human vs artificial intelligence – battle of trust · pdf filehuman vs artificial...

86
Human vs Artificial intelligence – Battle of Trust Hemil Shah Co-CEO & Director Blueinfy Solutions Pvt Ltd

Upload: doduong

Post on 24-Mar-2018

223 views

Category:

Documents


4 download

TRANSCRIPT

Page 1: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Human vs Artificial intelligence –

Battle of Trust

Hemil Shah

Co-CEO & Director

Blueinfy Solutions Pvt Ltd

Page 2: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 2

About

Hemil Shah – [email protected]

Position - , Co-CEO & Director at BlueInfy Solutions, - Founder & Director, eSphere Security & ExtendedITArms, Member of advisory board on several security consulting companies, Speaker & trainer at different conferences

Blueinfy – Professional Application Security Services Company

Blog – blog.Blueinfy.com

Interest Application security research (Web & Mobile)

Published research Articles / Papers – Packstroem, etc. Tools – DumpDroid, CheckDebugable, FSDroid, iAppliScan, wsScanner,

scanweb2.0, AppMap, AppCodeScan, AppPrint etc.

Page 3: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 3

Importance of manual application security reviews

Unique cases used by humans to identify high value security vulnerabilities in applications

Methodology of analyzing modern era applications to find complex security vulnerabilities

Suggestions to protect against the vulnerabilities

Key Points

Page 4: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 4

Vulnerabilities

Human Intelligence

2 Medium = 1 Critical = Compromise

Automated

2 Medium = 2 Medium

Page 5: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 5

Complex Structures

Stack

NodeJS, Mashup driven, Cross Domain integrations, Web services, Webhooks, Browser Extensions, Entity frameworks etc

Protocols

JSON, GWT, WebSockets, Custom, AMF 3.0, etc

Database and File System

MongoDB, Hadoop, IndexDB, FileAPI, etc

Client side

HTML5, AngularJS, ExpressJS, Knockout.js, etc

Page 6: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 6

Where are we standing?

Source: Most vulnerable operating systems and applications in 2014 by GFI Languard

Page 7: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 7

2015 – A Year that has been

Source – 2015 – Edgescan Status Report

Page 8: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 8

2015 – A Year that has been

Source – 2015 – Trustwave Global Security Report

Page 9: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 9

Zero application with NO vulnerability in first review

From the stats of Blueinfy’s data –

Top 5 Vulnerabilities

Page 10: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 10

Attacks and Hacks

98% applications are having security issues

Web Application Layer vulnerabilities are growing at higher rate in security space

Client side hacking and vulnerabilities are on the rise

Web browser vulnerabilities are growing at higher rate

End point exploitation shifting from OS to browser and its plugins

Page 11: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 11

Technology Trend

Page 12: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 12

Today’s Development Life Cycle

Rapid/Agile development

Catching up with new technologies – Web 2.0, HTML5, Framework driven, Mobile, Cloud and on on on on on…

Tight deadlines

Frequent release cycles

Business requirement

Security requirement

Page 13: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 13

Stack/Logic - Layers

Presentation Layer

Business Layer

Data Access LayerAuthentication

Communication etc.

Runtime, Platform, Operating System Components

Server side

Components

Client side

Components

(Browser)

• HTML 5

• DOM

• XHR

• WebSocket

• Storage• WebSQL

• Flash

• Flex

• AMF

• Silverlight • WCF

• XAML

• NET

• Storage

• JS

• Android

• iPhone/Pad

• Other Mobile

Page 14: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 14

Secure ADLC – Is it enough???

Page 15: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 15

Methodology, Scan and Attacks

Footprinting & Discovery

Enumeration & Crawling

Attacks and Scanning

Config Scanning

Web Firewall

Secure Coding

Assets

Secure Assets

Black White

Defense

Code Scanning

Page 16: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 16

Automated Blackbox

Footprinting & Discovery

Profiling & Vulnerability Assessment

Auto Attacks

Defense

Exploit (Missing) & Co-Relation

Page 17: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 17

Automated Whitebox

identified Threats

Identifying Configuration And Code Blocks

Configuration Review Code Review

Security Control

Vulnerability Detection (Exploit/Deployment)

Page 18: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 18

Automated - Whitebox & Blackbox

Blackbox method uses crawling and spidering to determine all possible resources

Application assets are residing in JavaScript and various other tags in HTML, it makes asset detection very difficult and blackbox approach fails in many cases.

Automated tools are headless and generate so many False Positives that usually real vulnerabilities are missed while eliminating false positives

Automated tools may not perform behavioral analysis effectively

Page 19: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 19

Modern Application Challenges

How to identify possible hosts running the application? – Cross Domain

Identifying Ajax and HTML5 calls Dynamic DOM manipulations Identifying XSS and XSRF vulnerabilities for Web 2.0 Discovering back end Web Services - SOAP, XML-RPC or REST. How to fuzz XML and JSON structures? Client side code review Mashup and networked application points

Page 20: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 20

Game is complex

Page 21: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 21

Value of Human in Application Security Reviews

Page 22: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 22

Server Side Session over riding

Typically found in multi-step or wizard based functionality implementation

The application is writing in to server side session to remember user selection/input from the previous page/step

The application performs validation on each step but fails to perform validation at the end before performing actual transaction

E-commerce application stores information when the user selects item

Banking/Currency conversion will require to ask for user’s authorization or transaction passwords

Page 23: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 23

Server Side Session over riding

Page 24: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 24

Server Side Session over riding - Attack

Page 25: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 25

Server Side Session over riding - Demo

Page 26: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 26

Bypassing Authorization with Response Fuzzing

Traditionally penetration testing has been focusing only on modification of requests.

As the browsers have become smart and feature rich, it provides a lot of functionalities along with storage on the client side

Developers are leveraging it As a result, some of the business logic has been shifted from

server side to client side Thus, it has become important to fuzz response along with

request At times, flag change in response opens up new functionality or

new menu items or access to an admin application

Page 27: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 27

Bypassing Authorization with Response Fuzzing

Page 28: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 28

HTML5 Client Side Storage Bypass

HTML5 brings two different types of storage in to browser XSS was pain as it was stealing my cookie, now I can save my cookies

in to client side storage in browser and XSS cannot steal it – REALLY???

Brute force DOES not work any more as the accounts are locked – REALLY???

Great, now I can save all my counters and information on the client side storage

All these are wrong assumption as automated scanners do not find these vulnerabilities

The applications are counting bad attempts and setting a value on the client side either in cookies or LocalStorage options provided by browsers

Page 29: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 29

HTML5 Client Side Storage Bypass - Demo

Page 30: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 30

Command Execution with File Upload

The application has a upload functionality My favorite place to attack Result can be command execution, path traversal to get

access to important files, impact system with virus Key is to find out where files are stored If uploads are not validated, can be very RISKY

Page 31: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 31

Command Execution with File Upload - Demo

Page 32: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 32

SQL Injection on Parameter Name

SQL Injection in parameter value is very common – isn’t it What if you are validating all user input value Should input validation be only on the VALUE and not on the

NAME if you are using it to construct query???

Page 33: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 33

SQL Injection on Parameter Name - Demo

Page 34: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 34

Third party posting, injection and streaming

There are number of applications out there which works as a proxy

An application will allow user to create custom widgets and configure what they would like to see on the widget

These widgets can make calls to third party server to fetch email, RSS feeds, blog, News, twitter, facebook and so on…

An attacker does not need to attack the application but needs to attack source of the application to compromise user

XSS attack from RSS feed can lead in to user’s loosing his session for the application and end up giving access to all other widgets of the user.

Page 35: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 35

Third party posting, injection and streaming

Page 36: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 36

Third party posting, injection and streaming - Demo

Page 37: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 37

Asynchronous injections across critical functions

Applications are leveraging Asynchronous channels i.e. email, OTP on the Mobile to implement critical functionalities

SOA has made it easy as third party API integration has became really easy

In the application, not all tasks need to be completed right away.

Possibly another program can take care of the task later If you request an old statement in bank, bank will have

transaction table where it enters the account number and run another program which runs at particular time

The program will run the job and send results to user over outside communication channel i.e. email

Page 38: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 38

Asynchronous injections across critical functions

What if we find SQL Injection and enter payload with account number???

The application will end up sending statement over email of all users

Page 39: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 39

Custom protocol handling

AJAX calls making calls using non HTTP protocol Tough to analyze and craft request Only HUMAN can do it unless custom program is written to

attack using custom protocol

Page 40: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 40

Information Leakage via Analytics calls

Most applications leverages analytics to understand user’s behavior

Sends information to third party analytical services Easy to implement across the application BUT should not be

implemented at key functionalities - Forgot password Change password page

Page 41: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 41

Input validation on the server side is key – Perform validation for type, size, length and expected characters

Client side validation is NO VALIDATION

Implement defense in depth – Defense at all possible layer

Sanitize all output or perform output encoding

Do not store files in webroot

Have proper permission on directories which stored uploaded files

Protect

Page 42: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Slide 42

HUMANs can find what machine can not

No matter what we do, HUMAN is going to be superior than machines to find HIGH risk vulnerabilities

Leverage combination of human intelligence and machine (Automated) to achieve maximum security (Minimize Risk)

Summary

Page 43: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

THANK YOU!

[Hemil Shah, [email protected]]

Page 44: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 1 XXXXXX XXX©

Human vs Artificial intelligence –

Battle of Trust

Hemil Shah

Co-CEO & Director

Blueinfy Solutions Pvt Ltd

Page 45: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 2

About

Hemil Shah – [email protected]

Position - , Co-CEO & Director at BlueInfy Solutions, - Founder & Director, eSphere Security & ExtendedITArms, Member of advisory board on several security consulting companies, Speaker & trainer at different conferences

Blueinfy – Professional Application Security Services Company

Blog – blog.Blueinfy.com

Interest Application security research (Web & Mobile)

Published research Articles / Papers – Packstroem, etc. Tools – DumpDroid, CheckDebugable, FSDroid, iAppliScan, wsScanner,

scanweb2.0, AppMap, AppCodeScan, AppPrint etc.

Page 46: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 3 XXXXXX XXX©

Slide 3

Importance of manual application security reviews

Unique cases used by humans to identify high value security vulnerabilities in applications

Methodology of analyzing modern era applications to find complex security vulnerabilities

Suggestions to protect against the vulnerabilities

Key Points

Page 47: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 4

Vulnerabilities

Human Intelligence

2 Medium = 1 Critical = Compromise

Automated

2 Medium = 2 Medium

Page 48: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 5

Complex Structures

Stack

NodeJS, Mashup driven, Cross Domain integrations, Web services, Webhooks, Browser Extensions, Entity frameworks etc

Protocols

JSON, GWT, WebSockets, Custom, AMF 3.0, etc

Database and File System

MongoDB, Hadoop, IndexDB, FileAPI, etc

Client side

HTML5, AngularJS, ExpressJS, Knockout.js, etc

Page 49: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 6

Where are we standing?

Source: Most vulnerable operating systems and applications in 2014 by GFI Languard

Page 50: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 7 XXXXXX XXX©

Slide 7

2015 – A Year that has been

Source – 2015 – Edgescan Status Report

Page 51: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 8 XXXXXX XXX©

Slide 8

2015 – A Year that has been

Source – 2015 – Trustwave Global Security Report

Page 52: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 9

Zero application with NO vulnerability in first review

From the stats of Blueinfy’s data –

Top 5 Vulnerabilities

Page 53: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 10

Attacks and Hacks

98% applications are having security issues

Web Application Layer vulnerabilities are growing at higher rate in security space

Client side hacking and vulnerabilities are on the rise

Web browser vulnerabilities are growing at higher rate

End point exploitation shifting from OS to browser and its plugins

Page 54: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 11

Technology Trend

Page 55: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 12

Today’s Development Life Cycle

Rapid/Agile development

Catching up with new technologies – Web 2.0, HTML5, Framework driven, Mobile, Cloud and on on on on on…

Tight deadlines

Frequent release cycles

Business requirement

Security requirement

Page 56: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 13

Stack/Logic - Layers

Presentation Layer

Business Layer

Data Access LayerAuthentication

Communication etc.

Runtime, Platform, Operating System Components

Server side

Components

Client side

Components

(Browser)

• HTML 5

• DOM

• XHR

• WebSocket

• Storage• WebSQL

• Flash

• Flex

• AMF

• Silverlight • WCF

• XAML

• NET

• Storage

• JS

• Android

• iPhone/Pad

• Other Mobile

Page 57: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 14

Secure ADLC – Is it enough???

Page 58: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 15

Methodology, Scan and Attacks

Footprinting & Discovery

Enumeration & Crawling

Attacks and Scanning

Config Scanning

Web Firewall

Secure Coding

Assets

Secure Assets

Black White

Defense

Code Scanning

Page 59: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 16

Automated Blackbox

Footprinting & Discovery

Profiling & Vulnerability Assessment

Auto Attacks

Defense

Exploit (Missing) & Co-Relation

Page 60: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 17

Automated Whitebox

identified Threats

Identifying Configuration And Code Blocks

Configuration Review Code Review

Security Control

Vulnerability Detection (Exploit/Deployment)

Page 61: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 18

Automated - Whitebox & Blackbox

Blackbox method uses crawling and spidering to determine all possible resources

Application assets are residing in JavaScript and various other tags in HTML, it makes asset detection very difficult and blackbox approach fails in many cases.

Automated tools are headless and generate so many False Positives that usually real vulnerabilities are missed while eliminating false positives

Automated tools may not perform behavioral analysis effectively

Page 62: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 19

Modern Application Challenges

How to identify possible hosts running the application? – Cross Domain

Identifying Ajax and HTML5 calls Dynamic DOM manipulations Identifying XSS and XSRF vulnerabilities for Web 2.0 Discovering back end Web Services - SOAP, XML-RPC or REST. How to fuzz XML and JSON structures? Client side code review Mashup and networked application points

Page 63: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 20

Game is complex

Page 64: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 21

Value of Human in Application Security Reviews

Page 65: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 22

Server Side Session over riding

Typically found in multi-step or wizard based functionality implementation

The application is writing in to server side session to remember user selection/input from the previous page/step

The application performs validation on each step but fails to perform validation at the end before performing actual transaction

E-commerce application stores information when the user selects item

Banking/Currency conversion will require to ask for user’s authorization or transaction passwords

Page 66: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 23 XXXXXX XXX©

Slide 23

Server Side Session over riding

Page 67: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 24 XXXXXX XXX©

Slide 24

Server Side Session over riding - Attack

Page 68: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 25 XXXXXX XXX©

Slide 25

Server Side Session over riding - Demo

Page 69: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 26

Bypassing Authorization with Response Fuzzing

Traditionally penetration testing has been focusing only on modification of requests.

As the browsers have become smart and feature rich, it provides a lot of functionalities along with storage on the client side

Developers are leveraging it As a result, some of the business logic has been shifted from

server side to client side Thus, it has become important to fuzz response along with

request At times, flag change in response opens up new functionality or

new menu items or access to an admin application

Page 70: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 27 XXXXXX XXX©

Slide 27

Bypassing Authorization with Response Fuzzing

Page 71: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 28

HTML5 Client Side Storage Bypass

HTML5 brings two different types of storage in to browser XSS was pain as it was stealing my cookie, now I can save my cookies

in to client side storage in browser and XSS cannot steal it – REALLY???

Brute force DOES not work any more as the accounts are locked – REALLY???

Great, now I can save all my counters and information on the client side storage

All these are wrong assumption as automated scanners do not find these vulnerabilities

The applications are counting bad attempts and setting a value on the client side either in cookies or LocalStorage options provided by browsers

Page 72: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 29 XXXXXX XXX©

Slide 29

HTML5 Client Side Storage Bypass - Demo

Page 73: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 30

Command Execution with File Upload

The application has a upload functionality My favorite place to attack Result can be command execution, path traversal to get

access to important files, impact system with virus Key is to find out where files are stored If uploads are not validated, can be very RISKY

Page 74: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 31 XXXXXX XXX©

Slide 31

Command Execution with File Upload - Demo

Page 75: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 32

SQL Injection on Parameter Name

SQL Injection in parameter value is very common – isn’t it What if you are validating all user input value Should input validation be only on the VALUE and not on the

NAME if you are using it to construct query???

Page 76: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 33 XXXXXX XXX©

Slide 33

SQL Injection on Parameter Name - Demo

Page 77: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 34

Third party posting, injection and streaming

There are number of applications out there which works as a proxy

An application will allow user to create custom widgets and configure what they would like to see on the widget

These widgets can make calls to third party server to fetch email, RSS feeds, blog, News, twitter, facebook and so on…

An attacker does not need to attack the application but needs to attack source of the application to compromise user

XSS attack from RSS feed can lead in to user’s loosing his session for the application and end up giving access to all other widgets of the user.

Page 78: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 35

Third party posting, injection and streaming

Page 79: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 36 XXXXXX XXX©

Slide 36

Third party posting, injection and streaming - Demo

Page 80: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 37

Asynchronous injections across critical functions

Applications are leveraging Asynchronous channels i.e. email, OTP on the Mobile to implement critical functionalities

SOA has made it easy as third party API integration has became really easy

In the application, not all tasks need to be completed right away.

Possibly another program can take care of the task later If you request an old statement in bank, bank will have

transaction table where it enters the account number and run another program which runs at particular time

The program will run the job and send results to user over outside communication channel i.e. email

Page 81: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 38

Asynchronous injections across critical functions

What if we find SQL Injection and enter payload with account number???

The application will end up sending statement over email of all users

Page 82: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 39

Custom protocol handling

AJAX calls making calls using non HTTP protocol Tough to analyze and craft request Only HUMAN can do it unless custom program is written to

attack using custom protocol

Page 83: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

TITLE

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

Slide 40

Information Leakage via Analytics calls

Most applications leverages analytics to understand user’s behavior

Sends information to third party analytical services Easy to implement across the application BUT should not be

implemented at key functionalities - Forgot password Change password page

Page 84: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 41 XXXXXX XXX©

Slide 41

Input validation on the server side is key – Perform validation for type, size, length and expected characters

Client side validation is NO VALIDATION

Implement defense in depth – Defense at all possible layer

Sanitize all output or perform output encoding

Do not store files in webroot

Have proper permission on directories which stored uploaded files

Protect

Page 85: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 42 XXXXXX XXX©

Slide 42

HUMANs can find what machine can not

No matter what we do, HUMAN is going to be superior than machines to find HIGH risk vulnerabilities

Leverage combination of human intelligence and machine (Automated) to achieve maximum security (Minimize Risk)

Summary

Page 86: Human vs Artificial intelligence – Battle of Trust · PDF fileHuman vs Artificial intelligence – Battle of Trust Hemil Shah ... • WebSQL • Flash • Flex • ... Human vs Artificial

Notes

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

________________________________________________________________________

__

TITLE

MIS Training Institute Section # - Page 43 XXXXXX XXX©

THANK YOU!

[Hemil Shah, [email protected]]