Re: sethhall/credit-card-exposure
Michael Shirk <[email protected]> Thu, 12 Dec 2019 09:19:53 -0500
| Newsgroups | gmane.comp.security.detection.bro |
|---|---|
| Message-ID | <CAL8PkUVvX820dikR+ZcYUxSmJgY08oJ6HGMzQnNuGQg9qb9JVQ@mail.gmail.com> |
--===============0183240268== Content-Type: multipart/alternative; boundary="0000000000000c618a05998271c2" --0000000000000c618a05998271c2 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable You can submit a pull request to Seth's GitHub repo if you can share the modifications with the community. -- Michael Shirk Daemon Security, Inc. https://www.daemon-security.com On Thu, Dec 12, 2019, 09:18 Nick Turley <[email protected]> wrote: > We=E2=80=99ve had pretty good luck with the package but we had to make > modifications to get it working the way we wanted. We also modified it so > it would work on Corelight. We=E2=80=99ve been running it on our Bro 2.6 = cluster > for some time. SSN detection is a high false positive game in a large > environment like ours, so our analysts are still required to review the > extracted payload and make a determination. > > Some of the modifications include extracting a chunk of the payload where > the SSN was detected and including that in the notice log. We also added > the protocol that was detected and associated info. For example, if SMB, = we > include the file name and location identified. As I recall, there was als= o > a bug we fixed that wasn=E2=80=99t masking the SSNs correctly. > > We also feed in all 50 state historical SSN prefixes and include the stat= e > data in the notice log. However, SSNs after 2011 I believe are now > randomized so this will be less effective over time. > > While we get a number of false positives, the module has also helped us > discover some fairly serious security issues. > > When I get to the office, I would be happy to share our code. > > Nick Turley > Security Architect > CES Security Operations Center > Office: (801) 422-4994 | Cell: (801) 310-3816 | [email protected] > ------------------------------ > *From:* [email protected] <[email protected]> on behalf of Scot > Harris <[email protected]> > *Sent:* Thursday, December 12, 2019 6:26:27 AM > *To:* [email protected] <[email protected]> > *Subject:* [Zeek] sethhall/credit-card-exposure > > > Does anyone have experience with the sethhall/credit-card-exposure packag= e? > > > > I installed it and it is generating some results that does not seem valid= . > > > > Running zeek 3.0 with this package installed using zkg. > > > > The odd data includes packets that go from my workstation to the zeek mai= n > server on port 80 that is flagged as having credit card numbers in it. > > > > I don=E2=80=99t think that actually occurred. > > > > So was wondering if someone else had that package and what kind of result= s > they are getting. > > > > Thank you. > > > > > > > __________________________________________ > *Scot Harris* > Network Engineer > City of Hollywood > Information Technology > > P.O. Box 229045 > Hollywood, FL 33022-9045 > Office: 954-921-3304 > E-mail: [email protected] > [image: www.hollywoodfl.org] > Notice: Florida has a broad public records law. All correspondence sent t= o > the City of Hollywood via e-mail may be subject to disclosure as a matter > of public record. > __________________________________________ > _______________________________________________ > Zeek mailing list > [email protected] > http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek --0000000000000c618a05998271c2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">You can submit a pull request to Seth's GitHub repo i= f you can share the modifications with the community.=C2=A0<br><br><div dat= a-smartmail=3D"gmail_signature">--<br>Michael Shirk<br>Daemon Security, Inc= .<br><a href=3D"https://www.daemon-security.com">https://www.daemon-securit= y.com</a></div></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class= =3D"gmail_attr">On Thu, Dec 12, 2019, 09:18 Nick Turley <<a href=3D"mail= to:[email protected]">[email protected]</a>> wrote:<br></div><blockq= uote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc = solid;padding-left:1ex"> <div> <div dir=3D"ltr"> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> We=E2=80=99ve had pretty good luck with the package but we had to make modi= fications to get it working the way we wanted. We also modified it so it wo= uld work on Corelight. We=E2=80=99ve been running it on our Bro 2.6 cluster= for some time. SSN detection is a high false positive game in a large environment like ours, so our analysts are still required = to review the extracted payload and make a determination.=C2=A0</div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> <br> </div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> Some of the modifications include extracting a chunk of the payload where t= he SSN was detected and including that in the notice log. We also added the= protocol that was detected and associated info. For example, if SMB, we in= clude the file name and location identified. As I recall, there was also a bug we fixed that wasn=E2=80=99t= masking the SSNs correctly.=C2=A0</div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> <br> </div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> We also feed in all 50 state historical SSN prefixes and include the state = data in the notice log. However, SSNs after 2011 I believe are now randomiz= ed so this will be less effective over time.=C2=A0</div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> <br> </div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> While we get a number of false positives, the module has also helped us dis= cover some fairly serious security issues.=C2=A0</div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> <br> </div> <div style=3D"color:rgb(0,0,0);background-color:rgb(255,255,255);text-align= :left" dir=3D"ltr"> When I get to the office, I would be happy to share our code.=C2=A0</div> <div style=3D"text-align:left" dir=3D"ltr"><br> </div> <div id=3D"m_-979988286312995127ms-outlook-mobile-signature"> <div style=3D"direction:ltr">Nick Turley</div> <div style=3D"direction:ltr">Security Architect</div> <div style=3D"direction:ltr">CES Security Operations Center</div> <div style=3D"direction:ltr">Office: (801) 422-4994 | Cell: (801) 310-3816 = | <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre= r">[email protected]</a></div> </div> </div> <hr style=3D"display:inline-block;width:98%"> <div id=3D"m_-979988286312995127divRplyFwdMsg" dir=3D"ltr"><font face=3D"Ca= libri, sans-serif" style=3D"font-size:11pt" color=3D"#000000"><b>From:</b> = <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre= r">[email protected]</a> <<a href=3D"mailto:[email protected]" t= arget=3D"_blank" rel=3D"noreferrer">[email protected]</a>> on behalf= of Scot Harris <<a href=3D"mailto:[email protected]" target=3D"_b= lank" rel=3D"noreferrer">[email protected]</a>><br> <b>Sent:</b> Thursday, December 12, 2019 6:26:27 AM<br> <b>To:</b> <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefe= rrer">[email protected]</a> <<a href=3D"mailto:[email protected]" target=3D"_bla= nk" rel=3D"noreferrer">[email protected]</a>><br> <b>Subject:</b> [Zeek] sethhall/credit-card-exposure</font> <div>=C2=A0</div> </div> <div lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72"> <div> <p>Does anyone have experience with the sethhall/credit-card-exposure packa= ge?</p> <p>=C2=A0</p> <p>I installed it and it is generating some results that does not seem vali= d.</p> <p>=C2=A0</p> <p>Running zeek 3.0 with this package installed using zkg.</p> <p>=C2=A0</p> <p>The odd data includes packets that go from my workstation to the zeek ma= in server on port 80 that is flagged as having credit card numbers in it.</= p> <p>=C2=A0</p> <p>I don=E2=80=99t think that actually occurred.</p> <p>=C2=A0</p> <p>So was wondering if someone else had that package and what kind of resul= ts they are getting.</p> <p>=C2=A0</p> <p>Thank you.</p> <p>=C2=A0</p> <p>=C2=A0</p> <p>=C2=A0</p> </div> <div>__________________________________________<br> <i><b>Scot Harris</b></i><br> Network Engineer<br> City of Hollywood<br> Information Technology<br> <br> P.O. Box 229045<br> Hollywood, FL 33022-9045<br> Office: 954-921-3304<br> E-mail: <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D= "noreferrer">[email protected]</a><br> <div><img alt=3D"www.hollywoodfl.org" src=3D"http://apps.hollywoodfl.org/im= ages/coh_logo_color.png"></div> Notice: Florida has a broad public records law. All correspondence sent to = the City of Hollywood via e-mail may be subject to disclosure as a matter o= f public record.<br> __________________________________________</div> </div> </div> _______________________________________________<br> Zeek mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">zeek@= zeek.org</a><br> <a href=3D"http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek" rel=3D"n= oreferrer noreferrer" target=3D"_blank">http://mailman.ICSI.Berkeley.EDU/ma= ilman/listinfo/zeek</a></blockquote></div> --0000000000000c618a05998271c2-- --===============0183240268== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Zeek mailing list [email protected] http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek --===============0183240268==--