Wednesday, December 14, 2016

Skills to build upon


There’s fun things to check out this holiday season! The SANS Holiday Hack Challenge just came out a few days ago. That’s a fun challenge that is accessible in a variety of ways to people with different skills and levels. Additionally, the previous year challenges and answers are also available which is pretty nice.

A skill I am increasingly spending more of my free time on involves manual code review and assessment. I use free tools (like those used in the SWAMP), but they seem to only find a handful of the issues in the code I’ve been checking out. I will be starting a new blog series exploring this and assessing code from different perspectives.

In the meantime, check out these resources from the Trail of Bits CTF Field Guide:

Not from the ToB site:

When this blog series starts, having reviewed those resources will be helpful!

Tuesday, December 13, 2016

Omaha OWASP Dec 2016 presentation

Last week I presented at the local Omaha OWASP chapter an overview of the SWAMP. It was a lot of fun to talk about the SWAMP, both in the cloud and the new on-prem (SWAMP-in-a-box) version. I've uploaded my presentation up at SlideShare and linked it here below.

http://www.slideshare.net/AndrewFreeborn/omaha-owasp-dec-2016

Thanks!

Tuesday, December 6, 2016

Fuzzy Assessment: Part 7 - Threadfix in the SWAMP

In the previous post, we viewed the results of the assessment with Code Dx. Another tool available in the SWAMP is ThreadFix. Different views of the same data may provide the other perspective needed to better remediate a vulnerability finding.

Let’s get back into the SWAMP!

  1. Log into the SWAMP
  2. We already have the package ready and assessed, so let’s click on “Results”


  3. Change the viewer from “Code Dx” to “Threadfix”


  4. Scroll down to the package results (in our case OpenSSH 4.3 blog2) and check the far left checkbox. After I did this step, the viewer changed back to “Code Dx”. Make sure your viewer is still set to “Threadfix”.


  5. If you scroll back down, at the time of this writing, only Clang is compatible with Threadfix and the only one that can be checked
  6. Scroll back to the top and click on “View Assessment Results” ensuring that Threadfix is still selected
  7. A new window should open up with a viewer to the results of the scan that’ll use Threadfix
  8. Click on “Latest Analysis Run” for the correct package


  9. After the viewer loads, click on “Scans” at the top


  10. This screen below shows some interesting results. Let’s review the first option with 16 results and click the “View Scan” link.


  11. In the “Mapped Findings” screen, we see all of the vulnerabilities from the scan:


  12. Let’s see more detail in the “packet.c” vulnerability finding. Click “View Finding” on this line:


  13. Here we can see additional detail for this finding:




There is not much more to say about this tool and the way we can look at vulnerabilities. Clicking on “Dashboard” at the top will return you to the main Threadfix screen that allows you to drill into vulnerability findings in a variety of ways that can help you track down specific issues.

Thursday, November 3, 2016

Fuzzy Assessment: Part 6 - Positives results from the SWAMP

In the previous post, we performed the right steps for a successful assessment of OpenSSH 4.3 in the SWAMP. As we learned, those results were hard won! Now we have a lot of results!

Let’s take a deeper look at what we have available to us:

  1. Log into the SWAMP
  2. Click on “Results”
  3. Click “any package”


  4. Change the dropdown for the package to the appropriate version (in our case “OpenSSH 4.3 blog2”)
  5. Now we can see results to this specific package with our successful results!


  6. At the top, we see “Viewer” with three radio buttons of “Code Dx”, “Threadfix”, and “Native”. The default option is “Code Dx” which is one of two options to coalesce results from analysis tools into a single pane of glass. The second option is “Threadfix” which is another option to view results from multiple tools into a single pane of glass. The third option of “Native” displays the result of the tool from the standard output of the tool and may or may not be pretty.
  7. To view the results of an assessment is a little bit confusing as there are a lot of things to click on. Let’s leave the default viewer of “Code Dx” selected.
  8. Click on the checkbox for GCC (but there’s two!). Click on the right-most GCC checkbox.


  9. Navigating the checkboxes becomes easier to understand. For instance, in the screenshot above, we see 5 checkboxes. The topmost checkbox would select all results on the page to view. The leftmost checkbox would select all of the results from that particular run. The second, third, and fourth rightmost checkboxes would select the results from the individual tools.
  10. We are going to see the results from GCC from this particular assessment.


  11. You may be tempted to click on “finished” for the GCC line expecting to see the 3,145 bugs from GCC. However, these are not the droids you’re looking for. If you were to click on “finished”, you would get the details of the GCC assessment itself, not the results of the assessment. Below are the details of the GCC assessment:


  12. If you clicked on “finished” click and see these results above, click on the “Ok” button at the bottom of the screen. Back in the main results screen, click the second, rightmost checkbox for GCC results as in step 10.
  13. To see the results from the tool, we need to make sure we have the lines we wanted selected and click “View Assessment Results”


  14. A new window will pop open and a viewer for our tool will be instantiated with our data.


  15. Once the viewer for Code Dx is ready, you may see results from other packages or just this one depending on what you’ve done in the SWAMP. In our case, we see this:


  16. Click on “Latest Analysis Run” to see the results from this assessment
  17. Here we can see all of the data that GCC found with OpenSSH 4.3


  18. With Code Dx, we have a lot of different ways to play with this data and do so much. We can filter data on the left by severity, flaws, or any number of ways. If we filter the data by “Tool”, “Type Conversion”, and then “signed to unsigned conversion”, we can see the data filtered as below.


  19. There’s a lot of things we can do further from here. We could filter the data to even more narrow results and then assign those issues to someone to fix with exact location. Let’s take a look at what kind of details we get.
  20. Click on “6261”


  21. A new window will pop open with all of this juicy detail below:


  22. Oh no, “goto” statements are used (line 1123). At least it’s not “goto fail”. But, we see things like the type conversion issue at line 1130, links to all kinds of sources, the ability to make notes, and more!


We briefly reviewed the results from the GCC tool within Code Dx. As we can see there is a lot of capability for teams to use the SWAMP to help secure their software! In the next post, we’ll go over Threadfix and continue to examine the results.