[00:00.000 --> 00:03.260] A couple of quick announcements... 7 o'clock. [00:03.400 --> 00:05.380] We're gonna have... there's nothing going on in this room. [00:05.500 --> 00:08.860] We're just gonna have closing ceremonies over in the big space in Manning. [00:09.060 --> 00:10.080] So don't miss that. [00:10.200 --> 00:12.200] There's definitely stuff going on that you will want to see. [00:12.600 --> 00:17.780] And we want you to be there when we wrap this all up and tell you how much you all mean to us. [00:18.180 --> 00:20.100] Because we couldn't have done any of this without you guys. [00:20.420 --> 00:22.340] Or we could have, but we would have just looked very silly. [00:25.060 --> 00:29.880] So without much further ado, I just want to also ask you, we don't have a clean-up staff. [00:30.120 --> 00:35.000] So if you have water cups, soda bottles, Club Mate bottles, unfortunately do not evaporate. [00:35.780 --> 00:38.320] So we're gonna ask you to please take your trash with you. [00:38.460 --> 00:41.260] The trash cans are by the exit on your way out. [00:42.320 --> 00:44.220] Okay, so let's move on. [00:44.600 --> 00:47.120] Our next presentation is Stupid White Hat Tricks. [00:47.320 --> 00:48.780] Ladies and gentlemen, Sam Bowne. [00:55.030 --> 00:55.830] All right, thank you. [00:56.410 --> 01:00.390] So, well, can you turn on those lights? [01:00.750 --> 01:01.390] Reckon they will. [01:01.610 --> 01:01.890] All right. [01:02.110 --> 01:07.010] So by the way, it's always going to be on the top two-thirds of the screen because I was sitting out there for the conference unable to see the bottom. [01:07.250 --> 01:07.630] All right. [01:07.950 --> 01:08.890] So I'm Sam Bowne. [01:08.970 --> 01:10.390] I teach at City College, San Francisco. [01:10.710 --> 01:13.350] I've been teaching ethical hacking, which is pretty exciting. [01:13.490 --> 01:15.410] It was a big deal when I started about seven years ago. [01:15.650 --> 01:20.410] And I was unaware of the fact that the only reason I was able to get away with it was because we had no upper management. [01:20.410 --> 01:25.170] That eventually got us in trouble, but it gave me a window of opportunity to do crazy stuff that no one would let me do. [01:26.230 --> 01:30.810] So I got involved in the hacking scene and teaching classes and going to conferences. [01:31.230 --> 01:37.750] And then I got involved in this crazy activity called White Hatting, which is quite controversial. [01:37.750 --> 01:41.530] I think it's less controversial than it was when I started, but it started with me when PBS got hacked. [01:41.690 --> 01:51.090] Back in 2011, the year of LulzSec, when everything was just completely insane, I got on an airplane, got off for like a one-hour layover, read PBS had been hacked. [01:51.190 --> 01:53.330] I had time to tweet about it, then jump on another airplane. [01:53.610 --> 01:56.850] By the time I landed, everybody was screaming at me that I shouldn't have tweeted about it. [01:57.690 --> 02:00.570] And it got me involved in this because I thought, they've been hacked. [02:00.810 --> 02:01.530] Where's their data? [02:01.710 --> 02:04.090] And people said, why do you say they got hacked? [02:04.210 --> 02:04.290] Why? [02:04.450 --> 02:05.670] They might still be wide open. [02:05.730 --> 02:06.670] They might not even know about it. [02:06.730 --> 02:08.470] And I said, well, I didn't even think of that. [02:08.690 --> 02:12.150] Is it possible that somebody got hacked and they didn't even notice yet? [02:12.570 --> 02:13.850] They didn't even fix the problem yet? [02:14.310 --> 02:16.510] And I said, well, then time went by. [02:16.510 --> 02:18.110] They hadn't even taken down their servers. [02:18.230 --> 02:19.330] They don't even know they're rooted. [02:19.950 --> 02:27.650] And this is when I began to get a clue that there are often things that happen that are blindingly obvious to me and to the people I talk to. [02:27.910 --> 02:30.290] And the people at the other end have no clue at all. [02:30.410 --> 02:31.790] And nobody's telling them. [02:32.030 --> 02:37.130] This is when I said, is it possible that I am the only person in the room that will tell them? [02:37.190 --> 02:37.970] And that was true. [02:37.970 --> 02:39.950] And I found out that is frequently true. [02:40.090 --> 02:56.310] I don't know how much it's true now, but I think it's still largely true that things are well known in the security echo chamber and nobody is telling the company because there's not anybody there that either feels any responsibility to do it or the people involved are the square establishment, [02:56.310 --> 03:00.810] law enforcement, FBI courts, and the people that know are nervous about talking to them. [03:00.810 --> 03:04.930] So I always emphasize to my students, make good law enforcement contacts early. [03:05.070 --> 03:15.830] Make a clear presence as a good guy early so you have law enforcement people you can talk to and people in the government you can talk to so you're ready if you have something you want to say to them. [03:16.370 --> 03:19.590] So I did tell them and they had no idea what to do. [03:19.770 --> 03:24.230] And I found somebody that agreed to fix their stuff for free and set them up and they got it fixed. [03:24.310 --> 03:28.690] But it took them almost a month to close their sequel injection at PBS because they had no money. [03:28.690 --> 03:32.510] And the same thing happened to a big media outlet, I think CNN, they fixed it in one day. [03:32.610 --> 03:33.650] Of course they have a lot more money. [03:33.830 --> 03:41.970] So this started me in this game, when you know something about somebody else's servers and they don't know, you can try to tell them. [03:42.070 --> 03:44.430] And this was considered highly controversial at the time. [03:44.970 --> 03:57.550] A lot of people told me who are security professionals and I'm relatively new at it, never do this, you will do no good, they will not listen to you, they will prosecute you, they will blame you for hacking them, they will call you a bad guy, you'll get in all kinds of trouble and do no good. [03:58.170 --> 03:59.910] And I said, well, I think I'll try it. [04:00.010 --> 04:01.470] But this is kind of insane. [04:01.710 --> 04:06.770] And obviously only for someone too much time in their hands, or with me, students that need homework, which amounts to probably the same thing. [04:08.110 --> 04:12.490] So I'm not going to get paid, I'm probably not even going to get a thank you, but you might do some good. [04:12.650 --> 04:14.890] And the interesting question is how much good can you expect? [04:14.910 --> 04:19.890] And I think it would help a lot for people to understand the answer is 25%. [04:20.610 --> 04:26.310] Only one quarter of the people that you tell about horrible things will ever do anything about it. [04:26.950 --> 04:32.210] So don't freak out if you tell them something that seems all important to you and they don't care. [04:32.350 --> 04:33.090] Expect that. [04:33.850 --> 04:39.610] Anyway, so there are laws, but the laws basically say that you can't run code on somebody else's machine. [04:39.690 --> 04:40.570] It's not complicated. [04:40.730 --> 04:44.030] I remember I taught ethical hacking and people said, Where's the lessons about ethics? [04:44.190 --> 04:46.330] And I said, Well, the lessons about ethics are up by one sentence. [04:46.750 --> 04:47.970] Do this on your own machine. [04:48.350 --> 04:50.270] Don't do this to somebody else without their permission. [04:52.110 --> 04:55.050] So the SSP has a code of ethics, which I thought sounded really good. [04:55.110 --> 05:02.410] Although, if anybody knows even one case where these code of ethics have actually done any good for anybody, I would love to hear it. [05:03.510 --> 05:08.430] They sound good, but I've never seen it work in practice that these actually accomplish anything. [05:08.970 --> 05:13.890] Except to harass good people, and when reports are made of clearly unethical things, they don't do anything. [05:14.050 --> 05:17.490] So I'm getting kind of as frustrated as other people have been about the actual practice. [05:17.710 --> 05:19.070] But the idea is a good idea. [05:19.430 --> 05:27.790] That people with that certification anyway, and people with certified ethical hackers, which is the same rules really, are here to try to hold things up and not break the law. [05:28.610 --> 05:33.910] So anyway, it is very, very common that there's something that somebody might care about. [05:34.490 --> 05:36.410] So, let me see where my mouse is. [05:36.410 --> 05:36.790] Okay. [05:37.790 --> 05:38.910] Still don't seem to have a mouse. [05:40.770 --> 05:43.130] Well, this is going to follow up my demo if I don't have any mouse. [05:44.450 --> 05:45.130] You see it? [05:46.830 --> 05:48.950] Oh, now I've lost... that's funny, now I've lost... [05:48.950 --> 05:49.410] Oh, it's over there. [05:49.530 --> 05:49.990] I see. [05:50.110 --> 05:51.290] Oh, my screens are not mirroring. [05:51.370 --> 05:51.610] Oh, good. [05:51.730 --> 05:52.770] Well, that's a solvable problem. [05:53.030 --> 05:53.110] Okay. [05:55.650 --> 05:55.970] Um... [05:56.650 --> 05:56.970] Displays. [05:58.850 --> 05:59.170] Arrangement. [05:59.690 --> 06:00.010] Mirror. [06:00.230 --> 06:00.810] Life is good. [06:01.870 --> 06:02.190] Alright. [06:02.650 --> 06:04.170] Now we should see the same nonsense. [06:05.410 --> 06:06.390] I think so. [06:06.670 --> 06:06.810] Alright. [06:07.550 --> 06:08.030] So... [06:08.790 --> 06:12.150] Now I've got a few things to show you live here. [06:12.430 --> 06:12.850] Alright. [06:12.970 --> 06:13.310] There we are. [06:13.790 --> 06:16.250] So I just looked on Pastebin last night. [06:17.390 --> 06:20.670] There were always people dumping SQL injection vulnerable sites on Pastebin. [06:20.950 --> 06:23.790] And here's the latest batch of them, maybe about a month old. [06:24.230 --> 06:28.770] Here's some company called LWSA Design. [06:29.890 --> 06:34.450] And if you go to that URL, you get a glorious SQL syntax error. [06:34.630 --> 06:38.390] And as you probably know, this means you could just take over that server trivially. [06:38.450 --> 06:39.790] It means you could deface their website. [06:39.910 --> 06:42.570] It means it's not entirely certain that you could, but you very likely could. [06:43.010 --> 06:49.890] Because the fact that this apostrophe here broke the syntax means I could follow this with more code, and it would execute that code on the server. [06:49.890 --> 06:52.890] Now, what I have done right now is not illegal. [06:53.750 --> 06:57.570] And I can talk about it to people over the telephone with unencrypted email. [06:57.750 --> 06:59.150] I can post blog posts about it. [06:59.410 --> 07:01.370] Because this is a really good thing for a white hat. [07:01.490 --> 07:03.250] The first thing is, I did not find it. [07:03.430 --> 07:06.530] I did not perform a vulnerability scan without permission or anything to do it. [07:06.910 --> 07:09.550] Somebody else found it, and somebody else published it. [07:09.830 --> 07:14.010] Now this person may very well have committed some sort of crime, but I didn't. [07:15.250 --> 07:18.690] And what I'm doing is telling them, you have a vulnerability. [07:18.950 --> 07:23.710] And you can put an apostrophe at the end of the URL and see this error, and that shows that they have a vulnerability. [07:23.910 --> 07:29.730] Now if I follow this by running a SQL map or something and dumping out their database, then I've committed a crime. [07:29.950 --> 07:34.330] Now I'm going to have a really hard time talking to that company because I'm on the wrong side of the law. [07:34.510 --> 07:37.590] But if I stop here, I know something, and I can contact them and tell them. [07:37.710 --> 07:38.690] And I've done a lot of this. [07:40.690 --> 07:43.810] All right, so get back to this one. [07:45.630 --> 07:47.110] All right, and so there's a lot of these. [07:47.230 --> 07:48.970] Here's another one of them with error in your SQL syntax. [07:50.250 --> 07:50.870] On it goes. [07:51.050 --> 07:53.670] I've seen dumps of 15,000 on Pastebin, which are a lot of true. [07:53.830 --> 07:55.550] So you have to contact these people. [07:55.630 --> 07:57.470] First, you'll take a look at it and verify the vulnerability. [07:57.970 --> 07:58.990] Don't go any further. [07:59.170 --> 08:01.310] Don't execute any code on somebody else's server. [08:01.410 --> 08:02.510] All I did was see an error message. [08:03.170 --> 08:06.610] And then you have to somehow contact them, which turns out to be a major pain. [08:07.370 --> 08:11.510] Theoretically, people are supposed to listen to anything going to security at domain name, abuse.domainname. [08:11.750 --> 08:13.390] In practice, almost nobody does. [08:13.750 --> 08:18.110] I was sort of horrified when I found out that MIT is a form to fill out on their website. [08:18.250 --> 08:20.830] It says we no longer pay attention to abuse.mit.com. [08:20.970 --> 08:23.130] We want you to find our form and fill out our form. [08:23.230 --> 08:30.130] So when I've got a list of 10,000 companies, I'm supposed to go hunt through every website for whatever junk they made up instead of obeying the standard. [08:30.330 --> 08:31.450] But that's the way it really is. [08:33.030 --> 08:36.090] So I sent them an email, something like this, telling me I have an open SQL injection. [08:36.090 --> 08:36.810] Well, I was surprised. [08:36.930 --> 08:40.830] A few people responded to me when I contacted the Supreme Court of the UK with a vulnerability. [08:41.190 --> 08:45.010] This person said, my heart stopped when I went to that website and I saw our URL. [08:45.150 --> 08:45.930] And I said, oh, my God. [08:47.310 --> 08:49.370] Well, that's what I wanted, is that they would pay attention. [08:49.710 --> 08:51.490] So I try to explain who I am. [08:51.530 --> 08:56.490] I try to explain the problem in very simple terms, assuming I'm talking to a non-technical management type. [08:56.950 --> 08:59.270] And I have been moving further and further up the food chain. [08:59.270 --> 09:00.710] I'll talk more about that later. [09:00.910 --> 09:01.330] But at first... [09:01.330 --> 09:01.890] I now go... [09:01.890 --> 09:05.730] Don't even bother notifying people unless I'm notifying the chancellor. [09:06.490 --> 09:09.370] And I recently went to the CEO of a major multinational company. [09:09.450 --> 09:10.970] You have to go all the way to the top. [09:11.130 --> 09:12.250] And I might as well mention it now. [09:12.330 --> 09:14.330] This is a fundamental lesson I learned at my own college. [09:14.690 --> 09:23.350] At my own college, somebody in the IT department had a great idea that they would save help desk time by putting a page so teachers could get a list of the students in their classes. [09:24.270 --> 09:26.050] And there was no login at all. [09:26.530 --> 09:29.690] So anybody could type in any course number and get the students in that class. [09:29.810 --> 09:31.350] And I made the same mistake 10 years ago. [09:31.670 --> 09:33.770] And I had students come and tell me, you can't do that. [09:33.830 --> 09:34.670] It's going to ruin my life. [09:34.850 --> 09:36.370] There are stalkers hunting me. [09:36.470 --> 09:37.910] There's a crazed boyfriend looking for me. [09:37.990 --> 09:41.170] If they find out in your class, they're going to hide out and shoot me with a gun. [09:41.290 --> 09:42.130] And I said, oh, my God. [09:42.270 --> 09:45.170] You know, like a lot of people have been talking about here. [09:45.230 --> 09:49.830] I just did not understand the fear that these people live in and the problems of their life. [09:50.050 --> 09:52.370] And that's why there's a law, FERPA, that says you can't do that. [09:52.370 --> 09:56.330] You can't publish any kind of directory of students at a college without getting the permission of those students first. [09:57.270 --> 09:58.590] Without giving them a chance to opt out. [09:58.890 --> 10:03.390] So I contacted the programmer that put up that page and I got nothing. [10:03.990 --> 10:04.910] For nine months. [10:05.410 --> 10:07.490] I contacted that programmer's boss. [10:07.850 --> 10:10.530] And I got a promise they would fix it followed by nothing. [10:10.930 --> 10:12.770] When you go up to the C level, you get there. [10:12.850 --> 10:16.050] And I finally realized I learned this myself when I worked under contract with the FTC. [10:16.790 --> 10:20.670] I was a database analyst at a company that was returning money to people that had money stolen from them. [10:20.670 --> 10:26.610] And I was amazed to discover that 90% of the workers had no concept of what the company did. [10:26.810 --> 10:28.030] And they didn't care either. [10:28.470 --> 10:33.470] All they cared about was that the stuff on my desk is where it should be and I got out of here at five. [10:34.010 --> 10:38.590] They didn't care whether they were driving the ship towards the rocks or backwards or going straight down. [10:39.110 --> 10:41.150] All they cared about was getting my paycheck. [10:41.410 --> 10:47.010] And if you showed any glimmer of clue about what the purpose of the company was, they would promote you immediately to management. [10:47.190 --> 10:47.930] That's where I ended up in a hurry. [10:48.010 --> 10:49.610] I didn't mean to be in charge of a division. [10:50.150 --> 10:52.130] But I actually cared about getting the job done. [10:52.330 --> 10:53.610] And I learned this. [10:53.990 --> 10:57.230] And the important thing, I think, is not to hate people for this on either side. [10:58.150 --> 11:02.890] Your detail end users worry about their details and they don't drive the ship. [11:02.890 --> 11:06.310] The guy driving the ship doesn't know about the details, but they care about driving the ship. [11:06.430 --> 11:07.210] They're different jobs. [11:07.370 --> 11:10.590] And you have to go all the way up to somebody that can actually understand. [11:10.890 --> 11:13.650] We have to obey the law or the government will shut us down. [11:13.830 --> 11:14.950] And that would be a problem. [11:15.170 --> 11:18.270] And this is not true that everybody in the company can understand that. [11:18.390 --> 11:18.870] Not at all. [11:19.050 --> 11:20.210] Or even care about that. [11:22.130 --> 11:23.850] So that's the point here. [11:24.030 --> 11:25.030] I put in real name. [11:25.170 --> 11:25.830] No demands. [11:25.830 --> 11:26.450] No threats. [11:28.970 --> 11:31.050] I did a simple investigation. [11:31.050 --> 11:32.630] 23 high profile companies. [11:32.830 --> 11:34.990] And you know, 30% of them fixed it after three days. [11:35.190 --> 11:36.410] And that was in 2011. [11:36.730 --> 11:39.510] So I started shooting my CSSP students doing the same thing. [11:39.650 --> 11:40.790] They contacted hundreds of sites. [11:40.990 --> 11:43.370] They got something like 15% fixing rate. [11:43.750 --> 11:45.470] Very few of them actually say anything. [11:45.630 --> 11:47.470] But a lot of them either take down the page or fix it. [11:47.550 --> 11:48.770] Or some of them do 15%. [11:50.690 --> 11:53.710] So I reported a lot of these to a lot of big companies. [11:54.230 --> 11:55.950] Then I came across... [11:55.950 --> 11:57.950] This one got me in a lot of trouble. [11:59.190 --> 12:02.690] See, LulzSec in 2011 would hack sites and dump stuff. [12:02.850 --> 12:05.610] And they would dump like 100 pages of garbage on base bin. [12:05.970 --> 12:09.070] And as far as I could tell, nobody read that stuff but me. [12:09.570 --> 12:11.110] And for some... somebody gave me a tip. [12:11.730 --> 12:18.430] And way down... three quarters of the way down a 200 page dump, they had six OpenSQL injections in Chinese government servers. [12:19.370 --> 12:26.330] And that week, Obama said, if there was a cyber attack in the United States, we would respond with military violence. [12:26.930 --> 12:29.010] And I said, this is a really bad idea. [12:29.330 --> 12:31.490] To have OpenSQL injections into the Chinese government. [12:31.690 --> 12:35.590] Which means anybody that wants to stir up trouble could use it and get stuff blamed on them. [12:35.770 --> 12:38.150] Of course, now I think that was pretty naive of me. [12:38.330 --> 12:40.070] That's basically been the situation all along. [12:40.290 --> 12:43.230] But anyway, right here I knew that the anonymous people had that. [12:43.970 --> 12:45.230] And the LulzSec people had that. [12:45.330 --> 12:45.990] They didn't use it. [12:46.050 --> 12:47.190] But I was afraid they would use it. [12:47.270 --> 12:48.830] And I wanted to tell the people in China. [12:49.650 --> 12:51.190] And I didn't know how to get contacts. [12:51.270 --> 12:56.170] I didn't know enough about these structures that you can't just call somebody in the Chinese government on the phone. [12:56.310 --> 12:58.530] You can't just call somebody in the FBI on the phone that can do something. [12:58.650 --> 12:59.330] You need a contact. [13:01.230 --> 13:02.950] So, I started using Twitter. [13:03.130 --> 13:04.970] Asking, I need a contact inside Microsoft. [13:05.190 --> 13:07.350] I need a contact in the Los Angeles Police Department. [13:07.890 --> 13:08.250] Apple. [13:08.910 --> 13:09.270] Oracle. [13:09.530 --> 13:11.050] And then somebody got something in the Chinese government. [13:11.410 --> 13:14.270] For about a week or two, I was posting a lot of these crazy tweets. [13:14.990 --> 13:18.170] Implying that I had really high value security vulnerabilities. [13:18.690 --> 13:23.710] And what I didn't expect was my primary opposition would come from professional security experts. [13:23.950 --> 13:25.850] Who were very, very jealous. [13:26.170 --> 13:28.070] How do you know all this great stuff? [13:28.430 --> 13:30.470] You must have done something terrible to find it. [13:31.210 --> 13:33.350] And I wasn't willing to tell them where I found it. [13:33.530 --> 13:37.190] Because they had made it clear from their attitude that they probably would do something stupid. [13:37.350 --> 13:39.370] Like hack China or hand it to bad people or something. [13:41.070 --> 13:43.150] So I refused to answer that question for about a week. [13:43.270 --> 13:44.390] And that got me in a lot of trouble. [13:44.750 --> 13:47.350] So anyway, it did also do a lot of good. [13:47.350 --> 13:49.670] These high value companies, you can sometimes reach them. [13:49.730 --> 13:50.670] Although you might like this one. [13:50.770 --> 13:52.650] The UN had a wide open injection hole. [13:52.970 --> 13:55.870] So I couldn't find any security contact on the UN website. [13:56.030 --> 13:58.270] So I called the New York City Police Department. [13:58.550 --> 14:00.430] And I said, do you have someone there? [14:00.870 --> 14:04.150] Do you have any idea how to report something to a security problem at the UN? [14:04.390 --> 14:05.250] And they hung up on me. [14:05.410 --> 14:07.290] And I said, well, I should have seen that coming. [14:07.470 --> 14:07.750] Anyway. [14:09.970 --> 14:11.410] So a lot of them got fixed. [14:11.530 --> 14:12.570] Some people got very upset. [14:12.570 --> 14:15.570] They accused me of being a spy, performing bogus scans. [14:15.570 --> 14:20.210] And they sent an official ethics complaint to the ISC to revoke my certification for unethical conduct. [14:20.590 --> 14:22.110] Which was complete garbage. [14:22.290 --> 14:24.490] And all I had to do was write a well-formed letter to get rid of it. [14:24.630 --> 14:25.810] But I found it pretty annoying. [14:26.630 --> 14:27.930] And that is how the structure works. [14:28.030 --> 14:33.450] If you have any accusation against anybody with a CISSP, no matter how bogus, you can write a letter. [14:33.450 --> 14:35.150] You do not need to be their client or have anything. [14:35.450 --> 14:38.630] And if you do, they have to respond in 30 days or they lose their certification. [14:40.350 --> 14:41.810] So anyway, that's the way it is. [14:41.950 --> 14:43.890] So let's talk about some colleges. [14:44.090 --> 14:45.250] Because colleges are the worst. [14:48.170 --> 14:49.290] And they're sort of well-known. [14:49.310 --> 14:51.310] If you want to do nasty things, you do it at colleges. [14:51.310 --> 14:54.690] So, here's a live one to see. [14:54.890 --> 14:56.010] This is Parsons College. [14:56.170 --> 14:57.030] I don't even know where it is. [14:57.210 --> 14:59.230] But they're a college called parsons.edu. [14:59.470 --> 15:02.970] And if you search for Viagra shop, you get 2,500 results. [15:04.810 --> 15:13.310] And if you go to this parsons.edu link, by clicking on the Google search results, it redirects to this page which will show you sex drugs. [15:15.230 --> 15:22.670] But if you go to the URL at Parsons, you will get a blog of some sort where the post-it is not the same. [15:22.870 --> 15:24.150] So this is a very interesting thing. [15:24.250 --> 15:25.690] And that's what caught my attention about this. [15:25.810 --> 15:27.430] This is a bunch of colleges. [15:27.950 --> 15:30.330] This is, in my opinion... [15:30.330 --> 15:31.150] See, here I am. [15:31.210 --> 15:32.250] This is the problem with white hatting. [15:32.330 --> 15:33.230] I can't get inside. [15:33.410 --> 15:34.150] I can't get good data. [15:34.230 --> 15:37.390] But from the outside, it appears to me this is far more than a defacement. [15:37.850 --> 15:39.850] This is active code running on a web server. [15:39.910 --> 15:43.770] Because if I go to the same link from Google, I get here. [15:44.350 --> 15:49.270] If I go to this actual URL by copying and pasting it, I go here, which is still inside their website. [15:49.650 --> 15:51.330] And a lot of them concealed this. [15:51.550 --> 15:55.890] So if you were inside the college, clicking links, everything works fine. [15:56.030 --> 15:58.190] It's only when you come from Google that you end up at the sex site. [15:59.150 --> 16:00.250] So this... what's that? [16:00.430 --> 16:01.270] It's the referrer. [16:01.270 --> 16:01.690] It is. [16:01.770 --> 16:02.490] It's the referrer. [16:02.690 --> 16:07.990] But that means they have compromised the web server so much that they put active code and filtering results to the web server. [16:08.070 --> 16:09.590] This is far more than just replacing a page. [16:09.730 --> 16:12.550] This is... it seems to me that's got to be active code on the web server. [16:13.090 --> 16:17.730] And therefore, it seems to me like this is a serious compromise. [16:18.630 --> 16:20.150] Somebody owns their web server anyway. [16:20.650 --> 16:21.590] Is that the JavaScript? [16:24.350 --> 16:26.170] No, but I guess I could. [16:26.290 --> 16:27.970] I could look for JavaScript here, but I don't think it's there. [16:28.370 --> 16:31.010] I think it's PHP somewhere on the server, but I'm not sure what it is. [16:31.210 --> 16:34.510] I've never been able to get any of these people to cooperate with me enough to get samples from the inside. [16:34.770 --> 16:35.490] I've been trying. [16:36.370 --> 16:37.850] Anyway, let's see. [16:37.950 --> 16:39.070] I don't know if I had another one here. [16:39.750 --> 16:42.810] Yeah, so here's the 19 colleges I found at first. [16:42.930 --> 16:43.930] I later found a bunch more. [16:44.930 --> 16:45.830] But here's some... [16:45.830 --> 16:47.970] I found these 19 colleges around December last year. [16:48.450 --> 16:49.870] And they're green if they fixed it. [16:50.830 --> 16:53.010] They're yellow if they fixed it within seven months. [16:53.150 --> 16:54.610] They're green if they fixed it within about three weeks. [16:55.470 --> 16:56.110] There's Parsons. [16:56.170 --> 16:57.290] These are the ones that are still infected. [16:57.290 --> 16:58.030] And there's the links. [16:59.070 --> 17:00.110] Berkeley in there. [17:01.530 --> 17:02.270] A bunch of them. [17:02.670 --> 17:04.650] Anyway, and here's all the people I notified. [17:04.850 --> 17:06.350] At this time, I didn't know who to notify. [17:06.510 --> 17:08.010] I went to each website and hunted around for people. [17:08.050 --> 17:10.170] I was beginning to get a clue, which has become my standard. [17:10.290 --> 17:16.070] I drew the chancellor, the IT staff, and somebody else who appears technical in the hopes that somebody will listen. [17:17.430 --> 17:24.110] And you see, a lot of these guys actually did eventually fix this because this is an actual, you are currently owned alert. [17:25.090 --> 17:27.010] And that might get a little attention, you would think. [17:27.570 --> 17:30.210] There's the Kentucky Wesleyan College one that started it all off. [17:31.250 --> 17:32.590] So five fixed within a few weeks. [17:32.750 --> 17:33.470] Seven still fix it. [17:33.670 --> 17:35.870] So less than half of them are still currently infected. [17:36.170 --> 17:38.310] But those seven have been infected for seven months now. [17:38.750 --> 17:45.810] And it seems to me that it is a fair statement to say for seven months those web servers have been under hostile control by Russian criminals selling drugs. [17:46.090 --> 17:48.230] Because these former websites are very well known. [17:48.570 --> 17:49.450] They come from Russia. [17:49.470 --> 17:50.550] They pretend to be in Canada. [17:50.790 --> 17:52.310] It's a big scam. [17:52.590 --> 17:54.730] And the point, I think, is reputation theft. [17:54.730 --> 17:58.810] They just want to up their Google rank by getting your EDU pages to point to them. [17:59.710 --> 18:00.990] Anyway, it is... [18:00.990 --> 18:04.110] So, I mean, you could say the college can still do its work. [18:04.110 --> 18:04.570] Who cares? [18:05.390 --> 18:10.250] But I think it implies that those guys could traverse laterally through your network and steal more stuff. [18:10.470 --> 18:12.370] And just ignoring it completely is unwise. [18:12.670 --> 18:13.470] Because of this. [18:14.310 --> 18:16.110] California already lived through this a couple of years ago. [18:16.610 --> 18:16.970] Maricopa. [18:17.090 --> 18:18.430] There was a college in California. [18:18.810 --> 18:20.910] They got compromised in 2011. [18:21.290 --> 18:23.410] The security team went and found out what they should do. [18:23.550 --> 18:25.110] And they didn't do any of it. [18:25.630 --> 18:27.370] And so two years later they got hacked again. [18:27.490 --> 18:28.850] And they stole all the data and dumped it out. [18:29.030 --> 18:31.710] And now they had a huge breach to report and apologize for and everything. [18:32.170 --> 18:34.590] And so it occurred to me when I was preparing another talk here. [18:35.490 --> 18:38.790] A talk in Los Angeles a few weeks ago. [18:39.670 --> 18:42.350] This really is essentially a situation at UC Santa Cruz. [18:42.450 --> 18:45.810] UC Santa Cruz was by far the worst with these pharmaceutical infections. [18:46.050 --> 18:48.070] They had about 8,000 infected pages. [18:48.430 --> 18:51.570] When I told them the first time, they imaged one server the next day. [18:51.650 --> 18:52.530] So they were clean for a day. [18:52.650 --> 18:54.310] Then they had four infected servers the day after. [18:54.890 --> 18:57.250] Because it's not enough to image one server anymore. [18:57.410 --> 18:58.910] That's not how modern infections work. [18:59.250 --> 19:00.030] They spread around. [19:00.150 --> 19:00.830] They're all over the place. [19:00.930 --> 19:03.550] This is like stepping on one roach and say, there, I solved that problem. [19:04.890 --> 19:06.650] So now they've been infected all along. [19:06.770 --> 19:08.370] So it occurred to me I could do something about it. [19:08.370 --> 19:10.910] So I sent a letter to Jerry Brown and Janet Napolitano. [19:11.110 --> 19:16.730] Now, the reason I did this, by the way, is because I found a problem on Jerry Brown's website in California. [19:17.170 --> 19:19.270] And I went to the website. [19:19.330 --> 19:20.050] I thought it was important. [19:20.250 --> 19:22.830] I found their phone number for general inquiries. [19:22.850 --> 19:23.830] And I called it. [19:24.030 --> 19:28.750] And I said to the random guy who answered the phone, I have a serious security vulnerability on your website. [19:28.810 --> 19:29.810] And I want to talk to somebody. [19:29.950 --> 19:33.730] And he immediately transferred me to somebody smart who immediately fixed it. [19:34.470 --> 19:36.930] And I said, wow, you know, Jerry Brown runs a tight ship. [19:36.930 --> 19:38.730] I know how hard it is to get that. [19:39.010 --> 19:41.050] What you usually get is, what? [19:41.130 --> 19:41.970] What are you talking about? [19:42.070 --> 19:42.890] Are you buying the product? [19:43.130 --> 19:43.730] Go away. [19:45.410 --> 19:46.970] Anyway, so I thought he might do something. [19:47.090 --> 19:47.670] And he certainly did. [19:47.750 --> 19:50.030] The day after I sent this, everything was taken down. [19:50.450 --> 19:53.810] All the infected pages were removed immediately from the UC Santa Cruz website. [19:53.970 --> 19:58.230] And I had been talking to the people there for months, saying, please let me visit your campus. [19:58.250 --> 19:59.010] It's not that far away. [19:59.090 --> 20:01.150] I'd like to go in and get samples of this stuff from inside. [20:01.250 --> 20:02.250] So I'd find out what's going on. [20:02.250 --> 20:03.570] But they wouldn't go for that. [20:03.690 --> 20:04.290] They wouldn't talk to me. [20:05.090 --> 20:06.290] So that cleaned it up. [20:06.530 --> 20:08.350] So going to the top is very good. [20:09.530 --> 20:11.190] Anyway, there's a lot of others out there. [20:11.330 --> 20:13.430] So let's talk about SQL injection at colleges. [20:13.910 --> 20:14.970] Boy, there's a lot of that. [20:17.250 --> 20:19.510] Let me clean out some of this stuff. [20:20.070 --> 20:20.310] All right. [20:22.270 --> 20:22.950] All right. [20:23.090 --> 20:24.090] So let's start with... [20:24.090 --> 20:25.690] Well, here's an even nastier one. [20:25.850 --> 20:28.170] Here's probably the worst case of SQL injection you can imagine. [20:28.870 --> 20:30.530] This is not exactly SQL injection. [20:30.730 --> 20:31.590] I thought it might be at first. [20:32.150 --> 20:33.830] But these guys have student data. [20:33.970 --> 20:34.690] And they still do. [20:34.790 --> 20:36.610] I told them eight months ago, and they haven't done anything about it. [20:36.710 --> 20:37.230] So here you go. [20:37.330 --> 20:39.650] Cambridge College, which I think is Massachusetts. [20:40.170 --> 20:41.630] My CC at Cambridge College. [20:43.050 --> 20:46.050] If you go there, click on that link, you get an Excel spreadsheet. [20:46.370 --> 20:50.510] If you open that Excel spreadsheet, you get a bunch of student names. [20:51.970 --> 20:54.210] I've been up here for nine months I know of. [20:54.690 --> 20:56.090] Just real student attendance. [20:56.090 --> 20:58.270] Now this is a FERPA violation. [20:58.610 --> 21:01.350] And most of them were able to understand that when I notified them. [21:01.430 --> 21:03.030] A lot of them took this junk down right away. [21:03.230 --> 21:17.950] And in fact, it turned out that the vendor, who wrote the software they were using, called Jezebel or something like that, he actually updated his stuff to get rid of this. [21:18.050 --> 21:24.490] There was some kind of software which would make a copy of the things you typed into it in some directory which could well be saved with the world. [21:25.370 --> 21:26.010] Shared with the world. [21:26.150 --> 21:26.950] So anyway, that's one problem. [21:27.170 --> 21:28.930] Here's another one that's kind of hard to believe. [21:29.070 --> 21:30.310] Notice what's going on up here. [21:30.470 --> 21:33.850] The URL has got SQL in it. [21:34.310 --> 21:35.630] ID equals minus one union. [21:35.790 --> 21:36.410] This is not... [21:36.410 --> 21:37.430] Now I would not dare do this. [21:37.490 --> 21:41.910] Remember I told you before I can put an apostrophe at the end and get an error message, but I wouldn't type a bunch of code. [21:42.110 --> 21:51.730] See what happened is some kind of automated tool from another country attacked a bunch of websites, found all these things, and stored the entire URL complete with the injection on a public list. [21:51.890 --> 21:53.070] And that got indexed by Google. [21:53.610 --> 21:54.750] So I went and started... [21:54.750 --> 21:56.510] But I found almost all these with Google dorks. [21:56.530 --> 22:00.770] I went to Google and I looked for stuff like union and select in the URL. [22:00.970 --> 22:01.990] And I found a bunch of these. [22:03.030 --> 22:03.750] So I... [22:03.750 --> 22:05.550] Again, here's my defense. [22:05.910 --> 22:07.130] No one's tried to lock me up yet. [22:07.270 --> 22:08.650] I'd say, you know, I didn't do it. [22:08.970 --> 22:10.130] I didn't publish it. [22:10.230 --> 22:11.650] I found it somewhere. [22:11.890 --> 22:13.290] And look, I'm just pointing at it. [22:13.390 --> 22:15.030] Look at what this rotten guy did over here. [22:15.390 --> 22:15.830] Not me. [22:16.530 --> 22:16.850] So... [22:18.130 --> 22:24.870] But this one's kind of incredible because it does a union select, group concat, username, user password, and you get the password. [22:25.290 --> 22:26.450] This is the password hash. [22:26.890 --> 22:27.610] There's the username. [22:27.770 --> 22:28.630] There's the password hash. [22:29.110 --> 22:31.730] And so I contacted them nine months ago. [22:31.830 --> 22:34.530] And I said, hey, guys, this is no way to run a college. [22:34.650 --> 22:35.210] They're in my town. [22:35.330 --> 22:36.870] These guys are in San Francisco, for crying out loud. [22:36.950 --> 22:38.170] I said, come on, guys. [22:38.370 --> 22:38.850] What's wrong with you? [22:39.010 --> 22:40.830] And they ignored me. [22:40.890 --> 22:42.350] So I went on Twitter and contested. [22:42.370 --> 22:43.190] Oh my gosh, that's terrible. [22:43.270 --> 22:44.290] Tell the webmaster right away. [22:44.730 --> 22:45.830] Nothing ever happened. [22:46.150 --> 22:48.630] Now, to be fair, I can't crack that hash. [22:48.850 --> 22:49.590] I've been trying. [22:52.270 --> 22:53.770] So maybe it's okay. [22:53.970 --> 22:54.810] And that's what defends in depth. [22:54.930 --> 22:56.550] That's why you do things like hash passwords, right? [22:56.630 --> 22:59.050] That's why if you have a problem, maybe your next variable will stop it. [22:59.110 --> 23:01.210] And at least for a wimp like me, I can't crack that hash. [23:01.430 --> 23:04.810] Now, if anybody's a good hash cracker out there and they can crack that thing, I'm interested. [23:05.810 --> 23:06.890] I tried Googling it. [23:07.450 --> 23:10.310] I tried a little bit more than that, but I couldn't crack it. [23:10.430 --> 23:13.530] It's not just a simple MD5, or if it is, what is behind it is not simple. [23:13.770 --> 23:15.110] Anyway, that's a... [23:15.110 --> 23:16.250] Then here's one at Harvard. [23:16.790 --> 23:18.890] Here's one at University of Illinois, my alma mater. [23:19.930 --> 23:20.830] And here's another one. [23:21.850 --> 23:22.350] All right. [23:23.110 --> 23:24.250] This is Harvard. [23:25.710 --> 23:28.430] Again, these are all things I told them seven months ago, and they don't care. [23:30.290 --> 23:32.190] This is University of Illinois. [23:32.590 --> 23:35.010] Notice down here, you've got your Microsoft syntax error. [23:35.250 --> 23:38.290] Same thing, syntax error near Union, select I, and all that jazz. [23:38.830 --> 23:41.670] Here you've got Yellowstone database. [23:41.950 --> 23:43.490] This is Washington State University. [23:43.710 --> 23:49.230] And again, this is how they decided to display this information, by just putting SQL right up there. [23:49.650 --> 23:51.550] And you know, this is just madness. [23:51.890 --> 23:53.530] This is like, I have a store. [23:53.870 --> 23:54.990] Here's a cash register. [23:55.170 --> 23:57.490] Please take the products and put the cash in the cash register. [23:57.490 --> 23:58.430] I'll see you next week. [23:58.590 --> 23:58.650] Yeah? [23:58.850 --> 24:02.430] Did you just shoot these emails and drop the entire database? [24:04.310 --> 24:07.290] I certainly could, but that's just what I'm not going to do. [24:08.050 --> 24:11.250] And again, I found this all ready to go someplace I didn't develop. [24:11.590 --> 24:12.950] Otherwise, I'd be committing a crime. [24:13.150 --> 24:14.430] All I'm doing now is... [24:14.430 --> 24:17.270] You just commit a crime and doing it. [24:18.190 --> 24:18.610] No. [24:19.430 --> 24:21.610] I know that's not true. [24:21.810 --> 24:25.330] I could go to jail if I type commands up here and execute them. [24:25.410 --> 24:26.510] I'm totally violating the law. [24:26.650 --> 24:28.030] I'm executing code on their server. [24:28.610 --> 24:29.090] Well... [24:29.090 --> 24:29.690] You're not. [24:29.790 --> 24:31.090] What if it's executing code? [24:31.190 --> 24:32.130] No, no, no, no. [24:32.390 --> 24:32.770] We... [24:32.770 --> 24:34.550] No, this is actually extremely important. [24:34.770 --> 24:41.170] If I put in any commands up there, I'm executing code in excess of reasonable use of their... [24:41.170 --> 24:45.650] There's no way that that was the intended use of the site and I'm not going to be able to justify it in court. [24:45.770 --> 24:56.830] Now, they might not press charges, but they totally could press felony charges against me for computer trespass and they would logically win because I am typing in codes to do something on their server that they clearly never intended. [24:57.370 --> 25:01.830] And unless I have been hired by the company to perform pen test, I don't have the right to do that. [25:01.930 --> 25:02.430] Not legally. [25:02.670 --> 25:03.950] So, that's where I stop. [25:04.170 --> 25:09.870] And they say, I'm glad you brought this up because an enormous amount of people that call themselves white hats do not stop at this point. [25:10.450 --> 25:16.550] And then, they really have committed a crime and now your life is really difficult when you whine and say they punish you. [25:16.790 --> 25:20.530] If you actually stop committing crimes, you'll be a whole lot safer. [25:22.910 --> 25:23.790] Anyway, um... [25:23.790 --> 25:25.030] Alright, so... [25:25.030 --> 25:31.450] But this is a huge issue and I was amazed when I see how many people cannot understand that you just have to stop before you commit the crime. [25:33.350 --> 25:34.230] Anyway, um... [25:34.230 --> 25:34.710] What's that? [25:37.910 --> 25:38.340] Yeah. [25:43.340 --> 25:43.980] It is. [25:44.120 --> 25:46.420] It's actually getting code on their server, but I didn't put the code there. [25:46.560 --> 25:49.200] All I did was find a link somebody else had and click on it. [25:49.300 --> 25:54.600] If you were running, it's like having a key and then you said, hey, somebody told me that the key was lying outside that door. [25:55.340 --> 25:55.660] Um... [25:55.660 --> 25:57.740] I tried to open it and then told them, hey, open it. [25:57.960 --> 25:58.700] Well, that's right. [25:58.740 --> 26:01.060] So, I warned them at this point, but I don't think what I've done is illegal. [26:01.300 --> 26:05.200] And I certainly haven't been prosecuted or anything for it, but I did get some in various forms of trouble though. [26:05.500 --> 26:10.960] I'm pretty sure I'm allowed to click a link that somebody else posts and you can't prosecute me if that link does something you don't like. [26:11.600 --> 26:18.540] But I certainly can't go hacking into the server by putting in commands where I know they're going to be executed without authorization. [26:20.440 --> 26:22.760] If the link dropped the whole database, that would be fine. [26:23.120 --> 26:24.820] Like that one link dumped out the password. [26:25.120 --> 26:26.360] I would never dare do that. [26:26.620 --> 26:26.700] Yeah. [26:41.470 --> 26:41.830] Yeah. [26:51.540 --> 26:52.680] Well, no, no. [26:52.860 --> 26:54.540] Actually, I'm glad you brought this up. [26:54.660 --> 26:59.180] So, suppose I take that previous one that showed the password hash and I crack the hash. [26:59.580 --> 27:00.900] Now, I think I'm allowed to do that. [27:01.440 --> 27:03.840] If I then log in with the hash, I've now totally broken the law. [27:04.020 --> 27:06.160] Because I've logged in with somebody else's credentials. [27:06.460 --> 27:07.640] This is like breaking enter. [27:07.740 --> 27:08.460] You're picking a lock. [27:08.620 --> 27:13.740] I'm allowed to examine what other people post and what their site puts out when you click on a link. [27:13.820 --> 27:16.760] But I'm not allowed to use it to go in where I know I don't belong. [27:17.700 --> 27:18.020] Yeah? [27:18.260 --> 27:20.420] Can you tell them to crash the password? [27:20.940 --> 27:21.680] Tell them that I what? [27:23.800 --> 27:25.600] Well, I would have told them, yes. [27:25.780 --> 27:33.140] If I could crack the password, I would say, not only have you got a hash leaking, but in fact, that hash can be cracked. [27:33.360 --> 27:36.420] But I was never able to even get to that level of intelligence discourse with them. [27:36.660 --> 27:38.120] There seems to be just nobody at the other end. [27:38.700 --> 27:39.040] Anyway. [27:51.860 --> 27:52.260] No. [27:53.160 --> 27:57.020] What you said is, is it a breach if I log in with someone else's credentials? [27:57.300 --> 28:06.140] And I would say, probably not a breach in the sense that they have to go through breach notification process, but it is certainly a crime and it's certainly a security event at their end. [28:06.480 --> 28:15.020] They will then have to spend a bunch of work trying to decide whether I took the confidential data out and how much trouble they're in, but I am hopelessly on the wrong side of the law now. [28:15.020 --> 28:20.180] I have totally taken a key I shouldn't have had and used it to go in where I knew I wouldn't belong. [28:20.400 --> 28:22.220] Yes, I thought it was not to accept all of them. [28:22.360 --> 28:23.060] Yeah, it's a crime. [28:23.200 --> 28:24.500] It's a crime, but it's not necessarily a breach. [28:24.700 --> 28:27.340] It's very important though, and I have a lot of issues. [28:27.500 --> 28:28.340] A gray area, but [28:33.140 --> 28:35.880] you're executing their code. [28:36.520 --> 28:38.280] Whether or not you construct a clear area. [28:38.280 --> 28:39.660] Well, well, we'll go ahead a bit. [28:40.140 --> 28:47.960] I think there is definitely a gray area, and I always try to stay completely on the white side because I have, I represent a college that has deep pockets. [28:48.240 --> 28:52.940] So the point is, people tell me, why don't you like download pirate stuff and have more goodies for your students in the lab? [28:52.980 --> 28:54.740] And I wouldn't even let them download pirate MP3s. [28:54.760 --> 28:56.400] If you're going to do that, you've got to do it at home. [28:56.600 --> 29:00.420] Now I know, it's not destroying the world, and you're not really going to get a felony. [29:00.600 --> 29:03.120] You're just going to end up getting a letter saying you have to pay a fine or something. [29:03.300 --> 29:08.980] But I can't do anything even a little shady on campus in part of my class because the college gets sued for that. [29:09.140 --> 29:12.060] So anything I do, I want to make sure it's 100% legal. [29:12.840 --> 29:15.840] So here's Brigham Young, for example, their SQL syntax open. [29:16.160 --> 29:20.240] So again, about a quarter of these guys fixed them, and then the error rate fell to zero. [29:20.380 --> 29:22.920] So I just published all the links and everything, and nobody cares. [29:24.600 --> 29:28.980] So then, but I put this stuff on Twitter, and some people saw it, and so people started sending me stuff. [29:30.340 --> 29:32.940] And Steven Veldkamp sent me his server logs. [29:32.960 --> 29:34.600] See, he got attacked with a denial of service. [29:34.920 --> 29:40.480] He got a big spike of traffic on one day here, and those things are all coming from WordPress bots. [29:40.720 --> 29:43.160] And he had the URLs and the IP addresses for them all. [29:43.280 --> 29:46.060] So I've looked through them and found them, and I notified all those people. [29:47.860 --> 29:50.180] By the way, I made a mistake in my notification. [29:50.460 --> 29:52.240] I had like 2,000 people notify. [29:52.560 --> 29:54.600] I said, I don't know how to send 2,000 emails. [29:54.900 --> 29:58.180] I could try to figure out how to run some kind of mail merge, but I'm not sure I want to do that. [29:58.180 --> 30:01.740] I sent out like 100 addresses at a time, like 20 emails. [30:02.220 --> 30:04.000] And I put them all in the 2 column. [30:04.580 --> 30:09.520] This is not good because some of them will start replying all and then you've got a bunch of spam. [30:09.740 --> 30:12.480] You know, so I should have put it in BCC and a bunch of them yelled at me about that. [30:12.600 --> 30:13.080] Yeah, okay. [30:13.900 --> 30:19.920] Anyway, one thing to know is whenever you do this, somebody's going to yell at you, no matter what you do. [30:20.160 --> 30:21.940] It's like you're telling them something they don't want to hear. [30:22.400 --> 30:24.640] So some of them are going to say, why did you tell us that way? [30:24.740 --> 30:25.620] Why didn't you tell us some other way? [30:25.700 --> 30:27.280] But anyway, you've got to have a thick skin. [30:27.280 --> 30:30.520] But as far as I can tell, you need a pretty thick skin to have anything to do with the hacking anyway. [30:31.120 --> 30:36.580] So I found out, this turned out to be the ping back vulnerability which WordPress has known about for seven years and they don't care. [30:36.700 --> 30:37.160] They like it. [30:37.400 --> 30:42.740] If you want a WordPress blog, you can send a packet to it which will then reply to a third party concealing your identity. [30:42.900 --> 30:46.720] It doesn't amplify the size by much, but it can be used to bounce things off. [30:46.880 --> 30:51.640] So the guy that sent me this traffic, I notified these people, they ran around figuring out what was going on. [30:52.720 --> 30:53.960] But they couldn't do much about it. [30:53.960 --> 30:59.840] Each individual WordPress user can turn off this feature, but the next time you update WordPress, it will automatically turn it back on again. [31:00.780 --> 31:02.340] WordPress really likes it for some reason. [31:03.380 --> 31:05.780] So here's the service that's being used, called NetSpoof. [31:05.880 --> 31:08.500] You can go here and pay these guys money to get various attack tools. [31:09.520 --> 31:09.840] Here they are. [31:09.900 --> 31:12.160] In NetSpoof they have all these different attacks they can perform. [31:12.600 --> 31:18.000] And the cheapest one, is renting those 2,000 WordPress bots to bounce things off of. [31:19.020 --> 31:19.620] So you can... [31:19.620 --> 31:25.740] WordPress is providing a convenient DDoS in anonymization utility, sort of like Tor, for us to use, to attack people. [31:27.080 --> 31:28.660] And they know it, and they don't care. [31:28.760 --> 31:30.180] They've known it for seven years and they won't fix it. [31:30.760 --> 31:33.600] Anyway, so then open DNS resolvers will do the same thing. [31:33.740 --> 31:37.400] People can send DNS requests and they can amplify things by a pretty large amount here. [31:37.520 --> 31:38.840] Like maybe up to 40 or 50 times. [31:39.180 --> 31:41.280] So these are used for really big DDoS attacks. [31:41.280 --> 31:45.260] And there's an open DNS project that lists all the open DNS resolvers. [31:45.400 --> 31:47.980] So I went through them and I found all the U.S. colleges on the list. [31:48.060 --> 31:52.460] Because I primarily focus on them just because I feel like I have some communication with colleges. [31:52.600 --> 31:54.480] And I kind of understand how things work at colleges. [31:55.280 --> 31:56.960] So here's the list of the ones I found. [31:57.140 --> 31:57.580] Some of them. [31:57.780 --> 31:59.060] And I notified a bunch of them. [31:59.160 --> 32:00.160] And that did have some... [32:00.160 --> 32:02.580] maybe 38% decrease in open resolvers. [32:02.760 --> 32:08.580] Only two colleges, out of the list of about 50 Icent, actually have no open resolvers anymore. [32:08.900 --> 32:11.640] But most of them decreased the number of their open resolvers. [32:11.940 --> 32:12.720] Which is kind of strange. [32:13.160 --> 32:17.800] Now I got a list from Cloudflare, with very kind of cooperation, of people doing NTP amplification. [32:18.500 --> 32:19.620] Which is really nasty. [32:19.760 --> 32:21.380] Like a hacker of 110 amplification. [32:21.660 --> 32:23.280] And I was going to notify those guys. [32:23.460 --> 32:25.160] But in fact, most of them noticed anyway. [32:25.600 --> 32:29.140] When people use your servers in an attack like that, they freeze your whole network. [32:29.520 --> 32:34.180] So you don't really need some idiot professor writing you next week telling you that a bad thing happened. [32:34.580 --> 32:35.900] Most of them figured it out by themselves. [32:36.620 --> 32:39.600] So anyway, then I decided to try insecure login pages. [32:40.260 --> 32:42.660] Now, I thought, how many people... [32:42.660 --> 32:44.940] How long has it been since they invented HTTPS? [32:45.620 --> 32:47.660] You know, how many people would really do this? [32:48.120 --> 32:50.360] You wouldn't think big name people would do this. [32:53.740 --> 32:55.320] Let's open up Wireshark and... [32:56.260 --> 32:59.620] Let's take a look at say, Johns Hopkins University. [33:00.640 --> 33:05.580] Which seems to me like they have not only usual security issues, but also HIPAA compliance issues. [33:05.780 --> 33:06.980] But what do I know? [33:07.400 --> 33:09.000] So, um... [33:09.000 --> 33:09.580] Let's not worry. [33:09.660 --> 33:10.660] Let's just start sniffing. [33:12.000 --> 33:13.960] And let's look only at frames. [33:16.920 --> 33:17.460] Contains... [33:17.460 --> 33:18.280] Hope. [33:20.120 --> 33:20.660] Okay. [33:21.000 --> 33:23.180] And then let's log in with username idiot. [33:25.420 --> 33:26.780] And password hope. [33:27.880 --> 33:28.420] Rocks. [33:29.300 --> 33:30.300] And log in. [33:31.360 --> 33:31.680] Okay. [33:32.240 --> 33:32.960] And there it is. [33:33.940 --> 33:39.880] So, Johns Hopkins University is sending my password up in this delightful fashion. [33:40.040 --> 33:41.380] Password hope rocks, you know. [33:41.500 --> 33:42.420] So, um... [33:43.200 --> 33:44.600] This is like... [33:45.620 --> 33:46.920] And, you know, you got... [33:46.920 --> 33:47.680] These are a lot... [33:47.680 --> 33:48.920] These are all over the bloody place. [33:49.120 --> 33:51.300] Here's Stanford doing the same thing. [33:51.660 --> 33:53.060] And here's the list of them. [33:53.400 --> 33:56.240] Now, really, a lot of people have learned what HTTPS is. [33:56.240 --> 33:57.380] Like 91%. [33:57.380 --> 34:00.540] There's only 9% of login pages I could find. [34:00.660 --> 34:01.320] I surrounded them on Google. [34:01.680 --> 34:04.480] Here's the 90 vulnerable colleges I found like six months ago. [34:04.660 --> 34:05.800] And there's quite a few big ones. [34:05.900 --> 34:08.380] So, I checked them yesterday morning, early at Starbucks. [34:08.720 --> 34:10.240] And this is how many of them fixed it. [34:10.680 --> 34:11.740] Not very many. [34:12.960 --> 34:21.780] These are the mixed mode, HTTPS, on an HTTP page, which is only a little bit better, because you all know you can hit that thing with SSL strip or a bunch of other tricks. [34:21.860 --> 34:23.800] This is almost as bad as plain text. [34:24.100 --> 34:26.140] But I notified them and a small number of them fixed it. [34:26.260 --> 34:27.120] Well, it's... [34:27.120 --> 34:27.480] What do you do? [34:28.500 --> 34:28.820] Um... [34:28.820 --> 34:31.980] Like I said, you've got to have low expectations when you're going to do this white-heading stuff. [34:33.180 --> 34:33.500] Um... [34:33.500 --> 34:34.700] A lot of big names are out there. [34:34.860 --> 34:35.920] A lot of people don't care. [34:36.440 --> 34:36.760] Um... [34:36.760 --> 34:38.200] So, again, notice these numbers. [34:38.280 --> 34:39.180] 28% have fixed it. [34:39.260 --> 34:40.220] 24% have fixed it. [34:40.220 --> 34:41.340] That's about what you're going to get. [34:41.460 --> 34:45.200] 20% to 30% response of people doing anything when you tell them. [34:46.100 --> 34:46.460] Um... [34:46.460 --> 34:49.060] So then, I was on the team to review DEFCON talks. [34:49.180 --> 34:50.500] Not this DEFCON, but the previous one. [34:50.600 --> 34:51.900] Which was a very interesting task. [34:52.540 --> 34:55.280] And one of the talks was about this thing called ActiveMQ. [34:55.460 --> 34:56.720] And I didn't even know what it was. [34:57.060 --> 34:57.860] So I read their proposal. [34:58.040 --> 35:03.440] They say, ActiveMQ is middleware used to connect one computer system to another and it's often deployed in a terrible, insecure way. [35:03.540 --> 35:04.920] And I said, I never heard of it. [35:05.000 --> 35:06.340] Let me just see if I can find some. [35:06.440 --> 35:09.400] So I went to Shodan and I found some ActiveMQ servers. [35:09.400 --> 35:12.420] It turns out ActiveMQ listens on port 8161. [35:12.600 --> 35:13.340] So I went there. [35:13.440 --> 35:16.040] And I found some website with a bunch of data. [35:16.240 --> 35:17.820] And there was no login anywhere. [35:18.000 --> 35:18.880] You could just see the data. [35:19.000 --> 35:21.260] You could alter the data, delete the data, watch it go by. [35:21.820 --> 35:24.100] You're apparently DEFCON logged in as administrator. [35:24.420 --> 35:27.400] So here's their log showing records going by. [35:27.460 --> 35:30.180] And when I looked at the records, the records were checks. [35:30.900 --> 35:32.600] Printing checks for health insurance. [35:33.460 --> 35:36.580] Now I found an abbreviation here. [35:36.860 --> 35:39.000] Which was like a four letter abbreviation for the company. [35:39.220 --> 35:41.640] And I couldn't figure out what company it was for a couple days. [35:41.820 --> 35:43.460] And then I Googled around until I found it. [35:43.520 --> 35:44.300] I found the company. [35:44.420 --> 35:48.940] It was a Canadian company that was sending their records to Texas to be printed. [35:49.260 --> 35:50.880] And they were going from some computer to another. [35:51.020 --> 35:53.640] And in an intermediate step that was wide open to the Internet with no password. [35:53.860 --> 35:55.640] So you could just modify it as the checks went by. [35:55.640 --> 35:58.300] So I said, you know, it seems like I really ought to tell somebody about this. [35:59.300 --> 36:04.460] So what I did was, I sent an email to the developer and to the customer. [36:04.780 --> 36:09.460] Saying, hey guys, you might be interested to the insurance company and the developer that designed it. [36:09.520 --> 36:12.620] Because I found the name of the developer that designed it and the company they worked at. [36:12.800 --> 36:17.980] And I even found the blog post from three years ago with that developer saying, I'm having trouble with ActiveMQ. [36:18.060 --> 36:19.580] Does somebody know how to get this password working? [36:20.460 --> 36:22.080] So I sent them an email. [36:22.800 --> 36:25.820] And so I sent it to the developer and to the client. [36:26.000 --> 36:27.500] Saying, this will probably get some attention. [36:27.740 --> 36:28.660] And it totally did. [36:28.900 --> 36:30.940] I immediately got, thanks, I'll fix that right away. [36:31.180 --> 36:33.620] And all I said was, you know, you should at least put it behind a VPN. [36:33.820 --> 36:35.660] If you're going to have this tiny nonsense going on. [36:36.200 --> 36:37.640] And next time I looked, it was gone. [36:37.800 --> 36:39.640] They put it behind something, turned it off, you know. [36:40.300 --> 36:41.260] And so that was great. [36:41.360 --> 36:44.540] So I said, I'm glad to see effective results coming out of this. [36:44.640 --> 36:45.300] So I feel pretty good. [36:45.440 --> 36:47.700] So next time I came across a small Canadian developer. [36:49.100 --> 36:50.120] I was at a conference. [36:50.120 --> 36:51.560] I don't know if this ever happened to anyone. [36:51.900 --> 36:53.200] I was going to talk and the talk sucked. [36:53.360 --> 36:54.180] So I had nothing to do to do. [36:54.260 --> 36:55.280] So I played around on my computer. [36:55.660 --> 36:56.500] So I did like I usually do. [36:56.600 --> 36:58.640] Go to a paste bin and see what the criminals are doing. [36:59.160 --> 37:01.440] And I found a bunch of these SQL injection websites. [37:01.660 --> 37:02.320] And I looked at it. [37:02.420 --> 37:06.580] And one of them at the bottom said, developed by web smart developers. [37:06.760 --> 37:07.280] And I said, really? [37:07.360 --> 37:09.120] I wonder how many other ones are developed by this guy. [37:09.660 --> 37:12.460] And it turned out 100,000 are developed by this guy. [37:12.580 --> 37:13.440] And they all have SQL injections. [37:14.420 --> 37:19.220] So I said, you know, now I'm thinking, how do I send 100,000 emails? [37:19.400 --> 37:20.080] Should I even try? [37:21.520 --> 37:22.840] What should I do about this? [37:22.960 --> 37:23.900] So I thought about it. [37:24.000 --> 37:25.680] And so I sent the first loop, just like the last one. [37:25.840 --> 37:26.620] I sent them a note. [37:26.720 --> 37:29.860] And I sent it to like, I tried 14 right there while sitting in a boring talk. [37:30.060 --> 37:32.180] And out of the first 14 I tried, 11 were vulnerable. [37:32.360 --> 37:35.220] So I contacted those 11 and the developer. [37:35.560 --> 37:38.440] And said, hey, I think the rest of them might be vulnerable too. [37:38.440 --> 37:39.440] And you really ought to look at this. [37:39.760 --> 37:42.940] So this guy did not respond well. [37:43.180 --> 37:46.180] He doesn't appreciate me contacting clients directly. [37:46.540 --> 37:47.660] That's very unprofessional. [37:48.240 --> 37:48.960] I had an ultimatum. [37:48.980 --> 37:51.020] See, I thought I would tell him, you know, I'm not going to sit on this forever. [37:51.160 --> 37:52.880] I'm going to wait like a week and then I'm going to tell the press. [37:53.820 --> 37:55.040] Or two weeks or something, I said. [37:55.160 --> 37:55.880] That was terrible. [37:55.940 --> 37:56.660] You didn't want to hear that. [37:57.360 --> 37:58.240] My scare tactics. [37:58.360 --> 37:59.920] He's going to notify my superiors. [37:59.960 --> 38:01.320] I have no right or authority here. [38:01.420 --> 38:05.040] Now, I don't need authority to send an email to some guy in Canada. [38:05.140 --> 38:06.200] He can just throw it away. [38:06.660 --> 38:07.620] Especially if it's true. [38:08.020 --> 38:10.680] I do not understand why this guy thinks he owns his customers. [38:10.760 --> 38:12.920] And they are like his children to be protected from my abuse. [38:14.040 --> 38:17.520] Anyway, any further correspondence must be directed only to him. [38:18.080 --> 38:20.200] And you go outside to mandate his employer. [38:20.360 --> 38:22.480] So I said, did I really step out of line here? [38:22.560 --> 38:24.100] I mean, I thought I was doing the right thing. [38:24.300 --> 38:26.060] But I've never touched anything this big. [38:26.160 --> 38:27.120] 100,000 customers. [38:27.440 --> 38:30.400] So I contacted people I knew that were famous in the industry. [38:31.220 --> 38:35.240] Somebody at a huge company with experience know what I should do here. [38:35.980 --> 38:37.140] I contacted journalists. [38:37.420 --> 38:38.180] Most of them ignored me. [38:38.260 --> 38:39.620] One of them said, well, you didn't work with the developer. [38:39.780 --> 38:40.060] You're wrong. [38:40.220 --> 38:41.820] I said, but, but... [38:43.200 --> 38:44.520] Anyway, so they mostly ignored me. [38:44.580 --> 38:46.900] One gave me a very nice, very polite letter. [38:47.020 --> 38:50.000] And I looked at that and said, boy, I really don't feel this nice towards this guy. [38:50.640 --> 38:51.680] But you're the pro. [38:51.860 --> 38:52.640] I'll try it your way. [38:52.740 --> 38:53.380] So there's this letter. [38:53.680 --> 38:54.860] I'm happy you responded. [38:55.020 --> 38:56.160] We got off on our own foot. [38:57.420 --> 38:58.580] I felt it was reasonable. [38:58.740 --> 38:59.920] Let's move forward cooperatively. [39:00.140 --> 39:02.820] And I said, I got a bad feeling about being nice to this guy. [39:03.040 --> 39:04.700] I think it's like being nice to a prison bully. [39:05.440 --> 39:07.700] And what happened is this made him madder than ever. [39:08.680 --> 39:10.120] Which is kind of what I thought would happen. [39:10.400 --> 39:14.360] After that, he sent me a response saying, you're the real sand bound. [39:14.480 --> 39:16.300] Somebody's impersonating you, harassing me. [39:16.480 --> 39:17.500] This can't really be you. [39:17.500 --> 39:21.280] And then, without telling me, contact my department chair to begin trying to get me fired. [39:21.440 --> 39:23.960] Now, thankfully, this is not my first rodeo. [39:25.900 --> 39:27.540] In 2011, I got in a lot of trouble. [39:27.660 --> 39:28.820] Several people tried to get me fired. [39:28.880 --> 39:30.360] From Gregory Evans to a bunch of other people. [39:30.680 --> 39:31.840] Send emails to everybody. [39:31.920 --> 39:33.440] Tell them I was a racist and whatever they want. [39:33.760 --> 39:36.360] And I warned everybody at the IT department administration. [39:36.540 --> 39:37.860] This is going to keep happening. [39:38.280 --> 39:39.380] Just get used to it. [39:39.980 --> 39:41.500] And pretty much they've gotten used to it. [39:41.560 --> 39:43.400] That guys are always trying to get me fired. [39:43.400 --> 39:44.860] So they pretty much didn't pay attention. [39:46.020 --> 39:49.400] But I did hold off a few days to meet with them to make sure they get a chance. [39:49.580 --> 39:51.620] So anyway, then I decided to go back and search. [39:51.720 --> 39:54.780] Got my students looking through how many other websites are out there. [39:54.780 --> 39:55.840] What do we do with 100,000? [39:55.960 --> 39:58.060] And I thought maybe we could find the most important ones somehow. [39:58.200 --> 40:01.240] The government agencies, the schools, or something like that. [40:01.380 --> 40:07.680] And then I found that there were prior reports already in 2010 and 2012 of people finding all these and publishing them. [40:07.760 --> 40:09.060] So the bad guys already know. [40:09.760 --> 40:13.220] So I said, at this point, I'm not worried about maintaining secrecy anymore. [40:13.220 --> 40:15.160] I just published the whole thing on my website. [40:16.660 --> 40:18.900] And anyway, he screamed bloody murder. [40:19.020 --> 40:22.140] He found some journal to write a big article about what a rotten guy I am. [40:22.700 --> 40:23.940] But there's enough of them out there. [40:24.020 --> 40:24.660] I can get used to it. [40:25.940 --> 40:28.540] And anyway, now 10 of the original 11 have finally been fixed. [40:28.780 --> 40:30.540] So he is fixing his stuff eventually. [40:30.780 --> 40:31.620] So I guess it worked. [40:31.840 --> 40:35.020] But anyway, that's the harassment you get. [40:35.140 --> 40:36.960] And I'm just, I'm extremely invulnerable. [40:36.960 --> 40:39.080] I mean, I have tenure at a college, as you may be aware. [40:39.220 --> 40:41.020] You can do anything once you have tenure at a college. [40:41.160 --> 40:45.640] You can, you can give the students LSD and have sex with them and call it research. [40:45.940 --> 40:47.320] And get away with this for years. [40:49.680 --> 40:51.660] So I'm not going to get fired for this stuff. [40:53.520 --> 40:56.060] But not very many people are in a position of such power. [40:57.520 --> 41:00.940] So I mentioned, if you do it the wrong way, you get in a world of hurt. [41:00.940 --> 41:02.560] And here's a couple of cases where that happens. [41:02.720 --> 41:05.260] This guy is VoodooCobra on Twitter. [41:05.940 --> 41:12.900] And he, when, back when LulzSec was hacking into the FBI, he tried to check his local chapter of InfraGuard. [41:13.020 --> 41:14.140] And he found a vulnerability. [41:14.520 --> 41:17.160] So he went on there and downloaded stuff. [41:17.360 --> 41:18.740] And then contacted them. [41:19.620 --> 41:21.200] And they prosecuted him. [41:21.260 --> 41:24.400] Because at that point, the FBI was really, really sore about LulzSec. [41:24.560 --> 41:28.020] And you couldn't tell them you hacked the FBI and expect them to say thank you at that point. [41:28.740 --> 41:30.800] So they prosecuted him and he got a felony. [41:30.980 --> 41:33.020] So he, I was on Twitter talking about this white hat stuff. [41:33.160 --> 41:34.480] And he said, never do this. [41:34.760 --> 41:35.640] Never tell people. [41:35.780 --> 41:36.900] They will just throw you in jail. [41:36.900 --> 41:37.920] They're a bunch of rotten bums. [41:38.020 --> 41:39.020] And I said, why do you say that? [41:39.200 --> 41:40.940] He said, I got a story I could tell you. [41:41.020 --> 41:42.140] I said, fine, email it to me. [41:42.360 --> 41:43.800] It's like two hours later, I got this email. [41:44.720 --> 41:45.280] Very clear. [41:45.460 --> 41:47.340] I said, man, you should just send that to 2600. [41:47.680 --> 41:48.740] He said, they wouldn't publish it. [41:48.800 --> 41:49.500] I said, sure they would. [41:49.540 --> 41:49.940] And they did. [41:50.000 --> 41:50.960] It was in a couple issues ago. [41:51.360 --> 41:52.360] And he's a very good writer. [41:52.400 --> 41:54.440] So I started hiring him to write technical projects for me. [41:54.840 --> 41:55.820] He used to work at a college. [41:55.840 --> 41:56.420] He's a cool guy. [41:56.420 --> 41:59.640] And I don't think he's a rotten guy because you hacked the FBI. [41:59.940 --> 42:01.500] I think he kind of learned to quit doing that. [42:03.380 --> 42:04.680] And so here's another guy, Storm. [42:04.780 --> 42:06.900] This guy was 18 years old in New Zealand. [42:07.040 --> 42:10.080] He started hacking universities, which is the kind of stuff I'm talking about. [42:10.100 --> 42:10.860] Although I stopped. [42:10.980 --> 42:11.960] See, before I break the law. [42:12.340 --> 42:13.020] But he didn't. [42:13.160 --> 42:19.440] He broke into universities, dumped out all their data, went back in after they said they patched it to prove they didn't patch it and so on. [42:19.540 --> 42:22.680] And then he went on the media and started giving interviews. [42:23.300 --> 42:26.020] Then he said, if they're going to arrest me for helping people, lock me up forever. [42:26.020 --> 42:27.640] And I'm saying, it just hurts, you know. [42:27.760 --> 42:28.820] I've got students like this. [42:29.080 --> 42:30.140] This is what I'm there for. [42:30.220 --> 42:32.680] To stop my students from doing self-destructive things like this. [42:32.760 --> 42:34.600] Say, look, I know you're brilliant. [42:34.760 --> 42:35.840] I know you want to change the world. [42:36.040 --> 42:37.480] This is not the way to do it. [42:38.860 --> 42:44.020] And if you get a felony on your record, you're going to cripple yourself as you try to get real jobs later and have somebody trust you. [42:44.020 --> 42:45.100] So I called him. [42:45.260 --> 42:46.040] I went on Twitter. [42:46.180 --> 42:46.940] I said, talk to me on Skype. [42:47.060 --> 42:48.280] So I talked to him for about a half hour. [42:48.640 --> 42:50.220] And I talked, you've got to knock this off. [42:50.320 --> 42:50.820] I said, what you're doing? [42:50.820 --> 42:51.640] You're playing Russian Roulette. [42:51.760 --> 42:55.480] He had a website with all these people he tested and then he listed his clients. [42:55.640 --> 42:57.940] And I said, what's going on here is those are your victims. [42:58.260 --> 42:59.520] Those are not your clients. [42:59.860 --> 43:01.720] They didn't authorize your tests. [43:02.100 --> 43:04.820] You hacked into them and they didn't happen to press charges. [43:04.820 --> 43:05.980] But this is Russian Roulette. [43:05.980 --> 43:09.820] You're just waiting for the one that will press charges and then you're going down. [43:10.040 --> 43:11.880] And on top of that, he dropped his anonymity. [43:12.020 --> 43:13.020] He published his real name. [43:13.980 --> 43:20.420] And I said, look, there are clowns like the Jester that do this and you can't stop him because you can't find him. [43:20.640 --> 43:24.040] And then there are people like me that put their real name on everything and don't break the law. [43:24.280 --> 43:29.120] Now, if you do both of these things at the same time, this is not a successful strategy. [43:29.600 --> 43:30.960] You've got to do one or the other. [43:31.540 --> 43:34.160] So if you're going to put out your real name, you've got to quit breaking the law. [43:34.260 --> 43:34.880] That's how it works. [43:34.880 --> 43:35.860] So he said he would. [43:36.000 --> 43:39.060] And the next day he said, ah, Sam Brown is an arrogant asshole telling me what to do. [43:39.160 --> 43:40.280] I'll just go on and do it again. [43:40.660 --> 43:44.800] So I contacted somebody in New Zealand I knew and said, maybe you'd like to hire this guy. [43:44.880 --> 43:46.040] So we offered him a job. [43:46.460 --> 43:48.020] But of course, you've got to go straight first. [43:48.180 --> 43:48.840] And that did it. [43:49.740 --> 43:53.740] So anyway, I'd like to snatch these guys back from the jaws of disaster if possible. [43:54.540 --> 44:02.860] Because, you know, if he had a sane structure, you know, if he had a sane structure, it wouldn't be the end of the world for people to do this hacking. [44:02.860 --> 44:06.340] But, you know, we need to respect these people. [44:06.480 --> 44:07.860] So anyway, I'll just mention another one. [44:07.940 --> 44:14.120] Ryan Satterfield is a guy who contacted me on Twitter two days ago, or three days ago, and told me about a major website. [44:14.300 --> 44:15.700] He had a major news organization. [44:16.640 --> 44:21.860] And he said, these clowns are using WordPress 3.4.1, two years out of date. [44:21.980 --> 44:25.600] Now, as you may be aware, WordPress all by itself is pretty much a security nightmare. [44:26.400 --> 44:30.280] Using WordPress that's two years old is like just begging for it. [44:30.360 --> 44:31.920] Like having SQL injection right in the URL. [44:32.580 --> 44:35.340] And he said, I called them and they just screamed at me. [44:35.440 --> 44:36.540] They said, we don't need your help. [44:36.680 --> 44:37.240] Go away. [44:37.340 --> 44:37.980] Who are you anyway? [44:37.980 --> 44:41.320] And I said, boy, well, I contacted the CEO of the whole company on Twitter. [44:41.540 --> 44:42.260] He followed me. [44:42.320 --> 44:42.920] I sent him the message. [44:42.960 --> 44:44.060] He said he was going to do something. [44:44.500 --> 44:45.620] So far, nothing happened. [44:46.760 --> 44:52.260] I'm not... I've censored this slide because I'm not yet ready to like publish all this and humiliate them exactly yet. [44:52.380 --> 44:55.320] It's only been a few days, but that time will probably come. [44:57.320 --> 44:58.940] Anyway, I think I ran out of slides. [44:59.680 --> 45:01.320] And it looks like I about ran out of time too. [45:01.320 --> 45:03.340] So if you got any questions, feel free. [45:03.500 --> 45:05.540] If somebody can turn on the lights so I can see people, that might be good. [45:16.580 --> 45:19.080] But I really appreciate the questions that already went by. [45:19.180 --> 45:20.320] You already hit on the topic points. [45:20.420 --> 45:21.740] This is a huge issue. [45:21.860 --> 45:24.200] People don't know where the law is. [45:24.340 --> 45:25.100] I don't get it. [45:25.200 --> 45:27.840] I guess my parents raised me worried about breaking the law more than other people. [45:28.000 --> 45:28.100] Yeah. [45:28.620 --> 45:31.680] Actually, an interesting legal question I have that you might know the answer to. [45:31.780 --> 45:39.480] If you disclose responsibly a vulnerability to, you know, let's say a bank, something really big, right? [45:39.840 --> 45:41.120] And you disclose this. [45:41.280 --> 45:42.280] And they just say, ah, screw off. [45:42.400 --> 45:43.120] We don't need your help. [45:43.280 --> 45:51.700] And then six, 12 months later, there's a huge loss of, you know, data, money, etc. [45:51.940 --> 45:57.060] Do you know, has anyone ever been held accountable for ignoring that? [45:59.740 --> 46:02.500] No, I'm not aware of a case like that. [46:02.660 --> 46:06.200] I do know, you know, Maricopa College thing was very close to that. [46:06.200 --> 46:14.160] And I think I heard that Facebook got sued for having their entire user database under, behind the password happiness so it all got stolen. [46:15.140 --> 46:22.260] I mean, there is, we may have, you know, if you just had a bank and you didn't close the vault at all and just left it hanging open and somebody stole the money, you would get sued. [46:23.220 --> 46:28.120] And we're getting to the point where there will actually be some kind of minimum responsibility required or you get punished. [46:29.020 --> 46:30.620] You remind me of something all important. [46:30.960 --> 46:41.340] Last week, or a couple of weeks ago, I was looking around on the Internet and I found an FTP server that had a defacement, a single file called Woot, with like 10 zeros in the middle, was on the FTP server. [46:41.560 --> 46:44.360] And I searched and there was like, this is happening in Microsoft FTP servers. [46:44.560 --> 46:47.280] There's about 150 of them with this Woot file on them. [46:47.400 --> 46:50.180] It's some kind of attack and I don't know exactly how it works. [46:50.180 --> 46:54.620] But so I looked at a university with the Woot file and then I said, ah, you've been defaced. [46:54.740 --> 46:55.540] You've got a Woot file on here. [46:55.620 --> 46:57.260] And then I said, what are these other files on here? [46:57.320 --> 46:58.920] And they were medical data from patients. [46:59.040 --> 47:00.020] It was a medical teaching college. [47:00.240 --> 47:01.060] Thousands of records. [47:01.400 --> 47:05.420] I said, well, you know, I was going to tell you about that Woot file, but let's just forget about that. [47:06.020 --> 47:07.860] And this is why I gained respect for HIPAA. [47:08.080 --> 47:11.720] Now, a lot of people in security communities say HIPAA is no good because it doesn't mean you're secure enough. [47:11.800 --> 47:14.000] But what it means is somebody cares. [47:14.280 --> 47:19.120] I sent an email to their HIPAA compliance office and that thing was down in four hours. [47:20.000 --> 47:22.440] So that's what the benefit of compliance is. [47:22.700 --> 47:23.900] It means that somebody is listening. [47:24.220 --> 47:26.500] Anyway, go ahead. [47:27.540 --> 47:33.700] If you haven't dealt with an independent software vendor that treats their customers like their property before, you haven't been around that much. [47:34.260 --> 47:35.420] They all tend to do that. [47:35.880 --> 47:42.760] However, my actual point was it goes without saying that you need to communicate very clearly when you're reporting these. [47:42.920 --> 47:44.080] I think you have, obviously. [47:44.340 --> 47:50.720] But I got, of all things, emails from AWS a while back where they said, you have a SMTP relay open. [47:50.880 --> 47:51.480] No, I don't. [47:51.640 --> 48:01.500] We went back and forth like 16 times and finally like, oh, we actually made you have an open resolver, but every single email we sent you up to this point actually said, open SMTP relay. [48:01.620 --> 48:01.960] Oh, yes. [48:02.100 --> 48:05.860] Because they tried to, you know, overload the one process with a different vulnerability. [48:06.500 --> 48:07.220] Also, you need to... [48:07.220 --> 48:07.700] Yeah, that's a huge issue. [48:07.920 --> 48:09.000] You need to communicate in writing. [48:09.000 --> 48:20.280] One time I verbally reported a vulnerability to a business partner site and then with their vacs then they tried to get me fired because, you know, I actually bothered to log in with slash no command on VMS or something. [48:20.580 --> 48:20.660] Whatever. [48:21.240 --> 48:23.060] Well, you remind me of something else I wanted to mention. [48:23.240 --> 48:29.260] I recently found a vulnerability in a bunch of routers and I made a video showing it and that is extremely effective. [48:29.480 --> 48:31.920] I don't hate videos myself because everywhere I go is too noisy. [48:32.380 --> 48:33.780] I like pages with instructions. [48:34.000 --> 48:34.620] Nobody reads that. [48:34.620 --> 48:35.820] I made like three-minute video. [48:35.920 --> 48:37.260] Here I am trashing your router. [48:37.700 --> 48:39.680] Man, in one day they were able to reproduce it. [48:39.860 --> 48:43.680] When I send in something with like ten steps on a page, they say, our team can't reproduce it. [48:43.980 --> 48:45.600] So, man, I've learned my lesson. [48:45.780 --> 48:47.980] I'm sending in video phone reports these days. [48:48.140 --> 48:48.180] Yeah. [48:51.160 --> 48:59.100] This kind of brought up something interesting which is that I probably have, you know, signed up for things that are run by morons. [48:59.920 --> 49:00.160] And... [49:00.160 --> 49:00.700] We all have. [49:00.840 --> 49:03.680] I have a couple websites and I'm most likely moron. [49:03.680 --> 49:05.740] So, like, they're really two of the same things. [49:07.840 --> 49:12.880] So, before I go ahead and sign up for a new web service, how do I make sure they're not idiots? [49:13.000 --> 49:13.920] What are some basic tests? [49:14.060 --> 49:17.680] And B, if I have my own site, what are some basic attacks that I can run on myself? [49:18.320 --> 49:20.100] Well, the first part is very clear. [49:20.200 --> 49:20.960] Don't trust anybody. [49:21.260 --> 49:22.040] Nobody is safe. [49:22.180 --> 49:23.360] The security companies get hacked. [49:23.460 --> 49:24.200] The government gets hacked. [49:25.120 --> 49:27.000] Everyone is getting hacked, right and left. [49:27.200 --> 49:30.220] Just assume that anybody you're dealing with is going to get hacked periodically. [49:30.740 --> 49:32.560] The best thing, of course, is use a password manager. [49:32.560 --> 49:35.720] Somehow have a variety of passwords, so you know which ones are more important than others. [49:36.420 --> 49:40.760] To protect your own site, you know, there's usual stuff you can do like the OWASP top 10. [49:42.980 --> 49:44.340] There's services like Securi. [49:44.440 --> 49:46.640] I don't know how good they are, but they'll attempt to scan your site. [49:46.840 --> 49:49.160] The phone scanners are pretty weak, but you know, there's the usual stuff. [49:50.520 --> 49:51.240] There are... [49:51.240 --> 49:53.200] SQL injection is the number one thing. [49:53.200 --> 49:58.400] I mean, I went to a talk and the guy there said, forget the OWASP top 10. [49:58.580 --> 50:00.480] We'll just do the OWASP top one, SQL injection. [50:00.640 --> 50:01.220] This is nonsense. [50:01.380 --> 50:02.060] Let's get rid of it. [50:03.160 --> 50:06.040] And that you can attest by just putting strange things in the field. [50:06.140 --> 50:07.220] Largely punctuation marks. [50:08.400 --> 50:08.720] Thanks. [50:09.180 --> 50:09.340] Yeah. [50:09.640 --> 50:09.860] Go ahead. [50:11.740 --> 50:13.820] What's your opinion on bug bounties? [50:14.000 --> 50:15.000] Are you for or against them? [50:15.120 --> 50:15.620] I'm for them. [50:15.720 --> 50:16.360] And this is wonderful. [50:16.500 --> 50:17.160] I'm glad you brought it up. [50:17.160 --> 50:21.980] Everybody should have either a bug bounty or at least a vulnerability disclosure policy. [50:22.720 --> 50:23.080] You should... [50:23.080 --> 50:25.040] Everybody should do this no matter how high security you are. [50:25.140 --> 50:32.000] You should have a policy that says, if you find a problem on our site, we will not prosecute you if you do this. [50:32.120 --> 50:36.440] And you just say something general like, you make reasonable efforts not to really expose any data. [50:36.660 --> 50:38.020] You don't interfere with business. [50:38.180 --> 50:41.000] You let us know and keep it quiet so we have time to fix it. [50:41.240 --> 50:42.560] And then we won't prosecute. [50:42.660 --> 50:43.740] This costs you nothing. [50:44.080 --> 50:46.440] People think this will attract attacks, but it won't. [50:46.980 --> 50:48.040] And you can totally do it. [50:48.140 --> 50:50.500] There's a company called Bug Crowd that does this in San Francisco. [50:50.900 --> 50:51.020] All right. [50:51.120 --> 50:51.760] I only got two minutes. [50:51.900 --> 50:52.660] But anyway, I'm glad you brought it up. [50:52.800 --> 50:53.480] Bug bounties are great. [50:54.040 --> 50:56.560] Number two was, what if you work for a company? [50:56.920 --> 50:58.420] How do these steps... [50:58.420 --> 51:01.220] How are these steps different if you work for a company and you want to report something? [51:02.380 --> 51:05.880] I don't think they're that much different at all, except you might have some credibility. [51:06.500 --> 51:08.440] And this was another big issue in San Francisco. [51:08.440 --> 51:17.980] The prosecution of the San Francisco network supervisor proved that your company can prosecute its own staff for hacking. [51:18.540 --> 51:24.700] So if you do things to your own company on the job that you're not authorized to do, you risk the same legal repercussions. [51:24.880 --> 51:25.500] So be careful. [51:25.860 --> 51:25.940] Yeah. [51:25.940 --> 51:26.840] Okay. [51:27.020 --> 51:30.800] I just kind of wanted to go on the video at least. [51:31.380 --> 51:38.580] The SQL injection that you mentioned, I'm just kind of going to repeat your answer as in that it's a bad idea to do it. [51:38.680 --> 51:44.080] Bad idea to execute any code that you didn't stumble upon yourself. [51:44.720 --> 51:46.860] Like modify the query into the URL. [51:47.020 --> 51:52.780] You can't hack into somebody, which means you can't do things to their server that you're not authorized to do. [51:52.920 --> 51:59.080] Despite the fact that all you're doing is... [51:59.980 --> 52:02.200] Yeah, you're reforming a URL. [52:02.540 --> 52:02.860] Yes. [52:03.120 --> 52:04.780] And see, this is, I think, a huge issue. [52:04.820 --> 52:06.360] And I hope I can get this to the world. [52:06.880 --> 52:11.060] People that are technical think what matters is how smart was the thing I did. [52:11.280 --> 52:13.380] That has nothing to do with legality. [52:13.380 --> 52:18.080] If there was a window and you threw a brick through it and went in and stole the server, you just committed computer trespass. [52:18.440 --> 52:21.660] It is not a crime based on how smart you are. [52:21.760 --> 52:23.660] It is a crime based on what you did. [52:24.460 --> 52:29.220] And if the result was you went to some place that you had no right to be, you're hosed. [52:29.740 --> 52:30.480] Anyway, I think... [52:30.480 --> 52:31.160] One more minute. [52:31.500 --> 52:31.680] Go ahead. [52:32.320 --> 52:32.720] Yeah. [52:33.320 --> 52:35.380] Regarding the cracking of the password hash... [52:36.180 --> 52:36.320] Yeah. [52:36.400 --> 52:39.080] I'm not convinced that that action would be legal. [52:39.240 --> 52:46.260] I think under the Computer Fraud and Abuse Act, even the possession, unauthorized possession, of an access control device could be illegal. [52:46.340 --> 52:47.260] Not just the usage. [52:47.460 --> 52:48.860] So the act of cracking it. [52:49.200 --> 52:51.520] I've heard cases where that's been used against people. [52:52.260 --> 52:52.820] That's interesting. [52:52.920 --> 52:53.640] I've been doing it for years. [52:53.740 --> 52:54.600] They do it at DEFCON. [52:55.160 --> 52:56.240] Maybe it is illegal. [52:56.340 --> 52:58.220] If it's illegal just to crack the hash, that's an issue. [52:58.860 --> 52:59.880] I've certainly been doing it. [53:00.100 --> 53:00.920] But it's time to quit. [53:01.400 --> 53:02.180] Thank you very much, folks. [53:02.180 --> 53:02.240] Thank you very much, folks. [53:03.000 --> 53:03.260] Thank you.