[00:00.600 --> 00:01.600] I got 11. [00:05.000 --> 00:05.640] You ready? [00:05.920 --> 00:06.180] Yeah. [00:11.960 --> 00:13.020] Good morning, everybody. [00:13.890 --> 00:15.120] We'll get started here. [00:15.390 --> 00:21.380] And our topic today is pen-testing the web with Firefox. [00:21.580 --> 00:22.140] Everybody hear me? [00:22.700 --> 00:22.800] Good? [00:23.120 --> 00:23.360] Audio? [00:23.520 --> 00:23.780] Great. [00:30.010 --> 00:40.110] Okay, so try to make, you know, everybody, you want to speak at a con, you try to make an interesting topic, and you're probably wondering, you know, you read the abstract, and you want to know, what's this thing about? [00:40.110 --> 00:42.150] So who are we, and what's this really all about? [00:47.090 --> 00:48.570] My name is Michael Schearer. [00:48.850 --> 00:49.910] Prez98 is my handle. [00:51.230 --> 00:53.810] I work for Booz Allen in Maryland. [00:54.130 --> 00:54.990] That's my job. [00:55.590 --> 00:59.290] I used to be... I spent a little over eight years in the Navy. [00:59.550 --> 01:04.290] I was a EA-6B Prowler electronic countermeasures officer. [01:05.970 --> 01:11.250] I also spent nine months on the ground in Iraq doing counter IED work. [01:11.250 --> 01:16.430] You may have seen me speak at DEFCON and HOPE on hacking IEDs. [01:19.590 --> 01:35.650] As with Tom, the last speaker, I've also contributed to a couple of Singer's books, including two of the ones he mentioned, Penetration Testers, Open-Source Toolkit, Volume 2, Netcat Power Tools, which just came out, you know, last month, and also Kismet Hacking, [01:35.650 --> 01:36.990] which should be coming out any day now. [01:38.350 --> 01:47.030] I'm also a licensed amateur radio operator, and active on a bunch of forums that you may be familiar with, NetSlumber, DEFCON, Remote Exploit Forums. [01:48.730 --> 01:56.590] If that doesn't fill up enough of my time, I try to coach football when I can, and I have three kids and a fourth on the way, so... [01:56.590 --> 01:57.350] You're keeping me busy. [02:03.670 --> 02:04.170] And... [02:04.170 --> 02:05.330] Good morning. [02:05.650 --> 02:06.790] I'm John Fulmer. [02:07.170 --> 02:08.550] My handle is DaKahuna. [02:09.310 --> 02:11.590] Comes from a number of years spent in Hawaii. [02:12.590 --> 02:15.630] Like Mike, I have a background in the military. [02:15.630 --> 02:17.270] I did 24 years in the U.S. Navy. [02:18.010 --> 02:20.730] I actually worked for a living instead of being an officer. [02:22.410 --> 02:23.210] That hurts. [02:23.250 --> 02:27.070] So, my background has been in telecommunications. [02:27.850 --> 02:34.090] I've worked with everything from HF, UHF, some VLF, satellites, Morse code. [02:34.310 --> 02:36.430] I'm also an amateur radio operator. [02:36.770 --> 02:41.750] Unlike Mike, I only have two children, the youngest of which is 33, so I'm an empty nester. [02:41.750 --> 02:58.130] And what I've managed to do is take a love for electronics, a love for finding out how things work, why things work, how to break things, what happens when you take things that are designed to do one thing and you ask them to do something else. [02:58.130 --> 02:59.910] That's my term of hacking. [03:00.390 --> 03:08.470] And I've managed to successfully put that into a career where I am now what might be considered to a lot of you the enemy. [03:09.310 --> 03:16.090] My role is I am the director of IT security for a large, large aerospace and defense company. [03:16.550 --> 03:27.750] And my day job is writing policies, standards, creating processes and stuff that are designed to ensure that our networks don't get penetrated. [03:28.310 --> 03:37.770] And a lot of that is also doing things such as making sure that people are actively trying to penetrate them that tell me what the results of that is. [03:43.590 --> 03:45.790] Okay, so what's this all about? [03:46.010 --> 04:02.730] Well, using the web or using your browser to penetration test, the way it used to be is, you know, you go into Google and, you know, you use Google or you use your browser as primarily an information gathering tool. [04:02.730 --> 04:05.210] And there's a lot of stuff out there and we'll talk about that. [04:07.650 --> 04:08.410] That's then. [04:08.590 --> 04:15.110] Now, we've got specialized websites that are specific, you know, for specific types of research. [04:15.890 --> 04:20.850] You know, then was individual programs for separate types of tests. [04:21.110 --> 04:25.690] Now, you can use Firefox as a platform to launch attacks. [04:27.470 --> 04:35.090] Then was different interfaces, whether it was a proprietary program or a specific interface. [04:35.250 --> 04:38.070] Every program you have some sort of different interface you have to learn. [04:38.170 --> 04:41.250] Whether it's command line or there's a... whether there's a GUI. [04:41.550 --> 04:45.210] Now, you can use the browser to launch your attacks from there. [04:46.910 --> 04:50.610] And then was generally OS-specific tools. [04:50.870 --> 04:55.630] If you want to use a specific tool, it's going to have to be on a specific platform. [04:55.810 --> 04:59.770] And a lot of those tools branch out and port to Windows or Linux or whatever. [05:00.130 --> 05:08.310] Now, mostly, you can do some penetration testing transparent to the operating system. [05:08.350 --> 05:09.350] So it doesn't really matter. [05:11.390 --> 05:16.210] Now, we're not suggesting that all hacking should be done through Firefox. [05:16.250 --> 05:21.490] We're not suggesting that it should be done that way or that it's desirable to be done that way. [05:21.990 --> 05:40.290] What we're suggesting is that the power of Firefox and, you know, essentially being able to put extensions on Firefox to add it to its capabilities really goes beyond the information-gathering stage of your pen-test. [05:40.510 --> 05:45.710] And that you really now have a very powerful platform for penetration testing. [05:45.870 --> 05:59.110] So not just gathering information and then going off to use your tools, but actually sitting there with the browser and being able to really do a good, you know, a decent penetration test using just the browser with your add-ons. [06:17.240 --> 06:19.180] So what are we going to talk about today? [06:19.340 --> 06:22.840] Some of the things we're going to start off with is penetration testing methodology. [06:23.200 --> 06:34.300] And we'll cover just really at a high level, introduce you, let you know that there are methodologies out there that are designed to help you follow a standardized process in doing pen-testing. [06:34.500 --> 06:36.120] It makes it a lot easier to do it. [06:36.280 --> 06:40.900] Then we're going to talk some specific things that you can do when pen-testing the web with Firefox. [06:41.320 --> 06:44.180] We'll get into how to use Firefox standalone. [06:44.620 --> 06:54.560] We'll get into how to do it with some of the website-based tools that you can get, certain websites that we have found to be useful when conducting pen-tests. [06:54.560 --> 06:56.720] And then there's plugins and extensions. [06:57.040 --> 07:03.880] I mean, anybody that uses Firefox on a regular basis probably has 20 or 30 of these extensions in there that they use quite frequently. [07:04.180 --> 07:07.220] Some of them we found quite useful. [07:07.600 --> 07:10.080] Some of them are, you know, you use day-to-day. [07:10.260 --> 07:12.620] Some of them you only use when you're doing specific tasks. [07:12.820 --> 07:15.480] And we'll talk about doing some setups and stuff. [07:15.620 --> 07:19.920] We'll also talk about using Firefox as a front-end to do a lot of things. [07:19.920 --> 07:27.920] And then we'll give you some ideas of places like those of you that were in here for Tom's talk previously. [07:27.920 --> 07:32.320] He talked about the live CDs and being able to do this in a safe environment. [07:33.400 --> 07:36.020] We're going to show you some websites that are designed. [07:36.180 --> 07:37.140] Tom's is one of them. [07:37.220 --> 07:45.600] There are others, some other distributions and stuff where you can go out and you can practice these skills and hone these skills without running afoul of the law. [07:45.600 --> 07:49.560] Because we all know we don't want to end up spending any time behind bars. [07:49.920 --> 08:01.520] So we're going to kind of help you do this kind of safely so that when you do get permission from a customer to actually do it, you've honed your skills, you know what to do, and you're very successful at it. [08:05.240 --> 08:12.840] The methodologies that we have, some of them that's here is like the Open-Source Security Testing Methodology Manual, OSSTMM. [08:13.820 --> 08:15.940] This is a freely available manual. [08:16.340 --> 08:17.600] There is a version 2. [08:17.840 --> 08:19.340] Version 3 will be coming out. [08:19.480 --> 08:22.560] If you're a subscriber, you can have access to version 3 now. [08:22.760 --> 08:25.800] If you're not, you have to wait until it's publicly released. [08:25.980 --> 08:27.320] But it is out there. [08:27.320 --> 08:28.340] It is very good. [08:28.340 --> 08:29.040] It's high level. [08:29.160 --> 08:32.020] It gives you a lot of the processes and the steps. [08:32.020 --> 08:47.300] And it lays it out in a manner so that if you follow them, then the chances of success in pen-testing are proving to the customer that their site is basically secure from everything that you're able to do is increased. [08:47.700 --> 08:54.580] The Open Web Application Security Project was another one that we found very useful. [08:54.860 --> 08:57.920] And since it's open source, it's available to all of you. [08:58.800 --> 08:59.320] NIST. [08:59.600 --> 09:04.580] I do, as does Mike, a lot of work with the federal government, federal government agencies. [09:04.940 --> 09:12.200] And there is a lot of information available from the federal government on doing pen-tests and securing systems and stuff. [09:12.240 --> 09:13.840] And I encourage you all to look at those. [09:14.120 --> 09:24.500] And then the penetration testing framework is another type of framework designed to help you, give you some hints, and tell you a standard process to go through. [09:24.500 --> 09:35.660] And when you go through standard processes, you have a better chance of being able to successfully do what it is because you're doing the same thing, you're using the same approach. [09:35.660 --> 09:38.600] It's not going to give you every step you should do. [09:38.760 --> 09:52.040] It's going to tell you some things to attempt, some things to look for, and then you have to use your experience and your knowledge as a pen-tester to take those and determine what it is you really need to focus and what some of the steps are. [09:52.040 --> 09:57.380] None of these methodologies and none of these frameworks are going to be a silver bullet. [09:57.560 --> 09:58.760] There is no silver bullet. [09:58.980 --> 10:06.880] The silver bullet is up here, it's years of experience, and it's being able to interpret correctly the results you get from your tools and stuff. [10:06.880 --> 10:13.220] So no matter which of the methodologies you choose, it's typically a process that you go through. [10:13.360 --> 10:16.780] And we found the process to be things like planning and reconnaissance. [10:16.980 --> 10:18.880] That's where you determine... [10:19.580 --> 10:20.420] Go back one. [10:24.470 --> 10:25.210] Next slide. [10:30.450 --> 10:31.190] Next slide. [10:31.950 --> 10:32.390] Oh. [10:32.490 --> 10:32.950] It's got it wrong. [10:33.730 --> 10:34.290] OWASP. [10:35.330 --> 10:35.890] OWASP. [10:37.010 --> 10:37.570] Wow. [10:39.870 --> 10:40.430] Amazing. [10:40.830 --> 10:41.370] Next slide. [10:42.590 --> 10:42.890] Okay. [10:43.350 --> 10:48.390] So planning and reconnaissance, this is where you know, you've got your target. [10:48.550 --> 10:57.050] You've been contracted by some company or your own company to go out and pen-test their external or internal and you start the planning of this. [10:57.050 --> 11:00.230] This is where you sit down and you look at the...it's the initial state. [11:00.510 --> 11:01.990] What is it you're trying to do? [11:02.110 --> 11:03.090] What are you trying to accomplish? [11:03.230 --> 11:07.250] You put all the rules in place, terms of engagement with the customer, etc. [11:08.050 --> 11:11.870] And then you start collecting information about your target network. [11:13.490 --> 11:15.510] Next one is the scanning enumeration. [11:15.710 --> 11:18.630] This is where you actually start doing things that are active. [11:18.890 --> 11:21.650] This is where you go out and you start doing the data collection. [11:21.910 --> 11:23.870] You scan what ports are open. [11:24.050 --> 11:25.810] Tom showed you earlier a live CD. [11:25.810 --> 11:42.710] And really, there's a couple of us in the audience, I'm not sure how many of you did it, actually did an M-Map scan on there and found about 27 different services that were wide open on that access point and that website and server that he had stood up running on his laptop. [11:43.170 --> 11:45.670] Then you get into gaining access and penetration. [11:46.010 --> 11:47.770] We're not going to get into that here. [11:47.770 --> 11:53.210] We are going to give you a little bit, but we're not really going to give you zero days or stuff like that. [11:53.210 --> 12:03.790] But there are things that you can do with Firefox to enable you to look and have a better idea and a better chance of successfully gaining access if in fact those services are exploitable. [12:04.390 --> 12:06.650] And then maintaining access and exploration. [12:06.970 --> 12:11.630] This is all part of the frameworks and the methodologies, but not something we're going to address here. [12:11.630 --> 12:14.730] And then finally, covering your tracks. [12:15.370 --> 12:16.970] Not going to touch that at all. [12:17.330 --> 12:24.590] Hopefully, when you're doing this, you're doing this legally and you have permission and you don't want to do any harm. [12:24.790 --> 12:29.010] That's the number one rule I have when I have to do these is I'll do no harm. [12:29.010 --> 12:34.770] I'll go as far as I can to prove that I could, but I'm not going to change or knock down any services intentionally. [12:41.470 --> 12:48.410] I want to go into some of the specifics about different ways of using the browser. [12:49.190 --> 12:50.290] First, standalone. [12:50.550 --> 12:53.390] So we're talking about just using your browser. [12:54.070 --> 12:58.670] You could download Firefox, no extensions and things you could do there. [12:59.130 --> 13:01.190] And the second one is website-based tools. [13:01.370 --> 13:06.030] So that's places you can go, websites that are already out there to do these things. [13:06.030 --> 13:09.170] So again, and really, both of these you could use any browser for. [13:09.270 --> 13:10.270] You could use Internet Explorer. [13:10.430 --> 13:11.890] I don't know why you'd want to, but you could. [13:15.540 --> 13:16.320] Google hacks. [13:16.620 --> 13:21.820] Johnny Long has talked for several years about the Google hacks and they're all out there. [13:21.920 --> 13:24.920] So, I mean, it would be remiss of you not to use that in your test. [13:26.860 --> 13:33.980] We'll give you example, three good examples, or what we found to be good examples of extensions or plugins that Firefox has out there. [13:35.920 --> 13:39.920] Firefox has a front end for other tools like Metasploit and such like that. [13:40.100 --> 13:44.020] And then, you know, we're going to say, hey, here's 60 good extensions. [13:44.040 --> 13:48.220] And you're probably not going to want to load up 60 extensions in your browser because it's going to be a memory hog. [13:48.500 --> 13:51.740] So we'll give you some ideas of how you can deal with that. [13:54.800 --> 13:56.530] So, standalone, out of the box. [13:56.640 --> 14:01.700] You download Firefox 3.0.1 now, off the website. [14:04.360 --> 14:09.300] Out of the box, you're largely limited to, you know, information gathering. [14:09.530 --> 14:13.400] And this makes sense because, like I said, you could use any browser to do this. [14:14.320 --> 14:16.030] But there's a lot of stuff out there. [14:16.480 --> 14:26.530] And in penetration testing, a general rule is the more information you can gather about your target, the better your chances are of exploiting that target. [14:26.720 --> 14:31.320] And how are you going to find that vulnerable service if you're not looking out there? [14:31.320 --> 14:34.300] So, who is searches out there? [14:34.580 --> 14:39.680] Sam Spade, DNS stuff, Netcraft toolbar, we'll talk a little bit about that. [14:40.860 --> 14:44.940] Edgar filings, a lot of people will forget to look in that stuff. [14:46.730 --> 14:49.540] And then, using Google, you know, news groups. [14:50.010 --> 14:57.160] How many network administrators have a problem with XYZ box and they go on to a news group and ask for people to help? [14:57.300 --> 15:01.040] They got a problem with, I got a problem with this device and I can't fix it. [15:01.040 --> 15:07.720] Well, if he's the network administrator for, you know, whatever corporation, now you know what devices they're using and you haven't even done anything. [15:08.080 --> 15:11.360] And you know, and you may even know what vulnerabilities he has. [15:11.510 --> 15:14.320] I mean, so, you know, and this is all passive. [15:14.420 --> 15:17.360] You haven't even touched any, you know, stuff that you're talking about now. [15:20.270 --> 15:21.730] So, website-based tools. [15:21.810 --> 15:34.050] Again, not necessarily something you'd have to use Firefox for, but website-based tools, Nmaps, you don't have Nmap on your computer, fine, just go, there's a website, NmapOnline that you can use. [15:34.690 --> 15:39.570] Leak checkers and hosted hashcrackers, and I'll talk about a few of these directly. [15:40.770 --> 15:47.510] So, here's a site that I, one example of a site that you may use, centralops.net. [15:47.510 --> 15:58.070] This has a whole bunch of tools, and I won't go into all the specifics, but you can do trace routes, pings, you know, all the tools that you can do from a command line, you can do from a site like this. [15:58.150 --> 15:59.190] So, this is pretty cool. [16:00.630 --> 16:02.710] And these are all free things that you can do. [16:02.930 --> 16:11.430] So, if you're, maybe you're, you know, a command line cripple like I am, and you need a GUI sometimes to get through the tool. [16:11.430 --> 16:13.630] Well, here you go, this is a great way to do it. [16:16.520 --> 16:18.180] Here you go, NmapOnline. [16:18.320 --> 16:23.900] So, you don't, you get to your pen-testing site, and for whatever reason, you got, you need Nmap and you don't have it. [16:23.960 --> 16:25.440] Well, here you go, NmapOnline. [16:25.580 --> 16:29.440] Go to this website, type in your target, boom. [16:30.760 --> 16:33.680] Now, granted, you have a few problems here. [16:33.820 --> 16:37.120] Well, first of all, that's not my IP because I am using Tor. [16:38.700 --> 16:40.800] But, you can customize the scan. [16:41.060 --> 16:47.680] You know, if you know the command line things you want to do here, in the custom scan here, set up whatever you want to do, and scan it. [16:47.740 --> 16:49.120] You're going to get your results right there. [16:49.500 --> 16:54.760] So, quick and easy way to use an online tool if you don't have something that you need. [16:57.740 --> 16:58.260] What's that? [16:58.380 --> 16:59.020] Terms of service? [16:59.920 --> 17:01.640] Go read them before you, I mean, yeah. [17:01.960 --> 17:06.120] You may not be able to use it to maintain all the limits of your target. [17:06.120 --> 17:11.980] Right, and like John mentioned to me, and we may talk about this a little later. [17:12.980 --> 17:20.100] Depending upon, you know, you're trying to disguise where you're coming from, Tor might be a good idea to use once you're doing active tests. [17:20.580 --> 17:24.980] Because, you know, if they know where you're coming from now, you've kind of given yourself away. [17:25.260 --> 17:30.280] So, Tor's not a perfect solution, but in this case, it provides you with what you want. [17:30.400 --> 17:31.920] You're disguising your own identity. [17:37.670 --> 17:43.750] This is a good example of a tool that you might use if you're doing, say, a vulnerability assessment. [17:43.750 --> 17:46.910] You're already on the inside, and you're doing a vulnerability assessment. [17:47.110 --> 17:53.170] So, this is kind of a... this Hacker Whacker, GRC or Gibson Research also has a leak checker. [17:53.370 --> 17:58.830] This is going to look kind of from the inside and say, hey, you're vulnerable to this and this and that sort of thing. [17:58.830 --> 18:05.250] So, something that's not necessarily going to work from a, you know, a black box type penetration test. [18:05.370 --> 18:09.290] But if you're on the inside doing a vulnerability assessment, something that you might want to consider. [18:12.720 --> 18:19.360] These are all examples of websites that have online hash crackers. [18:19.360 --> 18:28.680] So, you've grabbed a, whatever, MD5 or, you know, your LANMAN hash off of a website. [18:28.820 --> 18:32.700] You don't have your tables with you and you want to crack them. [18:33.200 --> 18:34.400] Post them on the website. [18:34.660 --> 18:38.400] You know, it might take a day or two, but you may get the results back. [18:39.580 --> 18:41.140] And a caveat here now. [18:42.700 --> 18:49.300] If you're doing a penetration test, you may... you probably have signed some sort of non-disclosure agreement with your client. [18:49.480 --> 18:51.160] That you're not going to reveal their data. [18:51.460 --> 18:58.640] Well, if you post their LANMAN hashes or whatever on this website, it's pretty much publicly available now. [18:58.880 --> 19:05.940] Now, that doesn't say this hash is associated with this particular company, but you're still exposing their data to the web. [19:06.100 --> 19:08.880] So, you want to be careful about using these sort of services. [19:10.440 --> 19:11.400] Here's a good example. [19:11.580 --> 19:20.020] If you're familiar with, like, SETI at home and all those distributed computing projects, this is a rainbow table distributed computing project. [19:20.160 --> 19:20.920] So, you sign up. [19:21.080 --> 19:24.060] It uses your CPU cycles when you're not using your computer. [19:24.220 --> 19:32.920] And you're basically helping them generate, you know, large-scale rainbow tables for LANMAN or MTLM or, you know, whatever you want to do, MD5 and such. [19:33.440 --> 19:40.840] So, if this is... and again, they also have a submission tool here where you can submit a hash and get information back. [19:40.980 --> 19:42.400] So, this is kind of cool stuff to use. [19:42.820 --> 19:48.340] Stuff that's out there, you know, I'm at the site and I forgot my drive that has my tables on. [19:48.580 --> 19:50.880] You know, this may help you in that case. [19:54.950 --> 19:57.530] This is Johnny Long's Google hacking database. [19:57.530 --> 19:59.150] Hasn't been updated in a few years. [19:59.330 --> 20:05.110] However, good examples, you know, you don't necessarily need this website to show you everything. [20:05.250 --> 20:12.330] But this will give you a good start of, you know, the whole concept of Google hacking is finding information that's not supposed to be on the web. [20:12.490 --> 20:17.890] But, you know, Google's spiders have crawled to it because of inadequate permissions or whatever. [20:17.890 --> 20:22.610] So, I mean, I can't understate the power of these things. [20:22.770 --> 20:26.610] I mean, there are people that just put their, you know, default installs on the thing. [20:26.750 --> 20:28.050] There's password lists. [20:28.230 --> 20:32.510] There's, you know, one of my friends likes to search foreign governments for password. [20:32.570 --> 20:35.710] I mean, he's found all kinds of stuff that's available out there. [20:37.430 --> 20:41.530] So, and this is, of course, you know, this is just using what's publicly available already out there. [20:41.910 --> 20:44.090] Information that's not necessarily supposed to be on the web. [20:44.350 --> 20:44.750] Yes? [20:44.750 --> 20:47.950] You can have a lot of new things publicly available on your website or something. [20:48.150 --> 20:50.590] Yeah, we can, we'll, we can post it online for you. [20:53.150 --> 20:57.210] And then don't, don't discount also, and I'll add this here. [20:57.530 --> 21:03.190] Don't discount the, using like Google Cache or like archive, or Internet Archives. [21:04.350 --> 21:08.070] So, some company has some sensitive data exposed on their website. [21:08.070 --> 21:16.210] They take it down and they think they're safe, but Google cache, Google cached it maybe, or archives, you know, are already online. [21:16.450 --> 21:18.010] So, you may find some stuff out there, right? [21:21.800 --> 21:22.540] Take it away. [21:27.820 --> 21:32.680] Using Firefox plugins and extensions, we've listed a couple here that we're going to talk about. [21:32.880 --> 21:37.820] The first one is what's called the Firefox Catalog of Auditing Extensions or FireCat. [21:38.300 --> 21:42.140] This is currently in a release four and it's available. [21:42.380 --> 21:47.300] And what this gives you is about 60 extensions and it's continuously growing. [21:47.600 --> 21:53.820] So, and it's got them out in a nice, those of you that are familiar with the mind map format that lays them out. [21:53.960 --> 21:58.960] And I'll show you a screen here in just a second of what it looks like and talk to you just a little bit about it. [21:58.960 --> 22:02.600] And then we're going to talk about a couple of examples that we're going to walk through. [22:03.140 --> 22:15.120] Not necessarily in the order shown here, but passive recon, exploit me, which is a group of exploit tools, and then a tool called tamper data that we find very useful. [22:17.240 --> 22:19.260] This here is kind of an eye test. [22:19.420 --> 22:21.320] This is the mind map for FireCat. [22:21.980 --> 22:31.080] And just to show you a couple things that are there, if you're using proxies or web utilities, here's a grouping of those and it shows you the plugins that you can get. [22:31.260 --> 22:32.500] Don't have to do all of them. [22:32.600 --> 22:34.800] You can do one or two, whatever you're familiar with. [22:35.660 --> 22:37.780] Then it talks about information gathering. [22:37.780 --> 22:42.620] These are the ones that have been pretty much the primary focus of what this talk is about. [22:42.840 --> 22:45.800] And as you can see, there are a number of sub areas under there. [22:46.960 --> 22:55.040] Tools like location information, doing enumerating, fingerprinting, data mining, Googling, spidering. [22:55.700 --> 22:57.960] Next is doing security auditing. [22:58.120 --> 23:02.680] These things like proxies, web filters and stuff. [23:03.000 --> 23:13.240] These are kind of neat tools and there's a lot of them, like you see, and the guy is constantly updating the site, updating the list as new plugins and stuff are made available. [23:13.700 --> 23:16.580] And then occasionally you do need to do some editing. [23:16.580 --> 23:23.500] So if you need to edit with Firefox or something, here's some Firefox extensions and plugins for doing that. [23:23.500 --> 23:25.980] And then network utilities. [23:26.220 --> 23:28.160] These are always quite useful. [23:28.400 --> 23:33.340] Doing FTP, intrusion detection, sniffers, database, Wi-Fi. [23:33.980 --> 23:38.920] And then there's also some miscellaneous ones as well as some others. [23:39.160 --> 23:40.220] But neat site. [23:40.480 --> 23:44.980] Do a search for the term FireCat on Google and it will take you right there. [23:45.320 --> 23:49.320] You may get directed to a link that shows version 1.2. [23:49.320 --> 23:52.460] If you do, go back to Google, look at another one. [23:52.580 --> 23:58.080] I think it's the second link that shows up now is version 1.4, which is the latest release. [24:03.720 --> 24:10.160] We wanted to... like we said, we got three examples of... and this is certainly not an exhaustive list of the best stuff out there. [24:10.220 --> 24:12.860] This is just three things that we picked that we think are kind of cool. [24:12.860 --> 24:16.900] The first one is actually a series of three extensions called ExploitMe. [24:17.140 --> 24:18.240] There's three extensions. [24:19.380 --> 24:23.980] This was introduced at Sektor in Toronto last year by the guys at Security Compass. [24:24.680 --> 24:28.360] They actually had a talk at Sektor specifically for these tools. [24:28.580 --> 24:33.100] So if you want more details than I'm giving you here, download their talk from the Sektor website. [24:33.680 --> 24:35.820] And you get a whole bunch of information. [24:37.000 --> 24:42.180] The first one is XSSMe, which is a cross-site scripting tool. [24:42.400 --> 24:44.500] It searches for cross-site scripting vulnerabilities. [24:46.740 --> 24:55.160] If you're a big fan of looking for cross-site scripting vulnerabilities, there's a website, xssed.com. [24:55.340 --> 24:58.480] It's basically a repository of XSS vulnerabilities. [24:58.820 --> 25:02.300] In fact, you can even sort them by page rank. [25:02.300 --> 25:05.040] So if you sort them, the number one that's going to come up is Yahoo. [25:05.220 --> 25:08.880] There's about 50 XSS vulnerabilities on different Yahoo pages. [25:09.440 --> 25:13.460] So pretty interesting site in terms of stuff that's already out there. [25:15.040 --> 25:18.300] The second one is SQL InjectMe. [25:18.540 --> 25:20.680] I'll show you a picture of this on the next slide. [25:21.660 --> 25:25.700] And this is, again, just testing SQL injection vulnerabilities. [25:26.080 --> 25:27.960] And then the third one is AccessMe. [25:27.960 --> 25:40.980] And this is basically when you surf to a website that requires you to enter some sort of permissions to get to, AccessMe will try to access the site without those permissions to see if there are permission vulnerabilities there. [25:42.300 --> 25:44.920] There's a couple tools that they're talking about releasing in the future. [25:45.880 --> 25:48.240] WebServiceMe, OverflowMe, EnumerateMe, and BruteForceMe. [25:48.340 --> 25:49.600] So these may come out in the near future. [25:49.660 --> 25:50.680] Hopefully they're still working on them. [25:53.500 --> 25:55.940] Here's an example of XSSMe. [25:57.420 --> 25:59.000] It's simply, it's a sidebar. [25:59.120 --> 26:01.020] You click on it and it's a sidebar and it comes up. [26:01.180 --> 26:08.240] And if you've got forms, or if you've got forms in your web page, they're going to be listed on the sidebar. [26:08.340 --> 26:12.300] For example, the 2600 page has a form on the sidebar. [26:12.300 --> 26:14.160] Or so it's displayed on the sidebar. [26:14.360 --> 26:18.820] And you literally just have to enter information, any valid information in the fields. [26:19.060 --> 26:20.060] And then you can test. [26:20.200 --> 26:27.020] There's also, there's a whole library of tests where you can just run through, you know, a series of tests. [26:27.180 --> 26:34.520] And then there will be a report to tell you this particular field or form was vulnerable to this particular exploit. [26:34.660 --> 26:35.320] So that's kind of cool. [26:37.360 --> 26:41.800] Now again, you click on that button to test, you realize what you're doing. [26:42.040 --> 26:44.740] You know, you're accessing somebody's website in a way it wasn't intended. [26:44.960 --> 26:46.320] You're, you may be breaking the law. [26:46.500 --> 26:50.500] So, I didn't click on this button, but it's there. [26:55.150 --> 26:57.590] SQL inject me is the same sort of thing. [26:57.750 --> 27:05.170] You've got a sidebar that comes out and any forms that are visible on the page will show up in the tabs. [27:05.170 --> 27:11.950] And you can simply, you know, test, you can test like the top, the most common vulnerabilities or you can test all the ones in the library. [27:12.170 --> 27:14.170] So literally, just click on it and you'll get a report. [27:14.930 --> 27:19.370] And I mean, so, is point and click the best way to go? [27:19.590 --> 27:20.550] Maybe or maybe not. [27:20.550 --> 27:35.390] But if you want to sit there and manually type, you know, whatever SQL strings you're trying to test, you know, instead of doing them one at a time, okay this one works, this one doesn't work, this is going to do it all for you. [27:35.530 --> 27:41.350] This doesn't replace your, you know, the importance for you to learn this stuff yourself, but this helps you automate it a little bit. [27:42.270 --> 27:46.370] Also, a disclaimer that this isn't necessarily going to find every single vulnerability. [27:46.550 --> 27:48.270] There may be something out there that this doesn't find. [27:48.690 --> 27:50.150] But, you know, it's a good start. [27:50.330 --> 27:53.490] This is kind of like the Nessus scan, you know. [27:53.570 --> 27:55.970] It's going to find a lot of stuff, but it's not going to find everything. [27:55.970 --> 27:58.230] And it doesn't absolve you from digging deeper. [28:01.890 --> 28:04.770] The second one I want to talk about is called Tamper Data. [28:05.110 --> 28:09.430] Tamper Data acts like a mini-proxy server in your browser. [28:09.690 --> 28:17.250] And it allows you to view and modify HTTPS headers as they're sent and returned to your computer. [28:18.130 --> 28:21.850] You can also trace times and responses and stuff like that. [28:23.890 --> 28:30.490] Unfortunately, this has become popular for hacking e-commerce sites that don't do server-side validation. [28:30.890 --> 28:33.790] In other words... and I'll show you an example here. [28:34.790 --> 28:47.010] And then, if you search... sadly, if you search on YouTube, you'll find that probably the most popular use for this is like changing the high score on Flash-based games so you have the highest score. [28:47.170 --> 28:51.390] I mean, it's kind of silly, but... But fun. [28:51.570 --> 28:52.690] But it could be fun. [28:53.090 --> 28:56.590] And I can't see my screen here, but I'm going to try to give you just a small example. [28:56.810 --> 29:01.750] I'll also caveat this, that the example I'm giving you here is already a known website that's vulnerable. [29:02.330 --> 29:04.950] I'm not... this is not the first time somebody's done this. [29:05.110 --> 29:08.230] And I'm not going to go through with it completely, but just to give you an example. [29:16.430 --> 29:16.790] Okay. [29:21.590 --> 29:24.850] Okay, there's a device called... you know what the TV-B-Gone is. [29:25.090 --> 29:26.390] It search... it goes through all the code. [29:26.510 --> 29:28.070] Well, there's another device called the Ninja Remote. [29:28.230 --> 29:29.030] And it gives you more... [29:29.030 --> 29:30.710] actually gives you a little bit more capability. [29:30.970 --> 29:33.830] You can actually change channels and change the volume and stuff like that. [29:34.310 --> 29:37.730] Well, this is the button... this device, you can buy them on this page. [29:48.780 --> 29:52.520] So, the links here are basically the more you buy, the cheaper they are. [29:52.680 --> 29:56.140] So, the first one is five Ninja remotes for $49.95 plus shipping. [30:17.930 --> 30:19.390] So, what do I want to pay? [30:21.530 --> 30:22.410] $9.99. [30:39.290 --> 30:41.230] Now, that's not an editable field. [30:41.390 --> 30:42.050] That's what's returned. [30:42.270 --> 30:48.030] And again, this is because their server is not validating the price when it comes back. [30:48.210 --> 30:55.010] So, again, now I can't guarantee that if you go ahead and buy this that you'll get it at that price because they may find it later on. [30:55.210 --> 30:58.010] But, the point is the website is vulnerable to that. [30:58.370 --> 31:01.050] And again, like I said, this has already been demonstrated. [31:01.750 --> 31:04.510] I'm not taking credit for finding this website and the vulnerability. [31:04.910 --> 31:06.790] But, pretty powerful stuff. [31:26.940 --> 31:28.020] what is it? [31:28.360 --> 31:28.560] What's it? [31:28.560 --> 31:29.220] All the way to the right. [31:29.840 --> 31:30.780] Sorry, I can't see. [31:30.920 --> 31:31.280] Right there. [31:33.760 --> 31:34.220] Thanks. [31:38.110 --> 31:39.870] We've got 25 minutes. [31:39.910 --> 31:40.750] So, we're doing good. [31:44.830 --> 31:48.250] I mentioned a tool called Passive Recon. [31:48.450 --> 31:51.050] And I'm going to show you a little bit about it here. [31:51.530 --> 31:55.770] Essentially, what it'll do is it automates a lot of things. [31:55.770 --> 31:59.130] There's a lot of areas that it gives you. [31:59.870 --> 32:00.990] DNS queries. [32:01.250 --> 32:04.190] It'll actually do trace routes for you. [32:04.630 --> 32:07.630] It'll use some of the Google scripts that we talked about. [32:07.650 --> 32:12.710] It'll search for text files, PPT, PDF, Excel spreadsheets, etc. [32:13.310 --> 32:16.050] And it's got it all nicely laid out and everything. [32:16.690 --> 32:19.190] So, we're going to do a little demo here. [32:19.330 --> 32:24.370] But to give you a heads up, this is the site. [32:25.830 --> 32:27.370] We chose somebody at random. [32:27.510 --> 32:29.970] This happens to be the RIAA. [32:30.990 --> 32:32.850] And so, go down to the bottom. [32:33.030 --> 32:35.790] And then all the way down to the bottom where it says Scan All. [32:36.110 --> 32:36.230] Whoops. [32:37.350 --> 32:37.930] Next one. [32:38.070 --> 32:38.470] There you go. [32:38.550 --> 32:39.230] Hit Scan All. [32:39.230 --> 32:45.230] Notice this thing is going to open 22 tabs across the top of the page here. [32:45.710 --> 32:51.690] So, each one of those commands that you saw a second ago are all being enumerated there. [32:51.870 --> 32:53.570] If you want to go in, there's Domain Tools. [32:53.910 --> 32:58.330] It gives you information about the domain, who it's registered to, how long it's been there. [32:59.930 --> 33:01.210] This is who is. [33:01.410 --> 33:04.710] It gives you the registrar information associated with the IP address. [33:05.230 --> 33:07.670] Looks like the network timeout. [33:08.450 --> 33:11.010] That must be the email servers. [33:11.810 --> 33:13.050] Domain exchange servers. [33:13.090 --> 33:15.050] You want to know what their email addresses are. [33:15.210 --> 33:16.450] There's a DNS tool in here. [33:16.590 --> 33:19.690] They give you A records, NS records, MX records. [33:19.850 --> 33:26.170] So, you can kind of look at things like they may be having someone host their websites for them. [33:26.250 --> 33:27.370] But you look at the A records. [33:27.370 --> 33:28.590] Different IP address. [33:28.830 --> 33:37.130] It may give you an idea that you may not want to detect the websites and may want to look at their host sites that are registered them and not to some service provider. [33:40.230 --> 33:40.630] NetCraft. [33:40.630 --> 33:43.250] This is a great tool when you use NetCraft. [33:43.470 --> 33:45.490] There's a lot of information it gives you here. [33:45.650 --> 33:52.150] But like I say, once you click on that one button and tell it to run all those tasks, it will open 22 different tabs. [33:52.150 --> 33:56.170] It will tell you, go to the one for the Google one. [33:57.370 --> 33:59.290] About some documents and stuff. [34:00.610 --> 34:02.690] Probably got to go farther to the right, Mike. [34:07.560 --> 34:08.120] Next. [34:09.480 --> 34:18.640] It also does Google searches for documents, PDF files, Excel files that are on the website that are available. [34:18.800 --> 34:20.060] So you might find something interesting. [34:20.060 --> 34:25.380] And it will give you links that will tell you what sites are linked on this site and what sites link to it. [34:26.140 --> 34:27.280] Quite a few of them there. [34:28.180 --> 34:31.120] So, you know, it's a fun thing to play around with. [34:31.380 --> 34:38.860] Even if you're not doing a pen-test and you just want to know a lot about some organization, you know, .gov, .mil or stuff. [34:39.060 --> 34:44.160] It's interesting to see what information is really available from them on the web. [34:44.340 --> 34:45.020] Back on the slides. [34:45.020 --> 34:45.440] Okay. [34:46.480 --> 34:52.840] And like I say, if you look down there, there's the list of them and the one all the way on the bottom there where it says scan all. [34:54.060 --> 34:58.820] So, you know, if you want to do, if you're looking for something specific, you can click on the individual ones. [34:58.980 --> 35:06.860] Or if you're just in a, you know, information overload junkie like I am, you click on scan all and then sit there and go through that for about half an hour or so. [35:08.780 --> 35:12.080] Here's a close look up of 2600.orgs. [35:12.580 --> 35:16.040] And this is what's registered on for them for the DNS. [35:16.620 --> 35:22.600] Interesting to note two different IP address ranges there. [35:25.470 --> 35:28.750] Another slide is here's their DNS information. [35:33.330 --> 35:37.530] Want to know what their mail servers and MX records, where they're at. [35:37.530 --> 35:41.750] Again, you'll notice the NS servers in two different places. [35:41.970 --> 35:43.870] So that means if one goes down, they got the other. [35:47.060 --> 35:49.060] And then want to look at some files. [35:49.200 --> 35:49.820] Here's the link. [35:49.980 --> 35:53.600] These are sites that 2600.org links to. [35:54.080 --> 36:02.260] So you can kind of tell what they're affiliated with, who they may be doing business with, and some other information like that going through that. [36:03.020 --> 36:07.440] And then want to know how long they've had the address. [36:08.060 --> 36:16.960] And one thing I haven't been able to figure out, if you look down there around 2000, in the Department of Treasury or Justice, is it, on 2600.org? [36:17.860 --> 36:21.480] Not sure how that got there, but that's the results I got when I went to the site. [36:21.620 --> 36:23.720] So you pick up some interesting stuff. [36:24.020 --> 36:27.200] And it just gives you a lot of information that's very, very useful. [36:27.540 --> 36:30.060] Because as Sun Tzu said, know thy enemy. [36:30.320 --> 36:45.240] So if you're doing a pen-test to get something, the best thing you can do is get very, very knowledgeable about the company, the business, or whatever your target is that you've been hired to legally do a pen-test of, so that you can better do it. [36:50.810 --> 36:52.090] Let me go back to this slide. [36:52.290 --> 36:54.550] Don't underestimate the power of information. [36:54.770 --> 36:57.270] Here's a good example, and not specifically on this slide. [36:59.230 --> 37:01.050] NetCraft, what's this site running? [37:01.050 --> 37:05.870] Okay, so you see that your target is running IIS whatever. [37:06.850 --> 37:10.650] And NetCraft also has uptime reports. [37:10.950 --> 37:25.070] Well, what if Microsoft released a patch to a critical IIS vulnerability on Tuesday, and the web's your target, which required a reboot, and your target hasn't been rebooted in a month? [37:25.870 --> 37:27.630] How powerful is that to you? [37:27.730 --> 37:29.250] That vulnerability is now yours. [37:29.250 --> 37:32.070] I mean, pretty powerful information out there. [37:32.270 --> 37:35.730] So, don't discount the power of passive information. [37:37.370 --> 37:38.110] Or a null. [37:41.410 --> 37:42.310] Is that the right one? [37:45.710 --> 37:48.210] These are a couple other add-ons that we think are nice. [37:48.310 --> 37:49.690] We don't really have time to talk about them. [37:49.810 --> 37:50.730] Add and edit cookies. [37:51.170 --> 37:53.430] It's pretty self-explanatory by its title. [37:54.690 --> 37:57.890] Firebug is a really cool tool for editing things on the fly. [37:57.890 --> 38:02.330] Editing the CSS or editing the HTML or JavaScript. [38:06.030 --> 38:07.890] Hackbar does a lot of cool things. [38:08.590 --> 38:10.030] You can obfuscate. [38:10.150 --> 38:11.090] That's a cool word, isn't it? [38:11.410 --> 38:11.850] Obfuscate. [38:12.550 --> 38:21.210] Say you have an SQL injection, but you think you might be able to bypass their IDS by obfuscating the URL that you're typing in. [38:21.450 --> 38:22.430] This will do it for you. [38:22.530 --> 38:23.190] How cool is that? [38:23.830 --> 38:25.890] And then web developer is a really cool tool. [38:26.030 --> 38:28.630] Not just for pen-testers, but for web developers in general. [38:33.330 --> 38:37.550] So, now we're moving on to using Firefox as a front end. [38:37.710 --> 38:41.170] So, using Firefox as kind of the interface for some other tool. [38:41.480 --> 38:42.940] Well, we already talked about Tor. [38:44.690 --> 38:48.480] The first... one of the first extensions out there for Tor was Tor Button. [38:48.650 --> 38:50.540] How many... pretty much everyone's here at Tor Button. [38:50.670 --> 38:51.070] It's pretty cool. [38:51.070 --> 38:55.480] I mean, click on it and it automatically changes your proxy settings for Tor. [38:55.710 --> 38:57.150] Well, what if you like to use other tools? [38:57.360 --> 38:59.020] Paros Proxy is one of my favorite tools. [39:00.000 --> 39:02.710] And then there's other ones, Burt Proxy, Spike Proxy. [39:02.900 --> 39:08.590] Well, you can use an extension called Switch Proxy, which allows you to do multiple extensions. [39:08.750 --> 39:12.590] So, you can put Tor, Paros, Spike, whatever. [39:12.590 --> 39:17.130] So, literally, click the button and you're done. [39:18.770 --> 39:21.480] You can also use Firefox as a front end for other tools. [39:21.770 --> 39:22.570] A Metasploit. [39:22.670 --> 39:23.900] A lot of people, you know... [39:23.900 --> 39:26.270] If you know Metasploit, you're probably a command line guy. [39:26.440 --> 39:30.540] But, you know, you could do it via the command... or via web front end. [39:30.960 --> 39:35.770] There's a tool that's specific to Backtrack called FastTrack. [39:36.380 --> 39:39.270] FastTrack's a really cool tool and I'll show you an example of what that looks like. [39:41.110 --> 39:45.940] InProtect has an extension that's a web interface for Nessus and Nmap. [39:46.310 --> 39:48.440] Now, those tools have to be installed on your system. [39:48.540 --> 39:50.980] But, that's kind of cool to be able to do it from a browser. [39:51.270 --> 39:54.380] And then, if you're using Snort, you know, and Base, you can... [39:54.380 --> 39:56.310] That's your front end for Firefox. [40:01.220 --> 40:02.040] Metasploit front end. [40:02.120 --> 40:07.880] This is the ever popular RPC DCOM exploit that you can use against, like, an IAS 5 unpatched. [40:08.680 --> 40:10.380] And it works really easy. [40:14.240 --> 40:15.460] This is FastTrack. [40:15.600 --> 40:16.980] It started out as a command line tool. [40:17.100 --> 40:18.140] But, you can see the cool things there. [40:18.260 --> 40:18.740] It does a... [40:18.740 --> 40:25.960] You can do, like, a Metasploit autopone where it just bangs a whole bunch of exploits against services that it finds to see if it's vulnerable. [40:28.260 --> 40:28.640] It's... [40:28.640 --> 40:28.900] Yeah. [40:29.760 --> 40:34.740] If you have, like, an XP service pack 2 or 3 box, this isn't going to work against it. [40:34.740 --> 40:35.540] But, I mean, it's... [40:35.540 --> 40:37.140] If you have something older, it's... [40:37.140 --> 40:37.760] It'll find... [40:37.760 --> 40:38.600] If you run this... [40:38.600 --> 40:48.840] For example, if you run this against, like, Windows Server 2000 with Service Pack 4 but no further updates after that, it'll give you, like, five different shells. [40:49.080 --> 40:49.980] So, I mean, it's pretty cool. [40:51.800 --> 40:53.620] SQL injection, all sorts of things. [40:56.870 --> 40:58.550] And, okay, a couple of recommendations. [40:58.850 --> 41:00.330] We've got about 10 or 15 minutes left here. [41:00.430 --> 41:01.890] We'll try to get done so we have time for questions. [41:02.050 --> 41:03.290] So, here's your concern. [41:03.290 --> 41:08.530] You just download FireCat and you've got 60 extensions and now Firefox takes forever to open. [41:09.310 --> 41:10.370] I'll give you an example. [41:10.990 --> 41:16.110] I loaded a clean profile, so Firefox with nothing on it, and then one with 20 extensions. [41:16.290 --> 41:17.470] And it used twice as much memory. [41:17.470 --> 41:18.930] So, I mean, that's a valid concern. [41:18.930 --> 41:21.470] You may have a lightweight system that you can't do that with. [41:22.390 --> 41:23.590] And if you download... [41:23.590 --> 41:26.130] If you're gonna install all 60 of those, there's gonna be a lot of duplicates. [41:26.210 --> 41:28.730] There's, like, three tools to switch proxies and, you know... [41:28.730 --> 41:30.710] So, you don't necessarily want all of them. [41:32.270 --> 41:35.110] So, it's a legitimate memory use concern and time to load. [41:35.830 --> 41:40.190] The fix for you, I recommend, is using Firefox Profile Manager. [41:40.410 --> 41:41.650] So, instead of... [41:41.650 --> 41:46.870] If, say, you're using Windows, Firefox.exe, Firefox.exe-Profile Manager. [41:46.870 --> 41:50.670] And what that does is it opens up a little box where you can create your own separate profiles. [41:51.190 --> 41:59.010] So, you could have an everyday profile that you use the web for, and then you could have a profile that you use for pen-testing that you have more extensions on. [42:00.710 --> 42:01.030] So... [42:01.030 --> 42:03.890] And then, just install those that you only use on a regular basis. [42:04.150 --> 42:09.010] You know, I have about 20 on mine, which is a lot for some people, but those are the ones I use. [42:09.150 --> 42:09.990] If you're not gonna use... [42:09.990 --> 42:12.110] If you find you're not using them, just take them out. [42:14.940 --> 42:16.500] A couple other concerns. [42:17.720 --> 42:18.160] Portability. [42:18.380 --> 42:31.820] So, you're always going from the office, to the client site, to another client, and for whatever reason, you may not have your own laptop, and you don't want to sit there and have to install individual extensions every time you go. [42:32.000 --> 42:37.000] There's a series of three extensions out there that will help you with do this. [42:37.000 --> 42:41.480] So, you don't want to sit there and install add-on, 20 add-ons every time you want to do this. [42:42.000 --> 42:45.100] The first one's called Phoebe, or Firefox Environment Backup Extension. [42:45.320 --> 42:47.240] This basically just backs up your extensions. [42:49.140 --> 42:51.860] Clio will actually take all your XPI files... [42:51.860 --> 42:54.200] XPI is just a compressed extension. [42:54.640 --> 42:57.840] We'll take all of your XPI files and put them into one XPI. [42:58.100 --> 43:01.520] So, you could have 20 and just install, and it'll install all of them at once. [43:01.620 --> 43:02.280] That's kind of cool. [43:02.980 --> 43:06.360] And then, you can also save and import and export your preferences. [43:06.360 --> 43:11.060] So, all these tools are pretty cool in terms of managing your extensions. [43:11.540 --> 43:13.440] So, extensions to manage your extensions. [43:16.640 --> 43:23.600] So, we started this presentation months ago, and Firefox 2 was the thing, and Firefox 3 had not come out yet. [43:24.200 --> 43:26.820] And I'm thinking, okay, I'm just going to stick with Firefox 2. [43:27.180 --> 43:28.420] Firefox 3 is going to come out. [43:28.540 --> 43:29.560] It's going to be a big version. [43:29.620 --> 43:38.700] And you know that most extensions are maintained by, like, one guy, and if he doesn't have the time to update for compatibility, and my stuff's not going to work, and presentation's going to fall apart, it's going to be horrible. [43:39.900 --> 43:45.380] So, and loss of functionality for an extension that you use all the time, that's a legitimate concern. [43:46.660 --> 43:50.580] Because some extensions will have slow updates to Firefox 3 compatibility. [43:50.920 --> 43:58.720] For example, the SQL inject me and access me, those haven't been updated yet to Firefox 3, but I'm running Firefox 3, and they're up there. [43:58.720 --> 43:59.800] So I'll show you how I did that. [44:01.720 --> 44:11.080] Your fixes are, you know, there's, sometimes people will, not someone other than developer, will download the code and fix it, and re-opt it with a slightly different name. [44:11.800 --> 44:15.560] One of the tools I mentioned before was Switch Proxy, which is one of my favorite tools. [44:15.820 --> 44:20.160] Well, there's now one called Multi-Switch Proxy, which is the same, or Multi-Proxy Switch, which is the same thing. [44:20.340 --> 44:22.020] It's just someone else fixed it. [44:22.860 --> 44:27.860] The second fix is to manually edit the extension yourself. [44:28.240 --> 44:29.800] And this requires a couple things. [44:30.060 --> 44:35.440] First of all, you actually need to sign up on the add-on, Firefox add-on's website, create your own account. [44:35.820 --> 44:38.040] This will allow you to do a couple things. [44:38.340 --> 44:48.720] If you try to download an extension for, if you say you have Firefox 3, and you try to download an extension for your laptop that isn't compatible, it's not going to let you. [44:48.780 --> 44:49.780] The box is going to be grayed out. [44:49.780 --> 44:55.580] If you sign in, you can click on Ignore Version Check, and then it will let you download it in any compatible version. [44:57.840 --> 44:59.560] So you download the XPI file. [44:59.660 --> 45:01.880] Like I said, the XPI is actually just a compressed... [45:01.880 --> 45:03.380] It's just a zip file. [45:04.880 --> 45:11.060] Open up the XPI, edit max version in the file, install.rdf, update the archive, and install it. [45:11.120 --> 45:11.880] And I'll give you an example here. [45:12.580 --> 45:15.000] Also, keep in mind that not all extensions are official. [45:15.180 --> 45:21.900] And when you sign in, you also have access to what are called experimental extensions, ones that aren't officially approved by Mozilla yet. [45:22.420 --> 45:23.700] So that may give you access to those. [45:23.860 --> 45:26.340] Now, keep in mind, there may be reasons why they're experimental, [45:31.070 --> 45:31.470] but... [45:31.930 --> 45:33.750] This is as simple as possible. [45:34.350 --> 45:36.870] I opened the install... [45:36.870 --> 45:44.750] I opened the XPI of a file, and in a program called 7-zip, which is freeware, it's out there, it's easy to use. [45:46.310 --> 45:51.830] I opened install.rdf in Notepad, and if you see that line, it says max version 2.0. [45:52.270 --> 45:54.610] Change it to something greater than what you're running. [45:54.670 --> 45:55.910] So I just changed it to 4.0. [45:56.570 --> 46:02.510] Now, this is not guaranteed to work for everything, because, again, there's reasons why Firefox 2 is different from Firefox 3. [46:02.670 --> 46:03.210] It may break. [46:04.070 --> 46:07.990] For example, this is a download manager tweak extension, which actually did not fix it. [46:07.990 --> 46:08.450] But... [46:09.410 --> 46:14.670] So save this file, update the archive, double-click again on the XPI file, install it. [46:15.210 --> 46:16.950] Nine times out of ten, it's going to work for you. [46:17.610 --> 46:26.670] If I might add, this morning I was able to use this using WinZip and WordPad to update the XSS me, access me, and exploit me. [46:26.850 --> 46:30.850] So if you're interested in those three, this technique does work for those three. [46:33.290 --> 46:34.430] So you want to... [46:34.430 --> 46:37.030] You've got all this cool stuff now, and you want to practice. [46:37.030 --> 46:41.790] The first thing I want to mention, if you were in here for the previous talk, we've already mentioned the de-ice pen-testing CDs. [46:42.110 --> 46:43.010] These are really cool. [46:43.730 --> 46:46.990] John and I have gone through all the levels of this, and it's... [46:46.990 --> 46:49.450] Trust me, that second level is tough. [46:49.770 --> 46:50.270] Now, we didn't... [46:50.270 --> 46:53.110] We weren't doing it eight hours a day, but it took us about a month to get through it. [46:53.270 --> 46:54.150] I mean, it's pretty tough. [46:54.530 --> 46:55.170] So if... [46:55.170 --> 46:58.390] Don't suspect that it's going to be, you know, point-click own. [46:58.530 --> 46:59.190] It's not that easy. [47:00.130 --> 47:00.770] OWASP has... [47:00.770 --> 47:01.890] See, I spelled it right on this one. [47:03.330 --> 47:06.450] OWASP has a project now called WebGoat, and this is pretty cool. [47:06.450 --> 47:07.410] It... [47:07.410 --> 47:08.450] It's a lot easier. [47:08.750 --> 47:10.290] You don't have to download as many things. [47:10.470 --> 47:13.610] It just downloads Apache Tomcat and a few other things. [47:14.270 --> 47:16.150] And it allows you to walk through. [47:16.330 --> 47:17.130] Pretty good tool. [47:17.290 --> 47:18.610] Again, it's mostly web-based stuff. [47:19.830 --> 47:26.150] Foundstone has a series of HackMe websites, like HackMe Bank and HackMe Travel Agency. [47:26.730 --> 47:27.850] And so you can go through... [47:27.850 --> 47:28.490] And they're... [47:28.490 --> 47:30.230] Intentionally have small vulnerabilities in them. [47:30.230 --> 47:33.010] So another thing that you can download to try out. [47:33.170 --> 47:34.770] The pen-testing CDs I already mentioned. [47:35.470 --> 47:36.950] Some people like VMware. [47:37.450 --> 47:42.210] You know, set up a server with a bunch of VMware images running on it and use that as your targets. [47:42.910 --> 47:45.770] And then there are safe hacking websites out there. [47:45.870 --> 47:50.650] I put safe in parentheses, and I'm not going to mention any specific ones because I can't guarantee you that they're safe. [47:50.650 --> 47:52.890] But, you know, I'll give... [47:52.890 --> 47:55.390] There's one called hackthissite.org. [47:55.510 --> 48:01.910] And, you know, like I said, I'm not endorsing any specific sites because sites may not be safe. [48:01.910 --> 48:05.910] But there are sites out there that allow you to practice and do sorts of things like that. [48:06.750 --> 48:08.730] And then, again, just a disclaimer. [48:08.910 --> 48:11.210] Don't be stupid and hack something you don't have permission to. [48:11.510 --> 48:18.170] I mean, yes, you get that rush of, like, I just did something illegal and nobody's going to find out. [48:18.170 --> 48:28.350] Because if you do something wrong and it, you know, crashes a site or something like that, you know, that you did something that you didn't intend to do, you know, that's just... [48:28.350 --> 48:30.050] You're just being dumb then. [48:30.290 --> 48:36.830] And, you know, it's been talked about before the myth of, you know, the more I hack and the more elite I am, somebody will hire me. [48:36.910 --> 48:39.290] There's very few people who go that route, you know. [48:39.610 --> 48:44.270] There's a lot more people sitting in jail or, you know, not everybody is Kevin Mitnick. [48:46.530 --> 48:47.810] And I don't mean that in a bad way. [48:47.810 --> 48:51.730] I mean, he's one of the few that kind of went the, you know, and he started his own business. [48:51.850 --> 48:53.050] So, it's not like somebody hired him. [48:55.870 --> 48:57.470] This is the stuff we talked about. [48:58.310 --> 49:00.830] First, using the Firefox as a standalone browser. [49:01.230 --> 49:09.690] So, just using the tools, website-based tools, Google hacks, a bunch of extensions and plugins that you may have known of a few. [49:09.810 --> 49:17.270] How many of you have seen something today, like an extension or something that I was like, wow, I didn't know I could do that. [49:17.390 --> 49:17.930] And that's pretty cool. [49:18.050 --> 49:18.590] How many... [49:18.590 --> 49:20.090] Does everybody find something useful out of it? [49:20.250 --> 49:20.870] Great, great. [49:22.070 --> 49:23.890] Using Firefox as a front end. [49:24.090 --> 49:27.030] And we didn't talk about FISA once. [49:28.150 --> 49:28.850] Until now. [49:30.550 --> 49:33.090] I will also not mention anything political. [49:35.030 --> 49:38.170] And then recommended setup, places to hack safely. [49:38.410 --> 49:41.650] There's a lot of ideas out there for other extensions. [49:41.970 --> 49:45.070] And you can go to Firefox and you can make your own extensions. [49:45.230 --> 49:46.130] They have templates. [49:46.390 --> 49:56.330] And if you want Firefox to do something that it doesn't do, you might be able to figure it out yourself if someone else hasn't already done it. [50:00.070 --> 50:02.330] We've got about five minutes left. [50:02.430 --> 50:04.050] And we will open it up for questions. [50:04.210 --> 50:10.970] We ask that if you're going to ask questions, please go to the microphone so that it gets recorded and we can hear you and everyone else can hear you. [50:11.270 --> 50:14.130] Because if you yell at us, somebody else may not be able to talk to you. [50:22.350 --> 50:23.250] I think it's off. [50:27.180 --> 50:28.160] Check for a switch. [50:34.380 --> 50:35.020] Maybe not. [50:36.620 --> 50:37.520] Just yell it out. [50:41.760 --> 50:43.900] Yeah, um, let's see. [50:44.260 --> 50:45.340] Where are we going to post it? [50:45.540 --> 50:47.520] Can you give me a card or something like that? [50:47.520 --> 50:50.080] And if I post it, I'll send it out to a mailing list? [50:50.920 --> 50:52.720] We'll try to give this to the HOPE folks. [50:52.840 --> 50:55.060] And then hopefully you can get it via their website. [50:55.940 --> 50:57.380] That's probably the easiest way. [50:59.600 --> 51:02.780] Otherwise, you know, just ask us for the contact information and we can post it. [51:05.320 --> 51:06.500] the mic doesn't work. [51:07.460 --> 51:08.800] The mic doesn't work. [51:10.880 --> 51:11.740] Just come up. [51:11.820 --> 51:12.580] Just come up and ask. [51:13.360 --> 51:14.680] Microphone in the back isn't working. [51:15.440 --> 51:16.380] What's your website? [51:17.600 --> 51:19.360] I don't have a website. [51:19.360 --> 51:23.500] I don't have any websites, user agreements about... [51:23.500 --> 51:25.760] So what is the specific language that they use? [51:25.940 --> 51:27.580] Like, what would you be looking for in their terms of service? [51:27.600 --> 51:28.520] It varies for your site. [51:28.720 --> 51:37.740] What we really encourage you to do, if you're engaged to do a pen-test of a site for a company... [51:37.740 --> 51:43.540] I'm thinking more in the sense of, if you want to order something from a site, but maybe like, you know, I want to see if this is secure. [51:43.540 --> 51:45.920] They aren't using, you know, certain validation. [51:46.240 --> 51:48.040] You know, is all my stuff going to be... [51:48.040 --> 51:48.920] No, I think about the one. [51:49.180 --> 51:49.840] You know... [51:50.400 --> 51:57.900] One, you want to make sure the site's prepared, because there's a number of different plugins and add-ins that you can add these days. [51:58.560 --> 52:04.200] And then we'll check a site to see if it is secure and safe. [52:04.860 --> 52:09.340] McAfee's got one that is fairly good. [52:10.300 --> 52:10.660] Okay. [52:11.000 --> 52:12.780] So, we do a lot of work that's for it. [52:13.240 --> 52:14.280] We're to come up and... [52:14.740 --> 52:16.060] We're actually two years for BEA Systems. [52:16.520 --> 52:18.000] And also, I'm over there all the time. [52:18.140 --> 52:18.980] So, I want you to give me my card. [52:19.200 --> 52:19.420] Cool. [52:20.520 --> 52:20.880] From... [52:21.360 --> 52:22.520] Yeah, we're gonna... [52:22.520 --> 52:25.340] We'll give it to the HOPE books, and we'll find a way to get a more... [52:25.340 --> 52:27.220] Site Advisor is what it's called. [52:27.320 --> 52:28.180] McAfee Site Advisor. [52:28.540 --> 52:29.140] Oh, yeah, actually, I have one. [52:29.520 --> 52:29.720] Yeah. [52:30.320 --> 52:32.920] That's one I found is very, very useful and stuff.