Tuesday, November 15, 2011

Inspecting HTTPS traffic on gateways

INTRODUCTION

In the past, security devices inspecting application content for attack patterns, misuse or malware, had been blind to encrypted traffic and due to this encrypted protocols like Hypertext Transfer Protocol Secure (HTTPS) have been a safe method used by attackers to bypass security inspection. Though reverse proxies and Web Server modules have been there for long, but they only inspect incoming traffic i.e. connections made to protected web servers in the organization. Inspecting outgoing traffic or traffic of connections made by users to outside world servers, not protected by the device, had been on the wish lists. Devices these days come with the capability to inspect Secure Sockets Layer (SSL) based outgoing traffic, however there are some concerns enabling such kind of inspection. In this article we cover some basics of SSL, the challenges in inspecting SSL traffic, and also see how Check Point's HTTPS Inspection feature starting from R75.20 is able to inspect HTTPS traffic at the gateway. After reading this article you will know the pros and cons of enabling SSL inspection on a gateway.

Read further or download the entire document in PDF format below:
Inspecting HTTPS Traffic on Gateways

Friday, May 27, 2011

SPG - informal meeting

Security Professional's Group (SPG) is having an informal bar meet on Sunday 29th May '11. If you are interested, send in your mobile no. to spg@ksecure.net

Thursday, March 31, 2011

Saturday, February 26, 2011

Hackers meet at Nullcon 2, GOA


Heard of Black Hat, White Hat and also Gray Hat but what does this Brown Hat??

Does it mean the chief of all the hats? or something else??

Had a great time at GOA and the second Nullcon conference in Feb 2011.

2.4 Million email account passwords leaked

Have you ever entered your email account password on some sites like social networking, contact management, birthdates management or may be email marketing? Well the site you used could be legitimate, but how good is their security?? Are they collecting your password or redirecting to a login page on the email server?

Hackers have got 2.4 million email account passwords of gmail, hotmail, yahoo, live etc. The no. is expected to go up to 24 mil soon and as this is not likely to be the result of compromising all the providers at a go, hence it seems to be data from 3rd party sites in possession of the password. If you like to see if you are one of the victims, you can check your email id here - http://dhamaka.nullcon.net

Saturday, December 11, 2010

Writing Snort Rules

Writing Snort Rules
by Kishin Fatnani

Snort, as you would know, is a tool used to detect intrusions on a network. Though the tool can also be used for packet logging, sniffing or as an IPS, however in this article we will look more into the concept of rules by which Snort detects interesting traffic for us, basically the kind of traffic we are looking for, like a network attack, a policy violation or may be traffic from a network application or device that you are troubleshooting. For instance, if someone is doing XMAS port scan to our network using nmap with the -sX option, Snort will give us the following alert message.

[**] [1:2000546:6] ET SCAN NMAP -f -sX [**]

[Classification: Attempted Information Leak] [Priority: 2]

10/15-08:51:46.970325 192.168.0.111:62202 -> 192.168.0.1:132

TCP TTL:53 TOS:0x0 ID:28031 IpLen:20 DgmLen:40

**U*P**F Seq: 0xD70FB1F3 Ack: 0x0 Win: 0x800 TcpLen: 20 UrgPtr: 0x0

[Xref => http://www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/SCAN/SCAN_NMAP][Xref => http://doc.emergingthreats.net/2000546]

If the use of P2P or IM applications is against the corporate policy, Snort can detect their use on the network and provide alerts with messages similar to these:


To read the complete article, download the magazine from here:
http://hakin9.org/magazine/1576-hakin9-starterkit-snort-exposed

Monday, December 6, 2010


Interest in information security or may be hacking seems to be really growing in India. Immediately after the first malware conference ended in Mumbai, another conference 'ClubHack' commenced in Pune. ClubHack is not new, it is India's first hacking convention and this was their 4th year. It's one of my favourite events and I make sure to attend every year, however this year I could just attend the technical briefings and missed the workshops and panel discussions.

The briefings surely had enough of good quality stuff to make it worth travelling all the way to Pune. It was great to learn about Android issues from an expert who has developed the most popular Android app 'Antivirus Free'. The session on Firefox security was also an eye-opener making us understand how easy it was to write a malicious extension for the browser and even easier was their installation. Another interesting presentation was about cloud computing for forensics in which it was demonstrated how to make the time consuming tasks in forensic analysis quicker and that to at a highly reduced cost.

Rohit and his team have been doing a fabulous job of conducting the conference each year and regularly publishing the ClubHack Magazine.