Episode 354: Here Come the Script Kiddies




TechSNAP show

Summary: <p>AutoSploit has the security industry in a panic, so we give it a go. To our surprise we discover systems at the DOD, Amazon, and other places vulnerable to this automated attack. We’ll tell you all about it, and what these 400 lines of Python known as AutoSploit really do.</p> <p>Plus injecting arbitrary waveforms into Alexa and Google Assistant commands, making WordPress bulletproof, and how to detect and prevent excessive port scan attacks.</p><p>Sponsored By:</p><ul> <li> <a rel="nofollow" href="https://do.co/snap">Digital Ocean</a>: <a rel="nofollow" href="https://do.co/snap">Apply our promo snapocean after you create your account, and get a $10 credit.</a> Promo Code: snapocean</li> <li> <a rel="nofollow" href="http://techsnap.ting.com">Ting</a>: <a rel="nofollow" href="http://techsnap.ting.com">Save $25 off a device, or get $25 in service credits!</a> Promo Code: Visit techsnap.ting.com</li> <li> <a rel="nofollow" href="http://ixsystems.com/techsnap">iXSystems</a>: <a rel="nofollow" href="http://ixsystems.com/techsnap">Get a system purpose built for you.</a> Promo Code: Tell them we sent you!</li> </ul><p>Links:</p><ul> <li> <a title="Audio Adversarial Examples" rel="nofollow" href="https://nicholas.carlini.com/code/audio_adversarial_examples/">Audio Adversarial Examples</a> — We have constructed targeted audio adversarial examples on speech-to-text transcription neural networks: given an arbitrary waveform, we can make a small perturbation that when added to the original waveform causes it to transcribe as any phrase we choose.</li> <li> <a title="Keylogger found on thousands of WordPress-based sites, stealing every keypress as you type" rel="nofollow" href="https://hotforsecurity.bitdefender.com/blog/keylogger-found-on-thousands-of-wordpress-based-sites-stealing-every-keypress-as-you-type-19501.html">Keylogger found on thousands of WordPress-based sites, stealing every keypress as you type</a> — But, in a twist, this particular attack isn’t just interested in mining Monero. While the website’s front-end is digging for cryptocurrencies, the back-end is secretly hosting a keylogger designed to steal unsuspecting users’ login credentials.</li> <li> <a title="Qubes Air: Generalizing the Qubes Architecture | Qubes OS" rel="nofollow" href="https://www.qubes-os.org/news/2018/01/22/qubes-air/">Qubes Air: Generalizing the Qubes Architecture | Qubes OS</a> — Qubes Air is the next step on our roadmap to making the concept of “Security through Compartmentalization” applicable to more scenarios. It is also an attempt to address some of the biggest problems and weaknesses plaguing the current implementation of Qubes, specifically the difficulty of deployment and virtualization as a single point of failure. While Qubes-as-a-Service is one natural application that could be built on top of Qubes Air, it is certainly not the only one. We have also discussed running Qubes over clusters of physically isolated devices, as well as various hybrid scenarios. I believe the approach to security that Qubes has been implementing for years will continue to be valid for years to come, even in a world of apps-as-a-service.</li> <li> <a title="Making network authentication simple in a Bring Your Own Device environment" rel="nofollow" href="https://medium.com/@anatole.beuzon/making-network-authentication-simple-in-a-bring-your-own-device-environment-9080baf39617">Making network authentication simple in a Bring Your Own Device environment</a> — In this article, we explore in depth the challenges we faced regarding compatibility, security, and user experience, and the solutions we came up with. We explain how we combined 802.1X authentication (wired &amp; wireless) and per-subscriber VLANs to offer our users a quality Internet experience.</li> <li> <a title="“Autosploit” tool sparks fears of empowered “script kiddies”" rel="nofollow" href="https://arstechnica.com/information-technology/2018/02/threat-or-menace-autosploit-tool-sparks-fears-of-empowered-script-kiddies/">“Autosploit” tool sparks fears of empowered “script kiddies”</a> — "AutoSploit attempts to automate the exploitation of remote hosts."</li> <li> <a title="AutoSploit: Automated Mass Exploiter" rel="nofollow" href="https://github.com/NullArray/AutoSploit">AutoSploit: Automated Mass Exploiter</a> — Clone the repo. Or deploy via Docker.</li> <li> <a title="How To Use psad to Detect Network Intrusion Attempts" rel="nofollow" href="https://www.digitalocean.com/community/tutorials/how-to-use-psad-to-detect-network-intrusion-attempts-on-an-ubuntu-vps">How To Use psad to Detect Network Intrusion Attempts</a> — The key to using psad effectively is to configure danger levels and email alerts appropriately, and then follow up on any problems. This tool, coupled with other intrusion detection resources like tripwire can provide fairly good coverage to be able to detect intrusion attempts.</li> <li><a title="Portainer: Simple management UI for Docker" rel="nofollow" href="https://github.com/portainer/portainer">Portainer: Simple management UI for Docker</a></li> <li><a title="What is iSCSI (Internet Small Computer System Interface)" rel="nofollow" href="http://searchstorage.techtarget.com/definition/iSCSI">What is iSCSI (Internet Small Computer System Interface)</a></li> </ul>