HN user

IncludeSecurity

190 karma

Erik from www.IncludeSecurity.com

Posts0
Comments42
View on HN
No posts found.

SEEKING FREELANCER | Remote | 4-12 Hours/Week

IncludeSecurity (http://includesecurity.com ) works on security assessments of cutting edge and mass scale tech. We are looking for a freelance technical writer to join our existing team who performs editorial review of our security assessment reports. We have excellent style guides and the QA process is asynchronous so the hours are very flexible. Previous experience in the tech industry or tech-adjacent roles preferred.

You can see some of our public reports at https://pentestreports.com/reports/ (search for IncludeSecurity)

Email resume/interest to: careers atsign includesecurity dot com

Log4j RCE Found 5 years ago

After having worked on software security for 20yrs+ I can tell you first hand that it is a long-term losing game. Libs, frameworks, and SDKs are written to provide functionality and interop. The more functionality/interop they have then the more popular they become and the more vulns they have.

The only winning move is not to code!

....OR learn to live in a state of constant vulns and put guardrails in place so that you can avoid shooting yourself in the foot as much as possible. In this case strict ngress/egress firewall rules in prod would prevent this from ever being exploited from what I've read on the vuln thus far.

Hey HN, we're IncludeSec. We've done thousands of assessmnts for hundreds of clients and are well on our way to replacing all of the legacy lower-quality junior heavy appsec consulting teams doing work in Silicon valley and the rest of the US tech sector...and we're continuing to growing quickly! (but we wont get too big, we like smaller company vibes)

We're currently looking for these roles:

1) (US Only) An application security expert who isn't afraid of the management side of things to join our rapidly expanding team as a Managing Consultant perhaps you're a people manager, or don't mind talking to clients and can help our sales team out with the tech side of things?

2) (EU, South Am, North Am) An application security hacker who wants to hack on a ton of apps for small and big tech companies and even loves security research too perhaps! https://old.reddit.com/r/netsec/comments/mi5lrc/rnetsecs_q2_...

Looking forward to hearing from you HN!

-Erik Cabetas- Founder, IncludeSec

<my first name>@IncludeSecurity.com

http://blog.includesecurity.com

Hi OP, I'm Erik CEO of IncludeSec. We do many FOSS audits for Mozilla, OpenTechFund, etc. I can give you some ranges and points of consideration from what I'm seeing in the industry today.

First consideration point is quality of the team and the seniority of the people ACTUALLY DOING THE TESTING (a lot of pentest shops do bait and switch senior presenting but juniors do the actual work.)

Next consideration is location of company; EMEA and Asia are lower hourly rates than US teams.

Next consideration is scope. Do you want the front door checked, or the entire house inside and out? In this case Cure53 spent 25 work days on this asmt, which gives quite a lot of time to analyze the software and check lots of different avenues of attack.

Next consideration is type of attacks to try and security assessment methodology. Do you want just fuzzing? Perhaps you can get that for free from Google's OSS-Fuzz, they will sponsor people to set up your FOSS app with their fuzzer via CI/CD. Do you want static analysis from some big COTS vendor like coverity/fortify/checkmarx/etc. that could be useful and they often have discounted/free scans they will do for FOSS. Or perhaps you want super smart hacker pentesters to code review and dynamically attack your app (that's what my team does)

Next consideration is publicity, do you want this reporting public? Some charge extra for that.

There's a million other thing to consider when hiring a pentester, but this message is already too long. To give you a ballpark, estimate $10k to $40k for small projects, $40k to $80k for medium sized projects, and $80k to $150k for large projects. YMMV of course, but those ranges and the consideration points should get you well on your way.

Hit us up if you need more tips, happy to help via email <myfirstname>@includesecurity.com

IncludeSec | app assessment/pentest | full-time | REMOTE World-wide||US Only (depends on role)

Hey HN, we're IncludeSec. We're well on our way to replacing all of the legacy lower-quality junior heavy appsec consulting teams doing work in Silicon valley and the rest of the US tech sector...and we're continuing to growing quickly! (but we'll never get too big, we like smaller company vibes)

We're currently looking for three roles:

1) (US Only) An application security expert who isn't afraid of the management side of things to join our rapidly expanding team as a Managing Consultant (4th MC on our team.) https://www.linkedin.com/jobs/view/2659055090/

2) (EU, South Am, North Am) An application hacker who wants to hack on a ton of apps for small and big tech companies and even loves security research too perhaps!

3) (US Only) Staff or Senior Technical Project Manager https://www.linkedin.com/jobs/view/2698925433/

Looking forward to hearing from you HN!

-Erik Cabetas- Founder, IncludeSec

Google is one of only a handful of companies in this world that can fundamentally change the state of security in the tech industry. I love google and have many friends who work there, I truly believe in their mission. They have the talent and the financial resources, but sometimes they do not use those in ways that are strategically scalable IMHO.

Here's some examples of ways they could use $100MM to completely flip the script on app security:

1) Google project zero - Some of the absolute best hackers in the entire world work on this team, they identify and exploit vulnerabilities at the same skill level of the best nation states. None of this significantly moves the needle. If they took this team, expanded it's skill-set, and redirected their efforts towards building protections for compilers, runtimes and framework then that would be much more impactful then showing off the next <ubiquitous software> 0day.

2) Google's partner program - Google has a program that forces all integrators of their OAuth APIs from Gmail to Gdrive to have 3rd party security assessments conducted. The 3rd parties they use put their most junior/scanner focused pentesters on those projects. The approved 3rd party vendors turn this into a cash cow because they hire kids straight out of school and bill them out at senior rates because the API integration partners are forced to use these junior teams. Instead they could create a register of ALL pentest companies and stop the SF/SV practice of secret lists and publish all data about security assessment/pentest firms and to prioritize the effective firms, not the junior firms.

3) Google could create zero trust FOSS software for all corporations. Zero trust is a hot topic, every COTS vendor now caters to the key buzz word. Often the COTS solutions are low quality trying to make bank off a trend. Google is in the unique position of advancing the state of Zero trust world-wide by FOSS releasing zero trust and allowing all corporations in the world to jump a light year in corp-sec.

4) Advancing the state of systems programing - I love C it was my second programming language and the one I first fell in love with, I won DEFCON CTF writing exploits for C code. All of that being said, there is almost no need at all for C in 2021. For almost all cases I can use Go, Rust, or something else memory safe instead of C. Google should move from using C for most programs and advance the state of Go and Rust via SAST tooling and security rules. Yes this includes Android, Android should support non-C code such as Rust in the kernel just like Linux is currently doing.

5) Align with security best practices on all OSes and desktop apps - MS is doing some amazing experiments with high-security to make their browser extremely secure, google should have been doing the same with Chrome for the past 10yrs https://microsoftedge.github.io/edgevr/posts/Super-Duper-Sec... I know the usability/memory trade offs being made here to keep the browser performant, I still think there is more that can be done here with genius tech/sec innovators that google has.

6) OpenSSF should create an alliance to fundamentally eliminate XSS and CSRF - Google is a huge sponsor (primary I think?) of OpenSSF. That org can create an alliance with all of the top web app frameworks (Django, Rails, Flask, Gorilla, Spring, ASPMVC, etc.) for an operating mode which fundamentally uses all of the new web app security hotness (CORS, CORP, CORB, COOP, COEP, CSP, site security, etc.) to absolutely eliminate all XSS and CSRF possibilities at the webapp framework level and SQLi at the ORM level for all notable webapp frameworks. This would set a precedence across the industry.

7) ...I'm gonna stop there, I can go on forever. These are things I think about a lot being in the hacking industry 20yrs+ I'm often dreaming of "If I just had $5MM in funding I could solve so many security problems!!", but the only currently feasible way to get that funding is to use it to create a commercially viable product. Google's pledge to fund cyber security in an altruistic manner changes the game.

Google, we love you! Help us secure the Internet, you've got the power to totally change the game...we hope you do! :)

-Erik- Founder, IncludeSec

IncludeSec | appsec/pentest managing consultant | full-time | REMOTE US ONLY

Hey HN, we're IncludeSec. We're replacing all of the legacy lower-quality junior heavy appsec consulting out there in the world and are growing quickly!

We're currently looking for an application security expert who isn't afraid of the management side of things to join our rapidly expanding team as a Managing Consultant (4th MC on our team.)

Come join a 60+ all-senior/expert only hacking team where hackers can do their best work: https://www.linkedin.com/jobs/view/2659055090/

-Erik Cabetas- Founder, IncludeSec

Enough is enough 5 years ago

I'd guess that those same presidents will call them up and buy. They'd rather be a customer than try and change a behemoth with political power like these guys.

We do security audits for a living.

In a nut shell, here's why things are so screwed up IMHO:

1) Most of these companies have had audits, but they're being done by 3rd rate or very inexperienced external consultants.

2) The companies limit the scope of the tests. Real hackers don't give a shit about your scope of work, they have no rules, only goals.

3) Even when a test is properly done the exec management looks for silver bullet product solutions instead of changing across people/process/technology

My company solves #1, but we can't do anything about #2 or #3 :-/

Include Security | Senior Security Assessment Research Consultants | Remote | Full-time |

https://www.includesecurity.com twitter.com/IncludeSecurity

  * You're a dev, but have always been really good at hacking apps and would like a change of pace.

  * Or perhaps you already do app hacking in your day job are sick of the bureaucracy and want a better working environment with more interesting clients/projects and paid research time.

  * We started in 2011 and now have 200+ client served including start-ups you've heard of and big tech you use, 31+ languages assessed.
If the above piques your interest you can read our full posting on /r/netsec https://old.reddit.com/r/netsec/comments/mi5lrc/rnetsecs_q2_...
GitHub Copilot 5 years ago

It says it's trained on "billions of lines of code"

I would augment that to "billions of lines of code that may or may not be safe and secure"

If they could tie in CodeQL into Copilot to ensure the training set only came from code with no known security concerns, that would be a big improvement.

CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks.

Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise.

If I had a static environment with no new software or business processes, then NO PROBLEM. I can lock it down in every kinda way and it stays locked down to a known baseline.

Add to that new biz processes and now I have interconnection internally and externally which make detection and prevention difficult. Things are much more difficult now.

Add to that new software, ever changing dev env, OS updates, firmware updates, software version updates, dev env dependency updates, now you're talking near impossible to keep up.

And that's the state we're in today. There are some generic mostly effective controls that if implemented correctly can stop most advanced attackers (the so called "20 security controls") https://www.yumpu.com/en/document/read/6582321/20-critical-s...

But even in spite of that, any major nation state had an arsenal of "capabilities" that allow them to dominate most cyber warfare area of operations in the civilian sector. US can do it, UK, Israel, China, Russia, probably even India and others!

Against nation states, there is no stopping nation states in the civ sector, despite what every F500 company's CSO wants you to believe.....sad but true.

On the security assessment side of tech we face similar problems that these types of awesome dev tools could help us solve.

Our clients either: 1) Have no docs (48%) 2) Have outdated/incorrect docs (48%) 3) Have correct and updated docs (2%)

Tools to understand source code/app architecture and increase understanding would make application security easier since there would be less incorrect assumptions and those doing security assessments would be much more effective and efficient in their work.

Having been in this silly industry of hacking for 20yrs, I really wish publishing negative results became more normalized. There are orders of magnitude more unpublished info regarding stories of not finding vulns there are about finding vulns. It just goes to show how much the industry really is flashy/stunt hacking.

p.s. Samuel who published the research OP posted is one of the best hackers I've ever met, he helped me code our interview challenge test that we still use (it's that good!)

Idea and driving force to make this product reality was Kevin Poulsen, Aaron Swartz did most of the code on the MVP, and James Dolan did most of the security/documentation/evangelism work.

Aaron and James are no longer with us.

Source: I was there to help out a small bit at the start with white-boarding security architecture ideas from the start, etc.

Having worked with all of the founders of SecureDrop (Aaron, James, and Kevin) to audit the alpha version it was tough to see Aaron go. Also super sad that we lost James a couple of years later too https://en.wikipedia.org/wiki/James_Dolan_(computer_security...

Cheers to everybody out there working on Internet freedom software. Thank you all for everything you do, next time you're at FOSDEM or browsing around some issues on github for your fav secure comms projects, let them know they are appreciated and they aren't doing this difficult work in a vacuum.

My .02 -Erik Cabetas-

Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity

  * You're a dev, but have always been really good at hacking apps and would like a change.

  * Or perhaps you already do app hacking in your day job are sick of the bureaucracy and want a better working environment with more interesting clients/projects and paid research time.

  * Starting in 2011, 200+ client served, start-ups you've heard of, big tech you use, 29 languages assessed.
If the above piques your interest you can read our full posting on /r/netsec https://old.reddit.com/r/netsec/comments/eo3wgn/rnetsecs_q1_...

This is a great FOSS tool if you don't want to deal with all of the low level stuff. https://github.com/StreisandEffect/streisand

We did an audit of it and they fixed lots of configuration problems, it's now pretty solid security defaults wise. And the WG integration works well.

They support the following setups: OpenSSH Tinyproxy OpenConnect / Cisco AnyConnect Stunnel Shadowsocks Obfsproxy WireGuard,

Running on: Amazon Web Services (AWS) Microsoft Azure Digital Ocean Google Compute Engine (GCE) Linode Rackspace

Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity

* You're a dev, but have always been really good at hacking apps and would like a change. * Or perhaps you already do this in your day job and want a better working environment with more interesting clients and paid research time. * Starting in 2011, 200+ client served, start-ups you've heard of, big tech you use, 29 languages assessed.

If the above piques your interest you can read our full posting on /r/netsec https://old.reddit.com/r/netsec/comments/eo3wgn/rnetsecs_q1_...

This sort of thing happens even for high-end pentesting. Here is the same assessment done by four decent consulting companies. They all found risks that the other companies missed.

https://ostif.org/four-audits-of-randomx-for-monero-and-arwe...

This is what I'm giving to clients who have unreasonable expectation that all vulns should be found during an assessment. The usually "time boxed" nature of this sort of work does allows for 1.5 sigma when many companies always expect 3 sigma coverage.

Hi hi! Speaking as both a bug bounty vet, and a consulting vet (I run includesecurity.com), here's my .02 on some things you may not have considered given your comment.

1) Sam and the other hackers did not do this as a full time gig, they primarily do this as moonlighting from their full time jobs (you can verify this on LinkedIn)

2) Consultants are often given tight scopes, and these artificial client-driven constraints often prevent consultants from identifying similar findings as Sam and crew found.

3) Bug bounties provide no defined level of assurance. They found an SSRF, but it is a very real possibility that somebody in their crew (or an individual bug hunter) doesn't have experience in that particular topic and Apple would have never been the wiser. In a bug bounty you're at the whim of the crowd's varying skills and interests. You can game this by offering larger bounties, but you can't pre-define a scope or level of assurance.

4) They've gotten paid ~$50k thus far for four bugs, if you read the article they mention they'll very likely be getting paid more. I'd be surprised if their total payout isn't six figures when all is said and done.

5) Your stated rate for consulting firms charge for a particular role is correct for the US market, but the level of "seniority" in a senior consultant varies wildly. Many large firms will undeservedly give somebody with two years experience the title "senior", regardless of actual skillset.

6) You state "a group of amateurs will do better work", first point is to note these five are not amateurs in any way! They're in the top 1% of global bug bounty hackers. Second it seems like you're defining "better" as "finds more vulnerabilities from a blackbox bug bounty perspective". I find that client's IRL don't define things in the same way you've done here.

7) "but over the years I've found that the difference in the security world is that you hire a small shop to discover the truth about risks, but you pay a big firm to lie about them." This I couldn't agree with you more on, it is MIND BOGGLING to me that firms with no ethics, actual standards, or transparency are the top firms in the security assessment/pentesting space. For an industry that proports to hate snake oil security, we sure are comfortable with a ton of snake oil security assessments.

8) This industry needs standards, for-profit old boys clubs are not the way https://www.theregister.com/2020/08/11/ncc_group_crest_cheat... And the grass roots/non-profit approach also failed due to lack of advocacy, adoption, and persistent leadership. http://www.pentest-standard.org/index.php/Main_Page

I'd love to see a world where Bug Bounties and full security assessments can live harmoniously and people do flip out declaring one or the other service totally useless all the damn time.

Calibre 5.0 6 years ago

The main developer of Calibre has had a long history of arrogant statements like that. Most famously illustrated in this bug report thread https://bugs.launchpad.net/calibre/+bug/885027

It's like...how many times do security researchers have to exploit your code (and your many "fixes") before you change your program's mounting architecture?

I read this bug report when I want to feel something.

Many mobile apps rely on shared components/libs/frameworks that are either developed by the company or are FOSS (libpl_droidsonroids_gif for example). In either case...they are platform agnostic and usually written in C. And as we all know C is full of memory handling problems like overflows.

Hopefully in 2020 and beyond people will be developing these shared components in Rust instead.