Thursday, February 23, 2006

Google Reader "Preview" and "Lens" Script Improper Feed Validation

My good friend, Debasis Mohanty, posted this to FD this morning.

---------------------------------

Google Reader "preview" and "lens" script improper feed validation ===================================================================
I. DESCRIPTION

Google Reader (http://www.google.com/reader/) helps organise the contents of those rss or atom feeds for which the user is interested in or subscribed to. The user instead of continuously checking his/her favorite sites or discussion groups for updates, (s)he can let Google Reader do it for them.

From news sites to your friends' blogs, Google Reader helps stay up-to-date with all the online information that matters most to the user.

II. VULNERABILITY DETAILS
Google reader is supposed to display only those contents which the user has subscribed to however two vulnerabilities has been identified which may allow an attacker to entice it's victim (using google reader service) to view unwanted web contents carrying malicious payloads.

a. Google reader "preview" script improper feed validation (without user
authentication)
----------------------------------------------------------------------------

Google feed reader "preview" script: The script
(http://www.google.com/reader/preview/*/feed/) is normally used for displaying the feed contents within the reader.

For example, the following request will display the rss content of the link
http://www.microsoft.com/athome/security/rss/rssfeed.aspx:
http://www.google.com/reader/preview/*/feed/http://www.microsoft.com/athome/
security/rss/rssfeed.aspx

Note: '*' in the above link can be replace with any word of your choice otherwise it can be left as it is.

This 'preview' script is only available to authenticated user but if a direct link is provided it doens't ask for user authentication. It can be very usefull for an attacker to mount an attack on its victim by directing them to view the content of malicious sites (carrying evil payloads).

b. Google reader "lens" script improper feed validation (with user
authentication)
----------------------------------------------------------------------------

Google feed reader "lens" script: The script
(http://www.google.com/reader/lens/feed/) is normally used for displaying contents of only those feeds to which an authenticated user has subscribed to.

However, it is possible to pass any rss / atom feed to the script as parameter to which the user has not subscribed but the un-subscribed feed contents can still be loaded within the user reader page.

For example, the following request will display the rss content of the link
http://www.securityfocus.com/rss/news.xml:
http://www.google.com/reader/lens/feed/http://www.securityfocus.com/rss/news
.xml

This 'lens' script is only available to authenticated user and can be usefull for an attacker to mount an attack on its victim by directing them to view the content of malicious sites (carrying evil payloads) even though the user is not subscribed to.

III. VENDOR
Google.com

IV. HISTORY
30th Jan, 2006 - Bug originally discovered
2nd Feb, 2006 - Vendor Notified
...
...
No vendor response
...
...
22nd Feb, 2006 - Vendor Notified again
22nd Feb, 2006 - Public Disclosre

IV. CREDITS
Debasis Mohanty
www.hackingspirits.com

---------------------------------

It isn't a killer RSS hole but just wait...this is just the beginning.

Wednesday, February 22, 2006

Uncomfirmed - Mozilla Thunderbird 1.0.7 : Remote Code Execution & DoS

Just posted to the FD list

--------------------------------
Mozilla Thunderbird : Remote Code Execution & Denial of Service

http://www.sysdream.com/article.php?story_id=230&section_id=78

Tuesday, February 21, 2006

Nmap 4.01 - Kinda old News

Just saw that Nmap was updated to 4.01 on the 10th. Just in case you didn't know...now you do. Kinda old news, but I am still catching up.

Nmap 4.01 fixed several bugs, including an important memory leak in the raw ethereat sending system. See other changes.

Possible False Positive Detection of OSX/Inqtana-B - UPDATED

Virus: 'OSX/Inqtana-B' detected in /Library/Printers/EPSON/
SP830Series.plugin/Contents/MacOS/SP830Series

Virus: 'OSX/Inqtana-B' detected in /Library/Printers/EPSON/C43Series.plugin/Contents/PDEs/
PrintSetting.plugin/Contents/MacOS/PrintSetting

Virus: 'OSX/Inqtana-B' detected
in /Library/Printers/EPSON/C44Series.plugin/Contents/PDEs/
PrintSetting.plugin/Contents/MacOS/PrintSetting

Virus: 'OSX/Inqtana-B' detected
in /Library/Printers/EPSON/PM860PT.plugin/
Contents/Utility/UTPM860PT.plugin/Contents/MacOS/UTPM860PT

Virus: 'OSX/Inqtana-B' detected
in /Applications/Microsoft Office 2004/Office/ShMem.bundle/
Contents/MacOS/ShMem

Virus: 'OSX/Inqtana-B' detected
in /System/Library/Extensions/
AppleVADriver.bundle/Contents/Resources/mp2decvbin1

Virus: 'OSX/Inqtana-B' detected
in /Applications/4D Client.app/Contents/4D Extensions/4D Carbon Support.bundle/Contents/MacOS/4D Carbon Support

-----------------------------------------

It would appear that Sophos may have a pretty big false positive issue on their hands....or at least I hope it is a false positive....more information to come.

The Sophos website seems to be running very slow (DoS'd), perhaps caused by this new detection issue.

Inqtana uses a Bluetooth vulnerability that was patched in Mid 2005, therefore most people saw the trojan as "low-risk". If my feelings are correct, the outcome of this false positive will be 100 times worse than the trojan itself.

UPDATE - 11:37AM Central

Sophos has pulled the IDE and confimed it was a false positive. Expect a new IDE within 45 mins.

Feb 2006 - Drone Armies C&C Public Report

Gadi Evron passed this nice report to the FunSec mailing list this morning.

While this information only appears to cover botnets that are reported, it does show which networks are willing to actively fight this growing problem and which aren't. Hopefully posting this information regularly will change some views and increase awareness of the issue.

Keep up the good work.

Monday, February 20, 2006

2006 - Year of the OS X Exploit?

In my personal view, Apple made the right move in using BSD code in OS X and in moving to the Intel chipset.

However, a smart man once said that every action has an equal and opposite reaction.

Why use OS X?

Apple’s use of the BSD microkernel code has turned OS X into the system of choice for both hackers and security professionals alike. As a result, many applications commonly used by on BSD/Linux have been ported to OS X. Some are even better on Apple, take KisMac for example. But all this positive attention hasn’t developed without some negative attention as well.

Opposite Reaction

Security Researchers and hackers now seem to have their sights on Apple’s OS gem.

Summary

Will 2006 bring an end to Apple’s current threat immunity? Perhaps - Only time will tell, but the force seems to be strong with those that want to dig in the OS X candy coating.

I have outlined several other security concerns for the Apple world with a good friend and hopefully we can put those all together in a more in-depth blog in the future.

Wednesday, February 15, 2006

Fun: Jamaica

Well, I spent most of the day in the rain forest of Jamaica. It was very muddy and wet...and pretty damn hot, but overall a very fun time. We are underway toward the Grand Caymans.

We will have a private tour on the next island, so driving around in a rented car/van should be pretty fun. As I have stated before, I am pretty much out of the internet security loop for the rest of the week. I hope the internet doesn't die on me....keep it going guys.

Tuesday, February 14, 2006

Fun: Haiti

As some of you may know, I am chilling in Haiti right now. I won't be around for around 4 or 5 days....so stay tuned. I have all types of stuff to catch up on. Not having the internet for a week is like not being alive for a full year. =)

Friday, February 10, 2006

Fun: WebShots Backgrounds

It would seem that someone from Peking decided to collect all the great backgrounds from WebShots and host them on a site in China.

www.mydeskcity.com

Not sure Webshots would like it however.

Security Breach Exposes CC Details of 200,000

Some of you may have heard about the data-security breach that resulted in numerous people having their debit cards cancelled this week. What happen? How big is the problem?

Details are still coming to light, but right now it sounds something like this -

A pretty big office-supply retailer was hacked and exposed the credit information over perhaps 200,000 people.

Bank of America, Wells Fargo and other banks were alerted by Visa and MasterCard to take security actions for those card holders.

Let’s remember, this isn't some stolen backup tape or a street thief wanting quick money on a laptop...it sounds like a real hacker that targeted the data storage of this retailer. This is my take on the issue and may not be true, but check these quotes from SFGate.com

1) Banking industry sources said they were notified last month by Visa and MasterCard that the computer system of a prominent merchant had been penetrated by a computer hacker, and that account information for thousands of customers had been endangered.

2) Rosetta Jones, a spokeswoman for Visa USA, acknowledged Thursday that the incident involved a U.S. merchant that "may have experienced a data security breach resulting in the compromise of Visa card account information."

3) Sharon Gamsin, a spokeswoman for MasterCard International, said the credit card company had been informed of "a potential security breach at a U.S.-based retailer."

Sounds pretty serious. Visa, MasterCard, BofA and Well Fargo seem to be reacting as required and expected. Issuing new cards and watching accounts is standard for security breach of this nature and is the correct step for customer protection.

So whats the big deal? The "Unknown" retailer is the deal right now.

Under California SB 1386 - requires an agency, person or business that conducts business in California and owns or licenses computerized 'personal information' to disclose any breach of security (to any resident whose unencrypted date is believe to have been disclosed).

So if the above is true, then we can assume one of the following -

1) The "Unknown" retailer has no business in California and therefore is not bound by SB 1386

2) They are bound by the law but all credit information exposed was encrypted.

3) They are bound by the law and they will disclose this breach in due time.

4) They are bound by the law and not following it as it was intended.

Someone needs to find out...and I would guess that we will all have more information very shortly. Keep your eyes out for this one.

Again, take this whole article with a gain of salt because information is will change.

The Secret 64-bit Life of the Intel Core Duo

It would appear that the new Intel Core Duo is really a 64-bit processor in hiding. So why won't Intel let your new iMac run 64-bit Linux??

More details are sure to be exposed. Is OS X 64-bit? Seriously, I am asking you....

Google Desktop = Security Risk?

---------------------------------------------
February 09, 2006

Google Copies Your Hard Drive - Government Smiles in Anticipation
Consumers Should Not Use New Google Desktop

San Francisco - Google today announced a new "feature" of its Google Desktop software that greatly increases the risk to consumer privacy. If a consumer chooses to use it, the new "Search Across Computers" feature will store copies of the user's Word documents, PDFs, spreadsheets and other text-based documents on Google's own servers, to enable searching from any one of the user's computers. EFF urges consumers not to use this feature, because it will make their personal data more vulnerable to subpoenas from the government and possibly private litigants, while providing a convenient one-stop-shop for hackers who've obtained a user's Google password.

"Coming on the heels of serious consumer concern about government snooping into Google's search logs, it's shocking that Google expects its users to now trust it with the contents of their personal computers," said EFF Staff Attorney Kevin Bankston. "Unless you configure Google Desktop very carefully, and few people will, Google will have copies of your tax returns, love letters, business records, financial and medical files, and whatever other text-based documents the Desktop software can index. The government could then demand these personal files with only a subpoena rather than the search warrant it would need to seize the same things from your home or business, and in many cases you wouldn't even be notified in time to challenge it. Other litigants—your spouse, your business partners or rivals, whoever—could also try to cut out the middleman (you) and subpoena Google for your files."

The privacy problem arises because the Electronic Communication Privacy Act of 1986, or ECPA, gives only limited privacy protection to emails and other files that are stored with online service providers—much less privacy than the legal protections for the same information when it's on your computer at home. And even that lower level of legal protection could disappear if Google uses your data for marketing purposes. Google says it is not yet scanning the files it copies from your hard drive in order to serve targeted advertising, but it hasn't ruled out the possibility, and Google's current privacy policy appears to allow it.

"This Google product highlights a key privacy problem in the digital age," said Cindy Cohn, EFF's Legal Director. "Many Internet innovations involve storing personal files on a service provider's computer, but under outdated laws, consumers who want to use these new technologies have to surrender their privacy rights. If Google wants consumers to trust it to store copies of personal computer files, emails, search histories and chat logs, and still 'not be evil,' it should stand with EFF and demand that Congress update the privacy laws to better reflect life in the wired world."

For more on Google's data collection:
http://tinyurl.com/chxk6
http://tinyurl.com/7wjyg
http://tinyurl.com/d85wt
http://tinyurl.com/aujee

Contact:
Kevin BankstonStaff AttorneyElectronic Frontier Foundation
bankston@eff.org
Posted at 11:04 AM
---------------------------------------------

When the first Google Desktop was released, I pushed up the ranks for this to not be used in the corporate world. People can (and will) do what they want on their personally computers, but in the business world...the "unknown" risk of this software is just unnecessary.

As attackers move away from OS levels, applications security problems will hit center stage. We are seeing this start to happen right now.

Remember the old OS security measure of reducing the number of running services? This reduces your online signature and therefore reduces the attack pathways. The same idea can be applied for system security at the application level.

More Applications = more lines of running code = higher change of security vulnerabilities

Need I say more....

Thursday, February 9, 2006

AOL/GoodMail - The Internet's First Email Tax

The "Fight for Internet Neutrality Principles" has moved into the e-mail system.

Ahh, back in the day. I remember when friends would tell me about how the Postal Service was going to impose a 5 cent surcharge on every e-mail message sent via the Internet. I used to laugh and just say "Ohh that is just an urban legend".

Well, sometimes the truth is scarier than legend. Change "Postal Service" to "AOL/Yahoo" and you are pretty close to truth.

AOL and Yahoo have decided that creating "mail classes" is the next best way to fight spam. They believe that by charging companies just factions of a penny, that they can cut spam. Factions of a penny? That isn't alot? Do you remember "Office Space"? It is alot....really alot.

I am not so sure that I agree with this method. Sounds like a way to make extra money, pretend they are doing something about the spam problem and a great way for other companies to spam directly into your inbox all the time by bypassing spam filters.

It also sounds like a GREAT reason to drop AOL for a better ISP, like you should have done years ago IMHO. If the systems doesn't catch on like expected, AOL may be running their own customers away. Kinda like Sony and the RIAA.

The New York Times had a great article on this very subject earlier this month. "AOL users will become dissatisfied when they don't receive the e-mail that they want, and when they complain to the senders, they'll be told, 'it's AOL's fault,' " said Richi Jennings, an analyst at Ferris Research, which specializes in e-mail.

AOL and Yahoo will be using Goodmail Systems’ processing system to collect the electronic postage and verify the identity of the sender. AOL will be implementing the system in the next two months, while Yahoo will be trying the system out, and has not yet decided how paid vs. unpaid mail will be treated.

Supporters of the system, say it is just like preferred mail classes at your post office. People against the system say it is only going to hurt customers and will be another nail in the "internet e-mail" coffin.

David Stanley, vice president and managing director of messaging security company CipherTrust, said the plan was "a ridiculous idea" and "nothing more than a money-making idea that will not stop spam but will give account holders free reign to send all sorts of 'authenticated' mail."

Umm, I guess the people of the world will have to get together, buy all the dark fiber and create an Open Source Internet. ;)

Wednesday, February 8, 2006

IE7 Beta Breaks Google AdSense

BetaNews - Developers testing out the latest version of Internet Explorer 7 are discovering a nasty flaw -- the browser seems to be incompatible with Google's AdSense advertising service. Although the problem seems limited to those running IE7 Beta under Windows XP, it still has some developers worried. For many, AdSense has become the de facto method for generating revenue for their sites. Google generates over $2 billion in revenue yearly from the program alone.

"Considering that by the end of the year, IE7 should be available for almost all versions of Windows, unless Microsoft wants to face the ire of developers everywhere, it had better fix this," Nathan Weinberg of the InsideGoogle Web log wrote Wednesday. Although it is unknown as to why this is occurring, it is suspected it may have to do with how IE7 now handles JavaScript. Microsoft could not be reached for comment.

-------------------------------------------------

Add this little piece of information with the rumors of Vista being released on Dec 1st and you have a adsense money problem in the making. =)

I guess Microsoft can fix this issue when they fix the Remote Code Execution buffer overflow flaw found on several weeks ago.

WMF Vulnerability Returns for IE5

Microsoft issued a new security advisory yesterday. Yet another WMF vulnerabilitiy.

(91333) Vulnerability in Internet Explorer Could Allow Remote Code Execution

This new advisory only relates to the following two cases :

1) Internet Explorer 5.01 SP4 on Microsoft Windows 2000 SP4
2) Internet Explorer 5.5 SP2 on Microsoft Windows Millennium

Note - This is not the same issue as the one addressed by MS06-001

Secunia Advisories (SA18729) - Highly Critical - System Access

Candidate CVE-2006-0020

It would appear that this might be connected to the flaw pointed out by HD Moore on the FunSec mailing list in Jan.

--------------------------------
More where that came from. The fun thing about these is that they DO apply to Windows 96, 98, 2000-2003, Vista. You can trigger it via RTF, directly inside IE, and anything else that loads metafiles. A fun bug you can find in a certain WMF parsing application...:

uint_size = wmf_header.size * 2;
ptr = malloc(uint_size);
read(fd, ptr, uint_size - sizeof(wmf_header));

:-)

-HD
---------------------------------

Upgrading to IE 6 SP1 is the suggested action on Windows 2000 SP4 and Windows ME

No patch for the older IE5. My suggested action would to get off Windows ME as soon as possible. The Win9x kernel is dead as dead...

Science: NASA Appointee Resigns

NYTimes.com - George C. Deutsch, the young presidential appointee at NASA who told public affairs workers to limit reporters' access to a top climate scientist and told a Web designer to add the word "theory" at every mention of the Big Bang, resigned yesterday, agency officials said.

Mr. Deutsch's resignation came on the same day that officials at Texas A&M University confirmed that he did not graduate from there, as his résumé on file at the agency asserted.

...

Mr. Deutsch, 24, was offered a job as a writer and editor in NASA's public affairs office in Washington last year after working on President Bush's re-election campaign and inaugural committee, according to his résumé. No one has disputed those parts of the document.

According to his résumé, Mr. Deutsch received a "Bachelor of Arts in journalism, Class of 2003."

Yesterday, officials at Texas A&M said that was not the case.

"George Carlton Deutsch III did attend Texas A&M University but has not completed the requirements for a degree," said an e-mail message from Rita Presley, assistant to the registrar at the university, responding to a query from The Times.

Repeated calls and e-mail messages to Mr. Deutsch on Tuesday were not answered.

Mr. Deutsch's educational record was first challenged on Monday by Nick Anthis, who graduated from Texas A&M last year with a biochemistry degree and has been writing a Web log on science policy, scientificactivist.blogspot.com.

--------------------------------------------

All political comments aside, how can a person work for the President and then for NASA and no one checks on their college degree??

Mind-blowing...

Tuesday, February 7, 2006

Verizon: We're Ending Google's "Free Lunch"

NetworkingPipeline Blog – “One more member of the Telco mafia has threatened Google with a bandwidth cutoff. Verizon senior VP and general counsel John Thorne told a conference that Google "is enjoying a free lunch," by using Verizon's network, and issued a veiled threat to cut off Google's bandwidth. “

Needle in the Neutrality Haystack that Telecos intend to burn.

All Your Data Belong to Us

Man, have the reports of data leakage been crazy the last couple of weeks. Here are some of the highlights...

1) Guardian Unlimited (Feb 7th) - Russian thieves have stolen more than €1m (£680,000) from personal bank accounts in France using "sleeper bugs" to infect computers. French authorities claim the thieves can take control of and empty a bank account in seconds. In one hit, a bank customer lost €40,000.

Police say the virus is embedded in emails or websites and remains dormant until the user contacts their bank online. When that happens, the bug becomes active and records passwords and bank codes which are then forwarded to the thieves. They then use the information to check the victim has money in the bank before transferring funds to the accounts of third parties, known as mules, who may have agreed to allow money to pass through their accounts in return for a commission of between 5% and 10%.

2a) Boston Globe - It has come to our attention that consumers are receiving telephone calls from companies offering to assist them prevent credit card fraud. These companies, including one calling itself the “National Verification Office”, are asking consumers to provide the credit card or bank card information the consumer used to pay his or her Boston Globe or the Worcester Telegram & Gazette subscription. These companies are NOT AFFILIATED with the Boston Globe or the Worcester Telegram & Gazette.

2b) Boston.com (Feb 1st) - Credit and bank card numbers of as many as 240,000 subscribers of The Boston Globe and Worcester Telegram & Gazette were inadvertently distributed with bundles of T&G newspapers on Sunday, officials of the newspapers said yesterday.

3) Networkworld.com (Feb 6th) - A small Lockport, Manitoba-based distributor of herbal remedies has for the past 15 months been mistakenly receiving faxes containing confidential information belonging to hundreds of patients with Prudential Financial's insurance group. The data exposed in the breach -- and faxed to the company by doctors and clinics across the U.S. -- included the patients' Social Security numbers, bank details and health care information.

4) InfoWorld.com (Feb 6th) - Honeywell International Inc. says a former employee has disclosed sensitive information relating to 19,000 of the company's U.S. employees. Honeywell discovered the information being published on the Web on Jan. 20 and immediately had the Web site in question pulled down, said company spokesman Robert Ferris.

5) Networkworld.com (Jan 27th) - About 365,000 hospice and home health care patients in Oregon and Washington are being notified about the theft of computer backup data disks and tapes late last month that included personal information and confidential medical records.

-----------------------------------------------

As you can tell, data loss comes in many forms.

Thieves stealing backup tapes, normal people making mistakes, old employees taking some anger out for kicks, and organized groups of hackers (perhaps even foot soldiers of Russian organized crime group).

Now just think about all the cases that are not reported....yeah - exactly.

WDRaptor X - World's First Clear Cover Hard Drive

Ok, it isn't the "first" hard drive to have a window, but it is the first to be available right from the manufacturer.

The old way of doing the HD windows included a zip-lock bag, time, glass, cutting tools and other equipment to open the drive. Sometimes this process would kill the drive, sometimes it wouldn’t. It is important to also note that this reduces the drives shielding from magnetic damage - this may have kept the WDRaptor X window small.

In college, I was all into hardware modding. I created a custom windowed CD-ROM, created a dual-windowed aluminum case, glow-in-the-dark cables and created my own custom CPU fan. Ahh, those were the days. Once you could buy a windowed computer with lights at CompUSA, I knew it was time to move on.

Pre-Order your WDRaptor X 150GB 10k RPM for $350

Toms Hardware has a write-up on the new WDRaptor X as well.

US DoD - Quadrennial Defense Review Report

Recently, the United States Dept of Defense released it Quadrennial Defense Review Report (pdf).

The report singles out India, Russia and China as "major and emerging powers" in Asia. However China is singled out on page 29 has the "greatest potential to compete militarily with the United States and field disruptive military technologies that could over time offset traditional US military advantage abset US counter strategies.

I don't see this sentence as unreasonable. The DoD is making any assessment of powers in the region and China is one of the biggest and less understood by the US government.

But China doesn't seem to really like the words used in the report.

See the Feb 3rd, QDR Pentagon Briefing in video or plain audio.

Monday, February 6, 2006

Internet Neutrality - US Senate Commerce Committee

Today the US Senate Committee on Commerce, Science & Transportation held a full hearing on the subject of "Net Neutrality".

I was unable to watch this hearing because of work, but I will be watching for updates.

This issue was summarized in a Jan 18 blog titled "The Fight for Internet Neutrality Principles".

During the week in Jan, the blogosphere was filled with stories about it - Jeff Pulver blog and of course Vint Cerf's Official Google blog.

Bluetooth Stack Vuln on Sony/Ericsoon Cellphones

This is exactly why I have bluetooth disabled on my black Moto. Just posted to the FD Security list.

------------------------------------

[Software affected] Bluetooth Stack on Sony/Ericsson cell phones

[Version] Sony/Ericsson K600i, V600i, W800i, T68i and certainly other models

[Impact] Bluetooth Stack Denial of Service (may be more - may be a rootkit :) - Phone DoS (reboot or shutdown) - White screen bug (freeze sleeping)

[Credits] Pierre Betouin - pierre.betouin@infratech.fr - Bug found with BSS v0.6 GPL fuzzer (Bluetooh Stack Smasher)

BSS could be downloaded on http://www.secuobs.com/news/05022006-bluetooth10.shtml

[Vendor] notified now

[Original advisory]
http://www.secuobs.com/news/05022006-bluetooth7.shtml#english
http://www.secuobs.com/news/05022006-bluetooth7.shtml#french

[PoC] download it on http://www.secuobs.com/news/05022006-bluetooth6.shtml

[PoC usage]
# ./reset_display_sonyericsson 00:12:EE:XX:XX:XX

[Details]
A short raw L2CAP packet such as :
08 01 01 00
It represents the following L2CAP header fields :
code L2CAP_ECHO_REQ;
ident 1
length 1
The "real" packet sent is, in fact, 4 bytes long.
The DoS can be triggered when the length sent in the L2CAP field is equal to the real length minus 3 (which is the size of the L2CAP header here).

------------------------------------

Independent Security Testing for DRM Software

It appears that SunComm has agreed to submit all future versions of its MediaMax DRM software for independent security testing in an effort to weed out any further vulnerabilities.

For those just tuning in to the story, late last year SunComm's MediaMax software was discovered covertly installing itself and leaving PCs vulnerable to attack.

SunComm hopes to reduce any future legal problems by using the independent software review model.

From the BBC article, it sounds like that testing might be headed by the EFF, which is good news. The EFF will look for security issues but will keep customer rights in mind at the same time.

But shouldn't the big record labels also have customer rights in mind? I would have said "yes" before the whole XCP/MediaMax incident. However it became very clear that security of their customers was pretty low on the DRM list of "things to do".

Will First 4 Internet, makers of the XCP DRM, make the same "good faith" move??

Should SunComm do this work in-house instead of using a non-profit group to secure their software??

Either way, this good is a positive step in protecting customer rights in the face growing DRM use.

Super Bowl XL Commercials on Google Video

Just in case you missed a commerical or two yesterday, Google is hosting them all on a special Google Video page.

Sunday, February 5, 2006

Science: When Giant Octopus Attacks

Just saw this on Bruce Schneier's blog. Wow!

Here is the full video via Google.

Friday, February 3, 2006

Keep your Applications Updated or else....

1) If you aren't on Winamp 5.13 yet, get it now. Remember the extremely critical system access exploit that was released for it. Well the exploit posted for this vuln is not being used to push spyware. It didn't take very long.

2) Get your Firefox updates. Firefox 1.5.0.1 was released recently. It fixes several highly ciritical security issues. Improvements include - better support for OS X, several memory leaks are fixed and several other security enhancements.

3) Recently, some vulnerabilities have been reported in Thunderbird, which could result in compromise of the user's system. Recommended workaround is to disable JavaScript.

4) Disabling JavaScript is also the only workaround for the vulnerabilities reported in the Mozilla suite as well.

Word Around the Campfire is...

Well, it is friday. As FatBoy Slim said - the weekend starts here....

1) eWeek.com is reporting that the WMF exploit was being sold in the middle of Dec 2005 on the Russia computer underground for $4,000 a pop.

2) Blue Boar posted information about a new project on the FunSec Mailing list this morning. The "mwcollect Alliance". Mwcollect is honeypot type program that can be ran in Linux or BSD to collect worms/bots and other bad stuff from right off the internet. Pretty cool sounding. After I move and get settled into my new place, I might have to play around with mwcollect.

3) Today is Feb 3rd. The day that CME-24 is set to attack full force. There have been initals reports from Indian about large volumes of e-mails and larger than normal to support centers, but initals reports always sound worse than truth.

Randy Abrams has a great blog about the work put into fighting the CME-24 threat. The TISF Blackworm task force worked very hard to reduce the damage worldwide. Good work guys. That "good work guys" also goes to Microsoft. =)

Watch for updates on the following sites.
ISC SANS & SecuriTeam Blog

While the global infection number of 300k isn't alot, it might hurt some of the top infected nations. We can only wait and see...no matter the outcome. We will still all be back at work on Monday - maybe even with a "case of the Mondays"

Thursday, February 2, 2006

CME-24 Worm - The Black Cloud

Well, tomorrow is the 3rd. The payload trigger for CME-24.

As it stands right now - India, Peru, Italy and Turkey will be hit harder than the US.

On Jan 27th, I blogged about how Microsoft's was not going to release an updated Windows Malicious Software Removal Tool before "D-Day". They stated this again on Jan 30th in this Anti-Malware Engineering Team blog, but they do remind us that the Windows Live Safety Center Beta will remove the threat.

They could had just said - "Yeah, we can save some of you, like we did for Zotob, but we really need you to test our new beta products - Safety Center and OneCare. Thanks".

I agree that Safety Center is a great free website. I will all my friends about it. It provides much more than just malware removal as well. Microsoft created it and they did a very good job.

But why not take the extra step while there was still time?

Remember they rushed out a new version of the Windows Malicious Software Removal Tool in August for the Zotob worm. Why not now? It is true that 300,000 people isn't anywhere near the numbers that could have been attacked by Zotob, but still.

Why not now? Microsoft, please tell me it isn't to get people on your beta programs...please...get me something. Anything.

Blue Light Reduces Melatonin Production

I was scanning over my Google Reader this morning and found this very cool Digg.com article. A small study, sponsored by National Space Biomedical Research Institute, suggest that subjects exposed to short-wavelenght light (aka blue light), are immediately perked up.

Very interesting. Back in a former part of my life, I was very into chromotherapy and Ayurvedic medicine in general. I am Pitta for the record. ;)

Anyways, lets get into the details of this blue idea.

1) In chromotherapy, Red is said to increase the pulse rate, to raise the blood pressure, and the rate of breathing. Perhaps this is why we always see red lights on planes in military movies, who knows.

2) Back in 2001, neuroscientists at Jefferson Medical College clarified how the human eyes uses light to regulate melatonion production. George Brainard, Ph.D. was a professor of neurology at Jefferson Medical College of Thomas Jefferson University in Philadelphia.

Remember that name ;)

Melatonin is a hormone produced in the pineal gland and also by the retina. It is commonly used against insomnia, jet lag and other types of sleep misalignments. In simple terms, melatonin makes you sleepy.

In the study, they looked at the effects of different wavelengths of light on 72 healthy volunteers, exposing them to nine different wavelengths, from indigo to orange. Subjects were brought into the laboratory at midnight, when melatonin is highest. The subjects’ pupils were dilated and then they were blindfolded for two hours. Blood samples were drawn.

Next, each person was exposed to a specific dose of photons of one light for 90 minutes, and then another blood sample was drawn. Wavelengths of blue light had the highest potency in causing changes in melatonin levels, he explains.

So bascially, certain light colors effects the production of melatonin in different ways. Very cool.

Now, if they can find the light color that inhibits serontonin reuptake in the synaptic terminls of neurons. That would be cool. Colored light should be much better on the body than ecstasy (MDMA), cocaine, and man-made TCAs.

Wednesday, February 1, 2006

Humor: Adages of the Internet

According to Wikipedia, adages are short, but memorable sayings, which hold some important fact of experience that is considered true by many people, or it has gained some credibility through its long use.

I was reading up on Moore's Law and started to think about all the weird Murphy's Law variants that my friends and I used in college. So, I started to dig. Wikipedia has a pretty good list going and I can only laugh when I read them.

Here are some of the better ones:

  • Murphy's Law - "If anything can go wrong, it will." - So true. I first heard about this law in college programming but by the end of college, it make so much sense (on many different levels)
  • Occam's Razor - "Given two equally predictive theories, choose the simpler." - Perfect example of not following this? Steve Gibson and the WMF exploit. Need I say more...
  • Hanlon's Razor - "Never attribute to malice that which can be adequately explained by stupidity. " - It is commonly said that people are the weakest security link, but why? Well this Jinx.com t-shirt says it all.
  • Parkinson's Law - "Work expands so as to fill the time available for its completion. " - Anyone that has ever worked in the corporate world, knows this is true. =)
  • Godwin's Law - "As an online discussion grows longer, the probability of a comparison involving Nazis or Hitler approaches one." - Anyone that has watched a security mailing list has seen this happen right in front of their eyes.
  • Amara's Law - "We tend to overestimate the effect of a technology in the short run and underestimate the effect in the long run. " - Happens all the time.

I am sure there are more floating around the internet today. Anyone have any to add??

Fyodor on Nmap 4.00

Great Fyodor interview over at SecurityFocus. He goes over several of the new features in detail. Very good read for those that love Nmap.

Former SoC student Zhao Lei is working on the second generation of OS detection, which will use many new tricks. Nmap 4.00 uses application heuristics along with TCP/IP fingerprinting. Cool improvement.

Tuesday, January 31, 2006

Microsoft Internet Explorer 7 Beta 2 Released

Internet Explorer 7 Pre-Release Beta 2 is open to the public. Come and get it.

It only works on Windows XP SP2 and some say it looks & feels alot like Firefox.

BetaNews.com has a write-up on the new public IE7.

Updated Security Tools - Ephedra Free

1) Nmap v4.0 was released over at Insecure.org today.

The changelog reports one change from v3.9999 -
  • Added the '?' command to the runtime interaction system. It prints a list of accepted commands. Thanks to Andrew Lutomirski (luto(a)myrealbox.com) for the patch.

2) The password cracker known by all as John the Ripper was updated to v1.7 recently. Claims of significant performance increases are along improvements in the changelog.

3) The brute-force login hacker, Hydra, was updated to v5.2 on Jan 27th. It includes fixes for the SSH2 module and a new "VMWare-Auth" module. That should be interesting to test.

4) Cain & Abel was updated to v2.8.4 on Jan 19th as well. New features include:

  • Rainbowcrack-Online client - The client has been developed in collaboration with Rainbowcrack-Online team. Cain can now interact with the outstanding power of this on-line cracking service based on RainbowTable technology. The service is not free and you need a valid account to use this feature, please check current rates on their site. The communication between Cain and the web site is SSL enabled to ensure privacy of transmitted information.
  • Oracle Password Cracker (Dictionary and Brute-Force Attacks).
  • Oracle Password Extractor via ODBC.
  • MySQL Password Extractor via ODBC.

Monday, January 30, 2006

OS X for Intel 10.4.4 Leaked

The news was released on the OSX86 Project today. I am not a Apple user but I believe 10.4.4 is the highest Intel OS X released to developers.

Of course, 10.4.5 was released to developers recently but it was for the PowerPC chip only, I believe. I could be wrong however.

Apple was smart to get the hacking geeks on their side...but it is a paradox box. Hacking geeks that want Apple on intel will get it...TPM or not.

Nmap 3.9999 - Runtime Interaction Feature

On Friday, I was asked to port scan a new server at work. Cool, portscans are always fun. I knew I had Nmap 3.95 on my laptop, but I jumped over to Insecure.org to make sure I still had the "latest and greatest"...well I didn't.

Checking out the changelog, I found a very cool feature introduced in 3.98 BETA1. It is called "Runtime Interaction". Yep, the name basically sums it up. This feature was created by Paul Tarjan as part of the Google Summer of Code. But initially, it only worked in the Linux/Unix version of Nmap 3.98 BETA1.

Well, Nmap 3.999 added runtime interaction support to the Windows port as well. Thanks to patches from Andrew Lutomirski and Gisle Vanem.

Then Nmap 3.9999 (that is four nines) was released. It added several minor nmap-protocols and mac-prefixes file updates over 3.999 (that is three nines).

Pretty cool. The runtime interaction feature should come in handy during large network scans. Anyways, update your ports or go directly to the source and get Nmap 3.9999

Friday, January 27, 2006

Microsoft Will Remove BlackWorm AFTER D-Day

The payload for the BlackWorm is set to activate on Feb 3rd but Microsoft isn't going to release their updated Windows Malicious Software Removal Tool until Feb 14th (Black Tuesday). Does that make any sense?

Sure, it really isn't Microsoft's job to clean worms off your computer - or is it?

Microsoft fully understands the worm at this point. They even wrote a full analysis of it. They call it a "Moderate" threat on their OneCare site as well.

Microsoft wants to make a move into the Anti-virus marketplace, right? Wouldn't this be a great chance to prove something to their possible customers?

Saving the data of thousands of people (perhaps tens of thousands) would be a good faith sign for a new comer in the AV world, would it not?

Microsoft cares about your security, seriously....as long as that caring can fall on the second Tuesday of the month (aka Black Tuesday).

Microsoft wants your money, they want your business but they can't release a tool a little early to save your data. However, normal people that just want to do good will spend all their free time protecting people they don't even know. In this case, that group was the BlackWorm Task Force.

Nice work Gadi and everyone that was involved in that underground effort.

Credit on the information dig goes to Fergie via the FunSec Mailing List.

Complacency – Still a Security Threat

You are the security administrator of a large data center. You have disabled all unnecessary services, triple-checked the firewall rules, conducted penetration tests on all active servers, written security procedures, and trained all employees on basic security ideas. You are golden right? Wrong.

One threat still remains – Complacency.

Complacency can be defined as the act of being content to a fault with one’s actions. In the information security world, it can be one of the hardest attack vectors to identify. Bleeding Snort does not have signatures on file to detect complacency and it will not show up in an event log report.

Complacency comes one from what some would call the weakest link in the security chain – people.

In simple terms, it is the difference in “doing everything you can to secure a network” and “thinking you already have”. Administrators aren’t perfect and therefore mistakes will be happen - c'est la vie. We are only human after all. But experts have warned about security complacency for years. However we never hear about the countermeasures.

I can only think of one – vigilance.

Always assume you have missed something, always watch for changes that were unexpected, stay on top of the news and emerging security threats, etc. Being vigilant should not control your every thought but it should be a layer in your thought process.

Recently, Bill Thompson over at BBC News cracked the hardened surface of this subject again in his “Mac user ‘too smug’ over security” article. He was quite surprised by the overall response of the Apple community.

Too many times, people feel they are more secure because they run _______. This is the red flag of complacency. This isn’t to say that people are wrong when they say “this operating system has a better security model (by design)” or “this operating system is more secure out of the box”. We all need to mindful no matter what OS we have on our machine.

It has always been my belief that a computer is only as secure as the person managing the box. Of course, all operating systems can be hardened beyond the default install. However, hardening servers should only be done by professionals that understand the workings of the system. If you don’t know what you are doing, you can easily harden yourself into an unscheduled DR situation. Anyone that works in the IT world knows managers don’t like unscheduled DR situations. =)

Moral of the Blog – Security is a very complex and fluid issue. Everyday, the security of a given system ebbs and flows as events on the internet unfold. Security isn’t filling in a checkbox on a requirement form or applying a single patch.

Staying vigilant is the only true countermeasure to security complacency.

Humor: Andy in Hyderabad, India

Most people know the pain of having computer problems, even IT professionals. We have all had those certain Tech Support calls that just didn't seem to really help. This great ConanO'Brien clip may give us insight into why this may happen.

Any goes to Hyderabad and causes trouble - (9MB Windows Media Vid)

Hyderabad is seen as the second "Silicon Valley" of India, after Bangalore. Hyderabad has several software technology campuses with leading companies such as Infosys, Microsoft, CSC, Oracle, Wipro, Kanbay, GE, iGate, ValueLabs, ADP, Dell, Deloitte, HSBC, SumTotal, Intergraph, Analog Devices, IBM, Keane, Baan, , Tata Consultancy Services, Amazon and Google having established centers in the city.

I love Wikipedia.

Thanks go to MW for the link.

TGIF

Thursday, January 26, 2006

Intel Macs - Get One Now or Wait?

Wired.com has a good article on just this subject.

Here are some of the reasons to wait:

1) "Most applications that run in OS X Tiger are able to run on Intel hardware via an emulation layer called Rosetta, but there are a few exceptions, spelled out in Apple's Universal Binary Programming Guidelines"

Also check out MacFixIt.com

2) "Jobs demoed Photoshop at Macworld, but conceded that the application's performance is worse under Rosetta than the speeds offered by older PowerPC hardware."

This is to be expected has that move to the Intel Chipset. Apps will be redesigned to take advantage of the Intel code, but that will take time.

3) "Almost every version of Windows requires a BIOS to launch, and Apple's Intel Macs use Intel's new extensible-firmware interface (EFI) instead, which Windows XP doesn't support. Vista supposedly will, so it might be possible by the end of the year."

Dual-Booting with Windows XP and OS X is not currently possible. But in a non-official way, this may be open to some hackers before the public. There is a contest running right now. First person to provide the steps and pictures will get a prize. That prize is currently over 7000 dollars and likely to go higher.

Tuesday, January 24, 2006

"Cleaning the Air" in Court (Fun)

I was reading the DailyDave mailing list this evening and found this little gem from Dave Aitel. After a quick Google search, I found this 2004 article over at SFGate.com

In February 2002, Consumer Reports published a lengthy article reviewing 16
different air purifiers. It placed the Ionic Breeze Quadra model at the bottom of its rankings, saying the device produced "no measurable reduction in airborne particles."

Consumer Reports ran a second article on purifiers in October 2003. Once
again, Ionic Breeze ended up near the bottom of the magazine's rankings.

Fun stuff. Not only does it not clean the air it produces high level of ozone.

In May 2005, Consumer Reports reported new finings that the Ionic Breeze Quadra S1737 SNX and four competing devices emitted excessive amounts of ozone that could cause respiratory difficulty when operated close to the user.

Wednesday, January 18, 2006

The Fight for Internet Neutrality Principles

Wikipedia defines Network Neutrality as the following:
Network neutrality is a principle of internet regulation with particular relevance to the regulation of broadband. It suggests that (1) to maximize human welfare, information networks ought be as neutral as possible between various uses or applications, and (2) if necessary, government ought to intervene to promote or preserve the neutrality of the network. Underlying the theory of the benefits of network neutrality is a belief that a neutral network promotes Schumpterian, or evolutionary innovation of information technology.

Sounds good eh? Well not everyone likes the sound of it.

BellSouth has talked about plans for a while to charge service providers extra for premium network usage. For example, Yahoo could pay BellSouth to make Yahoo Mail load up faster than Google Mail, or Microsoft could pay BellSouth to make MSN Search give results faster than Google Search - you get the idea.

Many in the IT world feel this new plan is direct more toward VoIP but who knows for sure and how really want to wait and find out. Opponents of this new plan as a power grab attempt by the major telephone companies, since most of them passed up the idea of the internet in the beginning.

Right now there is a piece of legislation at the U.S house of Representatives that connects directly with this "network neutrality" issue. Google believe this new legislation needs to be modified to protect the idea of neutrality for the internet.

Jeff Pulver, the man behind the company that is now called Vonage, even called for a Google and others to start a BellSouth Boycott yesterday.

Blogs and media sources have exploded in a new round of pay-for-QOS stories.
Silicon Valley.com Blog
Techdirt.com
MSNBC.com
CNNMoney.com

In response to this round of media noise, three consumer groups repeated today calls for a U.S law to prevent broadband providers from blocking or slowing customer access to some internet content by saying the public wants government protection.

"If we're not careful, we'll miss signs that there are threats to openness that makes the Internet so great," said Michael J. Copps, a Democrat on the U.S. Federal Communications Commission (FCC), speaking at the consumer groups' press conference. "The more concentrated that our [broadband] providers become, the more they have the ability, and possibly even the incentive, to act as Internet gatekeepers.

Google responded today with support for the neutrality principles in the NetworkingPipeline Blog.

Google's Barry Schnitt told Paul in an email: "Google is not discussing sharing of the costs of broadband networks with any carrier. We believe consumers are already paying to support broadband access to the Internet through subscription fees and, as a result, consumers should have the freedom to use this connection without limitations."

Tuesday, January 17, 2006

FSF Releases Draft of GPL v3

The Free Software Foundation (FSF) has released a draft of the GNU General Public License (GPL) Version 3.

One of the more interesting provision focuses on GPL software in DRM software. It prevents GPL-licensed software from being used in DRM copy-protection software.

"We are trying to do what we can, in a limited way, to use the freedoms that our licence gives us to actively work against the spread of DRM restrictions," said Eben Moglen, an FSF board member and one of the authors of the draft.

This provision was most likely set into stone after Sebastian Porst discovered LPGL code from the LAME project, mpglib and VideoLAN in the F4I code used in Sony's XCP software.

Monday, January 16, 2006

When Breakfast Shacks and Wifi Clash

Pretty cool story about how a small group of people found a connection between Starbucks new test ovens and their T-mobile wireless internet woes.

http://www.tmobiledoesntworkatstarbucks.org/

I have seen similar issues at my local starbucks, but it isn't every couple of mins.

New Security Tools - Now with Taurine!

Two updated tools were released on Sunday.

1) Paros Proxy 3.2.9 - Great tool to track Web Application traffic and check web application integrity. It allows the user to not only monitor and capture all HTTP & HTTPS data passing between severs and client, but it also allow users to track and modify cookies and form fields data on the fly.

2) Metasploit Framework v3.0 Alpha 2 - The Metasploit Framework (MSF) is an advanced open-source platform for developing, testing, and using exploit code. This project initially started off as a portable network game and has evolved into a powerful tool for penetration testing, exploit development, and vulnerability research. Remember this is a Alpha release and should only be used for testing purposes.

Ok, so I made up the Taurine part. While dietary taurine can be found in shellfish and organ meats like liver, I enjoy the primary taurine source of ubergeeks - Redbull.

Saturday, January 14, 2006

Open Source WMF Patch for Windows 98SE

As many of you know, Microsoft has decided not to release an official patch for the SetAbortProc() WMF flaw. Systems before Windows 2000 are not exploitable directly by default; therefore MS doesn’t see it as a critical security problem. It is also a great way for them to push users into upgrades however, but that is another issue all together. Lack of real security should be enough to force users into a move away from the Win9x kernel.

Microsoft has stated that they will only release really critical security patches for the Win9x platform until June 30 of this year.

But not everyone is happy about seeing this possible security risk before them. Open Source to the rescue. Inspired by Ilfak Guilfanov’s XP patch, Tom Walsh of the SecuriTeam blog has released his own open source WMF patch for Win9x Systems.

Nice work Tom.

Friday, January 13, 2006

The WMF Backdoor Debate

I don't believe the general press has grabbed on to this yet but there is a nice little debate happening right now on the security list. Was the WMF bug a deliberately designed backdoor into Windows?

Steve Gibson of GRC believes it might be and attempts to produce evidence on this Security Now Website.

I will let the reader decide on their own...but not everyone in the world agrees with Steve Gibson. I personally believe he may need to shave some off the top a bit. However we may never know the truth about why and how the WMF vuln was allowed to exist for so long.

Right now there is a great debate happening on Full-Disclosure and FunSec. Newer post are on the bottom.

Perhaps we can chalk it up to the today being Friday the 13th and a Full Moon.

Tuesday, January 10, 2006

Beware of Some "Antispyware"

Mark Russinovich has a great write-up on the new Antispyware Conspiracy. These so called "antispyware" products are pure danger and most of the times are far worse than the spyware they claim to find. This should be a good wake-up call to those users out there that fall for these types of tricks.

Stick to the popular and well-known products - Spysweeper, Counterspy, Ad-Aware, Microsoft Antispyware & SpyBot S&D.

Professionals also use more expert tools like HiJackThis. But due to damage that can be caused by this tools, only experienced people should go beyond the six stated above.

Dan Hubbard of Websense stated on the FunSec mailing list that they are tracking several of these fake antispyware programs at not just making you pay for nothing. Some are going a step beyond and planting keyloggers and traffic redirectors to steal credentials.

Patch Tuesday is Here

Here is what my computer just install - Windows XP SP2. This first one sounds pretty serious, going to keep eye on information connected to Kb908519

------------------------------
(KB908519) - MS06-002 - CVE-2006-0010

A vulnerability exists when viewing Embedded Web Fonts that could lead to remote code execution. Reported by eEye.

(KB902412) - MS06-003 - CVE-2006-0002

A vulnerability exists in TNEF messages that could allow remote code execution. Reported by John Heasman and Mark Litchfield of NGS Software.

The Spin Begins - Internet Explorer WMF DoS Vulnerability

Several days after the WMF DoS PoC was released, Lennart Wistrand @ Microsoft has responded on the MSRC blog.

"Lennart Wistrand here. I wanted to write a few lines about the public post made over the weekend about a new specially crafted WMF image that could potentially cause the application using the Windows Graphics Rendering Engine to crash. As it turns out, these crashes are not exploitable but are instead Windows performance issues that could cause some WMF applications to unexpectedly exit. These issues do not allow an attacker to run code or crash
the operating system. They may cause the WMF application to crash, in which case the user may restart the application and resume activity. We had previously identified these issues as part of our ongoing code maintenance and are evaluating them for inclusion in the next service pack for the affected products."

Wow. So now DoS is a performance issue. I rather Microsoft say "It isn't very dangerous yet, it isn't being exploited in the wild and we have more important issues to fix".

Important issues like:

EEYEB-20050505 - Remote Code Execution Vuln in IE and Outlook
EEYEB-20050627 - Remote Code Execution Vuln in Windows W2k-2003
EEYEB-20050801 - Remote Code Execution Vuln in Windows W2K-2003
EEYEB-20051017 - Remote Code Execution Vuln in IE and Media Player (metafile/media file??)

Let's not get into the DoS, Privilege Escalation, Security Bypass, System Access vulnerabilities listed for a wide range of Microsoft products on Secunia.

And those spoofing problems with IE that help phishers attack normal internet users.

Microsoft, you are doing better that is for sure, but the spin isn't needed. We are all adults here...

Monday, January 9, 2006

More WMF Woes for Microsoft - DOS Vulnerability - UPDATED

Symantec issued a vulnerability alert on its DeepSight Threat Management System that warns customers of multiple memory corruption vulnerabilities in the same rendering engine that Microsoft just patched (MS06-001).

As far as the information on the ground, it looks more like a DOS vulnerability at this point, but code execution should never be ruled out. Microsoft should remember this lesson from the IE flaw discovered by Benjamin Tobias in March of 2005. Once thought just to be a DoS vulnerability, it turns out that it also allows execution of arbitrary code.

Right now, it would appear that the DOS applies to Windows 98, 2000-2003 and Vista. Fine tuning of this information will occur over time however.

Moral to the story, no threat is too small to examine and take into account.

Reminds me of our ever changing road system.

At first, there are five pretty small potholes in the road. DOT comes out and fixes the biggest one, which most likely causes the most complaints and the biggest headaches. But after a while, those four other holes, grow and cause just as much problems if not more than the original.

UPDATE - It has been barely an hour from my original post. Andrey Bayora posted the following information on the FD Security Mailing list. I have no tested this WMF files at this point. Just passing the new information.

Well here is the PoC for the 2 new WMf vulnerabilities discovered by cocoruder and is not covered by MS06-001.

You can download WMF images at -http://www.securityelf.org/files/WMF-DoS.rar

UPDATE x 2 - It would seem that the first WMF flaw took Microsoft by surprise. Kevin Kean, a director in Microsoft Security Response Center (MSRC), said the following in this CNET article.

“"It is not a common buffer overflow," Kean said.”The software has a behavior that people can take advantage of. Obviously we did not intend it to be used in that way."

I was hoping Microsoft had learned that valuable lesson by now. Attackers and hackers use things all the time in a way they were not intended. This “Intending” issue is one of the core secure coding software problems.

Programmers always “intended” users to use correct data inputs and never “intend” to let the users input data over the limit of a buffer…but it happens. Part of the secure coding idea, is to look at your code and find the places were attackers could use the code in ways that were not “intended”.

On a positive node, this situation will remind Microsoft why it can not leave old code laying around. This new security push can only help in my mind. No pain, No gain.

Friday, January 6, 2006

Music DRM - Where are we now... UPDATED

Coldplay's new CD is loaded with DRM rules.

The CD has been manufactured for usage in regular CD players, but might not play in the following players:

  • Some CD players that have the capability of burning into an MP3 (such as portable players or car stereos)
  • Some CD players that posses CD-R/RW functions.
  • Blah, Blah, Blah.

Just look at the insert and you will quickly figure out that your freshly paid for CD will not play anything else a Generation 1 CD Player that has no other functions. Thank god for all these CD standards and new functions...right? Now we can't even listen to our music - which we just paid for.

Just so everyone knows, this huge list of stuff has done ZERO to stop internet trading. In this case, I saw the whole albums on BitTorrent sites almost 3 or 4 weeks before the CD was even released to stores.

So people can get it now or wait, pay and not be able to play it on their iPod, in their car or in their computer...umm...choices. =)

However in other more positive news, the EFF has sent an open letter to EMI records. In the letter published Wed, EFF urges EMI Music to publicly declare that it will not take legal action against computer security researchers who study copy-protected CDs released by record labels owned by EMI.

Basically the EFF believes that fans deserve to know whether EMI's copy-protected CDs are exposing their computers to security risks. After Sony attempted to sweep the whole XCP DRM rootkit story under the bed sheets, this sounds like a damn good idea - IMHO.

In late December, Sony BMG agreed settle to the class action over its XCP DRM rootkit. Mark Russinovich has a great blog about it as well.

One of the funny points in the agreement is that Sony BMG must provide the music on the CDs as unprotected MP3 files. Which is exactly the XCP DRM was created to stop. Ironic.

UPDATE - Paul Ferguson pointed me to a very interesting development in Sweden. A groups of students at the Viktoria Institude in Gothenburg has worked out a system of P2P music listening and sharing that runs on WiFi-enabled PDAs and allows users to actively recommend songs by pushing music to other users in the proximity. Wow.

Thursday, January 5, 2006

Official Microsoft Patch Released - MS06-001

http://www.microsoft.com/technet/security/bulletin/advance.mspx

"Microsoft announced that it would release a security update to help protect customers from exploitations of a vulnerability in the Windows Meta File (WMF) area of code in the Windows operating system on Tuesday, January 2, 2006, in response to malicious and criminal attacks on computer users that were discovered last week.

Microsoft will release the update today on Thursday, January 5, 2006, earlier than planned. "

Also, two other critical patches will be released in-band on Tuesday the 10th. Lets not forget about those and the chances that exploit could be created from those patches. If the holes are serious enough, that could be another whole problem in itself.

UPDATE - http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx - The patch is here.

Updated Microsoft Advisory for WMF

http://www.microsoft.com/technet/security/advisory/912840.mspx

The key changes are related to embedded WMF files via Office and the affected OS list. No real surprises here. They have basically just officially confirmed notes that you have seen on this blog and others.

1) Embedded WMF file in Office document are dangerous. This was known in the community.

2) Windows 9x & ME are less vulnerable to a direct OS Level attack by default, but if you are using third-party image viewers on these OSs, than it is possible you are vulnerable as well. Check with the vendor of your applications for the details.

WMF FAQ by HD Moore

The creator of the Metasploit Framework has released his own WMF FAQ. This was posted to the FD Security Mailing list this morning. Good information.

---------------------------------------------------

Q) Why did you release an IDS and AV evading exploit module so soon after the vulnerability was discovered?

A) The vulnerability was being exploited, in the wild, for at least two weeks (based on email reports) prior to the original BT post. The WMF structure is widely documented. The AV vendors were providing less-than-capable signatures for no reason other than that no public code was available that demonstrated alternate encodings. The IDS vendors were (and some still are) providing signatures that couldn't survive a single legal byte change in the WMF header. The release of a "polymorphic" (not) exploit forced the vendors to either fix their products or cry "irresponsibility" and give up. IPS vendors realized how SOL they are wrt to client-side HTTP attacks (so many encodings, so many ways to DoS an IPS that tries to decode them).

Q) The Windows Meta File format has a number of optional headers, can any of these be used to trigger the arbitrary code execution flaw via SetAbortProc?

A) No. The CLP headers (16 bit and 32 bit) cause the Picture and Fax Viewer (PFV) and Internet Explorer to throw an error when trying to render the image. Internet Explorer will only display an image internally if the "placeable" header has been prepend to the bare WMF header. If the "placeable" header exists, a device context check will fail during the call to Escape() and the SetAbortProc() function is not reached. This effectively prevents IE or the PFV from executing the SetAbortProc() call when any optional header has been prepended. This may not hold true for Explorer's preview and icon view.

Q) What about the Enhanced Meta File format? Does this format allow access to the exploitable function?

A) No. The EMF format has a separate API (which may or may not have its own problems), but it does not allow access to the WMF Escape() function. A WMF file can be delivered with the EMF extension however, which will cause it to be processed with the vulnerable API.

Q) Are there any other ways to obtain code execution besides via WMF files viewed by PFV or Explorer?

A) Yes. Any application that accepts WMF files and calls PlayMetaFile with the supplied data can be exploited. Some of these only recognize WMF files with the placeable header, which may prevent the application from reaching the SetAbortProc function. There are *many* other places where standard (ie. included with the OS) applications call the PlayMetaFile function, its just a matter of figuring out which ones can be used to deliver the malicious WMF content. A potential vector includes the display of icons stored inside of a standard executable. Viewing these files in an Explorer directory listing could result in the execution of code in an embedded WMF file. This has yet to be tested.

Q) What WMF header fields are mandatory for code execution through the PFV ?

A) Not many. The Windows Meta File header and possible field values are listed below:

# Possible values: 1 or 2 (memory or disk) WORD FileType

# The HeaderSize must always be 9
WORD HeaderSize;

# The Version field can be 0x0300 or 0x0100 WORD Version

# This parameter can be anywhere from 0x20 to 0xffffffff DWORD FileSize

# Completely arbitrary
WORD NumOfObjects

# Completely arbitrary
DWORD MaxRecordSize

# Completely arbitrary
WORD NumOfParams

The MSB of the actual MetaFileRecord function field is completely ignored.

Credits: A number of anonymous sources contributed to this information.

More information on the WMF structure can be found at the following sites:
- http://wvware.sourceforge.net/caolan/ora-wmf.html
- http://www.geocad.ru/new/site/Formats/Graphics/wmf/wmf.txt

-HD

Wednesday, January 4, 2006

Upcoming Sober Threat - Friday, Jan 6th

It is highly possible they will we see a new Sober variant this Friday.

The first Sober Worm appeared in October 2003, but now the word "Sober" has turned into a huge series of variants.

AV vendors don't use common names, so it is normally pretty hard for normal people to cross reference Sober variants. We are at Sober.Y, or is it Sober.AH? Who knows, just know that they are dangerous. =)

Algorithm-Based URL

Many of the sober variants contain a very complex algorithm that is used to compute the next series of download URLs.

LURHQ has a great write-up on the date algorithm.

You heard Jan5th right? So did I. But LURHQ reports that the branch logic points to Jan 6th.

"Note that the "begin update" logic in the current variant is actually "current date > Jan 5", not "current date == Jan 5", so the update other sources are saying will occur on Jan 5, 2006 won't actually happen until Jan 6, 2006. "

Keep your eyes open this friday for strange e-mails and keep your ears on all the AV news.

Advanced "Keep-alive" Tricks

Most Sober variants have been shown to deactivate many popular antivirus packages, including Microsoft AntiSpyware and HijackThis.

When it gets in, it is pretty hard to remove. Booting on a Linux disc and cleaning the infected disk sounds like a good idea however.

Mass-Mailing MO

Most Sober variants have their own SMTP engines and generate large amounts of e-mail traffic. Sober uses e-mail generation as a method to spread.

But how can e-mail spreading still be effective?? People have been told not to click on unknown links, don’t open e-mail from strange people…delete, delete.

Sober is the king of using Social Engineering (SE) attacks in mass e-mails however. Sober.X included real looking messages from the CIA, the FBI and the German Bundeskriminalamat (BKA).

An alleged child porn offender even turned himself in to the police after receiving one of these Sober e-mails.

History / Political Motivations

One Sober variant sent messages of support for the far-right groups in Germany pending the local elections in the state of North-Rhine Westphalia. Some groups see connections between Sober Key dates and important days in history. WW2, Battles in German, Nazi party, etc, etc.

Are these motivations true or just a smart SE attack? Who knows...and in the sense of security, I don’t care.

Summary

1) Watch your e-mail servers tomorrow. It is possible they we will see a huge flux of e-mails generated by this “Sober update code”.

2) Block the known update sites listed in this F-Secure blog entry.

3) Make sure you e-mail gateway AV is up-to-date and stays that way. Double check AV on your endpoints and make sure it is updating as well.

3) Remember the Sober creator (or group) aren’t stupid and most likely aren’t very poor either.

As that old NSA saying goes: “Attacks always get better, they never get worse.”

WMF - Six Days Til Checkered Flag

Information comes in as fast as Le Mans racers sometimes. Here is an update.

1) A pre-release "official" Microsoft patch was leaked from Redmond it would seems. People have tested it and it has caused many problems. BSOD, etc. So even if it is an "official" leak, it will break stuff. Don't mess with it.

2) The "patch" by Ilfak Guilfanov has been supported by many big groups (F-Secure, SANS, etc) but it isn't perfect. It would appear that some printing problems could occur. The GDI32.dll file is used commonly in Postscript printing, it would seem.

Administrators should NEVER push patches to large groups of computer without extensive and proper testing. This goes for ANY program (fix, patch, new program, update, upgrade, workarounds - whatever). Home-grown or official.

3) Take everything with a gain of Sodium Chloride (NaCl). The general media is great at taking any story and hyping it up. The WMF threat is real and it is dangerous, but it isn’t a RPC Buffer overflow. Remember Blaster & Sasser.

A freshly installed, up-to-date computer can not get infected without some form of user interaction. True, this interaction is small and likely to happen - if you plan on using your new shiny computer. =) Remember the ILOVE & Melissa viruses.

In the defense of the media however, most hype does start from inside the computer community itself. Professional that spend all days looking in the dark corners of the world for bad guys, will always see a threat like this as serious. The exploit code is everywhere, people do do whatever they want with it and post it everywhere, it is serious for corporate security professionals. They get paid to protect corporate assets and every threat must be battled. This fight isn't as direct in the home user world....

Sometimes hype is playing it safe...sometimes hype is good for selling products. Whatever you call it, hype brings security issues to the front page..which is something that is needed.

4) IMHO, home users are in much more danger than big corporate users. Most large companies have multiple defense systems and can reduce the WMF threat greatly without applying the suggested workarounds. Home users on the other hand, tend to be less informed and tend to already have a lot of “bad” stuff on their computers. Home users always want free e-mail smiley faces and free wallpapers and all the programs that could cause a security issue for large companies.

So in the end, practice safe hex, be prepared to battle any infection beyond the WMF and wait for Microsoft to release their patch on Tuesday.

Network and Security Professionals may want the extra protect of applying IIfak’s patch. Go ahead use it. All my home computers have it and my work laptop, but with multiple defense layers in place here at the office, I don’t see a huge need to push it out like its MS03-039.

Tuesday, January 3, 2006

Revision in WMF Vulerable Operating Systems - UPDATED

Larry Seltzer of eWeek reported on his weblog that only Windows XP and Windows Server 2003 are vulnerable in a practical sense.

It is true that this vulnerability is in GDI32.dll all the way back to Windows 3.0, but it would appear that Microsoft never set up WMF assocation before Windows XP. Therefore in older systems (Windows 2000/Me/98), the hole is there but much less of a direct threat.

It would seem that F-Secure and iDefense also agree with on this point.

Hopefully Microsoft will come out of the fog and start to see that allowing everything in the OS to run code by design isn't a good thing.

On a side note, HexBlog was taken down by its ISP for a short due to huge traffic flows. It would seem that Hexblog was slashdotted or dugg. =)

UPDATE - Alex Eckelberry of SunBelt has provided alternative download points for both the unofficial patch and checker.

UPDATE x 2 - Since high traffic make the ISP cut off Ilak's HexBlog. CastleCops has stepped up and offered him a home for now. See the new Hexblog forum.

Metasploit isn't a Virus

Richard M. Smith posted a rather funny message to the FunSec Mailing list this evening.
------------------------------------------
http://online.wsj.com/article/SB113630873566736620.html?mod=yahoo_hs&ru=yahoo

Microsoft Readies Fix As New Virus Spreads
By CHRIS REITER DOW JONES NEWSWIRES
January 3, 2006 1:20 p.m.

Microsoft Corp. plans to release on Jan. 10 a patch for a new Windows security flaw that is being exploited by a rapidly spreading computer virus strain known as "metasploit."

The virus surfaced last week as hackers took advantage of a flaw found in current server and desktop versions of Windows. It is considered serious because it requires relatively minor user interaction to be unleashed. The virus is carried in picture files and can be triggered if an image is viewed in an email or on an infected Web site.
---------------------------------------------

How could they be so wrong? Metasploit (MSF) isn't a virus, it is a tool (a pretty good tool IMHO). This tool does contain exploits that could be used combined with a payload to create a virus.

A tool is neither good nor bad, just like a knife itself is neither good nor bad. Tools are static; actions decide how the tool is viewed in most cases.

In court, a knife is seen as a "deadly weapon" but on Food TV, a knife is seen as an essential piece of equipment that no kitchen would dare be without.

Hopefully someone will point out the mistake to the WSJ. Metasploit is a very invaluable tool and it is sad to see its name misused this way.

When will WSJ report on the "PacketStorm" virus?? lol

Microsoft to Release Official WMF Patch on 10th

Updated Microsoft Security Advisory (912840) - Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution

"Microsoft has completed development of the security update for the vulnerability. The security update is now being localized and tested to ensure quality and application compatibility. Microsoft’s goal is to release the update on Tuesday, January 10, 2006, as part of its monthly release of security bulletins. This release is predicated on successful completion of quality testing."

What is Microsoft's response to Ilfak Guilfanov's Patch??

"Microsoft recommends that customers download and deploy the security update for the WMF vulnerability that we are targeting for release on January 10, 2006.As a general rule, it is a best practice to utilize security updates for software vulnerabilities from the original vendor of the software. With Microsoft software, Microsoft carefully reviews and tests security updates to ensure that they are of high quality and have been evaluated thoroughly for application compatibility. In addition, Microsoft’s security updates are offered in 23 languages for all affected versions of the software simultaneously.Microsoft cannot provide similar assurance for independent third party security updates."

No real suprise. It isn't their patch so that was exepcted. No big deal.

I am still using Ilfak's patch and will leave it in place until next week - 10th.