Monday, October 10, 2011

Web Application Penetration Testing

Nowadays everything we see and find is computerized and interconnected, and it is hard to find anything that is not computerized or cannot be computerized. Due this factor, many businesses have improved their efficiency, productivity, save lot of energy (human and machinery), introduce more innovative products and services as well as made services available at fingertips of customers. For instance, web enabled service of banks like internet banking, which enabled customers to stay at home and make all the transactions such as paying utility bills, making other financial transactions, transferring money, checking accounts details etc with comfort and ease. This became possible due to secure web applications used by banks. However, not to forget everything comes with a risk and side effects. In Web applications that we use can have numerous unidentified and hidden vulnerabilities, security loopholes, improper codes, errors and inconsistencies. These could open up disasters to organizations and users if not identified before hand and managed effectively. Hence, organizations need to test these web applications with proven web application testing methodology to correct these vulnerabilities. There are many methodologies existing and organizations can use what is most suitable for the web applications that they require to test. This article will illustrate how to perform web application penetration testing effectively with proven methodology.

Penetration testing is a process of proactive and authorized evaluation of organizational information for security weaknesses. During the process, it analyzes for design weaknesses, technical flaws and vulnerabilities. At the end of the security measures evaluation process, it delivers comprehensive report to executives, management and technical expert’s review. Penetration testing could satisfy the goals of organizations such as test and validate the efficiency of implemented security protections and controls, to enable internal and external vulnerability perspective to organizations, and provide productive information for auditing teams for regulatory compliances, etc.

Web Application penetration test is a part of penetration testing, which only focuses on penetrating web applications and identifying vulnerabilities and weaknesses. Thereafter, reporting that to management and technical experts via reports. This includes the assessment of the web applications and the impact to the organization and often with a proposal for risk mitigation or technical solution.

As of any software and product, Web Applications also need security test to verify that it can handle what they are promising. Web applications have taken serious measures in implementing security within the web applications. On the other hand, it provides required level of security and not susceptible to any identified security vulnerabilities, weaknesses or improper input, modifications, etc. For instance, consider an internet-banking site. It stores personal sensitive information of users such as sensitive financial information and transaction details. If an attacker is able to access this information due to vulnerability in the web application; attacker can perform any transaction, modification, or insert hidden code, etc to the web applications. Hence, could harvest all the customer information and financial details as well as manipulate any information. This would be devastating news for the banking institute as well as their customers. Hence, it is critical to validate the security posture of web applications with web application penetration testing ,to be sure the level of security of the organization.

Since, there are many vulnerabilities in web applications, web applications penetration testers and developers need to concentrate on these items during their testing and application development. It is much better if application developers are well aware and educated to develop secure web applications rather than fixing vulnerabilities later when implemented. Below given list include few of the common web application vulnerabilities.

· Cross-Site Scripting (XSS)

· Cross-Site Request Forgery (CSRF)

· OSAP injection

· SMTP command injection

· Blind SQL/XPath injection

· Code executioin

· CRLF injection / HTTP response splitting

· SQL injection

· Cookie manipulation

· Script source code disclosure

Web Application penetration testing is a complex task and requires very well organized steps to identify and evaluate security measures. Methodology allows this complex process to streamline and have a standardized way to perform each task. OWASP (Open Web Application Security Project) Testing Guide is a proven and recognized Web Application penetration methodology, as well as OSSTMM (Open Source Security Testing Methodology Manual).Below illustrates how to perform Web Application penetration testing and its steps. This is a lengthy process however; it is noted here with brief description.

i. Fingerprint web application environment - this is the basic step to start with, you need to identify web application environment such as used scripting language, web server software, version, operating system, etc.

ii. Investigate the output form HEAD and OPTION HTTP request - these two options usually contain with web server software version, scripting environment and operating system in use.

iii. Investigate format and wording of 404 and other errors - some application environment such as ColdFusion maintain custom error pages that consist of software versions of the scripting language in use.

iv. Test for recognized file types, extensions and directories - different web servers respond differently for unknown extensions than known. Request will monitor for any unusual output or error codes.

v. Examine the source of available pages - immediately accessible pages of front end application’s source code will give very useful details

vi. Manipulate inputs to elicit scripting errors

vii. Test the inner working of web application - scripting languages like Javascript and client-side code can provide information of inner working of web applications

viii. Test database connectivity - access rights should be limited to minimum rights required and limited to required time duration.

ix. Test application code - check for misuse of super user accounts, login ID and passwords, exception /error handling and backdoors left by developers.

x. Test GET and POST in web application - check how these GET and POST are used in web applications.

xi. Test for parameter tampering attacks on the website - try to manipulate URL strings to retrieve sensitive information.

xii. Test URL manipulation - modify URL to see whether you can access unauthorized areas.

xiii. Test Cross-Site Scripting - use tools like, Paros proxy, Fiddler, and Burp proxy to test for these vulnerabilities.

xiv. Test for hidden fields - inspect source code to see if there is any hidden information stored. Try to modify source code and save, then execute and see whether the changes are accepted.

xv. Test for cookies attacks - stealing user cookies will enable attackers to access an account without any authentication.

xvi. Test for buffer overflows - send large amount of data to the buffer, where the buffer will crash and will result in unexpected behavior.

xvii. Test for bad data - enter data in to application by entering between will store in the database, later will result in inaccurate reports.

xviii. Test for client-side scripting - capture a URL after valid login and enter that URL in to a new browser. Check whether you can login without authentication.

xix. Test for known vulnerabilities - use Bugtraq to monitor these vulnerabilities

xx. Test for race condition - application use multiple threads to achieve simultaneous processing, check for this condition.

xxi. Test user protection via browser settings - browser settings provide protection from harmful contents, check whether this is supported.

xxii. Test for command execution vulnerabilities - web applications not properly sanitize the user input data before using it within the application. Application could execute the operating system commands using this.

xxiii. Check for SQL injection attacks - when directly input SQL statements by user are not properly sanitized attacker can steal data from your database, modify and delete.

xxiv. Check for Blind SQL injection attacks - this is identical to SQL injection except it gets a generic page specified by the developer.

xxv. Test for session fixation attacks - this is where attacker tries to use previously used session ID to log again.

xxvi. Check for session hijacking attacks - attacker tries to locate active session and track it, disconnect the host and hijack the session and resume the session after hijacking and use to his will.

xxvii. Check for XPath injection attacks - technique use to exploit website that construct XPath queries from the user supplied input.

xxviii. Test for server side include injection attacks - this exploit web application’s failure to sanitize user supplied data before they are inserted to server side interpreted HTML file

xxix. Check for logic flaws - this is a failure of performing conditional branching or apply security in web applications.

xxx. Check for binary attacks - static buffers may be vulnerable to binary attacks such as format string bugs and butter overflows.

xxxi. Check for XML structural - try to overload the XML parser by sending large amount or malformed XML messages to server.

xxxii. Test for XML content level - use Webscarab tool to test Web Service Definition Language, modify parameter’s data based on WSDL’s definition and check whether you can use web services with escalated privileges.

xxxiii. Test for WS HTTP GET parameter/RESET attacks - check for maximum and minimum length, validate payload, validate the parameter’s names and existence

xxxiv. Test for suspicious SOAP attachments - search wed service definition language that accepts attachments.

xxxv. Test for WS replay - user tools such as WebScarab to capture HTTP traffic and try to perform replay attack.

Every vulnerability found during the web application penetration testing process should be properly documented with valid evidences. Do not try to fix or modify the vulnerability to enhance security of the web application at this moment. This is not a duty of a penetration tester. Penetration tester could inform the relevant authorities if there is an immediate threat, otherwise these findings should be included in to the final reports of the client organization. Make sure the identified vulnerabilities exist with evidence. Furthermore, have proof of concepts to show this could enable greater danger if exploited by an attacker. Penetration tester should not exploit the vulnerabilities and cause any harm to web application of relevant systems. However, if the organization requested and agreed to exploit any vulnerability found during the process, you may proceed. Penetration tester could recommend possible security control measures that organizations could take in order to mitigate the risk exposed due to the vulnerabilities.

This paper discussed briefly how and what areas of a web application needs to be checked for vulnerabilities. In addition, what sort of vulnerabilities that we can find in general. This does not cover comprehensive web application testing in detail or discuss tools in depth. However, few tools that can be used are listed and where the details of these tools can be referred is noted.

Why should we take great care when creating passwords?


This is a very simple and interesting cartoon that I came across while I was searching some information.I think this is very well depict the importance of setting a secure password. This is simple, humorous, educational and delivering the message with attraction.

It is almost one year

It is sad to note that I have not updated my blog for almost a year. It is terrible. Why can't I post something in my blog?
Let's start it again, this time I am going to make it through. No excuses. Let me start with my previous post about the bird. This bird's name is "Cuckoo", or else we commonly known as "Koha".

Saturday, October 23, 2010

Bird..!

Very recently I spotted a bird in our garden and though to capture few frames of the scene since that was the first time I spotted a bird in that nature. I don't know the name or anything but will try to find some information and post it here.







Different types of Wireless Networks and comparison of WLAN, WWAN and WMAN standards.

Wireless networks types can be noted as in two different kinds, one is wireless network by types connection and the other one is wireless networks by the geographical area of coverage. I have described the types of network by the connection below for the purpose of this assessment question.

  • Peer to peer network – This network allows wireless devices to directly communicate with the other devices. No intermediately devices are place to control or transmit wireless signals between devices. Mostly commonly two or many laptop intercommunicate with each other via wireless technology can be considered as peer to peer network.
  • Extension to a wired network – Extension point added to the wired network which act as a wireless relays.

  • Multiple access points – Multiple access points are attached to a wired network by the means of extending LAN with wireless. These networks communicate with wired network as well as wireless access points to fulfill corporate communication requirement.
  • LAN to LAN wireless network – This allows two wireless access points to interconnect two LAN segments via wireless communication. For instance, this will help to extend the corporate communication between two buildings of same organization via wireless technology.










Thursday, October 21, 2010

Key steps in conducting forensic investigations.

Before proceeding with the investigation, forensic investigation team must be well prepared and equipped with necessary prerequisite facilities. Below indicated steps define the steps that the forensic team should adapt to, although the steps are not limited to this.

I. Policy and Procedure development.

Developing proper procedures and policies will give a clear guidance of functional and operational behavior of the forensic unit, and the mission statement that will keep the unit focus on their existence.

· Software licensing – Purchase required softwares and licenses for the forensics unit

· Training – Forensic team requires specialized training for the investigation.

· Resource allocation – Funds and resource allocation

II. Evidence assessment

Forensic investigator must determine the actions to be taken after considering the evidence assessment against the scope of the case.

· Case assessment – Determine whether you need to sought additional evidences such as finger print, DNA analysis, etc.

· Processing location assessment – Identifying the place of the investigation ( In lab environment or onsite)

· Legal considerations - What is the extend of authority to search.

III. Evidence acquisition

Digital evidence has the tendency of getting destroyed, damaged or altered due to its sensitivity, thus protecting and handling them during the entire process is very critical.

· Imaging – Extract the evidence data by fixing the storage device to a forensically cleaned system.

· Write protection – Perform MD5 (Message Digest 5) or CRC (Cyclic Redundancy Check) before and after examination of evidence to determine if the evidence is being tampered during the examination process.

IV. Evidence examination

This process will defer according to the case that the investigator is working on, method, tools to be used and methodology of the investigation. Examination should not perform on original evidence.

· Preparation – Create a unique folder on a separate system to extract evidence data

· Extraction

i. Physical – Extract /recover data of the full physical drive

ii. Logical – Extract and recover data based on operating system, file stucture.ect

iii. Analysis of data – This is the method of matching the relevance of the evidence data to the case that is being examined.

V. Documenting and reporting

All the incidences have to be documented with the timelines of the occurrence from the beginning to the closure of the case and each and every supporting document should be filed accordingly. Final report has to be produced to the case if needed or only to the relevant authority.


Wednesday, October 20, 2010

How to implement Wireless VoIP

Comparatively wireless VoIP is slower than VoIP in wired network. Thus deployment of wireless VoIP needs to consider the real need of wireless VoIP to the corporate network. It is not the point to implement the latest technology but to implement the best system which serves the purpose of the corporate network. Below mentions are basic guidelines for wireless VoIP deployment and this can greatly vary according to the organizational requirements.

1. Make sure the network can handle VoIP.

When moving from wired communication channels to wireless communication channels it is vital to check whether current organizational structure is capable of handling the wireless VoIP requirement adequately and provide the level of expected results. Since data and voice are going to be transmitted through shared medium if the corporate network is also a wireless LAN. Even with the wired data network voice transmission required to be prioritized due to its real time requirement.

Determining the network's readiness for VoIP is essential. A readiness assessment to establish the baseline capabilities of the network will help determine which areas of the overall system need to be fine-tuned or upgraded to support the streaming media requirements of VoIP.

2. Keep the deployment simple.

Deployment of wireless VoIP should take place in parallel or pilot deployment due to the fact that if anything got backfired in the corporate network, it is easy to rectify and resolve without having to shutdown the whole communication lines. This pilot deployment helps to measure the pros and cons of the wireless VoIP implementation and take necessary actions in due places.

3. Create network service maps and update service-level agreements.

During pre-deployment, network administrators should create maps of the network and define service-level agreements with internal departments and external clients. With a proper inventory of the network in the form of a service map, administrators will be able to pinpoint potential bottlenecks and areas of the network that need to be upgraded or extended to support the additional traffic.

Setting requirements in advance is essential, because appropriate expectations and regular feedback between business owners, technology departments and end-users will result in a more successful VoIP experience. Define the policies for ongoing monitoring, performance measurement and management of the network and the VoIP system. Typical SLA metrics include network uptime, application availability, and network and application response time. The data gathered is used to measure pertinent service delivery aspects, such as delay, jitter and uptime, and report confirmation that all requirements and expectations are being met.

4. Consider QoE.

Quality of experience (QoE) is a way to understand the user's perception of the quality of the VoIP telephone systems which can give a correct feedback of the systems that you have implemented. QoE will help measure the success of the wireless VoIP deployment from the end users level.

5. Review, reassess and repeat.

Networks are not static, so implementing an ongoing monitoring process is important. Any change to the infrastructure or usage patterns has an impact to everything on the network. Bringing servers on and offline, upgrading hardware or virtualizing portions of the environment can impact VoIP services.

Continuous monitoring and measurement of IT operations and service-level reporting will provide needed information to quickly resolve network outages and system issues. This technical and business intelligence analysis supports service improvement plans that will sustain the VoIP implementation and make sure end-users do not experience call degradation issues.

Much of the management of the VoIP system and applications can be automated to allow network assessment and monitoring to be repeated consistently to maintain appropriate baselines. Baselines enable administrators to monitor performance and availability, as well as prevent, diagnose and resolve problems.