Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Thursday, April 12, 2007
The Spreading Al Qaeda Network
The recent attack in Algeria by Al Qaeda's Committee in the Islamic Maghreb in Algeria, coupled with the re-emergence and spread of the Islamist presence in Somalia, clearly show two things:
1) That the macro strategy of the core al Qaeda of fomenting the creation of small, autonomous groups to carry out jihad is firmly taking root and
2) That Africa, from the Northern tier to the Horn, with a network to Southern Africa and tactical alliances in West Africa, have made that continent one of the most important battle grounds in the long war on Islamist terrorism.
Algeria is particularly important because of its proximity to Europe and the large presence of Algerian diaspora in many European countries, and the radicalization of many of these diaspora groups.
The ability of the Algerian group to inflict large-scale casualties, the possible role of the group in fomenting violence in neighboring Morocco, and its operational presence down to Mali all indicate some important growth and growing capacity. My full blog is here.
Microsoft WGA Manager Responds to Vista BIOS Hack
I know many of you are aware of reports of hacks that attempt to exploit our OEM BIOS based activation. We're aware of this type of hack and I wanted to take a minute to describe how these work and how we plan to respond.
---------------------------------
This is a respond to Paradox, the application cracking group, releasing a BIOS Emulation Toolkit For Windows Vista x86 that bypasses the product activation requirement by emulating 'Royalty OEMs' licensed hardware.
While Alex talks about the BIOS hacks, he ends the blog with a not so strong signal.
Our goal isn't to stop every "mad scientist" that's on a mission to hack Windows. Our first goal is to disrupt the business model of organized counterfeiters and protect users from becoming unknowing victims. This means focusing on responding to hacks that are scalable and can easily be commercialized, thereby making victims out of well-intentioned customers.Sounds like they are more worried about China and private PC shops that sell computers with stolen OSs then the determined hackers that will do anything just to beat the system (and perhaps save a few bucks as well).
CD Lost in Shipping Contains Data On 2.9 Million Georgians
A computer disk containing personal data on 2.9 million current and former Medicaid and PeachCare recipients in Georgia was lost as it was being shipped out of state, officials said Tuesday.
The CD contained addresses, birth dates, names and Social Security numbers of Georgia participants in the health programs. The data covered a four-year period that ended in June 2006 and included some people who are no longer on the rolls. The breach was reported to the state by Affiliated Computer Services, a private vendor with a contract to handle health care claims for the state.
The CD was lost as it was being shipped from Georgia to Maryland, ACS spokesman David Shapiro said. The company had been working with the carrier for the last several days to find the package. Shapiro declined to name the carrier.
He said there are no signs that any of the personal data has been accessed.
"We are treating this as a missing package," he said.
The Georgia Department of Community Health is requiring the Dallas-based computer services company to provide written notification to all affected members as well as an application to receive a free credit report.
This story was reported to me by a friend and reader.
Wednesday, April 11, 2007
MOMBY - Trojaned Navigation Menu
http://momby.livejournal.com/
Myspace.com provides a site navigation menu near the top of every page.
Users generally use this menu to navigate to the various areas of the website. The first link that the menu provides is called "Home" which navigates back to the user's personalized Myspace page which is essentially the user's "home base" when using the site. As such this
particular link is used quite frequently and is used to return from other areas of the website, most importantly from other user's profile pages.
A content-replacement attack coupled with a spoofed Myspace login page can be used to collect victim users' authentication credentials. By replacing the navigation menu on the attacker's Myspace profile page, an unsuspecting victim may be redirected to an external site of the attacker's choice, such as a spoofed Myspace login page. Due to Myspace.com's seemingly random tendency to expire user sessions or log users out, a user being presented with the Myspace login page is not out of the ordinary and does not raise much suspicion on the part of the victim.
-------------------------------------------
What is not noted in the MOMBY post is that this attack vector was used in last 2006 in conjunction with a pretty serious Quicktime flaw to spread a worm.
So this Myspace flaw should be seen as "in the wild".
Cooling Computer Chips with Oil
Submerging computer chips in oil could make them more energy efficient, according to a UK company that hopes to start selling such systems within a year.
The microprocessors inside servers and desktop computers are normally cooled using fans that blow air across the components. But UK a company called Very-PC hopes to see a much more radical, oil-based alternative, take off instead.
"It is possible to cut power consumption in half," managing director Peter Hopton told New Scientist. "You don't need to drive inefficient fans, or the usual air conditioning."
UK Plans RFID License Plates
The British government plans to test RFID-embedded license plates, developed by Hills Numberplates. Such e-plates might be read by any strategically placed reader along a road at speeds of up to 300km/h and up to 100 metres away.
Applications include speed traps, detecting stolen vehicles, and traffic management. Network security firm McAfee reckons that the technology also lends itself to its use as a surveillance tool by governments or criminal exploitation.
Tuesday, April 10, 2007
AACS Hackers Team up with XBOX Hackers
The DRM "protecting" HD DVD and Blu-ray Disc films -- AACS -- continues to unravel at the seams. In parallel efforts, hackers in both the Xboxhacker and Doom9 forums have exposed the "Volume ID" for discs played on XBOX 360 HD DVD drives. Any inserted disc will play without first authenticating with AACS, even those with Volume IDs which have already been revoked by the AACS LA due to previous hacking efforts. Add the exposed processing keys and you can decrypt and backup your discs for playback on any device of your choosing. So yeah, it looks like last week's WinDVD update has been quickly and definitively made useless just as we expected it would be. Well, for XBOX 360 HD DVD drive owners anyway but you can see where this is heading, right? Now go ahead AACS LA, revoke the Toshiba-built XBOX 360 HD DVD player... we double-dog dare ya.
More Trouble in Casablanca
Moroccan security forces have killed what they described as a militant, and another blew himself up during a dawn raid in Casablanca.
The pair were killed in a dawn raid in the el Fida district of the port city as part of an operation to find suspects in an 11 March bomb explosion in an Internet cafe. Police said both were carrying explosives.
Hours later, a third suicide bomber blew himself up close to where the raid took place.
In March, the alleged leader of a suicide bomber squad detonated his explosives belt to stop police arresting him.
Another suspected member of the group and three customers in the café were injured.
Police believe the bombers were in the café to get instructions by email.
More than 40 suspected militants have been arrested in Morocco since then.Monday, April 9, 2007
Education Key to Protecting Kids on Myspace
Does the increased use of social networking sites by children lead to increased risk? Concern about online predators and pornography has led some politicians and law enforcement officials to call for unreasonable restrictions on public access to these sites.
But is the perception of increased risk accurate? How much of the public discussion of these trends is myth, and how much is fact? Two recent studies suggest that many fears are overblown.
The Crimes Against Children Research Center at the University of New Hampshire recently released a study that found that unwanted online solicitations are down from 19% in 1999 to 13% today — a decline that is taking place despite the rising popularity of social networking sites.
Of the unwanted solicitations that were received, a significant number (43%) came from other minors, not from adults.
A separate study of MySpace by Dr. Larry D. Rosen at Cal State found that only 7% (1 in 14) of those teens interviewed were ever approached by anyone on MySpace with a sexual intent. Nearly all of them simply ignored the person and blocked him from their page.
But in the face of this tempered analysis, legislators are still pushing for unreasonable restrictions. The Deleting Online Predators Act (DOPA), which has been re-introduced in the House and Senate, would cut funding to public schools and libraries unless they block access to social networking sites. Meanwhile, some state Attorneys General have been pushing for stricter age verification that will in all likelihood have little or no effect.
Adam Thierer, a senior fellow at the Progress and Freedom Foundation, says that attempts to block all social networking sites are likewise unworkable and undesirable, since under the current definition, sites as useful and diverse as Wikipedia, CBSNews, and Flickr would fall into that category.
Age verification is another unworkable solution, according to Thierer. As he points out in a recent paper, all the existing methods for verifying age are unreliable and easily circumvented. The danger with age verification solutions is that they may lead parents to a false sense of security.
The solution, says Thierer, is not stricter controls, but the same things that have helped defend children in the offline world: education, effective law enforcement, and healthy adult supervision.
-------------------------------------
I couldn't agree more....
Laptop Thefts Expose 40K Chicago Teachers
A thief walked into the headquarters of Chicage Public Schools (CPS) on Friday, April 6 and grabbed two laptops containing the names and social security numbers of 40,000 teachers. The CPS has released an image of the suspect captured by CCTV and is offering a $10,000 reward for information leading to the arrest of the thief or recovery of the data.
The laptops belonged to an accountancy firm and its subcontractor, who were auditing pension contributions made by teachers between 2003 and 2006. The data does not include date of birth or addresses, which is something, we suppose.
In a press statement today, the CPS apologized for this "breach of security, and we are working around the clock to get the information back in safe hands as quickly as possible". It is offering to pay for one year of credit protection for any employee or former employee affected by the theft.
Iraqi Gov Attempts to Control Chlorine Storage
The Baghdad security plan commanders have taken strict measures to control and monitor trucks loaded with fuel in Baghdad's neighbourhood, fearing that they might be loaded with chlorine to target civilians in residential areas.
Hamdi Ali, owner of a workshop for manufacturing cleaning materials in Zyoot district in Baghdad, told Gulf News: "Since armed groups started to use chlorine gas, my workshop was inspected three times by American and Iraqi forces, basically because I store a tolerable amount of this material to use in my work. Inspection operations are inconvenient but justified since the situation is dangerous," Ali added.
Due to this atmosphere of fear faced by Baghdad inhabitants, the Iraqi intelligence services took certain measures to avoid any further chemical attacks. These measures include: ordering the concerned bodies to check all stores that use chlorine in Baghdad and compel chlorine traders to submit a list on the imported and distributed quantities of this material.
Ineffectiveness of the UN Travel Bans on Iran Exposed
Well, if we needed further evidence of the lack of effectiveness of the United Nations travel ban lists (supposedly obligatory lists that ban the individual from traveling from his/her home country), we need look no further.
Just ask Gen. Mohammad Basqer Zolqadr, a Iranian Revolutionary Guard general and deputy interior minister. He publicly and happily violated the UN ban with a recent official visit to Russia. He not only traveled to Russia unimpeded despite being on the recently-mandated ban under Resolution 1747 because of his role in Iran's nuclear program, but he bragged that the six-day sojourn showed just how ineffective the resolution is.
"Despite resolution 1747 which imposed a travel ban on some members of the Islamic Revolutionary Guards Corps, including me, I traveled to Russia and no restriction was applied," Zolgadr crowed on returning home.
He is right. Without real international cooperation, the ability to violate the travel ban lists with impunity only add to the problem they are supposed to be tackling. My full blog is here.
This ineffectiveness was also noted by Fars News, which has connections to the Iranian government. But of course, they point the finger at Russia for allowing the travel in the first place.
As I reported on Friday, Iran declared on Monday that pressures and sanctions may not affect Iran's progress and activities in the field of nuclear technology. A ceremony held at Natanz enrichment center on Monday was used to announce Iran's success in gaining full access to the know-how required for the production of nuclear fuel at industrial scale.
But the Deputy head of Iran's Atomic Energy Organization (IAEO) Mohammad Sa'eedi said Iran's industrial production of nuclear fuel is not synonymous with the installation of 3000 centrifuges.
CIA to Oversee the New National Clandestine Service
The US has announced the creation of a new intelligence agency led by the CIA to co-ordinate all American overseas spying activities.
The National Clandestine Service (NCS) will oversee all human espionage operations - meaning spying by people rather than by technical means.
The move is the latest in the post-9/11 reforms of US intelligence agencies.
Analysts say the NCS restores some authority to the CIA after it lost overall control of US intelligence.
Perform a Security Code Review for Managed Code
http://msdn2.microsoft.com/en-us/library/ms998364.aspx
Google Takes On Local 411 Service
Google has quietly launched Google Voice Local Search, an experimental service that allows people to search for local businesses over the phone. There are no ads on the service, which is available only in the U.S. To use it people can dial 1-800-GOOG-411 (1-800-466-4411) from any phone and search for a business by name or category and be connected to the business at no charge. Users can also get the search results and additional details over SMS if they are on a mobile phone.
-------------------------
For those readers not in the USA, 411 is a phone service that is normally provided by the local phone company and can cost up to $1.25 USD per use. Approximately 6 billion calls are made to 411 within the United States each year.
So I am sure the local phone companies are happy about this move....not!
MS Windows GDI Local Privilege Escalation Exploit (MS07-017)
http://www.milw0rm.com/exploits/3688
-----------------------
Also on Milw0rm, Muts has posted several "points of interest" that he found in Microsoft Office 2007 using a small python file fuzzer.
Sunday, April 8, 2007
Open Source Gaim Project Gets Name Change
There is one catch, however - they have to change the project's name.
Now with this issue behind them, they hope to release Pidgin version 2.0 within days.After a long, and unfortunately secret debate (as we could not say why we were looking at a name change, we ended up just doing this ourselves), we settled on the name "Pidgin" for gaim itself, "libpurple" for libgaim (which, as of 2.0.0 beta6, exists), and "Finch" for gaim-text. Yes, the spelling of "Pidgin" is intentional, see http://en.wikipedia.org/wiki/Pidgin.
I have been using Gaim for several years now and I love it. I am glad to hear that this issue is behind them and that they will be able to work a bit more freely (without the fear of legal troubles from AOL).
Shmoocon 2007 Videos Released
Shmoocon Videos
Shmoocon Speaker List (including Bios)
Vigilantism Is a Poor Response to Cyberattack
Last month Marine Gen. James Cartwright told the House Armed Services Committee that the best cyberdefense is a good offense.
As reported in Federal Computer Week, Cartwright said: "History teaches us that a purely defensive posture poses significant risks," and that if "we apply the principle of warfare to the cyberdomain, as we do to sea, air and land, we realize the defense of the nation is better served by capabilities enabling us to take the fight to our adversaries, when necessary, to deter actions detrimental to our interests."
The general isn't alone. In 2003, the entertainment industry tried to get a law passed (.pdf) giving it the right to attack any computer suspected of distributing copyright-protected material. And there probably isn't a sysadmin in the world who doesn't want to strike back at computers that are blindly and repeatedly attacking their networks.
Of course, the general is correct. But his reasoning illustrates perfectly why peacetime and wartime are different, and why generals don't make good police chiefs.
----------------------------------I think Bruce's point is very important, especially when looking into some of the recent court rulings.
Army Considers Following Air Force into Cyberspace
The Army may follow the Air Force’s lead in setting up a cyber command.
“Cyber war is emerging as just as important as kinetic war, some say more important,“ said Vernon Bettencourt, the Army’s deputy chief information officer at the recent AFCEA Belvoir chapter/Program Executive Office Enterprise Information Systems industry day in Bethesda, Md.
“We are looking at what the Air Force has done and we keep asking ourselves, ‘Are there any ideas the Army should be adopting?’” Bettencourt added.
The Air Force announced it would create a cyber command last November that would be located at the 8th Air Force at Barksdale Air Force Base, La. The service named Lt. Gen. Robert Elder, commander of the 8th Air Force, as the command’s first chief. The command is scheduled to begin operations in May and be fully operational by October 2009.
Vulnerability Assessment - When is Enough Enough?
This is a fair and increasingly common question in web application security. Especially considering that we never know how many bugs (or vulnerabilities) actually exist in a piece of code. This is also why I tend to approach security as an attempt to make a system as hard as possible (not impossible, because that’s impossible) for the “bad guys” to break-in. Finding and fixing vulnerabilities, whether pre-deployment or post-production, makes the next vulnerability harder to identify. The idea is to require the bad guys to expend more resources (time, money, etc.) than it’ll be worth should they succeed. Realistically though given a long enough timeline, everyone gets hacked, if they haven’t been so already. Which begs the question, when do we stop looking for vulnerabilities?
Texas Sues RadioShack After Trashing of Customer Records
Texas is suing RadioShack after the retailer's employees dumped thousands of customer records in garbage bins behind a store near Corpus Christi, Texas, on March 21. The records contained Social Security numbers, credit and debit card information, names, addresses and telephone numbers, according to investigators.
Texas Attorney General Greg Abbott late on Monday filed documents charging that RadioShack had violated a 2005 law—the 2005 Identity Theft Enforcement and Protection Act—requiring businesses to protect and properly destroy any consumer records that contain sensitive information, including Social Security and bank account numbers.
RadioShack issued a statement saying that the Portland, Texas, store was out of line in this "isolated instance." The Portland store is part of a shredding program that RadioShack uses throughout Texas to ensure that documents are destroyed according to Texas law. "In this isolated instance, the store did not act in accordance with this program," according to the statement. RadioShack said it intends to work "amicably" with the Texas attorney general and that it takes seriously its obligation to maintain and safeguard company records, "especially when they contain a customer's non-public information." The retail company also said that it has moved quickly to reclaim and to secure the dumped documents.
The attorney general also charged RadioShack with violating Chapter 35 of the Business and Commerce Code, which requires businesses to develop retention and disposal procedures for clients' personal information. That charge could translate into fines up to $500 for each dumped record.
Filehippo Update Checker
I gave this checker a test run today, and it found several application updates on my laptop - Foxit Reader, Google Maps, Paint .NET, etc. It even reminded me that I forgot to install Update 1 for Java JRE 6.0 on this computer.
http://www.filehippo.com/updatechecker/
The Update Checker will scan your computer for installed software, check the versions and then send this information to filehippo.com to see if there are any newer releases. These are then neatly displayed in your browser for you to download.
The client is FREE, only 100kb to download and only takes seconds to run! In fact on our test machines the process is complete in under 2 seconds!
Saturday, April 7, 2007
Morocco Dismantles Terror Cell
Moroccan security forces have dismantled an Islamist cell recruiting volunteers to fight in Iraq and detained 62 people, the government said on Thursday. "The first elements of the inquiry reveal the existence of ideological links with and financial and logistical support for international terrorist groups," it said in a statement, cited by Reuters.
Those groups included al Qaeda, the Algeria-based Salafist Group for Preaching and Combat (GSPC) and other international terrorist organisations, it added. All those arrested were Moroccan.
In the summer of 2006, the Moroccan authorities said it had broken up a cell planning to declare a Jihad in northeast Morocco, attack tourist sites and assassinate people who symbolise the state.
The government statement said those arrested in the latest round-up would be brought before judicial authorities in line with Morocco's anti-terrorist laws.
-----------------------------------
It should be noted that the Algeria-based GSPC is now known as the Al-Qaeda Organization in the Islamic Maghreb.
Thailand Maintains YouTube Blocking
BANGKOK -- Thailand Friday expressed outrage at the posting of two new videos mocking the country's revered king on the video-sharing Web site YouTube, pledging to maintain a ban on the site.
"This group of people has found another outlet, taking another action that is considered very offensive to the king," said communications ministry spokesman Vissanu Meeyoo.
"Thailand does not want to take this kind of action. We are just doing it temporarily," he said of the ban imposed Tuesday.
The original video that prompted Thai authorities to block YouTube appeared to have been withdrawn by its creator, with a notice on the site saying it had been "removed by the user." But two more clips, posted by users with different screen names from the original video creator, surfaced Friday. The site was accessed in Bangkok via a foreign server.
Like the first video, one of the new postings showed images of King Bhumibol Adulyadej's face covered with graffiti or juxtaposed with images of feet, considered deeply offensive here. Another clip showed pictures of the king that had been digitally altered to make him resemble a monkey, and carried messages saying Thailand's leaders are "evil and hate free speech."
The second video used an expletive to denounce the king and the government.
"Officials will meet this afternoon with an association of Internet users to discuss taking further action, after the parent company, Google, failed to give any cooperation," the communications ministry spokesman said.
"We need cooperation from Internet users to monitor these groups," he added.
A spokeswoman for YouTube remarked before the new videos were posted that the company was "disappointed" with Thailand's ban of the site.
"We have asked the government to lift the block, and we look forward to the resumption of service to our Thai users," spokeswoman Julie Supan said.
The decision to block the entire YouTube site drew sharp criticism from media freedom groups, who said the ban highlighted a growing trend for the military government to censor political expressions on the Internet.
Thailand's king, almost universally adored by Thais, is the world's longest-reigning monarch, and one of the few who is still protected by tough laws that prohibit any insult against the royal family.
The ban came a week after Thailand jailed a Swiss man for 10 years for insulting the king by vandalizing his portraits during a drunken spree.
Malaysian Bloggers May Have to Reveal Identities
KUALA LUMPUR -- The battle to control cyberspace in Malaysia intensified Thursday as a minister said that bloggers may be forced to register their names to avoid unjust claims being posted on the Internet.
Deputy energy, water, and communications minister Shaziman Abu Mansor said that his department was considering an option to make surfers identify themselves so that the government can track their activities.
"We might follow some other countries who register bloggers as well," he said. "That's what Singapore is doing as well.
"It's much better if we can have a list of active bloggers ... We want to know who are the bloggers," he added. Malaysia's Prime Minister Abdullah Ahmad Badawi and a number of other ministers have launched attacks on Malaysian bloggers and Internet surfers in recent months, accusing them of spreading lies about the government.
Two prominent bloggers, Jeff Ooi and Ahirudin Attan, are currently being sued for defamation by the government-linked New Straits Times press newspaper group in an unprecedented case decried by rights activists as an attack on free expression.
However, Shaziman denied that he was floating the idea, first mentioned by him in parliament Wednesday, to curb comments published on the Internet.
"It's nice to have a list of bloggers, whoever they are," he said.
Human rights group Aliran Thursday condemned Shaziman's suggestion, saying in a statement that the attacks by politicians on bloggers "are a prelude to possible moves to control and censor the Internet."
Ministry officials said that there were no firm proposals to register blogs but that the option was being considered because of anonymous posts.
"For those bloggers who are anonymous, it's very hard for us to take action against them if they post on their blog," an official, who asked not to be named, said.
"Some of the bloggers are anonymous, so they are using their blog to write wrong information about leaders and all those people who are in high positions," said the official.
Writing Wednesday, Ahirudin said that politicians, including Shaziman, did not understand bloggers and were making the attacks out of fear. "We have people like Shaziman who think they can bully bloggers because bloggers are small individuals and make easy pickings," he wrote.
Malaysia's media is kept under tight control with laws allowing the government to revoke or suspend newspapers' publishing permits - a power that has been used several times in the last year.
Blogs have seen an increase in popularity as Malaysians take to cyberspace to discuss politics and social issues.
Friday, April 6, 2007
Iran Releases British Soldiers - Update
On arrival at Heathrow, the group were set to transfer immediately by Navy helicopter to the Royal Marines Base Chivenor, near Barnstaple, north Devon, for a debriefing and medical checks.
They were lined up while weapons were cocked, making them "fear the worst", one of the 15 freed sailors revealed.
The crew were told that if they did not admit they were in Iranian waters when captured that they faced seven years in prison, a press conference heard.
Opposing their captors was "not an option," they said.
And after the 15 marines and sailors were seized they were subjected to random interrogation and rough handling, and faced constant psychological pressure, they said.
At the same time, Fars News is reporting the following...
An Iranian MP said President Ahmadinejad's decision to pardon the British troop proved Iran's role in international issues and displayed the Islamic Republic's might and authority.
Speaking to FNA in the eastern city of Birjand on Thursday, representative of Ferdows, Sarayan and Tabas at the Islamic Consultative Assembly Amir Hassankhani said, "Today West intends to fade away Iran's role in international issues and President Ahmadinejad's decision about the sailors was a strong response to the said intention."
He said that Iran is a country which cannot be ignored due to both its extent and its power, reminding that pardoning of the British troops was a gift to the Britons and proved Iran's good intentions.
The legislative official further mentioned, "Arrest and release of the British sailors proved that if Iran's issues and demands are overlooked at the international level, the Islamic Republic can create different challenges for the other side."
Addressing western powers, he said, "Do not try to hide Iran's role in the international issues through your global media, because President Ahmadinejad's decision proved that Iran is prepared to give up its rights to help solve international issues."
There is no end to the spin......
Yesterday, John Bolton, former US ambassador to the United Nations, was interviewed on the US-funded Alhurra Arabic-language television network and said the following...
“In a way I think Tehran has won a double victory....They won a victory when they captured the hostages and they won a victory when they released the hostages“.
While we are on the subject of "giving up rights to help solve international issues", there are reports that Iran will mark its “National Day of Nuclear Technology” at the Natanz nuclear site on Monday, April 9th.
However, I have been unable to find this piece of information on any of the Iranian new sites as of right now.
Chlorine Bomb Attacks Continue in Iraq
BAGHDAD (AP) — A suspected al-Qaeda in Iraq suicide bomber smashed a truck loaded with TNT and toxic chlorine gas into a police checkpoint in Ramadi on Friday, killing at least 27 people — the ninth such attack since the group's first known use of a chemical weapon in January.
...
The bombing in Ramadi, the capital of Anbar province and an insurgent stronghold, left many people nearby with breathing difficulties and some needed hospitalization, according to police Maj. Jubair Rashid al-Nayef. Most were released in about 30 minutes. Thirty other victims were hospitalized with wounds from the explosion.
...
The first known chlorine attack took place Jan. 28, also in Ramadi. Pentagon officials first disclosed the attack, which killed at least 16 people. In low exposures, chlorine irritates the respiratory system, eyes and skin. Higher levels can lead to accumulation of fluid in the lungs and other symptoms. Death is possible with heavy exposure, according to the U.S. Centers for Disease Control and Prevention.
...
In the Internet feud, the Islamic Army in Iraq gave a rare glimpse of deep discord inside the Islamic State of Iraq, an umbrella organization for militant groups.
In a Thursday posting, the Islamic Army charged that al-Qaeda — a key group inside the Islamic State — was killing fighters of the Islamic army and other militant Sunni groups if they did not pledge loyalty to al-Qaeda.
It also charged that al-Qaeda had killed Harith Dhaher al-Dhari, a field commander of the 1920 Revolutionary Brigades, another organization under the Islamic State umbrella.
------------------------------------------
In these cases, I personally believe that Al-Qaeda sees the two fold "benefit" of using chemical agents in their attacks.
If the chlorine kills more people, I am sure they would like this.....otherwise it is sure to increase one other thing - fear.
The addition of chemical agents into an otherwise normal bomb is more about fostering fear than creating more damage. This is "terrorism" at its core.....
The last part of this article is important as well. There have been reports that Al-Qaeda (former GSPC) was using similar "bully-type" techniques in Northern Africa, if I remember correctly.Looks like Al-Qaeda is basically saying....you are either with us, or against us...and it seems to be working.
Missing Iranian General Story Deepens
Iran’s dep. defense minister for eight years up until 2005 - and before that a prominent Revolutionary Guards General, Ali Reza Asquari, 63, has not been seen since his disappearance in mysterious circumstances in Istanbul on Feb. 7.
The missing general has been identified as the officer in charge of Iranian undercover operations in central Iraq, according to DEBKAfile’s intelligence and Iranian sources. He is believed to have been linked to – or participated in - the armed group which stormed the US-Iraqi command center in Karbala south of Baghdad Jan. 20 and snatched five American officers. They were shot outside the Shiite city.
An Middle East intelligence source told DEBKAfile that the Americans could not let this premeditated outrage go unanswered and had been hunting the Iranian general ever since.
------------------------------------------
Possible Slant Indicator
*DEBKAfile is an Israeli, Jerusalem-based English language open source intelligence website .
It began in the summer of 2000, and has since received Forbes' Best of The Web award. Forbes identifies the best part of the website as its archives, but decries the fact that "most of the information is attributed to unidentified sources."
ASUS Website Hands Out ANI Exploits
We've just confirmed multiple reports about asus.com, a very well known hardware manufacturer, being compromised. There's an iframe added which leads to the recent ANI exploit.
The URLs in the exploit variants which we've detected are currently down.
We're trying to get in touch with ASUS. This latest case shows that you can get infected when visiting legitimate sites, so you should always install patches as soon as you can.
New Class of Attack Targets Embedded Devices
A security researcher at Juniper Networks says he plans to demonstrate a new class of attack that can be used to compromise electronic devices like routers or mobile phones.
The vulnerability lies in the ARM and XScale microprocessors, two chips that are widely used in these "embedded" devices. "There are interesting quirks in the ARM and XScale architectures that make things very easy for an attacker," said Juniper's Barnaby Jack. The technique he has developed is "100 percent reliable, and it results in code execution on the device," he said.
An attacker could launch this type of attack to run unauthorized software on a device connected to the network. In theory, criminals could use this kind of attack to steal sensitive information from mobile phones or redirect Internet traffic on routers, say from a user's online bank account to a hacker site set up to steal account and password information.
It's an alternative to hacker techniques like buffer overflow attacks, which attempt to trick the processor into running code that is snuck into the computer's memory.
Jack plans to disclose details on this attack -- and the things that device makers can do to avoid it -- at the CanSecWest security conference being held later this month in Vancouver.
He said he came up with the technique after spending several months cracking open and soldering test equipment onto a range of embedded devices. By taking advantage of a standard integrated circuit testing interface, called JTAG (Joint Test Action Group) Jack was able to sneak a peek at the systems' processors and get a close-up look at how they worked.
"With every hardware device, there has to be a way for developers to debug the code and all I did was take advantage of that," he said. "As I was digging deeper into the architecture, I saw a couple of subtleties which could allow for some interesting things.
JTAG is widely used because it gives engineers a way to debug software on embedded systems, but it presents a security risk as well, said Peter Glaskowsky, an analyst with the Envisioneering Group.
Though some companies are able to cut off the JTAG interface on their products, Jack said it was enabled in 90 percent of the devices he examined.
"It's definitely an issue," Glaskowsky said. "Some chips won't turn it off because they want it for later diagnostics if there's a problem with them"
Often, it's simply too expensive for hardware makers to shut down JTAG access, said Joe Grand, a hardware hacker who is president of Grand Idea Studio Inc., an electronics design firm.
Though there hasn't yet been a large amount of research into the kind of hands on hacking techniques being pioneered by people like Jack and Grand, though it appears that is set to change.
The tools and devices required to hack embedded systems are becoming less expensive and hardware hacking is developing a cachet in the security research community, Grand said. He will offer hardware hacking workshops at this year's Black Hat USA conference.
"It's exciting for the hacking community to say, 'I'm sick of software. Let's look at the hardware,'" he said.
Barnaby Jack has no plans to slow down his work.
"I'm looking at my microwave oven right now, but I don't think there's much I could do with that," he said.
Thursday, April 5, 2007
Discovery of Biological Agents in Moroccan Hideout
[After the March 11 suicide bombing in a cybercafe in Casablanca and the multiple arrests, here is what was found at the bombers’ place]
The most worrying finding of Moroccan authorities is the discovery of chemicals that could have been used for large-scale terror attacks. A microbial stock of “pathogenic Tetanus” cultivated by the terrorists was found in their hideout. This agent could cause death within 24 hours if person not inoculated with anti tetanus serum.
Three Charged with Aiding London Transit Bombers
LONDON — Britain charged three men Thursday with aiding the four bombers responsible for the July 7, 2005, attacks on London's transit system that killed 52 passengers.
The charges were the first related to the deadliest attack on London since World War II.
Peter Clarke, head of the Metropolitan Police's counterterrorism unit, said more arrests were likely.
"The search is not over," Clarke said. He said it was "only a matter of time" before police bring to justice everyone involved.
The three suspects — Mohammed Shakil, 30; Waheed Ali, 23; and Sadeer Saleem, 26 — were charged with conspiracy to cause explosions on transport or at tourist attractions that could endanger life or cause serious harm.
Humor: In the Heat of Hai-Karate
We were talking about Gmail Paper and other great April Fool's joke this year....when he said the following......
Here check this video out so that you might understand a little bit better the "f**king eliteness that I am all about."
As you can see, he is pretty humble...
Microsoft .NET Request Filtering Bypass Vulnerability
By understanding how ASP .NET malicious request filtering functions, ProCheckUp has found that it is possible to bypass ASP .NET request filtering and perform XSS and HTML injection attacks.
It was possible to perform redirect, cookie theft, and unrestricted HTML injection attacks against an ASP .NET application setup in a test environment. ProCheckUp has also found this issue to be exploitable while carrying out penetration tests on several customer's live environments.
--------------------------Check the link above for PoCs.
Bluetooth Remote Controlled Saab Coupe
Or, it is fake.
Here is the original article on the bluetooth controlled car. I don't speak Czech, but using some less-than-exact translation software, it sounds like they are using hydraulic & servo-motors to control the car's mechanical parts [perhaps in the engine bay].
They also make it very clear in the article that driving a car without a driver is totally illegal. Remember that kids...
This method would be easier than the custom computer interface module stuff anyways.
Just FYI, but the car is a Saab 9-3 2.0T Coupe w/ 150 brake horsepower (bhp).
----------------------
UPDATE - This is most likely an April Fool's joke..sadly. Thanks for the catch Steven.
Wednesday, April 4, 2007
French Scientist Held in Iran
Paris--On the day the Iranian government defused an international crisis by releasing 15 British sailors held captive since 23 March, a French newspaper revealed that Iran has also prevented a French scientist from leaving the country for more than 2 months. Sociologist Stéphane Dudoignon, of the National Centre for Scientific Research (CNRS) in Paris, was arrested on 30 January after taking photos of a religious procession in southeastern Iran. He was later released, but he has not received his passport and other documents and is stuck in Tehran.
The French Ministry of Foreign Affairs had kept Dudoignon's detention under wraps, but confirmed it after it was reported today by the newspaper Le Monde. The French government says it has asked Iran to release Dudoignon, who also teaches at the Graduate School for Social Sciences Studies in Paris.
According to the newspaper, Dudoignon was working in Sistan-Baluchestan, a province bordering Afghanistan and Pakistan that's home to a sizable Sunni minority and the scene of recent unrest and violence against Iran's central government. A bomb blast in the provincial capital of Zahedan in February killed 11 members of Iran's Islamic Revolutionary Guards Corps.
Yann Richard, a researcher at the Institute for Iranian Studies at the Université de Sorbonne Nouvelle in Paris, says Dudoignon told him that he was captured in an area harboring sensitive military installations that weren't on his maps. "Perhaps he shouldn't have been there, but he acted in good faith," Richard says. He says the Iranian government appears not to have charged Dudoignon with anything and believes it will release him eventually.
Thailand Blocks YouTube Over Insults to the King
Sitthichai Pookaiyaudom, the country's minister of information and technology, said YouTube had turned down his request to remove the contentious 44-second video, which shows graffitti-like elements painted over a slideshow of photographs of 79-year-old King Bhumibol Adulyadej.
One part of the clip juxtaposes pictures of feet over the king's image - a major taboo in a culture where feet are considered extremely dirty and offensive. The soundtrack is the Thai national anthem. "We are disappointed that YouTube has been blocked in Thailand, and we are currently looking into the matter," Julie Supan, a spokeswoman for Google Inc.'s YouTube, said in an e-mail.
According to Sitthichai, thousands of people have called the government to complain about the YouTube video. Sitthichai said Thailand's military-installed government also has blocked other sites deemed insulting to the king.
"People who create these (Web sites) are abusing their rights and clearly don't mean well for the country," Sitthichai said. "We have closed many and will continue to."
Thailand has no comprehensive law governing the Internet, and limits governing use and censorship are not clearly defined.
It's not entirely clear how the government was implementing the block. Domestic service providers are generally given lists of sites to block, but the control may be occurring at the government-owned gateways through which all Internet service providers are supposed to funnel data entering and leaving the country.
Blocking YouTube, of course, won't prevent someone from e-mailing the video or posting it on a Web site that is less popular and thus less noticed by the government. But any hurdles, even if they aren't foolproof, are likely to accomplish the government's goals, said Jonathan Zittrain, a professor of Internet governance and regulation at Oxford University.
"A lot of the time, the viral spread happens because it's just one click away," Zittrain said. "If you make something not one click away anymore, you can slow it down a little bit."
The U.S. Census Bureau Gave Up Names of Japanese-Americans in WW II
Despite decades of denials, government records confirm that the U.S. Census Bureau provided the U.S. Secret Service with names and addresses of Japanese-Americans during World War II.
The Census Bureau surveys the population every decade with detailed questionnaires but is barred by law from revealing data that could be linked to specific individuals. The Second War Powers Act of 1942 temporarily repealed that protection to assist in the roundup of Japanese-Americans for imprisonment in internment camps in California and six other states during the war. The Bureau previously has acknowledged that it provided neighborhood information on Japanese-Americans for that purpose, but it has maintained that it never provided "microdata," meaning names and specific information about them, to other agencies.
Influenza B Grows More Resistant to Drugs
Shuji Hatakeyama, M.D., Ph.D., of the University of Tokyo, Japan, and colleagues examined the prevalence and transmissibility of influenza B viruses with reduced sensitivity to neuraminidase inhibitors in Japan, where zanamivir and oseltamivir are now used more extensively than anywhere else in the world. In the winter of 2004-2005, an influenza B virus caused a widespread epidemic in Japan, creating an opportunity to assess the effectiveness of neuraminidase inhibitors. The researchers collected influenza B isolates from 74 children before and after oseltamivir therapy and from 348 untreated patients with influenza (including 66 adults). Four hundred twenty-two viruses from untreated patients and 74 samples from patients after oseltamivir therapy were analyzed.
The researchers identified a variant with reduced drug sensitivity in one (1.4 percent) of the 74 children who had received oseltamivir, and seven (1.7 percent) of the 422 influenza B viruses isolated from untreated patients were found to have reduced sensitivity to zanamivir, oseltamivir, or both. Review of the clinical and viral genetic information available on these seven patients indicated that four were likely infected in a community setting, while the remaining three were probably infected through contact with siblings shedding the mutant viruses.
Russian Court Convicts Officer of Spying
MOSCOW - A Russian military court convicted a reserve officer of treason Friday for spying for an unidentified European country and sentenced him to 12 years in prison.
The Moscow District Military Court found Valentin Shabaturov was recruited by and worked actively with a foreign intelligence service in 1999-2006, damaging national security by revealing state secrets, court spokesman Alexander Minchanovsky said.
The court said Shabaturov received a total of about $68,000 for information he handed over, the spokesman said.
Shabaturov was convicted of treason and sentenced to 12 years in a high-security prison, the shortest possible sentence because he acknowledged his guilt and cooperated with prosecutors, Minchanovsky said. He was also stripped of his medals and rank of colonel.
Russian authorities did not identify the European country involved, and Russian news agencies said the trial — which was not publicized — was closed until the announcement of the sentence because state secrets were involved.
Amid persistent distrust between Russia and the West, Russian security officials have repeatedly said foreign spies are active in Russia and often claim success in thwarting their efforts. American officials say, too, that Russian espionage activities are up in the U.S.
Russia's prosecutions of espionage charges have increased since the 2000 election of President Vladimir Putin, a former colonel in the Soviet Union's KGB secret police and one-time head of its main Russian successor, the Federal Security Service.
Shabaturov's conviction could have brought a maximum punishment of 20 years in prison, and Russian news agencies said prosecutors requested 14 years. Defense lawyer Oleg Avdeyev said he planned an appeal to the military branch of the Supreme Court, the RIA-Novosti news agency said.
CIA Chief Reports DPRK is Not a Nuclear Power
SEOUL (AFP) - Central Intelligence Agency director Michael Hayden has said the United States does not recognise North Korea as a nuclear power because its first atomic test last October was a failure, a report said Wednesday.
The US position was made clear when Hayden met South Korean Defence Minister Kim Jang-Soo on Tuesday, the JoongAng Ilbo newspaper said.
"The United States does not recognise North Korea as a nuclear power, because its nuclear test last year was a failure," Hayden was quoted by a South Korean defence source as telling Kim.
The source also said Hayden stressed the importance of exchanging intelligence on North Korea between Seoul and Washington.
"The United States has a large amount of intelligence on North Korea and South Korea has many experts who understand well North Korean sentiments and culture," Hayden was quoted as saying.
"US-South Korean intelligence exchange is crucial to analyse North Korea's decisions."
Russia Spy Agencies Building Up HUMINT in the US
WASHINGTON - Russia has fully restored its espionage capabilities against the United States after a period of decline following the Cold War, a senior U.S. counterintelligence official said Thursday.
Joel Brenner, the head of the Office of the National Counterintelligence Executive, said the United States is concerned that Russia is continuing to ramp up its operations.
"The Russians are now back at Cold War levels in their efforts against the United States," he said at an event held by the American Bar Association. "They are sending over an increasing and troubling number of intelligence agents."
The comments come at a time of greater tension between the two countries, as Russian officials have expressed frustration at what they see as U.S. foreign policy unrestrained by consultation with other world powers, including Russia. They have criticized the expansion of NATO into the former Soviet sphere of influence and U.S. plans to install radar and interceptors in Eastern Europe as part of a missile defense program.
In turn, U.S. officials have warned that Russia's increased assertiveness in challenging U.S. policy is complicating cooperation on important foreign-policy goals including counterterrorism, nuclear nonproliferation and democracy promotion in the Middle East.
Linden Lab Turns Blind Eye to Second Life Casinos
NEW YORK (Reuters) -- FBI investigators have visited Second Life's Internet casinos at the invitation of the virtual world's creator Linden Lab, but the U.S. government has not decided on the legality of virtual gambling.
"We have invited the FBI several times to take a look around in Second Life and raise any concerns they would like, and we know of at least one instance that federal agents did look around in a virtual casino," said Ginsu Yoon, until recently Linden Lab's general counsel and currently vice president for business affairs.
Second Life is a popular online virtual world with millions of registered users and its own economy and currency, known as the Linden dollar, which can be exchanged for U.S. dollars.
Yoon said the company was seeking guidance on virtual gaming activity in Second Life but had not yet received clear rules from U.S. authorities.
The FBI and the U.S. Attorney's Office for Northern California declined comment.
Hundreds of casinos offering poker, slot machines and blackjack can easily be found in Second Life. While it is difficult to estimate the total size of the gambling economy in Second Life, the three largest poker casinos are earning profits of a modest $1,500 each per month, according to casino owners and people familiar with the industry.
The surge in Second Life gambling coincides with a crackdown in the real world by the U.S. government, which has arrested executives from offshore gambling Web sites.
Most lawyers agree that placing bets with Linden dollars likely violates U.S. anti-gambling statutes, which cover circumstances in which "something of value" is wagered. But the degree of Linden Lab's responsibility, and the likelihood of a any crackdown, is uncertain.
...
"If you're buying money on the Lindex (a virtual currency exchange) and utilizing it for gambling purposes, Linden could have a much higher level of responsibility," he added. "If they would be found in violation, that's difficult to say, but I can see a much stronger case being made."
Linden Lab's rules prohibit illegal activity.
"It's not always clear to us whether a 3-D simulation of a casino is the same thing as a casino, legally speaking, and it's not clear to the law enforcement authorities we have asked," Yoon said.
Even if the law were clear, he said the company would have no way to monitor or prevent gambling in Second Life.
------------------------------------------
Sounds like Linden Lab needs to step up, take responsibility for what they have created. The rules do apply for this virtual world.In the future, If some vendor sold me sometime on SL and decided to screw me, then I damn well better be able to use the law to get my stuff.
Linden Lab should get that army of Agent Smiths ready....because they will need them if they plan on sticking around.
Breaking 104-Bit WEP in Under One Minute
We were able to extend Klein's attack and optimize it for usage against WEP. Using our version, it is possible to recover a 104 bit WEP key with probability 50% using just 40,000 captured packets. For 60,000 available data packets, the success probability is about 80% and for 85,000 data packets about 95%. Using active techniques like deauth and ARP re-injection, 40,000 packets can be captured in less than one minute under good condition. The actual computation takes about 3 seconds and 3 MB main memory on a Pentium-M 1.7 GHz and can additionally be optimized for devices with slower CPUs. The same attack can be used for 40 bit keys too with an even higher success probability.
http://www.cdc.informatik.tu-darmstadt.de/aircrack-ptw/
Erik Tews, Andrei Pychkine and Ralf-Philipp Weinmann are cryptographic researchers at the cryptography and computer algebra group at the technical university Darmstadt in Germany. Head of the group is Prof. Dr. Dr. Johannes Buchmann.
Iran to Release British Soldiers
------------------------------------
As I said on March 30th, Iran is just repeating itself.....and most likely got what it wanted. They put the soldiers on TV and did the pony show for the people...attempt to make the British look bad in the world view, but in the end...they look like heroes at home.
Tools of the Trade - En Passant Explained
On to the tools...
1) On March 29th, Paint.NET v3.05 was released. Paint.NET is free image editing and photo manipulation software designed to be used on computers that run Windows. It supports layers, unlimited undo, special effects, and a wide variety of useful and powerful tools. Check the download page for the latest changes.
2) On March 27th, The Metasploit team released Metasploit Framework v3.0.
Metasploit 3 is a from-scratch rewrite of Metasploit 2 using the Ruby scripting language. The development process took nearly two years to complete and resulted in over 100 000 lines of Ruby code. See details on the new features on the Metasploit blog.
3) On March 23th, THC released Hydra v5.4.
THC-Hydra - the best parallized login hacker: for Samba, FTP, POP3, IMAP, Telnet, HTTP Auth, LDAP, NNTP, MySQL, VNC, ICQ, Socks5, PCNFS, Cisco and more. Includes SSL support and is part of Nessus. Changes in 5.4: Several speed improvements, bug fixes and a few enhancements!
4) On March 24th, Tim Brown released Fuzzled v1.0.
Fuzzled is a powerful fuzzing framework for Perl programs. Fuzzled includes helper functions, namespaces, and factories which allow a wide variety of fuzzing tools to be developed. Fuzzled comes with several example protocols and drivers for them. I wonder if Tim knows what "Fuzzled" means...
5) On March 21st, Insecure.org released Nmap v4.21 Alpaha 4. See the change log for all the details.
6) On March 20th, Tenable Tenable released Nessus v3.1.3 beta has been released for the Linux, FreeBSD and Solaris operating systems. See the Tenable blog for the major changes.
7) Java has released several JRE updates as well.
Java JRE 6 Update 1 (ReleaseNotes) & Java JRE 5.0 Update 11 (ReleaseNotes)
Tuesday, April 3, 2007
Microsoft ANI Vulnerability Update
April 03, 2007 (Computerworld) -- Contrary to other reports, Mozilla Corp.'s Firefox 2.0 is vulnerable to attackers armed with the Windows animated (ANI) cursor exploit, a researcher said today.
Alexander Sotirov, the vulnerability researcher at Determina Inc. who discovered the ANI flaw last December and notified Microsoft Corp. of it later that month, yesterday posted a demonstration of an ANI exploit that hijacks a PC when Firefox users are conned into visiting a malicious site (see video).
"It turns out that Firefox uses the same vulnerable Windows component to process .ani files, which can be exploited in a way similar to Internet Explorer," Sotirov said during the demo.
--------------------------------------
Check out this ANI exploit other video by Muts (from the BackTrack team). He demos using BackTrack w/ the MSF SMTP exploit against a user...very slick.
In exploit news, Yag Kohha released a universal ANI exploit generator tool.
Microsoft has taken the threat pretty serious and released MS07-017 out of band. It is important to note that MS07- 017 fixes seven issues and not just the ANI vulnerability. There are some reports of this patch causing issues, so make sure you test it before deploying it in the enterprise.
Those that know more about this than me, tell me that the MS patch should fix the vulnerability for Firefox as well, since they are both using the same code in a round around way.
HD Moore has released two ANI exploits for MSF3.
Monday, April 2, 2007
JavaScript Hijacking Vulnerability
Fortify Software’s Web 2.0 Advisory (PDF)
Egypt Blogs Show Alleging Ballot Stuffing Footage
CAIRO (Reuters) - Egyptian blogs have published amateur video footage purporting to show ballot stuffing and vote fraud in a nationwide referendum on constitutional amendments which opposition groups say was rigged.
Egypt says it won 76 percent approval in Monday's vote for the amendments, which give the state powerful tools that could be used to drive opposition Islamists from politics. Rights groups say the changes are a step backward for freedom.
A handful of video clips, most of which appear to be taken by mobile phone cameras and circulated on Egyptian blogs and Web sites, contain some of the first images of alleged fraud in the vote and could reinforce the accusations of vote fixing.
Egypt says turnout in the referendum was 27 percent. But all main opposition groups boycotted the vote and rights groups said the real turnout was much lower. The independent Egyptian Organisation for Human Rights estimated that just 5 percent of registered voters took part.
In one of three clips viewed by Reuters, a man purported to be an election official in the Nile Delta appears to mark names on a voter list, then folds a pile of ballots and stuffs them into a transparent vote box. A close-up of one of the ballots shows it is marked with a "Yes" vote.
Another grainy video shows a man marking piles of blank ballots with "Yes" votes. In a third clip, which appears to be taken from a distance with a zoom lens, workers at a school are seen shuffling through ballots and folding them, while another person collects them and takes them out of sight of the camera.
"The overwhelming amount of evidence points in the direction of fraud. I doubt anyone needed to doctor or make up evidence," said Ghada Shahbender of the civil monitoring group Shayfeencom, which means "We are Watching You" in Arabic.
"At least some of them are valid. Some of them are very simple. They are not doctored. They are not edited," she added.
Justice Ministry officials declined immediate comment.
Three Tonnes of Explosives Found in Egypt
Egyptian authorities found three tonnes of explosives in the northern part of the Sinai Peninsula, a security source said on Saturday.
"The TNT explosives were found in a warehouse hidden under agricultural land in the Al-Towayel area," the source said, adding that they were hunting those involved in the cache.
The explosives could belong to disgruntled local Bedouin tribes who are suspected of being behind a number of terrorist attacks against Red Sea tourist resorts in southern Sinai over the last three years.
On February 23, Egyptian security forces discovered a tonne of explosives near the border with Israel, while on February 4, arms caches containing rockets and grenades were discovered.
Israel has long complained that Egypt is not doing enough to stem the flow of weapons and explosives into the Palestinian territories, though there have been announcements nearly every month of caches being discovered.
Jikto in the Wild
It appears that the source code to Jikto is in the wild. I suppose it was only a matter of time, even though as you will see SPI to extreme steps to prevent this from happening.
As my Shmoocon presentation slides discuss, Jikto bypasses the "Same Origin Policy" by using a proxy website like the-cloak, proxydrop, Google Translate, etc. This allows Jikto's code and the content of 3rd party sites to be loaded into the same security domain (ie the proxy sites), and thus read the responses. I believe pdp of GNUCITIZEN first discussed this and I based much of Jikto off his work. The consequence of this means that Jikto's code had to exist somewhere on the public Internet when I did my demo. Worse, when I got to Shmoo I saw that I didn't have a hard connection to the Internet, only wireless. This means anyone in the audience sniffing traffic would see where Jikto was and get a copy. Obviously I couldn't let that happen.
Instead I VPNed into SPI. This created an encrypted tunnel. I then remotely connected to my Desktop machine at work and did the demo from there. This means no one in the audience could sniff traffic and see where Jikto was stored. The problem is if someone watched very closely they could see the URL of where Jikto's code was. I ran all my traffic on the work machine through a proxy to show all the requests Jikto was making. The first request would have been to grab Jikto's code. Someone could have seen the URL and grabbed it.
Which is exactly what happened! A guy named LogicX grabbed a copy this way and posted it on Digg just a day after Shmoocon. However I contacted LogicX and asked him to take it down. I'm thankful he did. However, it seems someone else grabbed either his copy before it was removed or grabbed the code themselves at Shmoocon just like LogicX did.
The long and short of all of this is Jikto's code is in the wild. Regardless what you might have heard, SPI didn't leak it. Even LogicX admitted he snatched it because he got lucky. I suppose it was only a matter of time.
US Nuclear Security Agency Missing 20 PCs
Twenty desktop computers are missing from the US government department responsible for safeguarding technical secrets about nuclear weapons.
According to a recent audit by the Energy Department inspector general, 14 of the PCs were used to process classified information. The audit also found the department was using computers not listed in its inventory and one listed as "destroyed", the New York Times reports.
The National Nuclear Security Agency (NNSA) has a dismal record for keeping track of its PCs. The audit is the 13th time in four years that the agency has failed a PC inventory audit. "Problems with the control and accountability of desktop and laptop computers have plagued the department for a number of years," the report notes.the NNSA's record would be considered poor for a low security environment, suchas a college, say - but it beggars belief for an agency charged with monitoring and countering efforts to steal bomb information.
Craig Stevens, a spokesman for the department, said Energy Secretary Samuel Bodman "recognizes that we need to manage this place better".
Windows ANI Stack Overflow - Update
http://www.securityfocus.com/archive/1/464345/30/0/threaded
Also, Microsoft is planning an out-of-band patch for release tomorrow.
http://www.microsoft.com/technet/security/bulletin/advance.mspx
Heap Feng Shui in JavaScript
Heap Feng Shui is the ancient art of arranging heap blocks in order toredirectthe program control flow to the shellcode.
I just published the slidesfrom myBlackHat Europe presentation about a JavaScript implementation of this technique.
http://www.determina.com/security.research/presentations/
This work is an evolution of the heap spraying technique, but it allowspreciseapplication data overwrites and reliable browser exploitation. It will be ofgreat interest to everybody working on client side exploitation.The materials include slides, a paper and source code of a JavaScript heapmanipulation library.
Sunday, April 1, 2007
Busting the Bluetooth Myth - Getting Raw Access
This paper is the result of my research into this area, answering the question whether it is
possible or not.
Introducing Gmail Paper

Everyone loves Gmail. But not everyone loves email, or the digital era. What ever happened to stamps, filing cabinets, and the mailman? Well, you asked for it, and it’s here. We’re bringing it back.
A New Button
Now in Gmail, you can request a physical copy of any message with the click of a button, and we'll send it to you in the mail.
Simplicity Squared
Google will print all messages instantly and prepare them for delivery. Allow 2-4 business days for a parcel to arrive via post.
Total Control
A stack of Gmail Paper arrives in a box at your doorstep, and it’s yours to keep forever. You can read it, sort it, search it, touch it. Or even move it to the trash—the real trash. (Recycling is encouraged.)
Keep it Secret, Keep it Safe
Google takes privacy very seriously. But once your email is physically in your hands, it's as secure as you want to make it.
The Month of Myspace Bugs - No Joke Suckers
Here's our first MOMBY advisory. Note, it's a pretty light one, seeing how today is Sunday, and we don't really expect the crack MySpace Security Squad to actually do a lot of code changes on Sunday. So, we went with one they probably don't care about, and isn't terribly dangerous on its own. Hope you like it.
---------------------------------------
If you have been around on Myspace in the last week or so...you may have noticed parts of it were "under maintenance" / "being worked on" all over the place.
I wonder why?
Word on the street is that they have been rushing to fix issues that were reported...in advance of MOMBY.
So even if you think MOMBY is stupid (which is partly the point), then at least you can give a golf clap to the guys behind it....anything that makes Myspace fix their crappy code is a plus in my book.
Also, I recently heard from a reliable source that a video of the two masterminds behind the project will surface soon from one of the most unlikely of sources......that is all I can say.
Let the fun keep rolling...
Moral of the Story - Don't Hate, Congratulate!
Music Labels Move to Kill Internet Radio
While successful webcasters which have built loyal audiences can usually cover most of their costs from their revenue (and sometimes even make a little profit), these new rates will almost certainly destroy the Internet radio industry, as they amount to well over 100% of even the most-successful webcasters' online radio revenues. In other words, these fees are grotesquely disproportionate to any other expense a webcaster would normally face, and certain to bankrupt him or her.
Help us keep Internet radio from being shut down
http://www.savethestreams.org/serendipity/
-------------------------------------
Check out this Washington Post article to see what the large & small internet radio groups are doing about it...