Showing posts with label Papers. Show all posts
Showing posts with label Papers. Show all posts

Released the new version of OWASP Top 10 - 2013

This version was updated based on numerous comments received during the comment period after the release candidate was released in Feb. 2013.

  • A1 Injection
  • A2 Broken Authentication and Session Management
  • A3 Cross-Site Scripting (XSS)
  • A4 Insecure Direct Object References
  • A5 Security Misconfiguration
  • A6 Sensitive Data Exposure
  • A7 Missing Function Level Access Control
  • A8 Cross-Site Request Forgery (CSRF)
  • A9 Using Known Vulnerable Components
  •  A10 Unvalidated Redirects and Forwards

Get PDF format from: http://owasptop10.googlecode.com  - https://www.owasp.org/index.php/Top10

OWASP Top 10 Application Security Risks � 2013 Released


The OWASP Top 10 is based on risk data from 8 firms that specialize in application security, including 4 consulting companies and 4 tool vendors (2 static and 2 dynamic). This data spans over 500,000 vulnerabilities across hundreds of organizations and thousands of applications. The Top 10 items are selected and prioritized according to this prevalence data, in combination with consensus estimates of exploitability, detectability, and impact estimates.

Download: https://code.google.com/p/owasptop10

Source: https://www.owasp.org

Towards Elimination of XSS Attacks with a Trusted and Capability Controlled DOM

 awesome paper written by Mario Heiderich

Abstract 

The Internet has developed to an exchange medium for a wide range of transactions involving personal and sensitive data - while still relying on simple plain-text protocols such as the Hyper Text Transfer Protocol (HTTP). The user agents and browsers capable of requesting and rendering information and transaction results gained complexity, extended the list of provided features to gratify the needs of their users and slowly morphed from simple document renderers into complex operation system like information brokers.
 
With complexity comes complication and complication often yields security problems and con icts of interest. The Internet - because of its essential role in various use cases became a highly anticipated playground for criminals, helping them to generate illegitimate profit and damage with good chances for anonymity and timely delivery of their malicious intents. Attacks are carried out in numerous ways and almost arbitrary extent, including compromised servers and networks, attacks against website users and their browsers, information disclosure, denial of service attacks and Phishing. 

A lot of these activities and attacks occur on a speci c playground: the user agents and browsers. This work dedicates on elaborating on these types of attacks, thoroughly discuss the anatomy and speci cs of client-side attacks delivered via Internet and similar media. Furthermore, this work discusses existing mitigation and attack prevention techniques and outline obvious as well as less obvious weaknesses and bypass strategies.Ultimately, this thesis introduces a novel way of encountering and approaching web based browser and user agent targeted attacks and provide a lever to thrive towards elimination of scripting web attacks and web malware while being in harmony with latest draft spe -ciation additions to ECMA Script 6 (ES6). This is accomplished by de ning a technique we call pre-flight inspection (PFI) and combine it with ECMA Script 5 (ES5) object sealing to control and limit DOM object capabilities to be able to expose a trusted and attack resilient document interface retaining interoperability with modern Rich Internet  

Download PDF: http://heideri.ch

An Evaluation of the Google Chrome Extension Security Architecture

 Abstract
Vulnerabilities in browser extensions put users at risk by providing a way for website and network attackers to gain access to users� private data and credentials. Extensions can also introduce vulnerabilities into the websites that they modify. In 2009, Google Chrome introduced a new extension platform with several features intended to prevent and mitigate extension vulnerabilities: strong isolation between websites and extensions,privilege separation within an extension, and an extension permission system. We performed a security review of 100 Chrome extensions and found 70 vulnerabilities across 40 extensions. Given these vulnerabilities,we evaluate how well each of the security mechanisms defends against extension vulnerabilities. We find that the mechanisms mostly succeed at preventing web attacks,new security mechanisms are needed to protect users from network attacks on extensions, website metadata attacks on extensions, and vulnerabilities that extensions add to websites. We propose and evaluate additional defenses, and we conclude that banning HTTP scripts and inline scripts would prevent 47 of the 50 most severe vulnerabilities with only modest impact on developers. 


Download PDF:  http://www.eecs.berkeley.edu

Enter at your own Risk Cyber Awareness Magazine Released

As we promised last month,The Hacker News along with Security-FAQs, SecManiac, Korben, and SecTechno have come together to bring you an outstanding array of internet security and hacking information.  

Lee Ives from London, England talk about internet security for your children and what to watch out for and how to protect them and yourself.  

Pierluigi Paganini takes us on a visit to China and makes us wonder just how influential China�s hacking is on world internet security.

Mourad Ben Lakhoua takes us on a scary journey of what new Malwares are lurking about and what to expect in the future  

Patti Galle�s article on SOPA  

Manuel Dorne, administrator from Korben gives us a look at Mozilla Firefox security tools. A must for any techie interested in �how to.�

My submission about DefCamp,the first Romanian Security Conference.Thanks to Andrei Avadanei that is also the Founder 

And finally,a good read about politics in general in �No Turning Back� by The Hacker News editorial staff.

Download PDF: http://news.thehackernews.com

HTML5 Web Security v.1.0

This article is an extract of the master thesis written by Michael Schmidt. The security relevant aspects of HTML5 that were considered in this thesis are covered in the subsequent document.It needs to be considered that the content of this document was released in May 2011. Compass Security makes regular updates to its HTML5 security know how and provides additional information  

HTML5 Web Security describes issues, vulnerabilities, threat & attack scenarios and countermeasures across 80 pages including numerous well thought-out diagrams, and is backed up with detailed references and an appendix full of attack details. 

The main sections are:
2.2 Cross-origin resource sharing
2.3 Web storage 2.4 Offline web application
2.5 Web messaging
2.6 Custom scheme and content handlers
2.7 Web sockets API
2.8 Geolocation API
2.9 Implicit relevant features of HTML5
Web workers, new elements, attributes and CSS, Iframe sandboxing and server-sent events  

If you are already developing HTML, or planning to, read this document as soon as possible and update your requirements documents, specifications, design documents, coding standards, and test plans to incorporate the knowledge. 

Source: http://www.clerkendweller.com 

Download PDF: http://media.hacking-lab.com

OWASP Top 10 for .NET developers

Troy Hunt on observations, musings and conjecture about the world of software and technology . Everything you need to know about The OWASP Top 10 Application Security Risks 


Download PDF: http://dl.dropbox.com

Top 10 iPhone Security Tips

This paper offers guidelines on securing your iPhone using features provided by iOS and by following other security best practices.It begins by discussing basic security settings for novice users and then continues to discuss advanced techniques for expert users.This paper is intended for users who want to take proactive measures to secure their iPhones,companies willing to train their employees (before allowing corporate emails on the devices),and administrators working on developing strong policies.It confines its discussion to iPhone security features only and does not discuss similar features that may be available in other mobile device platforms such as Android.However,some of the concepts and standards apply across all these devices.  

Download PDF : http://www.mcafee.com

Recent Advances in Web Application Security

Introduction
Over the past decade, cross site scripting1 (XSS) has become one of the most ubiquitous vulnerability afflicting web applications. More recently �ClickJacking�2 was discovered which probably is even more prevalent than XSS in modern web applications. The ease with which these vulnerabilities can be identified and exploited along with the substantial benefits to be had (for e.g. compromising the user�s session to impersonate the victim user to the application, tricking the user into submitting sensitive credential information, performing a privileged action on behalf of the user etc.) by exploiting these vulnerabilities make them a perfect target for the attackers to look for and exploit in web applications.

In this article, we will survey some of the techniques that have been introduced by the browser makers that are designed to prevent exploitation of these widespread vulnerabilities.These techniques are not dependent on HTML5 but instead are standalone techniques. We will NOT be looking at purely client side techniques such as �Cross Site Scripting (XSS) filters� that are completely implemented and enforced client side. We will be focusing on the techniques that include a server side component and allow the web developer to control and tweak the level of protection enforced.Also note that there have been solutions presented to remediate these vulnerabilities; however these new techniques present the web developer and administrators an elegant and efficient way to eliminate these vulnerabilities as compared to the more involved techniques. All of these new mechanisms are enforced by the end user�s browser. Further, they are also backward compatible and as such a browser that does not understand these techniques continues to interpret and render the response as if they did not exist.


Download PDF: http://www.mcafee.com

Updates: ProcDump v4.0, Process Monitor v2.96, Process Explorer v15.02,and Zero Day Malware Cleaning

ProcDump v4.0: This update for ProcDump, a trigger-based process dump capture utility, enables you to control the contents of the dump with your own minidump callback DLL and adds a new switch, -w, that has ProcDump wait for a specified process to start.



Process Monitor v2.96: This release changes the appearance of its tooltips to the default theme, fixes a drawing bug in the treeview, and updates the graphs to match the style introduced in Process Explorer v15.



Process Explorer v15.02: Process Explorer v15.02 includes minor updates to the drawing routines.



Zero Day Malware Cleaning with the Sysinternals Tools (link to PDF): Mark has posted the slides from the highly-attended and well received Blackhat 2011 Workshop he delivered last week, Zero Day Malware Cleaning with the Sysinternals Tools, which demonstrates how to use the Sysinternals tools to hunt down and eliminate malware.




Source: http://blogs.technet.com

Updates: release of The Windows Sysinternals Administrator's Reference, Process Explorer v15, Listdlls v3.1 and new utility Findlinks v1

The Windows Sysinternals Administrator's Reference: We are excited and proud to announce the release of the official Sysinternals book, The Windows Sysinternals Administrator's Reference, from Microsoft Press. Written by Sysinternals founder and tool author Mark Russinovich, and Windows expert Aaron Margosis, the book is over 450 pages and covers all 70+ tools in detail, with full chapters on the major tools like Process Explorer and Autoruns. In addition to tips and tricks in the tool chapters, it includes 17 "Case of the Unexplained�" examples of the tools used by users to solve real-world problems. Buy the book today and take your Windows troubleshooting and systems management skills to the next level.

Process Explorer v15: Process Explorer v15 celebrates the release of the Sysinternals Administrator Reference and the upcoming 15th anniversary of Sysinternals.This major update to Process Explorer, a powerful tool for inspecting and controlling processes, threads, loaded DLLs, and more, adds GPU utilization and memory monitoring on Vista and higher. It also adds the ability to restart services, has a smaller memory footprint, and has visually cleaner performance graphs.

Listdlls v3.1: Listdlls, a command-line utility for listing and searching for loaded DLLs, now dumps full file version information, including digital signatures. It also adds a new option designed to aid in malware hunting that filters output to include only unsigned DLLs.


Findlinks v1: This new command-line utility lists the hard links associated with a specified file.


Source: http://blogs.technet.com

Mitigating Software Vulnerabilities

How exploit mitigation technologies can help reduce or eliminate risk, prevent attacks and minimize operational disruption due to software vulnerabilities

This whitepaper describes how exploit mitigation technologies can help reduce or eliminate risk, prevent attacks and minimize operational disruption due to software vulnerabilities.The whitepaper explores the exploit mitigation technologies provided by Microsoft and also provides a business case for the value of these technologies. The concept of an exploit mitigation is then solidified by introducing the fundamental tactics and technologies that are used to break exploitation techniques. This information forms the basis for providing guidance on how software development teams and IT administrators can use these technologies to protect the applications they develop and deploy.

Download: PDF

PuzzleMall - A vulnerable web application for practicing session puzzling

The project generally consists of two parts:

(1) The first sub-project is a paper & presentation on a new application level attack (session puzzle), that can "compete" with attacks such as SQL Injection & XSS, or alternatively, enhance them and enable them to bypass all the commonly used input validation mechanisms (by causing the attack to originate from internal resources, instead of external).

The new attack vector was presented in a local OWASP chapter meeting (7 days ago), and two scanner vendors that attended the lecture expressed their interest to develop a plugin that detects the new attack.

It's new, unknown to many and could probably interest a wide audience.

The paper & presentation could be obtained from the following address:

http://code.google.com/p/puzzlemall/

(2) The second sub-project is a new vulnerable web application designed for practicing session puzzling (locating session puzzle exposures).
The application is easy to install, contains mostly session puzzle exposures, and can be accessed in the following URL:



What is Zeus - Technical paper

Zeus or Zbot is one of the most notorious and widely-spread information stealing Trojans in existence. Zeus is primarily targeted at financial data theft; its effectiveness has lead to the loss of millions worldwide. The spectrum of those impacted by Zbot infections ranges from individuals who have had their banking details compromised, to large public order departments of prominent western governments.

We will explore the various components of the Zeus kit from the Builder through to the configuration file; examine in detail the functionality and behaviour of the Zbot binary; and assess emerging and future trends in the Zeus world.


Download: PDF

Securing The Kernel via Static Binary Rewriting and Program Shepherding

Abstract: Recent Microsoft security bulletins show that kernel vulnerabilities are becoming more and more important security threats. Despite the pretty extensive security mitigations many of the kernel vulnerabilities are still exploitable. Successful kernel exploitation typically grants the attacker maximum privilege level and results in total machine compromise.

To protect against kernel exploitation, we have developed a tool which statically rewrites the Microsoft Windows kernel as well as other kernel level modules. Such rewritten binary files allow us to monitor control flow transfers during operating system execution. At this point we are
able to detect whether selected control transfer flow is valid or should be considered as an attack attempt. Our solution is especially directed towards preventing remote kernel exploitation attempts. Additionally,many of the local privilege escalation attacks are also blocked (also
due to additional mitigation techniques we have implemented). Our tool was tested with Microsoft Windows XP, Windows Vista and Windows 7 (under both virtual and physical machines) on IA-32 compatible processors. Our apparatus is also completely standalone and does not require any third
party software.


Download: PDF

See also: hardened srv2.sys versus old smb2 exploit

Credit Card skimming and PIN harvesting in an EMV world

Chip & PIN is definitely broken

At the CanSecWest security conference held in Vancouver last week, four security researchers demonstrated the practicability of chip card skimming attacks � both with an insecure class of chip (SDA) and with a class that has been considered secure (DDA). EC and credit cards chipped according to EMV specifications are designed to hamper "skimming", an attack method which involves intercepting a user's card and PIN data.

Skimming attacks aren't an altogether new idea and can also be carried out via such devices as keyboard attachments. In their presentation, entitled "Credit Card skimming and PIN harvesting in an EMV world" , however, the four researchers describe how a flat circuit board inside the card slot can be used to intercept and manipulate the communication between terminal and chip in order to obtain a user's PIN. A circuit board is far more discrete than a wobbly, glued-on attachment.


Source: http://www.h-online.com

Download: PDF

Botnets: Measurement, Detection, Disinfection and Defence


�Botnets: Measurement, Detection, Disinfection and Defence� is a comprehensive report on how to assess botnet threats and how to neutralise them. It is survey and analysis of methods for measuring botnet size and how best to assess the threat posed by botnets to different stakeholders. It includes a comprehensive set of 25 different types of best-practices to measure, detect and defend against botnets from all angles. The countermeasures are divided into 3 main areas: neutralising existing botnets, preventing new infections and minimising the profitability of cybercrime using botnets. The recommendations cover legal, policy and technical aspects of the fight against botnets and give targeted recommendations for different groups.

Download: PDF

HITB Magazine Issue 005 released

The first HITB Magazine release for 2011

Contents:
Linux Security
-Investigating Kernel Return Codes with the Linux Audit System
Network Security
-Secure Shell Attack Measurement and Mitigation
-ARP Spoofing Attacks & Methods for Detection and Prevention
-Exploiting Web Virtual Hosting �Malware Infections
Windows Security
-Windows CSRSS Tips & Tricks
Professional development
-CISSP� Corner � Tips and Trick on becoming a Certified Information Systems Security Professional
interview
-Rolf Rolles

Download: http://magazine.hackinthebox.org

Symantec Report on Attack Kits and Malicious Websites

Attack toolkits are bundles of malicious code tools used to facilitate the launch of concerted and widespread attacks on networked computers. Also known as crimeware, these kits are usually composed of prewritten malicious code for exploiting vulnerabilities along with various tools to customize, deploy, and automate widespread attacks, such as command-and-control (C&C) server administration tools.

As with a majority of malicious code in the threat landscape, attack kits are typically used to enable the theft of sensitive information or to convert compromised computers into a network of zombie bots (botnet) in order to mount additional attacks. These kits are advertised and sold in the online underground economy�a black market of servers and forums used to advertise and trade stolen information and services.
Symantec has found that attack kits are significantly advancing the evolution of cybercrime into a self-sustaining, profitable, and increasingly organized economic model worth millions of dollars.


Download: PDF

Attack Toolkits and Malicious Websites SlideShare

Symantec Attack Kit Evolution Timeline

Trustwave's Global Security Report 2011: Web Application Risks

This report encompasses data gathered by the SpiderLabs Team during 220 forensic investigations and over 2,300 manual penetration tests. Notice the word "manual" was highlighted right? That means that this data was not gathered through the use of automated scanning tools but rather by manually testing target networks and applications. This means that we are able to dig in deeper into the target web application and uncover vulnerabilities that automated tools alone would never identify. While there is a ton of great data within the GSR 2011 report, for this blog post, I wanted to focus a bit of attention to the web application sections of the report.

Top 10 Web Application Risks

This Top 10 list was gathered by the Trustwave SpiderLabs Application Pentest Team. The attacks and vulnerabilities listed below are ranked by collective threat, based on the frequency of findings, difficulty in launching the attack and the potential impact when exploited by criminals. The report explains:

For example, while SQL injection is not the most common vulnerability we encounter, the potential for the bulk extraction of sensitive data makes it the number one threat of 2010. Conversely, cross-site request forgery (CSRF) is one of the most common application vulnerabilities, but requires a more complicated attack scheme, relegating it to eighth on the list.

Here is the Top 10 List:
SQL Injection
Logic Flaw
Authorization Bypass
Cross-site Scripting (XSS)
Authentication Bypass
Vulnerable Third Party Software
Session Handling Flaw
Cross-site Request Forgery (CSRF)
Verbose Errors
Source Code Disclosure

Download: https://www.trustwave.com
 

AbheLink Black or White ? Copyright © 2011-2012 | Powered by Blogger