Re: sethhall/credit-card-exposure

Michael Shirk <[email protected]> Thu, 12 Dec 2019 09:19:53 -0500
Newsgroups gmane.comp.security.detection.bro
Message-ID <CAL8PkUVvX820dikR+ZcYUxSmJgY08oJ6HGMzQnNuGQg9qb9JVQ@mail.gmail.com>
--===============0183240268==
Content-Type: multipart/alternative; boundary="0000000000000c618a05998271c2"

--0000000000000c618a05998271c2
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

You can submit a pull request to Seth's GitHub repo if you can share the
modifications with the community.

--
Michael Shirk
Daemon Security, Inc.
https://www.daemon-security.com

On Thu, Dec 12, 2019, 09:18 Nick Turley <[email protected]> wrote:

> We=E2=80=99ve had pretty good luck with the package but we had to make
> modifications to get it working the way we wanted. We also modified it so
> it would work on Corelight. We=E2=80=99ve been running it on our Bro 2.6 =
cluster
> for some time. SSN detection is a high false positive game in a large
> environment like ours, so our analysts are still required to review the
> extracted payload and make a determination.
>
> Some of the modifications include extracting a chunk of the payload where
> the SSN was detected and including that in the notice log. We also added
> the protocol that was detected and associated info. For example, if SMB, =
we
> include the file name and location identified. As I recall, there was als=
o
> a bug we fixed that wasn=E2=80=99t masking the SSNs correctly.
>
> We also feed in all 50 state historical SSN prefixes and include the stat=
e
> data in the notice log. However, SSNs after 2011 I believe are now
> randomized so this will be less effective over time.
>
> While we get a number of false positives, the module has also helped us
> discover some fairly serious security issues.
>
> When I get to the office, I would be happy to share our code.
>
> Nick Turley
> Security Architect
> CES Security Operations Center
> Office: (801) 422-4994 | Cell: (801) 310-3816 | [email protected]
> ------------------------------
> *From:* [email protected] <[email protected]> on behalf of Scot
> Harris <[email protected]>
> *Sent:* Thursday, December 12, 2019 6:26:27 AM
> *To:* [email protected] <[email protected]>
> *Subject:* [Zeek] sethhall/credit-card-exposure
>
>
> Does anyone have experience with the sethhall/credit-card-exposure packag=
e?
>
>
>
> I installed it and it is generating some results that does not seem valid=
.
>
>
>
> Running zeek 3.0 with this package installed using zkg.
>
>
>
> The odd data includes packets that go from my workstation to the zeek mai=
n
> server on port 80 that is flagged as having credit card numbers in it.
>
>
>
> I don=E2=80=99t think that actually occurred.
>
>
>
> So was wondering if someone else had that package and what kind of result=
s
> they are getting.
>
>
>
> Thank you.
>
>
>
>
>
>
> __________________________________________
> *Scot Harris*
> Network Engineer
> City of Hollywood
> Information Technology
>
> P.O. Box 229045
> Hollywood, FL 33022-9045
> Office: 954-921-3304
> E-mail: [email protected]
> [image: www.hollywoodfl.org]
> Notice: Florida has a broad public records law. All correspondence sent t=
o
> the City of Hollywood via e-mail may be subject to disclosure as a matter
> of public record.
> __________________________________________
> _______________________________________________
> Zeek mailing list
> [email protected]
> http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek

--0000000000000c618a05998271c2
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">You can submit a pull request to Seth&#39;s GitHub repo i=
f you can share the modifications with the community.=C2=A0<br><br><div dat=
a-smartmail=3D"gmail_signature">--<br>Michael Shirk<br>Daemon Security, Inc=
.<br><a href=3D"https://www.daemon-security.com">https://www.daemon-securit=
y.com</a></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=
=3D"gmail_attr">On Thu, Dec 12, 2019, 09:18 Nick Turley &lt;<a href=3D"mail=
to:[email protected]">[email protected]</a>&gt; wrote:<br></div><blockq=
uote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc =
solid;padding-left:1ex">



<div>
<div dir=3D"ltr">
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
We=E2=80=99ve had pretty good luck with the package but we had to make modi=
fications to get it working the way we wanted. We also modified it so it wo=
uld work on Corelight. We=E2=80=99ve been running it on our Bro 2.6 cluster=
 for some time. SSN detection is a high false positive
 game in a large environment like ours, so our analysts are still required =
to review the extracted payload and make a determination.=C2=A0</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
<br>
</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
Some of the modifications include extracting a chunk of the payload where t=
he SSN was detected and including that in the notice log. We also added the=
 protocol that was detected and associated info. For example, if SMB, we in=
clude the file name and location
 identified. As I recall, there was also a bug we fixed that wasn=E2=80=99t=
 masking the SSNs correctly.=C2=A0</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
<br>
</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
We also feed in all 50 state historical SSN prefixes and include the state =
data in the notice log. However, SSNs after 2011 I believe are now randomiz=
ed so this will be less effective over time.=C2=A0</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
<br>
</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
While we get a number of false positives, the module has also helped us dis=
cover some fairly serious security issues.=C2=A0</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
<br>
</div>
<div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align=
:left" dir=3D"ltr">
When I get to the office, I would be happy to share our code.=C2=A0</div>
<div style=3D"text-align:left" dir=3D"ltr"><br>
</div>
<div id=3D"m_-979988286312995127ms-outlook-mobile-signature">
<div style=3D"direction:ltr">Nick Turley</div>
<div style=3D"direction:ltr">Security Architect</div>
<div style=3D"direction:ltr">CES Security Operations Center</div>
<div style=3D"direction:ltr">Office: (801) 422-4994 | Cell: (801) 310-3816 =
| <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre=
r">[email protected]</a></div>
</div>
</div>
<hr style=3D"display:inline-block;width:98%">
<div id=3D"m_-979988286312995127divRplyFwdMsg" dir=3D"ltr"><font face=3D"Ca=
libri, sans-serif" style=3D"font-size:11pt" color=3D"#000000"><b>From:</b> =
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre=
r">[email protected]</a> &lt;<a href=3D"mailto:[email protected]" t=
arget=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; on behalf=
 of Scot Harris &lt;<a href=3D"mailto:[email protected]" target=3D"_b=
lank" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Sent:</b> Thursday, December 12, 2019 6:26:27 AM<br>
<b>To:</b> <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefe=
rrer">[email protected]</a> &lt;<a href=3D"mailto:[email protected]" target=3D"_bla=
nk" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Subject:</b> [Zeek] sethhall/credit-card-exposure</font>
<div>=C2=A0</div>
</div>

<div lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div>
<p>Does anyone have experience with the sethhall/credit-card-exposure packa=
ge?</p>
<p>=C2=A0</p>
<p>I installed it and it is generating some results that does not seem vali=
d.</p>
<p>=C2=A0</p>
<p>Running zeek 3.0 with this package installed using zkg.</p>
<p>=C2=A0</p>
<p>The odd data includes packets that go from my workstation to the zeek ma=
in server on port 80 that is flagged as having credit card numbers in it.</=
p>
<p>=C2=A0</p>
<p>I don=E2=80=99t think that actually occurred.</p>
<p>=C2=A0</p>
<p>So was wondering if someone else had that package and what kind of resul=
ts they are getting.</p>
<p>=C2=A0</p>
<p>Thank you.</p>
<p>=C2=A0</p>
<p>=C2=A0</p>
<p>=C2=A0</p>
</div>
<div>__________________________________________<br>
<i><b>Scot Harris</b></i><br>
Network Engineer<br>
City of Hollywood<br>
Information Technology<br>
<br>
P.O. Box 229045<br>
Hollywood, FL 33022-9045<br>
Office: 954-921-3304<br>
E-mail: <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D=
"noreferrer">[email protected]</a><br>
<div><img alt=3D"www.hollywoodfl.org" src=3D"http://apps.hollywoodfl.org/im=
ages/coh_logo_color.png"></div>
Notice: Florida has a broad public records law. All correspondence sent to =
the City of Hollywood via e-mail may be subject to disclosure as a matter o=
f public record.<br>
__________________________________________</div>
</div>
</div>

_______________________________________________<br>
Zeek mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">zeek@=
zeek.org</a><br>
<a href=3D"http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek" rel=3D"n=
oreferrer noreferrer" target=3D"_blank">http://mailman.ICSI.Berkeley.EDU/ma=
ilman/listinfo/zeek</a></blockquote></div>

--0000000000000c618a05998271c2--

--===============0183240268==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
--===============0183240268==--