Re: sethhall/credit-card-exposure

Nick Turley <[email protected]> Thu, 12 Dec 2019 14:47:51 +0000
Newsgroups gmane.comp.security.detection.bro
Message-ID <BYAPR08MB4613D39CA9BD12BBB4E8C3C59D550@BYAPR08MB4613.namprd08.prod.outlook.com>
--===============0742468411==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_BYAPR08MB4613D39CA9BD12BBB4E8C3C59D550BYAPR08MB4613namp_"

--_000_BYAPR08MB4613D39CA9BD12BBB4E8C3C59D550BYAPR08MB4613namp_
Content-Type: text/plain; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

We=92ve been meaning to share some of our work with the community so this h=
as prompted a call to action :)

Nick Turley
Security Architect
CES Security Operations Center
Office: (801) 422-4994 | Cell: (801) 310-3816 | [email protected]
________________________________
From: Michael Shirk <[email protected]>
Sent: Thursday, December 12, 2019 7:19:53 AM
To: Nick Turley <[email protected]>
Cc: Scot Harris <[email protected]>; [email protected] <[email protected]>
Subject: Re: [Zeek] sethhall/credit-card-exposure

You can submit a pull request to Seth's GitHub repo if you can share the mo=
difications with the community.

--
Michael Shirk
Daemon Security, Inc.
https://www.daemon-security.com

On Thu, Dec 12, 2019, 09:18 Nick Turley <[email protected]<mailto:nick_tu=
[email protected]>> wrote:
We=92ve had pretty good luck with the package but we had to make modificati=
ons to get it working the way we wanted. We also modified it so it would wo=
rk on Corelight. We=92ve been running it on our Bro 2.6 cluster for some ti=
me. SSN detection is a high false positive game in a large environment like=
 ours, so our analysts are still required to review the extracted payload a=
nd make a determination.

Some of the modifications include extracting a chunk of the payload where t=
he SSN was detected and including that in the notice log. We also added the=
 protocol that was detected and associated info. For example, if SMB, we in=
clude the file name and location identified. As I recall, there was also a =
bug we fixed that wasn=92t masking the SSNs correctly.

We also feed in all 50 state historical SSN prefixes and include the state =
data in the notice log. However, SSNs after 2011 I believe are now randomiz=
ed so this will be less effective over time.

While we get a number of false positives, the module has also helped us dis=
cover some fairly serious security issues.

When I get to the office, I would be happy to share our code.

Nick Turley
Security Architect
CES Security Operations Center
Office: (801) 422-4994 | Cell: (801) 310-3816 | [email protected]<mailto:=
[email protected]>
________________________________
From: [email protected]<mailto:[email protected]> <zeek-bounces@zee=
k.org<mailto:[email protected]>> on behalf of Scot Harris <SHARRIS@holl=
ywoodfl.org<mailto:[email protected]>>
Sent: Thursday, December 12, 2019 6:26:27 AM
To: [email protected]<mailto:[email protected]> <[email protected]<mailto:[email protected]=
>>
Subject: [Zeek] sethhall/credit-card-exposure


Does anyone have experience with the sethhall/credit-card-exposure package?



I installed it and it is generating some results that does not seem valid.



Running zeek 3.0 with this package installed using zkg.



The odd data includes packets that go from my workstation to the zeek main =
server on port 80 that is flagged as having credit card numbers in it.



I don=92t think that actually occurred.



So was wondering if someone else had that package and what kind of results =
they are getting.



Thank you.







__________________________________________
Scot Harris
Network Engineer
City of Hollywood
Information Technology

P.O. Box 229045
Hollywood, FL 33022-9045
Office: 954-921-3304
E-mail: [email protected]<mailto:[email protected]>
[www.hollywoodfl.org]
Notice: Florida has a broad public records law. All correspondence sent to =
the City of Hollywood via e-mail may be subject to disclosure as a matter o=
f public record.
__________________________________________
_______________________________________________
Zeek mailing list
[email protected]<mailto:[email protected]>
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek

--_000_BYAPR08MB4613D39CA9BD12BBB4E8C3C59D550BYAPR08MB4613namp_
Content-Type: text/html; charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3DWindows-1=
252">
</head>
<body>
<div dir=3D"ltr">
<div style=3D"color: rgb(0, 0, 0); background-color: rgb(255, 255, 255); te=
xt-align: left;" dir=3D"ltr">
We=92ve been meaning to share some of our work with the community so this h=
as prompted a call to action :)</div>
<div data-ogsc=3D"" style=3D"text-align: left;" dir=3D"ltr"><br>
</div>
<div id=3D"ms-outlook-mobile-signature">
<div style=3D"direction: ltr;">Nick Turley</div>
<div style=3D"direction: ltr;">Security Architect</div>
<div style=3D"direction: ltr;">CES Security Operations Center</div>
<div style=3D"direction: ltr;">Office: (801) 422-4994 | Cell: (801) 310-381=
6 | [email protected]</div>
</div>
</div>
<hr style=3D"display:inline-block;width:98%" tabindex=3D"-1">
<div id=3D"divRplyFwdMsg" dir=3D"ltr"><font face=3D"Calibri, sans-serif" st=
yle=3D"font-size:11pt" color=3D"#000000"><b>From:</b> Michael Shirk &lt;shi=
[email protected]&gt;<br>
<b>Sent:</b> Thursday, December 12, 2019 7:19:53 AM<br>
<b>To:</b> Nick Turley &lt;[email protected]&gt;<br>
<b>Cc:</b> Scot Harris &lt;[email protected]&gt;; [email protected] &lt;z=
[email protected]&gt;<br>
<b>Subject:</b> Re: [Zeek] sethhall/credit-card-exposure</font>
<div>&nbsp;</div>
</div>
<div>
<div dir=3D"auto">You can submit a pull request to Seth's GitHub repo if yo=
u can share the modifications with the community.&nbsp;<br>
<br>
<div>--<br>
Michael Shirk<br>
Daemon Security, Inc.<br>
<a href=3D"https://www.daemon-security.com">https://www.daemon-security.com=
</a></div>
</div>
<br>
<div class=3D"x_gmail_quote">
<div dir=3D"ltr" class=3D"x_gmail_attr">On Thu, Dec 12, 2019, 09:18 Nick Tu=
rley &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt;=
 wrote:<br>
</div>
<blockquote class=3D"x_gmail_quote" style=3D"margin:0 0 0 .8ex; border-left=
:1px #ccc solid; padding-left:1ex">
<div>
<div dir=3D"ltr">
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
We=92ve had pretty good luck with the package but we had to make modificati=
ons to get it working the way we wanted. We also modified it so it would wo=
rk on Corelight. We=92ve been running it on our Bro 2.6 cluster for some ti=
me. SSN detection is a high false positive
 game in a large environment like ours, so our analysts are still required =
to review the extracted payload and make a determination.&nbsp;</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
<br>
</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
Some of the modifications include extracting a chunk of the payload where t=
he SSN was detected and including that in the notice log. We also added the=
 protocol that was detected and associated info. For example, if SMB, we in=
clude the file name and location
 identified. As I recall, there was also a bug we fixed that wasn=92t maski=
ng the SSNs correctly.&nbsp;</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
<br>
</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
We also feed in all 50 state historical SSN prefixes and include the state =
data in the notice log. However, SSNs after 2011 I believe are now randomiz=
ed so this will be less effective over time.&nbsp;</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
<br>
</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
While we get a number of false positives, the module has also helped us dis=
cover some fairly serious security issues.&nbsp;</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
<br>
</div>
<div dir=3D"ltr" style=3D"color:rgb(0,0,0); background-color:rgb(255,255,25=
5); text-align:left">
When I get to the office, I would be happy to share our code.&nbsp;</div>
<div dir=3D"ltr" style=3D"text-align:left"><br>
</div>
<div id=3D"x_m_-979988286312995127ms-outlook-mobile-signature">
<div style=3D"direction:ltr">Nick Turley</div>
<div style=3D"direction:ltr">Security Architect</div>
<div style=3D"direction:ltr">CES Security Operations Center</div>
<div style=3D"direction:ltr">Office: (801) 422-4994 | Cell: (801) 310-3816 =
| <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre=
r">
[email protected]</a></div>
</div>
</div>
<hr style=3D"display:inline-block; width:98%">
<div id=3D"x_m_-979988286312995127divRplyFwdMsg" dir=3D"ltr"><font face=3D"=
Calibri, sans-serif" color=3D"#000000" style=3D"font-size:11pt"><b>From:</b=
>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferre=
r">[email protected]</a> &lt;<a href=3D"mailto:[email protected]" t=
arget=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; on behalf=
 of Scot Harris &lt;<a href=3D"mailto:[email protected]" target=3D"_b=
lank" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Sent:</b> Thursday, December 12, 2019 6:26:27 AM<br>
<b>To:</b> <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"norefe=
rrer">[email protected]</a> &lt;<a href=3D"mailto:[email protected]" target=3D"_bla=
nk" rel=3D"noreferrer">[email protected]</a>&gt;<br>
<b>Subject:</b> [Zeek] sethhall/credit-card-exposure</font>
<div>&nbsp;</div>
</div>
<div lang=3D"EN-US">
<div>
<p>Does anyone have experience with the sethhall/credit-card-exposure packa=
ge?</p>
<p>&nbsp;</p>
<p>I installed it and it is generating some results that does not seem vali=
d.</p>
<p>&nbsp;</p>
<p>Running zeek 3.0 with this package installed using zkg.</p>
<p>&nbsp;</p>
<p>The odd data includes packets that go from my workstation to the zeek ma=
in server on port 80 that is flagged as having credit card numbers in it.</=
p>
<p>&nbsp;</p>
<p>I don=92t think that actually occurred.</p>
<p>&nbsp;</p>
<p>So was wondering if someone else had that package and what kind of resul=
ts they are getting.</p>
<p>&nbsp;</p>
<p>Thank you.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
</div>
<div>__________________________________________<br>
<i><b>Scot Harris</b></i><br>
Network Engineer<br>
City of Hollywood<br>
Information Technology<br>
<br>
P.O. Box 229045<br>
Hollywood, FL 33022-9045<br>
Office: 954-921-3304<br>
E-mail: <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D=
"noreferrer">
[email protected]</a><br>
<div><img alt=3D"www.hollywoodfl.org" src=3D"http://apps.hollywoodfl.org/im=
ages/coh_logo_color.png"></div>
Notice: Florida has a broad public records law. All correspondence sent to =
the City of Hollywood via e-mail may be subject to disclosure as a matter o=
f public record.<br>
__________________________________________</div>
</div>
</div>
_______________________________________________<br>
Zeek mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"noreferrer">zeek@=
zeek.org</a><br>
<a href=3D"http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek" rel=3D"n=
oreferrer noreferrer" target=3D"_blank">http://mailman.ICSI.Berkeley.EDU/ma=
ilman/listinfo/zeek</a></blockquote>
</div>
</div>
</body>
</html>

--_000_BYAPR08MB4613D39CA9BD12BBB4E8C3C59D550BYAPR08MB4613namp_--

--===============0742468411==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Zeek mailing list
[email protected]
http://mailman.ICSI.Berkeley.EDU/mailman/listinfo/zeek
--===============0742468411==--