-->

whaust

2020年4月14日 星期二

WannaRen - New Ransomware -2020/04/05



WannaRen is a new ransomware 
first seen  on internet on 2020/04/05

Bitcoin address : 

1NXTgfGprVktuokv3ZLhGCPCjcKjXbswAM


E-mail :

WannaRenemal@goat.si

IOC : 

1de73f49db23cf5cc6e06f47767f7fda

46a9f6e33810ad41615b40c26350eed8


235cca78c8765fcb5cf70a77b1ae9d02

Microsoft Exchange 2003 - 應用事件日誌中記錄了事件ID 9187


MSExchangeSA 9186 , 9187

問題

每隔15-20分鐘,“Event ID: 9187”就記錄在應用事件日誌中:
事件ID:9187
源:MSExchangeSA
類型:錯誤
類別:常規
說明:
Microsoft Exchange系統助理未能將本地計算機添加為DS組對象的成員'cn = Exchange域服務器,cn =用戶,dc = microsoft,dc = com”。
請停止所有Microsoft Exchange服務,將本地計算機手動添加到組中,然後重新啟動所有服務。
Microsoft知識庫文章271335涉及了該問題,並建議開啟“ Exchange System Attendant ”服務。然後,Exchange Virtual Server離線,然後重新返回在線狀態。但是仍然記錄事件9187。

解決方法

如果面向Exchange 服務器的電腦用戶配置不正確,則會導致該問題。
  1. 打開“Active Directory Users”“Computers”
  2. 打開“Exchange server computer account”的屬性。
  3. 選擇“ Member of Tab ”。
  4. 查看“Primary group”是否設置為“Exchange Domain Servers”組。
  5. “Primary group”更改為“Domain Computers”
  6. 等待Active Directory複製或者執行Active Directory複製




Event Id9186
SourceMSExchangeSA
DescriptionMicrosoft Exchange System Attendant has detected that the local computer is not a member of group cn=Exchange Domain Servers,cn=Users,dc=microsoft,dc=com. System Attendant is going to add the local computer into the group. The current members of the group are CN=SERVERNAME,OU=NEWOU,DC=microsoft,DC=com; .
Event InformationAfter you move a Microsoft Exchange 2000 Server computer from one organizational unit to another within the domain, or after you rename the organizational unit, the above event with 9187 event id, are logged in the application event log.
Reference LinksSystem Attendant Generates 9186 and 9187 Event ID Messages


Event Id9187
SourceMSExchangeSA
DescriptionMicrosoft Exchange System Attendant failed to add the local computer as a member of the DS group object name. Please stop all the Microsoft Exchange services, add the local computer into the group manually and restart all the services.
Event InformationExplanation :
This event indicates that the System Attendant has detected that the local computer is not a member of the Exchange Domain Servers Security Group and failed to add it to that group.
While there may be other causes of this error, it can happen because the Distinguished Name (DN) of the Server has changed. This change in the DN can happen because the computer may have been moved to another organizational unit (OU) in Active Directory. This error may show up if even if the server is in the Exchange Domain Servers Security Group.

User Action :
Stop all Exchange services. If necessary, add the local computer to the Exchange Domain Servers Security Group and restart the System Attendant Service manually. Note that this will cause the Information Store service to restart. </p>
Reference LinksSystem Attendant Generates 9186 and 9187 Event ID Messages

2020年4月13日 星期一

國家信息保障認證和鑑定過程(NIACAP)角色

The National Information Assurance Certification and Accreditation Process (NIACAP) roles are nearly the same as the DITSCAP roles. Four minimum participants (roles) are required to perform a NIACAP security assessment:

國家信息保障認證和鑑定過程(NIACAP)角色與DITSCAP角色幾乎相同。進行NIACAP安全評估需要至少四個參與者(角色):

1. IS program manager (IS計劃經理):
  • The IS program manager is the primary authorization advocate. He is responsible for the Information Systems (IS) throughout the life cycle of the system development. 
  • IS計劃經理是主要的授權倡導者。他負責系統開發整個生命週期中的信息系統(IS)。

    2. Designated Approving Authority (DAA) 指定的批准機構(DAA):
    • The Designated Approving Authority (DAA), in the United States Department of Defense, is the official with the authority to formally assume responsibility for operating a system at an acceptable level of risk. 
    • 美國國防部的指定的批准機構(DAA)是有權正式承擔以可接受的風險水平運行系統的責任的官員。
    3. Certification agent (認證代理):

    • The certification agent is also referred to as the certifier. He provides the technical expertise to conduct the certification throughout the system life cycle. 
    • 認證代理也稱為證明者。他提供技術專長以在整個系統生命週期內進行認證。

    4. User representative (用戶代表): 
    • The user representative focuses on system availability, access, integrity, functionality, performance, and confidentiality in a Certification and Accreditation (C&A) process.
    • 用戶代表專注於認證和鑑定(C&A)流程中的系統可用性,訪問權限,完整性,功能,性能和機密性。
    * DITSCAP : Defense Information Technology Security Certification and Accreditation Program
                        國防信息技術安全認證與認可計劃

    NTP Attack .... What Hacker really want ...



    Juniper Junos OS之NTP套件存在多個安全漏洞,允許攻擊者遠端執行任意程式碼,請儘速確認並進行修正
    內容說明:

    Juniper Junos OS是Juniper Networks公司一套以FreeBSD為基礎所發展,專用於該公司網路設備的作業系統。
    Juniper官方於10月份的安全建議與警訊中,公告Junos OS之NTP套件存在多個安全漏洞,其中又以CVE-2018-7183最為嚴重,當攻擊者針對使用Junos OS的網路設備進行NTP功能查詢時,藉由發送特製的惡意封包可使其decodearr函數出現緩衝區溢位情況,導致攻擊者可遠端執行任意程式碼。



    目前已知影響平台如下:

    所有使用Junos OS的網路設備,包含:
    .J系列
    .M系列
    .T系列
    .MX系列
    .EX系列
    .SRX系列
    .QFX系列
    .NFX系列
    .PTX系列



    建議措施:

    目前Juniper官方已針對弱點釋出修復版本,請各機關可聯絡設備維護廠商將Junos OS升級至以下版本:
    .12.1X46-D77
    .12.3X48-D70
    .12.3X54-D34
    .12.3R12-S10
    .12.3R13
    .14.1X53-D47
    .15.1X49-D140
    .15.1X53-D490
    .15.1X53-D471
    .15.1X53-D234
    .15.1X53-D67
    .15.1X53-D59
    .15.1R4-S9
    .15.1R7-S1
    .15.1R8
    .16.1R4-S9
    .16.1R6-S4
    .16.1R7
    .16.2R1-S7
    .16.2R2-S6
    .16.2R3
    .17.1R1-S7
    .17.1R2-S7
    .17.1R3
    .17.2R1-S6
    .17.2R2-S4
    .17.2R3
    .17.3R1-S5
    .17.3R2-S2
    .17.3R3
    .17.4R1-S4
    .17.4R2
    .18.1R2
    .18.2X75-D5
    .18.2R1



    參考資料:

    1. https://kb.juniper.net/InfoCenter/index?page=content&id=JSA10898
    2. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7183
    3. https://www.ithome.com.tw/news/126377

    Source: https://www.nccst.nat.gov.tw/VulnerabilityDetail?lang=zh&seq=1090

    Publish Date
    2018/10/15 10:58:56


    2020年4月11日 星期六

    Purple Teaming in Java API Development


    MODULE 1

    Topic:  Secure Development LifeCycle And Chain of Security Tools.

    Description: This module mainly focuses on the introduction of security terminology and attacking vectors involved in an application. It also provides an overview of application architecture and the role of different tools involved during the entire course. Its content provides an offensive security methodology from a secure development perspective.

    Topics Covered:

    • JAVA Spring Boot features and its advantages
    • Developing a Spring Boot-based REST API
    • Enabling session time-out in the REST API
    • Hands-on introduction to ZAP and POSTMAN
    • What is:
      • Insecure Direct Object Reference
      • SQL injection
      • CSRF token
      • Serialization
      • Deserialization
      • Intercepting proxy tool

    Module 1 Exercises:

    • Clone the Spring Boot REST API from git repository and configure the cookies with domain, HTTP and Secure flag being set and explore additional Spring Boot security features
    • Use of POSTMAN client tool to trigger a request to API
    • Intercept the HTTP traffic via proxy tool (ZAP)
    • Modify the traffic and analyze the different sets of data (headers, tokens, etc.) being passed
    • Create a report on what security feature is missing in the HTTP traffic analysis of your developed API

    MODULE 2

    Topic:  Deserialization Issues in JAVA, Testing, and Mitigating

    Description: This module focuses on the different annotation features provided by Spring Boot and develop serialization-deserialization functionality in your API. It provides an overview of the issues related to deserialization in JAVA and how to mitigate these flaws in your API development, as well as different techniques to mitigate input validation bypass issue. It also covers creating custom extensions on ZAP.

    Topics Covered:  

    • Identifying Issues with deserialization
    • How to exploit deserialization issues
    • How to mitigate and fix deserialization issues
    • Validating input on the server side
    • Introduction to writing custom extensions on ZAP
    • Implementing a passive scanner on ZAP to check the API request-response
    • Using a basic authentication method for the APIs to restrict public access

    Module 2 Exercises:

    • Implement a passive scanner on ZAP with the following features:
      • Session cookie without 'HTTP Only' and ‘Secure’ flag in the developed API (from module-1)
      • to test whether CSRF token enabled for POST method or not (DVWA app)

    MODULE 3

    Topic:  Security Configuration in Spring Boot and Active Scanning using ZAP

    Description: This module focuses on implementing the scope-based authorization features of Spring Boot, secure configuration of an API, along with restricting end-points and internal methods. Moreover, it presents blacklisting of potential dangerous commands in your API Introduction to active scanning feature of ZAP tool.

    Topics Covered:

    • Spring Security libraries and java-container-security as dependency in POM file
    • Configuring Spring Security
    • Implementing Scope based authorizations and method level checks
    • Introduction to Spring Boot actuator end-points
    • Introduction to CVSS and active scanning of ZAP
    • Implementing an active scanner feature in ZAP with the following features:
      • Trigger a request on an unauthorized end-point and flag the HTTP code in response
      • Tamper HTTP verb in the API request and flag the response
      • Defining CVSS score and priority in case of a successful attack

    Module 3 Exercises:

    • Implementing method level authorizations in a REST API
    • Enable relevant actuator end-points securely
    • Implement an active scanner on ZAP with the following features to check permitted actuator end-points

    FINAL EXAM

    In this final exercise, you would work on the offensive and defensive side of security, attacking your own developed APIs and mitigating the issues found during your attack.

    1. Secure Development of a REST API with the following features:
    • Development of a REST API with the following features
      • authentication via OAuth 2.0 protocol using third party Authentication Server (Facebook, Google, etc.)
      • input validation scenario using regular expression:
    • Implement passive scanner and active scanner script on OWASP ZAP tool to check for the CSRF token bypass vulnerability (API would be provided to you)
      • empty value in CSRF
      • provide CVSS rating to the issues detected
    1. Provide a Final Secure analysis report of your API security testing against the OWASP Top10 attacks using the tools learned in this course.


    If any security issues are found during the test, mitigate/fix them and provide a PoC on the fix.

    Evaluation would be based on the number of implemented features from the above-mentioned exercise and on the number of vulnerabilities found and mitigated in the report.


    Source : https://pentestmag.com/product/purple-teaming-in-java-api-development/

    Wear Mask Save People.


    2020年4月10日 星期五

    檢測風險, 殘留風險, 固有風險, 次要風險

    檢測風險(Detection Risks)

    • 檢測風險是審計師無法找到他們要檢測的風險。因此,當實際存在材料狀況(故障)時,報告負面結果變得很繁瑣。
    • 檢測風險包括兩種類型的風險:
      • 抽樣風險:當審計師錯誤地接受或錯誤拒絕審計樣本時,就會發生此風險。
      • 非抽樣風險:當審核員由於未應用適當的程序或未使用與審核目標不一致的程序(檢測錯誤)而無法檢測到狀況時,會發生此風險。
    • Detection risks are the risks that an auditor will not be able to find what they are looking to detect.Hence, it becomes tedious to report negative results when material conditions (faults) actually exist. Detection risk includes two types of risk: Sampling risk: This risk occurs when an auditor falsely accepts or erroneously rejects an audit sample. Non-sampling risk: This risk occurs when an auditor fails to detect a condition because of not applying the appropriate procedure or using procedures inconsistent with the audit objectives (detection faults).

    殘留風險(Residual Risk)

    • 殘留風險是指儘管採取了科學上所有可能的安全措施(科學上可行的措施),但與科學並駕齊驅的行為或事件,方法或(技術)過程的風險或危險,儘管與科學並駕齊驅。 
    • 計算剩餘風險的公式為(固有風險)x(控制風險),其中固有風險為(威脅脆弱性)。在經濟方面,殘差是指“過程結束時剩餘的數量;剩餘數量”。
    • Residual risk is the risk or danger of an action or an event, a method or a (technical) process that, although being abreast with science, still conceives these dangers, even if all theoretically possible safety measures would be applied (scientifically conceivable measures). 
    • The formula to calculate residual risk is (inherent risk) x (control risk) where inherent risk is (threats vulnerability). In the economic context, residual means "the quantity left over at the end of a process; a remainder".

    固有風險(Inherent Risk)

    • 審計中的固有風險是指由於錯誤或欺詐而使被審計的帳戶或科目嚴重失誤而未考慮內部控制的風險。固有風險的評估取決於審計師的專業判斷,並且是在評估被審計實體的業務環境之後進行的。
    • Inherent risk, in auditing, is the risk that the account or section being audited is materially misstated without considering internal controls due to error or fraud. The assessment of inherent risk depends on the professional judgment of the auditor, and it is done after assessing the business environment of the entity being audited. 

    次要風險 (Secondary Risk)

    • 次要風險是由於實施風險應對措施而直接產生的風險。次要風險是應對原始風險的結果。次要風險不像主要風險那麼嚴格或重要,但是如果沒有適當地估計和計劃,那麼事實就是如此。
    •  A secondary risk is a risk that arises as a straight consequence of implementing a risk response. The secondary risk is an outcome of dealing with the original risk. Secondary risks are not as rigorous or important as primary risks, but can turn out to be so if not estimated and planned properly.

    Popular