Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Sunday, November 26, 2006
Video Game Makers are Worse than Dope Dealers
These video game manufacturers ought to be taken out back and fed to the virtual hogs.
Last Sunday, my daughter, Rachel, 15, asked if we could go to Best Buy so she could check out a video game she loves called "Zelda."
"I just want to hold it," she said.
That sounded to me like a plea from a kid who really wants to own this game. So I suggested to my wife, Kay, and Rachel that we go to the store and just buy "Zelda."
Not that I understand the frenzy here. I'm so low-tech I can limbo under a gigabyte. I don't know "Zelda" from "Alice in Wonderland."
But I figure if a kid wants a $50 game bad enough to just "hold it," I could spring for that.
That's when I was told the game needed a $250 game system, something mysterious called a Wii.
Undaunted, I figured, what the heck, let's go for it. To make a kid happy, I can get out the checkbook.
So on Sunday afternoon, the three of us headed off to the store to buy "Zelda" and Wii, or so I thought.
We hit about half a dozen South Austin stores and couldn't find either the game or the system.
Seems like the miserable creeps at Nintendo, the video company that makes both the game and the system, had sent out just enough Wiis to create what is known as market interest.
When we left the house, Rachel was bubbly and happy. Heck, she even voluntarily cleaned her room, the biggest upset I'd seen since the Red Sox won the World Series.
But by the time we found out the Target on Ben White Boulevard had run out of Wiis, Rachel was in tears. I felt like a bag of ham.
They were out at Best Buy, too. The clerk told us that there was a guy lurking about the floor, offering to sell his Wii for $450 to distraught customers who couldn't find one. He suggested we track him down.
This attempt by the toy manufacturers to turn our children into emotional wrecks began in the '80s with the Cabbage Patch doll.
My idea of Cabbage Patch Doll aerobics would be to drag one behind a truck.
But American grandmothers didn't see it that way. Oh, no, the old birds loved this doll because their grandkids wanted one.
So the long gray line would form outside the store at 6 a.m. Then, when the doors sprung open at 7, these old women would beat each other over the head with their handbags to get their wrinkled fingers on a doll.
This tradition of rioting over polyurethane products continues today with video games. Last week, a man was shot while standing in line for a Sony PlayStation 3.
Sony ought to make an action game out of that: a bunch of cartoon shoppers in line waiting to buy toys while the bad guy on the screen guns them down for points.
Why can't you greedy buzzards at the game companies send out enough of your product to start with so we don't all go crazy? Or is that just too much to ask?
Well said...whats up with that?
Saturday, November 25, 2006
Tools of the Trade - Now with Beta-Carotene!
New features:
- Cain's MitM NTLM Challenge Spoofing. (Requires APR to be active and a MitM condition between victim hosts).You can now spoof server challenges in NTLM authentications; this feature enables the use of RainbowTables for cracking network hashes. WARNING !!! Enabling Challenge Spoofing cause users to fail authentications so use it carefully.
- NTLM Session Security authentications downgrade to LM&NTLMv1. The following protocols are supported: SMB, DCE/RPC, TDS, HTTP, POP3, IMAP, SMTP.
- LM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
- HALFLM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
- NTLM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
- New types of RainbowTables have been added to Winrtgen v2.2. "lmchall" and "ntlmchall" tables can be used against LM and NTLM response hashes for spoofed challenges (0x1122334455667788). "halflmchall" tables can be used against the first 8 bytes LM response hashes for spoofed challenges to recover the first 7 characters of the original password.
2) Winamp 5.32 has been released. This release does not appear to be in response to any security issues however.
Teenager Builds Nuclear Fusion Reactor in Basement
An American teenager has built a working nuclear fusion reactor in the basement of his parents' home.
Thiago Olson, 17, spent over 1,000 hours and two years getting the reactor to work, scavenging old equipment, buying components on eBay and persuading manufacturers to give him large discounts.
The reactor works by sucking the air from a reaction chamber and injecting in deuterium, a form of hydrogen. A charge of 40,000 volts is then applied, using equipment from a gutted mammogram scanner, forming a small ball of plasma.
"Originally, he wanted to build a hyperbolic chamber," Olson's mother Natalice told the Detroit Free Press, adding that she promptly said "no". But, when he asked about the nuclear fusion machine, she relented.
"I think it was pretty brave that he could think that he was capable to do something so amazing," she said.
The process itself is safe since the reaction ends as the power drops. It emits very low levels of X-rays which are not at harmful levels.
Olson, who is nicknamed 'Mad Scientist' by his friends, intends to pursue a career in physics research.
"I thought he was going to be a cook, because he liked to mix things," said Natalice Olson.
Friday, November 24, 2006
Mujahideen in Lebanon Allege Hezbollah and Syrian Intelligence Assassination Plot
In a message posted to a password-protected forum today, Tuesday, November 21, 2006, the Mujahideen in Lebanon responded to the assassination of Minister Pierre Amin Gemayel in Beirut, an event which occurred only hours earlier. The group claims that Hezbollah, in coordination with Syrian intelligence, is directly responsible for the assassination, and further, that an effort is under way to frame the incident as an al-Qaeda operation.
The statement reads: “The assassination was directly executed by five individuals from Hezbollah. They were divided into two cars and a yellow motorcycle.” The group alleges a false statement was printed prior to the assassination, in the refugee camp Nahr al-Bared, in which al-Qaeda is implicated in the attack. The Mujahideen in Lebanon view the assassination of Minister Gemayel as part of a continued effort on the part of Hezbollah and its Syrian backers to coerce Shia ministers into withdrawal, ultimately facilitating an overthrow of the Lebanese government.
The statement closes, “We are monitoring them,” referring to Syrian-supported Shi’ites in Lebanon.
Radioactive Polonium-210 Found in Blood of Russian Ex-Spy
Traces of radioactive polonium have been found in the blood of the deceased Russian ex-spy Alexander Litvinenko, the UK’s Health Protection Agency (HPA) said on Friday. His urine also tested positive for radiation.
“This is an unprecedented event in the UK,” said HPA chief executive Pat Troop. “It is the first time someone in the UK has apparently been deliberately poisoned with a radioactive agent.”
The agency is now assessing the health risks posed to members of the public who may have come into contact with Litvinenko, including family members and hospital staff who cared for him during the weeks he spent in hospital. They are also trying to decide the safest way for pathologists to conduct an autopsy of his body, and indeed whether such a procedure is safe enough to be performed at all.
Litvinenko, aged 43, died on Thursday of heart failure after claiming he had been poisoned in a London restaurant. He was formerly an agent of the Soviet, then the Russian, security service. He specialised in investigating organised crime and its involvement with corrupt officials.
High levels of radiation have been discovered in a central London hotel that Litvinenko frequented, and at the sushi restaurant where he said he ate on 1 November 2006. The restaurant has now been closed, said the HPA.
“Tests have established that Mr Litvinenko had a significant quantity of the radioactive isotope polonium-210 in his body,” the HPA announced on Friday. “It is not yet clear how this entered his body. Police are investigating this.”
[...]
"To poison someone, large amounts of polonium-210 are required and this would have to be manmade, perhaps from a particle accelerator or a nuclear reactor," said Dudley Goodhead at the UK's MRC Radiation and Genome Stability Unit. “Polonium has a half-life of 138 days. This means that if that was the poison it will still be in the body and in the area – which makes it relatively easy to identify.”
China Obtains B-2 Stealth Engine Secrets
China obtained secret stealth technology used on B-2 bomber engines from a Hawaii-based spy ring in a compromise U.S. officials say will allow Beijing to copy or counter a key weapon in the Pentagon's new strategy against China.
Details of the classified defense technology related to the B-2's engine exhaust system and its ability to avoid detection by infrared sensors were sold to Chinese officials by former defense contractor Noshir S. Gowadia, an Indian-born citizen charged with spying in a federal indictment released by prosecutors in Hawaii.
Additionally, Mr. Gowadia provided extensive technical assistance to Chinese weapons designers in developing a cruise missile with an engine exhaust system that is hard to detect by radar, according to court papers made public recently.
He also helped the Chinese modify a cruise missile so that it can intercept U.S. air-to-air missiles, and helped Chinese weapons designers improve testing and measurement facilities, the court papers state.
Most of the indictment, handed up Nov. 8, outlines how the engineer helped China develop a radar-evading stealth exhaust nozzle for a cruise missile engine.
Additionally, the court papers indicated that Mr. Gowadia sent e-mails to Israel, Germany, and Switzerland in 2002 and 2004 that contained data labeled "secret" and "top secret" that was related to U.S. stealth technology intended for use in the TH-98 Eurocopter and for foreign commercial aircraft.
One computer file found in Mr. Gowadia's Maui, Hawaii, home was a file containing the radar cross-sections of U.S. B-1 and F-15 jets and the Air Force's air-launched cruise missile, information that would be useful to countering those systems by anti-aircraft missiles or other air defense weapons.
The case is the second major military technology espionage case involving China. Earlier this year, two Chinese-born brothers in Los Angeles were arrested as suspects in passing Navy warship and submarine weapons secrets to China.
In all, Mr. Gowadia is charged with making at least six secret visits to China from 2002 through 2005, and being paid at least $110,000 by Chinese officials for highly classified defense technology supplied through January, according to court papers. Investigators think he was paid as much as $2 million, some of which remains in foreign bank accounts.
Thursday, November 23, 2006
Urban Word of the Day - Tryptophanatic
One who eats until they are engorged...and then proceeds to eat even more, usually resulting in a turkey coma. A glutton -- but a happy glutton nontheless.See also Thanksgiving and Grandma's cooking.
"Yeah, I was a total tryptophanatic over the holidays. I think I slept for about 30 hours after I ate that second turkey."
Tuesday, November 21, 2006
Tools of the Trade - 2 Grams of Fiber per Serving!
- Fixed (I hope) a bug related to Pcap capture on Mac OS X. Thanks to Christophe Thil for reporting the problem and to Kurt Grutzmacher and Diman Todorov for helping to track it down.
- Integrated all of your OS detection submissions since ALPHA11. The DB has increased 27% to 189 signatures. Notable additions include the Apple Airport Express, Windows Vista RC1, OpenBSD 4.0, a Sony TiVo device, and tons of broadband routers, printers, switches, and Linux kernels. Keep those submissions coming!
- Upgraded the included LibPCRE from version 6.4 to 6.7. Thanks to Jochen Voß (voss(a)seehuhn.de) for the suggestion (he found some bugs in 6.4)
2) On Nov 16th, Snort 2.6.1 was released. Snort 2.6.1 provides new functionality including the following:
- New pattern matcher with a significantly reduced memory footprint
- Introduction of stream5 for experimental use
- Improvements to stream4, including UDP session tracking and optimizations for the reassembly buffer
- Handling for reassembly of SMB fragmented data in DCE/RPC
- An ssh preprocessor for experimental use
- Updated Snort decoder that can decode GRE encapsulated packets
- Output plugin to allow Snort to configure Aruba access control
- Bug fixes and performance improvements
Pitch Black Metal Created with a Laser Pulse
"We've been surprised by the number of possible applications for this," says Chunlei Guo, assistant professor of optics at the University of Rochester." We wanted to see what would happen to a metal's properties under different laser conditions and we stumbled on this way to completely alter the reflective properties of metals."
The key to creating black metal is an ultra-brief, ultra-intense beam of light called a femtosecond laser pulse. The laser burst lasts only a few quadrillionths of a second. To get a grasp of that kind of speed--a femtosecond is to a second what a second is to about 32 million years.
During its brief burst, Guo's laser unleashes as much power as the entire grid of North America onto a spot the size of a needle point. That intense blast forces the surface of the metal to form and nanostructures--pits, globules, and strands that both dramatically increase the area of the surface and capture radiation. Some larger structures also form in subsequent blasts.
Guo's research team has tested the absorption capabilities for the black metal and confirmed that it can absorb virtually all the light that fall on it, making it pitch black.
This trick increases the exposed surface area of the metal exponentionally, very cool stuff indeed.
Five Reasons To Ignore John Gruber’s OS X Security Pundity
Today’s Daring Fireball post has two objectives:
- To tar eWeek Security pundit Larry Setzer, and the trade press in general, as biased, lazy, and incompetent when it comes to Mac security.
- To claim that Mac security is better than Windows security.
We can get behind one of those objectives. But Gruber isn’t going to let us do that: instead, he borrows support for his defensible argument to shore up a weak argument. This isn’t a new idea; it’s straight out of the Mac zealot playbook, and it’s the same tactic Gruber used during the Mac wireless debacle when he hid behind Brian Krebs’ reporting to throw a smoke screen over OS X kernel wireless vulnerabilities.
Here’s an example from today’s article. <;/em>Seltzer’s article claims that a recently released Symantec report on OS X security “revealed a collection of vulnerabilities and potential attacks that rivaled any major operating system”, and “in fact things are getting worse.” Instead of arguing that Seltzer doesn’t (and can’t) support that argument with facts, which would be boring, Gruber plays to his base: “nowhere in the report does it indicate that the ‘collection’ as a whole rivals that of any other operating system.”
But that’s an equally indefensible argument! Seltzer himself names operating systems that are in positions comparable to OS X: Linux and Solaris. Gruber’s M.O. is simple and he counts on his audience not to notice it: when a pundit or reporter overreaches, Daring Fireball leaps on the opportunity to claim that the opposite argument is true. It almost never is.
Please read the full blog from the link at the top. Thomas is spot on. I couldn't say it better myself. I saw the OSX blog entry this morning and was thinking the same thing. Of course, John totally overlooks the Metasploit OS X wireless vulnerability that was released recently....and if he thinks the "shipping" version isn't open to the same type of attack...he is sorely mistaken.
Just because Apple doesn't like to talk about their holes doesn't mean that people are exploiting them already...John must remember that a blackhat world does exist and they have exploits that will never be released. How quickly we forget about the OS X kernel flaw that was released during MoKB (which BSD patched years ago)...
Week of Oracle Database Bugs (WoODB)
The Week of Oracle Database Bugs
Based on the great idea of H D Moore "Month of Browser Bugs" and LMH "Month of Kernel Bugs", we are proud to announce that we are starting on December the "Week of Oracle Database Bugs" (WoODB).
What is the WoODB about?
An Oracle Database 0day will be released every day for a week on December.
Why are you doing this?
We want to show the current state of Oracle software ("in")security also we want to demostrate Oracle isn't getting any better at securing its products (you already know the history: two years or more to fix a bug, not fixing bugs, failing to fix bugs, lying about security efforts, etc, etc, etc.).
Why are you targeting only Oracle?
We have 0days for all Database software vendors but Oracle is "The #1 Star" when talking about lots of unpatched vulnerabilities and not caring about security.
Why not the Month of Oracle Database Bugs?
We could do the Year of Oracle Database Bugs but we think a week is enough to show how flawed Oracle software is, also we don't want to give away all our 0days:), anyways if you want to contribute send your Oracle 0days so this can be extended for another week or more.
Symantec : Me code write good - The l33t skillz of the virus writer
http://www.symantec.com/avcenter/reference/me.code.write.good.pdf
It deals with the buggy code that can commonly be found in worms / viruses.
It is an interesting read, but I was sad to see one big virus bug missing.
The Sasser FTPD Exploit. The exploit attacked a buffer overflow in the FTPD server installed and used by almost all major variants of the Sasser worm.
I remember when that exploit was released and it was just too funny...an exploit created for a vulnerability in a virus that was designed to target another operating system vulnerability.
Irony is funny sometimes...
'Beer Goggles' Research Commissioned by Bausch & Lomb
The drink-fuelled phenomenon is said to transform supposedly "ugly" people into beauties - until the morning after.
Researchers at Manchester University say while beauty is in the eye of the beer-holder, the amount of alcohol consumed is not the only factor.
Additional factors include the level of light in the pub or club, the drinker's own eyesight and the room's smokiness.
The distance between two people is also a factor.
They all add up to make the aesthetically-challenged more attractive, according to the formula.
The formula can work out a final score, ranging from less than one - where there is no beer goggle effect - to more than 100.
Nathan Efron, Professor of Clinical Optometry at the University of Manchester, said: "The beer goggles effect isn't solely dependent on how much alcohol a person consumes, there are other influencing factors at play too.
"For example, someone with normal vision, who has consumed five pints of beer and views a person 1.5 metres away in a fairly smoky and poorly lit room, will score 55, which means they would suffer from a moderate beer goggle effect."
The research was commissioned by eyecare firm Bausch & Lomb PureVision.
A poll showed that 68% of people had regretted giving their phone number to someone to whom they later realised they were not attracted.
A formula rating of less than one means no effect. Between one and 50 the person you would normally find unattractive appears less "visually offensive".
Non-appealing people become suddenly attractive between 51 and 100. At more than 100, someone not considered attractive looks like a super model.
See the link above for the formula...good stuff.
Man Arrested with $78,000 and Data about Nukes & Cyanide
DETROIT - A man was arrested at Detroit Metropolitan Airport after officials say they found him carrying more than $78,000 in cash and a laptop computer containing information about nuclear materials and cyanide.
Sisayehiticha Dinssa, an unemployed U.S. citizen, was arrested Tuesday after a dog caught the scent of narcotics on cash he was carrying, according to an affidavit filed in court.
When agents asked him if he had any cash to declare, he said he had $18,000, authorities said. But when agents checked his luggage, they found an additional $59,000. When they scrolled through his laptop, they said they found the mysterious files.
At a court hearing Wednesday, Dinssa was ordered held in custody until at least until Monday at the request of prosecutors.
Assistant U.S. Attorney Leonid Feller argued Dinssa was a potential risk to the community and federal agents want to get a warrant to search his computer more thoroughly, The Detroit News reported Thursday. U.S. Magistrate Donald Scheer approved Feller’s request to detain him.
Dinssa, who is from Dallas, arrived in Detroit from Nigeria by way of Amsterdam and was headed for Phoenix, Feller said. He is charged with concealing more than $10,000 in his luggage, which carries a maximum penalty of five years in prison, the Detroit Free Press reported.
A message seeking comment was left Thursday with his lawyer, Leroy Soles.
I always love these vauge news reports of people having "information about nuclear materials"...what does that mean? I wouldn't call him a terrorist, but he was clearly doing something he shouldn't be doing...
Who would go to Phoenix from Nigeria via Amsterdam and Detroit?...it isn't like he didn't have the money to get a more direct flight. Very fishy indeed...
So we found this guy, what about the other 10 that grabbed their bags before the dog was around?
Humor: Making Critical Decisions
"Deciding Like A Ninja"
Monday, November 20, 2006
Social Networks and the Importance of “Who You Know”
The old bromide is truer than ever. It’s not what you know, it’s who you know. And it’s especially who knows you. The emergence and influence of a whole new breed of social networks is a rapidly growing phenomenon. Moreover, a number of people are paying attention to social networks — not just anthropologists, but historians, business leaders, and a host of teenagers.
In large part, we can thank — or blame — the Internet. Despite its vast size and complexity, the Internet has turned out to be a profoundly personal venue. People around the globe are forming connections based on every conceivable common interest, from the serious and practical to the outright silly. In 2005, the 80-million-member networking Web site MySpace, a gathering place where people introduce themselves publicly to friends and strangers, received more page views than Google. And the movement continues to grow.
[...]
Mr. Gladwell identifies three types of social networkers: Mavens, Connectors, and Salesmen. Mavens love to gather knowledge and pass it on to others: Mr. Gladwell describes one Maven who didn’t just recommend a Volvo to a colleague, he accompanied him when he went to buy one to ensure he got the best deal. The Maven likes to exercise expertise and be helpful.
Connectors seem to know everyone. They can get information where it needs to go because they just love to connect. Paul Revere, best known for rallying Middlesex, Mass., farmers with his cry, “The British are coming!” in the Revolutionary War, was a classic Connector, with a knack for knowing and attracting people. Had the silversmith been less gregarious, argues Mr. Gladwell, then the colonists might have lost.
Salesmen can be great persuaders. They are irresistibly positive; their ideas and attitudes are infectious. In effect, their positive emotions transmit to other people. Mr. Gladwell gives the example of Tom Gau, a financial planner in southern California, who made a ridiculously low bid on a new home, yet persuaded the seller to accept it. When these three types of people interact in the context of a social network, little ideas can turn into big deals with astonishing speed.
I am currently working as a pen-tester for an international financial institution in Austin TX. I didn't learn about this job from Monster.com or from the paper....a friend in the UK told me about the opening. I passed my resume to him and he sent it back to TX...which got me the interview.
I met this friend 2-3 years old again while on the Full Disclosure security mailing list...and we have never met in real life. I have only spoken with him on the phone once....
So if anyone can tell you how true the above story is...it is me.
Israel Attempts to Take UAVs to the Nano-Scale
JERUSALEM (Reuters) - Israel is using nanotechnology to try to create a robot no bigger than a hornet that would be able to chase, photograph and kill its targets, an Israeli newspaper reported on Friday.
The flying robot, nicknamed the "bionic hornet", would be able to navigate its way down narrow alleyways to target otherwise unreachable enemies such as rocket launchers, the daily Yedioth Ahronoth said.
It is one of several weapons being developed by scientists to combat militants, it said. Others include super gloves that would give the user the strength of a "bionic man" and miniature sensors to detect suicide bombers.
The research integrates nanotechnology into Israel's security department and will find creative solutions to problems the army has been unable to address, Deputy Prime Minister Shimon Peres told Yedioth Ahronoth.
"The war in Lebanon proved that we need smaller weaponry. It's illogical to send a plane worth $100 million against a suicidal terrorist. So we are building futuristic weapons," Peres said.
The 34-day war in Lebanon ended with a U.N.-brokered ceasefire in mid-August. The war killed more than 1,200 Lebanese, mostly civilians, and 157 Israelis, mostly soldiers.
Prototypes for the new weapons are expected within three years, he said.
'Second Life' hit by Worm - Players Blindly Help
A self-replicating worm Linden Lab dubbed "grey goo" overtook online world Second Life Sunday, forcing the world's owners to block all logins but their own for about half an hour. According to comments on the company's blog, the worm planted spinning gold rings in the world. Perhaps a Pavlovian response by fans of Sega's old Sonic the Hedgehog game, or an indication of the general curious nature of people playing Second Life, players willingly interacted with the objects, spreading the worm even further. As the worm spread, players reported serious lag in the virtual world.
According to blog entries posted by Linden Lab, the company blocked users from logging in at about 2:45pm PST in order to manually eradicate the virtual world of the rings. Login capabilities were restored half an hour later.
The worm may well be the largest of its kind to hit an online world.
Sunday, November 19, 2006
Attacking RSA with Simple Branch Prediction Analysis (SBPA)
Very recently, a new software side-channel attack, called Branch Prediction Analysis (BPA) attack, has been discovered and also demonstrated to be practically feasible on popular commodity PC platforms. While the above recent attack still had the flavor of a classical timing attack against RSA, where one uses many execution-time measurements under the same key in order to statistically amplify some small but key-dependent timing differences, we dramatically improve upon the former result. We prove that a carefully written spy-process running simultaneously with an RSA-process, is able to collect during one \emph{single} RSA signing execution almost all of the secret key bits. We call such an attack, analyzing the CPU's Branch Predictor states through spying on a single quasi-parallel computation process, a {Simple Branch Prediction Analysis (SBPA)} attack --- sharply differentiating it from those one relying on statistical methods and requiring many computation measurements under the same key. The successful extraction of almost all secret key bits by our SBPA attack against an openSSL RSA implementation proves that the often recommended blinding or so called randomization techniques to protect RSA against side-channel attacks are, in the context of SBPA attacks, totally useless.
Updated UK Computer Misuse Act Damaging to Secuirty Research
The Police and Justice Bill 2006, which received Royal Assent last Wednesday, contains amendments to the Computer Misuse Act 1990 that alter the law surrounding the creation and distribution of 'dual use' software tools. These are tools such as nmap — a security scanner — which are primarily used by legitimate users and security researchers, but can also be used by hackers to scan networks for vulnerabilities.
The amendments to the law could potentially prohibit the downloading of such security tools, according to Malcolm Hutty, head of public affairs at the London Internet Exchange (LINX).
"We do have to have responsible software supply. However, [under these amendments] any form of download tool could be prohibited," said Hutty earlier this week. "The Government is inadvertently throwing the baby out with the bathwater."
Part 37 of the Police and Justice Bill amends section 3A, clause 2 of the CMA, and states: "A person is guilty of an offence if he supplies or offers to supply any article believing that it is likely to be used to commit, or to assist in the commission of, an offence."
This will place serious constraints on the distribution of security tools, as the prosecution must only prove that the distributor believed it was likely that the tool will be used for hacking, even if this was not his intention, said Richard Clayton, a Cambridge University security expert. This would include malware researchers, ISPs and universities that host download tools, Clayton claimed.
Malware researchers could also be severely constrained by the new law because of the definition of "article", according to Clayton and Hutty. Clause 4 of section 3A states: "In this section 'article' includes any program or data held in electronic form."
The law is supposed to cover virus writing and hacking tools, but the wording of the law also covers the disclosure of software flaws, according to Hutty.
"In theory this covers the announcement of software flaws. The fear in the security world is that the legislation makes it possible for a vendor to come along and say that if security researchers are making [software-flaw] information available to the public, they must know it will be used to exploit software, as well as used for beneficial purposes," said Hutty. "The chilling effects on security research is a concern."
Clayton added: "If you approach a company and say you've found a problem, they can issue a writ to silence you. HSBC threatened to sue the Guardian [over reports of research by Cardiff University into HSBC's online banking authentication procedure]. This shows people are starting to think about going to the law to deal with bad news about security."
Old Web Censorship Law Might Become Enforceable?
Introduced by Rep. Mike Oxley (R-Ohio) in 1999, the Child Online Protection Act (COPA) makes it a crime for commercial Web sites to give minors access to "harmful material," defined as any sexually explicit communication that lacks "serious literary, artistic, political, or scientific value." Violators face up to $50,000 in fines and six months in prison.
This affects far more than just porn producers -- even news organizations publishing articles and videos that could be deemed "harmful to minors" might be in trouble. Just last week, the Florida Supreme Court upheld a state version of COPA that restricted e-mail that could be deemed "harmful to minors."
Shortly after the bill was introducted, The American Civil Liberties Union immediately filed a lawsuit to block the U.S. Justice Department, and a federal judge granted an injunction barring prosecutors from enforcing the law. That injunction has been in place ever since.
But now that could change. On Monday, U.S. District Judge Lowell A. Reed, Jr. in Philadelphia will hear closing arguments in the Child Online Protection Act case, and a ruling is expected by early 2007.
You might remember the big Google vs the Government issue after the government requested huge amount of search terms from all the major search vendors. Well, all of that was for this law...the government had to prove that porn was on the internet. Is it really that hard to prove?
After looking over all the data, the government has deemed 1% of the Internet as Porn. I still think that is very low in my view. They aren't getting P2P, BitTorrent or FTP into account...
Regards, the language used in COPA is much too vague for today's world...
Saturday, November 18, 2006
Friday, November 17, 2006
Cornell Robot Builds its Own "Self-Image"
So Cornell researchers have built a robot that works out its own model of itself and can revise the model to adapt to injury. First, it teaches itself to walk. Then, when damaged, it teaches itself to limp. Although the test robot is a simple four-legged device, the researchers say the underlying algorithm could be used to build more complex robots that can deal with uncertain situations, like space exploration, and may help in understanding human and animal behavior.
The research, reported in the latest issue (Nov. 17) of the journal Science, is by Josh Bongard, a former Cornell postdoctoral researcher now on the faculty at the University of Vermont, Cornell graduate student Viktor Zykov and Hod Lipson, Cornell assistant professor of mechanical and aerospace engineering.
Instead of giving the robot a rigid set of instructions, the researchers let it discover its own nature and work out how to control itself, a process that seems to resemble the way human and animal babies discover and manipulate their bodies. The ability to build this "self-model" is what makes it able to adapt to injury.
"Most robots have a fixed model laboriously designed by human engineers," Lipson explained. "We showed, for the first time, how the model can emerge within the robot. It makes robots adaptive at a new level, because they can be given a task without requiring a model. It opens the door to a new level of machine cognition and sheds light on the age-old question of machine consciousness, which is all about internal models."
The robot, which looks like a four-armed starfish, starts out knowing only what its parts are, not how they are arranged or how to use them to fulfill its prime directive to move forward. To find out, it applies what amounts to the scientific method: theory followed by experiment followed by refined theory.
It begins by building a series of computer models of how its parts might be arranged, at first just putting them together in random arrangements. Then it develops commands it might send to its motors to test the models. A key step, the researchers said, is that it selects the commands most likely to produce different results depending on which model is correct. It executes the commands and revises its models based on the results. It repeats this cycle 15 times, then attempts to move forward.
Playstation 3: What the Hell is Wrong with People?
I am looking over all this Playstation 3 news and I can only wonder -"When did everyone go insane??"
Engadget.com is pulling together a list of PS3 crime cases.
PS3 crime spree, part II: Fall of man
PS3 Line Insanity; Pregnant Woman Tries Not To Give Birth While Waiting
After all it is said and done, your PS3 might be used to break internationally law anyways.
Tools of the Trade - Now with Color Safe Bleach!
1) Just a little note about the Nmap 4.20 Alpha 11. Shortly after installing the alpha, I did a quick test and it didn't seem to work. I had to run, but I told myself to look into the issue later. As it turns out, the alpha install also seem to mess up my fresh Wireshark 0.99.4. ...this only points to one thing - Winpcap.
If you see the follow problem, just uninstall Winpcap and re-install Winpcap 4.0 beta 2 and you should be ok.
C:\Documents and Settings\test\Desktop>nmap 192.168.123.1
Starting Nmap 4.20ALPHA11 ( http://insecure.org ) at 2006-11-17 16:20 Central Standard
Timednet: Failed to open device eth0
QUITTING!
2) Just today, Oxid.it released Cain & Abel v3.9. The Airpcap USB adapter for Windows has been supported since v3.3
Updates for v3.9 listed below:
- Added Ophcrack's RainbowTables support for NTLM Hashes Cryptanalysis attack.
- Added ability to dump MSCACHE hashes directly from SYSTEM & SECURITY registry hive files.
- MSCACHE Hashes Cryptanalysis via Sorted Rainbow Tables.
- ORACLE Hashes Cryptanalysis via Sorted Rainbow Tables.
- New RainbowTable types have been added to Winrtgen v2.0. "mscache" and "oracle" tables can be used against MSCACHE and ORACLE hashes for specific usernames that can be set in the configuration dialog.
3) On Oct. 30th, Tenable Network Security, Inc. announced the availability of Nessus 3.0.4 for Windows, Mac OS X, Linux, Solaris and FreeBSD. The windows port is officially out of beta.
GPS, GSM Cellphone Jammers Hit Mainstream
Don't get too reliant on that GPS receiver, Magellan, since companies are now starting to release devices that locally block GPS signals. Detectnu's device not only block GPS signals within a 50-meter (164-foot) radius, but also GSM cellphone signals in a 20-meter (65-foot) radius. Another such device—the RJ-G1575 GPS jammer from Radixon Hadrian—blocks GPS signals in a 50-kilometer (31-mile) radius. Now, I can completely understand cellphone jammers (hint: people have no concept of tact in New York City and love to yap about God knows what quite loudly), but blocking GPS? What good does that do, other than give mischief makers a rise?
Now if I can just get one of these installed in my car....
The Chewbacca Defense
The term Chewbacca defense is used to refer to any legal strategy or propaganda strategy that seeks to overwhelm its audience or jury with nonsensical arguments, as a way of confusing the audience and drowning out legitimate opposing arguments. It is thus a kind of logical fallacy, specifically, an ignoratio elenchi (red herring) fallacy.
Fear, uncertainty, and doubt (FUD) also can be viewed as a particular case of Chewbacca Defense, where the confusing arguments are tools for the spread of FUD.
The term Chewbacca Defense originated in the animated series South Park. The show satirized attorney Johnnie Cochran's closing argument defending O.J. Simpson in his murder trial.
The term Chewbacca Defense was first used in the South Park episode "Chef Aid", which premiered on October 7, 1998 as the fourteenth episode of the second season.
In the episode, Chef discovers that Alanis Morissette's (fictional) hit song "Stinky Britches" is the same as a song he wrote years ago, before he abandoned his musical aspirations. Chef contacts a "major record company" executive, seeking only to have his name credited as the composer of "Stinky Britches." Chef's claim is substantiated by a twenty-year-old recording of Chef performing the song.
The record company refuses, and furthermore hires Johnnie Cochran, who files a lawsuit against Chef for harassment. In court, Cochran resorts to his "famous" Chewbacca Defense, which he "used during the Simpson trial", according to Gerald Broflovski.
Thursday, November 16, 2006
Tax Dollars at Work: The Air Force Wants to Build "Subterranean Vehicles"
The Air Force wants to build "subterranean vehicles" to attack hard, and deeply buried targets.
See the full SBIR Overview.
SANS Top-20 - 2006 Update
http://www.sans.org/top20/?ref=1814#w1 (PDF)
Thief Uses MP3 Player in Phreaker Style Credit Card Scam
These were then interpreted using a modem line tap, or MLT, acquired from Canada, or passed through a computer software program bought illicitly in Ukraine.
Parsons, of Gorton, Manchester, was able to exploit his knowledge of credit card security systems to put together credit card numbers and the cards’ expiry dates. The gang used the data to encode and clone a number of credit cards.
Wednesday, November 15, 2006
Desktop Background Sites for Geeks

555 Design
Art. Lebedev Studio
Caedes
ClearlyPixelated
DeviantArt
Digital Blasphemy - Top Downloads
Digital Blasphemy - User Gallery
EndEffect.com (wallpapers open in pop-up window)
Flickr Wallpaper Group
GNOME Art
GNOME-Look
Interfacelift
KDE-Look
MacDesktops
Mandolux (stopsign photo above found here)
Pixelgirl
RAILhead Design
Sensitive Light
ShiftedReality
Skeedz
TwistedSun
VladStudio
Tuesday, November 14, 2006
Symantec: The Mac OS X Threat Landscape
Security vendor Symantec has issued a detailed report on current Apple Mac OS X threats, covering a wide range of security issues that affect the platform today.
The 29-page Symantec DeepSight report (PDF) was released on November 13, 2006 and is being made available through SecurityFocus. It offers an in-depth look at the current threat landscape on Mac OS X and is likely the most comprehensive document of its kind for Apple security threats.
The research report looks at significant OS X threats including local, remote and kernel vulnerabilities and then discusses overall system design weaknesses that contribute to insecurities on the Mac platform. The document also reviews the current state of malicious code, discussing the presence of several viruses and worms and the existence of three known rootkits for OS X.
Conclusion - Mac OS X admins need to take the same security steps as everyone else.
Sounds pretty smart to me...
Black Tuesday - Patch'em if You Got'em
Make sure you get the XMLHTTP patch. Also, make sure to deselect IE7 if you are waiting on that...
Also note that XP SP1 is no longer a supported platform. If you aren't on SP2 yet, then you can't patch.
Get a full rundown on the released patches over at ISC.
Happy Tuesday.
Phishing Kits Banned by UK's new Fraud Act 2006
A new anti-fraud bill has been passed into law for England and Wales. The Fraud Act 2006 received Royal Assent last week and will come into force in early 2007.
The new law aims to close a number of loopholes in preceding anti-fraud legislation, which the Government said was unsuited to modern fraud.
Until now there has been no single, general fraud law in English law, but an untidy mess of eight specific statutory crimes, such as 'obtaining property by deception,' and a vague common law offence of 'conspiracy to defraud'. Scotland does have a common law crime of fraud, committed when someone achieves a practical result by a false pretence.
The Fraud Act introduces a general offence of fraud which can be committed by false representation, by failing to disclose information or by abuse of position. The offence carries a maximum sentence of 10 years' imprisonment.
Hopefully they aren't forgetting about the security researchers that might have a phishing kit or two. I think I have one somewhere on my computer from the PIRT team.
Monday, November 13, 2006
RumorConfirmed: Sun Makes Java Open Source
Sun Microsystems Inc. said it will offer Java for free to widen distribution and adoption of the software platform among developers and companies using open- source technology such as Linux.
Java is being distributed under an open-source licensing plan that lets developers view and modify the software and also distribute it for free with other open-source technology, Santa Clara, California-based Sun said in a statement today
Sunday, November 12, 2006
Rumor Mill: Sun to Open Source Java under the GPL on Nov 13th
No, I'm Not A Doctor -- But I Can Search Google
A new study from a group of Australian doctors says that Google can help doctors diagnose tricky cases.
It's hard to know exactly why they needed a study to figure this out -- it would seem like doctors would be pretty familiar with searching reference materials if they needed help making a diagnosis, and given the wealth of knowledge that's online, as well as instances where it's proven helpful to doctors, you'd think they'd have figured it out by now. But perhaps the bigger point is to emphasize the value of collective, shared knowledge.
One of the common retorts from critics of the likes of Wikipedia is that using it, or other internet sources, is like letting a crowd of untrained people perform brain surgery. That's patently false, and when you have a group of trained, intelligent people (in this case, doctors), that are able to pick out the expert resources from the unreliable ones, the crowd and its shared knowledge can be quite useful.
Of course, Google and the internet as a whole can be quite a boon to cyberchondriacs, and people who think they can diagnose themselves by looking things up online.
However, the internet won't replace doctors -- it just offers them a tool to supplant the Physician's Desk Reference, medical journals and other more traditional resources.
Vista RTM "Partially" Cracked by Pirates Already
Well, so much for closing piracy loopholes! With Windows Vista and Office 2007 only just going Gold, and not even available to Microsoft beta testers, developers or volume licence subscribers, the first cracked versions have already hit the pirate boards.
The Windows version which has been released is called Vista BillGates. It doesn’t feature any activation cracks itself, and the supplied product key is just for the installation.
The activation crack is a separate download, and works by replacing the licensing components with components from beta builds. Then using a product key from Beta 1, Beta 2, RC1 or RC2, the Gold version of Vista can be activated online.
Saturday, November 11, 2006
Hacking Firefox Extensions to Work with 2.0
After a bit of reading, I found that it will work if the extension is modified a bit. So I asked my friend and Firefox theme creator, Aaron Spuler, for a little help. He told me about a simple modification that I could do in seconds. Here is how it worked....
1) Download the XPI file and open it with WinZip or WinRar (or whatever you use). Extract "install.rdf" and open that file with WordPad.

2) Modify the "maxVersion" variable from "1.5.0" to "2.0.*". As far as I can tell, you only need to change the first set, but you might need to change all three sets.
Original

Modified

3) Save the file and copy it back into the XPI file (overwriting the original file).
4) Install the Extension into Firefox, restart and test.

Now this works for Swtichproxy, but this will not work for all extensions. Firefox did change APIs and other things since 1.5, therefore other extensions may need to be re-coded work correctly.
Perfect Blogger has two other methods that work as well.
It's a Silly World
Aussie beef cattle enjoy a relaxing bottle of red
SYDNEY: A glass of red wine traditionally goes well with a steak, so at the behest of a top Japanese chef an Australian company is adding wine to beef - while it is still on the hoof.
Each animal gets about a liter of a fruity cabernet shiraz merlot mixed in with its feed each day for 60 days, company director John McLeod told the Sydney Morning Herald.
The idea was proposed by Japanese celebrity chef Akio Yamamoto, who suggested that Margaret River Premium Meat Exports followed the example of the Japanese producers of famed Wagyu beef, who pamper their cattle with beer, massages, and music.
"It's quite a good drop actually and they tend to eat more than they should so I guess they like the taste.
"The antioxidant properties that we associate with red wine appear to have an effect on the meat's color and shelf life, and from the tests we carried out the meat also tastes sweeter."
Keeping up with the Joneses
LONDON: More than 1,000 people called Jones gathered under one roof to break the world record for the biggest get-together of people with the same name.
Some 1,224 Joneses packed into the Wales Millennium Centre in Cardiff, smashing the previous record gathering of 583, set by the Norbergs of Sweden.
Guinness World Record officials had the task of keeping up with the Joneses and validated the attempt, after people with the Welsh surname descended from as far afield as Australia and the United States to take part.
Grace Jones, the flamboyant Jamaican-born 1980s pop star and former Bond girl, was among the famous Joneses entertaining their namesakes at the theatre.
Designer naff is the new cool, says 'Vogue'
LONDON: Designer naff, from kebabs, diamante, and fluffy slippers, will be all the rage in the New Year, said the British edition of style bible Vogue in its December issue.
Package holidays, jelly shoes - a 1980s favorite of little girls - and even hamburgers have been redesigned to become chic, it said.
"Cheap and cheerful favorites are going up in the world. The buzz phrase is 'upmarket-downmarket'," Vogue explained.
Designers have turned their talents to tacky items, reviving the fortunes of all things tasteless.
Kebabs, often a late-night staple food for vomiting British drunks, need to be salmon shish to cut it with fashionistas, while hamburgers get the nod if they are made using ultra-pricey Wagyu beef from Japanese cattle fed on grain and beer and regularly massaged.
Fluffy slippers can be cool, as long as they're sheepskin.
And Louis Vuitton has created jelly shoes for £160 ($300) per pair as "the naff seaside staple hits new fashion heights."
Eunuchs an effective weapon against India tax evasion
NEW DELHI: Eunuchs in eastern India were drafted by authorities to sing outside the homes of tax evaders to embarrass them into paying up, a report said.
Sari-clad eunuchs turned out in force alongside local tax collectors this week in Patna, capital of Bihar, India's most lawless state, the Indian Express reported.
"Pay the tax, pay the Patna Municipal Corporation tax," chorused the eunuchs on the doorstep of their first target, Ram Sagar Singh, who owed Rs100,000 ($2,240).
A mortified Singh promised to pay within a week, the report said.
Toronto wine cellar in the sky creates a buzz with new world record
TORONTO: A Toronto restaurant in the CN Tower claimed a new world record this week for the highest wine cellar. It prides itself on having 9,000 bottles stored 351 meters (1,151 feet) above ground in the world's tallest structure.
"It's pretty high," said Guinness World Record keeper Carey Low, who was sent to verify the claim to fame.
"I don't think this record will ever be broken," he said. There are taller buildings now being constructed elsewhere but I don't think they have plans for a top-floor restaurant or wine cellar."
The European-style wine cellar at 360 Restaurant was built in May 1997.
It resembles a typical underground wine cellar, with cedar racks and cherry doors. It features more than 550 labels from around the world that sell for anywhere from C$40 ($35) to C$3,000 for a 1993 French Burgundy.
Tools of the Trade - 100% Vegan
Also check out the "--open" option. It causes Nmap to show only open ports. Ports in the states openclosed" and "unfiltered" might be open, so those are shown unless the host has an overwhelming number of them.
2) Gaim 2.0.0 Beta5 was released recently. They fixed a bunch of buglets from the last beta. The Gaim Team recommends this release to anyone using the earlier betas, and to anyone having problems with a Gaim 1.x.x release. I updated from Gaim 2.0. Beta4 without a real issue. I couldn't get my OTR plugin to work however.
3) Metasploit is working hard on the MSF3 (with all its wireless hacking mojo). However, not long ago, they released Metasploit 2.7. It is mostly just a maintenance release which includes minor tweaks and fixes for 2.6. Bigger console for msfconsole, UI tweaks, and some cosmetic changes, etc.
In the words of HD Moore, "basically it sucks less on Windows now". Exploit development for 2.7 is a bit slower than normal because 3.0 is getting all the extra attention. But fear not, new exploits for 2.7 will be created.
Friday, November 10, 2006
India Puts Airports on High Alert Due to Possible Al-Qaeda Threat
India has declared a high security alert at several of its airports, following the discovery of an anonymous letter threatening car bomb attacks by the Al Qaeda terror network, officials say.
Government officials say security has been tightened at six airports in the south, including Bangalore, after a security advisory was sent to most Indian airports.
"The high alert was sounded following the discovery of a threatening letter at a rubbish bin in Chennai airport," a Home Ministry official in New Delhi said, asking not to be named.
"All necessary security measures have been put in place at all the airports to thwart any attack."
The measures include special checks just before embarkation, increased security around airports, additional baggage screenings and a "bit of passenger profiling," he said.
The note, written in Tamil, warned that Al Qaeda militants would attack airports with car bombs or strike at individual passenger planes.
The letter was first found by a cleaner, who threw it away, but it was later rediscovered.
Chennai airport director S Sreekumar told reporters that security agencies were alerted and an emergency meeting called.
"Although we have received similar threats in the past, this time as the letter particularly mentioned car bombs we could not take it lightly," he said.
Cleric Ayatollah Mohammad Emami-Kashani Hails Democrat's Win As Victory for Iran
Supreme Leader of Islamic Revolution Ayatollah Ali Khamenei said here Friday that Republicans' defeat in this week's midterm legislative elections show public opposition to the US' war mongering policies.
"That can not be considered a mere domestic event, rather it marks failure of the war mongering policies of (the US President George W.) Bush worldwide," said Ayatollah Khamenei in an address to a group of locals on the third day of his tour of Semnan.
Ayatollah Khamenei said Republicans' elections defeat can also mean victory of the Iranian nation in this juncture.
"Since Washington's hostile and war mongering policies have always been subjected to the Iranian nation, the defeat is in fact landmark victory of the Iranian nation in this political juncture," said the Supreme Leader.
[...]
Ayatollah Khamenei praised Iranians' success in test-firing tens of sophisticated missiles and arms in wargames and said, "This apparently unattainable goal has now been materialized."
According to the Telegraph.co.uk, Ayatollah Khameni issued an unprecedented new fatwa, or holy order, sanctioning the use of atomic weapons against its enemies at the beginning of 2006.
However in recent remarks, the Ayatollah suggested that Iran is against nuclear arms. This latest fatwa report appears to be a complete reversal from his other fatwa in 2005. Ayatollah Ali Khamenei has reputedly issued a fatwa forbidding the production, stockpiling and use of nuclear weapons with was cited in an official statement by the Iranian government at an August 2005 meeting of the International Atomic Energy Agency (IAEA) in Vienna.
So who knows....
SecuriTea's Interview with LMH - Mastermind Behind MoKB
November has been informally designated the “Month of Kernel Bugs” in security circles. The Month of Kernel Bugs began on November 1, with the publication of a vulnerability in Apple’s AirPort drivers. SecuriTeam blogs did an interview with LMH, who hosts the Month of Kernel Bugs project (aka MoKB).
Web-Attacker Exposed: Source Code Discovered
While reading our previous posts, you may have noticed quite a few references to something called the Web-Attacker toolkit. The reason we have mentioned Web-Attacker so frequently is that nearly one-third of the malicious websites we discover are using it to infect their victims; it is incredibly popular. Take a look at an introduction to Web-Attacker, translated directly from the Russian website that sells the kit:
Dear Friends! We would like to offer you multi-component exploit Web-Attacker, that realizes vulnerabilities in the internet browsers Internet Explorer and Mozilla Firefox. With the help of this exploit you will be able to install any programs on the local disks of visitors of your web pages. In the foundation of work of the exploit Web-Attacker, there are 7 already-known vulnerabilities in the internet browsers.
Objective of the Exploit: Hidden drop of the executable from the deleted source to the local hard drive of the site visitor.
Follow the link above for all the details. Very good write-up about one of the most widely used website hacking toolkits ever created. Nice job Websense.
Data Mining And How it Can Affect You!
How frightened would you be if you were secretly planning to get pregnant, without telling your husband, and discovered that someone had written to him telling him about it? Or, put the other way, how would you feel if you discovered your wife was pregnant only when someone dropped you a letter?
And who would that person be? It would have to be someone like Robbie "Cracker" Coltrane, right? A deep profiler with the power of a hypnotist...? Or it would have to be a Government spook. They could do it, surely, the way the world's spooks monitor all of us: easy. They tap our phones, right?
Well, the thing to remember is that it really did happen. And no, if you thought it was phone tapping, you're wrong, and it's a misunderstanding which I won't make any friends for clearing up. But you need to understand the basic principles of data mining to understand why the world of spooks and the world of search engines are about to overlap, and why you should be nervous about this.
It is a rather simple example of the world that is changing around us...yet it holds a powerful message. If we don't look at what is happening now, how do we know when "they" have gone too far?
MOKB-09-11-2006: Mac OS X fpathconf() syscall denial of service
Failure to handle unknown file types by the Mac OS X kernel (XNU) fpathconf() syscall causes a kernel panic, leading to an exploitable local denial of service by non-privileged users. The bug was fixed by FreeBSD on Tue Jun 27 23:08:36 2000 UTC (6 years, 4 months ago).
Thursday, November 9, 2006
Voter Confidence and Increased Accessibility Act (HR 550)
On Election Day 2006, many Virginians were among the millions of voters nationwide who cast their votes on electronic machines that lack paper trails. Voters thus could not verify that their votes were accurately recorded, and election officials will not be able to conduct a full and thorough recount.
That's bad enough, and with the close margin in Virginia's Senate race and the U.S. Senate at stake, it is especially tragic for the entire country, regardless of whom is ultimately declared the winner. Simple precautions could have been taken to prevent this and myriad other e-voting problems. Indeed, Montana fortunately requires a paper trail, which could aid a recount in its tight Senate race.
Thankfully, there's an existing solution for the whole country: Rep. Rush Holt's Voter Confidence and Increased Accessibility Act (HR 550) contains several critically important election reforms, including the requirement of a paper audit trail for all electronic voting machines, random audits, and public availability of all code used in elections. The bill has gained the support of 220 bipartisan cosponsors, and, according to Holt, it even has a chance to pass before the next Congress takes office in January.
Via rushholt.com -
The Voter Confidence and Increased Accessibility Act (H.R. 550) will:
- Mandate a voter-verified paper ballot for every vote cast in every federal election, nationwide; because the voter verified paper record is the only one verified by the voters themselves, rather than by the machines, it will serve as the vote of record in any case of inconsistency with electronic records;
- Protect the accessibility requirements of the Help America Vote Act for voters with disabilities;
- Require random, unannounced, hand-count audits of actual election results in every state, and in each county, for every Federal election;
- Prohibit the use of undisclosed software and wireless and concealed communications devices and internet connections in voting machines;
- Provide Federal funding to pay for implementation of voter-verified paper balloting; and
- Require full implementation by the 2006 elections
Tools of the Trade - Now with Reduced Sodium!!
2) Foundstone has added several interesting tools to their free collection. I haven't personally tested any of these tools myself, so let me know what you think of them.
- FSCrack v1.0.1 - FSCrack is a front end for John the Ripper (JtR) that provides a graphical user interface (GUI) for access to most of JtR’s functions.
- CredDigger v1.0 - CredDigger™ is a tool that attempts to gather data to assist with penetration testing on a corporate network by determining every host on which a given set of user credentials is valid, while also building a database of all user ID’s through various means and protocols.
- dumpAutoComplete v0.7 - This application will search for the default Firefox profile of the user who runs the tool and dump the AutoComplete cache in XML format to standard output. Alternatively, autocomplete files can be passed to the application and they will be parsed as well. This application understands mork based autocomplete files (Firefox 1.x) as well as SQLite based formhistory and webappsstore files (Firefox 2.x).
3) On Nov 7th, GomoR released SinFP 2.0.4-1. SinFP is a Perl module for OS fingerprinting. It even works for Windows with ActivePerl. Much props on that one.
SinFP is a new approach to OS fingerprinting, which bypasses limitations that nmap has. Nmap's approaches to fingerprinting has shown to be efficient for years. Nowadays, with the omni-presence of stateful filtering devices, PAT/NAT configurations and emerging packet normalization technologies, its approach to OS fingerprinting is becoming quite dated.
4) On Nov 7th, XSS Shell was released.
XSS Shell is a powerful XSS backdoor which allows interactively control over a Cross-site Scripting (XSS) vulnerability in a web application. It is a tool that builds on the XSS-Proxy type attacks. This might be helpful for the hard core pen-testers out there, but it has the smell of a more "blackhat" type tool.
4) On Nov 6th, ClamAV v0.88.6 was released. Bugfixes in this release:
- freshclam: apply timeout patch from Everton da Silva Marques (new options: ConnectTimeout and ReceiveTimeout)
- clamd: change stack size at the right place (closes bug#103)
Patch from Jonathan Chen - libclamav/petite.c: sanity check the number of rebuilt sections (speeds
up handling of malformed files)
5) On Nov 2nd, Philippe Biondi released Scapy v.1.5.0.
Scapy is a powerful interactive packet manipulation tool, packet generator, network scanner, network discovery tool, and packet sniffer.
6) On Nov 1st, FileZilla v2.2.29 was released. See the changelog for the details.
Wednesday, November 8, 2006
Royal Air Force Radar affected Cars says Ministry of Defense
Engines and lights cut out and speedometer dials swung up to 150mph as motorists drove past the dome.
At the time the MoD said there was no guarantee that the Trimingham radar on the north Norfolk coast was the cause.
It now says it will consider claims for compensation after an inquiry found the radar was "out of alignment".
An MoD spokeswoman said the inquiry revealed the Type 93 radar spinning inside the dome had been out of alignment between November last year and this February.
The spokeswoman said that there was no danger to the public or personnel but the MoD would now consider outstanding compensation claims on a case-by-case basis.
Neil Crayford, who runs the nearest garage, Crayford & Abbs at Mundesley, said he dealt with 30 calls over a couple of months.
He said the problem was still happening.
"We have had a Nissan Terrano in here three or four times in the past week with the same sort of problems - dials going haywire and blacking out, which we had to reset."
But the MOD spokeswoman said: "There is no known recurrence of the problems experienced last year."
Myspace Phish - Currently Active
As you can see from the picture below, the link redirects you to a third-party site.

Once this link is clicked, you are directed to the third party site, which thens loads another page into an IFRAME.

The page loaded into the IFRAME is the real phish attack. As you can see from this screenshot.

The phish is being hosted in China and the DNS name was created 2 days ago.


Analysis: Rumsfeld's Resignation
Washington (dpa) - US President George W Bush on Wednesday announced that Defence Secretary Donald Rumsfeld has resigned, one day after his Republican party was defeated in congressional elections that largely reflected voter discontent over the war in Iraq.
Rumsfeld was a key target of Democrats who captured control of the House and appeared close to retaking the Senate by campaigning on public anger over the conflict that has claimed the lives of more than 2,800 US soldiers and on the lack of a strategy by the Bush administration to resolve the conflict.
"After a series of thoughtful conversations Secretary Rumsfeld and I have agreed that the time is right for new leadership at the Pentagon," Bush said in the surprise announcement at a White House press conference.
Firefox & ThunderBird 1.5.0.8 Released
These versions address some security issues covered in MFSA2006-65, MFSA2006-66 and MFSA2006-67.
Download Firefox 1.5.0.8
Download Thunderbird 1.5.0.8
Tuesday, November 7, 2006
Air Force Establishing Cyberspace Command
Bristling over the thought that terrorists and other U.S. enemies could be controlling portions of the nation's virtual air space, the U.S. Air Force committed to funding a Cyberspace Command in late 2008, military officials said on Thursday.
The command would eventually be on even footing with the military branch's Air Command and Space Command, Air Force officials told Reuters. The group will be tasked with protecting both military and civilian areas of the Internet.
"The equivalent of what's happening in the cyberspace domain right now is if we were allowing al Qaeda to fly fighters over the United States right now on a routine basis," U.S. Air Force Lieutenant General Robert Elder said on the Marketplace radio show. "No way would we allow that to happen. We would definitely challenge them."
Online attackers have struck at the U.S. military through the Internet on a regular basis. Attacks using stealthy Trojan horses sent to less than ten targets have increased over the last two years. Sensitive personnel data has been stolen from several branches of the military.
Because of such incidents, government employees are held to toughened standards on laptop use and the Army has started to require Trusted Computing hardware in every laptop procured in the future.
The Cyberspace Command will be based at Barksdale Air Force Base in Louisiana, according to Reuters.
HBO Special Hacking Democracy
Take it with a gain of salt, but think about the message. It is clear that there are problems with the current voting system (computer based or not) and hopefully this hits on a couple of core issues.
HBO isn't the Discovery channel...just remember that.
Monday, November 6, 2006
New Windows XMLHTTP ActiveX Zero-Day Found
Another new zero-day exploit for Microsoft systems has appeared, capable of compromising fully patched IE 6/7 systems when a user visits a malicious website.Microsoft has issued an advisory on the ActiveX vulnerability and exploit, first discovered by Secunia and labeled as "extremely critical." All Microsoft systems except Windows Server 2003 are vulnerable. Users may fall victim just by visiting a maliciously crafted website.Deflecting responsibility for the situation, Microsoft advises users affected by the zero-day exploit to, "contact their local FBI office or post their complaint on the Internet Fraud Complaint Center Web site. Customers outside the U.S. should contact the national law enforcement agency in their country." The vulnerability affects hundreds of millions of computer systems, however. Of those vulnerable, it is not known how many users will visit malicious websites that contain the exploit before an official patch appears from Microsoft.
Microsoft Security Advisory (927892)
Secunia Security Advisory (SA22687)
Sunday, November 5, 2006
Al-Qaeda Remains the Vanguard of the Jihadist Movement
After five years of being subjected to the “global war on terror,” Osama bin Laden, Ayman al-Zawahiri, and the rest of the al-Qaeda leadership still have much to celebrate. While al-Qaeda has suffered greatly since 9/11, with its training camps in Afghanistan destroyed and a significant number of operatives killed or captured, the terrorist organization has nevertheless received new pledges of allegiance from prominent jihadist groups. Within the past two months, though largely ignored by the media, both the Algerian Salafist Group for Call and Combat (GSPC) and a faction of the Egyptian Islamic Group (EIG) officially joined al-Qaeda. Likewise, other recent claims of terrorist attacks in the Sudan and Palestine have come from groups calling themselves Al-Qaeda. To the jihadists, al-Qaeda’s brand name continues to carry much clout, indicating that despite the setbacks al-Qaeda has faced, the group and its leadership remain the vanguard of the global jihadist movement.
A Surveillance Society - Still Emerging or Already Here?
Richard Thomas, who said he raised concerns two years ago, spoke after research found people's actions were increasingly being monitored.
Researchers highlight "dataveillance", the use of credit card, mobile phone and loyalty card information, and CCTV. Monitoring of work rates, travel and telecommunications is also rising.
Surveillance society - full PDF report
There are up to 4.2m CCTV cameras in Britain - about one for every 14 people.
But surveillance ranges from US security agencies monitoring telecommunications traffic passing through Britain, to key stroke information used to gauge work rates and GPS information tracking company vehicles, the Report on the Surveillance Society says.
It predicts that by 2016 shoppers could be scanned as they enter stores, schools could bring in cards allowing parents to monitor what their children eat, and jobs may be refused to applicants who are seen as a health risk.
Other surveillance scenarios for 2016 include:
- Cars linked to global satellite navigation systems, which will provide the quickest route to avoid current congestion, automatically debit the mileage charge from bank accounts and allow police to monitor the speed of all cars and to track selected cars more closely.
- Employees being subject to biometric and psychometric tests combined with lifestyle profiles and diagnostic health tests, with jobs refused to those who are seen as a health risk or those who don't submit to the tests, and staff benefit packages drawn up depending upon any perceived future health problems that may affect an employee's productivity.
- Schools introducing card systems to allow parents to monitor what their children eat, their attendance, record of achievement and drug test results.
- Older people becoming more isolated as sensors and cameras in their home provide reassurance to their families who therefore need to pay fewer visits.
The terms Surveillance Society, Big Brother and even Big Mama are not new.
Big Brother hit general use after the release of George Orwell's novel Nineteen Eighty-Four. In the essay section of his novel 1985, Anthony Burgess states that Orwell got the idea for Big Brother from advertising hoardings current during WWII for educational correspondence courses run by a company called Bennett's.
The original posters are claimed to have shown Bennett himself - a kindly looking old man offering guidance and support to would-be students, with the slogan "Let me be your father."
When Bennett died, his company was inherited by his son, whose rather aggressive-looking face appeared on the posters instead, accompanied by the unappealing slogan: "Let me be your big brother".
Looking back in the news, we see people warning for years of the "up and coming" Surveillance Society.
2001 - Wired.com
2002 - SFGate.com
2004 - TimeOnlineUK
2005 - BBC News
So, I can only question. Are we here? Or are we on the edge?
