{"id":20275,"date":"2012-07-20T15:09:54","date_gmt":"2012-07-20T21:09:54","guid":{"rendered":"http:\/\/rankexploits.com\/musings\/?p=20275"},"modified":"2012-07-20T15:09:54","modified_gmt":"2012-07-20T21:09:54","slug":"sophisticated-and-carefully-orchestrated-attack-or","status":"publish","type":"post","link":"https:\/\/rankexploits.com\/musings\/2012\/sophisticated-and-carefully-orchestrated-attack-or\/","title":{"rendered":"Sophisticated and carefully orchestrated attack? Or?"},"content":{"rendered":"<p>So the Climategate investigation is closed. We are told it was a &#8220;sophisticated and carefully orchestrated attack on the CRU\u00e2\u20ac\u2122s data files, carried out remotely via the internet&#8221;<\/p>\n<p>So, today, I saw something that made me wonder if The Blackboard is currently the focus of a &#8220;sophisticated and carefully orchestrated attack on [its] data files, carried out remotely via the internet&#8221;. Here&#8217;s a connection my software blocked today:<\/p>\n<p><code><br \/>\n#: 77327 @: Fri, 20 Jul 2012 00:51:24 -0700 Running: 0.4.10a1<br \/>\nHost: 95-65-87-21.starnet.md<br \/>\nIP: 95.65.87.21<br \/>\nScore: 1<br \/>\nViolation count: 1<br \/>\nWhy blocked: Bothost and\/or Server Farm (credit: eclecticdjs.com). ( 0 ); c= MD<br \/>\nQuery:<br \/>\nReferer:<br \/>\nUser Agent: WhatWeb\/0.4.7<br \/>\nReconstructed URL: http:\/\/ rankexploits.com \/<br \/>\n<\/code><\/p>\n<p>As happens on a nearly daily basis, something emanating from a suspicious server in Moldova got blocked. I think: &#8220;What the heck is WhatWeb\/0.4.7? &#8221;  <\/p>\n<p>So I googled to find <a href=\"http:\/\/www.morningstarsecurity.com\/research\/whatweb\">their self description:<\/a><\/p>\n<blockquote><p>Next generation web scanner. Identify what websites are running.<br \/>\nDownload whatweb-0.4.7.tar.gz<br \/>\nLatest Version 0.4.7, 5th April 2011<br \/>\nLicense GPLv2<br \/>\nAuthor urbanadventurer aka Andrew Horton from Security-Assessment.com<br \/>\nWiki The WhatWeb Wiki<br \/>\nDevelopment Version WhatWeb on GitHub<\/p>\n<p>Introduction<\/p>\n<p>WhatWeb identifies websites. Its goal is to answer the question, \u00e2\u20ac\u0153What is that Website?\u00e2\u20ac\u009d. WhatWeb recognises web technologies including content management systems (CMS), blogging platforms, statistic\/analytics packages, JavaScript libraries, web servers, and embedded devices. WhatWeb has over 900 plugins, each to recognise something different. WhatWeb also identifies version numbers, email addresses, account IDs, web framework modules, SQL errors, and more.<\/p>\n<p>WhatWeb can be stealthy and fast, or thorough but slow. WhatWeb supports an aggression level to control the trade off between speed and reliability. When you visit a website in your browser, the transaction includes many hints of what web technologies are powering that website. Sometimes a single webpage visit contains enough information to identify a website but when it does not, WhatWeb can interrogate the website further. The default level of aggression, called \u00e2\u20ac\u02dcpassive\u00e2\u20ac\u2122, is the fastest and requires only one HTTP request of a website. This is suitable for scanning public websites. More aggressive modes were developed for in penetration tests.<\/p><\/blockquote>\n<p>It continues&#8230;.<br \/>\nFor those wondering what I think this looks like:<br \/>\nSince <I>I&#8217;m<\/i> not running the scan, it looks like it could be someone running a scan to figure out how to hack my blog. More creatively, it could be someone who wants me to learn of the existence of their software hoping I will see this in my logs, visit their site and then buy the software.<\/p>\n<p>For another discussion of &#8220;webapplication fingerprinting&#8221; you can go <a href=\"http:\/\/anantshri.info\/articles\/web_app_finger_printing.html#theory\">here<\/a>:<\/p>\n<blockquote><p>Usage of Web Application Finger Printing<\/p>\n<p> Web Application finger printing is a quintessential part of Information Gathering phase [4] of (ethical) hacking. It allows narrowing \/ drilling down on specifics instead of looking for all clues. Also an Accurately identified application <em>can help us in quickly pinpointing known vulnerabilities and then moving ahead with remains aspects.<\/em> This Step is also essential to allow pen tester to customize its payload or exploitation techniques based on the identification and <em>to increase the chances of successful intrusion.<\/em> <\/p><\/blockquote>\n<p>Remember: <i>I<\/I> didn&#8217;t order this. So, it&#8217;s up to you to try to decide how one would &#8220;move ahead&#8221; after discovering known vulnerabilities. <\/p>\n<p>It&#8217;s also your guess whether a person running using available software to scan my site for vulnerabilities is &#8220;sophisticated&#8221; or whether this type of thing could be done by almost any motivated computer literate high school student. I suspect that the Norfolk Police would categorize it as the former.  I suspect it&#8217;s the latter. Both are just my guesses.   <\/p>\n","protected":false},"excerpt":{"rendered":"<p>So the Climategate investigation is closed. We are told it was a &#8220;sophisticated and carefully orchestrated attack on the CRU\u00e2\u20ac\u2122s data files, carried out remotely via the internet&#8221; So, today, I saw something that made me wonder if The Blackboard is currently the focus of a &#8220;sophisticated and carefully orchestrated attack on [its] data files, &hellip; <a href=\"https:\/\/rankexploits.com\/musings\/2012\/sophisticated-and-carefully-orchestrated-attack-or\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Sophisticated and carefully orchestrated attack? Or?<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[134],"tags":[],"class_list":["post-20275","post","type-post","status-publish","format-standard","hentry","category-politics"],"_links":{"self":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/20275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/comments?post=20275"}],"version-history":[{"count":0,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/posts\/20275\/revisions"}],"wp:attachment":[{"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/media?parent=20275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/categories?post=20275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rankexploits.com\/musings\/wp-json\/wp\/v2\/tags?post=20275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}