Showing posts with label TechEd. Show all posts
Showing posts with label TechEd. Show all posts

Friday, September 4, 2015

Ignite 2015: Hack-Ed: Building a secure http://anti-social.network

At Microsoft Ignite 2015 (formerly TechEd NZ), Kirk and Felix gave a talk titled "TBuilding a secure http://anti-social.network".

Social networks are a special breed of website, where small security issues can quickly multiply to cause a very large scale issue. Many of these security issues apply to regular (anti-social) websites too!
Join Kirk and Felix as they build up a social networking site that will rival the likes of MyBook and FaceSpace. Along the way, discover some of the traps that come with building a secure site for scale, as they discuss some of the security issues that can affect a popular website, and hack their way to an impressive friend list.
The video recording of the talk is available on Channel 9:

https://channel9.msdn.com/Events/Ignite/Microsoft-Ignite-New-Zealand-2015/M376

Thursday, September 3, 2015

Ignite 2015 - Hack-Ed: The Internet of Hackable Things

At Microsoft Ignite 2015 (formerly TechEd NZ), Kirk and Felix gave a talk titled "The Internet of Hackable Things".

This talk discussed the proliferation of devices that now connect to the internet, security mistakes seen in the industry and in our own research, and gave some advice on how to build more secure IoT devices.
Internet connected devices are all around us, listening to us sleep and watching our movements in our home. Windows 10 will even allow us to build better and smarter IoT applications on small platforms such as the Raspberry Pi 2. As we build applications on a new platform, we're experiencing new security issues. Come along to our talk to discuss the mistakes of the past, some tips for the future, and watch us "Hack all the things!!"
The video recording of the talk is available on Channel 9:

https://channel9.msdn.com/Events/Ignite/Microsoft-Ignite-New-Zealand-2015/M341


Thursday, September 11, 2014

TechEd 2014 - Hack-Ed: Threat Modeling your software to design for security

At TechEd 2014, Andy and Kirk gave a talk titled "Hack-Ed: Threat Modeling your software to design for security".

The talk covered the new Microsoft Threat Modeling Tool 2014 (a free download), and used the diagramming technique and threat generation as motivation for uncovering and remediating attacks against a sample web application.

Attacks covered Wifi sniffing and interception using Karma and the Wifi Pineapple, XSS via EXIF data embedded in JPEG files, and a couple of other techniques.

The slides for the talk are available here:

2014-ARC307-ProwJackson-HackEdThreatModeling (34mb PDF)

The video recording of the talk is available on Channel9:

https://channel9.msdn.com/Events/TechEd/NewZealand/2014/ARC307

Fun wifi analysis:

There were 261 devices in the Skycity Theatre probing for 485 different wifi networks.

Congratulations to the two folk with 26 stored wifi networks on their phones, you made the record books :)
(Although you might want to disassociate / remove some of those free wifi networks from your phones if you value your privacy)

A little unexpectedly, the probes for wifi networks were very diverse. 149 devices were probing for 'TECHED2014-SC', but there were no other networks in common with more than 7 people.


In comparison, the device sat upon my hotel windowsill while I was downstairs for breakfast this morning. 868 devices went past, probing for 1173 different networks.


Hotspot Number of People
Telecom WiFi 70
CP Public Wireless 66
SKYCITY 66
TECHED2014-SC 62
Spark WiFi 34
Auckland WiFi 17
Callplus Public Hotspot 15
Airport_Hotspot 9

You can see how profitable it could be to masquerade as one of these access points - something like 8% of devices will automatically join to your network!

While we demonstrated capturing network traffic, we didn't actually capture anyone's network traffic during our demos. You'll have to trust us :)

Kirk

Wednesday, September 10, 2014

TechEd 2014 - Hack-Ed: A day in the life of an Advanced Persistent Threatener

At TechEd 2014, Kirk and Andy gave a talk titled "Hack-Ed: A day in the life of an Advanced Persistent Threatener".

This talk covered the motivations of an "Advanced Persistent Threat" actor, and the cycle they go through when infiltrating your network.

The slides for the talk are available here:

2014-ARC304-Hack-Ed-APT-ProwJackson (41mb PDF file)

The video recording of the talk is now available in several formats:

http://channel9.msdn.com/Events/TechEd/NewZealand/2014/ARC304

Wednesday, September 11, 2013

TechEd 2013 - Hack-Ed: Application-Level Denial of Service

In our talks at TechEd 2013, we discussed application-level denial of service attacks, and included a couple of demo's of how easily you can open your ASP.NET site up to attack by just validating strings using regular expressions, or parsing XML.

Regular Expression DoS:

Regular expressions process input using a remarkably complex non-deterministic finite automaton, which repeatedly processes the input until it makes a match, following different paths through the regular expression and back-tracking where necessary.

In our talk we showed a simple regular expression that could take up 100% of the CPU on your server with only a short input string:

^(\d+)+$

This Bryan Sullivan article covers the hows and whys of ReDoS, and a possible approach for testing a regular expression for the pathological worst case.

We forgot to mention that .NET 4.5 now supports a MatchTimeout property on regular expressions, which means that you can limit the CPU time of regex processing.

XML DoS:

Any parsing of untrusted / user submitted files is complicated, and so receiving file uploads is fraught with danger.

In our talks we showed two XML attacks that could happen with just a simple .NET XmlDocument usage:


            XmlDocument xmlDoc = new XmlDocument();
           
            xmlDoc.Load(XmlFileUpload.FileContent);

            XmlPreviewLabel.Text = xmlDoc.DocumentElement.LastChild.InnerText;

The XmlDocument parser in .NET does not safely handle doc types or user-defined entities by default. This can lead to the "Billion Laughs" denial of service attack which chews up CPU and RAM, or to XML external entities reading files from off of disk.

Nazim's Security Blog shows a couple of examples where things can go awry, and gives a list of the .NET API's that are unsafe by default:

  • System.Xml.XmlDocument
    • Load and LoadXml UNSAFE unless you pass a safe XmlReader (DTD disabled) into it during initialization.
    • InnerXml is NEVER SAFE.
  • System.Xml.XmlTextReader
    • UNSAFE by default in .NET 3.5 and below.
      • You need to set ProhibitDtd=true to make this safe.
    • .NET 4.0 and above are safe be default.
  • System.Xml.Xsl.XslTransform
    • UNSAFE as it supports both entities and XSL script.
  • System.Xml.Xsl.XslCompiledTransform
    • Safe for XSL script since this is blocked by default.
    • UNSAFE for entity expansion unless a secure resolver is specified.
      • Pass an instance of XmlSecureResolver or null
  • System.Web.UI.WebControls.XmlDataSource
    • NEVER SAFE – supports both entities and XSL script.



Thursday, September 5, 2013

TechEd 2013 - Hack-Ed: Develop your Web-Security Spidey-Senses

Kirk and Andy presented at Microsoft's TechEd 2013 titled "HackEd: Develop your Web-Security Spidey-Senses".

The talk was accompanied by the following cheat-sheet:
WebSecuritySpideySense.pdf (228kb)



Friday, September 7, 2012

TechEd 2012 - Hack-Ed: Mobile Security

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The third talk was titled: Hack-Ed - Mobile Security
With millions of devices with more features, and more apps with more functions, and more users with more needs, and more developers with more ideas, and more tools with more power, and more hackers with more to gain... we need to make sure we get mobile app security nailed! Come along and see what security is being provided for you, and what things you need to take care of!
Download the PDF: 2012-SIA302-MobileSecurity-AndyProw-KirkJackson.pdf (20.6mb)

Thursday, September 6, 2012

TechEd 2012 - Hack-Ed: Design for Attack

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The second talk was titled: Hack-Ed - Design for Attack
Whether mobile, web, Windows client or server app; whether banking software or social app; whether internal corporate users only or open to all on the internet; your apps will be attacked. So, how do you design and architect the applications from the ground up to stop attacks, log and monitor attacks, and alert those who need to know? This session will ensure you're correctly considering all components so you can confidently know if you've been compromised, when, by whom, and what they did.
Download the PDF: 2012-ARC401-DesignForAttack-AndyProw-KirkJackson.pdf (18.7mb)

Wednesday, September 5, 2012

TechEd 2012 - Hack-Ed: From the Trenches

Andy Prow and Kirk Jackson presented at Microsoft TechEd NZ. The first talk was titled: Hack-Ed - From the Trenches

We all know that we need to make sure our apps are secure. We all hear about hacks in the news, whether privacy breaches, denial-of-service attacks or credit card fraud. But often those stories are a little detached from the day-to-day development that we do. This session will uncover some stories from the trenches to try and highlight the real attacks that go on in the real world, and why none of our systems are immune. It will also uncover some very real mistakes we see people making in the wild!

2012 Speakers - Day 1

Download the over-sized PDF: 2012-SIA201-FromTheTrenches-AndyProw-KirkJackson.pdf (20.5mb)

Thursday, August 25, 2011

TechEd 2011 - Hack-Ed: Boost your Defences!

Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The second talk was titled "Boost your Defences!":

Running a website is a risky business. Applications within organisations and on the internet are under attack all the time, by all kinds of people. How do you make your ASP.NET WebForms, MVC or SharePoint application as secure as possible? Which protection mechanisms are built in to the platform, and what are the recommended techniques for those that aren't? Come along to this talk where we will cover techniques for protecting your application from all of the common web attacks.

Further resources:

Wednesday, August 24, 2011

TechEd 2011 - Hack-Ed: The Attackers are Coming!

Andy Prow and Kirk Jackson presented two talks at TechEd NZ 2011. The first talk was titled "The Attackers are Coming!":
The internet is a fast moving business, web applications in 2011 are being attacked in new ways, using new tools and techniques. 
This talk will cover the state of the art in web security, and have some fun sharing stories of sites that have been attacked and how well they survived.

Further resources:

Wednesday, September 1, 2010

TechEd 2010: Hack-Ed II: Stop the hacking

At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed II: Stop the hacking".
How do you defend your website against the attacks the bad guys will throw at it? This code-focussed talk will cover some tips and tricks, out of the box features and extensions to make your web applications as strong as possible.
https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC302

TechEd 2010: Hack-Ed: The hacking never stops

At Microsoft TechEd NZ 2010, Kirk and Andy presented a talk titled "Hack-Ed: The hacking never stops".

Don't let down your defenses - the bad guys won't! This session focuses on the cool tricks that the bad guys use to attack your website, and will help you become a better developer.

A video of the talk is available on Channel9:

https://channel9.msdn.com/Events/TechEd/NewZealand/2010/SEC301

Wednesday, September 16, 2009

TechEd 2009: Hack-Ed: Teaching the Good Guys Bad Tricks

At Microsoft TechEd NZ 2009, Kirk and Andy presented their first Hack-Ed themed talk titled "Teaching the Good Guys Bad Tricks".

A video recording of the talk is available on Channel9:

https://channel9.msdn.com/Events/TechEd/NewZealand/2009/SEC313