Tuesday, September 19, 2006

HACKTIVISMO RELEASES TORPARK FOR ANONYMOUS, PORTABLE WEB BRO

FOR IMMEDIATE RELEASE

HACKTIVISMO RELEASES TORPARK FOR ANONYMOUS, PORTABLE WEB BROWSING

Torpark keeps Web surfers' identities private, can run off a USB stick, and scrubs tracks from host computers and browsers.

New York, NY (PRWEB) - September 19, 2006 – Hacktivismo, an international group of computer security experts and human rights workers, just released Torpark, an anonymous, fully portable Web browser based on Mozilla Firefox. Torpark comes pre-configured, requires no installation, can run off a USB memory stick, and leaves no tracks behind in the browser or computer. Torpark is a highly modified variant of Portable Firefox, that uses the TOR (The Onion Router) network to anonymize the connection between the user and the website that is being visited.

“We live in a time where acquisition technologies are cherry picking and collating every aspect of our online lives,” said Hacktivismo founder Oxblood Ruffin. “Torpark continues Hacktivismo’s commitment to expanding privacy rights on the Internet. And the best thing is, it’s free. No one should have to pay for basic human rights, especially the right of privacy.”

Torpark is being released under the GNU General Public License and is dedicated to the Panchen Lama*.

HOW TORPARK WORKS

When a user logs onto the Internet, a unique IP address is assigned to manage the computer’s identity. Each website the user visits can see and log the user's IP address. Hostile governments and data thieves can easily monitor this interaction to correlate activity and pinpoint a user's identity.

Torpark causes the IP address seen by the website to change every few minutes to frustrate eavesdropping and mask the requesting source. For example, a user could be surfing the Internet from a home computer in Ghana, and it might appear to websites that the user was coming from a university computer in Germany or any other country with servers in the TOR network.

It is important to note that the data passing from the user's computer into the TOR network is encrypted. Therefore, the user’s Internet Service Provider (ISP) cannot see the information that is passing through the Torpark browser, such as the websites visited, or posts the user might have made to a forum. The ISP can only see an encrypted connection to the TOR network.

However, users must understand that there are limitations to the anonymity. Torpark anonymizes the user’s connection but not the data. Data traveling between the client and the TOR network is encrypted, but the data between the TOR network and websites is unencrypted. Therefore, the user should not use his/her username or password on websites that do not offer a secure login and session (noted by a golden padlock at the bottom of the Torpark browser screen).

DOWNLOAD TORPARK

http://torpark.nfshost.com/download.html

Press Contact

press@hacktivismo.com

ABOUT HACKTIVISMO

www.hacktivismo.com

Hacktivismo is a group of international hackers, human rights workers, artists and others who seek to further the goals of human rights through technology. They operate under the aegis of the CULT OF THE DEAD COW (cDc). Hacktivismo is committed to developing technologies in support of the highest standards of human rights.

ABOUT THE CULT OF THE DEAD COW

www.cultdeadcow.com

CULT OF THE DEAD COW (cDc) is the most influential hacking group in the world. The cDc alumni list reads like a Who's Who of hacking and includes a former U.S. presidential advisor on Internet security, among others. The group is further distinguished by publishing the longest running e-zine on the Internet [est. 1984], stretching the limits of the First Amendment, and fighting anyone or any government that aspires to limit free speech.

* ABOUT THE PANCHEN LAMA

www.savetibet.org/news/positionpapers/panchenlama.php

The Panchen Lama is often referred to as the world’s youngest political prisoner. In May 1995, agents of the Chinese government kidnapped the six-year-old Panchen Lama and his parents. They have not been seen or heard from since, despite repeated calls from the United Nations and international human rights organizations. Chinese officials claim that the Panchen Lama is being held in “protective custody”. Six months after the abduction, China installed its handpicked version of the Panchen Lama. The boy is forced to act as a mouthpiece for Chinese policy in Tibet, and is referred to as “the fake” by Tibetans.

###

from http://www.prweb.com/releases/2006/9/prweb438978.htm | pdf version

Sunday, September 17, 2006

SF: A Question of Ethics

Check out the much needed article by Scott over at SecurityFocus. He hits the nail right on the head....where have all the good people in high positions gone?

My Consciousness - Part 1

Who am I? Why am I here? What makes me different than those around me? Perhaps these questions can never be answered, but I believe I can find answers that work for me....answers that allow me to move on...answers that allow me to live...answers that allow me to be happy. Don't we all just want to be happy in the end? I am sure my answers will not be like the answers of others, but isn't that the point? What I see as answers may only appear as more questions to the person that just handed me my coffee. I believe the answers are non-static and they cannot be set in stone, they are fluid, they are dynamic, they are the process of searching…

The process by which a thought becomes an idea is simple, yet cannot be measured, explained or classified by the scientific world. The brain might be the most complex thing that we have ever attempted to study. It is specialized yet decentralized. It is divided into two distinct halves, yet they work together on even the simplest task.

My brain contains billions of neuron cells. They are encased in my skull and surrounded by cerebrospinal fluid. But is this not true for all humans? So what makes me…me? Perhaps it is the emptiness, the space between the cells, the synapses…the intangible. Perhaps it is the un-scientific nothingness that makes me who I am. I know that I am not the grey matter or the white matter, I am not contained within the six layers of the neocortex and I am not locked away in the super-hard wired and amazingly neuron dense cerebellum.

I just want to be happy, is that so hard? The word is simple to say, but perhaps practically impossible to define. Is it possible that the things that make me happy…are not the same things that make others happy? I can recall memories of happy times, but where and what are memories? Are they simply a reflection of time pasted? Or are they what makes me unique? Can memories even BE happy or sad? Perhaps I sub-consciously attach feelings to my memories…and that is what determines my perception of them now. I may never know. Memories are memories…the past is the past….but can they stop me from finding happiness now? Can they stop me from moving forward….forward to true happiness?

Perhaps by disassociating the negative feelings that are currently attached to some of my memories, I can affect my future…perhaps I can affect how I feel years from now.

Perhaps if I let go…I can find true happiness…

Friday, September 15, 2006

New IE Zero-Day and Fresh Out of the Oven Firefox Updates

Via eWeek -

Security researchers in China have published detailed exploit code for a new zero-day vulnerability in Microsoft's dominant Internet Explorer browser.

The exploit, which was posted to XSec.org and Milw0rm.com Web sites, could be easily modified to launch code execution attacks without any user action on fully patched Windows machines.

A spokesman for the MSRC (Microsoft Security Response Center) said the company is investigating the latest warning, which adds to a list of known
high-risk vulnerabilities that remain unpatched.

Via SANS ISC -

My Firefox just jumped up at me and said "You have some updates".

Version 1.5.0.7 to be exact. So what's new? Well, Mozilla tells us over here.

MFSA 2006-64 (which, by the way, stands for Mozilla Foundation Security Advisory) -- "Crashes with evidence of memory corruption" Mozilla says, "...we presume that at least some of these [bugs] could be exploited to run arbitrary code with enough effort." So, get your patches!

MFSA 2006-62 -- Popup-blocker cross-site scripting (XSS)
More XSS stuff, except this time against the Popup-blocker feature. Mozilla doesn't really view this as a big threat: "The malicious page would first have to get itself framed by the target page, attempt to open a popup, and then convince the user that the popup contents were so important or interesting that it must be opened manually."

MFSA 2006-61 -- Frame spoofing using document.open()
This vulnerability is kind of a reshash of this one. "The victim site must first be opened in a new window (or tab) by the malicious site for this flaw to work." Basically, be wary of any sites or windows, not opened by you.

MFSA 2006-60 -- RSA Signature Forgery
Looks like Philip Mackenzie and Marius Schilder over at Google found this one.
"Because the set of root Certificate Authorities that ship with Mozilla clients contain some with an exponent of 3 it was possible to make up certificates, such as SSL/TLS and email certificates, that were not detected as invalid. This raised the possibility of the sort of Man-in-the-Middle attacks SSL/TLS was invented to prevent." Good, I read about this one not too long ago on a couple mailing lists that I lurk on.

MFSA 2006-59 -- Concurrency-related vulnerability
Mozilla has this to say: "We have seen no demonstration that these crashes could be reliably exploited, but they do show evidence of memory corruption so we presume they could be."

MFSA 2006-58 -- Auto-Update compromise through DNS and SSL spoofing
DNS and SSL spoofing vulnerability. Mozilla does offer some good advice on this one:
"Do not accept unverifiable (often self-signed) certificates as valid. If you must, accept them for the session only, never permanently." Rule of thumb.

MFSA 2006-57 -- JavaScript Regular Expression Heap Corruption
"...a regular expression that ends with a backslash inside an unterminated character set (e.g. "[\\") will cause the regular epression engine to read beyond the end of the buffer, possibly leading to a crash."

... and since Thunderbird uses the same browser engine as Firefox, you need to update it too!

Thursday, September 14, 2006

DHS Releases Cyber Storm Report

Via Infoworld Tech Watch -

The U.S. Department of Homeland Security (DHS) released its public findings from Operation Cyber Storm, a large-scale tabletop simulation of a coordinated cyber attack on the government and critical infrastructure that was held in February, 2006.

The exercise involved US-CERT, the Homeland Security Operation center as well as the National Cyber Response Coordination Group (NCRCG) and the Intragency Incident Mnagement Group (IIMG), various ISACs from the transportation, energy, IT and telecommunications sectors, and 100 private sector companies including Microsoft and VeriSign.

The report was released by DHS's National Cyber Security Division (NCSD) Wednesday and while no performance "grade" was assigned, read between the lines of the public report and the term "Needs Improvement" comes to mind.


The exercise simulated a large-scale cyber campaign that disrupts multiple critical infrastructure, as well as simulated "physical demonstrations and distrubances" to test the ability of government to respond to multiple incidents simultaneously, even when its not clear that the events are related (read: 9/11).

So how'd our government do? Not so well.



In a way, I am glad the government didn't "pass with flying colors". This leads me to believe that the test was created to truly challenge the departments and response teams. Like any DR test, the first one is almost always a total write-off. Lets just make sure we do what we need to do...and we do better next time.

Wednesday, September 13, 2006

THC and The Nokia Rom Images

THC has posted this little piece of news on their webpage.



THC and The Nokia Rom Images
2006-09-06

In mid july Nokia charged THC with copyright infringement and threatenedwith a lawsuit. THC took down thc.org to prevent further cost and alegal disaster.

A month earlier THC discovered significant security flaws in Nokia'sOperating System. To proof it THC published ROM images of 3 phones.THC did not publish the source code or tools but one thing becameapparent: To extract the ROM images core security features had to bebreached. THC's ability to load kernel modules and gain access to thecore of the OS (including the GSM stack) was something Nokia did notlike.

At the time of the release THC was not aware of any copyright protectedmaterial inside the roms. The question has to be asked if Nokia chosed the right method by threatening THC with a lawsuit or if an email couldhave achieved the same. Was their concern really copyright infringement? The software in the rom-images could not be used, not be ported and not berun on any other mobile phone. In addition all software is already availableon every phone. Phones that are given away by the mobile operators for1 Euro or sometimes even for free. So if everyone has access to the software anyway what is the point in threatening THC? What was their real intend? Wemight never find out. But what we know is that they managed to silence THC for a month.

If this is professional practice? We do not know. It is certainly the practice that Nokia chose. We also know that no attempt was made by Nokiato inquire about the security vulnerability. We also know that Nokia didnot provide any updates for their customers.

Making sure that the hardware we purchase is secure is not a crime.In fact taking a look at what we buy should be our duty. We should nottrust big corporates who claim in TV advertisements how secure andsafe our data is. We have to test it and proof them wrong whenever wecan.

In fact researchers should demand that manufactures like Nokia mustprovide full documentation of their hardware. The buyer becomes the ownerof the mobile phone and thus has the right to know how to program thehardware. Nokia does not provide any of such information. Free softwareor a different operating system can not be used because of limited accessto documentation. This is a classic example of a hardware giant allowingonly his own software to be used. This is what some people would considera Monopoly and an abuse of power.

THC is deeply concerned that Nokia did not choose the diplomatic route.




THC also released a Nokia Unlock Tool that removes the phone lock protection by exploiting a design flaw in the moblie phone. The tool does not remove the sim-lock however.

October 3rd Declared "Day Against DRM"



"If consumers even know there's a DRM, what it is, and how it works, we've already failed"
- Disney Executive


Tuesday, September 12, 2006

Vulnerabilities Released Today

I saw several vulnerabilities released via Secunia that were interesting.

SF: Analyzing malicious SSH login attempts

Christian Seifert of SecurityFocus posted a great little honeynet story yesterday. No super breaking news or anything, but some good hard data and results on malicious SSH brute forcing.

This SSH Scanner sounds like a pretty smart IRC bot spreading method...

Friday, September 8, 2006

PCI DSS Standard v1.1 Released

I believe it went public yesterday.

Here is the full PCI DSS v1.1 PDF

I haven't had a chance to fully read over it...

Microsoft Patch Tuesday - Advance Notice

On 12 September 2006 Microsoft is planning to release: Security Updates.

Two Microsoft Security Bulletins affecting Microsoft Windows.
The highest Maximum Severity rating for these is Important.
These updates will be detectable using the Microsoft Baseline Security Analyzer (MBSA).
Some of these updates will require a restart..

One Microsoft Security Bulletin affecting Microsoft Office.
The highest Maximum Severity rating for these is Critical.
These updates will be detectable using the Microsoft Baseline Security Analyzer (MBSA).
These updates may require a restart.

Thursday, September 7, 2006

Tools of the Trade

Lets look at some recent updates to the tools of the hacking trade..

1) Yesterday (9/6/2006) Michal Zalewski released p0f v.2.0.8

P0f is a very slick passive operating system fingerprinting tool. It provides features that you won't find in the great active scanner - masquerade detection, thru-firewall fingerprinting, profiling network topology distance and netlink information, etc.

2) Earlier this week, a security advisory was released for OpenSSL.

It appears that with the right conditions it is possible for an attacker to forge a PKCS #1 v1.5 signature that was signed using a RSA key with exponent 3.

Upgrade to 0.9.7k or 0.9.8c

3) On Aug 30th, Tenable Network Security released Nessus 3.0.3 Beta 14 for Windows.

If you are using Tenable Security Center to manage your Nessus installs, make sure you read the release notes for Beta 14.

4) On Aug 28th, my friend HD Moore released Metasploit Framework (MSF) 3.0 Beta 2.

Beta 2 is fully compatible with Linux, BSD, Mac OS X, and Windows using their custom Cygwin installer. MSF 2.6 and MSF 3.0 can be installed on the same computer; just don't run them at the same time. Please be aware that the web console is awaiting a serious re-write and therefore does not work very well in MSF 3.0. ;)

5) On Aug 28th, Snort was updated to 2.6.0.1

Martin Roesch noted on Packetstorm that new changes were added to allow configurable dropping of decoder alerts in inline mode. Updates were also added to the Oracle database plugin to handle large data blobs and graceful disconnection.

6) On Aug 23rd, Wireshark 0.99.3 was released.

It fixed several security issues, added support for several new protocols. See the release notes for the full details.

7) On Aug 1st, GnuPG 1.4.5 was released.

It included a moderately critical security fix and several tweaks.

Malware Using Built-In EFS as Protection

Via Mcafee Avert Lab Blog -

Recently a trojan was seen to take advantage of EFS to protect itself and execute with administrative privileges. This malware is composed of obfuscated DLL and PE files that are thoughtfully crafted. It has two main components, a dialer component that is detected as Qdial-45 the other is a downloader/dropper component detected as Spy-Agent.bf that drops this dialer along with an EFS encrypted downloader file. McAfee has been detecting variants of this trojan since August 02, 2006, however we have observed an upsurge in infection rates in last few weeks.

Tuesday, September 5, 2006

Using Old Tricks to Steal New Cars

Via MosNews.com -

A group of hijackers has used an old but still effective way to distract their victims’ attention at one of beaches near Moscow. The criminals brought with them three girls who bathed naked while they successfully stole four cars.The Moskovsky Komsomolets daily reports that the incident took place in the Moscow suburban town of Balashikha in late July.

People were relaxing at a river beach when a Toyota SUV stopped by and three beautiful girls got out of it. Eyewitnesses report that the girls fully undressed went knee-deep in the water and played there for a while.Naturally, all attention was drawn to the girls who were later described by the victims as the complete resemblance of adult magazine models. Suddenly, the naked bathers got back into the SUV and quickly drove away.

Only then did the people on the beach realize that four cars had been stolen. Other cars were broken into and various valuables were stolen as well

Johnny Cache, Blackhat & Wireless

There has been alot of "Mac" press around the Johnny Cache wireless vulnerability talk recently. I only have couple of points to make about the issue. I don't see why they would fake such a talk. If it were "all made up", then it would only end up hurting the company and the speakers in the eye of the community. I don't personally believe the information shown during the talk was fake....if you believe the whole thing is fake..then what the hell did Intel just patch??

I would tell Johnny to not let the Mac Blind get to him. Johnny doesn't need to take bets or prove that Apple has vulnerabilities to every other Mac user. Apple OSX has had vulnerabilities...and it will have more in the future. Stop crying and think about what you are going to do to protect yourself.

If / When Apple releases patches for its wireless products, we will all have the true answer to the question that is bugging everyone. That is if Apple tells us the real reason they are issuing a patch....at this point, I see no good reason why Apple would want to tell their general users the truth. Their general user already believes they don't have anything to worry about anyways.

I am sure the patch will be released on the first Tuesday of the month; under cover of a zero-day Windows patch...lol

I do agree that some of the media have blown the issue out of the box and applied strange negative spin to the real issue.

Real Issue = Device Drivers, as a whole, should be lookedb at as possible attack vectors and manufacturers need to start giving the same security attention to device driver code that they give to normal application code. Period.

Malware Found Using Another Office Zero-day

There has been another Office 0-day detected in the wild. Symantec calls it Trojan.Mdropper.Q

These attacks are normally targeted and present a lower risk to the general public. Secunia has tagged it as SA21735.

Check out this Symantec write-up - "New Tricks with Old Software - New Zero-Day in MS Office 2000".

SecuriTeam has also released a FAQ on this one. Very good stuff.

No patch date has been suggested by Microsoft at this point.

Sunday, September 3, 2006

New Al-Qeada Video

As you may have seen on the news, Al-Qeada released a new video today.

I was able to find, acquire and view this video just now. It is quite rare for me to be able to find it so fast.

It is a very long video, basically 45 mins, which amounts to a 500 MB MPEG file. But they always supply multiple links to lower quality realmedia versions as well.

The production quality is better than I have seen from other groups. It contains both English and Arabic subtitles, where removed the need for translation. Graphics are also very high quality.

On August 31st, As-Sahab released an advertisement for the upcoming video.

"Adam" is from Cali and is seen in the video as "Azzam the American". He spoke English mostly and talked about many political issues beyond what is described in the SITE article.

Read more about the content of the video over at the CounterTerrorism Blog.

Saturday, September 2, 2006

Walt Disney World Fingerprints Visitors to Fight Ticket Fraud

Via Boing Boing -

Disney is now fingerprinting visitors to Walt Disney World as part of its ticket-fraud prevention scheme. They're not being very transparent about it, either: there are no signs posted about the data collection or retention, and Disney's official line is that they're not collecting fingerprints, just mathematical representations of same.



Ummm, not taking fingerprints, just storing the mathematical representations collected by analyzing several key and unquie points in the fingerprint. Isn't that the how all fingerprints are taken? I believe so...which makes their statement crazy, IMHO.

Yet another reason never to go to Disney World.

Myspace and WMF Exploits

Myspace is the devil, we all know it. It kills productive and wastes a crap load of time, but it is a good way of keeping in touch with old friends and perhaps make a few new ones along the way. Strange friend request are all too common, but this morning I had one with a twist.

A profile that was linking to a WMF trojan.


Strange Friend Request



Trojan Hosted in the US and linked by Myspace profile

The profile ID and the IP address have been reported to the parties involved at the time of my writing.

This is just one example and this isn't a new. Myspace and the other social sites have become easy picking grounds for wrong doers. Corporations, schools and people must not be tricked by the false sense of community created by these sites.

I would bet 100 dollars that Mr Greenlee Lite is in my "Extended Network" on Myspace. Why and how?

Because Tom is automatically added as your friend upon sign-up, which in turns means everyone with Tom as a friend is automatically in your Extended Network. Even if you delete Tom, if one of your friends or one of their friends has Tom as a friend...it is still useless.

So why does the "Extended Network" even exist? To create a false sense of safety and community. Period.

Moral of the Story - Be careful out there, dangers are around every corner...

Friday, September 1, 2006

Black Rock City Rises from the Sands of the Desert



You might remember last year's Dance Dance Immolation



Burning Man 2006: Aug 28th - Sept 4th

http://www.burningman.com/

http://en.wikipedia.org/wiki/Burning_Man

Tuesday, August 29, 2006

Big Brother Gone Mad?

The government knows exactly how much trash you throw out and of what type. This isn't some movie trick, this is the real world.



Electronic spy 'bugs' have been secretly planted in hundreds of thousands of household wheelie bins.

The gadgets - mostly installed by companies based in Germany - transmit information about the contents of the bins to a central database which then keeps records on the waste disposal habits of each individual address.


Already some 500,000 bins in council districts across England have been fitted with the bugs - with nearly all areas expected to follow suit within the next couple of years.


Until now, the majority of bins have been altered without the knowledge of their owners. In many cases, councils which ordered the installation of the devices did not even debate the proposals publicly.


The official reason for the bugs is to 'improve efficiency' and settle disputes between neighbours over wheelie-bin ownership. But experts say the technology is actually intended to enable councils to impose fines on householders who exceed limits on the amount of non-recyclable waste they put out. New powers for councils to do this are expected to be introduced by the Government shortly.


But the revelation that the bins have already been altered ignited a 'Bin Brother' row over privacy and taxes. Conservative MP Andrew Pelling said burglars could hack into the computer system to see if sudden reductions in waste at individual households meant the owners were on holiday and the property empty.


He said: 'This is nothing more than a spy in the bin and I don't think even the old Soviet Union made such an intrusion into people's personal lives.


'It is Big Brother gone mad. I think a more British way of doing things is to seek to persuade people rather than spy on them.'



Has Big Brother in the UK gone mad?

Section 3 of the RIP Act, cameras on every corner of the UK, traffic tickets based on camera time calculations, etc.

I am a firm believer in the balance. The government has a right and a duty to protect its people, but it is also the duty of the public to keep the government in check, which means the general public should want to be informed, should want to know what is going on, they should get involved as much as possible.

Monday, August 28, 2006

Emerging Shifts in Cyberwar Tactics

Via FCW.com -

Cyberwar is changing, and network defense must adapt, two leading executives told a military audience at the Air Force Information Technology Conference at Auburn University’s Montgomery campus earlier this month.

“We are at a much more dangerous place today than we were four or five years ago,” said Steve Ballmer, Microsoft’s chief executive officer. The perpetrators of cyberattacks have shifted in recent years from amateur hackers seeking notoriety to organized criminal enterprises with financial or hostile goals, he said.

John Thompson, Symantec’s CEO, said today’s cybercriminal is interested in “perpetrating silent, highly targeted attacks to steal sensitive personal, financial and operational information.” That new criminal tactic marks a shift away from large-scale virus or worm attacks. The number of such attacks dropped from about 100 between 2002 and 2004 to only six last year, he said.

Responses to cyberattacks are evolving, too, Ballmer said. In the past, experts worked to close vulnerabilities in programs and shorten release times for upgrades and patches. Now they focus on building systems that intruders cannot penetrate, he said.

That new defense strategy requires abandoning the suit-of-armor approach, in which developers added layers of protection to keep information safe.

Those layers restricted data access, hampering real-time use and mission performance, Thompson said. Effective cyberdefense will depend on a combination of protecting the IT infrastructure, information and interactions among people using the information, he added.

Standardized data formats and a common software infrastructure are crucial to IT infrastructure protection, Thompson said. Organizations must be sure to transfer data to backup systems to be ready for natural or man-made disasters. “After all, servers and laptop [computers] can be replaced. The information on them most likely cannot,” he said.

Disgruntled or careless employees can do significant damage, so organizations must monitor transactions to instantly combat suspicious or dangerous activity, Thompson said. For example, comply-and-connect mechanisms can verify user identity, he said. The proliferation of wireless devices and telework requires increasingly sophisticated approaches to certification and authentication, he added.

The next cyberwar battle will be fought over unstructured data, including e-mail messages, instant messages, Microsoft PowerPoint and Word documents, and voice-over-IP conversations, which compose 80 percent to 90 percent of data accessible via the Internet, Thompson said.




While I agree with Josh's conclusion that the tactics of cyberwar are changing, I do not agree that corporations or people should abandon the "defense in depth" idea. Perhaps I am reading too much into this sentence - "That new defense strategy requires abandoning the suit-of-armor approach, in which developers added layers of protection to keep information safe."

Corporations must remember that the cyberwar is not a "single-front" war. It has to be defended on multiple fronts at the same time. Investing in new cutting-edge hardware isn't enough, you must invest in your corporate "software" (aka your employees).

Sunday, August 27, 2006

A Day in Amsterdam






















New PoC Virus Takes Aim @ AMD Processors

Via Computing.co.uk -

Security researchers at Symantec have discovered a new proof of concept virus that targets processors AMD rather than operating systems.

The worm comes in two versions, targeting 32-bit and 64-bit processors from AMD. Symantec refers to the online pests as w32.bounds and w64.bounds. Because it involves proof of concept code, both viruses are rated as low level threats.

Although at this point it concerns harmless proof of concept code, the virus could be used as a starting point for creating malware that affects computers regardless of the operating system that they run, cautioned Vincent Weafer, senior director of Symantec's Security Response Group.




It was only a manner of time.

Thursday, August 24, 2006

Tools of the Trade - Mini

Wireshark (formerly Ethereal) 0.99.3 has been released.

Some vulnerabilities have been reported in Wireshark, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.

  1. An unspecified error within the SCSI protocol dissector can be exploited to crash the application.
  2. Off-by-one errors exist in the IPSec ESP preference parser. Successful exploitation requires that Wireshark has been compiled with ESP decryption support.
  3. Errors in the DHCP dissector and potentially other protocol dissectors can be exploited to crash Wireshark due to a bug in Glib. This only affects the Windows version.
  4. An error within the Q.2391 dissector can be exploited to cause a DoS due to memory consumption. Successful exploitation of the vulnerabilities may cause Wireshark to stop responding, consume large amounts of system memory, crash, or execute arbitrary code.

Full Secunia Advisory & Original Wireshark Advisory

This "Tools of the Trade" is very small due to my current location, but just wanted to share this one to everyone.

Wednesday, August 23, 2006

Nothing like the Smell of Internet Tubes in the Morning

Via blogs.ittoolbox.com -

If you use any number of popular web forums or even some commercial services like classmates.com, amazon.com, netzero.com or your provider's webmail service, you may not be aware that you're sending your credentials over the internet in the clear.

Some sites appear to secure your credentials, but they really don't. Some offer SSL sign-ins, but don't make them the default. Others don't even make an attempt to use proper SSL encryption or any attempt to obscure the credentials.

Remember the wall of sheep from DefCon? All of those people that kept logging into net resources assuming that nobody was listening? They were wrong!





Defcon's Wall of Sheep was full of Myspace passwords this year. Freaking crazy.

This above blog isn't pointing out anything new or "super-leet", but it is providing a much needed reminder to the security world. SSL can be very effective if used properly. Imporper use and you create a false sense of secuirty.

Check out Number 8 in the OWASP Top 10 Web Applications Vulnerabilites.

Monday, August 21, 2006

Pluto Debate

I do not think Pluto or Xena should be planets or "plutons" or whatever. Thats all I am going to say on that.

TheStar.com - Why Mississauga is a pluton

ASCO Report Recommends More Open Source for the DoD

The Department of Defense has a problem and the only cure is more "cowbell"....wait a tick, I mean more Open Source Software.

The Advanced Systems and Concept Office (ASCO) recently released a report that recommends the Department of Defense to use and develop Open Source technologies.

The report was titled "Open Technology Development" and was prepared for Ms. Sue Payton, Deputy Under Secretary of Defense. (Full PDF).

It is good to see a group pushing the cultural shift that will be needed to use OSS in the government.

I also like the see the smart use of my tax money. ;)

Wednesday, August 16, 2006

Technocrat Goes to Europe

Well, I am off to Europe tomorrow. I will be in Paris most of the weekend and then will be working in London most of next week. For those readers in France and the UK, yet yell at me if you want to meet for a pint. =)

Due to my traveling, blogging will be light for the couple of weeks.

Fun: Bruce Schneier Facts

Dennis Henderson posted this on the FunSec mailing list this morning. Putting the fun back in Security.

This is just too funny not to share. I am sure we have all heard the Chuck Norris jokes...but here they are again with a tech angle. Good stuff, all in good fun of course.

http://geekz.co.uk/schneierfacts/fact/46

I really liked these:

"Bruce Schneier was only allowed to view the Kryptos sculpture at Langley for 1 second, in order not to spoil the fun other cryptographers. It was 0.9 seconds too much. "

"The nuclear launch codes held by the President of the United States are secured by an unbreakable system: a plain brown envelope with a picture of Bruce Schneier on the flap. "

"Bruce Schneier's Twofish algorithm has 16 rounds, but he always gets a knockout in the first."

UK Home Office to Enable Part 3 of the RIP Act

"Give us your private encryption keys...your keys beyond to us!"

Or at least that is what the UK government will be telling its citizens soon.

The UK's Home Office is seeking to turn on Part 3 of the Regulation of Investigatory Powers Act of 2000 (RIP or RIPA) very soon.

Part 3 of the RIP Act gives the police powers to order the disclosure of encryption keys or force suspects to decrypt encrypted data.

Anyone who refuses to hand over a key to the police would face up to two years of imprisonment. Under current antiterrorism legislation, terrorist suspects now face up to five years for withholding keys.

Please note this part of a recent ZDNet article.

Casper Bowden, a former director of the FIPR who led the fight against the introduction of the RIP Act several years ago, said during the meeting that Part 3 is flawed because defendants could be prosecuted for simply losing an encryption key.

"The burden of proof is on the suspect to prove that they don't have the key, and if they fail, they go to prison. But if they can give an explanation for not having the key, then the prosecution must prove beyond reasonable doubt that they are lying," Bowden said.

I understand why police want this power, but in my view...this is too wide and seems like it could be abused in a huge way by many groups of people.

Wikipedia shares this little piece of information as well.

In September 2003, Home Secretary David Blunkett announced wide-ranging extensions to the list of those entitled to see information collected under the RIPA. The list now includes jobcentres, local councils, and the Chief Inspector of Schools. Civil rights and privacy campaigners have dubbed these extensions a "snoopers' charter".

Here is the full text of the RIP Act of 2000.

Rickard Falkvinge, chairman of the Sweden's Pirate Party, might have said it best in this WiredFire.org article about about DarkNets.

"There are many legitimate reasons to want to be completely anonymous on the Internet" going on to add "If the government can check everything each citizen does, nobody can keep the government in check. The right to exchange information in private is fundamental to the democratic society. Without a safe and convenient way of accessing the Internet anonymously, this right is rendered null and void."

Sunday, August 13, 2006

Global MS06-040 Worm - Could it happen?

Sure it is very possible that the MS06-040 exploit could be used in a Sasser/MSBlast type of global worm...but I don't think it will happen. Why?

The LURHQ Threat Intelligence Group just released a great write-up on this exact issue and I see no reason to create the wheel again.

This make it very clear that botnet owners will add this exploit into their bots....it is would be silly on their part to not do it. This exploit could help them spread their botnets a bit more....but I don't see how they could get more than 5% or 10% growth, if even that much. LURHQ has already detected a Mocbot variant using MS06-040 to spread.

As LURHQ stated, machines with low service pack levels are most likely already owned by something or someone.

Let’s get down to the real issue however.

Why do holes like this exist in Windows?

It isn't because hackers find them…or because smart people make exploits for them....it is Microsoft shipped a product with vulnerable code and we all ran out to the store and got it. In essence, Microsoft put them there.

Hackers don’t inject buffer overflow or format string holes into code…they find what is already there. It would be easier to find these problems, since they have the source code…but it takes hackers looking around in binary code to find these issue and then they are the ones to blame? Interesting view…

Word around the campfire is that Microsoft has taken account of its faults and is attempting to reduce these threats with Vista. Good to hear and kudos to Microsoft for one of the largest security audits ever (or so I hear).

Of course, these issues are not just Microsoft’s problem. Software firms that build and release software for public or corporate use encounter the same issue on a daily basis. So in the end, it is in the hands of the programmers at these companies.

I know some companies have yearly security training for the programming staff, but sadly many do not. Times change and new things are discovered…so no code will ever be perfect but it is the duty of these companies to protect their customers and therefore it just makes sense to keep their programmers on the cutting edge of security.

I went to a fairly small college, but rarely did I hear the word “security” in any of my programming classes. I never saw a class called “Secure Coding Practices” or “Building Secure Software for the Future”. So perhaps some of the fault falls to the education system and to the teachers…but I can only assume things have changed since I finished college almost 4 years ago.

Some things change...and some things always stay the same...

Saturday, August 12, 2006

Defcon 14: Best Spot the Fed Ever!

Ok, I heard about this one while at Defcon, but I didn't personally see it. Perhaps someone can personally account for this event, but it is still a great story. Either way. It has to be the best Spot the Fed ever.

Gadi Evron just posted the small event that happened up on stage. Here it is again...

Not exact quotes:

Priest: “So, what makes you suspect this guy is a fed?”
Girl: “I don’t suspect, I know.”
Priest: “How do you know?”
Girl: “Yesterday after I slept with him, I went through the things in his bag and found his badge.”
Priest: “Are you saying you slept with him last night?”
Girl: “Yes. Can I get my T-shirt now?”


I can add to this a bit. She roughly said that she met him, got drunk with him at the bar, slept with him and then while he was sleeping, she went through his things. Great story. lol

I think Priest said the guy was a Marine.

OOOO-RAAAH!!

Friday, August 11, 2006

Dept of Transporation Stolen - 133,000 identifies

Via SecurityFocus -

A federal agent's stolen laptop in Florida has put 133,000 people's personal identities at risk.

In what is becoming a regular occurrance with U.S. government and military organizations, the laptop was stolen from a vehicle and contained sensitive personal information on individuals that was not encrypted in any way.

The Miami Herald is reporting the annoucment by the federal U.S. Department of Transportation, which discovered the theft on July 27th. The department claims the data had been previously encrypted, but was not encrypted at the time the laptop was stolen. The data contains the names, addresses, birthdates and Social Security numbers of Florida citizens. A second laptop was stored in the vehicle but was not stolen, puzzling investigators.

Recent laptop thefts have affected a number of U.S. agencies, including the U.S. Navy and the high-profile theft at the U.S. Department of Veteran Affairs that contained the identities of 26.5 million veterans. Back in June, the U.S. government issued a memo mandating the use of encryption and two-factor authentication on civilian government computers containing sensitive information.

This is my favorite quote of the day - "The department [of Transportation] claims the data had been previously encrypted, but was not encrypted at the time the laptop was stolen."

Why even bring that fact up?

Thursday, August 10, 2006

MS06-040 Public Exploit - UPDATED

Metasploit has added an exploit for the buffer overflow vulnerability in the Microsoft Windows Server service (MS06-40).

Description

This module exploits a stack overflow in the NetApi32 NetpIsRemote() function using the NetpwPathCanonicalize RPC call in the Server Service. It is likely that other RPC calls could be used to exploit this service. This exploit will result in a denial of service on on Windows XP SP2 or Windows 2003 SP1. A failed exploit attempt will likely result in a complete reboot on Windows 2000 and the termination of all SMB-related services on Windows XP. The default target for this exploit should succeed on Windows NT 4.0, Windows 2000 SP0-SP4+, and Windows XP SP0-SP1.

US-CERT recommends users and administrators apply the appropriate updates in Microsoft Security Bulletin MS06-040 as soon as possible.

More information about this vulnerability can be found in Vulnerability Note VU#650769 and Technical Cyber Security Alert TA06-220A.

I have heard about the campfire that Core Impact has also released a MS06-040 exploit module to their customers.

eEye Digital Security has released Retina MS06-040 NetApi32 Scanner. It can be used to find machines on your network that are still open to attack.

You may remember eEye from the third-party WMF patch media event.

** UPDATE **

I have already spotted several hits on this blog from people that found me via a Blogger search of "MS06-040 exploits". Why are they looking? Who knows...but everyone should patch'em if you got'em.

UK and US Push for More Security Measures on Airplanes

Ok, this is getting a little silly, seriously. Here is the rundown.

Via News24 - Britain went on its highest alert for terrorist attacks early on Thursday after the discovery of a plot to blow up several planes flying between Britain and the United States.

The level of alert was raised to "critical" from "severe" as airport security was tightened.
British police earlier announced they had thwarted a major terrorist plot to allegedly blow up aircraft.


The plan was uncovered in a joint operation by Scotland Yard's anti-terrorist branch and security service, the Metropolitan Police said. British television said about 20 arrests had been made.

Sounds good, nice work Scotland yards. But wow wow...now the US is matching the new measures put in place by the UK on hand baggage.

Via ElectricNews - A British government statement said passengers would not be allowed to take on board any hand luggage except essential items in see-through bags. The U.S. Department of Homeland Security announced it was taking similar steps, including barring passengers from carrying liquids, including drinks, hair gel and lotions, on planes.

Are they serious? How about we fix whatever caused the TSA and TSA-like agencies to miss these serious security issues? I am a firm believer that everyone in the country should do their part to protect the country but when is the line reached?

I can only assume this plot has something to do with liquids....but what makes everyone in the world assume that what the terrorists attempt to do in the UK will be copied by those in the US?

I am pretty sure these terrorist groups are smart enough to run two different plots in two different nations against two different mode of transportation. But that is just my 2 cents.

So lets all go to the airport with a clear bag...makes me feel like I am a girl working at the Dillards in the local mall.

Wednesday, August 9, 2006

Wireless Device Driver Vulnerabilities

Ok, I have read several media write-ups about the speech given by Dave Maynor and "Johnny Cache" at Blackhat / Defcon and I have to say a couple of things.

Most of these articles are focusing WAY too much on the operating system used. Yes, it was running OS X.

Big deal, get over it. Who told everyone that Apple computers are totally secure and un-hackable? It wasn't me, that is for sure.

The truth is Apple computers have been hacked, rooted and used in botnets for some time now, this is pure fact. Like all computers/operating system, Apples are open to attack given the correct conditions. Accept this statement or not, but this is the truth.

The speech is was designed to point out very serious code problems in device drivers, which can lead to the complete compromise of the operating system since drivers normally run at SYSTEM / Kernel level access.

Sure, it is flashy to use wireless device drivers to prove this point, but the real problem goes way beyond wireless. Attacking device drivers isn't a new idea in the security world, but it hasn't been taken very serious by the media or the manufacturers until now.

So lets all stop making a point about which OS does that...or it wouldn't work on this because of blah and lets all focus on the real issue.

Device drivers across all platforms have not been properly code audited and are a fresh new hacking ground.

Intel has released new wireless drivers recently, yet Apple seems to be working harder on keeping everyone quiet about the issue instead of fixing it.

Do OS X users really feel that Apple is keeping quiet to protect them? I don't see how. Apple is keeping everyone quiet to cover their bottomline...not the OS X faithful.

With all that being said, the video is quite amazing.

See the full media coverage at the SecureWorks website.

Tuesday, August 8, 2006

Black Tuesday - Microsoft Security Updates for Aug 2006

As part of Microsoft's routine, monthly security update cycle we released the following 12 security updates on August 8, 2006:

  • MS06-040 - Critical - Vulnerability in Server Service Could Allow Remote Code Execution
  • MS06-041 - Critical - Vulnerability in DNS Resolution Could Allow Remote Code Execution
  • MS06-042 - Critical - Cumulative Security Update for Internet Explorer
  • MS06-043 - Critical -Vulnerability in Microsoft Windows Could Allow Remote Code Execution
  • MS06-044 - Critical - Vulnerability in Microsoft Management Console Could Allow Remote Code Execution
  • MS06-045 - Important - Vulnerability in Windows Explorer Could Allow Remote Code Execution
  • MS06-046 - Critical - Vulnerability in HTML Help Could Allow Remote Code Execution
  • MS06-047 - Critical - Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution
  • MS06-048 - Critical - Vulnerabilities in Microsoft Office Could Allow Remote Code Execution
  • MS06-049 - Important - Vulnerability in Windows Kernel Could Result in Elevation of Privilege
  • MS06-050 - Important - Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution
  • MS06-051 - Critical - Vulnerability in Windows Kernel Could Result in Remote Code Execution

Mad Props to Austin's Pedram Amini of the TippingPoint Security Research Team for reporting the Hyperlink Object Buffer Overflow Vulnerability - CVE-2006-3086.

Go get'em @ WindowsUpdate

Political Hacking News

Via Breitbart.com -

Democratic Sen. Joe Lieberman, who was locked in a battle with a political novice fueled by anti-war sentiment in the nation's most closely watched primary race Tuesday, accused his challenger's supporters of hacking his campaign Web site and e-mail system.

Lieberman campaign manager Sean Smith said the campaign has contacted the Connecticut attorney general's office and asked for a criminal investigation by state and federal authorities.



Via Kxan.com -

An Austin company is caught in the crossfire of the Mid-East war as Hezbollah's terror reaches Central Texas.

Broadwing Communications essentially threw Hezbollah off of the Internet this week. It came after the discovery that terror propaganda was linking to the company's network.



Interesting indeed....

Monday, August 7, 2006

Blackhat & Defcon in Photos

ZDI Party @ Body English















ZDI Party @ Body English




















Microsoft Party @ Pool at the Palms















Microsoft AfterParty @ Rain















View from the Limo @ 4am















Entry @ Caesars Palace




















Defcon Stuff















People @ a Defcon Speech




















Wall of Sheep
















CTF Results




















Cute Roller-girl




















How to "Bump" open locks...




















SensePost releasing Suru and LR




















Wednesday, August 2, 2006

Apple OSX Fetchmail Buffer Overflow

KF is at it again, reminding the public that security isn't just about which operating system you use.....




DMA[2006-0801a] - 'Apple OSX fetchmail buffer overflow'

Author: Kevin Finisterre

Vendor:
http://www.apple.com/

Product: 'Mac OSX <=10.4.7'


References:
http://www.digitalmunition.com/DMA[2006-0801a].txt
http://www.digitalmunition.com/getpwnedmail-x86.pl
http://www.digitalmunition.com/getpwnedmail-ppc.pl
http://www.freebsd.org/cgi/query-pr.cgi?pr=83805
http://fetchmail.berlios.de/fetchmail-SA-2005-01.txt
http://www.securityfocus.com/bid/14349

Description:
fetchmail-SA-2005-01 states that 'In fetchmail-6.2.5 and older, very long UIDs can cause fetchmail to crash, or potentially make it execute code placed on the stack. In some configurations, fetchmail is run by the root user to download mail for multiple accounts.'. The authors of fetchmail made patches for these issues available to the public on 2005-07-21.

In defiance of a 'very proactive approach to security' Apple's OSX remained unpatched for approximately one year after the vendor supplied patches were made available. Shortly after the vendor disclosure of this bug exploits were made available by The Mantis Project (bannedit (at) frontiernet (dot) net [email concealed]). Conicidentally a recent paper was written about exploiting buffer overflows and this vulnerability was used as an example:
http://packetstormsecurity.org/papers/attack/payload-rewrite_exploit.txt

See the released exploit information here.





Yet another example of how OS X users can be vulnerable to attack because Apple doesn't patch its own use of open source software. It isn't the first time and I bet it won't be the last.

Tuesday, August 1, 2006

Blackhat & Defcon

Well, I am off to Vegas tomorrow...it is going to be a crazy week. If anyone wants to meet up for drinks...just let me know.

Interesting Quote: Sunshine

Recently Japan released its annual defense report, which featured both China and North Korea prominently. No suprises there really.

Foreign Ministry spokesman Tomhiko Taniguchi says openness from Beijing would help dispel concerns about China's military modernization. China has rapidly increased military spending in the past decade.

"Sunshine is the best disinfectant and you have to be very much transparent," he said. "The Defense Agency and the Foreign Ministry, as well, are requesting China reveal everything that is going on in terms of defense buildup and the amount of defense budget and what sort of equipment and weaponry the Chinese military is using."

Take Mr. Taniguchi's quote out of the military context and it still very powerful.

"Sunshine is the best disinfectant..."

These five simple words say so much.

It can be compared to many other sayings about completely different subjects:
  • "Truth can set you free..."
  • "Knowing is half the battle..."
  • Art of War by Sun Tsu - "So it is said that if you know your enemies and know yourself, you will not be imperiled in a hundred battles; if you do not know your enemies but do know yourself, you will win one and lose one; if you do not know your enemies nor yourself, you will be imperiled in every single battle."
  • The famous Linus's Law, "given enough eyeballs, all bugs are shallow"
  • The vulnerability full disclosure theory - details of a security vulnerability are disclosed to the public, including details of the vulnerability and how to detect and exploit it
  • etc, etc, etc

All of these are saying one thing.....Information is power.

So true. But this also means that Mis-information is power....something to remember.

Scammers deploy Bots for eBay manipulation

Via Vuunet.com -

Scammers have turned to automated bots to create Ebay accounts with a positive feedback record, reports security vendor Fortinet.

Online criminals use the automated scripts or bots to create vast collections of user accounts with positive feedback records. Those accounts can then be used to attract buyers by offering high value items that are never delivered after the bot-master criminals have received payments.




It was only a matter of time. Scammers and phishers have fine-tuned their social engineering skills in the last couple of years. Phishing sites are becoming more "real" as more and more of them use account checking scripts and IE toolbar spoofing.

They know what it takes to trick the normal person and usually don't take the time to trick the "good guys". Many times, I see comments in the phish page itself that tell me when and where they mirrored the site from. This is nice, since some of the phish are focused on local regional brands.

The backend control scripts normally contain any e-mail addresses used and perhaps their group name...

I always love to see comments like C:\Documents and Settings\Claude\update-phish.php in phishing sites...lol Way to go Claude! Nice work...

Monday, July 31, 2006

Insurance Companies Won't Pay Because Thieves are Too Good

Via Wired -

Last summer Emad Wassef walked out of a Target store in Orange County, California, to find a big space where his 2003 Lincoln Navigator had been. The 38-year-old truck driver and former reserve Los Angeles police officer did what anyone would do: He reported the theft to the cops and called his insurance company.

Two weeks later, the black SUV turned up near the Mexico border, minus its stereo, airbags, DVD player, and door panels. Wassef assumed he had a straightforward claim for around $25,000. His insurer, Chicago-based Unitrin Direct, disagreed.



So normal unlucky car owners get shafted by the insurance companies before the thieves were "too good"??


Are you serious?

It is a known fact that RFID system are breakable...so how can they do this?

The bad guys are basically using a digital lockpick. Would we get shafted the same if someone broken in our homes using a standard lockpick set??

Saturday, July 29, 2006

Mass Source Code Auditing using Google

I just found this gem over at RootSecure.net:

The Bugle Project - "Google Source Code Bug Finder"

He came up some the slick idea of using Google to search for known bad functions in internet readable source code.

Here is one example Google search

"strncpy(bufferbuf,str,len)" filetype:c - Strncpy length miscalculation

Super cool stuff. Nice work Cipher.

Friday, July 28, 2006

Myspace Phishing - It never ends...

** WARNING - THIS IS NOT THE REAL MYSPACE **

http://logintomyspacerighthere.50webs.com/

Found this URL in an auto-bulletin "posted" by a friend today.

When will Myspace take action to stop these auto-bulletins??

Myspace should:
  1. Use a simple cookie setting to remove the ability for a 3rd party site to post bulletin onto a user's profile.
  2. Go over to Verisign and drop the couple of hundred dollars and get SSL on your login page. Seriously...what is the hold up??

Social-networking Sites Rife with Wormable Flaws

Via F-Secure Blog -

Web Application Worms exploit persistent Cross Site Scripting (XSS) vulnerabilities in websites. It's a new category of malware and it's a growing concern for popular websites. Social Networking sites seem to be the most popular target as of now. MySpace has already been hit by two such worms - the Samy worm in October last year and last week's Flash worm. Samy was written by a guy who wanted to become popular on MySpace. So he designed the worm to crawl through the site while furiously adding people to his friends list. The result: over a million "friends" in a couple of hours. Last week's worm exploited a vulnerability in Macromedia Flash to redirect MySpace users to an objectionable webpage.

Last week MySpace was also the target of a malicious banner advertisement that ran on the site. It used the WMF vulnerability in Windows to serve adware to more than a million users with unpatched machines.

All this piqued our interest and we decided to see how secure other popular social networking sites are against "wormable" XSS vulnerabilities. We picked two among the top social networking sites with a reported combined user base of 80 million. Within half an hour we had discovered over half a dozen potentially "wormable" XSS vulnerabilities in each site! We stopped looking after finding half a dozen, but we are sure there are a lot more holes in there. With about a day's work a malicious attacker with a half-decent knowledge of javascript could create a worm using just one of these vulnerabilities.

Something to consider: The WMF banner ad successfully reached about one million users. An automated worm utilizing a similarly malicious WMF exploit or a similar browser expoit (maybe even a 0-day exploit) could potentially reach a much, much larger audience of unpatched machines. Theoretically, this could be the entire user base...

Recommendations -

  1. End users need to patch their machines. There's no excuse not to.
  2. Web application developers must start taking security seriously. Yes, XSS issues are silly, easy to find and omnipresent. And XSS issues have stopped being funny for a long time now. They are a real danger with the advent of Phishing and Web Application worms that exploit a mass user base of millions of users within a very short time.

Of course, we have reported the issues to the affected websites and are working with them to get the issues fixed. And, of course, we aren't taking any names here.




This isn't much of a shocker to me and to other people that have used these sites. Myspace is totally blind the the ad companies and other groups that are taking advantage of their user base.

What has changed since Myspace hired Hemanshu Nigam? It was great PR, sure...but Myspace's code practices are horrible.

Security did not become an issue to them until Sammy did what he did. But even right now, there are ways to see "private blogs", etc.

Myspace security is nothing but smoke and mirrors at this point.

Take into consideration the information that SPI Labs just released and the picture gets even darker.

Thursday, July 27, 2006

In Iraq, Anyone can be Policeman for Few Dollars

By Nafia Abdel Jabbar and Patrick Fort - Baghdad

A disreputable crew of unshaven men wearing police uniforms pounces on a businessman before the horrified eyes of his wife as he leaves his home in an upscale Baghdad neighbourhood.

Luckily for the hapless commuter, two crisply dressed "heroes" show up, swiftly disarm the attackers and derisively tear off their fake "Iraqi Police" armbands.

Welcome to the world of state-owned television's public service announcements.

Outside in the real streets, however, the heroes don't always arrive and survivors of incident after bloody incident report being attacked by gunmen wearing apparently official security uniforms - with total impunity.

The attacks have reached such a level that the interior ministry this week issued phone numbers for its operations room so people can call to confirm the identities of gunmen in uniform.

"The ministry asked citizens to prevent such criminals from carrying out their dirty intentions by using the name of a force which works hard to serve the people," the ministry statement said.

Many Sunnis have accused the country's Shiite-dominated security forces of involvement in attacks and kidnappings, but would-be gunmen don't have to look far to find security uniforms.

"Iraqi army, police, ministry of interior, US army - choose! We have all the uniforms," said one salesman in Baghdad's downtown Tahrir Square.

With shirts available for 3.25 dollars (2.55 euros), pants at 5.50 dollars and an "IP" armband for one dollar, a hypothetical kidnapper would only have to spend 10 dollars for his disguise.

For those looking to add flair to the outfit, unit insignia and ranks range from 15 cents to a dollar. Genuine medals can even be bought at stores in the major hotels.

"I regret that military clothing can be found freely sold in the market or be imported," said Major General Abdel Aziz Mohammed in a briefing this week.

"We will import new uniforms that will be distributed to our units that no one will be able to obtain otherwise, and will be difficult to imitate," he said, repeating the oft-heard promise of new uniforms.

At the start of a month-old Baghdad security operation, the government also said that police and military units would wear new outfits that would be hard to imitate. They have yet to appear.

There is debate over whether the new outfits will even solve the problem. Merchants selling military garb point out that while some uniforms are counterfeit, most are the real deal - obtained from soldiers and police themselves.

"It's members of the different units that sell their uniforms," said one salesman.

A major from the interior ministry walking through the market explained to AFP that he had come here to sell his new uniform and buy an old one.

The officer said he could make a little profit of between 20 and 30 dollars a uniform - but still show superiors that his unit has the correct number of uniforms.

Salaries for soldiers and police range from 250 to 400 dollars per month, depending on rank, with soldiers making more than police in a country where prices always seem to be rising.

"We buy new uniforms for between 20 and 25 dollars and then resell them for 40 dollars, with the price depending on the state of the uniform. The price can go down," the salesman said.

On one occasion a member of the army sold 60 uniforms at once, but then the next day there was an operation. "They wanted them back. As a rule, we store the uniforms elsewhere," added the seller.

The true prizes in the market for military clothing are the rare US uniforms sold by the local interpreters working with the US army. These cost more than Iraqi uniforms, at around 70 dollars each.

The boots are particularly valued and cost 70 dollars a pair.

"The American boots are the best. Inimitable!" the salesman said.

Wednesday, July 26, 2006

FireFox 1.5.0.5 Released - Sorta

The release page is up, but it isn't officially being released until tomorrow (July 27th).

However, it is currently on their FTP server. ;)

FBI Hacker Gets Merciful Sentence - 6 Months of Home Detention

Via Softpedia News -

The FBI hacker Joseph Thomas Colon accused of illegally accessing the bureau's secret network in 2004, using FBI agent's password has recently received a sentence that spared him of jail time.

Although he was facing a potential four years behind bars for hacking the FBI's network while working at BAE Systems on the Trilogy project to upgrade the federal institution's aged IT infrastructure, Colon has successfully proven that his hack, while premeditated, did nothing to threaten national security. Based on this argument U.S. District Judge Richard Leon sentenced Colon to only six months of home detention. In addition the hacker will have to pay $20.000 in restitution to the Federal Bureau of Investigation.

Colon had pleaded guilty to four misdemeanor counts. All of them concerned premeditated access of governmental information while exceeding the authorization level. In doing so, Colon had sensitive data of no less than 38.000 FBI employees at his fingertips. In his defense, the accused stated numerous times that he actually meant to bring to the surface the systems' vulnerabilities while increasing network processes performance and speed, as was his job, and not to hack into the system.This is not a case of al-Qaeda people trying to sneak into the FBI system, stated Judge Richard J. Leon when he delivered his ruling.






This sounds pretty fair. The judge is right; this wasn't a terrorist attempting to damage America or anything. However, what Joseph did was illegal and beyond his scope of work, therefore he got in trouble.

From what I gather, he had access to the network and used a password brute-forcer on some entry point (LDAP, AD, etc). The simple fact that he was able to do this proves two points that are well known in the computer security industry.
  • Internal network security is just as important as external network security.
  • Insider attacks are a real danger and normally are harder to detect.

This case just points out that the FBI, like most huge corporations in the world, are pretty vulnerable once an attacker is beyond the perimeter security.

I like to call it "M&M Security" - hard on the outside; soft in the middle.

Monday, July 24, 2006

A Tough Call: Invisible Phone Or Invisible Friend

Washington Post has a great article on those bluetooth earpiece wearing freaks. Yep, that is right...I called you a freak. I don't like it when you are yelling in public...I think you are talking to me and I just want to stab you.

Happy Monday...

Mwsearch - Finding Malware with Google






In early July, Websense released information on a technique they developed to acquire malware samples using Google. Websense did not want to release details of the technique, fearing that it would be used for evil. However, in today’s world, anything and everything can be used for good or evil.

It was only a matter of time, before blackhats coded a tool and started to collected malware. So why shouldn't the good guy have the same tools? Anti-spyware and anti-virus companies could use this technique to refine signatures or fill in the detection gaps.

Once an idea is released, it is only a matter of transforming it to code...this is exactly what HD Moore did with Mwsearch.

Check out HD's recent "Internet Drive-By Shootings" blog, to understand the type of information that can found with this new tool. It should help the good guys find out more about what the bad guys are doing....

Go, use, detect and clean the infected....

Sunday, July 23, 2006

Malicious Trojan Disguised as Google Toolbar

Via Softpedia News -

Online Security Company SurfControl based in Scotts Valley, California, has issued a public warning revealing that it has detected a new malicious threat that impersonates a Google product. SurfControl claims to have identified e-mails disguised as being originated by Google that invite the users to follow up a link that would lead to the installation of the latest variant of Google Toolbar. The use of Google’s brand in an attack translates into consumer confidence and a human based vulnerability.

The link comprised in the e-mail leads to a spoofed Google Toolbar Web site that apparently offers the Mountain Views Company’s toolbar. In actuality, the fake page delivers a Backdoor Trojan instead of the Google Toolbar plug-in.

The fake Google Toolbar Web was spoofed correct addresses, and SurfControl warned that the hackers made use of Google’s redirection service to hide the real addresses. Users downloading the malicious Toolbar will become infected with Backdoor Trojan W32.Ranky.FW. The malware will eventually turn a compromised machine into a bot zombie.

SurfControl did not rank the threat with a high level, partly because the attempt is a poor programming compilation and defective in achieving its purpose. The company claims that it has toned its security products in accord with the new threat and that its customers are well protected.

Saturday, July 22, 2006

DHCP Exploit Publicly Available (MS06-036)

Published: 2006-07-22,Last Updated: 2006-07-22 13:21:20 UTC by Swa Frantzen (Version: 1)

As a "present" for blackhat an exploit against the DHCP client of Windows 2000 was released publicly. See MS06-036 for more details.

The exploit claims to add the user "bl4ck" with a very insecure password and might cause the service to terminate. The author left some suggestions for "improvement" in the source code, so expect potentially nastier versions to be used in real life. If you still have not patched your Windows client systems, it is a very good time to do so now.

The nature of DHCP makes it so that any device on a LAN can answer any and all DHCP request. So be sure people understand there is no need to attack or compromise any server first. Detecting this is helped slightly by DHCP's use of broadcasts (the client doesn't have an IP address).It is quite imaginable that this gets used not just over wired networks - where the defending staff could disable a port in a worst-case scenario - but also over wireless networks, hotspots, hotels etc. where no such option is available. Or it could be used in a multi-stage attack where this gets inside your network in other ways and then does its "magic" on the local LAN.

-----------------------------------

After talking to a couple of friends, this exploit isn't the best in the world. Exploitation of the bug will crash the DHCP service, leaving the target box without an IP address....that is the rub.

Anyways, I know a couple of people that are looking into the issue...but this one is pretty tricky to use. This trickiness will hopefully give corporate patch administrators the time to make the patch package and get it rolling...

http://www.milw0rm.com/exploits/2054

-Technocrat

Friday, July 21, 2006

Hacktivismo Launches ScatterChat - Secure IM

FOR IMMEDIATE RELEASE

Hacktivismo Launches ScatterChat for Secure, Private Communication

CULT OF THE DEAD COW (cDc) subdivision releases user-friendly software to facilitate anonymous communication and secure file transfers

NEW YORK, NY (PRWEB) July 21, 2006 Hacktivismo, an international group of hackers, human rights workers, lawyers, and computer security experts announces the release of ScatterChat (http://www.scatterchat.com/), a free, open source application designed to facilitate secure and private real-time communication over the Internet.

ScatterChat is unique in that it is intended for non-technical human rights activists and political dissidents operating behind oppressive national firewalls. It is an instant messaging client that provides end-to-end encryption over the Electronic Frontier Foundation-endorsed Tor network. Its security features include resiliency against partial compromise through perfect forward secrecy, immunity from replay attacks, and limited resistance to traffic analysis, all reinforced through a pro-actively secure design.

According to lead developer J. Salvatore Testa II, The anonymity and encryption that ScatterChat provides ensures that both the identities and messages of activists remain a mystery, even to well-funded totalitarian governments.

Hacktivismo will be announcing the release of ScatterChat at the HOPE conference taking place July 21-23, at the Hotel Pennsylvania in New York, NY.

ABOUT HACKTIVISMO

Hacktivismo, a subdivision of CULT OF THE DEAD COW (cDc), has been combating information rights abuses for more than a decade. Its Goolag campaign brought great visibility to the issue of Internet censorship in China. Hacktivismo assumes as an ethical point of departure the principles enshrined in the Universal Declaration on Human Rights and the International Convention on Civil and Political Rights.

ABOUT CULT OF THE DEAD COW

Founded in Lubbock, TX, CULT OF THE DEAD COW (cDc) is the most influential hacking group in the world. The cDc alumni reads like a Whos Who of hacking and includes a former Presidential advisor on Internet security, among others. The group is further distinguished by publishing the longest running e-zine on the Internet [est. 1984], stretching the limits of the First Amendment, and fighting anyone or any government that aspires to limit free speech.

PRESS CONTACT: press@hacktivismo.com

Also check out:
ASCII version (thanks to Barium of ACiD)
PDF version (thanks to DaYuM of the Ninja Strike Force)

Using TrueCrypt With NTFS Alternate Data Streams

Video via IronGeek.com

Basically he is using the ADS of a text file to hide the encrypted volume - good idea.

In the video he uses a text file as just a demo example, but I like to hide my volumes as 800MB-1GB "video" files.

Just name your volume "Family Guy EP1.avi"

Wednesday, July 19, 2006

What Happens When Money is More Important Than the Customer?

The customer gets screwed...bottom line.

So you have heard me say that Myspace is nothing more than an advanced ad machine that is focused on money? Right? Well, it is.

Don't believe me? Check this little blog over at Security Fix.

An online banner advertisement that ran on MySpace.com and other sites over the past week used a Windows security flaw to infect more than a million users with spyware when people merely browsed the sites with unpatched versions of Windows, according to data collected by iDefense, a Verisign company.

So, one of Myspace's official online banner advertisements infected million of users with spyware....umm...I rest my case.

It is true that Myspace users aren't really paying customers...but Myspace wouldn't be alive if users weren't there to click on their ads - so in a way, they need us much much more than we need them.

Tuesday, July 18, 2006

Microsoft buys Winternals

Microsoft Buys Winternals

Larry Seltzer over at eWeek.com has the write-up.

Microsoft on July 18 announced that it has acquired Winternals Software, which provides security, recovery and management tools for enterprises as well as a respected collection of free Windows tools on the Sysinternals site.

Thursday, July 13, 2006

iPod Forensics

Very interesting look at the iPod and ways in which it is used by the real-world criminal element. Also the forensics used to dig into the device for invesigations purposes.

iPod Forensics (pdf) - International Journal of Digital Evidence

Tuesday, July 11, 2006

Black Tuesday!

Man, I haven't been deep in the patch management scene for a while now, but I do keep up with what is going on.

Microsoft has released a load of patches today. Go get them.

DHCP and the IIS ASP bugs look pretty bad.

Kudos to my fellow Austin friends for finding the Mailslot boundary error in the Microsoft Server Service. Well Done!

Let the patch reversing game begin....*shoots gun up into air*