4 ms·
Posting my long comment here because the Disqus bot and I don't get along for some reason. Troy, I think you have done a lot of good for infosec. Thank you. He
by utefan001 9y ago
Posting my long comment here because the Disqus bot and I don't get along for some reason.
Troy,
I think you have done a lot of good for infosec. Thank you. Here are my thoughts: You will be in a room full of lawyers. Examples that they understand are important. For example, (Full credit to @strandjs 2017 DerbyCon keynote) in the Crowdstrike v. NSS labs case, they sued to prevent "third parties to access or use the products" and prohibited "any competitive analysis on the product".
Sorry to get into the weeds here, but the TL/DR is the following.
- Delaware District court Judge Gregory Sleet's ruling supporting product performance assessments.
- Government funding to support projects like ModSecurity that contribute to US economic security.
- Whitelisting (that works) is the future.
Today's security vendor marketing seems to have a free pass to lie. Thankfully, on 2017-02-13, Judge Gregory Sleet of the Delaware District court ruled against Crowdstrike writing "The consumer review fairness act of 2016 underscores the public's interest in performance assessments. The new law voids provisions of form contracts that restrict a party to that contract from conducting a performance assessment of or other similar analysis of..." "The court finds the public has a very real interest in the dissemination of information regarding products in the marketplace." It goes on to say if NSS's data is inaccurate, Crowdstrike could publicly rebut that data with evidence and the public would benefit from the exchange helping inform the public if they should trust future NSS reports. He concludes "the public interest weighs strongly in favor of denying Crowdstrike's motion."
https://www.csoonline.com/a.. https://www.csoonline.com/a...
Security is hard. I have been researching the Apache Struts2 exploits that Equifax was hit by. Assume another vulnerability like this exists right now. It could be Struts or some other web framework. Webshells used in the Struts hack are really hard to stop for many reasons. As far as I understand, if ModSecurity's open source web application firewall was installed and properly configured (not a simple task), the CRS (core rule set) would have prevented the Apache Struts2 exploit from working. Open source projects that make major contributions to protect United States national and economic security should receive more support and funding.
As a recognition for the contribution of all open source, Richard Stallman and Linus Torvalds should be recommended to receive the Presidential Medal of Freedom.
ModSecurity works by looking for known malicious patterns and blocks them. I hope one day we can get web application firewalls to work well using a whitelist setup. Instead of trusting everything and blocking things that look bad, on highly sensitive systems like Equifax, I hope to see a way to trust nothing and allow traffic that is known good. For example..
import re
def findWords(string1):
return re.findall(r"\b[^\d\W]+\b",string1)
f = open("apache2-access.log", "r")
data = f.read()
data = data.upper()
answer = findWords(data)
for a in answer:
print(a)
Now use bash to sort and get count..
$ python3 words.py | sort | uniq -c | sort -n
The next step is to create a modSecurity rule that uses the same regex "\b[^\d\W]+\b" to only allow REQUESTS that contain words that are on an approved list using the @pmf parameter file as in this following example. Note I just started looking into this, so I will leave the rest as an exercise for the reader :)
SecRule
REQUEST_COOKIES|!REQUEST_COOKIES:/__utm/|REQUEST_COOKIES_NAMES|ARGS_NAMES|ARGS|XML:/*
"@pmf windows-powershell-commands.dat
See github owasp-modsecurity-crs/rules/REQUEST-932-Application-ATTACK-RCE
- jjirsa 9y agoI don’t know if you lost format or context moving from Disqus but I found this largely unreadable. Of the parts that were readable, I find myself strongly disagreeing with a majority of your paragraphs, notably: - I don’t see how Crowdstrike vs NSS has any relevance in this at all, especially given the preamble on Troy’s site. Reasonable people can disagree on the outcome of that case (as a former Crowdstrike employee, I can acknowledge my own biases there), but I just don’t see how it’s relevant. - Similarly, I don’t see how formally recognizing Torvalds and RMS does anything meaningful, and I can think of a dozen other researchers who have had objectively more concrete contributions to SECURITY than those two. - Whitelisting every url pattern isn’t going to ever be a viable solution - in large part because the white lists will eventually be regexes and people are bad at regex.
- utefan001 9y agoReplying to own comment.. whitelisting with modsecurity tutorial... https://www.netnea.com/cms/apache-tutorial-6_embedding-modsecurity/ https://www.netnea.com/cms/apache-tutorial-6_embedding-modse... Step 8: Writing simple whitelist rules "Using the rules described in Step 7, we were able to prevent access to a specific URL. We will now be using the opposite approach: We want to make sure that only one specific URL can be accessed. In addition, we will we only be accepting previously known POST parameters in a specified format. This is a very tight security technique which is also called positive security: It is no longer us trying to find known attacks in user submitted content, it is now the user who has to proof that his request meets all our criteria." "Our example is a whitelist for a login with display of the form, submission of the credentials and the logout. We do not have the said login in place, but this does not stop us from defining the ruleset to protect this hypothetical service in our lab. And if you have a login or any other simple application you want to protect, you can take the code as a template and adopt as suitable." SecRule REQUEST_FILENAME \ "@rx ^/login/(displayLogin|login|logout).do$" \ "id:10250,phase:1,pass,nolog,tag:'Login Whitelist',\ skipAfter:END_WHITELIST_URIBLOCK_login" # If we land here, we are facing an unknown URI...