sábado, 20 de janeiro de 2024

Thank You To Volunteers And Board Members That Worked BlackHat Booth 2019

The OWASP Foundation would like to thank the OWASP Las Vegas Chapter Volunteers for taking the time out of their busy schedule to give back and volunteer to work the booth at BlackHat 2019.  It was great meeting our Las Vegas OWASP members and working with Jorge, Carmi, Dave, and Nancy.  
Also, take a moment to thank Global Board Members Martin Knobloch, Owen Pendlebury, and Gary Robinson for also working the booth and speaking with individuals and groups to answer questions on projects and suggestions on the use of our tools to address their work problems.
OWASP can not exist without support from our members.  Related news

sexta-feira, 19 de janeiro de 2024

Why (I Believe) WADA Was Not Hacked By The Russians

Disclaimer: This is my personal opinion. I am not an expert in attribution. But as it turns out, not many people in the world are good at attribution. I know this post lacks real evidence and is mostly based on speculation.



Let's start with the main facts we know about the WADA hack, in chronological order:


1. Some point in time (August - September 2016), the WADA database has been hacked and exfiltrated
2. August 15th, "WADA has alerted their stakeholders that email phishing scams are being reported in connection with WADA and therefore asks its recipients to be careful"  https://m.paralympic.org/news/wada-warns-stakeholders-phishing-scams
3. September 1st, the fancybear.net domain has been registered
   Domain Name: FANCYBEAR.NET    ...    Updated Date: 18-sep-2016    Creation Date: 01-sep-2016
 
4. The content of the WADA hack has been published on the website
5. The @FancyBears and @FancyBearsHT Twitter accounts have been created and started to tweet on 12th September, reaching out to journalists
6. 12th September, Western media started headlines "Russia hacked WADA"
7. The leaked documents have been altered, states WADA https://www.wada-ama.org/en/media/news/2016-10/cyber-security-update-wadas-incident-response


The Threatconnect analysis

The only technical analysis on why Russia was behind the hack, can be read here: https://www.threatconnect.com/blog/fancy-bear-anti-doping-agency-phishing/

After reading this, I was able to collect the following main points:

  1. It is Russia because Russian APT groups are capable of phishing
  2. It is Russia because the phishing site "wada-awa[.]org was registered and uses a name server from ITitch[.]com, a domain registrar that FANCY BEAR actors recently used"
  3. It is Russia because "Wada-arna[.]org and tas-cass[.]org were registered through and use name servers from Domains4bitcoins[.]com, a registrar that has also been associated with FANCY BEAR activity."
  4. It is Russia, because "The registration of these domains on August 3rd and 8th, 2016 are consistent with the timeline in which the WADA recommended banning all Russian athletes from the Olympic and Paralympic games."
  5. It is Russia, because "The use of 1&1 mail.com webmail addresses to register domains matches a TTP we previously identified for FANCY BEAR actors."

There is an interesting side-track in the article, the case of the @anpoland account. Let me deal with this at the end of this post.

My problem with the above points is that all five flag was publicly accessible to anyone as TTP's for Fancy Bear. And meanwhile, all five is weak evidence. Any script kittie in the world is capable of both hacking WADA and planting these false-flags.

A stronger than these weak pieces of evidence would be:

  • Malware sharing same code attributed to Fancy Bear (where the code is not publicly available or circulating on hackforums)
  • Private servers sharing the IP address with previous attacks attributed to Fancy Bear (where the server is not a hacked server or a proxy used by multiple parties)
  • E-mail addresses used to register the domain attributed to Fancy Bear
  • Many other things
For me, it is quite strange that after such great analysis on Guccifer 2.0, the Threatconnect guys came up with this low-value post. 


The fancybear website

It is quite unfortunate that the analysis was not updated after the documents have been leaked. But let's just have a look at the fancybear . net website, shall we?

Now the question is, if you are a Russian state-sponsored hacker group, and you are already accused of the hack itself, do you create a website with tons of bears on the website, and do you choose the same name (Fancy Bear) for your "Hack team" that is already used by Crowdstrike to refer to a Russian state-sponsored hacker group? Well, for me, it makes no sense. Now I can hear people screaming: "The Russians changed tactics to confuse us". Again, it makes no sense to change tactics on this, while keeping tactics on the "evidence" found by Threatconnect.

It makes sense that a Russian state-sponsored group creates a fake persona, names it Guccifer 2.0, pretends Guccifer 2.0 is from Romania, but in the end it turns out Guccifer 2.0 isn't a native Romanian speaker. That really makes sense.

What happens when someone creates this fancybear website for leaking the docs, and from the Twitter account reaches out to the media? Journalists check the website, they see it was done by Fancy Bear, they Bing Google this name, and clearly see it is a Russian state-sponsored hacker group. Some journalists also found the Threatconnect report, which seems very convincing for the first read. I mean, it is a work of experts, right? So you can write in the headlines that the hack was done by the Russians.

Just imagine an expert in the USA or Canada writing in report for WADA:
"the hack was done by non-Russian, but state-sponsored actors, who planted a lot of false-flags to accuse the Russians and to destroy confidence in past and future leaks". Well, I am sure this is not a popular opinion, and whoever tries this, risks his career. Experts are human, subject to all kinds of bias.

The Guardian

The only other source I was able to find is from The Guardian, where not just one side (it was Russia) was represented in the article. It is quite unfortunate that both experts are from Russia - so people from USA will call them being not objective on the matter. But the fact that they are Russian experts does not mean they are not true ...

https://www.theguardian.com/sport/2016/sep/15/fancy-bears-hackers--russia-wada-tues-leaks

Sergei Nikitin:
"We don't have this in the case of the DNC and Wada hacks, so it's not clear on what basis conclusions are being drawn that Russian hackers or special services were involved. It's done on the basis of the website design, which is absurd," he said, referring to the depiction of symbolically Russian animals, brown and white bears, on the "Fancy Bears' Hack Team" website.

I don't agree with the DNC part, but this is not the topic of conversation here.

Alexander Baranov:
"the hackers were most likely amateurs who published a "semi-finished product" rather than truly compromising information. "They could have done this more harshly and suddenly," he said. "If it was [state-sponsored] hackers, they would have dug deeper. Since it's enthusiasts, amateurs, they got what they got and went public with it.""

The @anpoland side-track

First please check the tas-cas.org hack https://www.youtube.com/watch?v=day5Aq0bHsA  , I will be here when you finished it. This is a website for "Court of Arbitration for Sport's", and referring to the Threatconnect post, "CAS is the highest international tribunal that was established to settle disputes related to sport through arbitration. Starting in 2016, an anti-doping division of CAS began judging doping cases at the Olympic Games, replacing the IOC disciplinary commission." Now you can see why this attack is also discussed here.


  • My bet is that this machine was set-up for these @anpoland videos only. Whether google.ru is a false flag or it is real, hard to decide. It is interesting to see that there is no google search done via google.ru, it is used only once. 
  • The creator of the video can't double click. Is it because he has a malfunctioning mouse? Is it because he uses a virtualization console, which is near-perfect OPSEC to hide your real identity? My personal experience is that using virtualization consoles remotely (e.g. RDP) has very similar effects to what we can see on the video. 
  • The timeline of the Twitter account is quite strange, registered in 2010
  • I agree with the Threatconnect analysis that this @anpoland account is probably a faketivist, and not an activist. But who is behind it, remains a mystery. 
  • Either the "activist" is using a whonix-like setup for remaining anonymous, or a TOR router (something like this), or does not care about privacy at all. Looking at the response times (SQLmap, web browser), I doubt this "activist" is behind anything related to TOR. Which makes no sense for an activist, who publishes his hack on Youtube. People are stupid for sure, but this does not add up. It makes sense that this was a server (paid by bitcoins or stolen credit cards or whatever) rather than a home computer.
For me, this whole @anpoland thing makes no sense, and I think it is just loosely connected to the WADA hack. 

The mysterious Korean characters in the HTML source

There is another interesting flag in the whole story, which actually makes no sense. When the website was published, there were Korean characters in HTML comments. 



When someone pointed this out on Twitter, these Korean HTML comments disappeared:
These HTML comments look like generated HTML comments, from a WYSIWYG editor, which is using the Korean language. Let me know if you can identify the editor.

The Russians are denying it

Well, what choice they have? It does not matter if they did this or not, they will deny it. And they can't deny this differently. Just imagine a spokesperson: "Previously we have falsely denied the DCC and DNC hacks, but this time please believe us, this wasn't Russia." Sounds plausible ...

Attribution

Let me sum up what we know:

It makes sense that the WADA hack was done by Russia, because:

  1. Russia being almost banned from the Olympics due to doping scandal, it made sense to discredit WADA and US Olympians
  2. There are multiple(weak) pieces of evidence which point to Russia
It makes sense that the WADA hack was not done by  Russia, because: 
  1. By instantly attributing the hack to the Russians, the story was more about to discredit Russia than discrediting WADA or US Olympians.
  2. In reality, there was no gain for Russia for disclosing the documents. Nothing happened, nothing changed, no discredit for WADA. Not a single case turned out to be illegal or unethical.
  3. Altering the leaked documents makes no sense if it was Russia (see update at the end). Altering the leaked documents makes a lot of sense if it was not Russia. Because from now on, people can always state "these leaks cannot be trusted, so it is not true what is written there". It is quite cozy for any US organization, who has been hacked or will be hacked. If you are interested in the "Russians forging leaked documents" debate, I highly recommend to start with this The Intercept article
  4. If the Korean characters were false flags planted by the Russians, why would they remove it? If it had been Russian characters, I would understand removing it.
  5. All evidence against Russia is weak, can be easily forged by even any script kittie.

I don't like guessing, but here is my guess. This WADA hack was an operation of a (non-professional) hackers-for-hire service, paid by an enemy of Russia. The goal was to hack WADA, leak the documents, modify some contents in the documents, and blame it all on the Russians ...

Questions and answers

  • Was Russia capable of doing this WADA hack? Yes.
  • Was Russia hacking WADA? Maybe yes, maybe not.
  • Was this leak done by a Russian state-sponsored hacker group? I highly doubt that.
  • Is it possible to buy an attribution-dice where all six-side is Russia? No, it is sold-out. 

To quote Patrick Gray: "Russia is the new China, and the Russians ate my homework."©

Let me know what you think about this, and please comment. 

Related posts
  1. Android Hack Tools Github
  2. Hack App
  3. Hacker Tools 2019
  4. Pentest Tools Framework
  5. Computer Hacker
  6. Hacking Tools Pc
  7. Underground Hacker Sites
  8. Android Hack Tools Github
  9. Hackers Toolbox
  10. Hack Apps
  11. Hacker Tools
  12. Pentest Tools For Android
  13. Pentest Tools Free
  14. Hacker Tools Windows
  15. Hacking Tools For Games
  16. Pentest Tools Kali Linux
  17. How To Install Pentest Tools In Ubuntu
  18. Pentest Tools Bluekeep
  19. Pentest Tools Android
  20. Hack Website Online Tool
  21. Hack Tools Github
  22. Hacking Tools Windows 10
  23. Hacker Tools 2020
  24. Hacker Search Tools
  25. Tools 4 Hack
  26. Hacking Tools For Kali Linux
  27. Hack Tool Apk
  28. Hacking Tools For Pc
  29. Hacker Tools Online
  30. Pentest Tools Framework
  31. Hacking Tools Kit
  32. Hack Tool Apk No Root
  33. Hacker Security Tools
  34. Hacker Tools Linux
  35. Hack Tools For Ubuntu
  36. Hacking Tools Hardware
  37. Hacker Tools Free
  38. Pentest Reporting Tools
  39. Pentest Tools For Mac
  40. Hacking Tools Hardware
  41. Hacking Tools Usb
  42. Pentest Tools Alternative
  43. Hacker Tools Mac
  44. Hack Apps
  45. World No 1 Hacker Software
  46. Pentest Tools Apk
  47. Hacker Tools For Windows
  48. Pentest Recon Tools
  49. Best Hacking Tools 2019
  50. Pentest Tools Free
  51. Hacking Tools For Beginners
  52. Hack Tools For Games
  53. Hacking Tools For Pc
  54. Hacker Tools Online
  55. Hacker Tools Mac
  56. Hack Tool Apk No Root
  57. Hack Tools For Pc
  58. Hacking Apps
  59. Computer Hacker
  60. Hacker Tools Windows
  61. New Hack Tools
  62. Pentest Tools Review
  63. Hacker
  64. Physical Pentest Tools
  65. Android Hack Tools Github
  66. Nsa Hacker Tools
  67. Ethical Hacker Tools
  68. Hacker Tools 2020
  69. Hacking Tools Pc
  70. Hacker Hardware Tools
  71. Hacker Tools Software
  72. Growth Hacker Tools
  73. Pentest Automation Tools
  74. Hak5 Tools
  75. How To Hack
  76. Hacker Tools Windows
  77. Easy Hack Tools
  78. Hacker Search Tools
  79. Hacker Tools Mac
  80. Hacking Tools Online
  81. Pentest Tools Windows
  82. Hacking Tools Pc
  83. Hacker Tools Free Download
  84. Pentest Tools Tcp Port Scanner
  85. Pentest Tools Find Subdomains
  86. Hacker Tools Windows
  87. Underground Hacker Sites
  88. Pentest Tools Website Vulnerability
  89. Hack And Tools
  90. Hacking App
  91. Hacks And Tools
  92. How To Install Pentest Tools In Ubuntu
  93. Hacking Tools Download
  94. Hack App
  95. Pentest Tools Website
  96. Hak5 Tools
  97. Pentest Tools Linux
  98. Termux Hacking Tools 2019
  99. Hack And Tools
  100. Hack App
  101. Pentest Tools List
  102. Easy Hack Tools
  103. Hack Tools 2019
  104. Hacking Tools For Windows 7
  105. Hack Tools For Pc
  106. Pentest Tools For Mac
  107. Best Hacking Tools 2019
  108. Easy Hack Tools
  109. Hack Tools For Games
  110. World No 1 Hacker Software
  111. Hack Tools Github
  112. Pentest Tools List
  113. Easy Hack Tools
  114. Hacking Tools For Mac
  115. Pentest Tools Bluekeep
  116. What Are Hacking Tools
  117. Pentest Tools Bluekeep
  118. Pentest Tools Windows
  119. Hacker Tools Free
  120. Install Pentest Tools Ubuntu
  121. Hack Tools Download
  122. Hacker Tools Hardware
  123. Pentest Tools Review
  124. Hacker Tools Windows
  125. Hack Tools For Pc
  126. Hacking Tools For Kali Linux
  127. Hacker Tools Apk
  128. Pentest Tools Apk
  129. Hacker Tool Kit
  130. Github Hacking Tools
  131. Hack Apps
  132. Hacking Tools Free Download
  133. Tools Used For Hacking
  134. Hack Tool Apk
  135. Hacking Tools For Kali Linux
  136. Computer Hacker
  137. Beginner Hacker Tools
  138. Growth Hacker Tools
  139. Hacker Tools For Windows
  140. Hack Tools For Games
  141. Game Hacking
  142. Nsa Hack Tools Download
  143. Pentest Tools Alternative
  144. World No 1 Hacker Software
  145. New Hack Tools
  146. Pentest Tools Apk
  147. Hacker Tools For Pc
  148. Hacking Tools Software
  149. Hack Tools Mac
  150. Hacker Tools 2019
  151. Best Hacking Tools 2020
  152. Pentest Tools Nmap
  153. Hacking Tools 2019
  154. Pentest Tools Android
  155. Pentest Tools Website Vulnerability
  156. Pentest Automation Tools
  157. Hacking Tools 2019
  158. Underground Hacker Sites
  159. Hacker Tools For Ios
  160. Hack Tools Github
  161. Hacker Search Tools
  162. New Hack Tools
  163. Hack Tools
  164. What Is Hacking Tools
  165. Best Hacking Tools 2019
  166. Hacker Tools Linux
  167. Wifi Hacker Tools For Windows
  168. Free Pentest Tools For Windows
  169. Hacker Tools 2019

Learning Web Pentesting With DVWA Part 1: Installation



In this tutorial series I'm going to walk you through the damn vulnerable web application (DVWA) which is damn vulnerable. Its main goal according to the creators is "to aid security professionals to test thier skills and tools in a legal environment, help web developers better understand the process of securing web applications and to aid both students & teachers to learn about web application security in a controlled class room environment."

I am going to install DVWA in docker so the prerequisite for this tutorial will be an installation of docker (Docker is not the only way to install DVWA but if you have docker already installed then it may be the easiest way to install DVWA).

To install DVWA in docker run your docker deamon if it's not running already and open a terminal or powershell and type:

docker rum --rm -it -p 8080:80 vulnerables/web-dvwa




It will take some time to pull the image from docker hub depending on your internet speed and after it is complete it will start the dvwa application. In the command we have mapped the image instance's port 80 to our hosts port 8080 so we should be able to access the web application from our host at http://localhost:8080

Now open your favorite web browser and go to http://localhost:8080
You should be prompted with a login screen like this:



login with these creds:
username: admin
password: password

After login you'll see a database setup page since this is our first run. Click on Create / Reset Database button at the bottom. It will setup database and redirect you to login page. Now login again and you'll see a welcome page.



Now click on DVWA Security link at the bottom of the page navigation and make sure the security level is set to Low. If it is not click on the dropdown, select Low and then click submit.




Now our setup is complete, so lets try a simple SQL attack to get a taste of whats about to come.

Click on SQL Injection in navigation menu.
You'll be presented with a small form which accepts User ID.
Enter a single quote (') in the User ID input field and click Submit.
You'll see an SQL error like this:



From the error message we can determine that the server has a MariaDB database and we can see the point of injection.
Since there are many quotes we are not able to determine the exact location of our injection. Lets add some text after our single quote to see exactly where our injection point is.
Now I am going to enter 'khan in the User ID field and click Submit.



Now we can see exactly where the point of injection is. Determining the point of injection is very important for a successful SQL injection and is sometimes very hard too, though it might not be that much useful here in this exercise.

Now lets try the very basic SQL Injection attack.
In the User ID field enter ' or 1=1-- - and click Submit.



We will explain what is going on here in the next article.


References:-
1. DVWA Official Website: http://www.dvwa.co.uk/

Read more


  1. Wifi Hacker Tools For Windows
  2. Black Hat Hacker Tools
  3. Pentest Tools For Android
  4. Hacking Tools For Games
  5. Hacker Tools 2019
  6. Hack Apps
  7. Hacker Tools Free
  8. Usb Pentest Tools
  9. Pentest Tools Open Source
  10. Beginner Hacker Tools
  11. Hacking Tools Software
  12. Hack Tool Apk
  13. Hack Tools For Pc
  14. Hack Tools For Games
  15. Hacker Tools Apk
  16. Hack Tools
  17. Usb Pentest Tools
  18. Hacker Tools For Pc
  19. Hack Tools For Mac
  20. Hacking Tools Kit
  21. Pentest Tools Free
  22. Hacking Tools And Software
  23. Hacker Security Tools
  24. Underground Hacker Sites
  25. Pentest Tools Kali Linux
  26. Pentest Box Tools Download
  27. Pentest Tools Apk
  28. Hacker Tools 2019
  29. Hack Tools For Ubuntu
  30. Pentest Tools List
  31. Hack Tools Mac
  32. Hacking Tools Software
  33. Pentest Tools Bluekeep
  34. Tools For Hacker
  35. Hacking Tools Github
  36. Pentest Tools For Android
  37. Hacker Tools Online
  38. Hack Tools Mac
  39. Hacker Security Tools
  40. Pentest Tools Url Fuzzer
  41. Hacking Tools For Pc
  42. Hack Tools Github
  43. Pentest Tools Apk
  44. Pentest Tools Port Scanner
  45. Hack Website Online Tool
  46. Hacking Tools For Kali Linux
  47. Free Pentest Tools For Windows
  48. Hacker Tools
  49. Hacker Techniques Tools And Incident Handling
  50. Hack Tools Pc
  51. Pentest Tools Review
  52. Hacker Tools 2019
  53. Hacker Tools Linux
  54. Hack Tools
  55. Pentest Tools Framework
  56. Hacker Tools For Pc
  57. Pentest Tools Nmap
  58. Best Hacking Tools 2020
  59. Usb Pentest Tools
  60. Pentest Tools Online
  61. Hacking Tools 2020
  62. Hack Tools
  63. Hack Tools Mac
  64. Physical Pentest Tools
  65. Hacking Tools Windows
  66. Hacker Tool Kit
  67. What Is Hacking Tools
  68. Hacker Tools 2020
  69. Black Hat Hacker Tools
  70. Pentest Tools Tcp Port Scanner
  71. Pentest Tools Apk
  72. Hack Tools For Windows
  73. Hacker Tools Online
  74. Free Pentest Tools For Windows
  75. Pentest Tools Nmap
  76. Hacking Tools And Software
  77. How To Hack
  78. Pentest Tools Bluekeep
  79. Free Pentest Tools For Windows
  80. Hacking Tools
  81. Install Pentest Tools Ubuntu
  82. Hacking Tools Mac
  83. Physical Pentest Tools
  84. Hacker Search Tools
  85. Pentest Tools Review
  86. Hacker Tools Software
  87. Hack Website Online Tool
  88. New Hack Tools
  89. Growth Hacker Tools
  90. Pentest Tools Website
  91. World No 1 Hacker Software
  92. Best Hacking Tools 2020
  93. Best Hacking Tools 2019
  94. Hacker Tools For Pc
  95. Hack Tools For Mac
  96. Hacking Tools For Beginners
  97. Hack Tools Mac
  98. Growth Hacker Tools