<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">

<channel>
	<title>Security Ripcord &#187; Interviews</title>
	<atom:link href="http://www.cutawaysecurity.com/blog/archives/category/interviews/feed" rel="self" type="application/rss+xml" />
	<link>http://www.cutawaysecurity.com/blog</link>
	<description>Cutaway's Observations, Opinions, Rants, Raves, Tantrums, and Tirades</description>
	<lastBuildDate>Tue, 01 Jun 2010 15:17:09 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<creativeCommons:license>http://creativecommons.org/licenses/by-nc-sa/3.0/</creativeCommons:license>		<item>
		<title>DefCon 16 Interview &#8211; Monty McDougal</title>
		<link>http://www.cutawaysecurity.com/blog/archives/307</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/307#comments</comments>
		<pubDate>Sun, 07 Sep 2008 05:42:42 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[DefCon]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[DefCon16]]></category>
		<category><![CDATA[FoolMoon.net]]></category>
		<category><![CDATA[Helix]]></category>
		<category><![CDATA[Monty McDougal]]></category>
		<category><![CDATA[Security Ripcord]]></category>
		<category><![CDATA[WFT]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/?p=307</guid>
		<description><![CDATA[While at Defcon 16 I had the chance to sit down with Monty McDougal.  It started out more as a quick lunch to catch up with Monty as I had not seen him in quite a while.  But after catching up with him he told me that he had made some significant modifications to his [...]]]></description>
			<content:encoded><![CDATA[<p>While at <a title="DefCon 16" href="http://www.defcon.org/" target="_blank">Defcon 16</a> I had the chance to sit down with <a title="Monty McDougal" href="http://www.foolmoon.net/staff/mcdougal.html" target="_blank">Monty McDougal</a>.  It started out more as a quick lunch to catch up with Monty as I had not seen him in quite a while.  But after catching up with him he told me that he had made some significant modifications to his <a title="WFT" href="http://www.foolmoon.net/security/wft/index.html" target="_blank">WINDOWS FORENSIC TOOLCHEST</a>™ (WFT).  The last time I had worked with WFT it was at version 1.01 and Monty did not have time to devote to updating the tool with some of the new features that were rolling around in his head.  I knew that this disappointed him at the time because the tool had received such a good response from the SANS community.  Well, after speaking with Monty and looking at some of the updates that he has implemented I can see that he has been able to devote more than a little time to this excellent tool.</p>
<p>If you are not familiar with WFT, here is a brief overview from Monty&#8217;s website <a title="FoolMoon.net" href="http://www.foolmoon.net" target="_blank">FoolMoon.net</a>.</p>
<blockquote><p>The Windows Forensic Toolchest™ (WFT) is designed to provide a structured and repeatable automated Live Forensic Response, Incident Response, or Audit on a Windows system while collecting security-relevant information from the system. WFT is essentially a forensically enhanced batch processing shell capable of running other security tools and producing HTML based reports in a forensically sound manner.</p></blockquote>
<p>Actually, WFT is a lot more developed than this description.  WFT provides the user with a repeatable method to deploy many security and administrative tools designed to gather information about a Windows Operating System (OS).  These tools include tools present on specific OSes, tools provided through Windows Resource Kits, third-party tools, and even some tools (or soon to be) that Monty has written to include within WFT.  Monty goes to great lengths to respect all user agreements and licensing associated with each tool employed by WFT.  In version 3.0 the ability to automatically download tools and validate integrity is built directly into the toolchest&#8217;s functionality.  Updates to locations and code modifications are handled by an automated toolchest update process.  Although these methods of acquiring tools work when Internet access is available it is not always the case that connectivity will be available.  Monty has taken this into considetion and provided the WFT update capabilities to utilize the <a title="Helix" href="http://www.e-fense.com/helix/" target="_blank">Helix Incident Response &amp; Computer Forensics</a> CD-ROM as a source for the tools.</p>
<p>I was very surprised when Monty mentioned that he is now charging for the use of WFT.  In the FAQ on his site, Monty explains why he has moved to the commercial model.</p>
<blockquote><p><strong>What happened to the free version of Windows Forensic Toolchest™ (WFT)?</strong></p>
<p>After providing WFT for free to the security community for nearly 4 years, I have decided to make version 3.x a commercial product. WFT is still available for download, but the downloaded version is restricted to specific uses identified within its license. WFT has consumed several hundred hours of development and support over the last few years, and while $100 is a modest amount, it will help motivate me to continue to develop and support WFT (since the donation model did not work out at all). There is also a new WFT Pro version in development which will include several additional features useful in an enterprise environment along with a new GUI. Pricing for this version will be slightly higher, but will also include WFT. Paid WFT users will of course receive 100% upgrade credit towards the upcoming Pro version. I have no plans of supporting the 1.x or 2.x code bases in the immediate future and will instead be focusing on bringing new features to version 3.x.</p></blockquote>
<p>At the time I am writing this post the restricted version is no longer available for download and I can only assume that WFT has gone completely commercial at this time.  This means it is very likely that it will no longer be available via the Helix CD-ROM which was one of the original ways to obtain this tool.  Persons who have versions of WFT on their current Helix CD-ROMs will also find out that their version is broken due to a WFT update script.  When I questioned Monty about this he told me that the Helix update script was necessary to force Helix users to up-to-date versions of WFT because he could not support the questions he was getting about out-of-date versions.  He did assure me, however, that although the script on the current version of Helix is broken, he will be releasing a patch soon, which should be available on his website.  If you do not find it there (I did not at the time of writing this post) you can attempt to contact Monty and I am sure he will get back to you as soon as his busy travel schedule permits.  Unfortunately, it may be the case that he has dropped support for Helix altogether, but this has not been confirmed.</p>
<p>One of the things that Monty did show me while we were talking about WFT was the new Graphical User Interface (GUI).  This GUI will be provided as a part of a PRO version of WFT.  Currently the toolchest is controlled via a detailed configuration file.  The GUI will give the user complete control over which tools are run and how/when the tools are updated.  He was very excited that he was nearing the conclusion of this milestone as it was going to permit him to pursue some other key features that he has been considering.  These features include reporting tool outputs to a remote system, rewrites of certain tools so they do not have to be downloaded, and new tools that provide unique features.</p>
<p>It is unfortunate that I did not get a chance to test drive the new version of WFT before writing this article.  I am hoping that I can convince my new colleagues to consider putting WFT into our toolkit for Live Response.  Having this tool would simplify so many aspects of scripting, tool maintenance, and tool and output hashing for verification and validation.  Yes, most of what WFT can do can be done by hand, but <a title="Windows Incident Response With Only System Resources" href="http://www.cutawaysecurity.com/blog/windows-incident-response-with-only-system-resources" target="_blank">as I have mentioned before</a>, having a repeatable process that is the same everytime is critical to providing a consistent and professional incident response.</p>
<p>I would like to wish Monty and WFT the best of luck in the future.  I am looking forward to their continued success.</p>
<p>Go forth and do good things,</p>
<p>Don C. Weber</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/307/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>atlas &#8211; an Email Interview</title>
		<link>http://www.cutawaysecurity.com/blog/archives/229</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/229#comments</comments>
		<pubDate>Wed, 26 Mar 2008 04:06:36 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[CISecurity]]></category>
		<category><![CDATA[DefCon]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[InGuardians]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[atlas]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/229</guid>
		<description><![CDATA[Although I have never met atlas personally, I was originally made aware of him at RSA 2007 while speaking with Ed Skoudis.  I was talking to Ed about my interest in the DefCon CTF and he mentioned that his company InGuardians was working with altas on several projects because, among other reasons, of his [...]]]></description>
			<content:encoded><![CDATA[<p>Although I have never met <a href="http://www.flickr.com/photos/veruus/1043907281/in/set-72157601280791450/" title="atlas speaks" target="_blank"><em>atlas</em></a> personally, I was originally made aware of him at RSA 2007 while speaking with <a href="http://www.intelguardians.com/info.html" title="Ed Skoudis Bio" target="_blank">Ed Skoudis</a>.  I was talking to Ed about my interest in the DefCon CTF and he mentioned that his company <a href="http://www.intelguardians.com" title="InGuardians" target="_blank">InGuardians</a> was working with <em>altas</em> on several projects because, among other reasons, of his outstanding performances at DefCon.  The next time I heard about <em>atlas</em> was during last year&#8217;s <a href="http://nopsr.us/ctf2007/overview.html" title="DefCon CTF 2007 Overview" target="_blank">DefCon CTF 2007</a> when <em>invisigoth</em> mention how impressed he was with <em>altas&#8217;</em> leadership qualities during the intense competition as he lead his team, <a href="http://nopsr.us/ctf2007/" title="DefCon CTF 2007" target="_blank"><em>l@stplace</em></a>, to a second, consecutive, victory.  All of this peeked my interested and I was very keen on getting an interview to augment my post on last years DefCon CTF, <a href="http://www.cutawaysecurity.com/blog/archives/176" title="DefCon 15 CTF - WarGamez" target="_blank">DefCon 15 CTF &#8211; WarGamez</a>, but time quickly passed and I went ahead with the post without the interview as I was not aware at the time of <em>altas</em>&#8216; blog, <a href="http://atlas.r4780y.com/cgi-bin/atlas" title="-atlas wandering-" target="_blank">atlas wandering</a>.  After the post I mentioned my disappointment to my good friend Lara and she said, &#8220;Oh, he&#8217;s a great guy.  I&#8217;ll drop him a note tomorrow.&#8221;  For those of you who know Lara, she always comes through.</p>
<p>Sure enough <em>altas</em> emailed me several days later.  We quickly agreed to an interview but because of constant battles with SPAM filtering, multiple projects on both sides, and several <a href="http://atlas.r4780y.com/myimages/VulnCatcher-slides.pdf" title="Vulncatcher at POC" target="_blank">conference</a> <a href="http://www.shmoocon.org/speakers.html" title="Vulncatcher: Fun with VTRACE and Programmatic Debugging" target="_blank">presentations</a> by <em>atlas</em>, we just did not get it completed until a few days ago.   During one of the emails I asked <em>atlas</em> to mention some of the things that he was working on to help me write some pointed questions directed towards his interests.  He mentioned a few:</p>
<blockquote><p>I have been doing some fun stuff with 16-bit real mode, kernel module play in<br />
Linux, BIOS hacking, and of course disassembly and programmatic debugging.</p></blockquote>
<p>My first thought was &#8220;Uh, oh.&#8221;  Sure, I have heard of all of this but if you followed my failings with writing exploits for a <a href="http://www.cutawaysecurity.com/blog/archives/136" title="Testing Shellcode For Functionality" target="_blank">simple</a> <a href="http://www.cutawaysecurity.com/blog/archives/134" title="More Exploit Writing Failures" target="_blank">buffer</a> <a href="http://www.cutawaysecurity.com/blog/archives/131" title="Exploiting Programs - Pointers and Problems" target="_blank">overflow</a> you know that I am not going to be able to dig very deeply into these topics.   I did some quick research on the topics.  Then I reviewed his latest posts on his toolkit, <a href="http://atlas.r4780y.com/resources/atlasutils-2.2.5.tgz" title="atlasutils 2.2.25" target="_blank">atlasutils</a> and reviewed his presentation on <a href="http://atlas.r4780y.com/myimages/VulnCatcher-paper.pdf" title="Vulncatcher Whitepaper" target="_blank">Vulncatcher</a>.  I started to get a little frustrated.  After all, I did not want to waste the excellent opportunity just because I do not have a grasp of the integrate details of complex software and hardware relationships.  Ahhh, bingo.  I hit the nail on the head.  Looking over everything that I can find on <em>altas</em> I realized that he has one of those special eyes for detail.  He can see the integrate relationships within complex systems and understand how to research them.  Or, at least, he understands it enough to try and manipulate the relationship.  Hacking at its finest, its very core.  Excellent.  I might not be able to delve deeply into his research, but I can at least find out his opinions on this complexity.</p>
<p>First, a little Bio on <em>altas</em> stolen from his <a href="http://www.shmoocon.org/speakers.html" title="Look for it" target="_blank">ShmooCon 2008 introduction</a>.</p>
<blockquote><p>atlas is an average joe who spends his time learning new ways to make computer systems dance. When he&#8217;s not slicing and dicing windows and unix binaries, he&#8217;s writing tools to make vulnerability research simpler and more enjoyable. His hobbies include deadlisting (opcode disassembly), vulnerability research, and lately he&#8217;s been working on processor emulation and kernel-mode internals. atlas leads the capture-the-flag team, 1@stplace, who recently won back-to-back victories at defcon, which he blames on his teammates. &#8220;I surround myself with brilliant people,&#8221; he quips.</p></blockquote>
<p>So, without further ado, <em>atlas</em>.</p>
<hr align="center" color="#ff0000" size="2" width="80%" />
<blockquote><p><strong> DefCon CTF</strong></p>
<p><strong>1.  You have lead your team to two straight victories in the DefCon CTF. </strong><br />
<strong> Has this part of your life run its course or is it still challenging enough</strong><br />
<strong> to give it another run?</strong></p>
<p>Wow&#8230; it&#8217;s still challenging!  Each year we have been extremely challenged by<br />
amazing talent.  There is still immense question of how well we will place<br />
this year, with the outstanding talent the Naval Postgrad School puts forth<br />
each year, Vigna&#8217;s team has provided some serious domination in the past, we<br />
have several international teams which are doing very well, and other talent<br />
not yet &#8220;displayed&#8221; at defcon.  We have to go in each year focused on doing<br />
our best, regardless of who and what challenges we face.  How many more years<br />
I have left to give is another question.  It&#8217;s a very consuming weekend, and<br />
quals weekend, even though we don&#8217;t currently have to qualify, is challenging<br />
as well.</p>
<p><strong>2.  Your team is obviously very skilled but the types of personalities I</strong><br />
<strong> imagine that are involved are use to individual performance and behavior.</strong><br />
<strong> Was it a challenge to lead them and keep them focused on goals that</strong><br />
<strong> benefitted the group as a whole?  I.E. tracking down a problem that might</strong><br />
<strong> be too difficult for the competition or not worth the effort.</strong></p>
<p>If I&#8217;ve done anything really well in CTF it is selecting amazing people.  They<br />
have always been an honor to lead, and have actually helped me lead them in<br />
more ways than I can count.</p>
<p><strong>3.  Have you or your team members seen benefits develop from the amount of</strong><br />
<strong> time and effort you have placed in getting ready for DefCon CTF?</strong></p>
<p>Oh totally.  A few of my guys, myself included, have changed career paths<br />
based largely on how well they&#8217;ve proven themselves at ctf.  I can&#8217;t speak<br />
for the others, but I&#8217;m quite happy with the results.  I think we&#8217;ve all seen<br />
improvements in our daily tasks and our abilities to achieve our goals.<br />
We&#8217;ve built strong friendships within the team which has been very good.<br />
Management also responds well to our wins, as they are more likely to think<br />
we know what the heck we&#8217;re talking about.</p>
<p><strong>4.  Are you personally going to give it another run?  Will l@stplace return</strong><br />
<strong> as the same team or will you select different members to keep the blood</strong><br />
<strong> fresh and challenge high?</strong></p>
<p>We&#8217;ll return the same team we left.  I&#8217;ve been fortunate to find such amazing<br />
guys, hand-selected them based on their talent, skill and personality, and<br />
formed lasting friendships that transcend defcon.  I&#8217;m confident from our<br />
talks offline that we will all be returning this year, Lord willing.</p>
<p><strong>5.  Do you believe that there are real world teams, criminal or govenment,</strong><br />
<strong> performing detailed and near real-time application analysis to penetrate</strong><br />
<strong> businesses and government systems, much in the same manner that the teams</strong><br />
<strong> in the last DefCon CTF were doing?</strong></p>
<p>Certainly.  Absolutely.  No Comment.</p>
<p><strong>Program Research and Exploit Writing</strong></p>
<p><strong>6.  What was your background before you started really moving into program</strong><br />
<strong> and architecture research?</strong></p>
<p>I had been a coder since I was young, but got a career in sys-admin work, then<br />
moved into data-telecom where I was responsible for many security-related<br />
services, then got drafted into security.</p>
<p><strong>7.  To me some of the concepts are difficult to grasp and implement when</strong><br />
<strong> there are resources.  What did you do to help you get over the hump and</strong><br />
<strong> begin to fully understand the intricacies of low level programming and</strong><br />
<strong> analysis?</strong></p>
<p>Gave up.  Then I redoubled back.  I was freaked out at the possibility I&#8217;d<br />
fail.  So I decided that I couldn&#8217;t do it.  Once I had finished freaking out<br />
I decided to work it and grow.  Some people could and were doing this stuff,<br />
what&#8217;s the cost of throwing myself into the learning curve and seeing where<br />
it lead?</p>
<p><strong>8.  Your toolset, atlasutils, is a combination of python programs and</strong><br />
<strong> script that include a disassembler and other tools that help located and</strong><br />
<strong> provide information to exploit vulnerabilities.  I have noticed that Dave</strong><br />
<strong> Aitel likes to talk about writing his own debuggers as well.  Is this</strong><br />
<strong> because the tools that are out there are not useful, you have different</strong><br />
<strong> ideas that did not go into the usual debugger, or that you just need</strong><br />
<strong> something to help fit a specific niche?  Or, it is just fun to write your</strong><br />
<strong> down debugger? <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </strong></p>
<p>To quote a very good friend of mine, I write code because I&#8217;m lazy.  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />   Truth<br />
is, using others&#8217; tools is tiring, since I have to learn to think like<br />
them&#8230;  Writing my own forces to me to learn how to think about the things<br />
I&#8217;m trying to do, then write tools that help me next time I have to do them.<br />
I hope people find my tools useful, but they&#8217;re really for my benefit.  I<br />
often write my own tools because I&#8217;m forced to learn the details better&#8230;<br />
and then I can add my own whizbang fun new stuff on from there.  For<br />
instance, I&#8217;m rewriting disass, because there was an upper-limit in binary<br />
size, above which it simply took forever to process because of inefficient<br />
use of memory.  It was also very &#8220;dogmatic&#8221;, and not agile.  Some code I want<br />
to disassemble is packed/encrypted and wrapped with an unpacker/decryptor.<br />
That means the data/code actually changes post-loading.  Disassemblers have<br />
to account for that, which means they have to be &#8220;agile&#8221;, or able to adjust<br />
how they view the memory setup of a binary.  I&#8217;m also working parts of the<br />
remake of disass into an emulator (no, not complete emulation) which will<br />
allow me to better address certain laborious tasks.</p>
<p><strong>9.  When you are developing these tools, how do you pick a program to</strong><br />
<strong> analyze? Do you generate your own vulnerable code or find something with</strong><br />
<strong> known vulnerabilities to analyze?</strong></p>
<p>When developing tools I try to use them on anything I want to analyze, just to<br />
see them break (and wow they break).  Sometimes it&#8217;s code I&#8217;ve snagged from<br />
ctf, sometimes it&#8217;s my own code, sometimes it&#8217;s POSIX code or Win32 code, or<br />
&lt;insert-your-fav-commercial-app&gt; code.</p>
<p><strong>10.  As I look at the types of research you are performing I start to</strong><br />
<strong> wonder if computers are just too complex.  Or if the higher level</strong><br />
<strong> programming languages that we have just cannot securely support all of the</strong><br />
<strong> low level functionality.  Then I start thinking about the interactions and</strong><br />
<strong> complexity added by software and hardware interaction, BIOS, and firmware</strong><br />
<strong> and my head really starts to spin.  What are your thoughts on this</strong><br />
<strong> complexity and how it is affecting the security of technology as a whole?</strong></p>
<p>Well, you&#8217;ve really nailed it.  Computers have become very complex indeed&#8230;<br />
and continue to do so.  In many layers of &#8220;synthesis&#8221; the computer industry<br />
has striven to group low-level functions into simple-to-use functionality;<br />
for the developers and ultimately the end users.<br />
Each iteration of simplification masks many details from the users/developers,<br />
and with the disappearance of those details comes many assumptions.<br />
Assumptions are inevitable in our industry because you can&#8217;t teach *every*<br />
administrator and developer *every* detail about the computer.  Some in the<br />
security field have attained a great deal of understanding those details&#8230;<br />
and we tend to hail them as deities.<br />
False assumptions and the state of mind induced by details-overload work<br />
together to provide vulnerabilities for attackers to leverage.  Sometimes<br />
those vulnerabilities highlight a loss of communication, laziness, lack of<br />
understanding, or simply mistakes.</p>
<p>This dilemma is not going away.  We continue to see layered-development and a<br />
push for ease-of-use at every level.  Ease-of-use tends to be directly<br />
counter to security, in that we enable users and developers to do mighty<br />
things without realizing the truth of what they are doing.  For example,<br />
without proper education and focus on security, thousands of SQL-Servers were<br />
put on the Internet with a blank SA password (the default).</p>
<p>Security must become a baked-in part of the development culture.  Developers<br />
need to be screened for how seriously they take security, and continually<br />
trained and updated on new security problems, such as format-string bugs and<br />
buffer overflows in the 90s.  When the next new common programming flaw is<br />
identified, those mistakes must be put in front of developers to warn them<br />
and instruct what the computer is actually doing, or how attackers are<br />
leveraging the flaws to do evil things.  Each development team needs to have<br />
someone who understands how to think like an evil d00d.  I venture to say<br />
that every developer should become that person.</p>
<p>This complexity provides plenty of playground for attackers, but hackers are<br />
rising to the occasion, finding enjoyment in understanding systems better<br />
sometimes than their creators.  We insert stop-gap protections like ASLR and<br />
anti-corruption techniques and hackers find ways around them.  Worse than the<br />
time lost in the creation and adoption of those protections is the<br />
complacency they allow developers, who wrongfully think they are protected.<br />
With all the complexity of just learning someone else&#8217;s API and interacting<br />
with third-party products, as well as designing corporate-wide API&#8217;s that<br />
hundreds of developers may use, they are happy to think on the good sides to<br />
such protections, without being able to understand the details or<br />
limitations.  Even if they have the base-knowledge to understand, they simply<br />
are seldom given the time.</p>
<p><strong>11.  With this complexity, how can developers fix it?  I mean, programmers</strong><br />
<strong> just do not have the time and resources to think of every little piece of</strong><br />
<strong> the puzzle.  We cannot expect them to.  So, how do developers protect their</strong><br />
<strong> projects?  Do we just need to realize that we are in a constant state of</strong><br />
<strong> possible exploitation and accept that very expensive systems will get</strong><br />
<strong> exploited and we better have a good incident response team?</strong></p>
<p>See above&#8230; Good incident handling teams are invaluable for an organization.<br />
Teams who understand proactive security and the patching process are equally<br />
important.  Consider them &#8220;stoppers&#8221; and &#8220;sweepers&#8221; if you like futbol.</p>
<p>In the end, the ball is the developer&#8217;s court.  Each person who writes code<br />
needs to learn the details of what they are doing, and accept responsibility<br />
for the security of their work.  If format-string bugs seem impossible to<br />
exploit, that developer needs training (SANS SEC504 is generally very good<br />
for that).  If XSS doesn&#8217;t seem to be a big deal, training is necessary.<br />
Aside from great training, that SANS course will likely provide networking<br />
opportunities with people who think evil all day every day.  BlackHat and<br />
defcon are also good venues, but likely less substantive.  We need to stop<br />
training our developers only about how to enable things&#8230; because that only<br />
enables exploits.</p>
<p><strong>12.  Along the lines of complexity, most of the technologies that are put</strong><br />
<strong> out there, operating systems and applications, automatically have these</strong><br />
<strong> complexities built into them as features.  The Center of Internet Security</strong><br />
<strong> has long benchmarks to help guide administrators through steps that help</strong><br />
<strong> them limit their exposure to some of these complexities, but with each new</strong><br />
<strong> release of a product the administrator has to be worried about what is new</strong><br />
<strong> or what was modified that exposes the environment to additional risk.  What</strong><br />
<strong> recommendations can you make to these administrators as they are taking</strong><br />
<strong> these complexities into consideration?</strong></p>
<p>Good luck?  The truth is that CIS spits out some outstanding documents to help<br />
us get a certain level of security with the least outlay of effort.  It&#8217;s a<br />
bang-for-your-buck arrangement.  Unfortunately no benchmark or security guide<br />
is going to take the place of a solid understanding of the technologies one<br />
is using.  Best case, CIS guides serve as a litmus test and a guide to<br />
someone who already has a great understanding and the curiosity to know their<br />
playground well.  Someone who knows enough to know how much they don&#8217;t know<br />
so they welcome the help, but someone who plays with their tech and groks<br />
it&#8230; because they want to.  This is the part where I get to piss a lot of<br />
people off&#8230; if you don&#8217;t love security or IT or IS&#8230; get out.  There are<br />
many professions where you may be happier and more successful.  Computers<br />
have become the next &#8220;Doctor&#8221; or &#8220;Lawyer&#8221; profession, where people flood<br />
Computer college programs in hopes of a mighty paycheck.  Those people<br />
everyone views as gods in this industry are people who would tinker anyway,<br />
even if they were janitors during the day.  And if you *do* tinker and wind<br />
up in the industry&#8230; get yourself some security understanding.  Learn to<br />
think as your opponent&#8230; think about how someone who hates your guts and<br />
your programs would mess with them.  Get the training, from an organization<br />
or a friend if you cannot afford formalized training.<br />
And remember, patching is a vital, ongoing process organization-wide.</p>
<p>@</p></blockquote>
<hr align="center" color="#ff0000" size="2" width="80%" /> Of course you have to love any question that ends in &#8220;No Comment.&#8221;  The Mission Impossible music always seems to kick in at those moments.<br />
I hope all of you enjoyed this as much I as did.  Thank you to <em>altas</em> for being so patient and generous with his time.<br />
Of course, thank you to Lara who always pulls through for me and my family.</p>
<p>Go forth and do good things,<br />Don C. Weber</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/atlas" rel="tag">atlas</a>, <a href="http://www.technorati.com/tag/exploits" rel="tag">exploits</a>, <a href="http://www.technorati.com/tag/vulnerabilities" rel="tag">vulnerabilities</a>, <a href="http://www.technorati.com/tag/defcon" rel="tag">defcon</a>, <a href="http://www.technorati.com/tag/ctf" rel="tag">ctf</a>, <a href="http://www.technorati.com/tag/atlasutils" rel="tag">atlasutils</a>, <a href="http://www.technorati.com/tag/vulncatcher" rel="tag">vulncatcher</a>, <a href="http://www.technorati.com/tag/InGuardians" rel="tag">InGuardians</a>, <a href="http://www.technorati.com/tag/skoudis" rel="tag">skoudis</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/atlas+wandering" rel="tag">atlas wandering</a>, <a href="http://www.technorati.com/tag/l@astplace" rel="tag">l@astplace</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/229/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ron Woerner &#8211; an Email Interview</title>
		<link>http://www.cutawaysecurity.com/blog/archives/213</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/213#comments</comments>
		<pubDate>Wed, 28 Nov 2007 04:00:36 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Catalysts]]></category>
		<category><![CDATA[Speaking]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/213</guid>
		<description><![CDATA[Speaking, presentations, guided group discussions, brown bags, technical talks, impromptu meetings, moderated conference forums: security professionals at some point find themselves talking out loud in front of a wide variety of groups with a wide variety of skills and interests.  Indeed, I personally believe that speaking in front of a group of people is [...]]]></description>
			<content:encoded><![CDATA[<p>Speaking, presentations, guided group discussions, brown bags, technical talks, impromptu meetings, moderated conference forums: security professionals at some point find themselves talking out loud in front of a wide variety of groups with a wide variety of skills and interests.  Indeed, I personally believe that speaking in front of a group of people is one of the key skills necessary for all security professional.  Although some people are born with this skill, the rest of us have to work at it.  It takes guts, time, knowledge, and practice, practice, practice.  </p>
<p>Luckily for all of us we have security professionals like Ron Woerner.  Ron is a professional speaker who strives to provide guidance and leadership about speaking to anybody who will take the time to listen.  More than once I have found myself turning to Ron and he has always made time for me.</p>
<p>Because of his expertise in speaking and security I decided that it would be a good idea to have Ron do an email interview about security professionals and speaking.  First, let&#8217;s start with a little background on Ron.</p>
<blockquote><p>
Ron Woerner has over 17 years of experience in the security industry.  He has been quoted in CSO, SC, and Information Security magazines and has been a noted speaker at security conferences throughout the U.S. including the RSA, CSI and NebraskaCERT Security Conferences. He has been employed as an Air Force Intelligence Officer, the Information Security Officer for the Nebraska Department of Roads, a UNIX administrator for the Mutual of Omaha Companies, and the Lead Security Engineer for CSG Systems, ConAgra Foods and now TD Ameritrade. Ron earned a Bachelors degree from Michigan State University and a Masters degree from Syracuse University in Information Systems. He was awarded the CISSP security certification in August of 2001, the NSA IAM certification in August of 2003, the Certified Ethical Hacker (CEH) designation in December 2005 and is a Certified Forensics Investigator.
</p></blockquote>
<p>Before we get into the interview, I would like to thank Ron for his very detailed responses.  He really went above and beyond my expectations.  It does not surprise me, but I am truly thankful.</p>
<p>Now onto the interview.  The following, unedited, text is my questions and Ron&#8217;s responses.</p>
<blockquote><p>
<strong>1. In Episode 84 of the Network Security Podcast (<a href="http://netsecpodcast.com/?p=5">http://netsecpodcast.com/?p=5</a>), Rich Mogul talked about the importance of<br />
presenting skills.  How important is presenting to a security professional and do you think it is any different from that of any other professional?</strong></p>
<p>I agree fully with Rich Mogul that Security Professionals need to be able communicate in both speaking and writing.  </p>
<p>Communication skills distinguish security professionals from security technicians. This includes both spoken and written skills.  We are constantly selling our ideas.  If you can’t communicate, you can’t sell.  As a security professional, we need to be able to communicate well in order to influence others behaviors to be more secure.</p>
<p>We speak for three primary reasons: to influence, to inform, and to entertain. In security, we are primarily trying to influence others to be more secure.  Occasionally we are informing others about the state of security.  Even in technical presentations, don’t discount the need to entertain.  Think about the best speakers you’ve ever heard.  They were entertaining while informing or influencing.  </p>
<p>Consider the Wall St. Journal’s <a href="http://www.collegejournal.com/bschool03/articles/20020909-alsop-mbasurvey.html">list</a> of the traits that recruiters look for in business school candidates:</p>
<ul>
<li>Communication and interpersonal skills</li>
<li>Original and visionary thinking</li>
<li>Leadership potential </li>
<li>Ability to work well within a team</li>
<li>Analytical and problem-solving skills</li>
</ul>
<p>I ask, “Shouldn’t this be a similar list for security professionals?”  </p>
<p><strong>2. Do you think that the students coming out of college today are lacking the basic skills necessary for presenting information to a group?</strong></p>
<p>I don’t think they’re only missing the skills; they’re missing an understanding of its importance.  They will blow-off a basic communications class without realizing that it’s core to their success later on. </p>
<p>Additionally, many college classes require presentations, but often the students are told to do it without being shown how.  A history professor does not feel it is their place to show students the basics of presenting.  Plus the students aren’t given the right feedback to improve.  </p>
<p>There are two primary types of speaking: prepared and impromptu.  Most college classes focus only on the former.  This is unfortunate because the ability to speak without preparation or notes can easily separate high achievers.  </p>
<p>Security professionals need to be able to speak without a lot of preparation, because you never know when you’ll be called into the CIO’s office.</p>
<p><strong>3. The latest Security Ripcord Poll asks is there is a difference between presenting and being able to lead a group discussion.  Are these different skill sets or do you think they fall into the same category?</strong></p>
<p>I agree that, “All security professionals should be able to present well and lead conversations.”<br />
However, these are two different, yet related skill sets.  In presenting, you are front and center. You need to be able to address all questions and be seen as the SME.   In leading group discussions, the focus is on the topic and participants.  You don’t need to know the answers, but you do need to what questions to ask.  Plus the group is the SME.  </p>
<p>As Tony Jeary says, “<a href="http://books.google.com/books?id=LlUTCGOyrLEC&#038;printsec=frontcover&#038;dq=Tony+Jeary&#038;sig=Nu2KsBFJR7MEGVkZOa0-PpBpPB0">Life is a series of presentations.</a>”  Even in a group discussion, you will be presenting.  Both traits demonstrate the need for security professionals to be leaders.  As a security leader, you may be called to give a presentation or you may need to lead a discussion group.  You better be prepared.  One way is to learn and practice both skills.</p>
<p><strong>4.  What are some common mistakes that people who are new to presenting will find themselves doing?  What are ways to overcome these mistakes?</strong></p>
<p>Mistake #1:  Not preparing for everything. This includes the basics, but also the unexpected.  Murphy lives at presentations.  If the technology can break, it will.  Be ready for it. </p>
<p>Mistake #2: Depending too much on PowerPoint.  See #1.  Be ready to speak without a PowerPoint.  Don’t bulletize everything you’re going to say.  People came to hear you speak, not to read a book.  Also, don’t…read…from…your…slides. (See the <a href="http://www.lifehack.org/articles/communication/smallest-presentation-hack-ever.html">Smallest Presentation Hack Ever.</a>)  I’ve seen too many good presentations spoiled because of that.</p>
<p>Mistake #3: Too many grunts.  Grunts are ums, ahs, and ya knows that fill a presentation. Here’s a great LifeHack has a great article on it: <a href="http://www.lifehack.org/articles/lifehack/how-to-cut-crutch-words-when-giving-a-speech.html">http://www.lifehack.org/articles/lifehack/how-to-cut-crutch-words-when-giving-a-speech.html</a>. Most people don’t realize how much they grunt until they start listening to themselves.  </p>
<p><strong>5. What are some common mistakes that professional speakers can find themselves doing if they are not careful.  Can you recommend ways they can determine they are doing these things?</strong></p>
<p>See point 4 above.  Those mistakes can happen to anyone.</p>
<p>The most common mistake for experienced speakers is not fighting for feedback.  You need an unbiased evaluation in order to see your mistakes and grow.  Our good friend, Michael Santarcangelo (<a href="http://www.securitycatalyst.com/">http://www.securitycatalyst.com/</a>) pointed out that most professional sportsmen have coaches.  Speakers so have one as well.  </p>
<p><strong>6. If you had to pick one method to help a person improve their speaking skills, what would it be?</strong></p>
<p>Darren LaCroix, the 2001 World Champion of Speaking, has a mantra for building talent as a speaker: “Stage time, stage time, stage time.” Take every opportunity you can get to present; whether it’s with a couple of people or a whole roomful.  </p>
<p>One great place to develop both your speaking and leadership skills is Toastmasters (<a href="http://www.toastmasters.org/">http://www.toastmasters.org/</a>). A local Toastmasters club can provide all of the things I’ve talked about here.  You get practice with both planned and impromptu speeches.  You get evaluations from other experienced speakers.  You can also get leadership experience.  You can even take part in their many speaking competitions.  All for a low cost.  (I won’t say how much or else it may sound like a commercial.) </p>
<p><strong>7. Do you think that the use of presenting software like Microsoft Power Point or Apple&#8217;s Keynote have adversely affected the present skills of today&#8217;s professionals?</strong></p>
<p>I once asked Craig Valentine, another World Champion speaker why he didn’t use PowerPoint.  He laughed.  We place far too much reliance on presenting software.  It’s supposed to supplement our presentation, not be its focus.  Presentation Revolution has great comments on how, when, and where to use those programs. See its Change This manifesto: <a href="http://www.changethis.com/35.05.Presentation">http://www.changethis.com/35.05.Presentation</a>.</p>
<p><strong>8. Could you recommend any books, blogs, or websites that people can use to gather information about presenting skills?</strong></p>
<ul>
<li><a href="http://www.toastmasters.org/">Toastmasters</a>.  Join a club near you.  </li>
<li>Dale Carnegie has a number of books on leadership, speaking, and improving your people skills. </li>
<li><a href="http://www.peterursbender.com/spp/">Peter Urs Bender</a>, Secrets of Power Presentations (plus many other articles)</li>
<li>Businessballs article on Presentation Skills (<a href="http://www.businessballs.com/presentation.htm">http://www.businessballs.com/presentation.htm</a>).  We’re always saying that security needs to better connect with business.  Businessballs shows how.</li>
<li>I’ve also mentioned a number of sites through-out my comments above.</li>
</ul>
<p><strong>9.  Is there anything I have missed that you think it is important to talk about when discussing presenting skills?</strong></p>
<p>Don’t be afraid to get up and do it.  You really have little to lose and much to gain. Plus, it’s addicting, once you get into it.</p>
<p><strong>10. Is there anything you are working on that you would like people to know about?</strong></p>
<p>We are continuing to build the Security Catalyst Community (<a href="http://www.securitycatalyst.org/forums/">http://www.securitycatalyst.org/forums/</a>).  This is a great way to connect with other security professionals from around the globe.  </p>
<p>Let me know if you’re going to RSA 2008 in San Francisco.  I look forward to talking with you.</p>
<p>“By working together, we all become stronger.”</p>
<p>Ron W
</p></blockquote>
<p>Go forth and do good things,<br />
Don C. Weber</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/speaking" rel="tag">speaking</a>, <a href="http://www.technorati.com/tag/security" rel="tag">security</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a>, <a href="http://www.technorati.com/tag/Ron+Woerner" rel="tag">Ron Woerner</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/213/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Michael Farnum &#8211; an Email Interview</title>
		<link>http://www.cutawaysecurity.com/blog/archives/193</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/193#comments</comments>
		<pubDate>Wed, 26 Sep 2007 04:38:49 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Logging]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/193</guid>
		<description><![CDATA[I was going to post a comment to Michael&#8217;s Computer World post titled &#8220;OK CXO, does this incident convince you of the need for security???&#8221; when I decided not to do it.  Instead I realized that this is a prefect opportunity to do another Email Interview.  So I hammered out a few questions [...]]]></description>
			<content:encoded><![CDATA[<p>I was going to post a comment to Michael&#8217;s Computer World post titled &#8220;<a href="http://www.computerworld.com/blogs/node/6229">OK CXO, does this incident convince you of the need for security???</a>&#8221; when I decided not to do it.  Instead I realized that this is a prefect opportunity to do another Email Interview.  So I hammered out a few questions I figured would be easy to answer and then tossed them his way.  The following are his responses with the questions included in bold.</p>
<blockquote><p>
<strong>Who do you work for and what do you do?</strong></p>
<p>Accuvant.  Pre-sales Security Engineer.  Basically, I am in customer<br />
relations, with the occasional product evaluation installation thrown<br />
in.</p>
<p><strong><br />
Centralized logging is one of the keys to a good security posture.<br />
Percentage-wise, how many companies do you see doing this?</strong></p>
<p>Unfortunately, the customers I have been dealing with are very late<br />
coming to this game.  And I am not talking about SIEM either.  Just<br />
centralized logging.  Many of them have some kind of syslog server with<br />
a few logs getting thrown to it, but very few have any kind of real<br />
centralized logging solution where they can go do forensics and get a<br />
good idea of what was happening in their network as a whole at any given<br />
time.</p>
<p><strong>When they are designing the networks, do you find that the<br />
administrators are aware of the pitfalls and nuances of setting up a<br />
logging infrastructure?</strong></p>
<p>Generally they think it is just a matter of throwing some logs into a<br />
bucket o&#8217; hard drives and that is it.  Not many think about the logs<br />
being used for forensic purposes later in the case of an incident.  Many<br />
aren&#8217;t aware that normalizing logs pretty much makes it fodder for the<br />
defense attorney.  Administrators up until now have had to be concerned<br />
with keeping servers going, and they read the logs when there is a<br />
problem.  Most don&#8217;t think from a security mindset, so they don&#8217;t have a<br />
clue what to do to if those logs aren&#8217;t there (because they got deleted<br />
by Mr. Bad Guy).  There&#8217;s also the matter of retention and drive space,<br />
maintaining the logs in such a manner that they can&#8217;t be altered, etc.<br />
I mean, that is the central reason for logs: forensics.  And forensics<br />
does not necessarily mean criminal forensics.  It means that if there is<br />
any incident, malicious, accidental, mechanical, whatever.  And if the<br />
logs get corrupted, then you have problems.</p>
<p>Another problem that people don&#8217;t think about is application logs and<br />
&#8220;x&#8221;-flow data.  These are often very critical to determining what<br />
happened in incidents because they give you two ends of the spectrum<br />
that just server and device logs don&#8217;t give you.  Of course, that will<br />
greatly increase your storage needs, so be careful.</p>
<p><strong>Where are the common weaknesses and how can we educate our<br />
administrators better?  Certifications associated with log management<br />
and review?</strong></p>
<p>See above for common weaknesses.  As far as another specialized cert, I<br />
don&#8217;t think that is the way to go.  I know SANS is big on this, and I<br />
have nothing but respect for those guys, but I really think that<br />
security cannot be stovepiped anymore.  Security has to be a part of a<br />
sys admin&#8217;s job and training.  This is one facet of that training, and<br />
it realistically not all of security can be thrown into a couple of<br />
Windows courses.  But the mindset has to be taught more.  A single cert<br />
can&#8217;t do that.</p>
<p><strong>Is it common practice to have critical systems administered through a<br />
management network that does not touch the production network?<br />
Basically, a network that is separated from the intranet and Internet?</strong></p>
<p>Do you mean having something like separate NICs in critical servers<br />
plugged into a different VLAN for management, and plugging management<br />
NICS on devices into that same VLAN?  To my knowledge, that is not very<br />
common.  It makes sense, but I could see it being something of a<br />
headache to get setup.  As far a segmenting critical systems altogether,<br />
that is happening in a big way.  PCI is driving that everywhere.</p>
<p><strong>Can Small and Medium-Size Businesses really afford taking on a project<br />
like centralized log management?  What would be the first steps?</strong></p>
<p>Yes, SMB&#8217;s can do this.  I does not have to be expensive.  I did it when<br />
I was at an SMB.  I used the PRO version of KIWI syslog server<br />
(http://www.kiwisyslog.com/) and pointed all my devices and servers at<br />
it.  I used SNARE (http://www.intersectalliance.com/projects/Snare/) to<br />
push server logs to the KIWI syslog.  KIWI even has the ability to read<br />
application logs if they are put into a flat file.  It really is not<br />
hard to setup if you are willing to take the time to organize it.  But<br />
be sure to take note of the problems mentioned above.</p>
<p><strong>Do you have any recommendations for the Small/Home Office businesses<br />
when it comes to log management?</strong></p>
<p>See above.  Should also work for them.</p>
<p><strong>Companies are generally aware that they need to backup their common and<br />
critical data.  How much are they aware that they need to do the same<br />
with logs?  What is common practice in log retention?</strong></p>
<p>I think they are becoming MORE aware, but the awareness is not where it<br />
should be.  Again, this is a failing in training.  Security is not<br />
taught as a &#8220;baked-in&#8221; component of knowledge.</p>
<p>Common practice depends.  It seems like 7 years tends to be a good<br />
retention length of time, but that can change depending on compliance<br />
and other laws.  </p>
<p><strong>What types of sensitive information could be found in logs and what does<br />
this mean about the protections associated with collecting and retaining<br />
this information?  When do you think encryption would be necessary?</strong></p>
<p>It is feasible for access logs on servers containing data to hold<br />
sensitive information such as credit card numbers, SSN&#8217;s, etc.  It is<br />
also feasible for logs from network devices such as routers and<br />
firewalls to have sensitive data in them because the data passes through<br />
them.  That is why PCI specifically addresses this issue.</p>
<p>Encryption of sensitive fields in a database should always be in place.<br />
Encryption when transmitting data should be the norm.  And obfuscation<br />
of sensitive data (&#8220;x&#8221;ing out most of the SSN number or the CC number)<br />
should be done when records are viewed by parties that do not need the<br />
information to perform their duties.</p>
<p><strong>How does log management tie into forensic investigations?</strong></p>
<p>As I mentioned above, log management is crucial to forensic<br />
investigations.  Most log management systems normalize logs because they<br />
have to store the data in a manageable format.  However, there has to be<br />
some way to recover the raw log in order for the log to be used in<br />
investigations.  It is not as crucial if all you are trying to do is<br />
determine what happened in an event.  But if plans are to use the logs<br />
in prosecution of criminal activity, then you have to be able to prove<br />
that the logs are the raw, original logs that came from the servers and<br />
devices.  </p>
<p>If an investigation team walks in the crime scene and fouls evidence,<br />
the judge is very likely not to admit it.  Or if the cops don&#8217;t retain a<br />
good chain of custody of the evidence, then the defense lawyer can make<br />
the claim that there is no way to know that the police did not alter the<br />
evidence in some fashion. Logs are evidence, so the same rules apply.</p>
<p><strong>Do any of the forensic programs out there integrate with the logging<br />
solutions you are familiar with?</strong></p>
<p>Good question.  I don&#8217;t know of any that do off the top of my head.<br />
However, if standards are used to code each one, there is likely a way<br />
to integrate them and transfer logs between them.  But again, this can<br />
only be done successfully if the evidence is not altered in doing so.</p>
<p><strong>How can your company help with the issues related to this topic?</strong></p>
<p>Accuvant has four practice areas (Security Assessment, Compliance,<br />
Security Technologies, and Wireless).  Our compliance team would be<br />
specifically helpful with this kind of issue because they know the<br />
different compliance controls that would require a company to adhere to<br />
log management standards, and they could perform a gap analysis to let a<br />
company know where they are lacking.  They can also provide remediation<br />
assistance to fill the gaps.</p>
<p>The assessment team can perform policy review and architecture review to<br />
tell a company where they are lacking in this area and their security<br />
posture as a whole.  They can also perform penetration and vulnerability<br />
tests to see what is getting logged and at what level.  And they can<br />
perform application code review to determine if an app&#8217;s logging is<br />
sufficient.  They can also provide remediation assistance.</p>
<p>The security technologies team can help in recommending an appropriate<br />
log management solution, and they can provide professional services for<br />
installation, configuration, and management of the solution.</p>
<p>The wireless team does not seem to be specific to this issue, but<br />
wireless is actually an area that many administrators and managers tend<br />
to kind of forget is in their network.  Thus, logging rarely happens<br />
from these devices.  Our wireless team has expertise with many different<br />
manufacturers of wireless technology, and they would be able to provide<br />
best practices for gathering logs from these devices.</p>
<p><strong>You are a blogger and Internet author.  Tell us a bit about that.</strong></p>
<p>Internet author??  Really just a blogger since I have rarely written<br />
anything more than a page at one time.  But oh well.  It sounds good!</p>
<p>I started blogging a little over a year ago when I was in the trenches<br />
as an Information Security Manager at a small / medium-sized psychiatric<br />
clinic in Houston.  I really enjoyed being able to write about the<br />
things I ran into during the course of my job.  It gave me a chance to<br />
grow as a security professional, and it really helped me hone my writing<br />
style.</p>
<p>As I went forward with it, I realized that it was also a way to get my<br />
name known out in the world of security, which I think will help my<br />
career in the long run.  </p>
<p>I maintain two security-related blogs.  My personal blog is at<br />
<a href="http://infosecplace.com/blog">http://infosecplace.com/blog</a>.  That one is known as An Information<br />
Security Place.  I also blog about security at ComputerWorld at<br />
<a href="http://computerworld.com/blogs/farnum">http://computerworld.com/blogs/farnum</a>.</p>
<p>I also have a personal blog at <a href="http://infosecplace.com/tangential">http://infosecplace.com/tangential</a>.  I<br />
don&#8217;t update that on a lot.  It is mainly a place to keep anything<br />
personal I want to write about, and it helps me maintain a more pure<br />
security blog.
</p></blockquote>
<p>Nothing really ground breaking here.  Just a few questions that I thought might help others that are thinking about centralized logging.  Hopefully Michael&#8217;s answers will help you when you are considering initiating or increasing logging and log management within your environment.</p>
<p>I would like to thank Michael again for taking time out of his very busy schedule to answer these questions.  Check out his sites when you have a few extra minutes.  It is definitely worth bookmarking or placing into your feeds.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/logging" rel="tag">logging</a>, <a href="http://www.technorati.com/tag/Accuvant" rel="tag">Accuvant</a>, <a href="http://www.technorati.com/tag/An+Information+Security+Place" rel="tag">An Information Security Place</a>, <a href="http://www.technorati.com/tag/Computer+World" rel="tag">Computer World</a>, <a href="http://www.technorati.com/tag/Michael+Farnum" rel="tag">Michael Farnum</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/193/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>RSA Interview of Cutaway by Martin McKeay</title>
		<link>http://www.cutawaysecurity.com/blog/archives/118</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/118#comments</comments>
		<pubDate>Mon, 12 Mar 2007 06:44:32 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Helpful]]></category>
		<category><![CDATA[Interviews]]></category>
		<category><![CDATA[Kudos]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/118</guid>
		<description><![CDATA[I was interviewed by Martin McKeay of the Network Security Blog for PodTech at RSA 2007.  I had the pleasure of running around with Martin a lot during the conference.  He worked really hard and we should be seeing more than a few interviews coming from the footage taken at the Verizon Business [...]]]></description>
			<content:encoded><![CDATA[<p>I was <a href="http://www.mckeay.net/secure/2007/03/two_more_videos_rsa_2007.html" title="Two More Videos RSA 2007">interviewed by Martin McKeay</a> of the <a href="http://www.mckeay.net/secure/" title="Network Security Blog">Network Security Blog</a> for <a href="http://www.podtech.net/home/" title="PodTech">PodTech</a> at <a href="https://www.rsaconference.com/2007/us/" title="RSA 2007">RSA 2007</a>.  I had the pleasure of running around with Martin a lot during the conference.  He worked really hard and we should be seeing more than a few interviews coming from the footage taken at the <a href="http://www.verizonbusiness.com/us/" title="Verizon Business">Verizon Business</a> and <a href="http://www.f5.com/" title="F5">F5</a> booths.</p>
<p>In this interview we talk about how big the <a href="https://cm.rsaconference.com/US07/catalog/processSearchExhibitorCatalog.do?action=search&#038;showAll=true" title="RSA 2007 Vendor List">Vendor Exposition floor</a> was and how it was almost overwhelming for a first time, large conference, attendee.  The product I mention in the video is the <a href="http://www.norman.com/microsites/malwareanalyzer/" title="Norman Malware Analyzer">Norman Malware Analyzer</a>.  I still think that this type of product would be a good step for an incident response team who has found themselves responding to many malware incidents and outsourcing the analysis of that code to determine the actual intent of the malware.  I do have to say, though, that this is the first product I have seen to perform this task so although there may be others out there this is the first to which I have been exposed.  Something I just found, but haven&#8217;t watched yet is a SANS webcast covering this product: <a href="https://www.sans.org/webcasts/show.php?webcastid=90771&#038;utm_source=web&#038;utm_medium=text-ad&#038;utm_content=affiliate_link1&#038;utm_campaign=Cutaway_Security">Ask The Expert Webcast: Malware Analysis Shortcuts</a>.  Check it out and let me know what you think in the comments.</p>
<p>Here is the interview.  I hope you enjoy.</p>
<p><embed type="application/x-shockwave-flash" src="http://www.podtech.net/player/podtech-player.swf?bc=3F34K2L1" flashvars="content=http://media1.podtech.net/media/2007/03/PID_010485/Podtech_RSA_2007_Cutaway.flv&#038;totalTime=299000&#038;" height="269" width="320" /></p>
<p>I just realized that there are two videos.  This second one is a mixture of several interviews that Martin did throughout the conference.  Nothing new from me but the other interviews are worth checking out.</p>
<p><embed type="application/x-shockwave-flash" src="http://www.podtech.net/player/podtech-player.swf?bc=3F34K2L1" flashvars="content=http://media1.podtech.net/media/2007/03/PID_010481/Podtech_Verizon_RSA_New_communication.flv&#038;totalTime=789000&#038;" height="269" width="320" /></p>
<p>Thank you, Martin, for this and all rest of your support throughout the year.</p>
<p>UPDATE:  I corrected the glaring mistake I made in the name of the Norman Malware Sandbox Analyzer.  Thank you to <a href="http://anti-virus-rants.blogspot.com" title="Anti-virus Rants Blog">Kurt Wismer</a> for pointing that out to me and my apologies to Norman for the mistake</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/RSA" rel="tag">RSA</a>, <a href="http://www.technorati.com/tag/Norman" rel="tag">Norman</a>, <a href="http://www.technorati.com/tag/McKeay" rel="tag">McKeay</a>, <a href="http://www.technorati.com/tag/PodTech" rel="tag">PodTech</a>, <a href="http://www.technorati.com/tag/SANS" rel="tag">SANS</a>, <a href="http://www.technorati.com/tag/F5" rel="tag">F5</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/118/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>RaDaJo, an E-mail Interview</title>
		<link>http://www.cutawaysecurity.com/blog/archives/104</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/104#comments</comments>
		<pubDate>Mon, 12 Feb 2007 03:29:28 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Helpful]]></category>
		<category><![CDATA[Interviews]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/104</guid>
		<description><![CDATA[My initial interview with B10m sparked my interest in the security professional field in Europe.  As I had recently contacted the trio from RaDaJo about helping me notify a Spanish University one of their servers had been compromised, I decided to contact them with similar questions.  The RaDaJo name is a combination of [...]]]></description>
			<content:encoded><![CDATA[<p>My initial <a href="http://www.cutawaysecurity.com/blog/archives/96" title="Interview with B10m">interview with B10m</a> sparked my interest in the security professional field in Europe.  As I had recently contacted the trio from <a href="http://radajo.blogspot.com/index.html" title="RaDaJo">RaDaJo</a> about helping me notify a Spanish University one of their servers had been compromised, I decided to contact them with similar questions.  The RaDaJo name is a combination of the team member&#8217;s names:  RAul Siles, DAvid Perez, and JOrge Ortiz.</p>
<p>I had originally met these security professionals during a GSEC Advisory Board meeting in Washington D.C.  At the time they were working on another certification that would eventually apply towards their <a href="http://www.giac.org/certifications/gse.php" title="GSE">GIAC Security Expert</a> certification.  As you can see from the website they were the third, fourth, and fifth persons to receive this <a href="http://www.giac.org/certifications/GSE2005.pdf" title="See what it took.">intensive credential</a>.  During this meeting I was impressed with their outgoing nature and interest in promoting and growing the security industry.  The following interview demonstrates they have retained these qualities and that they are continuing to promote security advancement on their continent.</p>
<p>I also highly recommend that you visit their blog site.  They continue to provide great information and technical expertise that can be utilized by any security professional.  We all should watch out for their technical challenges as they have proven not only to be interesting but useful in real world situations.</p>
<hr align="center" size="2" width="70%">
<blockquote><p>
<strong>Why did you all start blogging?  I believe that you are all living in Spain but you blog in English.  Is there any particular reason? Do you maintain a sister site in Spanish?</strong></p>
<p>[Raul]<br />
The main reason we started blogging was to provide a security resource for technical people where anyone could see the things we are involved in our daily research and job tasks, and to publish details of specific security areas we are interested in. Additionally, we received several requests from people asking us to create a blog, so unconsciously, I think this also influenced us <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
<br />
We all live in Spain, and although we initially though about the language issue, we finally decided to blog in English to reach a broad population; almost all Spanish security professionals understand English, but obviously, the opposite is not true. At some point we thought about keeping two versions of the RaDaJo blog, in Spanish and English, but being realistic, it would be too much work with a reduced benefit.</p>
<p></p>
<p><strong>When you are teaching your training classes do you use English as a common language or does it just depend on the setting and individuals taking the class?</strong></p>
<p>[David]<br />
SANS regular conferences are always run in English. Otherwise we couldn&#8217;t get so many people people in class coming from so many different countries. Nevertheless, in a few occasions in Spain there have been courses run in Spanish (with the materials in English, though) and the feedback has been very positive. I think we may be seeing this more often in the future, but I&#8217;m just guessing here.</p>
<p></p>
<p><strong>If a security professional were going to fly to Europe for one security conference, which would you recommend and why?</strong></p>
<p>[Jorge]<br />
As always I would recommend SANS conferences. They really rock in all their tracks! <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  . I have also attended and enjoyed the ISSE Conference (http://www.eema.org/static/isse/ ).<br />
<br />
And we also have Black Hat Europe and some others, but I haven&#8217;t had the chance to attend yet.</p>
<p></p>
<p><strong>What resources do European security professionals look to during their day to day work to keep abreast of breaking news and events (e.g. Alert/Vulnerability Lists, Websites, Blogs)?</strong></p>
<p>[Raul]<br />
Based on our international experience, the same resources are used by almost all professionals, no matter were you are located. The most popular ones are SANS ISC, Security Focus bugtraq and mailing-lists, the FullDisclosure list&#8230; but, as you know, there are dozens of them.<br />
<br />
From the alert/vulnerability lists perspective, people use the generic ones, such as SANS Newsbites and SF Newsletters, plus the manufacturers resources (Cisco, Microsoft, Linux-vendor&#8230;).<br />
<br />
We suggest that every serious security professional should have its own preferred list of resources, created throughout the years, and at least including Websites, Blogs, Mailing-lists, Forums, Security Conferences and Podcasts.<br />
<br />
Unfortunately, there are no well known European-centric security resources. People tend to access global resources published in English (some of them located in Europe), and additionally, some localized country-based resources (published in your own language). However, due to the language barriers, it is not common to have lot of people from one EU country accessing resources from another EU country (if they are not in English).</p>
<p></p>
<p><strong>Obviously many people in Europe are multilingual but not everybody. How do these language barriers affect the security situation in Europe and how information flows and is interpreted?</strong></p>
<p>[David]<br />
I think security personnel in most, if not all, big companies can at least read English well enough to understand all technical documentation, articles and news, so getting information is not a problem. Writing and speaking is a little less universal but still most people can, so information also flows (less) in the opposite direction. However, the smaller the company the most common is that people only speak their own language, which is a serious limitation because not everything gets translated and even what it does get translated is never the latest.</p>
<p></p>
<p><strong>The basic security considerations and best practices are the same the world over, but society and business practices do change according to specific regions.  I would think that this make it a challenge to generate and enforce information security regulations that span the European countries.  Is this true?</strong></p>
<p>[Jorge]<br />
Although the European Union tries to create a common framework for all its countries, it is true that some specific laws are different from country to country. Besides, law enforcement has important barriers due to the different languages in each country and they need to establish good relationships (in their initial incident response phases) with every potential country an attack could come from.  Certainly, all this makes it more complex than in the US.</p>
<p></p>
<p><strong>Although security is still a young profession here in the United States the government and businesses are starting to understand and accept the need for security professionals or administrators with security training.  How does this compare to European governments and businesses?</strong></p>
<p>[Raul]<br />
We think it is very similar in the US and Europe. The information security field is still maturing and government and businesses are realizing of the huge needs of security professionals. Everything is being computerized, so this fact increases the protection demands and the need of security knowledge and personnel.<br />
<br />
Fortunately, the market has changed a lot in the last 7 years; when we started as full-time infosec pros in Spain around 2000 we needed to explain from scratch certain things and terms to customers. Nowadays almost anyone has heard about rootkits, penetration tests and forensics (just to cite some examples).</p>
<p></p>
<p><strong>Are there any security tools and products that are specific to Europe?</strong></p>
<p>[David]<br />
Not that I&#8217;m aware of. I think we use the same commercial and public domain tools as the rest of the world. This is a global village and market.<br />
<br />
[Raul]<br />
The only exception are government and defense organizations, where each country wants to manage their own security infrastructure. They typically use commercial and proprietary (home-made and secret) solutions.</p>
<p></p>
<p><strong>When Americans think of computer security and Europe many of them start thinking about organized crime and hacker groups from some of the former &#8220;Eastern Block&#8221; countries.  Is this being blown out of proportion?  From your experiences are businesses and end-users in Europe in more danger from organized crime and hackers from around the world than businesses and end-users in the United States?</strong></p>
<p>[Jorge]<br />
Well, there are several hackers from the Eastern Europe, but also from other European countries as well, like Germany that has a long lasting hacker tradition. However, I believe that organized crime has increased its activity in Europe during the last couple of years (or at least we have started to notice that it was happening), and started to hit some real businesses and getting some real money.<br />
<br />
Due to the nature of the Internet, everybody is equally exposed to the attacks. The only advantage in targeting the United States is that, even with the same percentage of vulnerable systems, the same attack can be used against a higher number of users ( i.e., that will speak the same language, go to the same web page and use the same bank, for example). Other than that we should all watch out!
</p></blockquote>
<p></p>
<hr align="center" size="2" width="70%">
<p>I would like to, once again, express my gratitude to RaDaJo for the time the took out of their busy schedule to answer these questions.  From this information I can see that the security profession is following much the same track as we are here in the Untied States.  This is not very surprising as the technologies and risks are generally the same.  Hopefully this interview will help people understand that the concepts, standards, and philosophies are generally similar throughout the industry despite international borders.</p>
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/RaDaJo" rel="tag">RaDaJo</a>, <a href="http://www.technorati.com/tag/GSE" rel="tag">GSE</a>, <a href="http://www.technorati.com/tag/GIAC" rel="tag">GIAC</a>, <a href="http://www.technorati.com/tag/SANS" rel="tag">SANS</a>, <a href="http://www.technorati.com/tag/Interview" rel="tag">Interview</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/104/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Interview with B10m</title>
		<link>http://www.cutawaysecurity.com/blog/archives/96</link>
		<comments>http://www.cutawaysecurity.com/blog/archives/96#comments</comments>
		<pubDate>Sun, 28 Jan 2007 06:48:35 +0000</pubDate>
		<dc:creator>cutaway</dc:creator>
				<category><![CDATA[Helpful]]></category>
		<category><![CDATA[Interviews]]></category>

		<guid isPermaLink="false">http://www.cutawaysecurity.com/blog/archives/96</guid>
		<description><![CDATA[As I stated in a previous post, I have been paying a little more attention to the information provided in URI and Refer sections provided by one of my Wordpress plugins.  This information has, at times, contained information about some systems on the Internet that are searching for other systems with vulnerable PHP installations [...]]]></description>
			<content:encoded><![CDATA[<p>As I stated in a <a href="http://www.cutawaysecurity.com/blog/archives/81" title="Botnets Spreading Via PHP Version all_most_happened_to_me">previous post</a>, I have been paying a little more attention to the information provided in URI and Refer sections provided by one of my Wordpress plugins.  This information has, at times, contained information about some systems on the Internet that are searching for other systems with vulnerable PHP installations and applications.  As I mentioned in the original post I found a blog where another blogger had <a href="http://menno.b10m.net/blog/blosxom/web/botnet-muie.html" title="The MUIE Botnet">already analyzed the scripts</a> that I found on a hacked server, which was scanning my web server.  The blog is <a href="http://menno.b10m.net/blog/blosxom/" title="B10[m|g]">B10[m|g]</a> and the blogger goes by the pseudonym B10m.</p>
<p>After reading <a href="http://menno.b10m.net/blog/blosxom/web/a-talk-with-a-botnet-script-kiddie.html" title="A talk with a Botnet script kiddie">another post where B10m confronted a script-kiddie botnet runner</a> with the cracker name &#8220;fazanul,&#8221; I decided that I would ask B10m to be my first blog interview.  He agreed.  The following contains my questions and his answers.  As you will see, B10m is not a security professional.  Rather, he is a software programmer.  Because of his interest and investigation into the IRC bot that queried his system, I assumed that he was a security professional or had close ties to them.  The majority of my questions take that misconception and run with it.  However, B10m was a good sport and answered each question he was able.  </p>
<p>I think it is a good sign that a software programmer decided to take action when he was presented with malicious activity.  I would not suggest everybody try to connect to the command and control channels of botnets they locate unless they have experience in the field of malware analysis.  Fortunately, B10m did know how to protect himself and his systems to a certain extent but, as he mentions during the interview, he has accepted a certain amount of risk associated with his actions.  My recommendations is that people wanting to make a difference against crackers a simple abuse report to the system owner, the system&#8217;s hosting company, and the system&#8217;s ISP is probably sufficient.</p>
<p>I would like to thank B10m for agreeing to the interview.  I hope you all enjoy.</p>
<hr align="center" size="2" width="70%">
<blockquote><p>
<strong>What made you start blogging?  From your site you appear to be living in The Netherlands but you blog in English.  Is there any particular reason?</strong></p>
<p>I&#8217;ve started blogging quite some time ago on my own hacked up Perl<br />
blogging system. When I found out other people build better systems,<br />
I used that. I was forced to create my own blog by a friend who -at a<br />
certain point- refused to publish my items any longer&#8230;</p>
<p>English just seemed to fit better with my topics (mainly technical<br />
issues). I usually get disappointed when I find a blog post in a<br />
language I don&#8217;t master, containing the exact error message, and<br />
most likely a solution, I was searching for  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   </p>
<p><strong>Are you a security professional? What industry do you work in (e.g. government, education, financial, consulting, etc)?  What are your primary duties?</strong></p>
<p>Not at all. I&#8217;m a software developer (somewhat) and don&#8217;t really<br />
have any real security background other than trying to get my apps<br />
to be as secure as possible.</p>
<p><strong>I am going to assume that you do malware analysis either for work or as a hobby.  How did you start and what training have you received?</strong></p>
<p>I&#8217;m a selftaught geek. Never really had any official training. Just<br />
a lot of reading code will do the trick (besides chatting with<br />
professionals over a few beers). Reading code is fun, and when it&#8217;s<br />
supposed to do evil things on my machine, it&#8217;s even more fun.</p>
<p>Going after these kiddies isn&#8217;t even a hobby though. I just got<br />
obsessed with this fazanul guy. I took a botnet down and rather<br />
quickly, he returned with a new server. So I had to take that down,<br />
and now we&#8217;re here. I&#8217;m scanning my logfiles for him on a daily base<br />
now. Others do get by, but I pay less attention to them.</p>
<p><strong>If a security professional were going to fly to Europe for one security conference, which would you recommend and why?</strong></p>
<p>I would have no clue. I&#8217;m not into those big conferences too much.<br />
So my answer would probably be Prague. Not because of any<br />
conference, but just because it&#8217;s an awesome city  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  </p>
<p><strong>What resources do European security professionals look to during their day to day work to keep abreast of breaking news and events (e.g. Alert/Vulnerability Lists, Websites, Blogs)?</strong></p>
<p>I&#8217;m not a security professional, so I can only speak for myself. I<br />
of course follow slashdot, subscribed to the CERT Advisory mailing<br />
list (so I can taunt MS Windows-using friends often  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />   and look at<br />
digg occasionally.</p>
<p><strong>What training (personal, certification, degrees) would you recommend for persons just starting to look into malware analysis?</strong></p>
<p>No clue, it&#8217;s not my job  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  </p>
<p><strong>Obviously many people in Europe are multilingual but not everybody. How do these language barriers affect the security situation in Europe and how information flows and is interpreted?</strong></p>
<p>Language barriers are not really a problem in Europe. Most kids<br />
learn at least 1 foreign language in school. In the Netherlands it<br />
used to be mandatory (still is?) to study English, German and French<br />
for at least one year in highschool. After that, German and French<br />
become optional. English is even being taught by the age of 10 or<br />
so.</p>
<p>I have never ran into an abuse desk that couldn&#8217;t communicate in<br />
English though. It&#8217;s part of the job. Abuse reports may come from<br />
all over the world&#8230; I do notice that people get working faster for<br />
you when you do address them in their native language though.</p>
<p><strong>You have started a conversation with a hacker who refers to him/herself as &#8220;fazanul,&#8221; why did you start that conversation?</strong><br />
The code he used for his attacks were full of &#8220;scriptkiddie&#8221; signs.<br />
A real coder has a certain programming style as to indentation, etc.<br />
This was clearly a cut&#8217;n'paste job, done by someone with little<br />
knowledge.</p>
<p>I wanted to see how many hosts actually were infected by this guy&#8217;s<br />
script, so I logged in, pretending to be a bot myself. He launched<br />
commands at me, which I replied with bogus replies, but looked like<br />
real system replies. That was fun for a while and he bought my<br />
answers up until I really made it ridiculous, like giving answers to<br />
questions he never asked&#8230;  and of course the &#8220;I refuse&#8221; answer was<br />
something he didn&#8217;t expect from a machine.</p>
<p>I was just messing with this kid and found it quite funny, so I<br />
continued talking to him (he doesn&#8217;t want to talk much to me<br />
though&#8230;).</p>
<p><strong>You used fazanul&#8217;s IRC bot to connect to his command and control channel, what did you do to protect yourself before making that connection?</strong></p>
<p>Not really. I read his code and connected to the IRC channel by<br />
BitchX, a regular IRC client.</p>
<p><strong>What tools would a young security professional want to become familiar with to begin to analyze malware like fazanul&#8217;s IRC bot?</strong></p>
<p>It just boils down to being bored and having some time left to waste<br />
on these things. I noticed the script being written in Perl. I&#8217;m a<br />
Perl hacker so it caught my attention. After that, it&#8217;s basic<br />
networking knowledge. It&#8217;s quite important to find out who to contact<br />
about network abuse etc. Just scan your logfiles every now and<br />
then for &#8220;weird&#8221; activity.</p>
<p>It&#8217;d probably help to read a little PHP too though. There&#8217;s a lot of<br />
horribly insecure PHP code available online. By being able to read<br />
PHP, you can spot errors in the code and patch it. Afterall, close<br />
to all of these attacks are PHP-script exploits.</p>
<p><strong>Have you noticed any type of DDoS towards your systems and what did you do to protect yourself from fazanul&#8217;s repercussions?</strong></p>
<p>Nothing. Since his botnets crumble rather fast I doubt he has the<br />
power to launch a real DDoS attack. If he does, oh well, my poor<br />
little server will suffer and my blog will be inaccessable for a<br />
while. Not that big of a deal. Then again, since this is really a<br />
scriptkiddie without a clue about what he&#8217;s doing, I don&#8217;t fear this<br />
guy. I fear my buggy harddrive more  <img src='http://www.cutawaysecurity.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  </p>
<p><strong>You have been contacting system owners and Internet Service Providers to report the systems being used to spread these IRC bots. Please explain how you do this so that others can do the same?</strong></p>
<p>As I stated before, the most important thing is to find out who is<br />
responsible for a box. First you go after the host of these files.<br />
They are usually not aware of this abuse so they are usually helpful<br />
and friendly. After that, I usually look up who&#8217;s currently logged<br />
in the IRC channel, find out their IP addresses and lookup the ISPs<br />
belonging to that. I use gwhois[1] for that. These admins are<br />
usually less helpful and friendly (calling my warnings &#8220;bogus<br />
claims&#8221; and &#8220;without logfiles, we won&#8217;t do anything&#8221; stuff).<br />
Nevertheless, most zombies in the botnet do disappear after my<br />
warnings though.</p>
<p> 1. http://freshmeat.net/projects/gwhois/
</p></blockquote>
<hr align="center" size="2" width="70%">
<p>Go forth and do good things,<br />
Cutaway</p>
<span class="ttag"><img src="http://www.cutawaysecurity.com/blog/wp-content/plugins/technobubble.gif" alt="Technorati Tags" /> <a href="http://www.technorati.com/tag/B10m" rel="tag">B10m</a>, <a href="http://www.technorati.com/tag/B10m|g" rel="tag">B10m|g</a>, <a href="http://www.technorati.com/tag/botnet" rel="tag">botnet</a>, <a href="http://www.technorati.com/tag/fanazul" rel="tag">fanazul</a>, <a href="http://www.technorati.com/tag/abuse" rel="tag">abuse</a>, <a href="http://www.technorati.com/tag/Security+Ripcord" rel="tag">Security Ripcord</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.cutawaysecurity.com/blog/archives/96/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
