Lilypie 1st Birthday Ticker

Monday, April 13, 2020

CSRF Referer Header Strip

Intro

Most of the web applications I see are kinda binary when it comes to CSRF protection; either they have one implemented using CSRF tokens (and more-or-less covering the different functions of the web application) or there is no protection at all. Usually, it is the latter case. However, from time to time I see application checking the Referer HTTP header.

A couple months ago I had to deal with an application that was checking the Referer as a CSRF prevention mechanism, but when this header was stripped from the request, the CSRF PoC worked. BTW it is common practice to accept empty Referer, mainly to avoid breaking functionality.

The OWASP Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet tells us that this defense approach is a baaad omen, but finding a universal and simple solution on the Internetz to strip the Referer header took somewhat more time than I expected, so I decided that the stuff that I found might be useful for others too.

Solutions for Referer header strip

Most of the techniques I have found were way too complicated for my taste. For example, when I start reading a blog post from Egor Homakov to find a solution to a problem, I know that I am going to:
  1. learn something very cool;
  2. have a serious headache from all the new info at the end.
This blog post from him is a bit lighter and covers some useful theoretical background, so make sure you read that first before you continue reading this post. He shows a few nice tricks to strip the Referer, but I was wondering; maybe there is an easier way?

Rich Lundeen (aka WebstersProdigy) made an excellent blog post on stripping the Referer header (again, make sure you read that one first before you continue). The HTTPS to HTTP trick is probably the most well-known one, general and easy enough, but it quickly fails the moment you have an application that only runs over HTTPS (this was my case).

The data method is not browser independent but the about:blank trick works well for some simple requests. Unfortunately, in my case the request I had to attack with CSRF was too complex and I wanted to use XMLHttpRequest. He mentions that in theory, there is anonymous flag for CORS, but he could not get it work. I also tried it, but... it did not work for me either.

Krzysztof Kotowicz also wrote a blog post on Referer strip, coming to similar conclusions as Rich Lundeen, mostly using the data method.

Finally, I bumped into Johannes Ullrich's ISC diary on Referer header and that led to me W3C's Referrer Policy. So just to make a dumb little PoC and show that relying on Referer is a not a good idea, you can simply use the "referrer" meta tag (yes, that is two "r"-s there).

The PoC would look something like this:
<html>
<meta name="referrer" content="never">
<body>
<form action="https://vistimsite.com/function" method="POST">
<input type="hidden" name="param1" value="1" />
<input type="hidden" name="param2" value="2" />
...
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html>

Conclusion

As you can see, there is quite a lot of ways to strip the Referer HTTP header from the request, so it really should not be considered a good defense against CSRF. My preferred way to make is PoC is with the meta tag, but hey, if you got any better solution for this, use the comment field down there and let me know! :)

Related posts

Social Engineering Pentest Professional(SEPP) Training Review

Intro:
I recently returned from the new Social Engineering training provided by Social-Engineer.org in the beautiful city of Seattle,WA, a state known for sparkly vampires, music and coffee shop culture.  As many of you reading this article, i also read the authors definitive book Social Engineering- The art of human hacking and routinely perform SE engagements for my clients. When i heard that the author of the aforementioned book was providing training i immediately signed up to get an in person glance at the content provided in the book. However, i was pleasantly surprised to find the course covered so much more then what was presented in the book.

Instructors:



I wasn't aware that there would be more then one instructor and was extremely happy with the content provided by both instructors. Chris and Robin both have a vast amount of knowledge and experience in the realm of social engineering.  Each instructor brought a different angle and use case scenario to the course content. Robin is an FBI agent in charge of behavioral analysis and uses social engineering in his daily life and work to get the results needed to keep our country safe. Chris uses social engineering in his daily work to help keep his clients secure and provides all sorts of free learning material to the information security community through podcasts and online frameworks.



Course Material and Expectation: 
I originally thought that the material covered in class would be a live reiteration of the material covered in Chris's book. However, I couldn't have been more wrong !!  The whole first day was about reading yourself and other people, much of the material was what Robin uses to train FBI agents in eliciting information from possible terrorist threats. Each learning module was based on live demo's, nightly labs, and constant classroom interaction. Each module was in depth and the level of interaction between students was extremely useful and friendly. I would say the instructors had as much fun as the students learning and sharing social techniques and war stories.
The class was heavily made up of ways to elicit personal and confidential information in a way that left the individuatial "Happier for having met you".  Using language, body posture and social truisms as your weapon to gather information, not intended for your ears, but happily leaving the tongue of your target.
Other class activities and materials included an in depth look at micro expressions with labs and free extended learning material going beyond the allotted classroom days.  Also break out sessions which focused on creating Phone and Phishing scripts to effectively raise your rate of success. These sessions were invaluable at learning to use proper language techniques on the phone and in email to obtain your objectives.

Nightly Missions/Labs: 
If you think that you are going to relax at night with a beer. Think again!! You must ensure that your nights are free, as you will be going on missions to gain information from live targets at venues of your choice.  Each night you will have a partner and a mission to gain certain information while making that persons day better then it started.  The information  you are requested to obtain will change each night and if done properly you will notice all of the material in class starting to unfold.. When you get to body language training you will notice which targets are open and when its best to go in for the kill. You will see interactions change based on a persons change in posture and facial expressions. Each day you will take the new techniques you have learned and put them into practice. Each morning you have to report your findings to the class..
During my nightly labs i obtained information such as door codes to secured research facilities, information regarding secret yet to be released projects.  On the lighter side of things i obtained much personal information from my targets along with phone numbers and invitations for further hangouts and events. I made many new friends inside and outside of class.
There were also labs within the confines of the classroom such as games used to solidify your knowledge and tests to figure out what kind of learner you are. Technical labs on the use of information gathering tools and ways to use phone and phishing techniques to your advantage via linguistically and technologically. Essentially the class was about 60% interaction and labs.


Proof it works:
After class i immediately had a phishing and phone based contract at my current employment. I used the email and phone scripts that we created in class with 100% click rate and 100% success in phone elicitation techniques. Gaining full unfettered access to networks through phone and email elicitation and interaction. Although I do generally have a decent SE success rate, my rates on return are now much higher and an understanding of what works and what doesn't, and why are much more refined.


Conclusion and Certification:
I paid for this class out of pocket, including all expenses, hotels, rentals cars and planes etc etc. I would say that the class was worth every penny in which i paid for it. Many extras were given including black hat passes, extended training from notable sources and continued interaction from instructors after class ended. I would highly recommend this class to anyone looking for a solid foundation in social engineering or a non technical alternative to training.  You will learn a lot, push yourself in new ways and have a blast doing it. However I did not see any sparkly vampires while in seattle.... Twilight lied to me LOL
The certification is a 48 hour test in which you will utilize your knowledge gained technologically and socially to breach a company.I am not going to give away to much information about the certification as i haven't taken it yet and I do not want to misspeak on the subject. However I will say that social-engineer.org has done an excellent job at figuring out a way to include Real World Social Engineering into a test with verifiable proof of results. I am going to take my test in a couple weeks and it should be a blast!!!

Thanks and I hope this review is helpful to all those looking for SE training.  I had a blast :) :)More info

WHAT IS ETHICAL HACKING

What is ethical hacking?

Ethical hacking is identifying weakness in computer system and/or computer networks and coming with countermeasures that protect the weakness.

Ethical hackers must abide by the following rules-
1-Get written permission from the owner of the computer system and/or computer network before  hacking.
2-Protect the privacy of the organisation been hacked etc.

Ethical Hacking and Ethical Hacker are terms used to describe hacking performed by a company or individual to help identity potential threats on a computer or network.
 

An Ethical Hacker attempts to byepass system security and search for any weak point that could be exploited by Malicious Hackers.
Related links

  1. Hacker Tools
  2. Hacker Tools Free
  3. Beginner Hacker Tools
  4. Pentest Tools Url Fuzzer
  5. Hacking Tools For Mac
  6. Pentest Tools List
  7. Pentest Tools For Android
  8. Hack Tool Apk No Root
  9. Pentest Tools Open Source
  10. Hacking Tools For Mac
  11. Pentest Tools Nmap
  12. How To Make Hacking Tools
  13. Hack App
  14. Hacker Tools Free
  15. Growth Hacker Tools
  16. Underground Hacker Sites
  17. Usb Pentest Tools
  18. Pentest Tools List
  19. Pentest Tools Subdomain
  20. Hak5 Tools
  21. Hacker Tools
  22. Hack Tools For Ubuntu
  23. Hacker Tools Github

Advanced Penetration Testing • Hacking The World'S Most Secure Networks Free PDF

More information


CEH: Identifying Services & Scanning Ports | Gathering Network And Host Information | NMAP


CEH scanning methodology is the important step i.e. scanning for open ports over a network. Port is the technique used to scan for open ports. This methodology performed for the observation of the open and close ports running on the targeted machine. Port scanning gathered a valuable information about  the host and the weakness of the system more than ping sweep.

Network Mapping (NMAP)

Basically NMAP stands for Network Mapping. A free open source tool used for scanning ports, service detection, operating system detection and IP address detection of the targeted machine. Moreover, it performs a quick and efficient scanning a large number of machines in a single session to gathered information about ports and system connected to the network. It can be used over UNIX, LINUX and Windows.

There are some terminologies which we should understand directly whenever we heard like Open ports, Filtered ports and Unfiltered ports.

Open Ports means the target machine accepts incoming request on that port cause these ports are used to accept packets due to the configuration of TCP and UDP.

Filtered ports means the ports are usually opened but due to firewall or network filtering the nmap doesn't detect the open ports.

Unfiltered means the nmap is unable to determine whether the port is open or filtered  while the port is accessible.

Types Of NMAP Scan


Scan TypeDescription
Null Scan This scan is performed by both an ethical hackers and black hat hackers. This scan is used to identify the TCP port whether it is open or closed. Moreover, it only works over UNIX  based systems.
TCP connectThe attacker makes a full TCP connection to the target system. There's an opportunity to connect the specifically port which you want to connect with. SYN/ACK signal observed for open ports while RST/ACK signal observed for closed ports.
ACK scanDiscovering the state of firewall with the help ACK scan whether it is stateful or stateless. This scan is typically used for the detection of filtered ports if ports are filtered. Moreover, it only works over the UNIX based systems.
Windows scanThis type of scan is similar to the ACK scan but there is ability to detect an open ports as well filtered ports.
SYN stealth scanThis malicious attack is mostly performed by attacker to detect the communication ports without making full connection to the network.
This is also known as half-open scanning. 

 

All NMAP Commands 


CommandsScan Performed
-sTTCP connect scan
-sSSYN scan
-sFFIN scan
-sXXMAS tree scan
-sNNull scan
-sPPing scan
-sUUDP scan
-sOProtocol scan
-sAACK scan
-sWWindow scan
-sRRPC scan
-sLList/DNS scan
-sIIdle scan
-PoDon't ping
-PTTCP ping
-PSSYN ping
-PIICMP ping
-PBICMP and TCP ping
-PBICMP timestamp
-PMICMP netmask
-oNNormal output
-oXXML output
-oGGreppable output
-oAAll output
-T ParanoidSerial scan; 300 sec between scans
-T SneakySerial scan; 15 sec between scans
-T PoliteSerial scan; .4 sec between scans
-T NormalParallel scan
-T AggressiveParallel scan, 300 sec timeout, and 1.25 sec/probe
-T InsaneParallel scan, 75 sec timeout, and .3 sec/probe

 

How to Scan

You can perform nmap scanning over the windows command prompt followed by the syntax below. For example, If you wanna scan the host with the IP address 192.168.2.1 using a TCP connect scan type, enter this command:

nmap 192.168.2.1 –sT

nmap -sT 192.168.2.1

Continue reading

Saturday, April 11, 2020

Vintage Computer Festival Southeast 6.0

When:
Saturday April 21, 2018, 10 a.m. to 7 p.m. and Sunday April 22 2018, 12 p.m. to 5 p.m.

Where:
A new location this year:  5000 Commerce Parkway, Roswell, GA 30076.
It's in the  Roswell Town Center mall, around the back off Commerce Parkway.
Please check the Google Map linked from the address, it's a little tricky to find the first time.
This  Map Link shows the entrance.

What:
Speakers — Come hear first-hand accounts of events in computer history and informative technical presentations.  We have again attracted some very interesting speakers this year!
Check the Speakers link above more details.
Exhibits (and exhibit registration) — Exhibits are presented Saturday and Sunday.   You'll find computers from the 60's, 70's, 80's and 90's.  From PDPs to Commodores to Apples… Some exhibits contain pristine original machines, others painstakingly restored machines and others focus on unique modern hacks.  You'll find all this and everything in between.
We will also be having a sneak preview screening and feedback session for an upcoming documentary Love Notes to Newton (click link for a trailer)  This will occur at 3 pm on Saturday.
Hands On Activities  — We offer a chance to let your inner engineer out.   A very popular feature of our Festival is the chance to create your own electronic device.   We have kits available for purchase (for everyone from complete beginner to those already handy with a soldering iron).
We also expect to again have a demonstration area put on by the FIRST Robot team  T\ They will be there to talk about their experiences at the FIRST competition as well.
Consignment — We offer a consignment area as part of our show.   We'll try our best to sell your vintage computer related  items. Details are on the Consignment link.  Please  remember this isn't a flea market.
Vendors — We invite folks who might have items that would be of interest to our audience to exhibit at our show as well.    Register using the exhibits link.
Concessions — We offer a concession area where you can get soft drinks, water, popcorn, etc. We also have Festival T-Shirts (and a few from previous years) along with some other computer related items.  Click the link for a more detailed list.

For whom:
Everyone! Computer geeks, families/children, STEM students, students, collectors, IT professionals, curious onlookers…

Admission: Free

http://vcfed.org/wp/festivals/otherevents/vintage-computer-festival-southeast/
https://mailchi.mp/computermuseumofamerica.com/vcfse60updates?e=fd35a5dce2

Wednesday, April 8, 2020

Comparing All Four Versions Of A Star Is Born

There are four movies called A Star is Born, all roughly following the same plot (here be spoilers):

An aging, alcoholic, male entertainer is just beginning to exceed the tolerance people allow him for his talent with the ridicule and distress he engenders with his destructive, obnoxious antics. Just at this time, he hears or sees a young woman with talent languishing in a small-time position and takes it upon himself to short-list her into fame and fortune. She initially resists, but falls for him and takes the opportunity. She becomes absorbed into the soulless hit-making factory of Hollywood and becomes wildly successful,, while the world turns away from him. They marry and move in together. He runs out of opportunities and people call him a has-been, in so many words; he even ends up taking phone calls or interview requests for her from people who don't even know him. She wins an award (Oscar or Grammy) and he shows up late to the ceremony and interrupts her speech with some kind of drunken scandalous antic. She asks her manager to give him some pity opportunities; he turns them down. She resolves (more or less) to quit the business in order to live a smaller life with him, since she realizes that he can't handle the situation as is (with her being successful and him not), but he discovers this and decides to kill himself in order to prevent this. She spends some time in self-pity. In the end, she publicly performs or says something to acknowledge his importance to her.

1937: Leads are Esther Victoria Blodgett aka Vivki Lester (Janet Gaynor) and Norman Maine (Fredric March). This is a fine film, although very much a period piece of the time it was made, so there are some rushed dialog, odd pauses, harsh sound, and bad lighting. The plot is well-paced and scripted. The actors are both likeable. The main actors recite some of their speeches woodenly but passionately at the camera (or just off to the left) and there are some hysterics. Everyone else talks like a 1930s gangster.

In this version, the main characters are actors. Esther starts on a farm and travels to Hollywood but meets rejection. Norman gets her into his pictures when he sees her waitressing. Someone directly and quite rudely tells Norman that he is washed up. Norman punches him, so Vicki has to bail Norman out of the police station. Norman overhears Vicki planning to give up her career, so Norman walks into the ocean  Vicki ends the movie by looking at the camera and calling herself Mrs. Norman Maine.

This is a fine and memorable movie, worthy of being redone.

1954: 17 years later. Esther Blodgett aka Vicki Lester (Judy Garland) and Norman Maine (James Mason). In this version, the main characters are actors / vaudeville performers singes and dancers. Norman finds Esther singing in a nightclub. The movie is punctuated with several musical performances that, I suppose, were entertaining to audiences of the 1950s. Anyway, they look a lot like bad musicals from that era, like the Road movies and so forth.

I have a hard time conveying the contempt I have for this film. It's mostly in two parts.

Firstly, the acting is always fairly terrible, but sometimes it rises to the level of horrifically terrible. The actors stare at the screen in horror with long pauses, bite their knuckles, fling themselves onto furniture, and weep or shout like idiots.

But mostly, James Mason's Norman grabs, yanks, hurls, pushes, interrupts, orders, and otherwise abuses Judy Garland's Esther throughout the whole movie, yet the movie conveys this as rough but charming. It's sickening. By the time she falls in love with Norman, he has done nothing but pull her through doors, push her into cars and rooms, and otherwise abuse her, but all she can think of is how he takes her breath away (duh, by never letting her think or talk). Most of the abuse comes from Norman, but some of it comes from other people, too. She is a rag doll. It's jaw-droppingly painful to watch. The very little agency she has in the film is to sing and dance, or to wail and cry over how sad it is that she can't do anything for Norman ("She can't! She can't! She can't! Ohhhhh aaahhhh aaahhhh!")

Norman overhears the fateful conversation and is (overacting) horrified and drowns himself. After getting yelled out and yanked by a few more people, Vicki ends the movie by looking at the camera and calling herself Mrs. Norman Maine. And then ...

1976: 22 years later. Esther Hoffman (Barbra Streisand) and John Norman Howard (Kris Kristofferson). This movie is thankfully a step up from the previous one. It's diverges a bit from the others as to how it fills in the plot scenes. The main characters are now singers. The movie starts with a big crowd and drunken stage performance.

They took the main outline of the plot and decided that everyone already knows it, so the movie is about 50% plot and 50% Barbra and Kris being playful and making love. It's very 1970s, not only the hair styles and crowd scenes, motorcycle and car driving, but with the casual flashes of nudity and almost relaxed attitude toward infidelity (it's an insult, but apparently an easily forgivable one). And now we have cocaine, not just alcohol.

The result is somewhat loosely plotted and kind of boring. We skip all the scenes of how she turns into a star (she just does, in a 2 minute montage), we skip her changing her name (she pooh-poohs that idea after being asked by a reporter), we skip the courtroom bailout scene, and we skip most of the conversation that is supposed to lead to his death. She yells at him once for sleeping around, saying that she doesn't want him to drag her down, and he races off into the desert and dies (whether by accident or deliberately is left a bit vague). She ends the movie by singling another song, no name assertion.

It's not only that neither of the main characters are likeable. It's that they don't have much in the way of character to like or to not like. John is kind of sympathetic. Esther is kind of ... well, she's just Barbra Streisand.

But Barbra can sing, and she sings fine. So fine that you kind of wonder how it is that she was languishing in obscurity to begin with.

This is not worth watching, but the soundtrack is lovely. And then ...

2018: 38 years later. Ally (Lady Gaga) and Jackson Maine (Bradley Cooper). The main characters are singers. The movie starts pretty similarly to the 1973 one (with better camera-work and sound), but the alcoholism is more subtle.

This one is, by far, the best one, with incredible performances, scripting, directing, and shooting. The music is amazing, and Lady Gaga is a great singer (okay, Barbra was better, but that's a given for just about anyone). Possibly the only issue I have is the rushed scenes leading up to his decision to kill himself. Ally only half-heartedly tries to throw Jackson some pity-bones (she says one quick sentence about not go on tour without him). The scene that struck me as most wrong was that someone flat out says to Jackson that he is a drag on her career and should disappear, rather than him overhearing it (like he does in the first two movies). It's not that this couldn't or wouldn't happen, it's just a less sympathetic way to depict it happening.

Jackson hangs himself instead of drowning. And Ally ends by introducing herself as Ally Maine, and then she sings a final song while she looks directly into the camera.

Bradley and Lady, as well as everyone else, do a great job of pacing and acting. They are likeable and tragic. The songs are pretty great, too. And the story is, apparently, timeless.