Sunday, December 21, 2008

Eating your own dogfood

I, and likely many of the readers of these posts, are security consultants and provide security recommendations to our clients in one way or another. As we continue to tell other people how to be secure, we must not forget that we have to take our own advice. Just consider the business risk of a security company suffering a security breach! Not exactly a top selling point on your sales slick sheet

From the article:
A local business owner is on the hook for a $52,000 phone bill after his voice-mail system was hacked and hundreds of calls were made to Bulgaria. Alan Davison, who owns HUB Computer Solutions, noticed something was wrong when "feature 36" -- a message unknown to him -- kept popping up on his phone.
Fraud is a pain and will no doubt require substantial follow-up to resolve the situation. However, the bigger issue may be convincing customers to still buy the IT security and VOIP consulting services offered by HUB Computer Solutions.

-Michael Coates

Friday, December 5, 2008

WebScarab Search Plugin Examples

Thought I'd share some of my favorite Search strings for webscarab.

If you've tried to use the search plugin before you may have scratched you head a bit in confusion. I certainly did for awhile. That's not because it doesn't work, its just because it doesn't work in the way we think of search (ie google style). However, once you learn how to use it, it is incredibly powerful.

For the record, most of these search strings I found posted in mailing lists (several from Rogan himself). I thought I'dd add the few I created and post them all together for all to enjoy.

Catch cookies not using secure flag when connection is over https
request.getURL().toString().startsWith("https://") && response.getHeader("Set-Cookie").indexOf("secure") == -1
Similarly, find cookies using the secure flag when connection is over https
httpsrequest.getURL().toString().startsWith("https://") && response.getHeader("Set-Cookie").indexOf("secure") > -1
Detect if the session ID is exposed from URL rewriting
request.getURL().toString().indexOf("jsessionid") != -1
Look for the password (or any other string) within in a response
new String(response.getContent()).indexOf("the_password") > -1
Filter out just the POST messages
request.getMethod().equals("POST")

And if you are having trouble with the Search gui for some reason, here's the steps broken down:
  1. Add a title for your search in the description box
  2. Add one of the above search strings to the search expression box
  3. Hit Add
  4. Capture some traffic & do some things
  5. To view the results, select the title within the box located below the add/delete/reload button


-Michael Coates

Monday, December 1, 2008

INSECURE Magazine features OWASP Portugal

December's issue of INSECURE Magazine featured a 3 page article on the OWASP Portugal Summit.

See page 68

-Michael Coates