Wednesday, May 29, 2013

Penetration testing must be a part of the your web strategy because all it takes is one malicious attack....

If, like most people that grew up in the late 20th century, you are a Bill Watterson fanatic – Then you will surely remember getting a kick out of this (pun intended). http://bestofcalvinandhobbes.com/2011/10/a-swifty-kick-in-the-butt-is-for-sale/


While the humor in these is sufficient reward, many times you can draw on Bill’s caricatures for real life learning. In this case, I immediately associate it with any company that has an online presence but is not conducting periodic sweeps of its website to test its own vulnerability. Obviously “a kick in the butt” is not an academically precise comparison but it’s a start and maybe just what the doctor ordered. 

While CTO’s are aware of increasing vulnerabilities to their websites, they are content with the “I have never been hacked, so why should I care?” philosophy. To this line of thinking, I rebut with “All it takes is once”.

If you hold customer information, you have an obligation to be pro-active in plugging holes within your portal. If you lose client confidential information once, you lose much more than immediate revenue. You lose trust which will affect future streams of revenue. Negative publicity spreads way faster than compliments. The only reason this will not bother you is if you are a one-man tea stall on a lonely road with no ambition whatsoever to grow. In that case, may I ask what you’re doing online? 

While following standards in secure web design will get you most of the way there, smarter people will inevitably find a way around it. In comes “penetration testing”. HackVidhi’s super smart team of programmers are standing by to get their hands dirty by “ethically hacking” your website before malicious hackers get a chance to.  

Penetration testing is not typically a scripted model. There are no clear steps 1 and 2 and 3 to follow. It’s a skill that’s learned over multiple hours of reading, experimenting and …you got it, ethically hacking websites. To boot, you cannot be an ethical hacker without already being a web designer. Consequently, this team is already well versed with web design and can school your web design team on establishing best practices and check points for secure design. 

If this has somewhat caught your attention and you have another 2 minutes before those pop tarts pop in your microwave, go on to http://hackvidhi.com/PenTesting.php for a pictorial overview of our services and shoot us an email for a free first round of penetration test. You have no obligation to continue, you get a free report outlining the first couple of issues found (if any) and you now have a better idea of how your web design will hold up to intrusions. If you do see value in our services, we will contract with you for periodic penetration testing and function as an extension to your current development and test team. Our paid services can also serve as part of your audit needs to showcase that you are taking necessary steps to protect your private data and those of your clients.

If you have any questions or want to get started simply shoot us a quick email here - contactus@hackvidhi.com

Monday, May 13, 2013

In-house Penetration Testing vs Outsourced Penetration Testing



For the management of a company with online presence, web security is a big concern now a days. Pen-testing is a way of finding security loopholes in the website. From the management point of view, the biggest doubt about pen-testing is -


Shall we develop our in-house pen-testing team or shall we outsource the testing? Is it worth developing in-house pen-testing team?


We, HACKViDHI, strongly recommend you to outsource the pen-testing work instead of developing your own pen-testing team, following are couple of worth mentioning points explaining why you should choose outsourcing -



In-house Penetration Testing
Outsourced Penetration Testing
Frequency of full penetration testing cycle
Penetration testing is often not needed as frequently as functional testing. A simple bug fix might need a complete round of functional testing while the same big fix might not need a complete penetration testing cycle.
So having an in-house penetration testing team might be overkill as the penetration testing team will only be needed from time to time.

When it comes to outsourcing penetration testing, you will outsource it only when you will need it. This will lead to reduced cost estimates.
Penetration testing toolkit
Penetration testing involves using some automated tools along with manual efforts. In-house team needs to buy or develop all such tools or softwares in order to proceed. This means investing significant amount of time\cost in order to prepare penetration testing toolkit.
On the other hand if you are outsourcing it, the vendor company should already have the required toolkit. Since they will be reusing this kit for all their clients, they will charge you less than what you would have invested it to prepare the same kit.
This fact, again, will lead to reduced cost estimates for pen-testing.
Experience does matter
In-house penetration testing team will know only about the issues that have been found in previous releases of the website, they will not be having any idea about what other prevalent issues are going on in other websites as the team has limited exposure.
This can lead to ignoring some important vulnerability while giving extra attention to the vulnerabilities found in last release.
The vendor pen-testing company has exposure to lots of type of security issues as they have experience of testing different type of websites. So they have idea about the hot issues with latest tools and technologies.

This will lead to quality results with proper emphasis to proper type of issues.
Learning new attack dimensions - training cost
Penetration testing is a continuously emerging field as new threat vectors are being discovered each and every day. In-house penetration testing team needs to be aware of all advancements in the field of web-security; this means the team will need continuous trainings and learning resources. These trainings will require signification amount of investment.

Investing in trainings will be costly for the vendor company as well but they will be using the knowledge gained from those training for the benefit of multiple clients. So while giving cost estimation for pen-testing they will be splitting the training charges.
For you, this is again a cost saving fact.
 

If you are from an e-commerce domain, or are associated with online business in any manner, it is imperative to you to make sure that your business and your customers information is in safe hands. With HACKViDHi penetration testing services, you can find out the vulnerabilities of your online business and, using our consultation, can work towards fixing them up so that you can save your business and customers information from exposing.

To know more, contact us by e-mailing us to contactus@hackvidhi.com or visit our website for a free trial  at http://www.hackvidhi.com and we will get back to you. 



-Archana


Top Web Security Threats

Here is our presentation on top security threats in the field of web application development -

This presentation also talks about the impact on the website if any of those threats are exploited. The presentation does not cover technical details of the threats, it focuses more on business impact.


-Archana


Friday, April 19, 2013

e-ShopLifting: An Introduction


Dictionary defines shoplifting as “To steal merchandise from a store that is open for business”. E-shoplifting is the act of stealing articles/modifying pricing or similar fraud done by a malicious user (an e-shoplifter) from an online shopping store.

With advancement of technology and e-commerce, the online business has grown exponentially. Unfortunately, with same pace or has advanced the malware and attacks on the internet. E-Shoplifting is  majorly used to buy a product in a price lesser than mentioned in the website. It also refers to stealing the customer details such as his/her credit card number, which could further lead to much more than stealing from a particular shopping transaction.
The e-shopping works around four entities:
1. The online store - which lists the items for sale.
2.The customer - who intends to buy the items, adds them to his 
shopping cart and finally enters details to make the payment.
3. Payment Gateway - It receives from the online store, the payment details provided by the customer,  communicate to his bank, enables the money transaction and once transaction is done, sends an acknowledgement to the online store.
4. Bank - Bank verifies the information sent by the payment Gateway and completes the transaction.
In case of e-shoplifting, there comes one more entity:
5. The E-shoplifter aka hacker, who tampers the customer’s details before it reaches to the payment gateway.


Among various measures used by the online stores, most famous are,  sending checksum with other details to make sure the data is not tampered and verifying the amount debited in the acknowledgement from payment gateway. These measures are not enough and provide only limited security. The checksum used here can be calculated by the hacker and even if the store uses a private key, seeing the modern computer’s processing power, it is possible for the hacker to guess the key too. Furthermore, the verification of the bank acknowledgement also does not guarantee security, as the e-shoplifter who tampered all details being sent to bank can also change the amount in the acknowledgement to match it with his tampered version.


E-shoplifting may not be 100% avoided even with complex security measures but can be reduced to a great extent only by implementing and adopting few security best practices in the online store website and in e-shopping workflow.  


If you are from an e-commerce domain, or are associated with online business in any manner, it is imperative to you to make sure that your business and your customers information is in safe hands. With HACKViDHi penetration testing services, you can find out the vulnerabilities of your online business and using our consultation, can work towards fixing them up so that you can save your business and customers information from e-shoplifting. To know more, contact us by e-mailing us to contactus@hackvidhi.com or register to our website for a free trial at http://www.hackvidhi.com and we will get back to you.


Check our presentation on E-Shoplifting @ http://www.slideshare.net/hackvidhi/e-shoplifting-hackvidhi.

Friday, March 15, 2013

Login CSRF Prevention - White Paper

Here is our first very first white paper - "Login CSRF Prevention – A Proposal"

Here is the abstract -


Cross site request forgery stands at 8th position in OWASP top 10 list of 2013. CSRF exploits trust relationship between an authenticated user and the website which provided the authentication. This papers aims at providing basic introduction of CSRF and, its special type, login CSRF along with preventive measures that are commonly being used. This paper will also introduce a new proposal of Login CSRF defense mechanism, a mechanism which aims at addressing the shortcomings with currently used approaches. This proposal can also be used to prevent standard CSRF attacks, there are certain trade offs though.


Please download complete white paper from here - http://hackvidhi.com/WhitePapers.php.


Please do share your feedback and comments, we will be happy to hear you!


-Archana

Thursday, March 14, 2013

HACKViDHi Course in Web Programming and Ethical Hacking


Hello friends,

After a break from blogging, we are back to share some good news with all of you. This week, the HACKViDHi Course in Web Programming and Ethical Hacking has received more than 150 enrollments. We are looking forward to many more curious guys and gals getting benefited from this free course. Keep spreading the word.
http://www.hackvidhi.com/courses.php

See you all in summer !!

- Richa

CSRF - Using Secret Tokens is NOT enough!!

I recently came across a popular e-Commerce site; they are using Secret Tokens to avoid CSRF possibility; still they are vulnerable to CSRF!! Oddly enough, they are not doing it right.

Sending a random token is not enough, it is also necessary to keep track of what token has been sent with what request i.e. with a particular request what token is expected to come. 


This is approximate approach that they are using to protect their site -



  • they have a collections of valid CSRF tokens.
  • with each request they send one of the CSRF tokens from the repository.
  • when the request is submitted they check whether the returned token belongs to their collection of token, if yes, then they just allow the request!!

Its very easy to circumvent this approach, just get hold of any of their valid tokens and play it with any valid CSRF request; your CSRF request will go through. 

Amazed by their approach, I did some analysis on CSRF token trends for 50 Indian websites which include -
  • top 20 eCommerce websites 
  • top 10 travel domain websites 
  • top 10 Matrimonial websites
  • top 10 Job portal websites
The results came up with interesting statistics. I will be sharing those stats in my upcoming blog post.

Stay tuned!

-Archana

Wednesday, December 12, 2012

Customized Best Practices from HackVidhi




A web application developer must always follow a set of best practices to ensure that his/her web application is secure. If followed properly, the best practices can guarantee a good fight against the malicious content and attacks. Yet, most of the application lack these practices and are vulnerable to web threats. For few, the practices were not followed due to the lack of time, few others had the functionality limitation while others had just a negligent attitude towards the security. The reason could be anything, but if exploited to the core, the consequences could be damaging.
The basic best practices you must follow in your web application -

  • Parameterized Queries: If your application deals with SQL, always write parameterized queries or prepared statements. This can save your application from SQL injection. In other terms, it won't allow an attacker to change the dynamic queries.
  • Save sensitive data: If your application stores sensitive files such as customer information, always store such files outside of the webroot. And if your application has limitation which does not allow you to do so, explicitly make sure to secure them using encryption.
  • Check for buffer-overflow:  Always make sure that there is enough buffer so that the flow of your application could not get choked by any bad intent. An efficient memory management should always be a  must-consideration.
  • Proper error-handling: One of the common strategy used by hackers is to make your web application fail and get the information out of the error thrown on the browser. So make sure that your web application has a proper error-handling mechanism implemented in it which will prevent leakage of any core information even if it fails.
This list is not complete yet. We can add few more points here and the list would still be incomplete

At HackVidhi, we help you understand these practices better. Along with all of our security testing services, you can exploit free consultation to make your website or web application secure and  we will also provide you a set of customized best practices tailor-made for your application. We believe in not only providing our clients the best services but also enriching their knowledge in the area of web security.
- Richa

Sunday, December 2, 2012

99% of Top Indian Websites can be 'UI Redressed'!!


Today I performed some analysis on current usage trend of X-FRAME-OPTIONS in top 500 websites of India (I used the sites listed here); this analysis came out with interesting statistics;



  • ·         92% of the top Indian websites don’t use X-FRAME-OPTIONS at all.
  • ·         Here the worth noticing point is that most of the 18% sites which use X-FRAME-OPTIONS are not of Indian origin, Alexa doesn't take into account the origin factor in enlisting top sites for a country; it sorts the websites based on number of hits.
  • ·         This eventually leads to the fact that only 1% Indian sites are actually using X-FRAME-OPTIONS!!
  • ·         Out of rest 99% top web sites (of Indian origin), half of them are relying on different frame-busting scripts to avoid this threat; and I will explain later that why scripts are not full proof, as there exists at least one way to break each of these scripts.
  • ·         Rest half of those 99% are not using any techniques to avoid UI Redressing attacks!!
  • To my surprise I even saw one web site using some strange value for this X-FRAME-OPTIONS header - ‘GOFORIT’, this too in a relatively popular telecom website.




This makes me very curious about the security practices that Indian websites are following. Web security if one of those areas which should not be overlooked; it should be given the amount of attention it deserves.



<Here is A brief overview of UI Redressing Attack; I am not going deep as a lot of useful material is available on the internet for UI Redressing Attack.>

UI Redressing attack in its basic form can be visualized as –




So the attack lies in having user see a different interface but actually interact with an altogether different interface. For instance in the example above the user will think that he is claiming his gift but actually he might be transferring his funds to some other bank account (of course if his account is open in some other tab). The most common vehicle of delivering this threat is to use iframe. Attacker embeds the webpage he wants to attack in his iframe and makes it invisible while making his own content visible; when a genuine user performs some actions on attacker’s page, the user is actually performing actions on background page as well.
There exist various advance mechanisms using which an attacker can manipulate user’s input on his page and force to send selective input on the hidden page. I will be writing about these advance exploitation mechanisms in a different article probably.


Possible Impacts-
Attacker can cause user to perform certain actions which he will not perform consciously; example of such actions include transferring funds from his online bank account, cancelling orders that he placed on some e commerce site or changing delivery address corresponding to those orders etc; the list can be endless.

Safety measure that websites are using to avoid this attack: FRAME-BUSTING-
Most of the websites today are using frame-busting techniques to overcome this threat; frame-busting as the name indicates involves detecting whether the page is being loaded in a iframe and then bust this frame to come out!! Different scripts are being used to achieve frame-busting in different sites.

How FRAME-BUSTING techniques\scripts can be circumvented-
There is a paper published by couple of Stanford University Students which talks about how the frame-busting scripts can be broken; this paper explains that eventually a way exists to break almost each of the scripts that websites are using currently to implement frame- busting. 


Moving Towards HTTP Header: X-Frame-Options-
This is better solution in comparison to frame-busting scripts. This header restricts the possibility of being the page framed; this header can have three possible values;
DENY-
This option means the page can never be framed by any page, even not by a page with the same origin.

SAMEORIGIN -
This option means the page can be framed, but only by another page with the same origin.

Allow-From-
This option means the page can be framed, but only by the specified origin.



-Archana

Wednesday, November 28, 2012

Pen-Testing as a Service (pTaaS)

Today the most popular term in software industry is probably 'SaaS --> Software as a Service ; which basically means 'Software on Demand'. In SaaS model software is hosted on some remote place and customer can access it using a web browser or so. The main benefits of SaaS models include-
  • customer needs not to worry about hardware and maintenance requirements of the software 
  • and in most of the cases customer has to pay only for what he is using i.e. in case of DynamoDB customer has to pay only for the amount of data he is storing or retrieving.
These  two benefits made SaaS a quite popular concept. 

In the term SaaS, 'service' word is being used as figuratively i.e. its like outsourcing your software's infrastructure and maintenance needs. When I said pTaaS i.e. Pen-Testing as a Service, I meant it literally rather than figuratively; i.e. by pTaaS I meant outsourcing your penetration testing work. 

The biggest hurdle in outsourcing some XYZ service is the amount of information that needs to be exchanged between the client and service provider; if the information exchange involves sharing something confidential then probably that service XYZ cannot be outsourced. As penetration testing in itself is a form of black box testing so it can be easily outsourced as pen-tester hardly needs any implementation or even design information. 

Although some forms of pen-testing can be better categorized as gray or white box testing but that's  not actual pen-testing; this is what I feel at least. Pen-Testing is basically thinking from an attacker's or hacker's point of view and then probing a piece of software for security vulnerabilities. Lesser information (off course about the targeted software) a pen-tester has in the beginning of the pen-testing, more effective and more practical pen-testing results are going to be !! When someone knows the internal details of a product YYY then for him it is comparatively easy to figure out the issues with that product YYY. But the real art lies in starting with zero information and then ultimately figuring out a way to compromise the whole product; this is what our pen-testing services are all about. 

If you allow us to do this service for you, then;


  •  we will be doing a complete analysis of your website by exploring all possible issues because of  which your website can be compromised;
  • and finally we will be sharing a detailed report of how those issues can be exploited along with the suggestions to fix those issues.

PS: In my last post I promised to discuss about UI Redressing attack and usage statistics for 'X-FRAME-OPTIONS'; please excuse me for changing the topic today; I will be writing on that topic very soon.

-Archana

Monday, November 26, 2012

Creating Website for Dummies -DreamWeaver and GoDaddy - Amazing Combo !!

Disclaimer: If you are an expert web designer then this blog post is not for you :) ; this is meant only for Dummies like me who doesn't have even very basic knowledge of website creation concepts.

My core interest is in Testing (i.e. breaking things, complaining about problems, shouting here and there on why things are not working etc. etc. :D) ; I never thought about the amount of effort that is actually needed to get a simple thing like static website working. Seriously, finding issues in working things is lot lot lot lot more easier that actually get those things working.

I was searching for easy solution to create a website with static content; hosting server 'GoDaddy' I immediately finalized (based on my brother's recommendation) but I  was not sure about the tool to use for creating those static pages. While browsing internet I suddenly saw Dreamweaver which reminded me my college days. I used Dreamweaver little bit in college, but that was around 4-5 years before and I didn't remember a bit about what Dreamweaver was like at that time.

So based on that fact that at least name of Dreamweaver is looking familiar; I downloaded trail version from here (CS6). Luckily I found this link for a video on internet in which integration of Dreamweaver to FTP server of GoDaddy was explained; the Dreamweaver version that they are showing in the video is probably some older version, still it was not tough to figure out the same settings in CS6. With 3-4 lines of settings for remote server in Dreamweaver I was able to directly sync my content with the content on GoDaddy FTP server!! I am not going to explain minute details of those settings here as I believe Dreamweaver UI is very intuitive and using the video, for which I shared the link above, it is very easy to figure out exact steps.

Our website is still under construction but the easiness provided by Dreamweaver (at least in syncing the content)  is awesome!!.

Keep tuned for coming post on UI Redressing attack and usage statistics for 'X-FRAME-OPTIONS'  in reference to Indian websites.

-Archana

Saturday, November 24, 2012

HackVidhi - Story of Inception


A warm midnight of October this year, myself and Archana bumped into a discussion of how her random attempt of placing an order online for a commodity (and not actually completing the order) resulted in a successful order notification and she was left with an order placed worth Rs 17,000 of a commodity that she neither intended to buy nor had she paid for it!!
I have once placed an order that I wanted to modify later and was left with no other way of editing my order but to write to customer care using their “Post us” form. Not to say the perplexed I was heartlessly filling the form rapidly thinking over what I could post in this form to inform them about an alteration I needed to make in my order.  When I was done with posting my query I started thinking if there was a different brain thinking ‘what all’ could be posted on this form rather than just what could be posted on such forms.

There are spams floating all around offering products that mislead the consumers to online frauds.
These represent a much larger gamut of such experiences in an online customer’s day to day life that makes him rethink over the fidelity of online endeavors and the fatality of them if precautions are overruled. For all we know in an online world the thick layer of underlying security vulnerabilities exposed by high traffic web applications and numerous bare loopholes make a great motivation for a series of malicious brains making their way into the world of tremendous possibilities termed as hacking.


The question comes, are today’s online businesses have enough investment awareness to protect their systems from potential attacks or the red carpet laid to welcome their customers are eventually trafficking the hackers.

The mere thought process took us through a joy ride of much interesting discussion on how we can explore these possibilities and help online business hear the Ninja's nocks on their doors!
Result of our discussion was Hackvidhi - a simple and thoughtful initiative to provide quality assurance services for the magnitude of security vulnerabilities unleashed by millions of dollars worth insecure information travelling through trapped tunnels.
At HackVidhi and in this blog we will continually talk about

-          Most common Web App Security threats

-          Current Hacking trends and Math of Security Risks
-          Dynamics of site exposures and Threat Modeling
-          Preventive measures and our offerings
-          Penetration Testing : Raising the bars
-          Specialized service for Web Application Security

Look for our upcoming posts on Web Application Security hazards, making your Web App your secure home, Keys to your own doors of Assured and Secured success and a lot more.