrest to get access to this.

If you design ur self right you, you use –T cause if you web server is interactions with database server if someone slips some sql code in the stuff that gets stuff into the data server can do bad things, get access, integrity, unauthorized, find credit card numbers.


DNS poisoning put false entries, collecting data,

Identity theft,

New devices for password, MLS and email password for only 30 seconds


Assignment 1


WHOIS
GOOGLE
DNS Tools


CanadianISP.com

Take it a generate a report a .pdf file and you can upload it