Friday, September 26, 2008

2008 OWASP USA Roundup

On Wednesday, I had the pleasure of attending the 2008 OWASP USA Conference in NYC. While I could only attend day one (start-up life, what can I say), it was well worth the visit. As with any conference, it wasn't possible to hit all of the talks that I was hoping to see but there were a few highlights.

Clickjacking - yea, this is bad... (Jeremiah Grossman and Robert 'RSnake' Hansen)
This is one of the talks that I was particularly looking forward to given that it was to reveal a new client-side exploitation technique. Unfortunately, ahead of the conference, Jeremiah and Robert decided to pull the talk as Adobe had requested additional time to address the vulnerabilities before details were made publicly available. In the end they proceeded with the talk but were limited to discussing why they had chosen not to proceed, so very little was disclosed that wasn't already known. I was pleased to see Adobe acknowledge the choice made my Jeremiah and Robert. Adobe has come a long way from the arrest of Dmitry Sklyarov at Blackhat in 2001. While I'm sure that I would have made the same decision as Jeremiah and Robert, it always makes me nervous when knowledge of the existence of a vulnerability is public but the timeline for details is in the hands of vendors. If Dan Kaminsky's DNS vulnerability taught us one thing, it's that you can't 'kind of' disclose a vulnerability without peaking the interest of smart and motivated researchers that are likely to beat the vendor to the punch.

Http Bot Research (Steven Adair)
Andre' DiMino was unable to present due to a work conflict but Steven did great job flying solo. I'm particularly intrigued by the growth of HTTP as the protocol of choice for bot herders. It's a logical progression from IRC and P2P based botnets, given the ubiquity of HTTP traffic. Ports 80 and 443 are always open on corporate networks and it's easy for C&C traffic to hide like a needle in a haystack among the sea of requests/responses traversing a typical network. Steven even went so far as to state his belief that HTTP is now the dominant protocol for C&C traffic. I discussed this with him afterward given that C&C blacklists that I've seen to date typically have minimal port 80/443 addresses. He felt that this is more a reflection of our comfort with detecting IRC based botnets, which has been largely automated and not a reflection of the real distribution. When it comes to analyzing HTTP based C&C traffic, we still have plenty to learn.

Industry Outlook Panel
Being a New York based conference, we were treated to a panel filled with true industry heavyweights. CISO and SVPs from a half dozen major financial institutions discussed their thoughts on where web security needs to go in the financial sector. It was certainly an interesting time for such a panel given the current financial crisis. Half of the panel had inherited new employers in the past week while the other half were coping with new regulations thanks to becoming commercial banks literally overnight.

All in all, the conference was another great OWASP initiative. My hat is off to Jeff Williams, Dave Wichers, Tom Brennan, Dinis Cruz and the rest of the crew for all of their hard work.

- michael

No comments: