Wednesday, March 21, 2007

Researchers Track Down a Plague of Fake Web Pages

Via NewYorkTimes.com -

Tens of thousands of junk Web pages, created only to lure search-engine users to advertisements, are proliferating like billboards strung along freeways. Now Microsoft

researchers say they have traced the companies and techniques behind them.

A technical paper published by the researchers says the links promoting such pages are generated by a small group of shadowy operators apparently with the acquiescence of some major advertisers, Web page hosts and advertising syndicators. The report is available at www.cs.ucdavis.edu/~hchen/paper/www07.pdf

The finding is striking because it hints at the possibility of curbing the practice.

Turkish Defacer Strikes Again

The Turkish defacer, aLpTurkTegin, is at it again...it would appear that he has hacked over 500 sites within the last couple of days. See all the new defacements over at Zone-H.

Looks like aLpTurkTegin isn't happy with his current spot of 7th.

Gozi Trojan Discovered Under The Radar

Via SecurityFocus -

Security firm SecureWorks announced on Tuesday that the firm had uncovered a previously unknown Trojan horse and its associated data cache, both which showed the increasing sophistication among data thieves.

The program, which the company dubbed "Gozi," evaded discovery by security firms for almost a month, records the user names and passwords of online accounts, bypasses secure sockets layer (SSL) encryption, and uses a central server that also acts a point-of-sale to underground data thieves. The SecureWorks researcher found nearly 10,000 account credentials belonging to 5,200 victims, including government employees, on the server. Account credentials for more than 30 banks and credit unions were on the central server.

"SecureWorks had contacted several of the companies affected and is working through various other channels, including law enforcement, to notify the remaining affected parties," Don Jackson, a security researcher for SecureWorks, stated in his analysis of the Trojan horse.

Firefox 3 to Support HttpOnly Cookies

Via Securiteam Blog -

HttpOnly cookies are a mechanism Microsoft developed for IE6 SP1 to add some security to cookies. The web developer would set a cookie (for instance the session cookie) to be HttpOnly (both ASP and PHP support setting HttpOnly cookies) and the browser would only ever use that cookie when sending HTTP requests, not when client side scripting asks to read the cookie. This means if there was a cross site scripting flaw on the website the JS wouldn’t be able to use the cookies. The solution isn’t perfect, but it does what it’s meant to do and doesn’t harm anyone.

Support for this is already in the Firefox 3 alphas, if you are inclined to use them, otherwise you’ll have to wait until November or so for the first official ff3 release.

If you are a web developer I suggest you start updating your code to use HttpOnly where applicable.

---------------------------------------------

Microsoft MSDN - Mitigating Cross-site Scripting With HTTP-only Cookies

I guess it is only a matter of time before Opera supports them as well....

BMW Dealership in California Requiring Thumbprints

Via SunBelt Blog -

Wow, this reeks to high heaven. There’s lots of BMW dealerships out there in Southern California. Go to one which does not have an absurd policy of demanding a thumbprint in order to buy a car (like this South Bay BMW and Mini outfit). The dealership is apparently owned by Hitchcock Automotive Resources — ironically, the subject of a Cisco White Paper.

DoD Looks to the Mind for Better Design

Via Wired.com -

The U.S. military is working on computers than can scan your mind and adapt to what you're thinking.

Since 2000, Darpa, the Pentagon's blue-sky research arm, has spearheaded a far-flung, nearly $70 million effort to build prototype cockpits, missile control stations and infantry trainers that can sense what's occupying their operators' attention, and adjust how they present information, accordingly. Similar technologies are being employed to help intelligence analysts find targets easier by tapping their unconscious reactions. It's all part of a broader Darpa effort to radically boost the performance of American troops.

"Computers today, you have to learn how they work," says Navy Commander Dylan Schmorrow, who served as Darpa's first program manager for this Augmented Cognition project. He now works for the Office of Naval Research. "We want the computer to learn you, adapt to you."

So much of what's done today in the military involves staring at a computer screen -- parsing an intelligence report, keeping track of fellow soldiers, flying a drone airplane -- that it can quickly lead to information overload. Schmorrow and other Augmented Cognition (AugCog) researchers think they can overcome this, though.

The idea -- to grossly over-simplify -- is that people have more than one kind of working memory, and more than one kind of attention; there are separate slots in the mind for things written, things heard and things seen. By monitoring how taxed those areas of the brain are, it should be possible to change a computer's display, to compensate. If a person's getting too much visual information, send him a text alert. If that person is reading too much at once, present some of the data visually -- in a chart or map.

At Boeing Phantom Works, researchers are using AugCog technologies to design tomorrow's cockpits. The military expects its pilots to someday control entire squads of armed robotic planes. But supervising all those drones may be too much for one human mind to handle unassisted.

Boeing's prototype controller uses an fMRI to check just how overloaded a pilot's visual and verbal memories are. Then the system adjusts its interface -- popping the most important radar images up on the middle of the screen, suggesting what targets should be hit next and, eventually, taking over for the human entirely, once his brain becomes completely overwhelmed.

South Korean Intelligence Wire Tapping Increases

Via DailyIndia.com -

SEOUL, March 21 (UPI) -- The number of wiretaps done by the South Korean National Intelligence Service went up last year while those carried out by other government agencies dropped.

There were 8,440 interceptions of telephones and e-mail by the NIS in 2006, up 4.4 percent from 8,082 in 2005, the Ministry of Information and Communications reported.


Choi Young-hae of the information ministry suggested that the reason for the large number of NIS wiretaps was the investigation of two North Korean spy rings, the Korea Times reported.

There were sharp drops in the much smaller amount of wiretapping done by other law enforcement agencies. The prosecution service carried out 43 wiretaps, down from 100 in 2005, while police wiretaps dropped 46 percent to 131 and those by military investigators dropped 54 percent to 51.

Iran to Hit Back at US ‘Kidnaps'

Via Intelligence Summit -

IRAN is threatening to retaliate in Europe for what it claims is a daring undercover operation by western intelligence services to kidnap senior officers in its Revolutionary Guard.

According to Iranian sources, several officers have been abducted in the past three months and the United States has drawn up a list of other targets to be seized with the aim of destabilising Tehran’s military command.

In an article in Subhi Sadek, the Revolutionary Guard’s weekly paper, Reza Faker, a writer believed to have close links to President Mahmoud Ahmadinejad, warned that Iran would strike back.

“We’ve got the ability to capture a nice bunch of blue-eyed blond-haired officers and feed them to our fighting cocks,” he said. “Iran has enough people who can reach the heart of Europe and kidnap Americans and Israelis.”

The first sign of a possible campaign against high-ranking Iranian officers emerged earlier this month with the discovery that Ali Reza Asgari, former commander of the Revolutionary Guard’s elite Quds Force in Lebanon and deputy defence minister, had vanished, apparently during a trip to Istanbul.

Asgari’s disappearance shocked the Iranian regime as he is believed to possess some of its most closely guarded secrets. The Quds Force is responsible for operations outside Iran.

Last week it was revealed that Colonel Amir Muhammed Shirazi, another high-ranking Revolutionary Guard officer, had disappeared, probably in Iraq.

A third Iranian general is also understood to be missing — the head of the Revolutionary Guard in the Persian Gulf. Sources named him as Brigadier General Muhammed Soltani, but his identity could not be confirmed.“

This is no longer a coincidence, but rather an orchestrated operation to shake the higher echelons of the Revolutionary Guard,” said an Israeli source.

Other members of the Quds Force are said to have been seized in Irbil, in the Kurdish area of northern Iraq, by US special forces.“

The capture of Quds members in Irbil was essential for our understanding of Iranian activity in Iraq,” said an American official with knowledge of the operation.

One theory circulating in Israel is that a US taskforce known as the Iran Syria Policy and Operations Group (ISOG) is coordinating the campaign to take Revolutionary Guard commanders.

The Iranians have also accused the United States of being behind an attack on Revolutionary Guards in Iran last month in which at least 17 were killed.

Military analysts believe that Iranian threats of retaliation are credible. Tehran is notorious for settling scores. When the Israelis killed Abbas Mussawi, Hezbollah’s general secretary, in 1992 the Quds Force blew up the Israeli embassy in Argentina in revenge.

Despite the Iranian threat to retaliate in Europe, Iraq is seen by some analysts as a more likely place in which to attempt abductions.“

In Iraq, the Quds Force can easily get hold of American — and British — officers,” said a Jordanian intelligence source.

Tuesday, March 20, 2007

Winter Music Conference 2007

WMC 2007
March 20 - 25, 2007
Miami Beach Resort & Spa

Winter Music Conference, in its 22nd year, is regarded as the singular networking event in the dance music industry, attracting professionals from over 60 different countries. With its high concentration of top international artists, DJs and industry professionals, WMC permeates the international press and is thereby one of the most publicized events in the business. Every aspect of the industry is represented including the top technological innovators, artists, DJs, producers, radio and video programmers, retailers, distributors, audio manufacturers and many more. There are countless reasons why people from all over the world return year after year for this event, the most outstanding one being that there is nothing else in the world like it.

Genetically Modified Mosquito Could Fight Malaria

Via BBC News -

A genetically modified (GM) strain of malaria-resistant mosquito has been created that is better able to survive than disease-carrying insects.

It gives new impetus to one strategy for controlling the disease: introduce the GM insects into wild populations in the hope that they will take over.

The insect carries a gene that prevents infection by the malaria parasite.

Details of the work by a US team appear in Proceedings of the National Academy of Sciences journal.

The researchers caution that their studies are still at an early stage, and that it could be 10 years or more before engineered insects are released into the environment.

"What we did was a laboratory, proof-of-principle experiment; we're not anywhere close to releasing them into the wild right now," co-author Dr Jason Rasgon from Johns Hopkins University in Baltimore, Maryland, told BBC News.

The approach exploits the fact that the health of infected mosquitoes is itself compromised by the parasite they spread. Insects that cannot be invaded by the parasite are therefore likely to be fitter and out-compete their disease-carrying counterparts.

DoD Moves Toward Standard Desktop Configs

Via FCW.com -

The Office of Management and Budget will require agencies to move to a standard configuration for Microsoft Windows desktop by Feb.1, 2008.

In a memo that will be signed off on as early as today by OMB Deputy Director for Management Clay Johnson, and supplemented by an e-mail that went out today to CIOs from OMB Administrator for E-government and IT Karen Evans, the White House is expanding the work the Air Force did with Microsoft Corp. governmentwide.

Starting in 2004, the Air Force began shifting more than 525,000 desktop computers to three predetermined configurations. It also preconfigured all software on its computers with security settings specific to Air Force requirements.

The Army also is following the Air Force’s lead and implementing the standard configuration.

The National Institute of Standards and Technology worked with the Air Force and other Defense Department agencies to develop guidance about securing Windows operating systems, including XP and Vista. OMB is making this guidance mandatory in order to improve IT security across the government, experts said.

-------------------------------------------

Standard desktop configurations are a very good thing. They help streamline patch management processes and helpdesk issues.

Microsoft Search Engine More Dangerous Than Google

Via theregister.co.uk -

Everybody knows that Windows Live Search, Microsoft's little search engine that could, lags far behind Google and Yahoo! in the race to capture eyeballs. Here's one place where the software juggernaut's offering leads the pack: referrals for sites that actively try to infect end users' machines with some of the vilest malware known to man.

To see for yourself, type "veicolo commerciale noleggio" into Live.com and watch what gets returned. The first result (at the time of writing, anyway) is for a site at b9n3q3.info/yb6u46p76.html, which uses a Javascript to redirect users to another site. This second site actively tries to install several varieties of malware, in some cases the nasty Trojan known as Rustock. This return is just one of many malicious referrals Live.com makes when entering the above search term, which is Italian for "commercial vehicle rental."

According to researchers at Sunbelt-Software, Live.com's affair with malicious sites runs so torrid that malware-related returns on the search engine number in the thousands. Terms that trigger similar results tend to be Italian phrases, including, to name a few, "adsl offerta toscana," "istituto geografico italiano," "dvd da scaricare" and "testi reggae." Sunbelt blogged here about the sludge fest two weeks ago, but Live.com has continued to spew the noxious results unabated. Google and Yahoo long ago managed to filter most of the same sites from their returns.

"I don't think it was very responsible to keep these malware sites up for so long," says Francesco Benedini, a spyware researcher at Sunbelt. "I'm not saying Google and Yahoo! don't have a problem, but it's much more invasive on Live.com."

Gentleman Thief Takes Dutch Bank for £15m

Via theregister.co.uk -

A "smooth-talking" thief has taken ABN Amro bank in Antwerp for £15m worth of diamonds, making off with 120,000 carats despite using nothing more than chocolates and charm in the audacious blag.

The grey-haired man posed as Argentinian businessman Carlos Hector Flomenbaum, the Daily Telegraph reports. The heist was clearly intelligently planned, since he was able to foil "one of the most sophisticated security systems in the world" without resorting to thermal lances or sawn-off shotguns.

Antwerp's Diamond Council spokesman, Philip Claes, admitted: "He used no violence. He used one weapon - his charm - to gain confidence. He bought chocolates for the personnel, he was a nice guy, he charmed them, got the original of keys to make copies and got information on where the diamonds were."

Police believe the thief had planned the raid for more than a year, and rate it as possibly the biggest single-person theft in history. Accordingly, there's a reward of £1.37m on his head.

FBI Internet Crime Report 2006

The Internet Crime Complaint Center (IC3) is a partnership between the Federal Bureau of Investigation (FBI) and the National White Collar Crime Center (NW3C).

The 2006 statistics don’t represent the universe of Internet crime, since they are based on submitted reports, but they do provide important insights for investigators and a benchmark from year to year. The idea is to help us better understand the threat, so we can better protect you and your families.

IC3 Internet Crime Report 2006 (PDF)

Italian Police Arrest 171 People in Crackdown on Mafia in Naples

Via Pravda.ru -

Italian police on Tuesday arrested 171 people in Naples in a crackdown on organized crime that put entire families behind bars and broke up a lucrative drug trafficking ring, authorities said.

The Naples prosecutors' office said the arrests mainly stemmed from the testimony of a boss-turned-informant who started cooperating with magistrates five years ago.

The morning raids in downtown Naples involved about 1,000 police officers.

The arrests targeted two clans of the Camorra crime syndicate that controlled the drug trafficking ring in and around the southern Italian city for the past decade, authorities said. In some cases couples were accused of selling the drugs with their children.

The crackdown also highlighted the increasing role of women in the Camorra.

"What has emerged is the involvement of many women, some of whom had important duties in controlling the 'piazzas' where the drugs were sold, or were in charge of transporting" the substances, said Col. Gaetano Maruccia of Naples Carabinieri, reports AP.

While female bosses remain rare, investigators have said that women have started taking a more active role in the mob as Mafia men are put behind bars.

Al Qaeda Confessions Make the Case for Immigration & Border Controls

Via CT Blog (by Mike Cutler) -

The wheels of justice sometimes turn slowly but in most instances, inexorably. Finally the terrorist behind the bombing of the USS Cole and other horrific terrorist attacks has confessed to his role in several terrorist attacks. Walid Muhammad bin Attash, also known as Tawfiq bin Attash, has also confessed to having masterminded the nearly simultaneous attacks on the United States embassies at Kenya and Tanzania that resulted in the slaughter of more than 200 people and the wounding of many other victims.

What needs to be considered is that in order to create the wholesale destruction of the embassies and the serious damage to the USS Cole, bin Attash not only needed to obtain explosives, he needed to obtain false travel documents for his operatives in order to facilitate their travel in preparation for the attacks. Bin Attash also stated that he spent a year and a half preparing for the attack and referred to those who participated in the attack has the "cell." He noted that he provided members of the cell with false documents and also came up with stamps (presumably in their passports) and visas to facilitate their international travel. Clearly he, himself, traveled across international borders as he prepared the deadly attacks in which he was in charge. International travel is absolutely an intrinsic component to a terrorist attack. This should be a common-sense concept, but where the open borders advocates are concerned, common sense has been tossed in the trash can, because they do not want to hear anything that would deter or otherwise hamper their grandiose plans to virtually remove our nation's borders.

If our nation's leaders refuse to secure our nation's borders, they cannot protect our nation from international terrorists who would enter our country to attack our country. The effective enforcement and administration of our nation's immigration laws have to be considered a component of national security. The politicians often repeat slogans that they hope will ultimately gain "traction" if they repeat it often enough. A good example of such a phrase is that intelligence can prevent terrorism but that immigration has nothing to do with terrorism! Of course they don't provide a plan for obtaining effective intelligence, it is just that they will look for any supposed solution to protecting our country just as long as it does not involve securing our borders and making certain that the immigration benefits program has meaningful integrity. I can tell you from experience that valuable intelligence is often provided by informants. If you are concerned about terrorists who may have embedded themselves in our country creating a so-called "sleeper cell," then you need to cultivate informants in the United States who can act as the eyes and ears of law enforcement agents who are conducting investigations of terrorists and other criminals. Such informants can be absolutely essential in uncovering terror cells and criminal organizations. The easiest way to cultivate informants is to arrest an individual for violating various laws and offering him (her) and opportunity to avoid prosecution or have potential criminal charges reduced in exchange for the cooperation of this individual. The greater the cooperation and the higher the quality of the information, the greater are the rewards that are offered to the cooperating individual. The use of immigration benefits can also be a very attractive carrot in some situations. In fact, having spent roughly half of my career working closely with other law enforcement agencies, I can tell you from first-hand experience that the immigration component can be absolutely vital in convincing a bad guy to cooperate with law enforcement.

Meanwhile, at present, newly hired special agents at ICE (Immigration and Customs Enforcement) who are being trained at the academy are not getting foreign language training and they are not receiving critical training in the identification of counterfeit, altered or otherwise bogus identity documents! Identity documents and supporting documents such as birth certificates, marriage licenses and other such documents are absolutely vital to the effective enforcement of the immigration laws and the accurate adjudication of applications for a wide variety of immigration benefits.

The Guest Worker Amnesty Program that are so strongly being advocated by President Bush, Senators McCain, Kennedy, Reid, and all of the usual suspects would represent a major gift to terrorists who want to create false identities for themselves to better hide in plain sight and embed themselves in our country as they put together the next terrorist attack.

Month of PHP Bugs: Mid-Month Analysis

Jeff Forristal of SPI Dynamics has a great mid-month analysis of the ongoing MoPB project over at his blog.

Good reading for those interested in PHP Security.

I wonder if I could ask him for another one of those "CYA" shirts.....

Monday, March 19, 2007

FireFox 2.0.0.3 RC1

There are now candidate builds available for 2.0.0.3 and 1.5.0.11 available. Because we had a number of serious regressions that caused this quick release after 2.0.0.2, we would like to get as many people testing these before we push a final release live. Please file bugs on any regressions from 2.0.0.2 and nominate for blocking!

Google Summer of Code (SoC) 2007

Google Summer of Code is a program that offers student developers stipends to write code for various open source projects. Google will be working with a several open source, free software and technology-related groups to identify and fund several projects over a three month period. Historically, the program has brought together over 1,000 students with over 100 open source projects, to create hundreds of thousands of lines of code. The program, which kicked off in 2005, is now in its third year, following on from a very successful 2006.

--------------------------------------

Most of the big name OSS projects take part in SoC.

Nmap, Adium, Gaim, Mozilla Foundation, Fedora Project, etc.

Dark Reading Interview with Joanna Rutkowska

Via Dark Reading -

She hacked the Windows Vista kernel, she administered a Blue Pill to an operating system, and she pioneered rootkit detection research, but Joanna Rutkowska doesn't know how to drive a car.

...

"It's very difficult to pass the driving exam in Poland, and it's not unusual for people to try three or five times in a row," she says.

It's hard to imagine Warsaw-based Rutkowska -- who has quietly taken the male-dominated research community by storm with her groundbreaking research in Vista hacking and in creating and detecting stealth malware in operating systems -- failing at much of anything. The confident yet self-effacing researcher shrugs off the discovery of that now famous crack in the Vista fortress as just part of her research.

----------------------------------

Joanna, license or not, is still bad ass in my book....