<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: diminutive]]></title>
    <link>http://securityratty.com/tag/diminutive</link>
    <description></description>
    <pubDate>Fri, 04 Jan 2008 13:28:08 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Diminutive Worm Contest Wrapup]]></title>
      <link>http://securityratty.com/article/6d13b9777a184bcc19b56b633c0aa3be</link>
      <guid>http://securityratty.com/article/6d13b9777a184bcc19b56b633c0aa3be</guid>
      <description><![CDATA[While the fun is over, there is a lot to talk about in the wrap-up. So much so that I think it will take longer to deal with the output of the contest than the contest itself took. First of all, a...]]></description>
      <content:encoded><![CDATA[<p>While the fun is over, there is a lot to talk about in the wrap-up.  So much so that I think it will take longer to deal with the output of the contest than the contest itself took.  First of all, a huge congrats to both <A HREF="http://sla.ckers.org/forum/read.php?2,18790,page=19">Giorgio Maone and Sirdarckcat</A> for winning the contest with an incredibly small 161 byte worm.  They tied because they both had nearly the same vector and it worked equally well.  It was a tough battle and there were a lot of close calls, but various rules, cross browser compatibility and interoperability with Apache caused the pool of potential winners to be relatively small when the scoring was complete.  However, that&#8217;s not to diminish everyone&#8217;s work - everyone did amazingly and I was very impressed when it all came together.</p>
<p>But now that leaves us to the aftermath.  After looking at the contest for the first four days <A HREF="http://ha.ckers.org/xss-worms/">we may have figured out a way to potentially stop worm propagation</a>.  Unlike tracking this method actually may help companies devise plans on how to reduce the likelihood of worm propagation across their websites.  This should put to rest the nay sayers who thought nothing good could come of this contest.  The paper is not for everyone - it&#8217;s pretty complex (as worms tend to be), but I think the people who have the problem will understand how to use it in their own environments.</p>
<p>That said, there is at least two or three more potential outputs of this contest - including papers on propagation analytics, worm tracking technology, and potentially other things that I&#8217;m not privy to.  Was it worth it?  Absolutely.  I couldn&#8217;t have been happier with the results.  Thanks again to everyone who made it such a success.  It was a lot of work, but it was the first step towards large scale worm defense.  Again, a huge congrats to Giorgio Maone and Sirdarckcat!</p>
<!--Thu, 10 January 2008 19:01:15 +000-->]]></content:encoded>
      <pubDate>Thu, 10 Jan 2008 20:26:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/worm">worm</category>
      <category domain="http://securityratty.com/tag/stop worm propagation">stop worm propagation</category>
      <category domain="http://securityratty.com/tag/worm propagation">worm propagation</category>
      <category domain="http://securityratty.com/tag/scale worm defense">scale worm defense</category>
      <category domain="http://securityratty.com/tag/huge congrats">huge congrats</category>
      <category domain="http://securityratty.com/tag/giorgio maone">giorgio maone</category>
      <category domain="http://securityratty.com/tag/byte worm">byte worm</category>
      <category domain="http://securityratty.com/tag/cross browser compatibility">cross browser compatibility</category>
      <category domain="http://securityratty.com/tag/companies devise plans">companies devise plans</category>
      <source url="http://ha.ckers.org/blog/20080110/diminutive-worm-contest-wrapup/">Diminutive Worm Contest Wrapup</source>
    </item>
    <item>
      <title><![CDATA[Diminutive XSS Worm Contest Drama and Status Update]]></title>
      <link>http://securityratty.com/article/6cc26b39bb04fbbc92e101f0931e8488</link>
      <guid>http://securityratty.com/article/6cc26b39bb04fbbc92e101f0931e8488</guid>
      <description><![CDATA[Well, so far this week has probably been one of the most interesting Ive had in running this site in a long time, not only from a technical perspective, but the ethical debate on whether I am sheer...]]></description>
      <content:encoded><![CDATA[<p>Well, so far this week has probably been one of the most interesting I&#8217;ve had in running this site in a long time, not only from a technical perspective, but the ethical debate on whether I am sheer evil or contributing to the greater good rose it&#8217;s ugly head once again.  This was in regards to the <A HREF="http://ha.ckers.org/blog/20080104/diminutive-xss-worm-replication-contest/">diminutive XSS worm contest</a>.  One of my favorites was where I was being compared to <A HREF="http://rationalsecurity.typepad.com/blog/2008/01/grab-the-popcor.html#comment-96054688">arming people with nuclear weapons</a>.  Clearly, and admittedly most of these people have no background in the issue and have never read this site or the rest of sla.ckers, as there is lots of samples of existing worm code in lots of places on the Internet now.  Just because they don&#8217;t know about it doesn&#8217;t mean it&#8217;s not there.</p>
<p>The existing samples of code that we have are always plagued by three things though, which makes them difficult to work with and which I don&#8217;t care about.  Each contain obfuscation for filter evasion, which we&#8217;ve already researched to death, payloads, which we have also researched heavily and lastly site specific code, which really is uninteresting to me, unless I were trying to help out that company in particular solve an existing problem.  So the goal is to remove those things and focus on the actual XSS propagation, for which there has been little research done to date.</p>
<p>I&#8217;ve always said, you don&#8217;t understand a problem until you see it and play with it.  This is why having experience is always more valuable than schooling in a topic.  It&#8217;s like trying to get in a fist fight with a professional boxer having never sparred before and expecting to win.  <b>If working to help the understanding of worm propagation makes me evil, so be it</b>.  I&#8217;d rather be evil and be able to help solve problems than be good and be useless at solving the problem (as are most of the nay-sayers, I&#8217;ve found).  That&#8217;s why people like <A HREF="http://noscript.net/">Giorgio Maone</a> (the author of the noscript plugin) chipped in to help the contest.  People like him are solving the problem in their own ways as well.  It&#8217;s in everyone&#8217;s best interest to understand all the vectors.  Will this empower bad guys?  I&#8217;d be nieve to say there&#8217;s no chance of that.  However, the goal here is to understand why the propagation methods were chosen so we can build defenses against them.  We actually had tons of interesting findings that will help us narrow down the most dangerous strains, and start making suggestions to browser companies and security companies that are in development of security technologies so that they can build tools to prevent this.</p>
<p>For people who liken me to an anti-virus company writing viruses, I&#8217;d like to point out the fact of the matter which is that I don&#8217;t get paid to consult with browser companies on browser security (at least I haven&#8217;t in the last several years that I&#8217;ve been doing this).  In the spirit of full disclosure, I have gotten paid to help out with other things, but not browser security.  That&#8217;s right, I give advice in the browser security arena for free (for which I have actually been chastised by other executives who feel like I&#8217;m wasting my time since I&#8217;m not making any money on it).  I do it because I&#8217;m actually interested in solving the problem.  To date I also have never been paid by any company who has ever been hit by an XSS worm.  I have, however, on several occasions given them intel and advice, pro-bono.  Also, unlike an anti-virus company, I don&#8217;t have a security product in development.  So, yes, tin foil hat wearers can rest easy - this actually is academic.  I know, crazy talk!  That&#8217;s why this is an web app security lab.  People visit this site (or should, at least) with the knowledge that we are pushing the boundaries of what&#8217;s know about web application security.  We aren&#8217;t talking about yesterday&#8217;s problems.  <b>Think the bad guys are going to stop their own research if we stop talking about it?</b>  In this profit driven malicious ecosystem, there&#8217;s no chance of that anymore.  At least in an open format we can come up with solutions, and see the results of each other&#8217;s work.</p>
<p><A HREF="http://anti-virus-rants.blogspot.com/2008/01/ethical-conflict-in-webappsec-domain.html">Another interesting point of view, by Kurt Wismer</A> was that I was that by creating diminutive code I will always get an output of obfuscated code (which I have said a number of times I was trying to avoid) because of the coding tricks necessary to make it that small.  He&#8217;s absolutely right, of course, but that&#8217;s a red herring.  See, there are two types of obfuscation, which may be beyond the grasp of people who don&#8217;t actually work in this field.  The first type is obfuscation to create short/lean code.  The second is obfuscation for filter evasion (MD5ing something, hex encoding something, making something polymorphic, not using the word &#8220;eval&#8221; but &#8220;ev&#8221;+&#8221;al&#8221; to beat some regex or string matching, etc&#8230;).  I&#8217;m sorry I didn&#8217;t clarify - that&#8217;s probably non obvious for people who don&#8217;t understand webappsec.  So unfortunately, for the most part that&#8217;s actually not an interesting comment, although there are some tidbits in some of the variants of code that actually do cause some problems that I will need to disregard for the sake of research, which I&#8217;ll talk about after the contest is over.</p>
<p>Anyway, over the last few days I&#8217;ve been called a <A HREF="http://www.channelregister.co.uk/2008/01/05/worm_replication_contest/comments/#c_125694">moron, an idiot</a> and probably a half dozen other things.  But through it all, I&#8217;m 100% confident that this will lead to previously non-published/understood results about worm propagation (I&#8217;m confident, because it&#8217;s already yielded some various interesting problems that we have had to clarify using rules that I didn&#8217;t even think would come up).  And I&#8217;m also confident that this will lead to ways in which we can protect ourselves from them - not today, certainly, but over time as we as a community start building tools to prevent these issues based, in part, on the results of this contest.  I wouldn&#8217;t guess that everyone reading this will &#8220;get it&#8221; as most people don&#8217;t really understand how the security world works.  I would, however, hope that everyone sits tight and holds their dramatic postings for the results, or at least asks me what I think instead of jumping to wild conclusions.  Christmas is already over though, and I already got my wishes granted so I won&#8217;t be surprised if it doesn&#8217;t happen.  <img src='http://ha.ckers.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So that&#8217;s the drama!  Gotta love it, huh?  Where would I be without the under-educated rants and conspiracy theories?  The good news is that there is a lot of really interesting research coming out of the contest, and numbers are approaching the 150-170 byte range.  We&#8217;re already seeing some trends emerge about the most size efficient ways to write the code, and the ways in which the code must work for best propagation results and portability.  The two methods of actual spread that appear to be building to a consensus among the submissions are XMLHttpRequest and submit events.  We&#8217;ll see how things turn out, but I&#8217;m quickly getting a feeling these are by far the two most likely candidates for worm propagation.  My question is what sort of valid reasons can people come up with on why the browser should automatically submit a form without user interaction?  More detailed analysis to come once we get closer to the cutoff.  Amazing stuff!</p>
<p>Pandora is already out of the box, folks, and for good or bad Samy was the culprit, not me.  Time to start working on solutions, rather than trying to keep the research quiet.</p>
<!--Sun, 06 January 2008 13:01:52 +000-->]]></content:encoded>
      <pubDate>Sun, 06 Jan 2008 14:34:38 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser companies">browser companies</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/browser security arena">browser security arena</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/people visit">people visit</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/worm code">worm code</category>
      <category domain="http://securityratty.com/tag/diminutive xss worm">diminutive xss worm</category>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <source url="http://ha.ckers.org/blog/20080106/diminutive-xss-worm-contest-drama-and-status-update/">Diminutive XSS Worm Contest Drama and Status Update</source>
    </item>
    <item>
      <title><![CDATA[Diminutive XSS Worm Replication Contest]]></title>
      <link>http://securityratty.com/article/344db5d72e2ce2559ca116abd8f02c97</link>
      <guid>http://securityratty.com/article/344db5d72e2ce2559ca116abd8f02c97</guid>
      <description><![CDATA[For those of you who are familiar with the RSA diminutive munitions project from ages ago, back when it was illegal to export certain crypto systems , and the diminutive PERL contests Ive enacted a...]]></description>
      <content:encoded><![CDATA[<p>For those of you who are familiar with the <A HREF="http://www.cypherspace.org/adam/rsa/">RSA diminutive munitions project</a> from ages ago, back when <A HREF="http://www.cypherspace.org/adam/rsa/legal.html">it was illegal to export certain crypto systems</a>, and the <A HREF="http://incompetech.com/gallimaufry/vipul.html">diminutive PERL contests</A> I&#8217;ve enacted a similar contest to write a diminutive self replicating XSS worm (with a non-dangerous payload).</p>
<p><A HREF="http://sla.ckers.org/forum/read.php?2,18790,18790">The diminutive XSS worm replication contest</a> is a week long contest to get some good samples of the smallest amount of code necessary for XSS worm propagation.  I&#8217;m not interested in payloads for this contest, but rather, the actual methods of propagation themselves.  <A HREF="http://sla.ckers.org/forum/read.php?2,14477">We&#8217;ve seen the live worm code</a> and all of it is muddied by obfuscation, individual site issues, and the payload itself.  I&#8217;d rather think cleanly about the most efficient method for propagation where every character matters.</p>
<p>digi7al64 has already posted a sample piece of code, setting the baseline.  His code is an impressively small 292 characters.  There&#8217;s no prize here, however, I will definitely be talking about the winner&#8217;s code.  The winner will be announced on the 10th after all submissions are in and posted.  Visit the thread for more details.  This should be interesting for anyone looking at worm propagation issues!</p>
<!--Fri, 04 January 2008 13:01:47 +000-->]]></content:encoded>
      <pubDate>Fri, 04 Jan 2008 13:28:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xss worm">xss worm</category>
      <category domain="http://securityratty.com/tag/propagation">propagation</category>
      <category domain="http://securityratty.com/tag/worm propagation issues">worm propagation issues</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/diminutive">diminutive</category>
      <category domain="http://securityratty.com/tag/live worm code">live worm code</category>
      <category domain="http://securityratty.com/tag/xss worm propagation">xss worm propagation</category>
      <category domain="http://securityratty.com/tag/winners code">winners code</category>
      <category domain="http://securityratty.com/tag/diminutive perl contests">diminutive perl contests</category>
      <source url="http://ha.ckers.org/blog/20080104/diminutive-xss-worm-replication-contest/">Diminutive XSS Worm Replication Contest</source>
    </item>
  </channel>
</rss>
