Saturday, September 17, 2016

Introducing myself into EnCase v8

Since we finally get workable dongles I've started to get into v8 to see it, feel it myself and
find possible drawbacks.
Since experience with introduction of v7 there is no enough testing.

 There are already some very good comparative testing done with earlier versions and other forensic tools like this one
I'd like to try it on configurations have close and how different version influence each other, especially since there are issues with v7 and new v8 dongles.

I've noticed two things, on very low end configuration v8 gets about 25% improvement in case processing speed, what looks related to improvement in disk access. The other thing is that if you change dongle to v7 and start v7 it hangs if it was done after using v8, reboot helps . This is consistent with problems in version licencing differences.

At the moment I' using tdurden evidence file which comes with intro self trainign for v7. I'll post configurations and results later.
After playing with tdurden I'll go for new versions of EnCase training and try to see if all works as it should be. After that I'll go to try some NIST materials to see how that work too.

My first impressions are not very dramatic, it is interface polish with appearance change but again with some important issues missed, still no conditions in bookmark view and for some strange reason renaming records view into artifacts.

24th Sep. 2017
I forget to mention most of old scripts which works in recent v7 version also works in v8, shame for this is not true for regripper wrpapper.

Wednesday, August 31, 2016

Lack of talents in cybersecurity

"Lack of talents in cybersecurity", it was a title on one of the miriard articles and posts about current sorry state of  security in IT.  So at the moment there is shortage of people, in that branch but what are actually expertise, skills and capabilities, what problems have to be solved by this people and why they are called talents and most important why there is shortage ?

I don't think it was much reaserached but more seen as golden opportunity. Educational / training industry is mass producing certified experts, recruiters are recruting, experts are "experting" all around but somehow only one gaining results are attackers.

Actually there was one research here, recently among employers about IT sec. profession and IT security general, it turns out that virtually no employer see a need for such expertise or knowledge in next 10 years period.

Lets get back from local peculiarities to big picture.So there is a shortage of cybersecurity experts, without actually providing a definition what is a "cybersecuirty talent",  it's a bit fishy isn't it ?
And most of it how this new branch of experts will fit into existing systems ?

I should say it is a big failure of academic education and professional trainign since a huge amount of IT professionals are stamped out each year and somehow all this professionals are missing security awareness and skills.  It simply sounds silly if someone will hire programmer who does not know to write safe and reliable code but looks like this is a standard practice  Same for the syadmins or any other role in the big picture. What I like to stress is  ability to provide secure and reliable IT products and services, not to produce and use new branch of epxerts, It is like a game of adding people to project which is late, it will only slow it down and make  things worse.

You don't need to be rocket scientist or cybersecurity talent to know that if you enterprise is running on windows infrastructure you are in trouble. It is actually fixing a problem from inside of system, not from top with blessed talents. There is gaziolion of vendors, tools companies, almost miracle makers and not much more security and reliability. It is fun watching all this but somehow I'm expecting to see cyberplaque  (I can't resist to user Cy-word again) like old  black death plaque with real deaths before something change ...

Tuesday, August 2, 2016

TV CSI horrors anywhere

Recently while I spend some time on vacation I was forced to watch and listen, listen mostly,  some of horrible CSI-everywhere, Criminal Minds and such TV shows. TV producers are making a lot of money out of that misery, out of that science and law-enforcement exploitation TV programs.
If there is only a way to sue TV producers to get that profit into something useful like enhancing security and safety,   

Monday, July 25, 2016

Some thoughts about SWIFT banking incident

One of my recent gigs was result of  SWIFT banking incident in Bangladesh, Just to put thighs right I'm not expert on the malware analyses, my knowledge is related only to few online papers about incident  and chats with few law enforcement officers who were involved. My experience with SWIFT and banking is ancient one, last meddling was more than 10 years ago my last SWIFT system was installed on AIX machines.

Available resources in detail presents how attacked worked, high quality of attack code, results of investigations etc.. very much detailed from technical point. Since original incident  same attack was also done in fer other places.

What surprised me horribly was fact that SWIFT subsystem was implemented on windows machine,
I'm really curious why and how something so critical was put on windows and what was reasoning for that. Decision to use windows OS and SWIFT looks like disaster from any angle I can think of.  I really can't figure out what is a benefit of such solution. I really like to understand a) what was reason for SWIFT  to create windows version and b) what was the reason for bank to use windows version of SWIFT.

The scenario which comes to my mind is very much like one been explained to my why major forensic software vendors does not have UNIX versions. It is like our customers want us to use windows platform because this is the only platform they can efficiently use ... Basically it boils down to cutting expenses what is as we know from history a common cause of any horrible disaster
The reasoning chain behind this is very common among no-IT industries, where people do not understand their own business process, its critical dependency on IT and related risks. I'm quite confident we will see a lot of trouble of that type in future especially with "intelligent" devices and IOT (Internet of Things) expansion.

27.7.2016

So how can we rationally explain using swift on windows ? When you chat with people it comes out that the most common technical expertise is based on windows OS and MS based OS are majority in medium business and enterprise, so it means a huge base of people and low expenses. In the other hand UNIX based expertise is scare and not easy to find, sometimes it is even worse UNIX based systems and expertise are lot more expensive.  Using AIX machine for this purpose in completely windows based enterprise create small expensive island if you compare it only to production costs, but if you compare it to possible incident cost  it is quite cheap.  It is easy to prove, total breach was about 800 million dollars, while unrecoverd sum is about 80 millions, compared to 80 millions total costs of any AIX swift subsystem is invisible.
So we have here a rational chain of thought, decision based on available expertise, commonality of OS and not taking into account risks and its costs. Something to think about since this is not technical issues but organisational and managerial.

PS: I'm talking about AIX not because of IBM PR, but because my only SWIFT experience is with AIX. To be honest in my days I've seen few situations which were very deadly even for AIX/SWIFT combination but there was no breach.

1.8.2016
Very detailed report about bank interaction on Reuters site, worth of reading , The SWIFT hack How the New York Fed fumbled over the Bangladesh Bank cyber-heist

26.8.2016
I finally managed to chat about this story with friend and  coleagues. Different postions  and experiences from FIRST to banking regulatory.

1.9.2016
A new articles about new developments and new attacks.
When you think, for attacker it is best to have weak entry-point into system, like windows node, than to attack connection between bank and swift or bank IT. It is cheaper, since it is common point, in other hand each internal banking IT is a uniqe form of chaos ..

2.9.2016
From SANS newsbites

SWIFT Warns Member Banks of More Attacks
(August 31, 2016)
 
In February 2016, attackers stole US $81 million from Bangladesh Bank. In a letter to its clients earlier this week, global financial messaging system SWIFT disclosed that there have been more attacks, some successful, against member banks and urged them to adopt strong security measures.

Read more in:
-
 http://www.reuters.com

16.10.2016
Again From SANS newsbites, now everyone found that SWIFT systems are hackable

Odinaff Trojan Targets SWIFT System
(October 11, 2016)
 
Malware known as Odinaff is being used to target the SWIFT funds transfer system. Symantec says that roughly 100 organizations have been infected with Odinaff. The malware makes its way into systems by getting users to click on a malicious Microsoft office macro or password-protected RAR archive file.
Editor's Note

[William Hugh Murray]
Banks should use the indicators of compromise (IoCs) at https://www.symantec.com/security_response/writeup.jsp?docid=2016-083006-4847-99&tabid=2

Read more in:
- 
http://www.eweek.com: Odinaff Trojan Taking Aim at Financial Services
- http://www.theregister.co.uk: Second hacking group targets SWIFT-connected banks
- http://www.v3.co.uk: British banks targeted in new wave of Swift payments system attacks
- http://arstechnica.com: Emboldened by $1B Bangladesh hackers, new group targets SWIFT users
- http://www.computerworld.com: Second group of hackers found also targeting SWIFT users



19.12.2016 
There are more news about this story, looks like more incident happened and been "under-carpet-stored" interestingly not much fuss, Now it is normal that such "strong" organisation  fails with huge flop.. Banks, governments.. .. 
All this and yahoo breach story remembers me on old truth if you need action you must have a heap of dead bodies.

 7.3.2018
New stories about swift bank attacks about some banks in Russia. It is on the Sans news  bites. It show how a good investment pays off for a long time

Saturday, July 23, 2016

Probably a scam ...

A lot of connections coming trough this URL http://bit.ly/29ufKZW to this blog, It redirects to some fraud page somewhere far away ..  so be careful

Wednesday, July 6, 2016

Trying to get EnCase v8 ..

On the dreaded Guid portal  "Customer Community knowledge base" new version of EnCase is listed

Software


EnCase v8 - 8.01
EnCase v7 - 7.13
EnCase v6 - 6.19.7
Portable - 4.06.02
eDiscovery - 5.13
Endpoint- 5.13

But ... when you'll get only v7.12 when you try to download it ..

also customerservice@guidancesoftware.com. does not exist

KB is almost empty with one article about codemeter problems with v8


12. July 2016 today we just get announcement of v7.13 release, intead of 8 :)

It starts to be scary .. I suppose everyone is dead scared of version 8, Guid because of disaster with 7, customers because of getting something completely different and no one knows what from Guid.

It looks like a lost-lost situation

A than suddenly on completely unexpected account v8 arrived
looks like there is a v8.0.1 in wild

13. July 2016 v8 is not working with our edu dongles :)

It means no way to try and test trainign scenarios to see how it works. It is our practice for each release, since v7 get out into public, too see how trainign scenarios behave with new EnCase.
We always tried from EnCase Essentials,  Forensic 1 and Forensic 2 with some examples from Advanced Forensics training.  Encase essential is perfect since each dongle can open tdirden evidence file and customer can do test in environment.

2. August 2016

This morning we have announcement about v8 version of former EnCase Forensic I and EnCase Forensic II. Now there are new names:

EnCase Computer Forensics I is DF120-Foundations in Digital Forensics with EnCase Forensic.

EnCase Computer Forensics II is DF210-Building an Investigation with EnCase Forensic

What worries me my educational dongles are still not working with v8 and there is no official policy or announcement what and when this will happen. Looks like all training partners are in same trouble.

8.8.2016

looks like it is possible now to get a extension certificate for edu dongles, we will see if this will work
basically procedure is to contact customer support as ATP, send request for update with dongle id and order id.

20.8.2016

Still same, no version which can run on educational dongles

26.8.2016 

Finally organised and negotiated we will get a educational v8 dongles, our v7 dongles will get usual extension certificates for one year more, but we will get no NAS licence.
I feel tired it takes us as ATP almost a month to get v8.
As collateral looks like it is again possible to get demo versions of enterprise and related tools.
I am so tired and fed up of commercial forensic vendors and products
It is quite obvious why any attacker can wreck havoc ...

12.9.2016

Finally we get v8 dongles and it works !

20.10.2016 
There was announcement of new licencing server for integration of dongles or better to say NAS replacement with EnCase v7,14, instructions are extremely long and look complex, not a promising sign.