Tuesday, February 8, 2011

صورة من ميدان التحرير

في ناس كتير -للاسف- لحد النهرده مرحتش التحرير, إزاي التحرير فيه كل طوائف المصريين!!, إزاي المسيحي والمسلم, الليبرالي والشيوعي, السلفي والاخواني كل دول في مكان واحد

أنا هحاول ارسملك صورة من التحرير عشان تصدق إنك ليك مكان هناك مهما كان توجهك السياسي أو حتى لو مالكش أي توجه زي معظم الموجودين هناك

هانتنزل من المترو محطة الأوبرا وتتمشى على كوبري قصر النيل, العربيات حواليك والناس في كل مكان مئات مروحين من الميدان والاف بدلهم داخلين,خلصت الكوبري هتلاقي صف دبابات واقف جنب مكتبة الجامعة الأمريكية وناس مدنيين عاملين صف بعرض الشارع

,بابتسامة, واحد منهم هيطلب منك البطاقة هتلاقيه مهتم إنه يشوف الوظيفة - تقريبا مش بيدخل حد تبع الأمن - وهيفتشك,

طبعا في بنات موجودين في اللجنة ده عشان يفتشوا البنات

خلصت تفتيش هتبدأ مظاهر الإحتفالات صفين طوال نسبيا بتاع 25 متر بيصفقو ليك ويغنوا لك

أهم أهم أهم, المصريين أهم

كله بيضحكلك في الغالب هتكون أول مرة تحس فيها إنك مهم قوي كده, كل الناس ده فرحانة بيك, طبل وأغاني وزمامير عشانك إنت بس

على اديك الشمال مسجد عمر مكرم مليان على اخره اللي بيصلي واللي نايم واللي عايز يروح الحمام, كمل مشي

الميدان على بعد 70 متر أهو, هتلاقي الحتة ديه الصحفيين والمراسلين بالكاميرات بيتكلموا مع الناس لو ليك فالجو ده برشت على أي قناه

طيب أروح فين من هنا بقى

بص يا سيدي التقسيمات من هنا كتير

بإختصار فيه 6 تقسيمات

القسم الديني

القسم الترفيهي

القسم السياسي

قسم اللوحات

قسم الخيم

القسم الطبي

القسم الثورجي

القسم الديني

وده في الغالب موجود عند تمثال عمر مكرم وشوية عند المجمع هتلاقي ازهريين كتير بالعمة والقفطان وملتحين بيدعوا أو بيقولوا خطب سياسية بمرجعية دينية, أذكار الصباح والمساء, يعني أنت فاهم الجو ده

القسم الترفيهي

وده قسمي المفضل وده موجود مابين المجمع و الميدان, بتاع 200 سماعة فوق بعض و واحد ماسك عود أو فريق ماسكين جيتارت أو طبول وبيغنوا, بص جامدين موت أنا فاكر شوية لسة من كلمات الاغاني

يا مصر يا أجمل دولة في الكون, العاقل فيكي يشوف نفسه مجنون

وفاكر برضه

قالوا مجنون اللي يفكر الدنيا فيها أكتر ويقول إزاي ومنين

قالوا مجنون اللي يخلي مبارك كابس تملي من سنة واحد وتمانين

طبعا مش دايما بيبقى فيه ناس بتغني ساعات برضه تلاقي في المكان ده خطب سياسية

القسم السياسي

وده مركزه عند هارديز وبيملك اكبر عدد من السماعات المنتشرة في كل مكان

وده برده المكان اللي بنصلي عنده وفالغالب بيكون فيه قنوت في الصلاه

هتلاقي بقى هنا كل الناس بيقولوا خطب وشعارات سياسية

عبد الحليم قنديل

العوا

نادر السيد

ناس مجهولة

لو عايز تحس بجو المظاهرات فـده مكانك بالتأكيد

قسم اللوحات

وده موجود في كل مكان, الشعب المصري اثبت موهبة مدفونة في الموضوع ده

ده شوية من اللي فاكره

مبارك, طير أنت

يا مبارك يا طيار جبت منين 70 مليار

ارحل بقى ابوس التيت

بص جامدين جدا, الاف من الناس معاها شعارات جامدة السنين

قسم الخيم

كل يوم حجمهم بيزيد موجودين في كل الجناين, الميدان و تمثال عمر مكرم في جوانب الشوارع

هتلاقي جواه ناس نايمة أو مستلقية أو ناس بتاكل

كل المستويات موجودة الفلاح نايم جنب المحامي جنب المهندس جنب أطفال

ساعات بتبقى شباب نفس المحافظة مع بعض, تلاقي كتبلك على الخيمة تجمع أبناء سوهاج

بص ظراف عدي على أي حد منهم هتلاقيهم بيكلموك وعايزينك تاكل معاهم أو يواسعولك حتة تنام فيها

القسم الطبي

وده برضه منتشر في حتت كتير, الخيمة الكبيرة في قلب ميدان التحرير و فيه خيم ناحية عبد المنعم رياض عشان ده مكان هجوم البلطجية. مئات من الداكترة منتشرين في كل حتة من جميع التخصصات

الظريف بقى إن الدكاترة ده ظهروا أصلا عشان يسعفوا المصابين في يوم الأربع الاسود, بس هتلاقي ناس جيالهم من البيت مخصوص عشان يكشفوا ببلاش. كل الدكاترة اللي هناك بيكشفو على أي حد ببلاش سواء كانت اصابة المعارك أو واحد عايز يكشف عادي. مفيش بقى استغلال الدكاترة اللي معروف. كل الناس ظريفة اكننا شعب تاني

القسم الثورجي

وده القسم الاكثر خطورة وده من عند عبد المنعم رياض لحد مدخل المتحف المصري, شباب معظمهم اصيب في الإشتباكات اللي فاتت -معظمها اصابات في الرأس- ومصممين يدافعوا عن الميدان

للأسف هتلاقيهم مبهدلين قوي اللي لبسه مقطع واللي الطينة لازقة في وشه هاتفتكرهم في الأول متسولين أو ناس غلبانة والمفاجأة إن معظمهم دكاترة أو اساتذة في الجامعة أو مهندسين حالفين مش هيسيبوا المكان ده إلا لما مبارك يمشي وانهم حيدافعوا عن الميدان بحياتهم. اللي رجلوا اتكسرت وبرده مش عايز يسيب مكانه

فيه جزء منهم بينام جوه الجنازير بتاعت المدرعات عشان المدرعات متسبش المكان وبيبدلوا

عاملين هناك زي متحف صغير للشهداء, فيه صور الشهداء ولبسهم اللي لسة فيه دم

الناس ده عندهم عزيمة مشفتهاش قبل كده, ربنا يكرمهم ويديهم ثواب المرابطين

يا ترى بقى إنت مكانك فين هناك؟

طبعا وأنت ماشي هتحس إن كل المشاعر اللي في الدنيا جواك

الفخر, الخوف , الحب, الضحك, القهر, العزة, والكبرياء

مش عارف فعلا اوصفلك هتحس بإيه بس عمرك م هتلاقي الإحساس ده في مكان تاني

صفين طوال حتقبلهم وإنت مروح بردو بيغنولك ويقولوا

معادنا بكرة وبعد بكرة

إن شاء الله احنا نفسنا أطول ومش هنسيب الميدان لحد لما الظالمين يسيبوا البلد

شكرا لوقتك لو عايز تقابلني أنا موجود في التحرير كل يوم

Thursday, March 18, 2010

Cairo Code Camp 2010 and my Security sessions

27th and 28th of Feb DotNetWork organized one of the biggest IT conferences in the Middle East, it's Cairo Code Camp 2010. I was honored to be one of the speakers in the event. My main talks were about Application Security.
Frankly the audience I had were the best I ever saw. people were really so excited about the topic, unfortunately most of them almost knew nothing -or very little- about "Application Security" which is a little bit disappointing. but the good news is my sessions -especially the second- was crowded. This means that we do have now an increased number of "Security Aware" developers :).


Here is the sessions Slides

Application Security Fundamentals



Application Security Attacks






I would like also to share some photos for the event and my sessions

This was for the audience of the second session "Application Security Attacks"















that was my special thanks to the audience -they know what does it mean :)-















This is from the first session "Application Security Fundamentals"





Sunday, June 14, 2009

What happened in the last quarter of 2007

This post is totally unrelated to "Application Security", I was quering Google Trends for some websites and I found a very strange peek at the last quarter of 2007 for all major websites, does anyone know what happened?









































Try any other major website and you'll see this peak, is it a bug in Trends or was there an important event that I missed?

Tuesday, June 2, 2009

Torpig: The most advanced pieces of crimeware ever created, Part 1

A group of researchers from the University of California, Department of Computer Science, Security Group made a comprehensive research[must read] about what is known to be "The most advanced pieces of crimeware ever created".

Torpig worth a lot of attention from the community so I decided to write two posts about Torpig.
part 1 will be just an overview about how Torpig works, and most importantly part 2 which will discuss the weaknesses of the Torpig and raise the question of "If this malware were designed without these weaknesses -I'll suggest how-. How can good guys defeat it"

Torpig is a sophisticated malware program that is designed to harvest sensitive information (such as banks account and credit cards data) from the machines it infects.
What is very unique about this malware is its ability to spread, collect sensitive information from infected machines and communicate with the botmaster to provide him with the collected data.

First, let's start by understanding how this malware works -according to the paper-.

* The malware spread using different techniques (drive-by download).
The fact here that we have at least 182,800 infected machines and the number is increasing

















* The downloaded executable acts as an installer for Mebroot. The installer injects a DLL into the file manager process (explorer.exe), and execution continues in the file manager’s context.
This makes all subsequent actions appear as if they were performed by a legitimate system process. The installer then loads a kernel driver that wraps the original disk driver (disk.sys). At this point, the installer has raw disk access on the infected machine. The installer can then overwrite the MBR of the machine with Mebroot. After a few minutes, the machine automatically reboots, and Mebroot is loaded from the MBR.














* The malware gather sensitive information using a lot of techniques (e.g. gather all web traffic made by the infected machine, use phishing attacks for banks and major financial sites (PayPal), email clients, instant messengers, etc)










* The malware uses the "domain flux" (periodically generate a large list of domain names infected machines are to report to)












well this is how generally Torpig works, please refer to the paper to get more details about it. and follow the next post that will discuss the weaknesses of Torpig and how it could have been mitigated.

Thursday, May 28, 2009

Web Application Security Trends Q3-Q4 2008

The "Web Application Security Trends Q3- Q4 2008" is published, I guess there are a lot of interesting findings in this report, I'm sharing here with you what I see the most important stuff

1- SQL injection got its first position back over XSS














2- as expected more and more hackers are joining the club












3- IE and FF are gaining almost the same attention












4- CSRF is gaining more attention everyday















5- more important, CSRF was usually exploited by whitehats for demonstrations, Q3-Q4 2008 is the first time for blackhats to use it. So I guess more attention should be paid now for it.















if you have any comments about this report please share it with me in the comments area.

Tuesday, May 19, 2009

Yahoo Groups Voting Vulnerability

I found a very interesting security bug at Yahoo Groups Voting System, exploiting this bug leads to complete control of the voting result. 

You can watch the video to see how I made 4 polls -they could be more- using a single account


<br/><a href="http://video.msn.com/video.aspx?vid=cf581209-ad25-4920-821f-0a11bf849cf4" target="_new" title="Yahoo Groups Voting Bug">Video: Yahoo Groups Voting Bug</a>

Bug Demonstration
It's clear that the voting system is differentiating between different users by examining the email address that is associated with the group, and since you can add unlimited number of emails associated with single Yahoo ID and the group settings allow you to change between these emails. you can simply add your vote then change the associated email then vote again as a new voter, you can keep repeating this until you fully manipulate the voting results to the one of your choice.

Simple steps to reproduce this security bug
1- go to the poll of your choice
2- select your candidate of the choices
3- click "Edit Membership"
4- under "Email Address" click "Add new email address" and verify it
5- keep repeating step 4 until you add sufficient number of email addresses
6- now choose any of them as your default associated email
7- go to the poll again and congratulations you can add your vote as it's your first time to add it
8- keep changing the associated email address until your candidate of the vote options win :)

Conclusion
It's very clear that this bug is a security logic vulnerability and hince no static code analysis tool is able to find it (never depend on static code analysis tools only).
Although it's very easy to exploit this vulnerability (I didn't write scripts, didn't run automated scans or use any complex method to exploit this vulnerability) the imact of the vulnerability is very high (maybe all the votes that were created before were manipulated).
There could be more vulnerabilities in Yahoo Groups that I didn't investigate if they have more stuff depending on the associated email 

Keep checking this blog as I decided to publish more and more security vulnerabilities at major websites, since they never fix their issues unless you fully disclose their bugs :)


Sunday, April 26, 2009

CSRF session at Microsoft innovation day (22nd April, 2009)



I was invited by the CuttingEdge Club to make a presentation about "Application Security" in Microsoft Innovation Day, I thought first that most of the attendees will be professional developers so I decided to exclude common topics in application security like "XSS, SQL Injection, Input Validation".

I decided to make it about "Cross Site Request Forgery" specifically the session title was "How do I: Protect from Cross Site Request Forgery in ASP.NET". I think it was quite interesting for the audience -specially that most of the other sessions were about SharePoint-.

I found out later that most of the attendees are students so I tried to use only simple terms -I don't think I managed to do it- as CSRF is quite complicated by nature and most developers confuse it with XSS.

Anyway I think I managed to spread the awareness of application security vulnerabilities and their huge impact -either financially or from privacy prospective- on the internet today.


Here is the presentation