jueves, 4 de octubre de 2012

Export Audit Policy Configuration - Windows


secedit command allows to export Security policy configurations besides other acctions.

The possible actions are:
  • configure 
  • analyze
  • import
  • export
  • validate
  • generaterollback
To use secedit you must have a Security Database.

To create a Security Database (sdb) you must:
  1. open "mmc" (from start>run just type "mmc")
  2. click on File > add/remove snap-in
  3. Select "Security configuration and analysis"
  4. Button "Add" & "OK"
  5. Right click & New database & Select a name for the database & click open
  6. Define the policies you would like to export (define any value if you only need to export the configuration. define the propper values if you like to analyze)
  7.  
psexec @filserver.txt secedit /export /db security.sdb /areas SECURITYPOLICY GROUP_MGMT  GROUP_MGMT  GROUP_MGMT GROUP_MGMT  GROUP_MGMT /cfg output.txt >> outputLog.txt

psexec is used to run this command in several computers. The @filserver.txt file contains a list computers / servers.

viernes, 31 de agosto de 2012

Windows: Local account management


To create a local user massively in a list of servers, you can use this command:

Psexec \\server1 net user user01 Pass.128 /ADD
Psexec \\server2 net user user01 Pass.128 /ADD
...

Use the excel to concatenate the fields, so you can have a full list of command, without typing each server.

Then, add the propper permission:

Psexec \\server1 net localgroup administrators /add user01
Psexec \\server2 net localgroup administrators /add user01 
...

If  you just want to allow access to a domain user, is pretty similar:

Psexec \\server1 net localgroup administrators /add contoso\user02
Psexec \\server2 net localgroup administrators /add contoso\user02
...

Then if you need to remove permissions, issue this command

Psexec \\server1 net localgroup administrators contoso\user02  /delete



jueves, 9 de agosto de 2012

Web VRA: Google skipfish

Skipfish is an active web application security reconnaissance tool from Google. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.
Key features:
  • High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.
  • Ease of use: heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form autocompletion.
  • Cutting-edge security logic: high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors.
The tool is believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments.

Home Page:
http://code.google.com/p/skipfish/

Wiki Doc:
http://code.google.com/p/skipfish/wiki/SkipfishDoc

jueves, 19 de julio de 2012

Delegar permisos sobre Security logs

En los entornos corporativos y sobre todo para los ambientes Windows es muy comun encontrar que las áreas de Auditoría cuyos usuarios no son privilegiados deseen visualizar logs de Seguridad. En Windows Server 2003 esto es una tarea algo compleja y riesgosa para lo que nos tiene acostumbrados Microsoft y deberemos utilizar el lenguaje SDDL:

CUIDADO: Este procedimiento mal implementado puede impedir el acceso y requiere de reinicio del equipo.

Delegating access to the event logs

In Windows Server® 2003, Windows Vista, and Windows Server® 2008, it is possible to customize the permissions on each event log on a computer. This capability was not available in previous versions of Windows. Some organizations may want to grant read-only access to one or more of the System event logs to some members of the IT team, such as auditors. The access control list (ACL) is stored as a Security Descriptor Definition Language (SDDL) string, in a REG_SZ value called "CustomSD" for each event log in the registry. The following procedure shows how to delegate read-only access for an event log. You will need to repeat this procedure for each event log that you wish to delegate read-only access to by changing the registry key as needed.
CautionCaution
Incorrectly editing the registry may severely damage your system. Before making changes to the registry, you should back up any valued data on the computer.
To delegate access to an event log using the registry
  1. Open Registry Editor.
  2. Navigate to the following registry path:
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EventLog
    You will see that there are keys available for each event log. Select the event log for which you want to delegate read-only access.
  3. Add a new key with the name CustomSD to the event log you selected.
  4. Add a new String value to the CustomSD key. The name of this string is not required, but it represents the access control list for the event log in the Security Descriptor Definition Language (SDDL) syntax. In this procedure this value will be referred to as SDDLACL.
  5. Set the value of the SDDLACL to the following:
    O:BAG:SYD:(D;;0xf0007;;;AN)(D;;0xf0007;;;BG) (A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x5;;;SO)(A;;0x1;;;IU)(A;;0x1;;;SU) (A;;0x1;;;S-1-5-3)(A;;0x2;;;LS)(A;;0x2;;;NS)
Once you edit this value and restart the computer, the new setting will take effect. Be certain that you fully understand SDDL and the default permissions that are placed on each event log before you use this procedure. Also, be certain to test any changes thoroughly before you implement them in a production environment, because you could accidentally configure the ACLs on an event log in such a way that no one could access it.

Additional references

The following links provide additional information about event logging in Windows Server 2003 and Windows Vista:



Extraido de: http://technet.microsoft.com/en-us/library/cc722385(WS.10).aspx

Mas info: http://support.microsoft.com/default.aspx?scid=kb;en-us;323076

jueves, 21 de junio de 2012

Obtener datos de Active Directory desde Excel

En el día de hoy tuve la necesidad de buscar información en Active Directory a partir de un listado de usuarios que tenia en excel con  información faltante.


En vez de hacer un script WMI o una consulta utilizando dsget / dsquery, decidí investigar que herramientas existen para hacer busquedas en AD desde excel. Para una grata sorpresa mia encontré la siguiente herramienta gratuita:


http://excelldapsearch.sourceforge.net/


Hasta ahora rara vez me he encontrado decepcionado con los proyectos hosteados en sourceforge, por lo que me embarque en la prueba.


El producto se instaló muy bien en mi Windows 7 x64 (english). Luego realicé la customización del archivo ini que se abre al finalizar la instalación.


Los parametros a modificar son:


En la sección [Connection]
;#colocar el servidor que corresponda, perferentemente el mas cercano

server=server.dominio.empresa.ccf
;#dejar el default
port=389
;#colocar el usuario que corresponda utilizar para conectarse
binddn=CN=myUser,OU=AR,OU=Users,OU=Accounts,DC=americas,DC=empresa,DC=ccf 
bindpw=<password>


No es necesario utilizar un usuario que sea Domain Admin, solo con un usuario miembro de Users bastará (si es que la configuración de AD es la default)


En la sección [Search]
;#colocar el que corresponda, esto restringe la búsqueda de objetos para que sea mas performante
basedn=OU=AR,OU=Users,OU=Accounts,DC=americas,DC=dominio,DC=ccf



En la sección [LDAP Attribute Descriptions] agregúe esta propiedad que me resulta util
manager=Manager


En caso de que necesites algún otro atributo que no esté por default en el ini, puede usar la tool AD Explorer de sysinternals (www.sysinternals.com) para browsear el Active Directory y obtener el nombre de todos los atributos de los objetos deseados.


Luego de realizadas estas parametrizaciones, procedemos a abrir el excel y en la opcion Add-ins del ribon aparece Run LDAP Search. (si teniamos el excel abierto es cuestion de cerrarlo y abrirlo para que aparezca la opción)


Con el excel con la información que queremos buscar, abrimos el LDAP Search y le definimos:

  1. Que filas buscar
  2. En que campo buscarlas
  3. Cuantas columnas mas hacia la derecha devolver los resultados
  4. que atributo/s devolver