Jump to content

Recommended Posts

Posted
It is one thing for out of the box sessions like this, but it is more fun to watch the competitions against hardened machines.

 

InfoSec used to do a session each year of it, but I didn't see it at all last year. I won't be attending this year, but it is always a good session to look for.

 

That would be cool to watch!

 

I haven't been to Infosec so haven't seen the past sessions that have showed this. Are they available online or is there any information on them anywhere (just rushing off to Google anyway).

 

Paul

Posted
I meant MS need to go back to the drawing board

 

yeah, they keep going 'back to the drawing board', in fact each release is 'written from the ground up' or 'from scratch' so the marketing machine tells us.

 

The reason linux is more secure is because it is open source. Anybody can read and improve the code. Unlike windows or OSX, linux doesn't require a plethora of extra utilities to provide functionality like opening pdf's, xls etc. In this case its the closed apps (Safari, ActiveX) that are the security vulnerability.

Posted
yeah, they keep going 'back to the drawing board', in fact each release is 'written from the ground up' or 'from scratch' so the marketing machine tells us.

 

The reason linux is more secure is because it is open source. Anybody can read and improve the code. Unlike windows or OSX, linux doesn't require a plethora of extra utilities to provide functionality like opening pdf's, xls etc. In this case its the closed apps (Safari, ActiveX) that are the security vulnerability.

 

No problem with what you have said there for the most part, except I think it is now coming out that it was in fact part of the Java WebKit in Safari that was used to allow the vulnerability to take hold. If that is the case, then this is in fact an Open Source effort. In any case that doesn't mean anything (true or not). Apple ship Safari with OS X and it is Apple's Safari *shipped with OS X* that has the issue. It needs to be patched (might be in 10.5.3 from what we are hearing from other rumours).

 

I am sure Microsoft will *help* Adobe work on the other exploit revealed during the competition ;)

 

Paul

Posted
yeah, they keep going 'back to the drawing board', in fact each release is 'written from the ground up' or 'from scratch' so the marketing machine tells us.

 

What you're saying is very true and it is a lot of what we hear from Microsoft's marketing team.

 

The reason linux is more secure is because it is open source.

 

I agree and disagree, simply because MS are in a unique position. They have something like 90 - 95% of the world market, so their code is tried and tested a lot more than any other code on the planet. Thinking about it from a mathematical point of view, there's inevitably going to be a much higher probability that an exploit will be found in Windows or one of its components.

 

I'm not a virus writer/hacker (and I do not condone it); however if I was, I would put all my effort into attacking Windows. There's a larger user base and because lots of its components are enabled by default, it means the attack surface is greater. MS have done a good job with Windows Server 2003/2008, starting with minimal functionality and it does appear Windows 7 could go down this route too. It's nothing new, but I do think this will be part of Microsoft's going back to the drawing board plan.

Posted

I agree and disagree, .......

 

I can't argue with that

 

They have something like 90 - 95% of the world market, so their code is tried and tested a lot more than any other code on the planet.

MS still have a 90-95% lead on desktop systems, but that doesn't translate to all the code on the planet!

 

 

I'm not a virus writer/hacker (and I do not condone it); however if I was, I would put all my effort into attacking Windows.

So do the script kiddies do it because it's an easy target, it's more profitable or just because they are pis*ed off at MS ?

 

There's a larger user base and because lots of its components are enabled by default, it means the attack surface is greater. MS have done a good job with Windows Server 2003/2008,

I don't have experience of 2008 server, but 2003 certainly doesn't come with services off by default !

Posted
MS still have a 90-95% lead on desktop systems, but that doesn't translate to all the code on the planet!

 

I never said it was all code, but it's the single most tested code because of the large user base.

 

So do the script kiddies do it because it's an easy target, it's more profitable or just because they are pis*ed off at MS ?

 

All three.

 

I don't have experience of 2008 server, but 2003 certainly doesn't come with services off by default !

 

As quoted from microsoft.com

 

To improve performance and security in the Windows Server 2003 family, several services have been disabled by default that were previously enabled on Windows 2000.
Posted
I'm not a virus writer/hacker (and I do not condone it); however if I was, I would put all my effort into attacking Windows.

 

The source code is freely available for both Linux and BSD - why not attack those? A lot of people, myself included, believe that security through obscurity is a bad thing. Shown by this recent triumph by open source.

Posted
One thing that no-one has mentioned is to what extent the machines were hacked. Was it complete root-kit? ie. Did they have complete control of all aspects or did they just have access to user level privileges? If it is the prior, this is worrying for both companies. If the latter, it is not quite as bad...
Posted
yeah, they keep going 'back to the drawing board', in fact each release is 'written from the ground up' or 'from scratch' so the marketing machine tells us.

 

But if they have too drastic a break with the past then they get castigated for breaking legacy apps. Aside from the increased resource requirements, a lot of members on this forum have been given reduced backward compatibility as a reason for not adopting or delaying deploying Windows Vista in their schools.

 

The reason linux is more secure is because it is open source. Anybody can read and improve the code.

 

Sure, anyone and his dad can fork Red Hat code but few corporate IT departments would deploy the resulting distro.

 

Unlike windows or OSX, linux doesn't require a plethora of extra utilities to provide functionality like opening pdf's, xls etc.

 

You're joking, right? Last time I checked a PDF reader has not been integrated into the Linux kernel and what about all those Firefox plugins, for that matter. The FOSS movement is also producing its equivalent of Flash ( Gnash?).

 

In this case its the closed apps (Safari, ActiveX) that are the security vulnerability.

 

It's not the closed source nature which was the problem. There have been vulnerabilities in FireFox and in open source VM frameworks. In the Windows case Microsoft has used unsafe practices such as tight OS integration of its web browser as a way of achieving vendor lock-in to sure up its monopoly in the desktop operating systems market.

 

Open Source is does not always prevent problems. As a case in point look at the security issues there were with PHP last year.

 

Open source like democracy is not panacea but it does a better job of mitigating the excesses of dominant parties.

Posted

So do the script kiddies do it because it's an easy target, it's more profitable or just because they are pis*ed off at MS ?

 

Script kiddies as their name suggest run ready made exploits. The high level of research interest in Windows by both legal and clandestine forces means there a lot more of these about.

 

The many eyes theory of open source is all well and good but if the bragging rights are all in busting Windows then you know where most of the attention is going to go.

 

What has helped Linux is that the *nix security model does a better job of mitigating the effect of the compromise of unpatched (either by vendor or admin) software.

 

I don't have experience of 2008 server, but 2003 certainly doesn't come with services off by default !

 

Now you're being contrary for the sake of it. What Michael was alluding to was that Windows 2003 does not start out any with listening services (daemons) enabled out of the box. You have to deliberately choose to make Windows 2003 act as file or web server. This definitely was not the case with Windows 2000 or NT4 server.

Posted
The source code is freely available for both Linux and BSD - why not attack those? A lot of people, myself included, believe that security through obscurity is a bad thing. Shown by this recent triumph by open source.

 

Because Linux comparatively has a small user base compared to Windows. Hypothetically speaking, even if you did find something to exploit in Linux, you'd have to find a Linux machine to attack first!

Posted
Because Linux comparatively has a small user base compared to Windows. Hypothetically speaking, even if you did find something to exploit in Linux, you'd have to find a Linux machine to attack first!

 

Not in the server market - it is still the leading os for hosting websites on. Google, for example, makes use of Linux... Imagine a hacker taking over their server farm.

Posted (edited)

Sure, anyone and his dad can fork Red Hat code but few corporate IT departments would deploy the resulting distro.

Novel customers?

 

You're joking, right? Last time I checked a PDF reader has not been integrated into the Linux kernel and what about all those Firefox plugins, for that matter. The FOSS movement is also producing its equivalent of Flash ( Gnash?).

 

You can't seriously be avocating putting FF/PDF stuff in the kernel .

Edited by CyberNerd
Posted
Not in the server market - it is still the leading os for hosting websites on. Google, for example, makes use of Linux... Imagine a hacker taking over their server farm.

 

If I am wrong, why don't we see more attacks on Linux performed/created? I'm sure if someone managed to hack into Google's server farm, they'd have a wealth of information on their hands. No doubt here, but I have no doubts also that Google's servers are going to be behind hardware firewalls too. There are far more Windows exploits created and far more Windows clients to target or attempt to target.

Posted (edited)
Novel customers?

 

You're not getting my point. Vendor size or more importantly install base, does have an effect how a threat can be handled. So if Big Linux Co. was tardy in reacting to news of a vulnerability, a remedial fork by a smaller 3rd party would not necessarily get wide adoption.

 

Occasionally there are 3rd party patches to Windows vulnerabilities as well but everyone tends to wait for the official Microsoft ones.

 

You can't seriously be avocating putting FF/PDF stuff in the kernel .

 

No I wasn't. Read my post again. I was just wondering why you were criticising Windows and OSX for having utilities to open PDFs, XLS files etc.

That's what *nix does too. In fact a major part of the *nix philosophy is the modularization of code so that, as much as possible, particular programs do specific tasks rather than act as jack of all trades.

Edited by ITWombat
Posted
Not in the server market - it is still the leading os for hosting websites on. Google, for example, makes use of Linux... Imagine a hacker taking over their server farm.

 

Most crackers attention is focused against consumer desktops. Even corporate Windows admin are getting better at securing their servers and networks.

 

As I have said in other posts, the *nix secuity model is generally better but let's not get complacent. Don't be like those Mac users who thought they were impregnable until last week. One the whole, Mac OS X is still safer than Windows you still have to be careful what you do with it.

Posted
You're not getting my point. Vendor size or more importantly install base, does have an effect how a threat can be handled. So if Big Linux Co. was tardy in reacting to news of a vulnerability, a remedial fork by a smaller 3rd party would not necessarily get wide adoption.

 

you are not getting the point of how OSS security vulnerabilities are distributed.

When a problem is discovered it is patched promptly and distros do their job -> test and repackage !

Posted
Most crackers attention is focused against consumer desktops. Even corporate Windows admin are getting better at securing their servers and networks.

 

As I have said in other posts, the *nix secuity model is generally better but let's not get complacent. Don't be like those Mac users who thought they were impregnable until last week. One the whole, Mac OS X is still safer than Windows you still have to be careful what you do with it.

 

Agreed, complacency is a dangerous thing whatever your OS. However, the point I was making was that Linux use isn't as low as was being made out. I think the overall thought is that Windows gets attacked as it is the most widely used OS in the world. I was simply pointing out that Linux is the most widely used OS in the web server world, yet attacks on it are low.

Posted
One thing that no-one has mentioned is to what extent the machines were hacked. Was it complete root-kit? ie. Did they have complete control of all aspects or did they just have access to user level privileges? If it is the prior, this is worrying for both companies. If the latter, it is not quite as bad...

 

Excellent question, and one that I think we need the answer to before we proclaim anything damned. To gain root access on an OS X system takes a *lot* more than visiting a web site as a user and clicking a link. You have to *enable* root on OS X. Of course I know Apple users who do indeed enable the root account and leave it logged in!

 

I agree though- if it were a root-kit access to the system then both Microsoft and Apple need to get it fixed. And quickly. Reminds me of the VMSPLICE exploit found in kernel 2.6 at the start of the year in Linux- a root shell could be started through exploit code because of a bug in the kernel. It was patched *very* quickly- but it was there for all to see :-)

 

Paul

Posted
Agreed, complacency is a dangerous thing whatever your OS. However, the point I was making was that Linux use isn't as low as was being made out. I think the overall thought is that Windows gets attacked as it is the most widely used OS in the world. I was simply pointing out that Linux is the most widely used OS in the web server world, yet attacks on it are low.

 

Yes, yes- but if you are a criminal/cracker who wants to exploit bugs in code or otherwise harness information on systems belonging to other people then Windows is the *obvious* choice. So many business and home users have this system that you would target that to get to your main point (wouldn't you?).

Posted
Yes, yes- but if you are a criminal/cracker who wants to exploit bugs in code or otherwise harness information on systems belonging to other people then Windows is the *obvious* choice. So many business and home users have this system that you would target that to get to your main point (wouldn't you?).

 

Well, not really. The computing power of server clusters, combined with the high speed internet access they have makes servers a prime target for rooting for the purpose of sending spam. Afterall, sending spam is the main reason viruses are spread. The other bits and pieces (more malware/spyware) is another thing entirely, but yes, i'd focus on Windows desktop machines for this aspect.

Posted

Hackers arn't interested in local windows machines, malware writers are. Owning someones windows porn collection isnt really that much of a priority to a hacker. Whereas Malware writers/spreaders do want to target the masses.

 

The title is misleading too, the guy had been working on this 0day for over 2 weeks at least, 'MAC owned in under 2mins'? kinda lame.

 

I heard some Mac fanbois saying it was a popularity contest and he only owned the Mac and not its competitors because he wanted to take it home...lol.

 

The author of the flash bug also admitted he could get the bug working on other arch's, e.g. linux could of been owned too so make of that what you will.

 

And you only have to take a look into the vmsplice bug, read the vulnerable code. Its shocking!

 

The whole competition is a farce anyway, the only reason no one entered on the first day (remote exploits) was because no one would sell (effectively what you are doing here) a remote 0day for 20k USD. Governments pay a lot more as has been documented publically in the past.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...