Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Monday, March 29, 2010
RumorMill: Out-of-Band IE Patch Coming Tomorrrow
More stuff over at ISC - http://isc.sans.org/diary.html?storyid=8524
More rumors = more real - clearly.
Thursday, February 19, 2009
RumorMill: Another Processor Breach??
Banks around the country are reportedly receiving warnings, and perhaps even new lists of cards to replace. This is apparently regarding another credit card processor, unrelated to Heartland Payment Systems, having a significant breach.
OSF has received multiple tips from multiple sources, all sounding nearly identical.
From what we've heard, this second breach is significant in scale, but we have not as of yet been told who the processor is.
Also BankInfoSecurity.com has released an article about three people being arrested for allegedly using credit cards from the Heartland Breach. And also, their list grows of institutions affected by the Heartland incident (they maintain a much more comprehensive list than we did). Hats off!
We'll post more details as we become aware of them.
-----------------------------
Last week, a friend informed me that she had received a letter from Compass Bank..and would be getting a new card. As of right now, Compass Bank is not listed as one of the 400 institutions affected by the Heartland Breach.Therefore, it could be part of another beach...but that doesn't mean it was another processor however.
Sunday, December 7, 2008
Rumor Mill: Pentgon USB Worm Attack Started in Parking Lot
Someone infected thumb drives with the WORM then dropped them around the Pentagon parking lot. The employees, picked them up, took them into their offices and plugged them into their office computers to determine the owner of the drive.Is it the truth? Who knows.....I would consider it a rumor/educated-guess at this point.
But this type of social enginnering attack is not new and is one of the toughest threat types to migitate.
Edward's law states - "You cannot apply a technological solution to a sociological problem."
Tuesday, September 2, 2008
RumorMill: Google Chrome Vulnerabilities
Sunday, August 17, 2008
RumorMill: Musharraf to Resign on Monday
Pakistani President Pervez Musharraf is expected to resign Monday and fly into exile in Saudi Arabia, where he is to remain for the next three months, a former aide to the president has told NEWSWEEK on condition of anonymity because of the sensitivity of the issue. The aide added that the news had been relayed to the nation's top military brass, including its powerful corps commanders.
Though a current aide to Musharraf confirms that the president will resign, officially, Musharraf's camp denies the story. "Your source is a liar," retired Maj. Gen. Rashid Qureshi, a presidential spokesman, told NEWSWEEK when asked about the president's resignation and possible flight into exile. "The information you have is absolutely untrue."
Sunday, August 3, 2008
RumorMill: DNA Links Man to Anthrax Mailings
DNA evidence from the deadly 2001 anthrax mailings led authorities to a suspect who officials say killed himself, according to a source familiar with the investigation.
The DNA linked the anthrax used in the mailing to a flask used in Bruce Ivins' lab at the U.S. Army Medical Institute of Infectious Diseases, said the source, who was not authorized to speak publicly about the case.
Officials say Ivins, a scientist at the lab in Fort Detrick, Maryland, committed suicide. He was found unconscious at his home July 27 and died at a Maryland hospital Tuesday, the same day he was to have discussed a plea deal with prosecutors.
Authorities may release their evidence against Ivins, 62, as soon as this week before closing the case, sources said.
No charges have been made public, and no arrests have been made in the anthrax probe.
Five people died and more than a dozen others became ill after letters containing anthrax were sent to congressional offices and media organizations soon after September 11, 2001, terrorist attacks.
Among those who died were two postal workers. Two contaminated letters were sent to senators, exposing 30 staffers.
Ivins, of Frederick, Maryland, worked for decades in the biodefense lab at Fort Detrick, where he was trying to develop a better vaccine against the anthrax toxin.
The FBI traced the anthrax used in the attacks to the lab by using a new genetic technology, a U.S. official familiar with the probe said.
Authorities were looking at whether Ivins released anthrax as a way to test a vaccine he was working on, another official said.
At the time of his death, Ivins was under a temporary restraining order sought by a social worker who counseled him in private and group sessions. She accused him of having harassed, stalked and threatened violence in the previous 30 days.
The woman told the court in her complaint that Ivins had spent time at a mental health facility.
---------------------------------
Perhaps in connection to this growing story...the FBI seized two public computers from the C. Burr Artz Library this week. This were taken without a court order.
Saturday, April 19, 2008
RumorMill: Windows XP Service Pack 3 Coming Soon
Information Week and Neowin.net are reporting that Windows XP Service Pack 3 may be showing up at the end of this month. OEMs and MSDN/Technet subscribers will apparently have access on the 21st, with release to Windows Update on the 29th.
http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=207200856
This is an unofficial report - we do not have confirmation from Microsoft for this.
Tuesday, January 1, 2008
RumorMill: Bhutto Was Set to Reveal Poll Rigging Plot
Benazir Bhutto had planned to brief visiting American politicians about an alleged poll-rigging plot orchestrated by Pakistan's intelligence agencies on the day she was killed, senior officials of her Pakistan People's Party (PPP), said on Monday.
Bhutto had obtained details of an Islamabad safe house run by the country's Inter-Services Intelligence (ISI) agency from where it intended to manipulate the poll, said Sarfraz Khan Lashari, an official on her party's 10-member election-monitoring cell.
The ISI-led operation would rig the vote in favour of President Pervez Musharraf's Pakistan Muslim League-Q party through ballot stuffing in constituencies across Sindh and Punjab provinces, he said.
Bhutto intended to discuss the allegations, which had been provided by informants within the intelligence services, with Senator Arlen Specter and Representative Patrick Kennedy, on the evening she was killed.
"That's what she was going to explain to the US senators," he said. "We have a lot of evidence that the government is involved in rigging. It was going to be discussed on that evening."
Bhutto's husband, Asif Zardari, confirmed that his wife had received allegations about the Islamabad safe house. "Yes we know about that," he said on Monday.
He refused to give further details, saying it was "not the right time" to discuss them.
The Guardian was given a rough location of the safe house by a PPP official but a search in Islamabad failed to pinpoint the building.
The ISI has a long history of meddling with elections in Pakistan, usually in the interest of the country's military establishment. In 1990 the ISI received 140-million rupees (£1,1-million at current values) to rig national elections, according to Supreme Court testimony by the then-chief of army staff, General Mirza Aslam Beg.
There is no ISI spokesperson but a government official, speaking on condition of anonymity, denied the claims. "How can you run an election-rigging campaign from a safe house? There is a lot of talk about the ISI but not much substance," he said.
Lashari, an environmental economist, said the PPP had prepared two reports on vote-rigging. The first, about 200 pages, detailed election abuses across Pakistan and was intended for presentation to Western diplomats in Islamabad.
A smaller report, identifying the ISI safe house in Islamabad, was of much greater sensitivity.
Lashari said that document was not even for circulation in private, and Bhutto intended to discuss it only with selected diplomats and politicians. "It was very sensitive. The details were for people who were sympathetic to the party," he said.
Lashari said he thought an official from the British high commission was among those to be taken into confidence. A spokesperson in Islamabad said the British high commission had not received any reports from the PPP of ISI rigging.
Saturday, December 1, 2007
Rumor Mill: Mac OS X Might Run Windows Apps in the Future
Once Intel chips landed inside Macs and Boot Camp made its debut, it got a lot harder to blame rumor mongers for making a certain leap: Mac OS X could one day run Windows apps sans-Windows. Indeed, projects like the open source Wine have facilitated some of this functionality, albeit in a limited fashion, for some time now. But a new discussion on a Wine mailing list could refresh hope for those looking to get their Frankenstein on with Mac OS X and Windows computing.
The discussion begins with a mailing list message called Interesting Behavior of OS X, in which Steven Edwards describes the discovery that Leopard apparently contains an undocumented loader for Portable Executables, a type of file used in 32-bit and 64-bit versions of Windows. More poking around revealed that Leopard's own loader tries to find Windows DLL files when attempting to load a Windows binary.
Yes, that last bit is the juicy one. According to the fledgling investigation in this as-yet short message thread, folks are suspecting that Leopard contains at least the building blocks for Apple to one day add a compatibility layer to Mac OS X for running Windows apps right alongside Mac OS X apps. "Just add Windows" and Boot Camp itself could fall off the list of ingredients for bridging these two computing worlds.
Of course, this could also be nothing; perhaps leftover from some behind-the-scenes project, spare code from adopting EFI (though this reply notes that PE files are flat-out rejected in Tiger on Intel Macs), or who knows what else. Still, if your conspiracy theory wells have run dry during Macworld's pre-season, this should be more than enough to keep you busy for at least a week or so.
--------------------------
I would love to see how Apple deals with malware then...lol