Dailydave mailing list archives

Re: mqsvc fun


From: Gadi Evron <ge () linuxbox org>
Date: Wed, 13 Apr 2005 01:35:23 +0400

Dave Aitel wrote:
http://www.microsoft.com/technet/security/bulletin/MS05-017.mspx

So Immunity released our exploit for mqsvc in CANVAS. It's only rated "Important" but I think it's neat anyways. Next up, I guess Exchange (go Mark Dowd and Ben Layer) and TCPIP.SYS. (go Neel Mehta!)

I honestly think it's weird when people talk about patch windows. Your patch window today was 25 minutes or negative 5 years, depending on how you look at it. Once you accept that 0day exists, you need to look into secondary layers of defense that actually work. Whining about the amount of exploit information available to the public is missing the point.

Dave, we should discuss routers one day...

Beside the point, I'd be pleased if people would actually patch against
known vulnerabilities before they start worry about 0days.
Stating the obvious.. applying patches as soon as patches are out is
*not* a solution to 0days, though. People don't understand the concept.

Moving on, a good point would be that good security planning is
something that most lack.. and then they start yelling "0days, O 0days -
how do we protect against you?" or "What? 0days? What's that?!". 0days
or no 0days, good planning and building right from the offset is how you
defend any and every thing - correctly.

I don't mind people making money, I do mind and am rather disturbed by
an industry that doesn't want to work for that cash. Filled with a
million "experts" and people who just try to stick some more products up
people's hole.

I have a personal liking to hexa, bits and bytes.. and the l33t
reversers and hackers that go with it. That's the elite for you.

I actually believe, however, that methodology and strategic planning in
security, problem solving, organizational security, etc. is just as
important if not more so, and perhaps (in my personal opinion) somewhere
the low-level people should move to eventually. I strongly believe it's
a critical part of the industry and that it lacks good people who had
the prior necessary training, tech understanding and the correct mindset.

Problem today is, however, that most of the people who *DO* work in that
particular field know squat about shit. I can count the people I really
appreciate when it comes to "corporate security" or "security problem
solving", etc. on a high level. It's a damn shame, too. Most of them
just throw buzzwords and have some letters after their names.

I'm not trying to be-little anybody, I just pretty much despise that
entire "consultants" industry as it is today. And that's where the
problems begin.

One tiny practical example:
Say you have a server. It is secure, hardened, locked and chained. It is
then protected on the network itself by a firewall, a router doing some
filtering and an IPS system.
Then, for kicks, we also have some "URL FILTER" tool, all the latest
patches, etc.

Wow, you even did a pen-test when you went live with your original site.

I'll move on and let you decide for yourselves why the above sucks.

Say this machine is pwned.. that's nice. Does it have a server farm
behind it? Is there something blocking that server from connecting
openly to every other server in that farm or in your organization? How
about the Internet?

As to "thinking", I can count the people I would go to when I need to
discuss difficult security strategy/methodology problems, and ways of
solving them.

For example; how would you authenticate said front-lines server with a
database back in your organization? You can, rather easily. But if we
are to ignore the regular issues with authentication - how would you
make sure it's really the server? How can you prevent an attacker from
simply using the key, password, whatever else? How can you identify a
machine?
There are solutions, but if you go and think about this a bit, you'll
see a huge hole in today's security offerings, as an example.

Most consultants would sell an organization "solutions". These
organizations know FAR less  than our AVG geek list members, that's why
they need outside help. So, a ready-made hardening paper, maybe a
strategy paper from his last job if they pay enough, and yet another IPS
product... oh, and let's not forget yet another anti-virus. Give me a break.

To make this short, I can't agree with Dave more, although for different
reasons.

        Gadi.

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: