<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ayoi&#039;s &#187; Analyst Journal</title>
	<atom:link href="http://blog.hazrulnz.net/category/analyst-journal/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.hazrulnz.net</link>
	<description>What&#039;s with the blog?</description>
	<lastBuildDate>Fri, 30 Dec 2011 14:55:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>New approach, old objective..</title>
		<link>http://blog.hazrulnz.net/1732/new-approach-old-objective.html</link>
		<comments>http://blog.hazrulnz.net/1732/new-approach-old-objective.html#comments</comments>
		<pubDate>Mon, 08 Mar 2010 12:08:09 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[work and IT]]></category>
		<category><![CDATA[phising]]></category>
		<category><![CDATA[scam]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1732</guid>
		<description><![CDATA[My email used to be bombarded with spam or phising emails either for Paypal, Maybank or CIMB and sometimes Amazon as well. Usually these emails are in the same format (sometimes even same wordings), same email subject and lil bit different header images and of cause different sender address. But today (the email actually received [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1732/new-approach-old-objective.html' addthis:title='New approach, old objective.. '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<div id="attachment_1744" class="wp-caption aligncenter" style="width: 275px"><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/phishing.jpg"><img class="size-full wp-image-1744" title="phishing" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/phishing.jpg" alt="" width="265" height="270" /></a><p class="wp-caption-text">img source: wearecentralpa.com</p></div>
<p>My email used to be bombarded with spam or phising emails either for Paypal, Maybank or CIMB and sometimes Amazon as well. Usually these emails are in the same format (sometimes even same wordings), same email subject and lil bit different header images and of cause different sender address. But today (the email actually received yesterday but I only open my trusted Thunderbird today) the content is lil bit different, convincing enough and yeah even the sender address seems like from legitimate source for the unsuspecting users.</p>
<p><span id="more-1732"></span></p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam1.png"><img class="aligncenter size-medium wp-image-1734" title="scam1" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam1-300x178.png" alt="" width="300" height="178" /></a></p>
<p>As usual my Thunderbird categorized this email as probable Scam Email (as for some of my unfortunate friends email as well haha). Anyway for the first time I just remove the Scam tag and let the image load (after checking the email content source of cause).</p>
<p>As you can see the link stated in this email SEEMS to point to actual maybank2u website. But wait.. do not click it yet. Just move your mouse over the link and you can see the exact place where this link will lead you..</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam2.png"><img class="aligncenter size-medium wp-image-1735" title="scam2" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam2-300x178.png" alt="" width="300" height="178" /></a></p>
<p>Yup.. Instead of going to maybank2u website, the link actually will lead (or mislead in this case) you to http://foto.asmul.com/gallery2/modules/icons/iconpacks/KSIcons/M2ULogin.doaction=Login.htm <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  . So what if you really click on that link? For a start Firefox will not publish the site immediately but will give you an ample warning about that site instead.</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam3.png"><img class="aligncenter size-medium wp-image-1736" title="scam3" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam3-300x187.png" alt="" width="300" height="187" /></a></p>
<p>And if you superbly ignorant or stubborn and choose to ignore the warning instead, you will be presented with this page</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam4.png"><img class="aligncenter size-medium wp-image-1737" title="scam4" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam4-300x178.png" alt="" width="300" height="178" /></a></p>
<p>Ok even though the page bear resemblance with the actual maybank2u login page (refer image below) but IF you compare with these two, there are few glaring items that HOPEFULLY will make you aware that you are in a wrong/spoof/phising/<em>tipu</em>/<em>kencing</em> site.</p>
<p>The most obvious one is the <strong>address</strong> of the link. IF you are presented with maybank2u login page but the url shows address others BUT maybank2u&#8217;s, close your browser/tab and for precautionary move, run your antivirus or whatever anti spyware/bot/adware that you have in order to detect any possible unwanted malware (malicious software) downloaded unwittingly into your precious computer.</p>
<p>Like in this case, instead of having this address on the url field: https://www.maybank2u.com.my/mbb/m2u/common/M2ULogin.do?action=Login; you can see the address actually is http://foto.asmul.com/gallery2/modules/icons/iconpacks/KSIcons/M2ULogin.doaction=Login.htm with maybank2u login page.</p>
<p>Besides there&#8217;s a date on actual maybank2u&#8217;s login page, there are other differences that you should notice. Be my guest to download the images and play the &#8220;spot the different&#8221; between those images yourself as I&#8217;ve had enough of this game during my school years <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div id="attachment_1738" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam5.png"><img class="size-medium wp-image-1738" title="scam5" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam5-300x178.png" alt="" width="300" height="178" /></a><p class="wp-caption-text">The real maybank2u&#39;s login page</p></div>
<p>Well what will happen if you login or inserting your credential at this page..</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam6.png"><img class="aligncenter size-medium wp-image-1739" title="scam6" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam6-300x178.png" alt="" width="300" height="178" /></a></p>
<p>Unless your username is testing and the password is 12345678abcd, you have nothing to worry about. And even with this false information, the page will &#8220;process&#8221; and lead you to another page..</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam7.png"><img class="aligncenter size-medium wp-image-1740" title="scam7" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam7-300x178.png" alt="" width="300" height="178" /></a></p>
<p>Yup.. the infamous &#8220;update your Profile&#8221; page. Again unless your email is spongebob@krustykrab.com (is it yours?? sorry but I think you do not have maybank2u account rite? You do?&#8230;)</p>
<p>And the rest of the process is similar with the old phising scam.. Get TAC number, enter your TAC number, and the usual do not login to your account within 24 hours..</p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam8.png"><img class="aligncenter size-medium wp-image-1741" title="scam8" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam8-300x178.png" alt="" width="300" height="178" /></a></p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam9.png"><img class="aligncenter size-medium wp-image-1742" title="scam9" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam9-300x178.png" alt="" width="300" height="178" /></a></p>
<p>That&#8217;s for now. it seems there&#8217;s something interesting from the traffic generated by these activities. Will update on later post.</p>
<p>Oh yeah, it seems the site has been taken down <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam10.png"><img class="aligncenter size-medium wp-image-1743" title="scam10" src="http://blog.hazrulnz.net/wp-content/uploads/2010/03/scam10-300x187.png" alt="" width="300" height="187" /></a></p>
<h2><span style="color: #800000;">Anyway.. be careful and IF you have doubts, ALWAYS call your bank whenever you received any email from them. Just for confirmation and yeah you have to call them even you know that their Customer service is SUCKS..</span></h2>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1732/new-approach-old-objective.html' addthis:title='New approach, old objective.. '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1732/new-approach-old-objective.html/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Forensic Readiness Policy and watch your steps eh..</title>
		<link>http://blog.hazrulnz.net/1725/forensic-readiness-policy-and-watch-your-steps-eh.html</link>
		<comments>http://blog.hazrulnz.net/1725/forensic-readiness-policy-and-watch-your-steps-eh.html#comments</comments>
		<pubDate>Sat, 27 Feb 2010 10:27:32 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[work and IT]]></category>
		<category><![CDATA[forensic]]></category>
		<category><![CDATA[Indonesia]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1725</guid>
		<description><![CDATA[Greeting guys.. I&#8217;ve spent the past two weeks getting the draft for forensic readiness policy complete for submission to our client in Indonesia. To be honest this time around I need to assist our sister company there in designing an SOC for that particular client. In sense of security policy, bulk of the task was [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1725/forensic-readiness-policy-and-watch-your-steps-eh.html' addthis:title='Forensic Readiness Policy and watch your steps eh.. '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<div id="attachment_1726" class="wp-caption aligncenter" style="width: 310px"><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/02/logo_forensics.jpg"><img class="size-medium wp-image-1726" title="logo_forensics" src="http://blog.hazrulnz.net/wp-content/uploads/2010/02/logo_forensics-300x203.jpg" alt="" width="300" height="203" /></a><p class="wp-caption-text">Pic source: kellepcharles.blogspot.com</p></div>
<p>Greeting guys..</p>
<p>I&#8217;ve spent the past two weeks getting the draft for forensic readiness policy complete for submission to our client in Indonesia. To be honest this time around I need to assist our sister company there in designing an SOC for that particular client. In sense of security policy, bulk of the task was done by my colleague there. She&#8217;s very good in integrating the client&#8217;s security policies into ours. I really impressed with her works tho <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align: center;"><span id="more-1725"></span><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/02/DSC001181.jpg"><img class="aligncenter size-medium wp-image-1728" title="DSC00118" src="http://blog.hazrulnz.net/wp-content/uploads/2010/02/DSC001181-225x300.jpg" alt="" width="225" height="300" /></a></p>
<p>So what the heck is Forensic Readiness Policy?</p>
<p>The main objectives of this policy are to maximize the usefulness of incident data and minimize the cost of forensics during incident response. Very clear eh? <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Well the elements of forensic readiness usually:</p>
<ul>
<li>How Logging is done</li>
<li>What are the activities/items that being logged?</li>
<li>Intrusion Detection System (Network and host based)</li>
<li>Forensic Acquisition</li>
<li>Evidence Handling</li>
</ul>
<p>So before this post become a mini howto, better for me to stop till there. Nowadays more and more organizations aware on the importance of preserving or maintaining a proper record especially on their network traffics (based on my limited encounter lah.) There was a time when firewall or filtering via the boundary routers can be considered enough for network security. Now it seems that at least Intrusion Detection Systems (IDS) is the must have within the list of security devices for an organization (whether there are analysts or at least people monitoring this IDS outputs is another story). Also from my (limited) experience, most of our clients do have either one or more logs repository. Again the question whether if these logs are reviewed or not is not for me to answer.</p>
<p>So what does it mean?</p>
<p>It means that nowadays the www is not as wild wild web like it used to be. You hit and then you left the scene without much fuss on the trail. Bypassing filtering device like firewall is something cool but now if you brag on how you managed to bypass layer 3 and 4 filtering device, I guess people will just shrug off and ignore you. Now there are mechanisms to detect your activities whether on network or on the attacked system itself. Hacking is not Harry Porter stuff and you do leave a trail. Sooner or later, your &#8220;hacking&#8221; activities trails will lead to you.</p>
<p>With this kind of policy and many other similar policies as well, organizations perhaps are well prepared to detect and respond to any security incidents. Because for me, eventually you will be hacked or compromised. The important thing that you have to remember is how do you detect, respond and recover from these attacks.</p>
<p style="text-align: center;">
<div id="attachment_1729" class="wp-caption aligncenter" style="width: 127px"><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/02/prepared.jpg"><img class="size-full wp-image-1729" title="prepared" src="http://blog.hazrulnz.net/wp-content/uploads/2010/02/prepared.jpg" alt="" width="117" height="146" /></a><p class="wp-caption-text">Prepared - source :www. antithesiscommon.com</p></div>
<p>So bragging about your &#8220;hacking&#8221; activities in forums or blogs IMHO is a NO NO. It makes the task for the LEA easier especially when you include your handler in the page that you &#8220;hacked&#8221; <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Anyway, somehow <a href="http://taosecurity.blogspot.com/2010/02/max-ray-butler-sentenced-again.html" target="_blank">crime doesn&#8217;t pay <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </a></p>
<p style="text-align: center;"><a href="http://blog.hazrulnz.net/wp-content/uploads/2010/02/jailed.jpg"><img class="aligncenter size-medium wp-image-1730" title="jailed" src="http://blog.hazrulnz.net/wp-content/uploads/2010/02/jailed-300x262.jpg" alt="" width="300" height="262" /></a></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1725/forensic-readiness-policy-and-watch-your-steps-eh.html' addthis:title='Forensic Readiness Policy and watch your steps eh.. '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1725/forensic-readiness-policy-and-watch-your-steps-eh.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Good Doors but still you need CCTV</title>
		<link>http://blog.hazrulnz.net/1604/good-doors-but-still-you-need-cctv.html</link>
		<comments>http://blog.hazrulnz.net/1604/good-doors-but-still-you-need-cctv.html#comments</comments>
		<pubDate>Wed, 08 Jul 2009 06:18:14 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[work and IT]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1604</guid>
		<description><![CDATA[Recently one of my friends performed penetration testing on one of our client&#8217;s networks. Well most of the times the penetration testing will be done based on &#8220;white box&#8221; testing technique and yeah sometimes the client of cause request &#8220;black box&#8221; technique as well. And sometimes we just performed both of these techniques also. During [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1604/good-doors-but-still-you-need-cctv.html' addthis:title='Good Doors but still you need CCTV '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1618" title="cctv" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/cctv-300x225.jpg" alt="cctv" width="300" height="225" /></p>
<p>Recently one of my friends performed penetration testing on one of our client&#8217;s networks. Well most of the times the penetration testing will be done based on <em>&#8220;white box&#8221;</em> testing technique and yeah sometimes the client of cause request <em>&#8220;black box&#8221;</em> technique as well. And sometimes we just performed both of these techniques also. During the <em>&#8220;black box&#8221;</em> session, he mentioned that it seems that this particular client has some sort of content filtering device or mechanism that managed to block most of his <span style="text-decoration: line-through;">attack</span> assessment techniques. I assume that this client has an IPS installed on their network. No, this is not IPS bashing posting from me OK?</p>
<p><span id="more-1604"></span></p>
<p style="text-align: center;">
<div id="attachment_1619" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1619" title="SQLInjection1" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/SQLInjection1-300x200.jpg" alt="http://www.thetechherald.com/article.php/200817/811/" width="300" height="200" /><p class="wp-caption-text">http://www.thetechherald.com/article.php/200817/811/</p></div>
<p>OK.. So after few more others failed attempts on manipulating the user queries, my friend decided to (based on what he told me) use the old IDS evasion techniques like<em> fragmentation overlaps</em> and <em>fragmentation overwrite</em> with little expectation but <em><span class="ital-inline">voilà</span></em>, he managed to bypass the IPS or content filtering devices of that client. Of cause he executed his next tasks happily and I think he is lil bit astonished by how these filtering devices still can be deceived by old techniques.</p>
<p style="text-align: center;">
<div id="attachment_1620" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1620" title="DOSA_3" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/DOSA_3-300x172.gif" alt="http://archive.networknewz.com/networknewz-10-20021016NetworkDenialofServiceAttacksCanyouhackit.html" width="300" height="172" /><p class="wp-caption-text">http://archive.networknewz.com/networknewz-10-20021016NetworkDenialofServiceAttacksCanyouhackit.html</p></div>
<p>Actually it is quite difficult for me to comment on this because this is based on my friend&#8217;s story and I was not there to see the actual technique that my friend used to bypass the IPS (my assumption but my friend told me that the client did mention on their content filtering device). Maybe he used the fragmentation techniques to evade the IPS, and maybe he combines that technique with other as well.</p>
<p>Anyhow here is my view on this matter.</p>
<p style="text-align: center;">
<div id="attachment_1621" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1621" title="failKORR" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/failKORR-300x300.jpg" alt="http://www.markhoustonrecovery.com/relapse_prevention_.php" width="300" height="300" /><p class="wp-caption-text">http://www.markhoustonrecovery.com/relapse_prevention_.php</p></div>
<p>This condition does prove few things. First of all, it shows that prevention eventually fails. To be honest with you, I do really love that phrase. I do not know about you but most of the time I always being asked on the necessity of having IDS since IPS managed to do what ever IDS meant to do and on top of it, instead of only detecting, it also can perform active responses like reject or deny. Some of my students in my training classes also express their intention of removing the IDS since they have or acquired the latest content filtering appliance.</p>
<p>OK. Maybe they were right. Why you still want to keep the &#8220;old&#8221; technology since the &#8220;latest&#8221; one is available where the &#8220;latest&#8221; is the enhancement or evolution of the &#8220;old&#8221; one? Hmm but then perhaps most of us forgot that the &#8220;holy grail&#8221; of IDS is to achieve minimum or better still 0 false positive outputs from these IDSes (which in practice is impossible). I believe these &#8220;enhanced&#8221; technology also inherit the same &#8220;holy grail&#8221; as the old one.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1622" title="false-positive" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/false-positive-300x233.PNG" alt="false-positive" width="300" height="233" /></p>
<p>To make things more difficult, the positioning of these two systems in the network. In order to provide active responses to any malicious packets, IPS/content filtering/layer 7 firewalls (network based) usually will be emplaced in line with the network flow. For firewall (either network based or personal/host based), the best practice is to have a &#8220;default deny&#8221; policy where it will allows only selected traffics/transactions and denies the rest of them. Can IPS or any content filtering mechanism/device be implemented according to that kind of policy? Be my guest to answer this..</p>
<p style="text-align: center;">
<div id="attachment_1623" class="wp-caption aligncenter" style="width: 260px"><img class="size-full wp-image-1623" title="illustration292" src="http://blog.hazrulnz.net/wp-content/uploads/2009/07/illustration292.jpg" alt="http://www.linuxfocus.org/English/May2003/article292.shtml" width="250" height="183" /><p class="wp-caption-text">http://www.linuxfocus.org/English/May2003/article292.shtml</p></div>
<p>While as IDS is only providing the detection services, usually this device will be em placed at the network access points where it can monitors the network or network segments that suppose to be monitored, passively without interrupting the network flow. Even though the IDS is collecting every single bit of data and inspect those traffics right up to the application layer, it wont pose any problems or interruption to the network.</p>
<p>So does this mean we should start throwing our IPS out from our network? Does this mean that IPS is bad and IDS is good? No. It just means that substitution of these two do not improve your security posture at all. I also believe that these two must be seen as complementary of each other.</p>
<p>The best thing is to identify your monitoring zones, have your IPS filtering the allowed traffics into the network by the firewall, have your IDS then scrutinize the traffics filtered by the IPS and this traffic again will be filtered by the personal/host based/application level firewalls.</p>
<p>Anyway, that&#8217;s my view only and as usual I welcome any other opinions as well.</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 80px; width: 1px; height: 1px;">
<h2 class="me">voi⋅là</h2>
</div>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1604/good-doors-but-still-you-need-cctv.html' addthis:title='Good Doors but still you need CCTV '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1604/good-doors-but-still-you-need-cctv.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Service for Hire&#8230; Interested?</title>
		<link>http://blog.hazrulnz.net/1591/service-for-hire-interested.html</link>
		<comments>http://blog.hazrulnz.net/1591/service-for-hire-interested.html#comments</comments>
		<pubDate>Mon, 15 Jun 2009 09:05:01 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1591</guid>
		<description><![CDATA[Nowadays, either people are getting lazier than before or the technology is becoming too convenient  for us. We used to go to the bank for financial matters, to respective utility companies for settling our monthly utility bills, go to the shop/mall for shopping. Now everything (mostly) can be done via click of the mouse. In [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1591/service-for-hire-interested.html' addthis:title='Service for Hire&#8230; Interested? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<div id="attachment_1592" class="wp-caption aligncenter" style="width: 210px"><img class="size-full wp-image-1592" title="work" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/work.gif" alt="http://www.linux.org.au/projects/grants/" width="200" height="197" /><p class="wp-caption-text">http://www.linux.org.au/projects/grants/</p></div>
<p>Nowadays, either people are getting lazier than before or the technology is becoming too convenient  for us. We used to go to the bank for financial matters, to respective utility companies for settling our monthly utility bills, go to the shop/mall for shopping. Now everything (mostly) can be done via click of the mouse. In fact wifey once bought  traditional food/cookies via internet and that goodies were sent via Pos Laju. By the time we receive that particular parcel, I think some of the cookies were not in their original shape and crushed <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p>And recently I received this in one of the posts comment section awaiting to be approved by me <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><span id="more-1591"></span></p>
<pre>Tired of a competitor's site? Hinder the enemy? Fed pioneers or copywriters? 

Kill their sites! How? We will help you in this!
Obstructions of any site, portal, shop! 

Different types of attacks: Date-attack, Trash, Attack, Attack, etc. Intellectual
You can work on schedule, as well as the simultaneous attack of several sites. 

On average the data, ordered the site falls within 5 minutes after the start.
As a demonstration of our capabilities, allows screening. 

Our prices 

24 hours of attack - $ 70
12 hours of the attack - $ 50
1 hour attack - $ 25

Contact via ICQ: 588 666 582</pre>
<p><span style="text-decoration: line-through;">Ahh.. Let me think.. Hmmm there are one of two websites that I love to shut those down. These guys loves arguing with me so better to shut them up by shutting down their sites.. </span></p>
<p>Lol just kidding guys. No offend ok? I love visiting your sites btw <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  And yeah, to be honest I didn&#8217;t call those as argument but it&#8217;s more like intellectual discourse <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>On serious note, it seems that <a href="http://www.google.com.my/search?hl=en&amp;q=dosed3drifa%40gmail.com&amp;btnG=Google+Search&amp;meta=&amp;aq=f&amp;oq=" target="_blank">this person/group has sent/posted their offererings to various websites/forums</a>. And yes, <a href="http://people.icq.com/people/full_details_show.php?uin=588666582" target="_blank">the ICQ ID number does exist but no detail information</a> (of cause lor for this purpose <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>Maybe the content is lil bit confusing but perhaps that comment originally in German language and he used translator to translate those into English. German because so far if you search on the email address of the owner, it seems that most of this comment were done using network belongs to Deutsche Telekom AG. (Note to my friend, Deutche is NOT Dutch spelled in a fancy spelling OK?)</p>
<p>If you have 70 bucks (I guess it&#8217;s in USD and not using Euro € due to exchange rate perhaps) to spare, why not buzz him/her/them via ICQ? And good luck for that anyway LoL. (And please dun target this blog btw)</p>
<p>Is this service for real or not, I dun have any idea but if it is then I think the economy crisis is worst than I thought <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1591/service-for-hire-interested.html' addthis:title='Service for Hire&#8230; Interested? '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1591/service-for-hire-interested.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>On this Mourn-day</title>
		<link>http://blog.hazrulnz.net/1583/on-this-mourn-day.html</link>
		<comments>http://blog.hazrulnz.net/1583/on-this-mourn-day.html#comments</comments>
		<pubDate>Mon, 15 Jun 2009 06:22:54 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[work and IT]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1583</guid>
		<description><![CDATA[I think somewhere around January, I did mention to my colleagues on the possible rise of cybercrime cases due to the world economy crisis. There will be more spam email than before, more phising emails than before and yes, this time the target has been shifted to client or user side Why? Because it is [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1583/on-this-mourn-day.html' addthis:title='On this Mourn-day '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-full wp-image-1585" title="phising" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/phising.jpg" alt="phising" width="194" height="192" /></p>
<p>I think somewhere around January, I did mention to my colleagues on the possible rise of cybercrime cases due to the world economy crisis. There will be more spam email than before, more phising emails than before and yes, this time the target has been shifted to client or user side <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Why? Because it is a &#8220;lucrative&#8221;, often overlooked, less controlled and high in numbers. Instead of controlling few servers in that particular organisation (and difficult as well because most of the times these servers will be highly protected, monitored as those machines are in the high priority list <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ) why not just concentrate on the users. 1% of let say 1000 users is not bad eh? <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  My friend mel posted one of the trick of misleading the users at <a href="http://security.org.my/index.php?/archives/Another-Scam-Targetting-Gullible-Malaysians.html" target="_blank">security.org.my</a></p>
<p><span id="more-1583"></span></p>
<p>There are many ways or patterns of how these phising emails may looked like. Previously it&#8217;s about how &#8220;our&#8221; bank&#8217;s servers were DDoSed and the needs of so called re-activation or re-verification of our accounts. For that purpose we need to login to our online account, retrieve the TAC number and submit those information (user name, password and TAC numbers) to the &#8220;verification&#8221; servers that happened to be located outside of Malaysia. <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Oh yeah, failed to perform this activity, your account will be terminated within 24 hours. As simple as that. One more thing, once you&#8217;ve &#8220;verified&#8221; (submitting the information to the &#8220;verification&#8221; server), you are not allowed to use your online account for 48 hours. Hmm I thought all these internet thingy/stuffs usually processed within seconds if not miliseconds.. LoL.</p>
<p>Now the trend is &#8220;Unblock you Account&#8221; email.</p>
<p>&#8220;<em>Unblock your Account</em></p>
<p><em>For security reasons, your Maybank2u.com account has been blocked due to inactivity or becouse of too many failed login attempts.</em></p>
<p><em>Please login at maybank2u to restore your account access.</em></p>
<p><em>Online banking: Login</em></p>
<p><em>Maybank Berhad</p>
<p>https://www.maybank2u.com.my</em></p>
<p><em>© 2001-08 Maybank. All rights reserved.&#8221;</em></p>
<p style="text-align: center;"><em></p>
<div id="attachment_1586" class="wp-caption aligncenter" style="width: 340px"><em><img class="size-medium wp-image-1586" title="meibeng" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/meibeng-300x213.jpg" alt="Thunderbird thinks that this email is scam. I love thunderbird" width="330" height="234" /></em><p class="wp-caption-text">Thunderbird thinks that this email is scam. I love thunderbird</p></div>
<p></em></p>
<p>Cool eh&#8230; Too many failed login or due to inactivity (in sense of what? Never logged on? Less money transaction?) and this will caused your online account suspended. And yeah, it seems that one of the largest banks in our country is trying to save every penny that instead of inform me directly via phone call, they chose to send an email with poor spelling (if you want to &#8220;phis&#8221;, do it properly) and what the heck what kind of official email send to &#8220;undisclosed recipient&#8221;?. It doesn&#8217;t matter whether my balance is RM2.75 or RM 2.75 million, I am still your customer and you used my money for your business (credit creation.. ever heard of this? that&#8217;s why you need to have minimum balance), so please send a direct email ONLY to me OK? lol.</p>
<p>Sorry for that rant. Maybe because it is MOURNday&#8230; ANyway, further checking will reveal that this email is not from maybank (in fact if you look at the sender&#8217;s email address, you will know right away that this is non valid email.) There is not MX record for maybank2u.com.my. Maybank2u.com.my is only a domain specifically for web purpose, no other functions OK? This means that the only valid email that you will received from maybank personnel should has this address =&gt; <em>blabla@maybank.com.my</em> and NOT<em> blabla@maybank2u.com.my</em> or any other. Expect next time these phisers will use maybank.com.my as the sender email address <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> . For that just take note that you should call any maybank branches (or your branches) for verification. Better still, you go there and talk to their representative.</p>
<p>For the email that I received, the email actually was sent from an insurance company called <a href="http://alandale.com/" target="_blank">Alandale Insurance</a> Agency. As the source of the email revealed that it was sent from a server called server.alandale.com (and if you query for its MX record, server.alandale.com is used as the mail exchanger with priority 5). I guess maybe one of the users&#8217; machines was infected by worm that utilizes the email traffics on spreading its spam etc.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1587" title="alandale" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/alandale-300x117.jpg" alt="alandale" width="300" height="117" /></p>
<p>The best part is, the guy or gal who created this phising email has the audacity to use one of the images in yours truly website for this phising purpose.. Sigh..</p>
<p style="text-align: center;"><img class="aligncenter size-large wp-image-1588" title="phis" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/phis-1024x174.jpg" alt="phis" width="656" height="111" /></p>
<p>Oh yeah.. all the links point to this site : http://75-149-136-211-connecticut.hfc.comcastbusiness.net/indexx.html which has been reported as &#8220;Web Forgery&#8221; by firefox.. (ok not by firefox)</p>
<p>Nice try guys <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1583/on-this-mourn-day.html' addthis:title='On this Mourn-day '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1583/on-this-mourn-day.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Chill out ;)</title>
		<link>http://blog.hazrulnz.net/1560/chill-out.html</link>
		<comments>http://blog.hazrulnz.net/1560/chill-out.html#comments</comments>
		<pubDate>Fri, 05 Jun 2009 08:09:01 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[friends]]></category>
		<category><![CDATA[maya karin]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1560</guid>
		<description><![CDATA[It seems that my previous posting did offend some people. I want to take this opportunity to say sorry to whoever offended either directly or indirectly by that post and there are no malicious intentions in it. As most of the people in this particular industry I can call them as my friends and professional [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1560/chill-out.html' addthis:title='Chill out ;) '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1563" title="chill-out-photographic-print-c12255139" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/chill-out-photographic-print-c12255139-300x249.jpg" alt="chill-out-photographic-print-c12255139" width="300" height="249" /></p>
<p>It seems that my <a href="http://blog.hazrulnz.net/1557/if-it-was-me.html" target="_blank">previous posting</a> did offend some people. I want to take this opportunity to say sorry to whoever offended either directly or indirectly by that post and there are no malicious intentions in it. As most of the people in this particular industry I can call them as my friends and professional colleagues. But with that in mind, these people also entitled for their comments, views and opinions.</p>
<p><span id="more-1560"></span>A comment from y0muds is a comprehensive and long one (Sorry dude, I just dunno why but <a href="http://akismet.com/" target="_blank">akismet</a> consider your comment as spam <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  and I guess perhaps because of the length).</p>
<p>Anyway like I mentioned before, I do have intention to attend the hackaton day as most of presentations on that particular day are dealing with web intrusion as perhaps there are some techniques on detection or prevention that can be implemented for our daily operations. Alas, I have to abandon that idea as I have other important matter that I have to attend.</p>
<p>Anyway, I think both of the parties have given their views and opinions; I guess now is the time for us to chill out ok? <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Take a break, have a glass of nescafe (Maya Karin said nescafe has a high level of <a href="http://en.wikipedia.org/wiki/Antioxidant" target="_blank">antioxidant</a>) and a cigar&#8230;</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1562" title="content-1239756686" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/content-1239756686.gif" alt="content-1239756686" width="145" height="150" /></p>
<p>p/s: Anyway I do like to have this kind of interaction.. Just like the ones that we had at <a href="http://security.org.my/index.php?/archives/On-exposing-vulnerabilities-on-.gov.my-websites.html" target="_blank">security.org.my during the hackingexpose event</a> <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  <a href="http://www.ahaq.net/" target="_blank">Ahaq&#8230;</a></p>
<p>And NO, I do not like to raise contraversial issue or disturb other people nerves like most of you tend to believe.</p>
<p>I&#8217;m just an ordinary, happy and nice guy.. Honest..</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1561" title="me_2" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/me_2.jpg" alt="me_2" width="162" height="212" /></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1560/chill-out.html' addthis:title='Chill out ;) '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1560/chill-out.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If it was me&#8230;</title>
		<link>http://blog.hazrulnz.net/1557/if-it-was-me.html</link>
		<comments>http://blog.hazrulnz.net/1557/if-it-was-me.html#comments</comments>
		<pubDate>Mon, 01 Jun 2009 09:25:18 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[structured traffic analysis]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1557</guid>
		<description><![CDATA[As usual, Monday is a very bad day for me. Dun ask me why but perhaps I&#8217;m watching /reading too much Garfield and influenced by this fat lazy but adorable cat obsession on hating Mondays . So while doing my usual Monday activities (this of cause after reading my emails especially the ones in the [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1557/if-it-was-me.html' addthis:title='If it was me&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;">
<div id="attachment_1558" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-1558" title="pg_263597014" src="http://blog.hazrulnz.net/wp-content/uploads/2009/06/pg_263597014-300x225.jpg" alt="http://www.dailystrength.org/people/110944/photos-videos/item/293887" width="300" height="225" /><p class="wp-caption-text">http://www.dailystrength.org/people/110944/photos-videos/item/293887</p></div>
<p>As usual, Monday is a very bad day for me. Dun ask me why but perhaps I&#8217;m watching /reading too much Garfield and influenced by this fat lazy but adorable cat obsession on hating Mondays <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> . So while doing my usual Monday activities (this of cause after reading my emails especially the ones in the inbox as I&#8217;ve filtered other emails to their respective mailing list folders, so the ones arrived in the Inbox are usually meant for me personally:)), one of my friends &#8220;buzzing&#8221; me via one of the Internet Messenger clients.</p>
<p><span id="more-1557"></span>&#8212;&#8211;Snip&#8212;&#8211;<br />
<em>my_friend</em>: awat hang tak mai s emalam<br />
<em>my_friend</em>: hackaton<br />
<strong>soulkipper</strong>: aku balik ktn ler<br />
<em>my_friend</em>: cybercert sucks arr  die nye  demonstration hackin<br />
<em>my_friend</em>: gile lame<br />
<em>my_friend</em>: sep baik a ku duk kat *******<br />
<strong>soulkipper</strong>: btw aku not 1337 enuff<br />
<strong>soulkipper</strong>: hahaha<br />
<em>my_friend</em>: tak bukan leet<br />
<em>my_friend</em>: ade mamat tu(bukan adli  maupun mahmud)<br />
<em>my_friend</em>: nak tunjuk<br />
<em>my_friend</em>: remote file inclusio n nue  attcak<br />
<em>my_friend</em>: tapi<br />
<em>my_friend</em>: haha<br />
<em>my_friend</em>: global variable dlm php.ini<br />
<em>my_friend</em>: lupe<br />
<strong>soulkipper</strong>: remote file inclusion<br />
<strong>soulkipper</strong>: alaaa<br />
<em>my_friend</em>: nak enable<br />
<strong>soulkipper</strong>: tu lama punya<br />
<em>my_friend</em>: so buatx2 tak jadi<br />
<em>my_friend</em>: haha</p>
<p>&#8212;&#8212;-snip&#8212;&#8212;&#8212;-</p>
<p>I do believe that my friend has really good intention on mentioning those. Perhaps in the future the presenter can show some latest trend and techniques or emphasis on the rise of client side attacks on the net. I also believe that the speakers or presenters had gone through their presentation materials and the live demo steps and methods. Maybe some unexpected condition arised during the presentation time hence the unsuccessful live demo.</p>
<p>If I&#8217;m not mistaken during the 2007 Technical forum at PWTC, one of the presenters who tried to show some demo on Bluetooth hacking also failed. SO this kind of thing may happened to anybody. It happens to me a lot during my training sessions especially when dealing with my VMWares..Sigh..</p>
<p>If it was me then;</p>
<p><strong>soulkipper</strong>: kalu aku, aku tunjuk je structured threat analysis using open source tools<br />
<strong>soulkipper</strong>: abih cite<br />
<strong>soulkipper</strong>: takpung collecting Network based evidence using open source tools</p>
<p>Yeah, I will do some demo on performing structured threat analysis or collection network based evidence using open source tools like argus, tcpdump, snort, tcpflow etc..</p>
<p>Hmm maybe I can use this topic for my next knowledge sharing session or we called it here &#8220;<em>kopitiam session&#8221;</em>. Materials? I can collect the network traffics and do the demo on the virtual machine. Eh.. I forgot that currently I&#8217;m using the &#8220;borrowed&#8221; laptop. I dun think running virtual machines on this laptop is a good idea&#8230;</p>
<p>Ahh later <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p><em>p/s: To protect the identity of my friend, I have to filter some of the communication content between us <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </em></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1557/if-it-was-me.html' addthis:title='If it was me&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1557/if-it-was-me.html/feed</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Perimeter defense is not enough</title>
		<link>http://blog.hazrulnz.net/1494/perimeter-defense-is-not-enough.html</link>
		<comments>http://blog.hazrulnz.net/1494/perimeter-defense-is-not-enough.html#comments</comments>
		<pubDate>Wed, 22 Apr 2009 09:02:29 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[halizain]]></category>
		<category><![CDATA[mod_security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1494</guid>
		<description><![CDATA[My friend&#8217;s gave a presentation on the mod_security usage last few weeks to a group of users from the government. In his presentation he gave a demo on how mod_security managed to prevent &#8220;blind sql injection&#8221; attacks on the application run on mod_security enabled web engine. He even received a thunderous applaud from the audience [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1494/perimeter-defense-is-not-enough.html' addthis:title='Perimeter defense is not enough '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-full wp-image-1496" title="dsc01330-300x2251" src="http://blog.hazrulnz.net/wp-content/uploads/2009/04/dsc01330-300x2251.jpg" alt="dsc01330-300x2251" width="300" height="225" /></p>
<p>My friend&#8217;s gave a presentation on the mod_security usage last few weeks to a group of users from the government. In his presentation he gave a demo on how mod_security managed to prevent &#8220;blind sql injection&#8221; attacks on the application run on mod_security enabled web engine. He even received a thunderous applaud from the audience once he concluded his presentation. However one of the attendees asked one good question afterward.</p>
<p>&#8220;My friend said you do not need to installed any WAF (web application firewall). All you need to do is fine tune the firewall filtering policies and that&#8217;s it.&#8221;</p>
<p><span id="more-1494"></span>Well that view is not wrong. No sir, it&#8217;s not wrong at all. But then again, security is about minimizing the risk from being compromised. But still, it doesn&#8217;t matter how vigilant you are in following the security processes because eventually everything that you&#8217;ve done are not enough to prevent your asset from being compromised.</p>
<p>Lets take a building (we call this building, Building A) as an example. Most of the time (and most of the building), the only place accessible for anybody is the lobby (and perhaps the toilet also). When you try to access beyond the lobby, usually you need to register yourself at the registration table  placed before the lift lobby. Usually you need to identify yourself by presenting your ID card, inform your destination (and sometimes purpose of visit as well) received guest pass and off you go to your destination.</p>
<p>Now if let say that&#8217;s the only defensive measures that the building have, the risks for the building tenants to be compromised is high. Agree? Ok now we want to fine tune the filtering process at the reception, let say everybody must be body searched or provide other detailed information or other checking methods, I believe the queue will be long and the time taken for any guest to proceed to their destination will definitely not short. Hence due to the hassle that each guess need to face before proceed with their tasks, they will decided against visiting that particular building in the future.</p>
<p>So now let create another example, we call this building, Building B. Besides the need to register at the reception, it also equiped with doors that require access pass. Every guess will be issued access pass only to the intended floor and office (Even some offices in a building have their own lobby or reception). On top of that, your movement within the building will be monitored by CCTVs and if you appeared to be in the wrong floor or doing something funny, the friendly security guard will waste no time in coming to you and do any action necessary. Meaning there are many security layers for these buildings and we can assume that the risks for the tenants to be compromised is not as high as the building that has only reception table as the defensive measure (Building A). Agree?</p>
<p>Like I said before, both of the security measures taken by building A and B is not wrong. But then again, security is about reducing the risk of being compromised. So for you, what kind of security measures that you want to implement?</p>
<p>The ones like Building A (only perimeter defense &#8211; firewall via reception) or Building B (firewall &#8211; reception, IDS &#8211; CCTVs, Host Based or WAF &#8211; doors that require access card)?</p>
<p>That&#8217;s my opinion btw <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1494/perimeter-defense-is-not-enough.html' addthis:title='Perimeter defense is not enough '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1494/perimeter-defense-is-not-enough.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Aint no April Fool&#8230;</title>
		<link>http://blog.hazrulnz.net/1471/aint-no-april-fool.html</link>
		<comments>http://blog.hazrulnz.net/1471/aint-no-april-fool.html#comments</comments>
		<pubDate>Wed, 01 Apr 2009 08:37:57 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[conficker]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1471</guid>
		<description><![CDATA[Again.. Sorry for the long Hiatus.. Anyway I did received an email from one of my friends at CyberSecurity Malaysia.. &#8220;maybe u can pos something useful &#38; reminder in your blog &#38; security.org.my to remind your blog visitors bout this malware. thanks bro..&#8221; Ahhh the link.. http://www.mycert.org.my/en/services/advisories/mycert/2009/main/detail/647/index.html Yeah guys.. This ain&#8217;t no HOAX. In fact, [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1471/aint-no-april-fool.html' addthis:title='Aint no April Fool&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-full wp-image-1472" title="worm2" src="http://blog.hazrulnz.net/wp-content/uploads/2009/04/worm2.jpg" alt="worm2" width="225" height="230" /></p>
<p>Again.. Sorry for the long Hiatus.. Anyway I did received an email from one of my friends at CyberSecurity Malaysia..</p>
<p><em>&#8220;maybe u can pos something useful &amp; reminder in your blog &amp; <a href="http://security.org.my/">security.org.my</a> to remind your blog visitors bout this malware.<br />
 <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  thanks bro..&#8221;</em></p>
<p>Ahhh the link.. <a href="http://www.mycert.org.my/en/services/advisories/mycert/2009/main/detail/647/index.html" target="_blank">http://www.mycert.org.my/en/services/advisories/mycert/2009/main/detail/647/index.html</a></p>
<p>Yeah guys.. This ain&#8217;t no HOAX. In fact, there are few entries in SANS Handler&#8217;s diary regarding the increase of DNS polling performed by the infamous Conficker or Dowandup (from 250 different domain names per day to 500 ).</p>
<p>Read it here : <a href="http://isc.sans.org/diary.html?storyid=6091">April 1st &#8211; What Will Really Happen?</a></p>
<p>Btw Felix Leder, Tillmann Werner of The HoneyNet Project produced one good writeup &#8220;<a href="http://honeynet.org/node/388" target="_blank">Containing Conficker</a>&#8220;. I recommend you guys to <a href="http://honeynet.org/node/388" target="_blank">download that paper and read i</a>t. Also read another good writeup of Conficker variants <a href="http://mtc.sri.com/Conficker/addendumC/index.html" target="_blank">by SRI here.</a></p>
<p>Also you can now identify possible Conficker infected machines by performing network scanning via NMAP or NESSUS.</p>
<p>For NESSUS the related plugin description :<a href="http://www.nessus.org/plugins/index.php?view=single&amp;id=36036" target="_blank">PluginID 36036</a></p>
<p>How to scan using NMAP can be read from this site : <a href="http://www.skullsecurity.org/blog/?p=209" target="_blank">www.skullsecurity.org</a></p>
<p>For removal instructions and tools, just follow the links provided in <a href="http://www.dshield.org/diary.html?storyid=5860" target="_blank">special Conficker page at Dshield site</a>.</p>
<p>There you go folks. Sorry it&#8217;s lil bit late and yeah I&#8217;m lil bit tight right now..</p>
<p>p/s: Btw my friend mel already post an entry regarding Conficker worm at <a href="http://security.org.my/index.php?/archives/Be-Prepare-for-Conficker-on-April-1st.html" target="_blank">security.org.my</a></p>
<div class="headline"></div>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1471/aint-no-april-fool.html' addthis:title='Aint no April Fool&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1471/aint-no-april-fool.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WebGoat: Exploit and Learn&#8230;</title>
		<link>http://blog.hazrulnz.net/1455/webgoat-exploit-and-learn.html</link>
		<comments>http://blog.hazrulnz.net/1455/webgoat-exploit-and-learn.html#comments</comments>
		<pubDate>Thu, 19 Mar 2009 11:18:20 +0000</pubDate>
		<dc:creator>ayoi</dc:creator>
				<category><![CDATA[Analyst Journal]]></category>
		<category><![CDATA[owasp]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[webgoat]]></category>

		<guid isPermaLink="false">http://blog.hazrulnz.net/?p=1455</guid>
		<description><![CDATA[Dun know about you guys but during my time (not that long ago lah), the only avenues for me to test my newly acquired skills and tools (most of the time to test the tools and scripts -yeah I used to be a script kiddie ) are servers, websites, routers belong to other people. Ahh [...]<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1455/webgoat-exploit-and-learn.html' addthis:title='WebGoat: Exploit and Learn&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1456" title="webgoat_logo" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/webgoat_logo-294x300.jpg" alt="webgoat_logo" width="294" height="300" /></p>
<p>Dun know about you guys but during my time (not that long ago lah), the only avenues for me to test my newly acquired skills and tools (most of the time to test the tools and scripts -yeah I used to be a script kiddie <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> ) are servers, websites, routers belong to other people. Ahh forgot to mention that I used to test these tools on other PCs in the CyberCafe as well <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> . In that time also IRC chatrooms can be the testing ground and learning centre as well. Mind you that at that time, VMWare just founded and the first product (VMWare Workstation) only delivered a year later <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Nowadays  you only need a PC/laptop, internet browser (for WIMP users, no worries on this part) and you dun even have to be connected. Thanks to <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">OWASP&#8217;s WebGoat Project</a> <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align: center;"><span id="more-1455"></span><img class="aligncenter size-full wp-image-1457" title="webhacking" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/webhacking.jpg" alt="webhacking" width="119" height="147" /></p>
<p>So what is WebGoat? Let this lazy bum quote the <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">Goal of this WebGoat project from its page</a>.</p>
<p>&#8220;The primary goal of the WebGoat project is simple: <strong><em>create a de-facto interactive teaching environment for web application security</em></strong>. In the future, the project team hopes to extend WebGoat into becoming a security benchmarking platform and a Java-based Web site Honeypot&#8221;</p>
<p>&#8220;<strong>WebGoat</strong> is a deliberately insecure J2EE web application maintained by <a class="external text" title="http://www.owasp.org" rel="nofollow" href="http://www.owasp.org/">OWASP</a> designed to teach web application security lessons. In each lesson, users must demonstrate their understanding of a security issue by exploiting a real vulnerability in the WebGoat application&#8221;</p>
<p>What I can conclude is <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">WebGoat</a> is the right avenue for you to learn the Web application attack techniques (Nowadays most of the attacks are layer 7 attacks <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> ) Instead of performing the &#8220;try and error&#8221; (the old school) way on the applications belong to others, you can learn these techniques and why the application succumbed to those techniques without causing any damage to others belonging. Hey it also saves you from any entanglement with the Law as well. <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1458" title="freebsd_300x300" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/freebsd_300x300.png" alt="freebsd_300x300" width="300" height="300" /></p>
<p>With that spirit, I decided to have WebGoat installed onto one of our testing machines (virtual that is) in lab environment so the Analysts can learn and play around with the application.</p>
<p>One thing that I didn&#8217;t notice is the size of WebGoat is around 83MB and took some time for me to complete the download process as it seems that our line decided to drag its feet while transporting the data. Sigh.</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1459" title="java" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/java-299x300.jpg" alt="java" width="299" height="300" /></p>
<p>WebGoat requires JDK to be installed first. So when I run the usual make install command at <em>jdk15</em> port (<em>/usr/ports/java/jdk15</em>), I was presented by this message:</p>
<p><em>IMPORTANT: To build the JDK 1.5.0 port, you should have at least<br />
2.5Gb of free disk space in the build area!</p>
<p>Due to licensing restrictions, certain files must be fetched manually.</p>
<p>Please open http://download.java.net/tiger/archive/tiger_u14/<br />
in a web browser.  Download the<br />
Update 14 Source, jdk-1_5_0_14-fcs-src-b03-jrl-05_oct_2007.jar and the<br />
Source Binaries, jdk-1_5_0_14-fcs-bin-b03-jrl-05_oct_2007.jar .</p>
<p>Please open http://java.sun.com/javase/downloads/index_jdk5.jsp<br />
in a web browser and follow the &#8220;Download&#8221; link for<br />
&#8220;Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy<br />
Files 5.0&#8243; to obtain the JCE policy file, jce_policy-1_5_0.zip.</p>
<p>Please open http://java.sun.com/javase/downloads/index.jsp<br />
in a web browser and follow the &#8220;Download&#8221; link for<br />
&#8220;JDK US DST Timezone Update Tool &#8211; 1_3_11&#8243; to obtain the<br />
time zone update file, tzupdater-1_3_11-2008i.zip.</p>
<p>Please download the patchset, bsd-jdk15-patches-8.tar.bz2, from</p>
<p>http://www.eyesbeyond.com/freebsddom/java/jdk15.html.</p>
<p>Please place the downloaded file(s) in /usr/ports/distfiles<br />
and restart the build.</em><br />
Whaaaa&#8230; I need to download those files manually. With the download &#8220;speed&#8221; that I have at that time, I have to download :</p>
<p>jdk-1_5_0_14-fcs-src-b03-jrl-05_oct_2007.jar = 55MB</p>
<p>jdk-1_5_0_14-fcs-bin-b03-jrl-05_oct_2007.jar  = 2.1 MB</p>
<p>jce_policy-1_5_0.zip = 10K  (Thank God)</p>
<p>tzupdater-1_3_11-2008i.zip = 288K (Fortunately)</p>
<p>bsd-jdk15-patches-8.tar.bz2 = 800K</p>
<p>So once finish downloading all those files, the installation process commenced immediately and after a looooooooooong while it completed.</p>
<p>Next is the process of extracting the WebGoat application onto my virtual server and some configuration performed:</p>
<p>a). Defining the JAVA_HOME</p>
<p>b). As by default WebGoat meant to be run on localhost, a simple configuration in sense of providing the listening IPs and Ports in the<em> server_80.xml</em> file within the <em>tomcat/conf/</em> directory of the WebGoat folder.</p>
<p style="text-align: center;"><img class="aligncenter size-full wp-image-1460" title="pro-apache-tomcat-6" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/pro-apache-tomcat-6.jpg" alt="pro-apache-tomcat-6" width="240" height="240" /></p>
<p>But the moment I execute webgoat.sh start80, I&#8217;ve been presented by this message:</p>
<p>&#8220;<strong>Please set JAVA_HOME to a Java 1.5 JDK install</strong>&#8221;</p>
<p>And it doesn&#8217;t matter how many times I define those fields (including symbolic link as well) the message keeps on appearing when I tried to start the application. So I search through google and <a href="http://carnal0wnage.blogspot.com/2007/12/webgoat-50-on-ubuntu.html" target="_blank">discover this technique</a>:</p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1461" title="c0_electric3" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/c0_electric3-300x80.jpg" alt="c0_electric3" width="300" height="80" /></p>
<p>Delete the check code of the java version, put export JAVA_HOME=to the installed jdk location at the top of the script which made my webgoat.sh look like this:</p>
<p>ayoi# less webgoat.sh<br />
#! /bin/sh</p>
<p>SYSTEM=`uname -s`<br />
CATALINA_HOME=./tomcat<br />
PATH=${PATH}:./tomcat/bin<br />
export CATALINA_HOME PATH<br />
export JAVA_HOME=/usr/local/jdk-1.5.0<br />
chmod +x ./$CATALINA_HOME/bin/*.sh</p>
<p>case &#8220;$1&#8243; in<br />
start80)<br />
cp -f $CATALINA_HOME/conf/server_80.xml $CATALINA_HOME/conf/server.xml<br />
$CATALINA_HOME/bin/startup.sh<br />
printf &#8220;\n  Open http://127.0.0.1/WebGoat/attack&#8221;<br />
printf &#8220;\n  Username: guest&#8221;<br />
printf &#8220;\n  Password: guest&#8221;<br />
printf &#8220;\n  Or try http://guest:guest@127.0.0.1/WebGoat/attack \n\n\r&#8221;<br />
sleep 2<br />
tail -f $CATALINA_HOME/logs/catalina.out<br />
===============SNIP==================</p>
<p>So when I execute the webgoat.sh start80 command, voila..</p>
<p><em>ayoi# ./webgoat.sh start80<br />
Using CATALINA_BASE:   ./tomcat<br />
Using CATALINA_HOME:   ./tomcat<br />
Using CATALINA_TMPDIR: ./tomcat/temp<br />
Using JAVA_HOME:       /usr/local/jdk-1.5.0</p>
<p>Open http://127.0.0.1/WebGoat/attack<br />
Username: guest<br />
Password: guest<br />
Or try http://guest:guest@127.0.0.1/WebGoat/attack</em><br />
===============SNIP=========================</p>
<p>The WebGoat is now running and ready to be hacked <img src='http://blog.hazrulnz.net/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="text-align: center;"><img class="aligncenter size-medium wp-image-1462" title="webgoat_page" src="http://blog.hazrulnz.net/wp-content/uploads/2009/03/webgoat_page-300x187.jpg" alt="webgoat_page" width="300" height="187" /></p>
<div class="addthis_toolbox addthis_default_style " addthis:url='http://blog.hazrulnz.net/1455/webgoat-exploit-and-learn.html' addthis:title='WebGoat: Exploit and Learn&#8230; '  ><a class="addthis_button_facebook_like" fb:like:layout="button_count"></a><a class="addthis_button_tweet"></a><a class="addthis_counter addthis_pill_style"></a></div>]]></content:encoded>
			<wfw:commentRss>http://blog.hazrulnz.net/1455/webgoat-exploit-and-learn.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.975 seconds -->

