Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Sunday, June 4, 2006
eBay Raises the Stakes on Net Neutrality with E-mail
Forwarded message:
As you know, I almost never reach out to you personally with a request to getinvolved in a debate in the U.S. Congress. However, today I feel I must.
Right now, the telephone and cable companies in control of Internet accessare trying to use their enormous political muscle to dramatically change theInternet. It might be hard to believe, but lawmakers in Washington are seriouslydebating whether consumers should be free to use the Internet as they want inthe future.
The phone and cable companies now control more than 95% of all Internetaccess. These large corporations are spending millions of dollars to promote legislation that would divide the Internet into a two-tiered system.
The top tier would be a "Pay-to-Play" high-speed toll-road restricted to onlythe largest companies that can afford to pay high fees for preferentialaccess to the Net.
The bottom tier -- the slow lane -- would be what is left for everyone else.If the fast lane is the information "super-highway," the slow lane will operate more like a dirt road.
Today's Internet is an incredible open marketplace for goods, services, information and ideas. We can't give that up. A two lane system will restrict innovation because start-ups and small companies -- the companies that can't afford the high fees -- will be unable to succeed, and we'll lose out on the jobs, creativity and inspiration that come with them.
The power belongs with Internet users, not the big phone and cable companies.
Let's use that power to send as many messages as possible to our electedofficials in Washington.
Please join me by clicking here right now to send amessage to your representatives in Congress before it is too late. You can make thedifference.
Thank you for reading this note. I hope you'll make your voice heard today.
Sincerely,
Meg Whitman
President and CEO
eBay Inc.
P.S. If you have any questions about this issue, please contact us at government_relations@ebay.com.
-------------------------------------------------
Hopefully, this is real...
Fun: My Encrypted Life v0.7
The everyday elements of understanding life are there in plain view for all to see, but are beyond the mental capacity of the majority - including me.
The output of life is directly related to input fed into it, just like an algorithm. Each person puts in a unique input and consequently receives unique output. However, once in a blue moon, two distinct inputs into life produce identical outputs resulting in a collision. A collision of the mind or of the bodies.
Some people get the output they want, others do not.
-Technocrat
--------------------------------------------------------
This blog is a direct result of my failed attempt to depress my central nervous system on a Saturday night.
Killing off my excessive neurons and glial cells with fine imported ethanol could have stopped this from happening.
Don't ask me why it is subversion 7 when it is really the first instance of the creation. =)
Demonstration held in response to the raid on The Pirate Bay
Demonstration in Stockholm. A one hour demonstration was held today in response to the raid on The Pirate Bay, Piratbyrån and more on May the 31:th, where over 100 servers were seized. This without any proven criminal offence.
The demands of the demonstration were that the Swedish goverment, instead of criminalizing more than one million of their citizens should seek a compromise in the issue.The organizers were Piratpartiet, Piratbyrån, Grön ungdom, Liberala Ungdomsförbundet and Ung vänster.
---------------------------
When this story first broke, it was rumored that the raid's true target was Piratbyran and not Pirate Bay itself. Piratebyran is the communtiy board of the group, I do believe.
Anyone heard this as well?
Something about the Swedish government attempt to silence certain groups.
Video games seized from Teen’s home
West Feliciana Parish Sheriffs Capt. Spence Dilworth said deputies seized several video games rated M for Mature from the residence of Kurt Edward Neher, 16, but the detective said he is not drawing any conclusions from his findings.
I think it goes beyond video games, but whos to say? Dilworth said of the slaying of Michael Gore, 55, of 10077 La. 421, St. Francisville.
--------------------------------------------
This is just silly. Now I don't really know if the kid did it or not...and it really doesn't matter. The problem isn't the video games; it is the kid and his environment.
While I love science, it is inherently flawed. People look at violent kids and see their video games as the cause. I have an idea...what if the game video is really just an outward sign of the inner problem?
So, I say this.
Do "M" rated games make people kill other people? No, of course not.
Are violent people instinctually pulled toward violent games? Yes, of course.
So, what the hell does grabbing games do toward fixing the problem?
In my mind, nothing. But maybe I am wrong...
Saturday, June 3, 2006
In the Terror News....
The article doesn't say which chemical weapon was possibly produced there, but I would guess they were talking about Ricin. Again I have no proof of that. Just a guess since it was found to be produced by other people in the UK.
Today, it appears that Canada has arrested 17 people in a terror raid of its own. Weapons, radios and large quantities (3 tons) of ammonium nitrate were found.
Pirate Bay is Back! Now Named Police Bay
It is now being hosted in the Netherlands - Holland most likely.
At the same time, music companies are getting a backlash via defacement attacks. Turkish hackers have defaced several Sony websites. Is this payback for Pirate Bay or the DRM?
Who knows....
Police will not Pursue Ransom Hackers
Greater Manchester Police (GMP) will not be pursuing the criminals who used a Trojan horse program to lock a Manchester woman's files and demanded a ransom to release them.
The malicious Archiveus program was unintentionally downloaded by Helen Barrow of Rochdale, who found it locked her files into a 30-character password-protected folder. A ransom note instructed her to avoid going to the police, and buy pharmaceutical products online to gain the password to release her files.
Barrow did not pay, and managed to recover some data. The police, however, will not be investigating the crime.
"We aren't investigating the incident as it's an Internet crime, and not within the GMP area — technically it's international," a spokeswoman for GMP told ZDNet UK.
"Trying to find who did this it would be a monumental task," a spokeswoman for GMP told Out-Law.com.
-------------------------------------------------So basically the police are saying that fighting this type of crime would be too hard? I agree that a local area police force is most likely not equipped to deal with the overall international threat....but isn't someone?
There has to be some group in the world that can look into this. If there isn't yet, there really should be. Seriously. Of course I understand the problems with fighting internet-based crime. If we roll over and let them know that we aren't going to do ANYTHING will only drive them to do more of it.
What can we do? International cyber threats are very hard to fight. It has many of the same traits of normal terrorism. People are protected by the country they live in. Protected by people with guns, rooted into a protective culture - almost untouchable. Sometime protected by law even.
The attackers don't have to worry about laws or rules...they can operate without worry. But the protectors have tons of rules, steps to watch.
It is like fighting your own shadow with both hands behind your back....
Friday, June 2, 2006
Pirate Bay Story: Hackers Hit Swedish Police Site
Cyber vandals have attacked the website of the Swedish police, forcing it to shut down.
Police said the site was taken offline after it was overloaded by net data.
The attack came a day after the police raided several locations linked to a website accused of directing users to pirated films, music and software.
ThePirateBay.org had described itself as the largest search index for BitTorrent, a system used for sharing large files over the internet.
The entertainment industry welcomed the action against a site it argued was a major source of music and film piracy.
-------------------------------------
My previous post on the issue stated that the Swedish government had a hand in the take down. At this point that isn't known for sure - but the police force was involved.
There also have been reports that Pirate Bay may be back up in the near future, but this time it would be hosted in a non-EU nation. Again, this are only rumors at this point.
Keep your ears open for more news on this one.
Disappearing Data: The Ernst & Young Plot Thickens
Well the plot thickens. The Register is reporting that Ernst & Young lost information on 243,000 Hotels.com customers as well. Is it the same laptop? No one knows at this point, but I am leaning toward that idea.
Mozilla Firefox and Thunderbird 1.5.0.4 Released
Secunia has the details on the critical vulnerabilities released for both Firefox and Thunderbird.
Mozilla has released 1.5.0.4 to counter these vulnerabilities.
Thursday, June 1, 2006
Tools of the Trade - New and Updated
1) Yesterday the Openwall Project released John the Ripper Pro. It is currently available for Linux on x86 processors, with support for the latest Intel and AMD process features such as SSE2.
The features currently specific to the Pro versions are:
- Pre-built and well-tested native package (RPM) which may be installed with a single command - no need to compile
- Automatic detection of processor architecture extensions such as SSE2 and MMX for much faster processing, with transparent fallback on older CPUs
- A large multilingual wordlist optimized specifically for use with John the Ripper (4,106,923 entries, 43 MB uncompressed) is included in the package, and John the Ripper is pre-configured for its use
- The included documentation is revised to be specific for the given package and OS rather than generic, making it easier to understand
As a bonus, the full source code sufficient to rebuild the package is also provided (can be downloaded separately)
2) On May 23th, Metasploit v2.6 was released. This relese includes 43 more exploits, numerous bug fixes, improvements to the SMB/DCERPC layers and a few cosmetic changes.
3) On May 22th, Cain & Abel v2.9 was released.
New features include:
- Added Ophcrack's RainbowTables support for LM Hashes Cryptanalysis attack.
- Added hashes syncronization functions (Export/Import) to/from Cain for PocketPC via ActiveSync.
- Added VoIP sniffer support for the following codecs: G723.1, G726-16, G726-24, G726-32, G726-40, LPC-10.
- Added support for Winpcap v3.2.
4) Paros Attack Proxy has been updated to v3.2.12.
New Features include:
- Use newest external library for HTTP handling.
- enable/disable spider to POST forms in options panel to avoid generating unwanted traffic (default to enable). This is requested by many users.
- Decrease the number of possible combinations crawled by spider on forms with multiple SELECT/OPTIONS. This make crawling less resource consuming and lower chance to affect application being scanned.
- Minor UI changes.
Fixes include:
- Fallback database library to previous version as in Paros 3.2.10 because of a problem with hsqldb where some byte combination may consume 100% cpu time.
- Increase width of method display in history to cater for other longer method names.
- Default file scans may display incorrect HTTP message body if the original message is a POST request.
5) FileZilla 2.2.24a was released recently.
Personal Data of 1.3 million Borrowers Lost
Texas Guaranteed Student Loan Corp. said a contractor has lost a piece of equipment containing the names and Social Security numbers of 1.3 million borrowers.
But there is no evidence, the company stressed Wednesday, that the information has been misused.
The loss occurred May 24, but Texas Guaranteed didn't find out about it until Friday. It then spent the Memorial Day weekend identifying whose information was on the missing equipment. "It was not a security breach where someone hacked into our system," said Sue McMillin, Texas Guaranteed's president and chief executive. "At this point, we are not aware of any impact."
Round Rock-based Texas Guaranteed said it had sent encrypted electronic files containing the names and Social Security numbers to an office for Toronto-based Hummingbird Ltd., which helps companies manage large amounts of information. No other personal information was sent, Texas Guaranteed officials said.
A Hummingbird employee downloaded, decrypted and stored the files on a piece of equipment that was later lost. The companies declined to elaborate on what the equipment was, where it was lost or what specific law-enforcement authorities were notified other than to say it was local police in a U.S. city.
"I don't want to give out any information that could make it easier for anybody to do anything," Hummingbird President and chief executive Barry Litwin said. But, he added, it is "extremely unlikely" for the information to be used inappropriately because it is password-protected "many times over."
So the data is not encrypted but password protected? By what? The Windows XP login password? I love how the media always stresses how the information hasn't been used in bad way, instead of talking about what they are going to do to prevent it in the future. It doesn't make me feel comfortable to hear, "At this point, we are not aware of any impact."
Wait, I am aware of a couple impacts.
1) You lost the personal information on over million people.
2) Smart ID crooks are just going to wait 6 months before using the information. By this time you aren't watching and the customer is no longer watching. So saying that there is no bad activity at this point is just silly.
I will agree that most lost laptop cases do not result in massive ID crimes. Perhaps the thief just wants the quick money for the physical equipment. If this has been the case up to now, then we should call it luck.
Because real crooks with serious information security understanding can pull off a grab job like this in their sleep and then eat your account dry before you know what hit you.
Wednesday, May 31, 2006
Swedish Government Shuts Down "The Pirate Bay"
In the morning of 2006-05-31 the Swedish National Criminal Police showed a search warrant to RixPort80 personnell. The warrant was valid for all datacentres of RixPort80 and was directed at The Pirate Bay. The allegation was breach of copy-right law, alternatively assisting breach of copy-right law.
I suppose it was only a matter of time.....
Stardust: OpenOffice PoC Virus
Check this SF article for more details.
An unknown virus writer has created the first macro virus that targets computers running the alternative word processors OpenOffice and StarOffice, antivirus firm Kaspersky Labs said on Tuesday.
The virus, which Kaspersky called StarOffice.Stardust.A on its Viruslist blog, is written in StarBasic, a variant of the BASIC programming language designed for scripting common functions in the StarOffice and OpenOffice word processors. While the virus attempts to spread to computers through OpenOffice and StarOffice, Kaspersky called the functionality theoretical.
Tuesday, May 30, 2006
Fun: Recently Unearthed E-Mail Reveals What Life Was Like In 1995
Sunday, May 28, 2006
THC Courts Phone Hackers
Posted on THC.org by DerSteppenwolf :
THC is the world's first group to release ROM images and memory maps from Nokia Mobile Phones. This is an invitation for Reverse Engineers and hackers to discover hidden secrets and backdoors on mobile phones.
http://thc.org/thc-rom/
The Perfect Recipe for Defacement
It appears that Turkey as a whole isn't letting up on the defacements. They can account for over half of all the defacements tracked by Zone-H.org - taking the spot from Brazil just recently.
Recent Turkish Defacements
aLpTurkTegin - http://woodlandsperfumers.com/
SanalYargic - http://grupocastor.com.uy/portal/index.php
TurkStorm.Org - http://www.progtv.be/
yusufislam - http://gladtidingsofduluth.org/forum/
narcotic - http://upload.neuper-team.com/index.html
The list goes on and on....
The Internet Storm Center is already reporting a possible "script kiddie contest" underway. Crazy kids.
Looks like alot of the defacements are caused by PHP security issues.
Saturday, May 27, 2006
BackTrack 1.0 Final Released
If you are still using Security Auditor or WHAX, then catch up with the times and get the new BackTrack...you will be glad you did.
Apple Failed in Battle to Slient the "Media"
Charles Cooper has a great article over at CNet.com -
Hopefully Apple is making an effort to find the leaks inside, instead of just pulling the A-team of lawyers out at the drop of a hat.
Friday, May 26, 2006
Microsoft Word Unspecified Remote Code Execution - UPDATED
Most of the antispyware friends that I talked to have samples and didn't really see anything different than has already been reported. But it did take a while for everyone to get a sample, this shows just how rare it is in the wild.
I have a sample as well, but haven't had a chance to look at it. I have almost zero RCE skills, so I don't think having a sample is going to help me understand it much better.
The first attack was very limited in scope and Microsoft appears to be doing the right think and will not jump the gun to release a patch early. Some people are giving them hell about that, but I don't see a real reason for them to rush it at this point - in this exact case.
In some cases, it doesn't make sense to hold the patch until Patch Tuesday.
If the vulnerable function is known and being exploited in the public, then the patch should be released as soon as it is ready. Releasing it early in this current case, will expose the true vulnerability to groups that may not have it now, and in the end this will only increase the number of active exploits against this vector.
SANS - http://isc.sans.org/diary.php?storyid=1345
Microsoft - http://www.microsoft.com/technet/security/advisory/919637.mspx
Blah: Long Weekend
It is amazing the see how empty the Houston airport can be on a Friday night. All the shops are closed and my ice latte is all watered down now. I suppose it is time to break out the redbull and security books until my flight.
Everyone have a great holiday weekend and don't get into too much trouble.
For your weekend reading, check up on the new Norton Corporate Anti-virus hole discovered by eEye and read about this special ring-tone used by teenagers in class.
Wednesday, May 24, 2006
ScanDoo Beta - Making Searching Safe
It is called ScanDoo.
Scandoo is based on ScanSafe’s web security technology that currently scans billions of web requests for corporate employees around the world. ScanSafe software developers were often asked by their friends and family if they could protect home Internet use in the same way that they protect corporate users. When our lab came up with safe searching technology we thought it was such a good idea that we wanted to make it available to all.
When you search in Scandoo, each site is compared to the ScanSafe's database and given an icon.
- Green Check is safe
- Yellow is a warning
- Red is bad
- Black Bug is totally unsafe - known website that contains malware or evil script
This is a great idea for those people that search at work...and don't want the proxy admin at their desk ;)
Tuesday, May 23, 2006
Veterans Affairs Department- data on millions of veterans stolen
The Veterans Affairs Department today revealed that personal, identifying data for as many as 26 million American veterans was stolen from a VA employee's home in May. The information is a list of all veterans who served in the military and were discharged since 1975. A VA employee took files home as part of department work on a data collation project to simplify some VA processes. Subsequently, someone broke into the employee’s home and stole the data. The career employee, a data analyst, was not authorized to take the files home, said VA secretary Jim Nicholson in a teleconference with reporters. He would not say what form the data was in.
I am going to guess and say CSV. ;)
In light of this news, William Jackson wrote a pretty good little article over at GCN.com as well. It is just a reminder that we aren't just holding a PC in our hands, we are holding data that other people might want.
Sunday, May 21, 2006
Google Summer of Code 2006
While it is impossible to talk about all the possible projects, here are a couple of ideas from a couple of the project. Remember, these are just ideas. Students are welcome to submit original ideas and we will see some of those when the dust settles.
Apache SoC 2006
Mozilla SoC 2006
FreeBSD SoC 2006
My coding skillz are very very far from Kung Foo level, but I just might apply for this project idea suggested for Nmap SoC 2006:
------------------------
Slacker
Nmap developers are known as some of the most productive in the open source world. In order to crank out more code, many eschew luxuries like classes, social lives, sex, and sleep. To counterbalance all of this planned productivity, we may need some experienced slackers to spend the summer playing video games, watching TV, reading Slashdot, and dating. You will report these activities in a weekly status report so the rest of us can live our lives vicariously through yours.
Since lazyness is a virtue for this position, our normal application form is not required. Just tell us your best time-wasting story or any other relevant credentials for this critical role.
------------------------
In 2005, there were around 43 mentoring groups signed up for the Summer of Code.
This year they have over 100.
This fall, we should see a ton of great enchancements and new features created by the community for the community. Open source, it is a good thing....
Saturday, May 20, 2006
New Computer Laws - Are they too Broad?
There are hard questions and I don't have all the answer, but here are same of my thoughts on the issue.
1) Dual-Edged Sword - The tricks, skills and tools of the IT security world are commonly called dual-edged swords. Security tools are just that - tools, no different than a gun, a sword, a hammer or a butter knife. We deal with these pretty good in the real world. Cops don't go out into the woods and arrest hunters because they are carrying shotguns. Do they? Intent and context are the true factors that give the law weight. Exploits, like guns, can be used to break into a network...but that same exploit can be used by a security network admin to find a vulnerable server on the network and as a result jump start the protection process.
2) The Grey World - For a long time, I have talked with my friends about the balance of the force in the world. People have the ability to be good or bad, tools have the ability to be used for good or bad. The world truly is Yin and Yang. I am a huge believer in maintaining the balance. Most of the governments in the world are based on the idea and will fail to function without it. If the balance is not maintained, then things start to function in ways that are not desired - Absolute power corrupts absolutely.
So how do we as a world, apply the black & white letters of the law to a world of grey? Very carefully, that is how. It is like a never ending dance...ever changing, ever shaping. What is illegal today could be legal tomorrow...and vice vera. This idea seems very simple when applied to the real world...but it becomes much more cloudy when applied to the virtual world.
We are seeing just how cloudly with these new bills:
1) Possible Update to the UK Computer Misuse Act (CMA)
2) Truth in Caller ID Act of 2006 - this one is pretty good since this trick rarely needed beyond law enforcement....that assumes I am ok with PI's tricking people..umm...I guess so.
4) UK RIP Act - forcing people to hang over encryption keys....
So how do we make objective laws that take into account subjective intent and context? That is a question for the ages, I think.
Friday, May 19, 2006
Microsoft Word Unspecified Remote Code Execution
Symantec has tagged the new backdoor as Backdoor.Ginwui. Norton detects the dropped trojan as Trojan.Mdropper.H - but this is expected to change in my view. This dropped trojan could be replaced in the future with a new altered trojan that is not detected.
Some people are using the term 0-day, but until more information is known, I don't want to use that.
Remember that Microsoft patched several Office remote code execution bugs in MS06-012.
Thursday, May 18, 2006
Fun: 48-Hour Internet Outage Plunges Nation Into Productivity
BOSTON—An Internet worm that disabled networks across the U.S. Monday and Tuesday temporarily thrust the nation into its most severe maelstrom of productivity since 1992.
"In all my years, I've never seen anything like this," said Price Stern Sloan system administrator Andrew Walton, whose effort to restore web service to his company's network was repeatedly hampered by employees busily working at their computers. "The local-access network is functioning, so people can transfer work projects to one another, but there's no e-mail, no eBay, no flaminglips.com. It's pretty much every office worker's worst nightmare."
According to Samuel Kessler, senior director at Symantec, which makes the popular Norton Antivirus software, the Internet "basically collapsed" Monday at 8:34 a.m. EST.
The Gibe-F worm, an e-mail-transmittable virus, initiated cascading server failures. Within an hour, Internet service to more than 90 percent of the U.S. was disabled, either by the worm or by network firewalls that initiated security protocols.
"Unlike SoBig or Blaster, this worm didn't harm individual computers; it just used them as a gate to attack the Internet at the ISP level," Kessler said. "Computer technicians at most offices couldn't do anything but sit by helplessly as people worked through stacks of filing, wrote business-related letters they'd put off for months, and sold record amounts of goods and services over the phone."
Wednesday, May 17, 2006
BackTrack Live CD: Pre-Release Beta Preview
After booting up and looking over the tools quickly, here is what I have.
Kernel – Linux Slax 2.6.15.6
Firefox – 1.5.0.3
Nmap – 4.03
KDE – 3.5.0

There were several tools that were not totally up-to-date, like Ethereal, but I assume there will be another tool update before the finally release. It looks like they were right in the middle of a tool upgrade, I saw several version of John the Ripper and a couple of other tools. I did notice the new Metasploit 3 Alpaha in there as well. ;)


All the normal tools are included. Anyone that has used Backtrack before knows the list is huge, so I won’t even attempt to do that, but if you haven’t see the list – check it.

The new wireless driver switcher is pretty cool as well.
Nice work to the Remote-exploit.org team and all the testers.
I have to run back to work, but look for the new release really really soon.
Apple Releases a Whopping 43 Security Updates
Apple last week released a massive security update package for their Mac OS X operating system as well as updates for the QuickTime player bundled with Mac OS X. The update fixes a number of security issues including a number of code execution vulnerabilities that could allow an attacker to compromise Mac OS X and run undesirable programs.
The update also includes fixes for Apples popular Quick Time player that could allow an attacker to use malformed media files launch denial of service attacks or compromise a users system. The update to QuickTime also improves the applications stability.
The Mac OS X update also fixes code execution vulnerabilities in AppKit, ImageIO, BOM, CFNetwork, ClamAV, CoreFoundation, Finder, FTPServer, FlashPlayer, LaunchServices, libcurl, Preview, QuickDraw and QuickTime Streaming Server.
Anyone have a breakdown on the time between fixes in the open source world and when they are fixed in OS X??
ClamAV and several of the other products are open source, and it is well known that vulnerabilities found in open source products are also found in their OS X couterparts.
This fact isn't something that Apple can afford to overlook. When open source products are patched, the details are handed to the bad guys. How long will that vulnerability exist in OS X before it is fixed??
When Spammers Hit Back
Perhaps one day, the Can-Spam Act can be used to fight the real spam problem, at this point it is just a sheet of paper in my view. Used against real companies that make mistakes, it isn't stopping PharmaMaster and others like him.
------------------------------
Starting May 2, a spammer known as PharmaMaster used a massive network of zombie computers to flood Blue Security's database servers with fake traffic and hijacked a little-known Cisco Systems router feature known as "blackhole filtering" to block anyone outside Israel from accessing Blue Security's homepage.
Blogging software provider Movable Type's hosted service, TypePad, also fell victim to PharmaMaster's bot network, after Blue Security realized that no one could reach its homepage and posted a message to its users on its old blog. Thirty minutes later, PharmaMaster started an attack that brought down thousands of blogs.
Tuesday, May 16, 2006
Myspace Phishing Attacks on the Rise

Phishing Attacks against the very popular social networking website are on the rise.
Newest one discovered - http://www[dot]myspacealbum[dot]com/.login/index.html
Abuse Contact @ the Domain has been alerted by e-mail.
This URL was passed around in a bulletin titled "CHECK OUT these old school pictures...". The bulletin was posted by a friend without his knowledge.

Malware or some type of script injection attack might be the bulletin posting vector.
But if they can send bulletins as you without your knowledge, then can install a bank info stealing trojan with a IE vulnerability. The malware or attack script could alter your profile enough that all visitors (your friends) get attacked via drive-by-install.
Within the past week, another bulletin about "party pictures" was used to spread another phishing URL.
Perhaps Myspace should use some of those ad dollars and think about getting a security@myspace email account working ;)
The collected e-mails and passwords could be used to collect more important information. Tons of people use the same password for both for multiple pages.
Lets just hope that most of the younger people don't have paypal accounts ;)
As these social network groups grow, they are now in the crosshairs to become a future attack vector.
Malware distributors can operate hidden behind the cloak of "fun harmless social interaction" and take advantage of client-side vulnerabilities via script injection - Myspace worm ring a bell.
Sun to Open Source Java
SAN FRANCISCO -- Sun Microsystems Inc. at its JavaOne conference today announced plans to open source Java, but said before it does so company officials have to be certain the move won't lead to diverging paths in the code.
Richard Green, Sun's executive vice president of software, made it absolutely clear that Java would be opened source.
Very interesting but not totally shocking. Sun already has plans to move Solaris totally into the open source model. OpenSolaris.org was opened and already has working open source OS.
In the end, it will be kinda like the Fedora project before the Fedora Foundation was created =)
Perhaps Sun sees that the open source model is the only way to stay in the fight ;)
Sunday, May 14, 2006
Fun: Happy Mothers Day
happy mothers day
Morse Code:
.... .- .--. .--. -.-- -- --- - .... . .-. ... -.. .- -.--
Leet Speak:
h4ppy m07h3r5 d4y
Hex Encoded:
68 61 70 70 79 20 6d 6f 74 68 65 72 73 20 64 61 79
Binary Encoded:
01101000 01100001 01110000 01110000 01111001 00100000 01101101 01101111 01110100 01101000 01100101 01110010 01110011 00100000 01100100 01100001 01111001
Octal Encoded:
150141160160171040155157164150145162163040144141171
Base64 Encoded:
aGFwcHkgbW90aGVycyBkYXk=
ROT13 Encoded:
unccl zbguref qnl
DES Encrypted Using the Phase "candy":
8cIWUhWVxn5iGO1OmCTuFjsC9I9eXUuF
Politicians Target Social Sites For Restrictions
"Politicians are looking for reasons to convince citizens to vote in November, and polls say suburban parents are worried about the internet. Wednesday top House Republicans announced a bill to make 'social' Web sites unreachable from schools and libraries. The bill is intended to go after MySpace, but the actual text of the legislation covers sites that let users 'create profiles' and have a 'forum' for conversations -- which would include Slashdot and many blog sites. House Speaker Dennis Hastert claims it's necessary to stop 'dangerous predators' out here on the Interweb."
I don't like the sound of that at all. Schools should have the power to block whatever you want to protect the student and their network, but this bill sounds way too wide. CNET allows a forum to talk about articles? Will that be blocked? Google has groups, will that make all of Google blocked? Slashdot itself might even be blocked.
IMHO, this will not help anything anyways. Students of this generation are very tech smart, perhaps smarter than the people that are passing the laws. Most students can bypass school proxy systems already very easily. There are whole teen groups and sites dedicated to sharing bypass information. So what is this going to do?? Really?
System Virginity Verifier (SVV) Code Released
Dave Aitel stated that he would work the code into CANVAS - so that each new node could be checked for previous pwners =) Damn cool.
BTW, Happy 30th B-day Dave.
Saturday, May 13, 2006
Fun: Today's Acquisitions
Inside Threat - Designer Virus?
I found this article over at CRN.com.au about a pretty silly virus, but there are notes in the article that point to it being a real life digital designer virus. Even if it was some kid working at BestBuy....
Interesting stuff.
Automated Malware Classification
The company unveiled its plans at the EICAR (European Institute for Computer Anti-Virus Research) conference in Hamburg, Germany, proposing the use of distance measure and machine learning technologies to come up with automatic classification of viruses, Trojans, spyware, rootkits and other malicious software programs.
A research paper presented by Microsoft's lead anti-virus researcher, Tony Lee, described the existing process of manual human malware analysis as "inefficient and inadequate" and suggested an ambitious method that combines runtime behavior analysis, static binary analysis and adaptable algorithms to automate classification.
See the full Microsoft white paper in .DOC form.
Thursday, May 11, 2006
Tools of the Trade - Update
They have also released a Windows setup bundle. It takes care of the Winpcap install, the registry changes and everything for you. Sig DB has increased as well. Go get it.
2) THC has updated Hydra to 5.3 - They added a HTTP form module and NTLM support for pop3, imap, smtp-auth and http-proxy. Very cool.
Brutus has a pretty advanced form module that learns the parameters from the page itself, but it lacks a directory input field for HTTP auth attacks - which is a very nice feature of Hydra.
3) Ethereal 0.99.0 was released out of development. Too many fixes to count. Check out the changelog.
Tuesday, May 9, 2006
Network Neutrality - Money Can't Buy Love
Annalee Newitz said it better than I could myself in her recent column.
Although never written into US law, this principle holds that nobody's Internet traffic should be privileged over anybody else's -- to do so would be like letting an electricity company cut a deal with GE so that only GE appliances got good current. As it turns out, the neutral network provides an excellent platform for business models that cluster at the ends of the wires: Everything from Google and eBay to ISPs and music-downloading companies are based on the idea that money is made by shooting good stuff over the wires, not by making some wires better at getting good stuff.
Well said indeed. Lets show them that no amount of money can take the internet away from us.
Ethics, Hacking and Religion
This hits upon the idea that I talk about once in a while.
Morally right does not always equal legally right; Morally wrong does not always equal legally wrong.
This is the truth that is created by applying black&white rules to a very grey world.
This article brings up a very good view that I haven't seen talked about before now. Very interesting.
I like this quote from Johnny Long - "I felt like God wasn't on the Internet."
Personally I feel we fall into the Yin/Yang world. The world of balance. But I won't go into my balance speech now. lol
Monday, May 8, 2006
Geek vs Nerds
Pundits and observers dispute the relationship of the terms nerd and geek to one another. Some view the geek as a less technically skilled nerd. Some factions maintain that "nerds" have both technical skills and social competence, whereas geeks display technical skills while socially incompetent; others hold an exactly reversed view, with geek serving as the socially competent counterpart of the socially incompetent nerd, and call themselves geeks with pride (compare Geekcorps, an organization that sends people with technical skills to developing countries to assist in computer infrastructure development). Another view is that "geeks" lack both social competency and technical skills. Arguably, a nerd is a more self-controlled sort of person, while a geek can be something of a loose cannon--or at least more awkward in an obstructive way than a nerd.
Everyone knows that geeks are way cooler than nerds....come on!
Vulnerability Disclosure - Moving Toward the Event Horizon
Why is this happening? Lets look at several points then will help paint scene:
1) More and More independent security researchers are getting into legal trouble
I won't sit here and defend people that break the law to show that a piece of software is vulnerable, but where is the line? What is breaking the law and what is not? Security researchers are normal people and like normal people, some are seen socially as good (whitehats) and some are seen socially as bad (blackhats).
Abraham Lincoln once said,
"Discourage litigation. Persuade your neighbors to compromise whenever you can. As a peacemaker the lawyer has superior opportunity of being a good man. There will still be business enough.”
2) It is easier to catch the bass, than the shark - The real evil people in the world are very hard to catch. They are smart, silent and very well organized.
Example 1 -
- Caught - Eric McCarty was arrested after indirectly reporting a vulnerability in a USC student database. He conducted the "attack" from his house and used minimal effort to "cloak" himself. He didn't sell the information to Russian or to a carding crew.
- Not Caught - For two weeks, some people "in Asia" who have been illegally accessing information on 200,000 people at the University of Texas. What are they doing with it? Who knows? Will they be caught? Very unlikely.
Example 2 -
- Caught - William Genovese A.K.A. illwill turned himself in for selling Windows source code for $40. Let’s remember, that the source code was already on P2P and anyone could download it at that point. He did break the law by selling it, no contest with that...but he didn't steal it. It is clear that his punishment was based on past events.
- Not Caught - The person that really stole the code. I guess Microsoft wasn't on the FD security list in 2004. Where are these guys? Microsoft isn't after the real people? It is funny how they fail to note that illwill didn't sell the code when they talk about the arrest in the press. SecurityFocus is one of the few articles that showed the other side.
3) Money moves the world - Even if independent researchers do find problems in Microsoft products, what do they get? They could just pass the vulnerability information on to a third-party and perhaps get a little money out of the deal. What is wrong with that? At least Mozilla gives something back to researchers that report security problems.
4) Big Vendors are hiding vulnerability information - Apple and Microsoft fix more vulnerabilities than are commonly known. They secretly fix security problems in patches and never tell you. But once the patches are released, the bad guys know about these unreported security issues. IDS are slow to catch these issues, because of the reverse engineering time needed to provide protection.
In the end, this all adds up to the public being exposed to less and less vulnerability information.
Sunday, May 7, 2006
Pfizer accused of testing drug on children
A panel of Nigerian medical experts has concluded that the world's largest pharmaceutical company, Pfizer, violated international law by testing an unapproved drug on children with brain infections at a field hospital.
Real Life "Constant Gardener" anyone?
CCTV Planning Documentary on Fall of America
Via the China Confidential Blog -
A China Central Television (CCTV) unit is developing an epic, fall-of-Rome-flavored documentary TV series around the theme of America in decline.
Unlike the crude state-sponsored videos that glorified the September 11 terrorist attacks as a humiliating strike against an arrogant superpower, the planned multipart production promises to be a slick dissection of American economic and military might.
Production notes for the CCTV series, which is tentatively scheduled to air in 2007, are said to provide a revealing glimpse of how certain government officials see the US--namely, as a dying hegemon. The Chinese view is that a number of factors, including "structural" economic problems and imperial overstretch, are combining to end US global supremacy.
In an effort to support and promote this point of view, the CCTV documentary plans to cover all the bases, to use an old American expression borrowed from baseball.
For example, the producers plan to devote at least one episode to the US immigration crisis and attempt to draw historical parallels between a commonly perceived cause of the fall of ancient Rome--unchecked immigration and invasions--and the flood of illegal immigrants pouring into the United States from Mexico and Latin America.
In an ironic twist, the segments on the US economy will supposedly highlight the gloom-and-doom opinions of some smart, successful citizens--fund managers, investment bankers, and analysts--who argue that the country has entered a long period of decline, an economic twilight of sorts, from which no escape is realistically possible. The talking heads of finance are expected to make the case for aggressively investing in emerging markets, especially the so-called BRIC countries (Brazil, Russia, India, China) that are destined to dominate the global economy by 2050, according to an increasingly fashionable Wall Street concept. The CCTV documentary intends to contrast the US financial community's seemingly boundless enthusiasm for investing in China and other emerging markets with an apparently deepening disinterest in domestic investments (except for some stocks, prime property deals and a relative handful of healthcare and high-technology ventures).
The segments on US military power are likely to play up the hoary Mao-era "paper tiger" propaganda line, but with much more finesse than the above-mentioned anti-American videos. Highlighting mistakes made by the Pentagon in Afghanistan and Iraq, the production is expected to make the point that despite its awesome destructive power and global reach, the US military is increasingly overextended and incapable of swift, decisive action around the world. Besides, the documentary is expected to argue, the Iraq experience shows that the American people have lost their taste for foreign intervention and prolonged overseas conflict.
Translation: the US will be in no position to stop China if/when the time comes for it to invade and conquer Taiwan.
Friday, May 5, 2006
Science: Ensign, Engage the Cloak!!
Did you ever play with a tuning fork when you were little? You hit it against the table and then hold it up to a wine glass....the wine glass would match the tuning fork. Pretty cool.
What if we made a light tuning fork? Read on...
Thursday, May 4, 2006
Gone in 20 Minutes: Using Laptops to Steal Cars
High-tech thieves are becoming increasingly savvy when it comes to stealing automobiles equipped with keyless entry and ignition systems. While many computer-based security systems on automobiles require some type of key — mechanical or otherwise — to start the engine, so-called ‘keyless’ setups require only the presence of a key fob to start the engine.
The expert gang suspected of stealing two of David Beckham’s BMW X5 SUVs in the last six months did so by using software programs on a laptop to wirelessly break into the car’s computer, open the doors, and start the engine.
I guess this shouldn't surprise me. As software moves more and more into other parts of our lives, we will see things get hacked that were once only in the hardware hacking world.
Tuesday, May 2, 2006
Water in my Pocket - Nanoelectronics
A team of experimentalists and theorists at the University of Pennsylvania, Drexel University and Harvard University has proposed a new and surprisingly effective means of stabilizing and controlling ferroelectricity in nanostructures: terminating their surfaces with fragments of water. Ferroelectrics are technologically important "smart" materials for many applications because they have local dipoles, which can switch up and down to encode and store information. The team's work is reported in the April issue of Nano Letters.
Wow that is pretty cool, so when can I get my water filled NanoUSB??
Sunday, April 30, 2006
Data Breaches - As Common As the HouseFly
In a security incident with a Slovak National Security Office server, a great amount of data has been downloaded by crackers, as Slovak community website (www.blackhole.sk) informed on April 25th.
Crackers got access to and downloaded "20 gigabytes of emails, internal documents, directives etc.." as described probably by the authors of these attacks, crackers got access thanks to weak security, specifically the intruders tried a common account name "nbusr" followed by password nbusr123 guessing it at the first attempt.
See the full article above for more details. They even su'd with no password.
-------------------------------
Via FCW.com -
The Defense Department announced April 28 that someone broke into a Tricare Management Activity (TMA) public server and gained access to information. The compromised information included personal information about military employees, DOD officials said.
“As a result of this incident, we immediately implemented enhanced security controls throughout the network and installed additional monitoring tools to improve security of existing networks and data files,” said William Winkenwerder Jr., assistant secretary of defense for health affairs. “Such incidents are reprehensible, and we deeply regret the inconvenience this may cause the people we serve.”
Investigators do not know the motive for the crime or whether the information has been misused. The Defense Criminal Investigative Service is participating in an investigation. DOD sent letters to employees who were affected by the intrusion to inform them of potential identity theft.
Tricare is DOD's Military Health System, which provides health care for members of the uniformed services and their families and for retirees. TMA oversees Tricare activities.
Friday, April 28, 2006
Fun: Manifesto of the Technocrat - v2
"I am the Technocrat. I live in a world beyond your world; where names are unknown. The world of the packet and the switch. In this world, alliances are fluid like water. In this world, the attackers are invisible and so are the protectors. At the very instant this world emerged from its electronic birth, a war began. A war void of guns and bombs. A war in which the only weapons are light and electrical pulses. The battles are silent, but each has the potential to alter your very existence in unfathomable ways. This is the world in which I live, endure and excel."
- Technocrat (2006)
---------------------------
I was bored and decided to write my own manifesto. Lame, I know. It was inspired by The Hacker's Manifesto, of course.
Thanks for the input from one of the cDc Ninjas, you know who you are.
New Bill Threats MP3 Streaming Radio
The Washington Post reports that Senators Feinstein (D-Cal.) and Graham (R-S.C.) have introduced S. 2644, dubbed the PERFORM Act, that is aimed at punishing satellite radio for offering its subscribers devices capable of recording off the air.
Buried in the bill, however, is a provision that would effectively require music webcasters to use DRM-laden streaming formats, rather than the MP3 streaming format used by Live365, Shoutcast, and many smaller webcasters (like Santa Monica's KCRW and Seattle's KEXP). The streaming radio stations included in iTunes also rely on MP3 streams (since Apple isn't about to license the Real or Microsoft streaming codecs).
...
If the PERFORM Act becomes law, webcasters who use the statutory SoundExchange licenses to play music would have to give up MP3 streaming in favor of a DRM-restricted, proprietary formats that impose restrictions on any recordings made. So much for great time-shifting technologies like Streamripper and RadioLover.
Apple Argues Bloggers Can't Protect Source
"A trial court ruled last year that if a journalist publishes information that a business claims to be a trade secret, this act destroys constitutional protection for the journalist's confidential sources and unpublished materials."
What are the rules for claiming a "trade secret"? Is the model of my KVM switch a trade secret? What about the model number of the copier down the hall? My cube number? Come on...
Apple has a right to defends its "real trade secrets", but it better wake up and see that they are no longer making computers just for teachers and artists. They have opened OS X (and their very company) to a world that they were not expecting. It is the largest paradox box they have ever seen and they better learn how to deal with it quick.
Thursday, April 27, 2006
Paros Proxy Updated
---------------------
Paros is pretty cool. I don't know if I like it more than some of the others....java is a hog, but it is free. So what are you waiting for? Go try it..
Wednesday, April 26, 2006
Fun: IT = Insomniac Tendencies
Reflecting back on what just happened. Just 3 hours ago, I received an IM from a friend that works right down the road from me. He was still at work, so I figured I would help him mentally unwind a bit.
Like most computer programmers, he tends to keep strange hours. But everyone in IT is used to that...it is almost the standard. For most of us, work is play...play is work.
Anyways, I show up and he starts to tell me about how he has been working since 9am. In my mind, I was thinking...well 12 hours, that isn't normal, yet it isn't too crazy either. But he didn't mean 9am Tuesday morning....he meant 9am Monday morning. He didn't go home last night.
He was pushing on 40 hours without sleep. lol
After dinner, he went back to the office and appeared to get back into "code mode", so I left.
Now it is almost 1am and he is still at work. His cat is most likely going insane without food.
Moral of the Story - Perhaps IT doesn't stand for Information Technology...maybe it means "Insomniac Tendencies ".
Many of the people reading this right now will understand this fact all too well. =)
Goodnight...
Tuesday, April 25, 2006
Tools of the Trade - Get'em Updated
2) For all you people that need to test IPv6, try out the new THC IPv6 Attack Suite. I haven't tried it yet however.
3) Sensepost has updated Wikto to 1.63.1-2279. Wikto is basically the Windows port of Nikto, plus a forced browser, Google Hacker and more. HTTPrint and HTTrack both work in conjunction with this program as well.
4) On 4/19, Cain & Abel v2.8.9 was released. Added support for Winpcap v3.2
5) On 4/13, the stable branch of Kismet was updated to 2006-04-R1. Remember all new development is in the "Newcore" branch, so most of the changes in stable are just fixes and some new chipset support.
6) This isn't really new, but it is pretty cool. PHP.Hop created by the PHP Honeypot Project (PDF).
7) Winamp isn't a security tool, but I use it and I figure alot of people that stream radio do as well. So make sure you grab the new Winamp 5.21.
8) This is pretty cool as well. I have been hearing stuff about using a RTOS or a Linux OS that runs in parellel with your Windows OS to help fight rootkits, but it seems that this takes that and puts it on a PCI processor. It is Gamma from Komoku - DARPA funded startup.
Next out this eWeek article on the product.
Monday, April 24, 2006
OS X Safari 2.0.3 DoS Vulnerabilitiy
----------------------
Apple Mac OS X Safari 2.0.3 Vulnerability =========================================
Release Date:
April 23th, 2006
Vendor:
Apple Computer Inc.
Tested on:
- iBook G4 1.2 GHz with Mac OS X 10.4.5 (Build 8H14) + all Updates from Apple except "10.4.6 Update"
- iBook G4 1.33 GHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
- PowerMac G4 Dual 867 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
- iMac G4 800 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple
Versions affected:
- Safari 2.0.3 (417.9.2) latest version under 10.4.5 (Build 8H14) and perhaps prior versions
- Safari 2.0.3 (417.9.2) latest version under 10.4.6 (Build 8I127) and perhaps prior versions
Overview:
A vulnerabilitiy exists in Safari 2.0.3 (417.9.2) and perhaps in prior versions which causes the operating system to slow down SRCOD (Spinning Rainbow Cursor Of Death), and therefore, it's not possible to launch any applications like Terminal to kill the process. After several minutes Safari crashes.
For an expample click at the link with Safari (WARNING: That crashes Safari after several minutes an first the SRCOD (Spinning Rainbow Cursor Of Death) is there for all the time!) http://www.yanux.ch/exploits/safari/example.html
Report:
iMac G4 800 MHz with Mac OS X 10.4.6 (Build 8I127) + all Updates from Apple http://www.yanux.ch/exploits/safari/bugreport_imac_g4.txt
Vendor Status:
Apple has notified of this issues on 04/23/2006
Solution:
Currently no patches have been released for this vulnerability.
Discovered by:
Yannick von Arx
yannick[dot]vonarx[at]yanux[dot]ch
Possible Firefox 1.5.0.2 Remote Code Execution
---------------------------------------------------
Software:
Firefox Web Browser
Tested:
Linux, Windows clients' version 1.5.0.2
Result:
Firefox Remote Code Execution and Denial of Service - Vendor contacted, no patch yet.
Problem:
A handling issue exists in how Firefox handles certain Javascript in js320.dll and xpcom_core.dll regarding iframe.contentWindow.focus(). By manipulating this feature a buffer overflow will occur.
Proof of Concept:
http://www.securident.com/vuln/ff.txt
Credits:
splices(splices [dot] org)
spiffomatic64(spiffomatic64 [dot] com)
Securident Technologies (securident [dot] com)
------------------------------------------------
Sunday, April 23, 2006
Computer records on 197,000 people breached at UT
Microsoft Internet Explorer Nested OBJECT Tag Memory Corruption Vulnerability
Microsoft Internet Explorer is prone to a memory-corruption vulnerability. This issue is due to a flaw in the application in handling nested OBJECT tags in HTML content. An attacker could exploit this issue via a malicious web page to potentially execute arbitrary code in the context of the currently logged-in user, but this has not been confirmed. Exploit attempts likely result in crashing the affected application. The issue could also be exploited through HTML email/newsgroup postings, or other applications that employ the affected component.
Microsoft Internet Explorer 6 for Microsoft Windows XP SP2 is reportedly vulnerable to this issue; other versions may also be affected.
See the SF page above for PoCs.
Michal Zalewski
Saturday, April 22, 2006
OS X Flaws Put Mac Users At Risk
Good write-up over @ CNET.com dealing with the recent information disclosure of several serious Mac vulnerabilities.
Looks like at several key quotes.
1) Apple believes the public disclosure of security flaws doesn't help anyone, a position shared by most software makers. "We don't feel that our customers are better served by public disclosure of potential issues," Tribble said. "We think that in the general case, people who need to know about issues are the ones that can actually fix the bugs."
While Apple may not agree with Tom, I bet his action will get the problems fixed faster. Apple would have sat on them for as long as they could, all along claiming they weren't a danger. Which brings me to quote number 2.
2) Apple's vice president of software technology told CNET News.com. "I think it is important to note that although these are potential vulnerabilities, there are no known exploits to them and they are not affecting customers today."
There are no exploits in the public, maybe...but that doesn't mean that they aren't being exploited. This could be of no importance to Apple; these are very serious vulnerabilities and should be fixed. IMHO, only companies that are using Apple products should be focused on whether exploits are public or not. Since this fact does alter the patch management cycle in most cases.
3) Apple silently fixed one of the flaws related to the handling of TIFF image files in update 10.4.6, Ferris said. The other bugs remain unpatched, he said, adding that he reported the issues to Apple earlier this year.
Umm...this issue sounds very familiar. As I stated before, we need to hit Apple on this exact issue as well. Microsoft isn't the only one not doing the right thing in my view.
4) Apple expects to address the issues in an upcoming security update but could not say when that fix might be released. "Our target is to do it promptly," Tribble said. "How quickly that can be done depends on a lot of variables, in terms of how much information we get and how complex the things are to address."
This quote only supports my comment on quote #2. They have known about the issues all year and they are going to fix them "promptly"....umm..and people say public disclosure doesn't work. =)
Friday, April 21, 2006
Mac OS X Multiple Potential Vulnerabilities
1) An error exists in the "BOMStackPop()" function in the BOMArchiveHelper when decompressing malformed ZIP archives.
2) Some errors exists in the "KWQListIteratorImpl()", "drawText()", and "objc_msgSend_rtp()" functions in Safari when processing malformed HTML tags.
3) An error exists in the "ReadBMP()" function when processing malformed BMP images and can be exploited via e.g. Safari or the Preview application.
4) An error exists in the "CFAllocatorAllocate()" function when processing malformed GIF images and can be exploited via e.g. Safari when a user visits a malicious web site.
5) Two errors exists in the " _cg_TIFFSetField ()" and "PredictorVSetField()" functions when processing malformed TIFF images and can be exploited via e.g. the Preview, Finder, QuickTime, or Safari applications.
The vulnerabilities have been reported in version 10.4.6. Other versions may also be affected.
Solution:
Do not visit untrusted web sites, and do not open ZIP archives or images originating from untrusted sources.
Provided and/or discovered by:
Tom Ferris
Original Advisory:
Tom Ferris:
http://www.security-protocols.com/sp-x25-advisory.php
http://www.security-protocols.com/sp-x26-advisory.php
http://www.security-protocols.com/sp-x27-advisory.php
http://www.security-protocols.com/sp-x28-advisory.php
http://www.security-protocols.com/sp-x29-advisory.php
http://www.security-protocols.com/sp-x30-advisory.php
Thursday, April 20, 2006
The Dark Side of Patching
Microsoft has 'fessed up to hiding details on software vulnerabilities that are discovered internally, insisting that full disclosure of every security-related product change only serves to aid attackers.
I love it. Microsoft once said that all exploits come from reversed patches and now it seems they believe the exact opposite. Can't they just sit in the middle and understand that both happen?
Blackhats have zero-days that Microsoft "may" find and fix internally. Microsoft itself has detected unknown hackers using unknown vulnerabilities in the wild. The JView bug that was discovered by Microsoft's honeymonkey project, for example.
But then the world has the vulnerabilitiy once a patch is released. There are places on the internet that tell you step by step how to do a binary diff on patches. Therefore, there is no silence fix.
For Microsoft to keep silence on the issue after the patch is only hurting their customers. Period.
Hopefully once we get Microsoft right on the issue, we can all move to Apple and start over.
Wednesday, April 19, 2006
TrueCrypt 4.2 Released
New Features:
- TrueCrypt volumes can now be created under Linux.
- Ability to create a ‘dynamic’ container whose physical size (actual disk space used) grows as new data is added to it. (Dynamic containers are pre-allocated NTFS sparse files).
- Volume passwords/keyfiles can be changed under Linux.
- Keyfiles can be created under Linux.
- Volume headers can be backed up and restored under Linux.
- Multiple keyfiles can be selected in the file selector by holding the Control (Ctrl) or Shift key (Windows).
- It is now possible to enable and directly set keyfiles by dragging the icon of keyfile(s) or of keyfile search path(s) to the password entry window (Windows only).
- New Linux command line option: -u, --user-mount, which can be used to set default user and group ID of the file system being mounted to the user and group ID of the parent process. Some file systems (such as FAT) do not support user permissions and, therefore, it is necessary to supply a default user and group ID to the system when mounting such file systems.
- The build.sh script can now perform automatic configuration of the Linux kernel source code, which is necessary in order to compile TrueCrypt on Linux. Note that this works only if the installed version of the kernel enables/supports it.
- TrueCrypt volume properties can be viewed under Linux.
- New Mount Option: 'system'. It is possible to place paging (swap) files on a TrueCrypt volume that is mounted with this option enabled. Thus, it is possible to use TrueCrypt to on-the-fly encrypt a paging file. (Windows, command line usage)
- New Mount Option: 'persistent'. A volume mounted with this option enabled is not displayed in the TrueCrypt GUI and is prevented from being auto-dismounted (‘Dismount All’ will not dismount the volume either). (Windows, command line usage)
Monday, April 17, 2006
News: Iran Researched P2 Centrifuges
P2 centrifuges have steel rotors as opposed to the P1's aluminum rotors and can enrichment uranium twice as fast as normal P1 centrifuges.
I tend to agree with the unnamed US government official that said "The more the IAEA looks, the more they find and the more Iran says 'Oops, we need to amend our declaration'."
Perhaps the NPT needs to be fixed to remove this "ohhh, you mean those 4000 magnets" loophole. Keeping to the faith of the NPT does not include that type of "forgetfulness" in my mind.
Science: Megacryometeors
A megacryometeor is a very large chunk of ice, which, despite sharing many textural, hydrochemical and isotopic features detected in large hailstones, are formed under unusual atmospheric conditions which clearly differ from those of the cumulonimbus clouds scenario (i.e. clear-sky conditions). They are sometimes called huge hailstones, but don't need to form in thunderstorms. Jesus Martinez-Frias, a planetary geologist of the Center for Astrobiology in Madrid pioneered research on megacryometeors in January 2000, after ice chunks weighing up to 6.6 pounds rained on Spain out of cloudless skies for 10 days.
Recently these have been hitting Cali again - ABC News and Chron.com
Fun: US Marines Experiment with "Urban Combat Skateboard"
Wow. I heard stuff about the Future Combat Systems, but this has to be a joke. How much did that "Urban Combat Skateboard" cost to "develop" and "fine-tune"? 10k? 50k?
I mean it is the government; couldn't they get Tony Hawk to give them a sick board for free testing? Seriously...no really...
It would seem that I was some type of future urban warrior at the age of about 12 and I didn't even know it.
NEWS FLASH – The "Urban Two-wheel Cycle" has been developed to be used in conjunction with the "Urban Combat Skateboard" accompanied by the "Urban Combat Ski Rope".
Sunday, April 16, 2006
Another Credit Card Information Breach
Specialty retailer Ross-Simons said a security breach detected earlier this month compromised personal information on tens of thousands of customers. The breach affects about 32,000 customers who applied for store credit cards from October 2004, when the cards were first issued, to April 4, when the problem was verified, Ross-Simons spokesman Dante Bellini Jr. said Thursday.
------------------------------------
Paying cash for things is looking better everyday..
Saturday, April 15, 2006
Will Pay for Software Bugs - The Debate
On one hand, I like to see my friends get paid for finding software bugs in software. Why shouldn't they? They spend large amounts of time looking for and finding security issues, which they then report to the vendor.
They aren't making an exploit and creating a new huge botnet - they are helping the vendor. Hopefully helping the vendor become more secure and therefore sell more products. But what do my friends get? Money? Rarely. Sometimes they don't even get a pat on the back. Some vendors claim the bug isn't a problem and that the researcher doesn't know what they are doing....only later to fix the issue in a "feature update". ;)
But Jennifer paints a very real picture in her article. If the third-party broker market keeps growing, issue of information control will come to light. Vendors pay for the "information" and they use it to make their products better - new IDS/IPS Sigs, early forecasting, etc. That sounds like normal business to me....but it isn't without a negative side - as Jennifer points out.
It is a slick slop and I hope the security community overall can find a balance. Perhaps the original product vendors should start to pay for vulnerability information, like Mozilla. I don't know.
Let me know what you think...I want input on this issue.
Are we heading down a bad road??
By not paying for vulnerabilities, are companies not stepping up to the plate to protect their customers?? They pay programmers to write the code and they have their own security people? They pay them all day right? Why not pay a non-employee that helps you better your product?
Tuesday, April 11, 2006
MySpace.com Hires MS Employee to Oversee Security
----------------
Because of concern by parents and school and law enforcement officials that the site sometimes unwittingly makes young people vulnerable to pornographers or predators, the company has hired Hemanshu Nigam, director of consumer security outreach and child-safe computing at the Microsoft Corporation, to oversee safety, education and privacy programs and law enforcement affairs.
----------------
About damn time. Too bad I never heard anything back from Myspace.com when I contacted them about using SSL for login. Self-sign certs should be able to fit in their budget. ;)
Saturday, April 8, 2006
The Technocrats of Urban Communication
The Graffiti Research Lab is dedicated to outfitting graffiti artists with open source technologies. Pretty cool. The graffiti scene has moved from pure paint to LED throwies and art via light projection. I really like this new movement because of its less-damaging outcome.
Check out this Wired.com write-up on this movement in NYC.
The Security Illusion vs Cross-Platform Malware
We live in a world were no computer or OS is safe. Botnets have been found that only contained Linux and OS X bots. If you think your OS is protecting you from the evil of the virtual world...you are dead wrong.
This is the security illusion - I sometimes call it "security complacency".
Any system is open to attack. Bad guys want your computer to be a node on their botnet....it doesn't matter if you are running Windows 98, Windows 95 or OS X. I saw a Windows 98 yesterday with a bot on it. It was scanning for a load of vulnerable PHP applications, most likely an attempt to spread.
Moral of the Story - Don't have a big head. Every computer user needs to be smart and take steps to protect their data, money and their existence.
MacBook Pro / Boot Camp
Read about Jim Dalrymple's experience with Boot Camp over at Macworld.
Before OS X was released, I never wanted a Mac. I didn't see the reason to get one. They had fewer programs, fewer places to get them repaired (which I mostly did on my own anyways) and cost twice as much as my x86 PCs. Apple didn't support the geek overall. They didn't want you to open the case, didn't want you to modify things too much. So again - why would I?
Once OS X was released, my new found love for Linux/BSD could be filled with a really damn cool GUI interface. The once BSD-only ports system works on it. Almost any Linux security tool works on it...and some tools even go beyond their Linux counterparts - KisMac for example.
They are still high priced in my mind. I am typing on my personal Dell Latitude D505 that I got off Ebay for 800-900 dollars (with warranty days left on the machine). Hard to beat that deal. But I found myself thinking about getting a Mac laptop with my tax money. I would have to get a laptop, of course.
But you really have to get a MacBook Pro to get all the function I need. PCMCIA slots, Intel chipset, etc. So there goes 2000 dollars, plus money on the extras. That isn't cheap. Therefore I decided against it. I like my Dell and don't really see what I would do with another laptop.
But I have to say for the first time in my life. If I didn't have a laptop right now, I would be moving toward the MacBook Pro.
I still have some problems with Apple on a couple of issues, but Microsoft isn't much better these days.
I better go disable my Active Scripting in IE now before I catch a virus.
Friday, April 7, 2006
Defense Science: Fighting RPGs with "ForceFields"
Pretty cool. It isn't really a forcefield in the Sci-Fi terms...but it is protection. I do wonder how the system can fire a counter projectile at the correct angle in such a quick manner.
I am still a fan of "Creating wrap bubbles around vehicles" idea. lol
Thursday, April 6, 2006
Black Tuesday : Microsoft to Patch Five Vulnerabilities
Security Updates
* Four Microsoft Security Bulletin affecting Microsoft Windows. The highest Maximum Severity rating for these is Critical. Some of these updates will require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scan Tool. One of the updates will be a cumulative Internet Explorer update that addresses the publicly known "CreateTextRange" vulnerability.
* One Microsoft Security Bulletin affecting Microsoft Office and Microsoft Windows. The highest Maximum Severity rating for this is Moderate. These updates may require a restart. These updates will be detectable using the Microsoft Baseline Security Analyzer and the Enterprise Scanning Tool.
http://www.microsoft.com/technet/security/bulletin/advance.mspx
----------------------------
I would like to thank Fergie for the heads up. I am a busy man..lol
What other non-public vulerabilities will be fixed in the "Cumulative Internet Explorer Update"??
Sunday, April 2, 2006
Fried Phish & French Phries
The site was being hosted at a US company website, looked like a third-party hosted site. Third party hosted is even worse, since that means that other sites are could be open to whatever attack vector was used.
It was using advanced javascript URL-bar spoofing tricks, stuff I have on a couple of sites in Korea before. It is a paypal phishing tool that is dropped on an open site as a ZIP or a RAR, then unzipped - bang - up and going. This allows for very fast delivery and fast phishing.
Report phishing sites to the PIRT via their Fried Phish website.
Tools of the Trade
1) Fedora Core 5 (FC5) was released a couple of weeks ago. All new graphics as well. Looks much better than FC4.
2) On March 29th, Nessus 3.0.2 beta was released for Mac OS X. It runs native on both PPC and Intel CPUs. I just installed the new one on FC5, working pretty good. Remember the GUI client isn't packaged with the main server party anymore...so make sure you grab the GTK client or use the remote NessusWX.
3) On March 16th, Cain & Abel v2.8.8 was released over at oxid.it. They added VoIP sniffer support for the following codecs: G723.1, G726-16, G726-24, G726-32, G726-40, LPC-10.
4) On March 30th, Aircrack-ng 0.3 was released for both Linux and Windows. If you haven't used Aircrack before, you should try it on your wireless network, you might be shocked to see how well it works.
5) Recently, Ophcrack 2.2 was released. Check out the Ophcrack Live CD. It is a linux bootable CD-Rom with Ophcrack and a set of pre-computed tables. Nice ;)
6) John the Ripper 1.7.0.2 was released for *nix systems. The change was irrelevant for Windows users.
7) Watch out for a Kismet update soon. Development hasn't stopped, it has just shifted into the "NewCore" branch. I am running the development version on FC5, looking good so far. I still haven't seen any information about the Kismet hole leaked at DefCon...strange.
8) Gaim 2.0.0 Beta 3 was released on March 29th. I am currently running the beta 2 - I like it. Time for a upgrade.