Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, August 20, 2008

Authentication & Authorization

Use AD for authentication and DB for authorization

I'm trying to reason out the above statement with best of my knowledge, this may be specific to windows environment. Do leave your thoughts if you know of better reasons.

A company intranet website application can be open to entire domain users and hence don't need any authentication at all. But we may need to restrict access to a phone list application to certain groups, this application may include additional authorization restrictions like certain group of users should not be able to view some section of data say for example "personal mobile numbers". Best approach is to authenticate all users with a AD group and use different authorization data store like a database.

Can we not use db for authentication, like use "authorization data store" and check if user is not authorized to do any steps in the application and redirect to access denied page? Though its a technically possible option, in this case, control on who gets access to phone list application is thro' db. Everyone will agree, access to that is weaker compared to a secure AD group membership which are restricted to AD administrators hands. Inherently. access to application db has wider spread, compared to AD. Also AD authentication blocks unauthorized users at the gate i.e stopped even before entering into application.

In other end of spectrum, why we should not use AD for authorization. For simplicity sake, if we have 3 authorization groups for each application and we have 10 applications and toss in 2 environments (dev/prod), we end up with 60 AD groups. Its work on AD admins that in course of time will become un-manageable, worst-case scenario, someone getting access which they shouldn't.

That said, there is room for all shades of grey, for example any enterprise has to maintain AD groups for something or other, like share folder access. Using the same phone list application, if there is a requirement to restrict users from viewing sr. mgmt contacts. I'd rather make that authorization against AD than have it inside my application db.

Sunday, August 19, 2007

History of hAcKiNg

After a longgg time had some time to vetti browsing :) Down below is quite a interesting documentary on the topic.

My take on this, black or white hat, he is just curious (hmm may be little bit too much). Whatever! Here is one of my recent discovery, hole in e.p.a.p.e.r edition of The H>i>n>d>u, deciphering the filenaming took less than 5 mins from start to finish, i think i talked about this hole in one of my prev post; servers change, hole remains.

Few months back, in a IIS7 feature demo there was one interesting item that i can recollect; a managed module for all IIS requests (even for static files); so theoretically i can write a HTTPModule to validate authentication and serve as gate keeper of any IIS requests.

url:
http://e^p^aper.theh^indu.com/pdf/YYYY/
MM/DD/YYYYMMDD?_###$$$.pdf
ex:
http://e^p^aper.theh^indu.com/pdf/2007/
08/19/20070819A_001101.pdf

take out ^ char in the url

? -> content
A --main paper
B --metropulse
C --opportunities or second supplement
T --may be special supplement

### -> running page number

$$$ -> edition
101 - chennai
102 - delhi
103 - hyd

batch download with flashget completes the square. Ok now goes the documentary,



Do i know you ???
I don't think so !!!

Sunday, May 13, 2007

A key logger

Many came to me asking how a key logger will go undetected with all these security options. I think it may be due to the fact that AV scanners look for known keylogger signatures and if i happen to write and build one, it may not be able to find it. Here is source code of a simple key logger written in VB, tell me if it goes undetected in your AV scan. But this is just a payload, how you infect the client and transmit data out of the client is where the fun is.

<< i support white hat >>

Wednesday, November 22, 2006

Shopping for Holidays: Why not checkout google ?

Shopping for this holiday season, do check if you can get something by using the google checkout. Technically it's like old wine in old bottle with new cork. I'm sure this is not going to wipe out Amazon, i go to Amazon 'coz of low price and high quality shipping service, many-a-times free.

Hype or Not, you get $10 to $20 Orders with Google Checkout now, in many participating merchants. If you buy something closely above the set limit, that's some discount, on top of your other discounts and coupons, why waste that, i did that few days ago.

Ok now the scary part, if you had clicked that "Remember me" checkbox when you login for convenience of using any other google feature, say gmail, i see many do that; your payment information is thrown open to anyone using that computer, 'coz you just clicked on that innocent looking checkbox. WTH! With that always signed-on feature, it simply takes me to screen where i just need to click one button to buy, what was google thinking ??? I expected them to authenticate me again before getting into this final order page.

Anyone who has never made a mistake has never tried anything new. – Albert Einstein

Happy Thanks giving.

Wednesday, November 08, 2006

Am I Secure - Really ?

One of the colleague was talking to me on security of home computer he has, this becomes a more important topic with all those spy wares, trojans , bots and rootkits out there. Hmm, going back to the discussion with him, i found I'm bit more secure than his setup, but I'd be foolish to think i kept all doors locked, this brings up question, Am I Secure - Really ???

Here is my setup in what i have,

Firewall. No questions, everyone needs it, not that dumb WinXP firewall (looks like finally MSFT ships Vista with decent firewall features). I finally threw out the popular but most resource hogging security suite to a simple firewall, which provides blocking any incoming connection and outgoing connection (all except configured apps) . Firewall also includes Network and Host based Intrusion prevention system.

Anti-Virus/Anti-Spyware. In future should be a standard OS feature, still this is more of a after-the-fact solution with signature based detection. Check out a interesting rootkit demo at TechNet Webcast.

Anti-Phishing. This I'm dead serious about, if anti virus takes me down, i may have to
spend some hours cleaning up or re-installing, But i don't want to lose out my bank acct information and i know I'm really screwed by that time. On top of Firefox 2.0 and google toolbar anti-phishing features, i run Netcraft to make sure the bank site I'm accessing is not hosted from Russia or Taiwan. I use a PG open source app to store my sensitive and ultra complex online credentials, just to throw another layer on top.
based
Network Security. Home wireless network uses WPA encryption and locked by MAC address. If you like to learn some tips on this, here is a link.

Few years back learnt how easy to write a keylogger, which later transformed to trojan with payload from a file share, though strictly for fun and knowledge, that still keeps me little bit cynical and hence backup-ed data last week. :-)

Thursday, April 06, 2006

Reverse Engineering Taboo

Many (esp in IT world) think this a taboo, well here i'm trying to break. I don’t understand why such negativity associated with this; if this is not so in other industries. Take an automobile manufacturing industry, isn't a common practice to buy competitor product and disassemble it to examine and understand for the purpose of enhancing their vehicles/components. If you can consider that legal (of course if it doesn’t violate any patent/copy-right), then it should be okay to disassemble software for the purpose of understanding and enhancing existing system.

For people who confuse this with Security Hack, question yourself why you have that secured data/logic in the binaries which can be reversed in a matter of seconds (Lutz Roeder's .NET Reflector), esp with the these high-order languages. No, not even NGEN isn't protected from reversing, hmmm, are you still in Fool's Paradise!

Wake-up Buddy. The silent guy in that last desk could be a black hat! Hahahaha.

Friday, July 01, 2005

p&p CMAB encryption feature

I still don't find time to put down my ramblings on CMAB, but today i was asked to tweak the block to use client's encryption helper component instead of out-of-box encryption. Unlike other blocks, I have a great respect to this block for its sound design (as usual no COM+ support).

I wonder why didn't MSFT create a encryptionHelper component, that can be used across other blocks or a stand alone encryption application block, instead of implementing the algorithm in the CMAB block itself???

Tuesday, December 21, 2004

Power of CSS attack.

When i came to know about the Cross Site Script (CSS) attack long time back, i thought how good an attack can it be, if the script is running in a client browser and that too in a controlled execution environment provided by many modern browsers.

I found that someone can inject a script to refresh the page in some shorter interval of time and can effectively bring down the web server with lot of load from just a fraction of legitimate users.
DOS. My intial (illiterate) assumption was some hacker has to control a large no. of zombie clients to use this techinique, that was totally busted with a simple CSS.

A lesson to all those who believe world is so NICE!!!

Monday, December 20, 2004

Quantum Cryptography -

EinsteinEncryption
"Cryptographic key communication can be guaranteed absolutely secure, even over completely unsecured lines."

Hits me like anything, but it looks like its practically possible (though with some practical limitations that needs to be overcome) with quantum physics.

I luv google caching

Personally to me this doesn't mean end of mathmatical cryptography. As this looks like half of the security, just securing data communication. I am not aware of any usage of this priniciple for securing stored data. I believe this one should also have overhead as we do have in asymm crypto but more secure than that. Hopefully this could be useful for securing communication of symm keys. I am sure first practical install will be a "secure proton tunnel" between Pentagon and WhiteHouse or Camp David.

"I think I can safely say that nobody understands quantum mechanics."
- Richard P. Feynman

Thursday, December 16, 2004

Digital Signature Simplified

I was hit on this concept when i am working in customization of Configuration Management Application Block. Though, initially it didn't strike me, how best this can be leveraged in an application architecture. Later i realized how simple and effective this technique can be used to tamper-proof content delivery. If used along with a public/private key encryption, this can prove to be very effective in verifying authenticity of content.

Enough of my blabber, how D-S works:

Content author, uses a hash algorithm and gets a hash of the message {AKA message digest}, he then encrypts the hash using the private key. The "encrypted hash" is the D-S of the content. Usually delivered along with the orginal message/content.

Content consumer, uses the same hash algorithm to generate the hash and decrypts the signature using the public key. If hash matches, vola the receiver can be sure of the sender's identity and that the message arrived intact.

Looks solid and simple techinique for me. If needed we can also add "salting" techinique. I believe there is no perfect security, it's always 1 layer up and make sure we aren't hit by performance.

To end with an conspiracy theory, i am one of those, who strongly believes that some tactical project could be nudging closer to techinique of inverting {so called} trap door one-way function, its a TWILIGHT ZONE.

Ignorance is NO bliss in world of digial security!