NCC Group admits its training data was leaked online after folders full of Crest pentest certification exam notes posted to Github
- Reference: 1597157886
- News link: https://www.theregister.co.uk/2020/08/11/ncc_group_crest_cheat_sheets/
- Source link:
The documents, posted to the cloudy code shack by an account set up last month, were held in a folder marked "cheatsheets". They appeared to be a collection of exceptionally frank and well informed training materials.
[1]
An NCC-branded "solution" from the Github "cheat sheet" repo. Click to enlarge
The docs offered step-by-step guides and walkthroughs of information about the Crest exams. One file, called notes.txt and no longer available on Github, included the line: “clone of the app exam so u can pass 1st time” adding “speak to your line manager or AD first to book before your exam”. It also referred to “mock rigs” and “inhouse crt rigs to solve” on a “CRT training course”.
[2]
Some of the files in a repo labelled "cheatsheets and write ups for the CREST CRT and CTT exams". Click to enlarge
Crest offers a certification called CRT: Crest Registered Tester. As [3]explained on the Crest website, the exam is a practical exercise where candidates are “expected to find known vulnerabilities across common network, application and database technologies”.
The revelation of the internal company docs have provoked a debate in Britain's tight-knit infosec community about the nature of the relationship between NCC and Crest.
An NCC Group spokeswoman told The Register that the files were “a combination of old NCC Group internal training materials and content that has either been incorrectly attributed to NCC Group or which is unconnected to NCC Group.” She also confirmed that NCC CISO Dominic Beecher had posted on Github asking the person who shared them to get in touch.
[4]
NCC Group confirmed to El Reg that this was a genuine message posted by CISO Dominic Beecher to the Github leaks page
Sources who contacted The Register and spoke on condition of anonymity described the data's existence as an “open secret” in the British infosec community. Another who examined the files told us: “Some of the material is current exam content, while some of it is over a decade old (but current at the time of the material being created as per its date).”
Crest's CRT certification exam also includes a “multiple choice section aimed at assessing the candidate’s technical knowledge.” Copies of what appeared to be multiple choice test questions had also been uploaded to Github, complete with highlighted answers.
[5]
A screenshot of what appears to be a multiple choice exam with correct answers highlighted in yellow
At least some of the files in the repo also appeared to be connecting to a domain called canarytokens-dot-net when opened, multiple sources told The Register . VirusTotal entries shown to us suggested that one file was loading something that registered with two detection engines as a generic remote access trojan; however, the canarytoken website appears to be a freely available honeypot-style file tracking token designed to phone home once a file including them was opened.
“CREST have strict NDAs in place which forbid the disclosure of ANY exam/lab content for these exams and quite rightly so,” said a Reg reader who asked to be identified only as S. “I know that if I was a customer of NCC Group, I would be annoyed that I had paid for a qualified CREST tester, and may have received a tester who only passed the exams due to receiving these [documents].”
Others on Twitter expressed similar concerns:
It's been forked, but that isn't really the issue at hand here. It's the abuse of the NDA and breach of both the CREST company CoC along with the member CoC for those who trained or authored the materials. NCC and CREST are like a jam sandwich and this is one sticky situation. — Scriptmonkey_ (@scriptmonkey_) [6]August 11, 2020
A Crest spokeswoman told The Register the training materials were not relevant to current exams, while acknowledging their origin from NCC, which is a founding member of Crest. In a statement the organisation said:
CREST is aware of the content that has been posted by an individual on Github. We have conducted our initial investigation and this does not affect the integrity of current CREST examinations. The content appears to mainly be internal training material produced by a member company. There is also a small amount of old exam material that has been posted by the individual however this is out-of-date and is no longer used in CREST examinations.
Crest’s spokeswoman added: “We can confirm that neither the ‘crestnda’ nor the ‘crestapproved’ replies on Github were posted by CREST and that these accounts are not affiliated with us in any way. We are continuing to investigate this incident.
NCC’s spokeswoman added to El Reg : “We take our membership of CREST, the integrity of the CREST Code of Conduct, and our related obligations very seriously and comply with our obligations as a CREST member. We are currently reviewing the materials that have been posted, and are working closely with CREST.”
A couple of years ago a grad trainee who evidently did not have access to any cheat sheets [7]took NCC to an employment tribunal , having emailed 300 staff asking for help on locking Kali Linux before stepping away from her laptop.
NCC’s share price on the London Stock Exchange was 181.30p at the time of writing. ®
Get our [8]Tech Resources
[1] https://regmedia.co.uk/2020/08/11/crestncc3.png
[2] https://regmedia.co.uk/2020/08/11/crestncc2.png
[3] https://www.crest-approved.org/examination/registered-tester/index.html
[4] https://regmedia.co.uk/2020/08/11/crestncc1.png
[5] https://regmedia.co.uk/2020/08/11/crestncc4.png
[6] https://twitter.com/scriptmonkey_/status/1293142699990712321?ref_src=twsrc%5Etfw
[7] https://www.theregister.com/2018/11/27/ncc_group_employment_tribunal_grad_trainee/
[8] https://whitepapers.theregister.com/
NCC Groups understanding of Git is apparently as good as their understanding of NDA's
ET Phone Home
They put in a phone-home thingie on _files from an infosec course_? Really? Lesson 1, laddie: air gap. Or use Someone Else’s Computer (™). Or set the firewall, etc, on the home server (anyone taking infosec courses would have a home server or two, right? DHCP, DNS, RRAS, ADDS, Pi-hole, etc...). Or some combination of the three. Anyone who got caught by this should fail twice. Once for cheating, once for not taking elementary precautions.
Outdated, I dont think so.
One of those cheat sheet documents is an exact abbreviated walkthrough of an exam box I saw before the Covid-19 lockdowns. Some of this is definitely recent. I am appalled buy their attitude and attempts to talk this down. Especially, when others have worked very hard for the qualification.
On trusting trust
An online exam for pen testers. What could possibly go wrong?
Re: On trusting trust
Bonus points for pwning the host?
Depending on the scope of the course and exam this may be a valid solution (but harder to grade, counting multiple choice answers is probably a more fair assessment).
In the context of being a certified pentester I fail to see what knowing the blocksize of DES brings to the table. Unless I'm missing something.
I assume you haven't still used that data as a pick up phrase yet. If it doesn't work when combined with "I am a certified pentester", you need to try at different kind of pub.
"One file, called notes.txt and no longer available on Github"
Uh... false? Seems to still be there to me...