Skip to content
AppSec PodcastThe Application Security Podcast — home
47 min

Sam Stepanyan -- OWASP Nettacker Project

With Sam Stepanyan

Security TestingVulnerabilities and ExploitsConferences and Community

Sam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in software engineering and web application development. Sam has worked for various financial services institutions in the City of London, specializing in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 8 chapters
  1. 00:00Meet Sam Stepanyan: OWASP Nettacker ProjectAudioVideo ↗
  2. 01:48Like we typically do, we'd like to start off with yourAudioVideo ↗
  3. 05:34Yeah, that was a great event to be a part ofAudioVideo ↗
  4. 13:36The security team, that is one of the foundational tools thatAudioVideo ↗
  5. 16:44About performance. So when I hear you describe it's written inAudioVideo ↗

About this episode

Sam Stepanyan is an OWASP London Chapter Leader and an Independent Application Security Consultant with over 20 years of IT experience and a background in software engineering and web application development. Sam has worked for various financial services institutions in the City of London, specializing in Application Security consulting, Secure Software Development Lifecycle (SDLC), developer training, source code reviews and vulnerability management. He is also a Subject Matter Expert in Web Application Firewalls (WAF) and SIEM systems. Sam holds a Master’s degree in Software Engineering and a CISSP certification. Sam Stepanyan is an OWASP chapter leader and an independent application security consultant with over 20 years of experience in the IT industry with a background in software and web app development.

You are now listening to the Application Security Podcast brought to you by Security Journey.

About Security Journey
Hey folks, welcome to another episode of the Application Security Podcast, and this is Robert Hurlbut.
Learn more about Security Journey

Connect with Sam Stepanyan:
OWASP Nettacker
OWASP ZAP

Resources
OWASP Nettacker
OWASP ZAP
Metasploit
Kali Linux
Jeremiah Grossman
OWASP Top Ten
Black Hat

Actionable

From this conversation

  1. Control scan speed

    Of course, another thing about NetTacker is you can control the speed, because the way how the scans work, it's all multi-threaded, and the user is in control of how many threads per scan you wish to use.

    17:21
  2. Scan your network for new vulnerabilities

    Instead of saying scan one website for any vulnerabilities you can find, you say, nope, scan my entire network for one vulnerability.

    32:49
  3. Use NetTacker for asset inventory

    If you do have the problem in your organization that you don't know your assets, you have an asset inventory issue, all right, I would invite everyone to use NetHacker to find out the assets.

    40:21
Transcript · 47 min conversation

0:00Chris RomeoSam Stepanyan is an OWASP chapter leader and an independent application security consultant with over 20 years of experience in the IT industry with a background in software and web app development. Sam has worked for various financial services institutions in the City of London, specializing in AppSec consulting, SDLC, developer training, source code reviews, and vulnerability management. He's also a subject matter expert in web app firewalls and SIEM systems. Sam holds a master's degree in software engineering and a CISSP certification. Sam joins us to introduce us to OWASP NetHacker. He describes the tool's capabilities, how you can put it into use in various scenarios for asset generation and vuln scanning, and how you can contribute to the project going forward. We hope you enjoy this conversation with Sam Stepanyan.

0:52You are now listening to the Application Security Podcast brought to you by Security Journey. When you finish this episode, check out our other shows Hi5 to stay up to date with all the hot AppSec news.

1:02Chris RomeoHey folks, welcome to another episode of the Application Security Podcast, and this is Robert Hurlbut. I am the Principal Application Security Architect and Threat Modeling Lead at Acquia, and I'm joined by my co-host Chris Romeo. Hey Chris! Hey Robert, Chris Romeo, Chief Security Officer at Security Journey, and happy to be here to discuss all things application security. I don't know that we're going to cover all the things, but we'll cover some segment of it for today. Absolutely. And today we have Sam Stepanyan. Thank you for joining us, Sam.

1:40Sam StepanyanThanks so much for inviting me. Hi there. Hi, Chris. Hi, Robert.

1:45Chris RomeoAbsolutely.

1:46Sam StepanyanHello.

1:47Chris RomeoSo like we typically do, we'd like to start off with your security origin story. How did you get into this great world of application security?

1:58Sam StepanyanYeah, my story I think is quite typical for most AppSec people because I started my journey as a developer and not pretty much concerned about security 20 years ago because, well, as you know, that was the problem. And the reason why I moved into security is I got promoted to be a team lead and I had several developers reporting to me and we were looking at one of the applications that my team was developing and this was actually an e-commerce system selling tickets to British railway operators. People can just go online and say, I want to buy a train ticket. I discovered to my horror that the credit card numbers were stored in MySQL database completely unencrypted. I thought, okay, that is not right. Then that coincided with PCI DSS started coming out, actually quoting OWASP Top 10. That's how I met OWASP. Okay, let's go check out what is this OWASP Top 10 because I knew already that storing credit card numbers unencrypted was a big problem. That's how my journey started and I moved on from development into application security and absolutely loved it since then. Since then I worked for several companies. Biggest stint I had was at NTT Security, and in a consultancy, security consultancy role. And then I went independent, and at the moment I'm an independent application security consultant working primarily within the financial services sector here in the City of London. So people like banks, investment funds are my typical, typical customers, and that's where I help development teams to write more secure code and of course help the management understand the application security posture.

3:57Chris RomeoAnd you're part of the OWASP chapter there too, right, in London?

4:03Sam StepanyanThat's right, yes. So in, I think, 2007, 2008, I've discovered that there is an OWASP London chapter. I started attending their meetings as the regular attendee, and in November 2015— so now I think I will be celebrating 7 years of becoming an Alwast London chapter leader. The previous chapter leader moved to a different country because of job and family purposes, as far as I remember, and he offered to myself and to another very keen Alwast London chapter meeting at Indis, Sharif Mansour, to basically take over the chapter leadership and to continue in his absence. And that's what we've been doing for the past 7 years. I would say the chapter is quite successful. We have quite a large number of members and trying to run regular meetings. I think our next meeting is going to be in a couple of weeks' time. So yeah, love absolutely everything about OWASP, attending quite a few global AppSec conferences. And we actually hosted one back in 2018. That was the OWASP Global AppSec Europe, which got renamed to AppSec London. I think that was the first year when we started naming cities instead of regions for the global conferences. And Chris, that's where I met you, where you presented your talk back in 2018.

5:34Chris RomeoYeah, that was a great event to be a part of. And I guess just a plug for any AppSec people in the US, one of the big things that I found when I visited the EU conference, there's a whole other population of people there that don't come to like AppSec US. They're not gonna be in San Francisco this year, but there's a whole other segment of the AppSec population. So you can get to know some, a completely different set of people that are still, they love the same things we love. They love OWASP and all the different projects and stuff. So I guess that's a plug if you ever get a chance. The next Global AppSec in Europe is in Dublin in the February timeframe. And the call for papers just reopened again for a short period of time. So you might be able to sneak a paper submission in there somewhere. But The focus of this conversation, we want to learn, Sam, about this project Net Hacker. And so, I thought we would start— let's start by just defining what Net Hacker is because I can say I had heard about it, but I didn't have a whole lot of perspective when I originally kind of started talking to you about this. So, what is Net Hacker?

6:41Sam StepanyanWell, you're not alone, Chris, because when I first heard about Net Hacker, I was just like you. I saw NetHacker appearing somewhere in the list of OWASP projects, so I tried looking at it and figuring out what it does, and then I couldn't understand what it was doing, so I just closed it and forgot about it. And that kind of changed in 2018, in December time, because for the listeners here, in case if you don't know, we actually have Black Hat Europe conference, which is basically a sister event to Black Hat USA. Black Hat USA happens in Las Vegas every year around August time, and Black Hat Europe happens in London every December. Out of the blue, I had an email from a few guys from OWASP NetTacker projects, and they were saying, hello, OWASP London chapter leaders. We are the project leaders of NetTacker project. Unfortunately, for whatever reasons, we're unable to travel to London in time to demonstrate our project because it's going to be a demo of it at the Black Hat Europe Arsenal track. Would you be so kind to present our project instead of us? And myself and my chapter co-leader, Dr. Greg Frakos, we said, yes, of course, we'd like to help our fellow OWASPers. And but we had no idea what was that project. So we got on a Zoom call with the project leaders, and they walked us through the project. We absolutely loved it. The morning after, we went to Black Hat Europe, and I took my laptop, connected it to a big screen, and opened the tool. Suddenly, we had hundreds and hundreds of conference attendees wandering around the business hall of Black Hat Europe coming to our booth and looking at the demo. I figured that there's something very interesting about this project. Why is it attracting so many people? The reason is because NetTacker is quite an interesting tool because What it actually is, it is a well we can call it an automated penetration testing framework or vulnerability scanner. The whole idea of it is that it is a framework written in Python, and the idea is it's a modular framework, and you can have various modules performing different tasks. And these tasks they all provide. the outcome of the work of that module into a very nice consumable form, into a report form. And one of the other great things about NetTacker, because obviously one of the first modules that we had there was a port scanner, and people say, oh, what's the difference between something like Nmap and NetTacker? And so, well, hang on, one of the differences of course is NetTacker is, first of all, is written in Python and is written in such a way that it's a little bit kinder to your network because Nmap is known to cause all sorts of issues if you start to run port scans on your network. But another great advantage is that NetHacker has a built-in database, and that is what's great about it. So it's a small, very handy kind of Swiss Army knife tool with lots of modules, and every scan you run with it is stored in the database. And because it's a command-line tool, you can automate it, you can run it in a batch script, you can run it in, your CI/CD pipeline. You can run it as a scheduled job overnight. And that's, that's basically what NetTacker is. But the origin story, because of course we want to talk about the origin story, originally NetTacker was called IoT Scan. That used to be called OWASP IoT Scan Project. And the idea that the original project leaders had for it was to run it on the network where you have lots of IoT devices, for example, security cameras, right? And I actually did run the attacker on a network where you have security cameras, and the tool will go and discover all the open ports on all the devices attached to the network. It will go discover all the services, and it will also try to do some brute forcing. So that was unique. So it was combining things like scanning for services and open ports and also trying to brute force its way. And obviously, as we know, IoT, Internet of Things devices, they still have this problem of default credentials I think there are probably hundreds of various IoT device manufacturers which still have something like admin/admin as a default username and password. And this is a great task that the attacker can achieve. And I actually had an engagement with a financial services institution in London where I did exactly that. So I took the attacker, I ran it on my customer's local network. It scanned because they said, we have a whole bunch of security cameras. We don't know where they are. We don't know how many we have, and we don't know how many of them still have the default credentials admin/admin. So NetHacker was perfect because I just took it to the network, connected, performed a scan of the entire IP range of all the network, found the devices, the webcams, because they were responding with a specific server banner. And then I ran a brute-force scan, and I found A whole bunch of them, I think probably about 20% of the cameras still had default credentials admin/admin. For this being an OWASP tool, and this is actually quite unique because I don't think you can actually perform this task with any other tool really. Another advantage of it is, again, I keep bringing it up every time when I speak about NetTacker. I've got quite a few presentations on NetTacker. You can probably check them out on YouTube because I presented talks about NetTacker at various conferences. I'm quite proud of it because this is a very unique thing. All NetHacker results can be presented in an old-style but very useful spreadsheet format. So it's a security tool which can go scan your network, find all the open ports, find all the vulnerabilities, do some brute forcing, and give you a whole list of the default credentials and on which devices they actually— these default credentials are still enabled. give you a nice spreadsheet. So it's, I think it's quite unique. So it's not just the JSON. So other formats include, of course, JSON, which is a structured format to be consumed by other tools, XML or text or HTML report. But the fact that the also CSV output is produced, its instant value, added value, is I think absolutely fantastic.

13:25Chris RomeoYeah, and let's not forget, I mean, Microsoft Excel is a security tool. So there was a Exactly.

13:32Sam StepanyanName a company which doesn't use Excel as a security tool.

13:36Chris RomeoAnd the security team, that is one of the foundational tools that we use. And someday I'll figure out how to do a pivot table. Like, I can fake it right now, but just that's because Excel's carrying me forward. So, you were not, Sam, you were not one of the original founders then of Project Zero?

13:52Sam StepanyanI wasn't the original founder. I joined it probably a year and a half later because the leaders invited me to become a project co-leader straight away. And one of the great things that we did with Nentacker is, uh, we enlisted it into Google Summer of Code project. And for those of you who don't know, Google Summer of Code is an initiative by Google which is run every year. And that initiative allows students to spend their summer breaks to actually work and collaborate on open source code. And there are various open source organizations OWASP is one of them, where students can basically submit an application and say, well, I would like to work on project XYZ, and this is what I propose to do. And these proposals are then being reviewed, and then Google allocates slots. And these students now get a chance to work for— during their summer breaks on this open source project and actually get paid by Google. So this is a very useful, I think, initiative because because students get to work with experienced mentors. They also have an opportunity to implement their ideas. They also get an opportunity to probably enhance their knowledge of the programming language and the way how things work, probably how open source and GitHub works. And of course, it's a mutual win-win situation. So we were actually quite lucky because we had students from Google Summer of Code working on NetTucker over a number of years. And that's why the project is where it is today. And I quite frequently, when I speak about NetTucker, I actually look at GitHub stars and how popular the project has become. Because if you order all the OWASP projects by the number of GitHub stars and you look at basically top 10 projects, we were— NetTucker was like number 10 in the OWASP GitHub projects top 10, and I think it's now number 8 in the list of top 10 most starred on GitHub projects. So a lot of people love it because it's in Python. People like the fact that it's Python. A lot of people, including myself, like the fact that it doesn't use any external tools, so it doesn't actually execute Nmap or any other tool. All the scanning functionality is written in Python itself. That makes it possible to run NetTucker on anything which supports Python. For example, I managed to run it on Raspberry Pi, and that's absolutely brilliant, which means you can have a security scanning device running Raspberry Pi and Python, which will scan your network, scan your applications, and tell you about the vulnerabilities, open ports, and brute force credentials.

16:43Chris RomeoWhat about performance. So when I hear you describe it's written in Python, it doesn't call external tools— like, one of the things about Nmap, Nmap runs at the speed of light. Like, it can scan something so quickly because, you know, it's written in a lower-level language so that it can optimize and go— not written in Go, but it's written in a way that it can, it can go fast. So when I hear something's written in Python, I immediately think, oh, it's probably going to be a little bit slow if it's natively doing all these things. What's your, what's your perspective as someone who's used this on the performance side of NetTacker?

17:21Sam StepanyanYeah, so from the performance perspective, uh, we recently made some improvements because rather than using Python's requests library, we switched to the asynchronous input/output HTTP library, aiohttp, which has increased the performance significantly. And of course, another thing about NetTacker is you can actually control the speed, because the way how the scans work, it's all multi-threaded, and the user is actually in control of how many threads per scan you wish to use. So for each module, for example, if you want to do a, let's say, a port scan on a network, you can go say, this is how many threads I would like to launch. And once a scanning thread hits a host on your network, then you can define how many sub-threads per each host you want to go and look for, let's say, open ports or for vulnerabilities. So performance is actually quite good and is improved recently. And again, one of the main advantages of NetTacker is that it's not just port scanning. It's the fact that it, at the moment, it has 3 different types of scanning modules. So one is is basically your generic scanning. So again, that could be a port scanning or, say, subdomain scanning. And subdomain scan is actually very important to NetHacker because it's one of the key modules. Another type or category of modules that it has is a vulnerability scanning module. So these modules are looking for a particular vulnerability, and the idea is you send a specific payload to the target, and then you expect a specific response to be returned. And of course, if you're looking for something in response which indicates that the target is vulnerable to this vulnerability, then say, yep, there you go, this IP address or this subdomain or this server is actually vulnerable. So that's a vulnerability scanning module. And the third most important type of modules inside an attacker is brute force modules. And you can brute force using Telnet, SSH, you know, HTML forms. So, you know, if you have applications which have your traditional username passwords, or FTP, NTLM, various, various ways how an attacker can actually scan the network and perform brute forcing. And for brute forcing, again, you can use any dictionary you want because, again, you can provide a username and password dictionary and the command line, and you can supply, for example, quite well-known password and username dictionaries that you can get from GitHub and various other projects. There's a few of them built into Kali Linux, for example. So I think that that combination is actually what, of 3 different types of modules, is what's making the Tacker quite unique and why more and more people start using it. And I think that's what makes it quite unique as an OWASP project, as a very handy little scanner, as an incubator project, a student project, but it is maturing. I think every summer we improve it a little bit more.

20:37Chris RomeoIn terms of, you mentioned vulnerabilities and having a library of vulnerabilities, how often is that updated and how do somebody who's using NetAttacker, how would they get those updates?

20:52Sam StepanyanThat is a very good question, Robert, and that's probably what I'm being asked quite frequently whenever I talk about NetAttacker. The problem with Netshark, just like with any other open-source projects, is that it is run by volunteers. So we don't really have a team which watches for any new CVEs released daily and utilizing, you know, writing modules, which of course it can be done. It's just, you know, because it is a volunteer-based project, we don't really have that team. However, There are pre-existing modules on quite a lot of CVEs there already, which I think is quite important. Whenever there's something big, you know, we did have quite a few very big vulnerabilities hitting the headlines. For example, I wrote a module for the Citrix CVE, which back in 2019 was quite big. And I think a lot of people using Citrix devices were affected. And again, the question is, if you don't know how many vulnerable devices you have on your network and where they are, what are their IP addresses, how do you solve this problem? Of course, you can do it with the commercial tools, but OWASP NetAttacker solves it with an open-source tool. And I remember at one of the Black Hats, I think Black Hat Europe 2019, I had someone approaching me from a very large charity organization, and I said, Sam, thank you very much for this tool because we're a charity, so we cannot actually afford to spend lots of money on commercial tools. But they used Att&cker to actually scan and find vulnerable Citrix devices on the network because that was a very big CVE back then, and we helped them out. Another very big one was ProxyShell last year, right, in March 2021. And of course, there were lots of Microsoft Exchange servers affected by it, and I released a module. So we, our team worked on it, and we, we very quickly wrote the blog post saying OWASP Nodacker is a free open source tool which has a module allow you to scan for vulnerable Microsoft Exchange Service with CVE-2021, I think it's 26855. That was a proxy shell vulnerability, and Yeah, we even had some of the government's cybersecurity authorities approaching us. So let's say it was— these were small, small countries in Southern Europe who actually sent me a big thank you saying, Sam, thank you very much for OWASP NetAttacker because we used it to scan our entire country's IP ranges, and we found organizations which are still running vulnerable versions. over Microsoft Exchange Server. And as far as I remember, I think this is a very unique thing because I think even the US government and FBI got involved in patching ProxyShell back then. And it was very, very big last year. But again, these are the examples. But to answer your question, it is not very frequent because we would always— we would love to have people to contribute and write new modules for CVEs whenever a new vulnerability is out.

24:16Yeah.

24:17Sam StepanyanBut because it is volunteer-based, usually we would only write the module ourselves if there is a very big vulnerability making headlines. But of course, because it's an open-source project, everyone's welcome to write a new module and submit a pull request on GitHub.

24:35Chris RomeoYeah, and we're recording this interview the day after the latest OpenSSL vulnerability vulnerability came out and kind of fizzled a little bit, you know, as it went from critical to high to, you know, how exploitable is this actual thing. But yeah, that's a good— and it sounds like y'all are doing a lot of work towards making updates as much as you can in an open-source world with a project that's staffed by volunteers. But it's really cool to hear that, you know, you're getting some feedback from folks around the world where You're building a tool that has an impact on charitable organizations that can't spend money, on smaller governments of the world, which may not have, you know, full-on cyber departments with thousands of people in it. And so, that's just— that's one of the powers of open source right there is they don't have to write a check to be able to use this technology. And so, kudos to you and the team for just driving that I did want to bring this back around and get super practical now. And so, when we think about our developer people that are listening, our AppSec people, I think they probably have a little bit— they're probably starting to put together in their minds how they could put this into use inside of their companies. But Sam, I'd love it if you'd just lay out for us, for a developer, for an AppSec person, let's say they have a pretty immature program right now.

26:00Sam StepanyanYeah.

26:00Chris RomeoSo they don't have a lot of commercial tools and things that are doing different scans and whatnot. What would be your recommendation/advice for how they take NetHacker and bring it into their organization and really get the most value out of it?

26:16Sam StepanyanYes, definitely. So NetHacker, first of all, will be very useful for network security and application security teams within the organization, especially as you mentioned, if they don't have an established, uh, you know, commercial tooling. Uh, what I find interesting, of course, in terms of potential users, it's not necessarily— well, charities is one good example, right? People who have a very limited budget, uh, to spend on the commercial tooling for scanning networks. But usually charities are the organizations which actually have very large networks because, uh, a lot of charities doing a lot of sort of research and development work, and they do have quite a big IT, but again, they don't really have any way to manage their estate. And this is how an attacker can help them. And one of the— and of course, the other potential use is for open-source tool is startups, because there are a lot of startups who are just, you know, starting up their businesses, and they don't really know what kind of cybersecurity tools they need to buy to bring into their networks. And yeah, that's another use case where NetAttacker as an open-source tool, as an open-source scanner, can help them out. One of the main tools within the main uses within our organization that I always try to tell people is very useful for an attacker is to create an asset inventory. If you remember, Jeremiah Grossman many years ago said that OWASP Top 10 is missing number A0 in its list because it's asset inventory. Because if you don't know the assets that you've got, you have no idea what you're securing, right? So you need to have the asset inventory. And I think we still have this problem. You go into an organization and say, okay, give me a list of all the servers that you have, and they will just look at you strange to think we don't have that, right? And especially now in the cloud-enabled world where you can have, you know, virtual machines and new services spun up in the cloud with a click of a button or, you know, automated scripts. Do you really know all the subdomains, all the hosts, all the servers that exist on your network within your domain? Do you have a list of all the open ports on them, right? So this is like number one use Of Netacker, and of course the other feature is that Netacker can actually take the server banners from the web service. Let's say Apache, Microsoft IIS, Citrix, whatever, and also the X-powered by header, and it can give you in a very handy Excel spreadsheet format an asset inventory for all your IP ranges or for your subdomain. And another great thing about Netacker is. You can actually create a list of all your assets in a simple text file, right, of all your networks. So you can go and say, okay, I'm an organization, my name is, for example, owasp.org, we own owasp.org, and these are the IP ranges where we have our assets. That's it. You give that list as an input to an attacker, and it will perform scans, and you will then tell an attacker, oh, I want to find out all my open ports, I want to find out what other web servers running in my network. I want to find out if I have anything which will respond to admin admin default credentials over SSH or over FTP. And these are the kind of tasks that you can do with Net Attacker and what you can automate. And of course, when it comes back, you will have your nice Excel spreadsheet with asset inventory, and you you will be able to figure out everything that you have. And also. What is also very important, because I think these days there's a whole industry around what it's— Gartner, I think, calls it external attack surface monitoring, right, or EASM. There are lots of solutions out there doing attack surface monitoring. So yes, NetTacker can be used as a free and open-source attack surface monitoring, but not necessarily external. If you go and, for example, scan your organization from outside. So you run an attacker somewhere in the cloud or on your computer, and you scan, scan your organization's resources from outside, externally visible. Well, you will get the picture of your external attack surface and external assets, externally facing assets and open ports and servers and vulnerabilities if you use vulnerability scans. But you can also take this tool and run it internally inside your network. You can just have it running in a Docker container And there's another very great feature about NetTacker that I haven't talked about yet. It has a web UI, so you can actually access NetTacker using a URL. And because it has an API and web UI, log into it, and it has a search engine. So it is basically like a little Google, or sometimes I call it Shodan, for your internal network. Because you can just have a search string and say, okay, do I have expired SSL certificates? Do I have port 22 anywhere open on my system? Do I have anything which responds to admin/admin? You can answer these questions using a web interface. You can start scans using web interface. And when the results are available, you can download the scan results in JSON or again in CSV format. So you can look at them in Excel, and of course you can export them out to other tools. And web UI, I think, is very important because you can literally roll out NetTacker in under 3 minutes in your network as in a Docker container, perform a scan of your subdomain or your IP ranges, find out all the open ports, all the types of web servers and applications running and then get the results straight away on a simple web page and then perform search within your assets and then download it as Excel. So I think this is what makes this little tool very, very valuable for many organizations, because if you go to a company and say, well, can you give me the list of all your servers with all open ports on them? Let's see how long it's going to take them to do that.

32:40Chris RomeoAnd with the attacker, you can do it in literally just a couple of months. Just a couple of months. We can have a list in a couple of months. I mean, it will be a couple months old at that point, but that's all good.

32:49Sam StepanyanWhen vulnerability is out, right, how can you go and say, okay, uh, do you have, uh, this vulnerability on your network? And people say, oh yeah, we do use, I don't know, vulnerable application, whatever that is— OpenSSL, Microsoft Exchange, Citrix F5, or whatever other— the very big vulnerabilities making the headlines. But how can you scan your whole network and find out if you have vulnerable devices, sort of mass scan. And this is actually what is different, um, uh, for an attacker comparing it with other popular tools, AppSec tools such as Burp Suite or OWASP ZAP, because tools like Burp Suite or OWASP ZAP, they are different types of scanners. They are web application vulnerability scanners which as a target that take one You give them, this is my URL, go and find vulnerabilities. So what ZAP or Burp Suite will do, they will try to spider that URL. They will try to discover all the paths, all the, they call the directory tree. They'll try to find all the forms, all the buttons, all the parameters. They will try to then to exploit all sorts of vulnerabilities. And in the end, will give you the report of any vulnerabilities found in just one target. NetTacker is different because it scans a whole network. It can scan thousands or tens of thousands of targets, your entire network, for just one vulnerability. You see, you completely flip the scan. Instead of saying scan one website for any vulnerabilities you can find, you say, nope, scan my entire network for just one vulnerability. Do I have anything with port 22 open, or do I have anything with, I don't know, port 9000 open? Do I have anything which has Apache-specific version running? Do I have any asset which responds to this vulnerability, for example, Citrix vulnerability or proxy shell vulnerability? And most importantly, let's not forget the brute forcing. Do I have any asset on my network which will respond to default credentials? Or you can just perform brute forcing and say, okay, do I have any devices with weak passwords from one of the published dictionaries in Kali Linux or any recent password leak? So these are all the questions that you can actually address and answer using NetTacker, and these are the questions that are not usually covered by ZAP and Burp Suite because they're different tools. They're different tools, they have different targets, and they were created for different purposes. It was pentesting of one system While NetAttacker is a whole framework and it consists of 2 words, right? Network and attacker. It attacks your network and then gives you a result and stores the result in its internal searchable database. And Metasploit, I think one of the questions, I think Robert, you mentioned Metasploit. So the difference with Metasploit is that it's much easier to automate NetAttacker. Than Metasploit. Kind of functionality, you might say it's a little bit similar, but the fact that NetTacker also performs things like subdomain scans and brute-forcing on top of vulnerability scanning, that's what makes it different. But because Metasploit just does vulnerability scanning, and again, you can probably give it a range of IP addresses and network, but the great thing about NetTacker, and as we will what I think differentiates it from everything else, including Nmap, you can give it a domain name. You can go and say, okay, this is mydomain.com. NetTucker will go and discover all the subdomains of yourdomain.com, and then it will go and hit every single subdomain in your network, and it will run whatever module you tell NetTucker to run on each target. And if you want to do a port scan on each target, it will do a port scan. If you want to discover if there is a particular piece of software running, it will do that. If you want to check if there is a vulnerability on any subdomain, it will do it. That is what is making it great because, of course, you can use— what I see usually on Twitter when people make recommendations, how other people would do that, they chain different tools, existing open source together. So they would go and chain let's say, subdomain finder, something like subfinder or tool, and then they will chain and will give it to another tool which will resolve it into IP addresses, and then it will give all these IP addresses to Nmap, right? So you don't need to do all this, the chain with a pipe in Attacker, because it has this functionality built in, and that's actually what we are looking to implement in the future. That's a feature called workflows. And the idea of the workflows is that the, the modules will be called sequentially in the order defined by the user in a workflow if it makes logical sense to do so. So to give you an example, for example, if I want to find out if my network has vulnerable WordPress, a service running vulnerable WordPress application, a specific plugin. The problem is, if you just run a WordPress vulnerability module on your network, it'll be very, very slow, to answer your question, earlier question, Chris, because a lot of the subdomains, a lot of IP addresses, they probably don't even run a web server, right? So if you don't know where the problem is and you start sort of blindly mass scanning everything, This is going to take a long time. However, we can write a workflow which says, okay, scan the target, perform a port scan on port 443 first. If there is a response of port 443, so it is open, then try to check if there is a web server running on it, and if, uh, then check if the, uh, what technologies are running on it. So if it runs, for example, PHP, right, for WordPress, only after that you can run the specific WordPress vulnerability scan, or you can even bundle it because we, for example, we have a WordPress version module as well. So you can go say, okay, run the WordPress version scanning module on the target. If the response is greater than or less than a specific version, only then proceed with the module. So you, you basically chain the modules and they will run depending on the results of the previous module execution. That is going to be a very valuable module. At the moment, we kind of have this built in with subdomains, and that's why people love NetHacker, because you can just give it the domain name, it will go and perform it for all the subdomains. But it doesn't— apart from the subdomain scan, it doesn't really have any other workflow. So that's the feature that we're working on at the moment. Hoping to release hopefully by next summer.

39:58Chris RomeoYeah. So, what's a key takeaway then or a call to action here, Sam, that would, as we kind of land the plane on, now that I know it's Network Attacker, that's kind of a little bit of an inside scoop right here. I know kind of where the name came from. But what would be a key takeaway or a call to action you would have for our audience here that they can do?

40:21Sam StepanyanYeah, I think first of all, I will invite everyone to go and check it out. So if you do have the problem in your organization that you don't know your assets, you have an asset inventory issue, all right, I would invite everyone just to use NetHacker just to find out the assets. And you can find out the assets just based on subdomains. And several organizations I talked to They were very happy because they can run this tool and we can find out what we have running on all our subdomains, and we can get asset inventory. I think this is the OWASP A0, according to Jeremiah Rossmann, our asset inventory. That's the call to action. So this is where the most useful bit is. The other, of course, takeaway would be, if there is a big vulnerability out there making headlines, go and check if there is a module already in NetTucker which can help you scan your entire network or networks And all your assets for this vulnerability. And if there isn't, you can actually contribute one yourself. And we're coming to contributions. So if you are a Python developer, and actually nowadays you don't even need to be a Python because we've changed our modules from being Python modules to YAML modules. So actually writing a module is very, very simple these days because it's all based on YAML. Text-based. So if you know what payload you want to send to the target and what response from the target would indicate that there is a vulnerability, you can write your own module and of course contribute it. And I welcome contributions from everyone. OWASP Net Hacker, just like all OWASP projects, is an open-source project, which means we're always open to collaborators and contributors. And we've been actually quite lucky having quite a few students contributing. And yeah, I think if there's a latest and greatest CVE that everyone's talking about, creating new modules I think is very useful. So major takeaway is go and try it and see if it works for you. There are several vulnerabilities that NetTacker scans out of the box and including things like proxy shell and a lot of other older vulnerabilities, perform some port scans and see if it works for you. And if you can provide us with any suggestions for improvement to the project team, we would greatly appreciate it. You can do it using GitHub if you go to github.com/owasp/nettacker because that's where the project lives and you can just raise a GitHub issue as a new feature request or any bug. And of course, we welcome all contributions, not necessarily code or ideas. We try to make NetTacker an international tool because there are quite a lot of languages already contributed. And even if you can translate the command line interface or the web interface messages into a different language, that will help. If you can help us with documentation, if you read the documentation and you couldn't figure out how to do something and then you actually figured out yourself. Yeah, we're very welcome. We would invite people to come and contribute documentation as well. So there are many ways, and it's a relatively new tool. Of course, NetTacker was only created in 2017, and it didn't get enough attention originally, but I think it's growing, and I feel that it has quite a good future because it provide OWASP with having an alternative network scanner, because at the moment we only have a web app scanner. Um, so yeah, I think that's the, the main invite. And of course, your previous question, Chris, for the developers and how you can do the pipeline— they can of course, uh, perform scans of the infrastructure, uh, of their cloud infrastructure in the pipeline. They can perform scans of open ports. They can for example, nightly run brute forcing attacks and check that no one created a weak password. And it's actually quite flexible because developers can just take YAML code and automate any fuzzing tests that they would like, because anything, any test that you can think of where you send a particular payload to the target and then you check what response you get back, and you'll have your expected response And if you don't get the expected response, you can then flag it as a finding, and then you can run it overnight, you can run it in a pipeline, and then get all the results. It's a very, very flexible system now that we've got YAML, and we're trying to expand YAML as well. So it's not just send-receive kind of logic. We're trying to add if-then-else. There is already a reverse logic, so OWASP can report something as a vulnerability if it doesn't find something in a response as well. So there's a reverse logic there, but we're trying to add sort of if-then-else and even, you know, things like while loops in YAML, uh, which again means sort of without even knowing a single line of code, people like QA and testers can utilize this tool and use it for security testing.

45:35Chris RomeoYeah, that's great. So, um, yeah, so Sam, kudos once again to you and the team for all of your efforts into bringing Net Hacker to the world. And I guess we just hope you keep moving forward with it. And once again, thanks for sharing this with our audience today and look forward to connecting with you at an upcoming conference and probably hearing another talk about Net Hacker as we go along the way. So, thanks, Sam. Thanks for being with us.

46:03Sam StepanyanThanks very much for having me.

46:05Thank you for listening to Security Journeys AppSec Podcast. You can find us on Twitter @AppSecPodcast, on LinkedIn as the Application Security Podcast, or on the web at www.securityjourney.com/resources/appsecpodcast. Find Chris on Twitter @edgerow and Robert @RobertHerwitt. Remember, there are many application security paths, but only one destination.

7,522 words · transcript by assemblyai

More like this

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.