<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag exploits</title>
    <link>http://blog.clearnetsec.com/articles/tag/exploits</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>True penetration testing?</title>
      <description>&lt;p&gt;
This from the new 
&lt;a href="https://www.pcisecuritystandards.org/pdfs/infosupp_11_3_penetration_testing.pdf"&gt;PCI information supplement&lt;/a&gt;: (regarding the required annual penetration testing for compliance)
&lt;/p&gt;
&lt;img src="http://blog.clearnetsec.com/files/paperBag.jpg" align="right"&gt;
&lt;blockquote&gt;
The penetration tests should attempt to exploit vulnerabilities [&#8230;] attempting to penetrate both at the network level and key applications
&lt;/blockquote&gt;
&lt;p&gt;
Really?  I laughed when I read this, seriously.  It made me think for a second about how many consultants &lt;b&gt;&lt;i&gt;really&lt;/i&gt;&lt;/b&gt; have the skills to chef-boy-ar-dee exploits under pressure.  It&#8217;s clear too; this is not about a vulnerability sweep, they want you to bust in.
&lt;/p&gt;
&lt;blockquote&gt;
Penetration testing [..] should occur from both outside the network trying to come in (external testing) and from inside the network.
&lt;/blockquote&gt;
&lt;p&gt;
Wow.  &lt;b&gt;&lt;i&gt;True penetration testing&lt;/i&gt;&lt;/b&gt; from inside the network?  How many internal networks have you seen that would survive a blitzkrieg attack from a good penetration test team?      
&lt;/p&gt;
PCI states:
&lt;blockquote&gt;
&#8220;resources must be experienced penetration testers&#8221;
&lt;/blockquote&gt;
&lt;p&gt;
What does that mean?  
&lt;/p&gt;
&lt;p&gt;
I&#8217;m sure the PCI council is of compos mentis, and I&#8217;m not trying to rain on the PCI council or ASVs or QSAs, though it&#8217;s funny the council points out that &lt;i&gt;&#8220;The PCI DSS does not require that a QSA or ASV perform the penetration test&#8221;&lt;/i&gt;.  That statement wouldn&#8217;t be because most of them couldn&#8217;t penetration test there way out of a paper bag even if they were handed a loaded metasploit gun, right?    
&lt;/p&gt;
&lt;p&gt;
With the huge number of companies bemoaning PCI compliance, I just don&#8217;t see most getting a &lt;b&gt;&lt;i&gt;true&lt;/i&gt;&lt;/b&gt; penetration test.  I guess I could be reading too much into this.  Maybe the skills bar level I consider for experienced penetration testers is way higher than what the PCI council considers experienced or what others consider experienced or good?
&lt;/p&gt;
&lt;p&gt;
Do you have penetration testing skills?  What does that mean to you?  Do you think most of the companies that buy a penetration test actually get one?
&lt;/p&gt;

</description>
      <pubDate>Sun, 04 May 2008 22:45:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:470c8a22-8394-42f3-865f-16f2cea23a84</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/05/04/true-penetration-testing</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>vulnerability</category>
      <category>Penetration Testing</category>
      <category>PCI</category>
      <category>ASV</category>
      <category>exploits</category>
      <category>QSA</category>
    </item>
    <item>
      <title>The booming exploit market and bye bye to swaths of products</title>
      <description>&lt;p&gt;
There are lots of articles mentioning the &lt;a href="http://www.digitalarmaments.com/challenge200801566321.html"&gt;Digital Armaments bounty for exploits&lt;/a&gt;.  I wrote a &lt;a href="http://blog.clearnetsec.com/articles/2007/12/28/%E2%80%9Cbig-money-big-prizes-i-love-it-%E2%80%9D"&gt;snippet&lt;/a&gt; on the commercial exploit market about a month ago, whereby I was simply listing the prices for subscribing to the different exploit houses.
&lt;/p&gt;
&lt;p&gt;
I guess I forgot to consider another complexity of all this and that is from the influence the organizations who compete to purchase exploits are having (e.g.  iDefense, 3COM/TippingPoint, Governments, people and groups w/lots of money).  
&lt;/p&gt;
&lt;p&gt;
I wonder how extensive this really goes &#8211; I mean, it seems this market is in a boom of sorts which implies there are lots of private exploits trading hands.  Exactly how many would be interesting to know.  Hell, any numbers would be nice.    
&lt;/p&gt;
&lt;p&gt;
One thing is apparent though, if this market continues to grow then how can any security products based on &#8220;knowing attacks&#8221; succeed?  They won't.  An IDS vendor is not going to be able to afford to purchase all; no company will have a monopoly.  


</description>
      <pubDate>Thu, 31 Jan 2008 23:50:00 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:656fdeec-7440-4a99-94be-62030c0fa12e</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/01/31/the-booming-exploit-market-and-bye-bye-to-swaths-of-products</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>ids</category>
      <category>ips</category>
      <category>exploits</category>
      <category>vulnerabilities</category>
    </item>
    <item>
      <title>&#8220;Big money!  Big prizes!  I love it!&#8221;</title>
      <description>&lt;img src="http://blog.clearnetsec.com/files/smashtv1.jpg" align="right"&gt;
&lt;p&gt;&lt;a href="http://en.wikipedia.org/wiki/Smash_TV"&gt;Smash TV &lt;/a&gt;quotes.  Love &#8216;em.  
&lt;/p&gt;
&lt;p&gt;
Speaking of big money, the commercial exploit market&#8217;s growth isn&#8217;t making it any easier to bid on penetration test gigs.  If you want to provide the highest assurance you&#8217;re capable of to clients, then of course you would like to have your hands on all the exploits out there, both public and private.      
&lt;/p&gt;

&lt;table border="1"&gt;
  &lt;tr&gt;
    &lt;th&gt;product&lt;/th&gt;
    &lt;th&gt;to start&lt;/th&gt;
    &lt;th&gt;quarterly&lt;/th&gt;
    &lt;th&gt;total&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;&lt;a href="http://d2sec.com/products.htm"&gt;d2&lt;/a&gt;&lt;/td&gt;
    &lt;td&gt;$1,950&lt;/td&gt;
    &lt;td&gt;$850&lt;/td&gt;
    &lt;td&gt;$5,350&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;&lt;a href="http://gleg.net/vulndisco_prices.shtml"&gt;gleg&lt;/a&gt;&lt;/td&gt;
    &lt;td&gt;$1,400&lt;/td&gt;
    &lt;td&gt;$700&lt;/td&gt;
    &lt;td&gt;$4,200&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;&lt;a href="http://gleg.net/argeniss_pack.shtml"&gt;argeniss &lt;/a&gt;&lt;/td&gt;
    &lt;td&gt;$1,000&lt;/td&gt;
    &lt;td&gt;$500&lt;/td&gt;
    &lt;td&gt;$3,000&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td&gt;&lt;a href="http://www.immunitysec.com/products-canvas.shtml"&gt;canvas&lt;/a&gt;&lt;/td&gt;
    &lt;td&gt;$1,450&lt;/td&gt;
    &lt;td&gt;$730&lt;/td&gt;
    &lt;td&gt;$4,370&lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;br /&gt;
&lt;p&gt;
And the cr&#232;me of the crop:&lt;br /&gt;
&lt;b&gt;Immunity Sec&#8217;s Vulnerability Sharing Club	$50,000 - $100,000 per year&lt;/b&gt;
&lt;/p&gt;
&lt;p&gt;
Attacking with anything less in hand tends toward negligence, especially if you do so without disclosing what you&#8217;re missing.  Pay to have all and you&#8217;ve likely priced yourself out of competitive bids.  
&lt;/p&gt;
&lt;p&gt;
The winners here, again, are the attackers.      
&lt;/p&gt;
&lt;p&gt;
&#8220;Good Luck&#8230; you&#8217;ll need it!&#8221;
&lt;/p&gt;
&lt;img src="http://blog.clearnetsec.com/files/smashtv.jpg" align="left"&gt;
&lt;br /&gt;

</description>
      <pubDate>Fri, 28 Dec 2007 08:57:00 -0700</pubDate>
      <guid isPermaLink="false">urn:uuid:5b29bc79-91d9-4ca9-bf12-d9426ee719ee</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2007/12/28/%E2%80%9Cbig-money-big-prizes-i-love-it-%E2%80%9D</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>Penetration Testing</category>
      <category>gleg</category>
      <category>immunity</category>
      <category>argeniss</category>
      <category>d2</category>
      <category>exploits</category>
    </item>
  </channel>
</rss>
