HN user

raffi

1,952 karma
Posts65
Comments347
View on HN
blog.strategiccyber.com 12y ago

User Account Control – What Penetration Testers Should Know

raffi
2pts0
blog.strategiccyber.com 12y ago

Man-in-the-Browser Session Stealing

raffi
2pts0
blog.strategiccyber.com 12y ago

I was most productive--when I was unemployed

raffi
1pts2
www.youtube.com 12y ago

Tradecraft - Free Red Team (Hacking) Operations Course

raffi
1pts0
blog.strategiccyber.com 12y ago

The ACE Problem Solving Method (I use this)

raffi
1pts0
blog.strategiccyber.com 12y ago

Email Delivery - What Penetration Testers Should Know

raffi
3pts0
www.youtube.com 12y ago

Browser Pivoting (FU2FA)

raffi
1pts1
blog.strategiccyber.com 12y ago

Browser Pivoting (A way to get past two-factor auth)

raffi
1pts0
blog.strategiccyber.com 12y ago

How to crack my software and add a back door

raffi
177pts55
blog.strategiccyber.com 12y ago

How to Inject Shellcode from Java

raffi
1pts0
blog.strategiccyber.com 12y ago

Phishing System Profiles without Phone Calls

raffi
1pts0
blog.strategiccyber.com 12y ago

Why is notepad.exe connecting to the internet?

raffi
4pts0
blog.strategiccyber.com 13y ago

Hacking through a Straw (Pivoting over DNS)

raffi
1pts0
blog.strategiccyber.com 13y ago

Staged Payloads - What Pen Testers Should Know

raffi
3pts0
blog.strategiccyber.com 13y ago

That'll never work--we don't allow port 53 out

raffi
2pts0
blog.strategiccyber.com 13y ago

DNS Command and Control Added to Cobalt Strike

raffi
1pts0
blog.strategiccyber.com 13y ago

Goading Around Firewalls

raffi
1pts0
blog.strategiccyber.com 13y ago

Western Regional CCDC - A Red Team Perspective

raffi
1pts0
blog.strategiccyber.com 13y ago

A Vision for Distributed Red Team Operations

raffi
1pts0
blog.strategiccyber.com 13y ago

Getting Started with Armitage and the Metasploit Framework (2013)

raffi
1pts1
blog.strategiccyber.com 13y ago

Tactics to Hack an Enterprise Network

raffi
3pts1
blog.strategiccyber.com 13y ago

How to Milk a Computer Science Education for Offensive Security Skills

raffi
7pts0
blog.strategiccyber.com 13y ago

Offense in Depth

raffi
2pts0
www.advancedpentest.com 13y ago

Beacon - Covert C2 for Penetration Testers

raffi
1pts0
blog.strategiccyber.com 13y ago

Go Down the Stack Young Man – Story of a (Network Performance) Bug

raffi
7pts0
blog.strategiccyber.com 13y ago

I lost my voice before speaking to 1,000 people at DEFCON

raffi
2pts1
www.advancedpentest.com 14y ago

Show HN: Advanced Penetration Testing Software

raffi
5pts0
rsmudge.wordpress.com 14y ago

DARPA's Cyber Fast Track: How to get your security idea funded

raffi
15pts5
io9.com 15y ago

The Greek engineer who invented the steam engine 2,000 years ago

raffi
5pts0
www.fastandeasyhacking.com 15y ago

Cyber Attack Management for Metasploit - Meet Armitage

raffi
20pts1

I took the Computer Security and Internet Security courses from Professor Du at Syracuse University, years ago. Both courses had end projects that required extending a kernel and userspace to implement security functionality.

At that time, we had the option to work with MINIX. Here are the MINIX Role-based Access Control and Firewall Labs:

https://web.ecs.syr.edu/~wedu/seed/Labs_12.04/System/RBAC_Ca... https://web.ecs.syr.edu/~wedu/seed/Labs_12.04/Networking/Fir...

Professor Du's materials are also packaged for self-learners and other teachers to use, as the open source SEED project. A few of the current SEED projects are implementation-exercises similar to the above two labs.

https://seedsecuritylabs.org/

I highly recommend the above resources.

I'm going to assume you're interested in network penetration testing in large traditional-IT enterprises:

It's very common for folks to enter the security testing field mid-career with a background in something else. This is almost preferable. The domain knowledge you have from your other experiences will serve you well when trying to understand [and find] security issues in related areas.

1. A potential path forward: Don't try to sell yourself as a penetration tester. Sell yourself as a developer who can support penetration testers/red teamers.

Modern ethical hacking requires a lot of coding to write new tools and customize existing ones. Even if you don't know much about how to get domain admin, escalate privileges, etc.--you can provide a lot of value just by the ability to ferret through MSDN and turn around C or .NET code that reproduces someone else's research or techniques for a team's internal use.

Rewriting existing stuff is really important as a lot of defenses are developed and tuned to public POCs or samples without much imagination for how the technique can vary with a little effort.

2. The Red Team Ops and Adversary Simulation community has a great culture of open research and code. Contribute to an existing project or start your own collection of interesting stuff to demonstate you have the chops to contribute as a developer.

3. If you're looking for the right "foot in the door" qualification, get the Offensive Security Certified Professional (OSCP) certification. It's hands-on and very well respected by the practitioners in this field. While the course will not turn you into a penetration tester, it demonstrates you can tackle the types of technical problems and concepts required to succeed in this work.

https://www.offensive-security.com/

4. Daniel Duggan's Red Team Ops course is good exposure to the concepts and workflows a lot of red teamers/penetration testers work with today:

https://www.zeropointsecurity.co.uk/red-team-ops

When I was in high school and early on in college--I didn't enjoy math. I always thought of math as the drone of memorizing formulas and plug+chug.

I later took a class that used a textbook, Laboratories in Mathematical Experimentation. The book and that class were the first time math became play for me. A big part of that class was digging into graph theory.

Really fun stuff.

I launched Feedback Army on HN in 2008. It's consistently paid my part of my Washington, DC rent for years. I gave some details about how I marketed it on its blog and in the side projects book someone put together awhile ago. Sadly, I can't find a link to the side projects book or I'd post it here.

http://blog.feedbackarmy.com/

I owe a lot to Feedback Army. It was the first thing I made where I made money without putting an hourly value on a unit of my time. I learned to think of my business as a system for fulfilling what I promised and collecting money from customers. This side project was a great way to cut my teeth on some business and service fundamentals.

I am a one-man shop and sell software in the enterprise space. I also have competitors and while I see my product as very different, a lot of my work goes into educating my market about why.

Most of my customers are household names and they're not averse to dealing with my one-man shop. It doesn't even come up. Their staff wants my software and they work their process to buy it. That's it.

I have not had to answer any of these objections (thankfully). I'd probably pass on the customer if they came up.

Re: CS Secret Handshake--years ago, I found the Programming Interviews Exposed book. I own the first edition. It's a lot of concise explanations of different Computer Science topics. The authors focus on things that are likely to come up in an interview. The book provides a few tricks and an orientation to topics that are worth looking at further.

I've lived in DC for nearly five years and I run a software company here. Here are my thoughts:

1. The quality of life here is very high. I believe this is probably one of the best places in the US for young professionals (its reputation hasn't caught up with it yet).

* We have a strong bike sharing program and decent biking infrastructure. I'm not a biker and I use this most days now.

* I recently got rid of my car. I simply didn't need it. I can walk in four directions to neighborhoods with great restaurants. I also have several grocery stores within walking distance.

* The North West part of the city is very clean.

* I don't own a car. So long as I live here--I will not need a car.

* When I want to go running, Rock Creek Park is nearby. Same for the National Mall. If I want to go Kayaking on the Potomac, it's a longer walk, but I can hit a Dept. of Parks and Recreation boathouse and get a kayak.

* DC has a short-ish winter. We get one and it gets cold. Some days we get snow the city doesn't know what to do with. Overall though, January and February are the worst of it. Sometimes we get hints of Spring in March. April, Spring is usually here full bore. Spring and Fall here are beautiful. I'm from MI and I lived in Syracuse, NY. I judge weather through this lens.

2. DC is very expensive. I incorporated in DC and I suspect the city took a cue from the Spanish government in terms of forms and prerequisite forms and licenses one must acquire to start a business. They claim they're pro-startup. I don't see it. I just see a bureaucracy that nickels and dimes small businesses. Taxes are high too.

3. For my sector (cyber security) and the types of customers I have; DC is the perfect home base. I'm close to my customers and potential strategic partners. We even have a cyber security related accelerator in Northern Virginia. I see the concentration of folks and businesses in my industry as a big plus.

4. I travel a lot for my business. If I need to go to NYC--I take the Accela and I'm there in three hours. If I need to get into the suburbs of MD, I use the MARC train. If I need to fly, I have three airports to choose from. The closest airport (Reagan) is a 15-20 minute cab ride.

5. We have had a massive growth of startup and coworking spaces in the past two years. I don't know where they all came from--but it's insane. If you're looking for semi-affordable office space co-located around other startups--you'll find something here, probably walking distance from where you live.

6. DC benefits from a flood of ambitious folks who want to change the world and start their career here. When I moved here, I expected a scene of lawyers, lobbyists, politicians, and their hanger-ons. It's not like that at all here. This is a very ambitious city with people who work very hard to make things happen. I like its energy and this is probably where I will stay.

SPF only checks the message envelope. His target's email provider may not correlate the MAIL FROM statement in the envelope with the From header inside of the message content. Some large webmail providers will use this mismatch as a cue to send a file to the spam folder.

Delivering a targeted phish requires situational awareness, but it's quite feasible to pull off something convincing.

http://blog.strategiccyber.com/2013/10/03/email-delivery-wha...

I run a business selling penetration testing software that I develop. It's completely bootstrapped. I do very little services work (I actively send this type of stuff to friend's companies). Right now, it's just me, although that's probably going to change. By most of my own definitions and the one you posted here... it's successful.

How did I get started on this? Sort of by accident.

I was working for Automattic after an acqui-hire thing. After a year there, I found that I missed working in security. I found a full-scope penetration testing gig three blocks from my apartment.

In my spare time, I started to tinker with a few ideas and released them as an open source project. Said project saw a lot of interest within the hacker community very quickly. I didn't expect this. Folks formed an opinion on it pretty quickly. Some people hate it. Others love it. Of those who know it, very few are in-between.

I left my pen testing job with a decent amount of money saved up. I didn't know exactly what I would go and do afterwards. I spent some time tinkering with Android, just for giggles.

I was very reluctant to start a business that used my "successful?" open source project. Partially because it leverages another open source project owned by another company.

I was at a conference in 2011 and someone from a US government agency asked if I was selling anything. I said no. He said that was too bad, because he had end of year money, and he liked my open source stuff. It was then that I decided to look at expanding my open source kit into a commercial product.

April will mark the two year anniversary of my first customer. My customers are well known organizations and they trust my software to assess how well they protect their networks. I'm constantly in awe of this.

Value gets us paid.

Working as an engineer, I'd probably pull a similar salary between a company like Apple or a high-end consulting firm. The profit per employee between these firms is drastically different though. We're not paid in proportion to the value we generate. We're paid in terms of market forces with a slight bump if our company especially values us. We don't see the upside of our efforts, the companies we work for do.

I work in the security industry. Quite a few folks in this industry will quit their job to just go learn. They then jump back into a job once they get the skills they wanted. They do it out of passion for the work. I've made a sustainable business model out of my work. I don't talk to that piece, but I try to reflect on why I (and my friends who take a hiatus) are more productive when we're free of a normal workplace.

On HN, we're well acquainted with the benefits of working on our own. In the security industry, this isn't a common mindset yet.

A browser pivot is a way to inherit a user's identity by forcing their browser to fulfill requests for an attacker. This attack gets cookies, session cookies, HTTP authentication, and even SSL sessions authenticated with a client SSL cert.

(1) Social engineering is a key component of several high profile intrusions that happen today. The best way to help an organization understand their ability to detect, mitigate, and/or contain this type of attack is to do it.

https://www.google.com/#q=phishing&tbm=nws

(1a) Statements, such as "it requires social engineering" [it's not a valid vector] represent a dated understanding of hacker tactics and part of my work is to help folks with your view move their understanding forward. Usually the conversation is not a response to an adversarial comment like yours.

Here are a few talks/papers that I recommend:

http://blog.strategiccyber.com/2012/12/19/hacking-like-apt/

(2) Cobalt Strike builds on something called the Metasploit Framework. The Metasploit Framework is the largest open source collection of safe exploits. My product addresses gaps in this kit for executing attacks that mimic those high profile intrusions mentioned a moment ago. A successful operation requires more than an email with something bad attached.

http://blog.strategiccyber.com/2013/01/14/tactics-to-hack-an...

(2a) Cobalt Strike's open source little sister is Armitage. A popular user interface and collaboration tool for the aforementioned "better and powerful and safer open source alternative to run exploits". I'm the developer of Armitage as well.

http://www.fastandeasyhacking.com/

I'll answer to unzip. In the post, I'm using a Linux distribution called Kali Linux. Kali is the successor to BackTrack Linux. Most people who use my software, use it with Kali Linux.

Kali is a distribution with a focus on offensive security. Most tools require root to run. It's very rare to find a Kali user who uses sudo and works from a non-root account. root for all actions is normal.

Some people may use Kali day to day, but it's built to do a job.

http://www.kali.org/

I didn't call out Kali specifically, but all of my screenshots show Kali's default window manager theme. I don't know if my audience earns the "hacker" badge by your standards... but I suspect most of them recognize Kali from a distance.

I look at this as knowing my audience. I sell software for penetration tests and red team assessments (e.g., to hack into stuff; not check a box). The people who use my software easily have the skill set to do what I wrote about and defeat any anti-piracy measure I come up with. What to do? I think it's best to be very customer friendly, trust my audience, and make light of the 1337 cr4x0r who thinks they won a game I won't bother to play.

@valleyer: He "signed up" for a trial and emailed me for help. But, when he asked for help, he provided the tar command he typed and the output of the tar command.

He changed the tar command he typed to make it look like he was trying to install my trial.

The output of tar told a different story though. The cracked trial was distributed as a .tgz with a space in it. Because this guy didn't know to put quotes around the filename, tar gave him an error he didn't know how to interpret.

He left the output untouched, and I was able to determine the name of the file he was trying to extract, google it, and strongly conclude he was asking for support for a cracked version of my software.

I read shadowOfShadow's comment the same way you do. (for others reading this): in the comments section, I reproduce an exchange (anonymized, of course) I had with someone complaining about my support--when they were trying to install a cracked version of my software. This exchange is what led to the blog post linked here.

My startup creates software for use in penetration tests and red team assessments. I distribute backdoors and I'm quite aware of it. :)

I wrote this post to show how to use my software to backdoor a pirated copy of my software.

After I wrote that blog post, I also added the ability to tunnel traffic through Beacon when its checking in several times each second. Recently, I added the ability for it to download a large file, a piece at a time, with each checkin. The size of the piece depends on the data channel (DNS vs. HTTP). It's all encrypted too.

- http://blog.strategiccyber.com/2013/06/20/thatll-never-work-...

- http://blog.strategiccyber.com/2013/07/09/hacking-through-a-...

Cobalt Strike is a commercial tool, so it better include the bells and whistles. The OP does a good job of showing code that anyone can play with, right now.

Dan Kaminsky's BlackHat presentations on OzymanDNS are excellent as well.

I noticed from last month's Ruby on Rails vulnerabilities that many in the HN crowd had not heard of or used the Metasploit Framework before. I wrote a comment "What is Metasploit?" that many of you found helpful. This blog post expands on that comment to help you get started playing with Metasploit through the Armitage GUI. The goal--next time something that hits close to home is made available, you'll know how to jump in and test the attack against your own systems.

Very good. I brought a project to Automattic a few years ago and was able to work on it with nearly the same autonomy and freedom I had when I was on my own. Well, one difference, I had more resources and reach to see how far I could take my ideas. Automattic is a great company and one I use as a model for my current venture as it grows up.

Hi guys, there's been a lot of news on HN lately about the Java 0-day, the Ruby on Rails exploit, etc.

There's a lot of misconceptions about hacking and what it looks like now. This blog post attempts to raise awareness about what a targeted attack looks like today. It's a lot more than scanning systems for open services and launching a remote exploit.

-- Raphael

For those who aren't familiar with the Metasploit Project, it's an open source collection of safe and vetted exploits. Once an exploit module makes it into the Metasploit Framework, it's immediately available to ~250K users. The Metasploit Framework isn't just exploits though, it's an integration point for offensive capabilities that simply work together. It's also very easy to hook your own stuff into it.

There are several programs that build on the Metasploit Framework and take advantage of it. Rapid7 has commercial penetration testing products. I build the open source Armitage GUI for it and a commercial add-on called Cobalt Strike.

It's worth spending some time to learn how it works and what it does. Here's a few links:

Metasploit Unleashed Wiki: http://www.offensive-security.com/metasploit-unleashed/Main_...

My 7-part course on pen testing (with Cobalt Strike & MSF): http://www.advancedpentest.com/training

Quick demo of what it looks like to attack a workstation and use it as a hop point to get other things: http://www.youtube.com/watch?feature=player_embedded&v=S...

The best way to try the Metasploit Framework is to setup BackTrack Linux in a virtual machine: http://www.backtrack-linux.org/

A free vulnerable target is the Metasploitable virtual machine, available at: http://sourceforge.net/projects/metasploitable/files/Metaspl...

Thank you for the correction. My intent was not to speak to the state of Groupon. Groupon has had far more success and impact than anything I have created to date. I felt it best to not argue with the parent and focus on the attitude behind the comment and not an assessment of Groupon.

Most companies fail. It's a safe bet to predict failure. It's pretty lame to celebrate that failure from the sidelines.

Vision is not "how is this guaranteed to fail?" but how could it possibly succeed despite the odds?

Which voice do you want to bring to this community?

I joined Hacker News 1,570 days ago (~4 years). I launched my first two ventures here. One of them, Feedback Army, was concieved and built entirely from my interaction in this community. Three years ago, the feel of this community was very much one of support and maybe, a little self esteem boosting. It certainly worked for me and I was very grateful to this community for what it contributed to helping shape me as an entrepreneur.

I still come here for the articles and I occasionally read the comments but I don't participate much. I feel the same way as the original poster. I see someone post something genuine and then I see someone else rip it apart in a condescending way.

I used to come to HN and on the other side of the usernames, I pictured the leaders in our field, the pioneers of the next steps of our information age, and people who I wanted to emulate.

It's not this way for me any more.