Wednesday, December 13, 2006

UCLA Computer Security Breach Exposes 800,000 Students

Via Washington Post -

LOS ANGELES -- The University of California, Los Angeles alerted about 800,000 current and former students, faculty and staff on Tuesday that their names and certain personal information were exposed after a hacker broke into a campus computer system.

It was one of the largest such breaches involving a U.S. higher education institution.

The attacks on the database began in October 2005 and ended Nov. 21 of this year, when computer security technicians noticed suspicious database queries, according to a statement posted on a school Web site set up to answer questions about the theft.

Acting Chancellor Norman Abrams said in a letter posted on the site that while the database includes Social Security numbers, home addresses and birth dates, there was no evidence any data have been misused.

The letter suggests, however, that recipients contact credit reporting agencies and take steps to minimize the risk of potential identity theft. The database does not include driver's license numbers or credit card or banking information.

"We have a responsibility to safeguard personal information, an obligation that we take very seriously," Abrams wrote. "I deeply regret any concern or inconvenience this incident may cause you."

School representatives did not return calls for additional comment.

The breach is among the latest involving universities, financial institutions, private companies and government agencies. A stolen Veterans Affairs laptop contained information on 26.5 million veterans, and a hacker into the Nebraska child-support computer system may have gotten data on 300,000 people and 9,000 employers.

Security experts said the UCLA breach, in the sheer number of people affected, appeared to be among the largest at an American college or university.

"To my knowledge, it's absolutely one of the largest," Rodney Petersen, security task force coordinator for Educause, a nonprofit higher education association, told the Los Angeles Times.

Petersen said that in a Educause survey released in October, about a quarter of 400 colleges said that they had experienced a security incident in which confidential information was compromised during the previous 12 months, the newspaper reported.


In 2005, a database at the University of Southern California was hacked, exposing the records of 270,000 individuals.

This spring, Ohio University announced the first of what would be identified as five cases of data theft, affecting thousands of students, alumni and employees _ including the president. About 173,000 Social Security numbers may have been stolen since March 2005, along with names, birth dates, medical records and home addresses.

Jim Davis, UCLA's chief information officer, said a computer trespasser used a program designed to exploit an undetected software flaw to bypass all security measures and gain access to the restricted database that contains information on about 800,000 current and former students, faculty and staff, as well as some student applicants and parents of students or applicants who applied for financial aid.

"In spite of our diligence, a sophisticated hacker found and exploited a subtle vulnerability in one of hundreds of applications," Davis said in the statement.

The university's investigation so far shows only that the hacker sought and obtained some of the Social Security numbers. But out of an abundance of caution, the school said, it was contacting everyone listed in the database.

About 3,200 of those being notified are current or former staff and faculty of UC Merced and current or former employees of the University of California Office of the President, for which UCLA does administrative processing.

Teenager Ran Internet Banking Scam Worth Nearly 50K

Via Stuff.co.nz -

A 16-year-old who police sent on a computer training course to improve his behaviour has admitted using a computer in an attempt to defraud banks of nearly $45,000.

The Upper Hutt teenager faces 26 fraud charges after hacking into people's internet banking accounts in August and September.

Police say he posted a computer virus on an internet message board and used it to capture details from people's personal computers.

Westpac, ANZ and ASB were all hit. The biggest transaction involved $6323, but the banks agreed to reimburse the losses.

The scam, combined with the boy's age, has raised fresh questions about the security of internet banking. It is just six months since banking ombudsman Liz Brown said banks had been slow to introduce two-factor authentication measures to fight internet fraud.

Judge Pat Grace remanded the youth to a secure residential facility in Palmerston North when he appeared in Upper Hutt Youth Court yesterday.

"You had set up quite a sophisticated operation to obtain some $50,000 from unsuspecting users of the internet.

"With the seriousness of this offending, I must be considering a custodial sentence as far as you are concerned, and because of that I'm going to decline your application for bail."

The youth, who cannot be named, has also admitted unrelated charges of kidnapping, aggravated robbery, threatening behaviour, unlawfully taking a motor vehicle, reckless driving, failing to stop and a string of driving offences. He is understood to owe about $35,000 in fines.

The computer fraud is believed to have been committed at his parents' home while he was unemployed.

The court is awaiting a psychological and social workers' report before hearing submissions on which court he should be sentenced in.

He faces up to five years' imprisonment if sentenced in the district court.

Constable Chris Muir said the youth decoded large amounts of information from people's computers to get account numbers and passwords.

"He just keeps the things he wants. He is a very clever boy."

It was possible that others had been targeted but had not complained to police.

About $15,000 had been recovered. The outstanding money had mainly been sent to the bank accounts of several co-offenders, who were also before the courts.

"It's very concerning that someone can basically sit at home and get everything off the internet and do what they want."

The police electronic crime lab's national manager Maarten Kleintjes said internet banking fraud was becoming more sophisticated.

He would not say if it was increasing, because banks shared the information with police in confidence.

Two-factor authentication - in which customers are issued with a new security code each time they log on - was the best way to guard against internet banking fraud.

Though it was compulsory in many countries, several major New Zealand banks - Westpac, ANZ and National - were yet to introduce the technology.

"The attacks are now being taken to a new level whereby people's machines are deliberately infiltrated with very sophisticated spyware, Mr Kleintjes said.

"They basically take control of your machine. They access your bank accounts but also steal your identity."

------------------------------------

The question is...was this young kid truly at the top of the scam? I find it hard to believe, but it is possible. The article only states that he uploaded the virus, did he also create the virus? If he didn't create the virus, then we have to ask who did...and what was their take on the scam?

Tuesday, December 12, 2006

Black Tuesday - Microsoft December Patches

As part of Microsoft's routine, monthly security update cycle, we released the following security updates on December 12, 2006:
  • MS06-072 - Critical - Microsoft Internet Explorer (KB925454)
  • MS06-073 - Critical - Microsoft Visual Studio (KB925674)
  • MS06-074 - Important - Microsoft Windows (KB926247)
  • MS06-075 - Important - Microsoft Windows (KB926255)
  • MS06-076 - Important - Microsoft Windows (KB923694)
  • MS06-077 - Important - Microsoft Windows (KB926121)
  • MS06-078 - Critical - Microsoft Windows Media Player (KB923689 and KB925398)
  • MS06-059 (re-release) - Critical - Microsoft Office (KB924164)

Note that the MS06-059 bulletin has been updated, revised and re-released for Microsoft Excel 2002 to address the issues identified in Microsoft Knowledge Base Article 924164. So no fix for the new Office zero-day, as expected.

Also, note that the ASX vulnerability that was released by sehato recently has been patched as part of MS06-078.

Patch'em if you got'em!

New IBM Memory Device Could Trash Flash

Via Unstrung -

Leap-frogging Moore's Law, scientists from IBM Corp. will announce on Wednesday a prototype of a new type of memory device that has the potential to replace flash memory in mobile devices such as music players, cell phones, and digital cameras.

Called "phase-change memory," the new technology runs more than 500 times faster than today's flash memory while using less than half the power to store information. Like flash, phase-change memory is "non-volatile" in that it retains data even when power to the device is switched off.

[...]

In other words, unlike flash, phase-change memory technology can improve as it gets smaller. The prototype device has a cross section of 3 nanometers (nm) by 20 nm, far smaller than flash can be built today and equaling the industry's chip-making size goals for 2015.

Because it uses so much less power, the new technology could also help solve the battery-life limitations now facing mobile-device makers.

[...]

Built around a core of a sophisticated alloy of germanium and antimony, phase-change memory devices work by alternating between a crystalline, ordered "phase," or arrangement of atoms, and a random, "amorphous" phase. An electrical pulse triggers the rapid shift by heating the alloy almost to the melting point.

So powerful and economic is phase-change memory, at least in theory, that it is seen as a possible replacement for disk drives in computers.

Monday, December 11, 2006

How to Survive a Robot Uprising

If popular culture has taught us anything, it is that someday mankind must face and destroy the growing robot menace.In print and on the big screen we have been deluged with scenarios of robot malfunction, misuse, and outright rebellion. Robots have descended on us from outer space, escaped from top-secret laboratories, and even traveled back in time to destroy us.

Today, scientists are working hard to bring these artificial creations to life. In Japan, fuzzy little real robots are delivering much appreciated hug therapy to the elderly. Children are frolicking with smiling robot toys. It all seems so innocuous. And yet how could so many Hollywood scripts be wrong? So take no chances. Arm yourself with expert knowledge. For the sake of humanity, listen to serious advice from real robotics experts. How else will you survive the inevitable future in which robots rebel against their human masters?

http://www.robotuprising.com/home.htm

McAfee's 2006 Virtual Criminology Report Released in Europe

Via the BCC -

Some criminal gangs are paying students while they study to ensure they have a pool of tech-savvy workers to call on, says the report from McAfee.

Others are cashing in on the glamour of the hi-tech world to tempt youngsters into embarking on a life of crime.

McAfee said children as young as 14 years old were being targeted by some criminal gangs.

Greg Day, security analyst at McAfee and one of the authors of the Virtual Criminology report, said it aimed to explore the digital underground and how and where the criminal and hi-tech worlds meet.

"We wanted to understand a bit more about the motivation and how people end up on this career path," said Mr Day.

The most successful cyber crime gangs were based on partnerships between those with the criminals skills and contacts and those with the technical ability, said Mr Day.

"Traditional criminals have the ability to move funds and use all of the background they have," he said, "but they don't have the technical expertise."

As the number of criminal gangs looking to move into cyber crime expanded, it got harder to recruit skilled hackers, said Mr Day. This has led criminals to target university students all around the world.

"Some students are being sponsored through their IT degree," said Mr Day. Once qualified, the graduates go to work for the criminal gangs.



So this report was released in Europe last week, but won't be released in the US until early January. So can someone in Europe provide a link to the report somewhere? =)

Sunday, December 10, 2006

EPA to Consider Removing Lead from Regulated Pollutant List

Every since I was a little kid, I have had various government groups telling me that lead was not something I wanted in my body. So why now is the EPA talking about maybe pulling it from the Regulated Pollutant List??

According to Wikpedia,

Lead is a poisonous metal that can damage nervous connections (especially in young children) and cause blood and brain disorders. Long term exposure to lead or its salts (especially soluble salts or the strong oxidant PbO2) can cause nephropathy, and colic-like abdominal pains. The historical use of lead acetate (also known as sugar of lead) by the Roman Empire as a sweetener for wine is considered by some to be the cause of the dementia which affected many of the Roman Emperors. At one point in time, some lead compounds, because of their sweetness, were used by candy makers. Although this has been banned in industrialized nations, there was a 2004 scandal involving lead-laced Mexican candy being eaten by children in California.

The concern about lead's role in mental retardation in children has brought about widespread reduction in its use (lead exposure has been linked to schizophrenia). Lead-white paint has been withdrawn from sale in industralised countries. The yellow lead chromate is still in use; for example, Holland Colours Holcolan Yellow. Many older houses may still contain substantial lead in their old paint; it is generally recommended that old paint should not be stripped by sanding, as this generates inhalable dust.
We have created tons of laws and rules to reduce the amount of lead in our environment, to remove lead from paint and gas, to educate the public on the dangerous of lead in the body......we even worked to remove it from the air. And this measures appear to have worked.

So can someone tell me why we would remove lead from the Regulated Pollutant List (as it applies to the Clean Air Act)?

Perhaps I am just missing something.

Saturday, December 9, 2006

MS Windows DNS Resolution Remote DoS PoC (MS06-041)

This was posted on Milw0rm today.

http://www.milw0rm.com/exploits/2900

This vulnerabilitiy was patched by Microsoft in August 2006 (MS06-041).

According to Microsoft, code execution is possible with this hole. So take this DoS PoC seriously and patch if you haven't already.

Then again, if you haven't applied the patches that were released in August, then you have a load of other trouble beyond this...

Humor: Apple Employee Fired For Thinking Different

Via theOnion (1999) -

CUPERTINO, CA—Brent Barlow, 27, a software analyst and beta-tester at Apple Computer headquarters in Cupertino, was fired Monday for "thinking a little too different."

Apple spokespersons said the firing was necessary because Barlow "consistently failed to adhere to the normal standards of conduct and daily routines expected of employees of Apple Computer."

Among the floutings of convention cited in Barlow's Apple employee file: developing a pulley system to store his mountain bike above his workstation, listening to Bob Dylan on his headphones while testing software, and taking barefoot walks around the Apple campus to "feel more connected to the creative energy of others."

"It's okay to think outside the box," said Avie Tevanian, Apple senior vice-president of software engineering. "In fact, we very much encourage that sort of thing here at Apple. But in Mr. Barlow's case, he went just a bit too far."

Barlow was first written up in September 1996, when he was cited for "unprofessional and inappropriate personal modifications to his workspace." In addition to taped-up pictures of Mahatma Gandhi, Albert Einstein and R. Buckminster Fuller, Barlow painted a large red question mark on the side of his monitor, scanned and displayed a non-approved desktop screen image of Jim Henson, and replaced his computer's trademarked Apple system beep with a snippet of the John Lennon song "Imagine."

"I like to explore problems from unusual angles," said the ponytailed Barlow, cleaning out the desk he has occupied since joining Apple in 1995. "And being in a free-form environment of my own creation really helps me get in the right frame of mind."

Barlow's most recent formal write-up came last Thursday, when his team supervisor caught him doing a headstand.

"I was stuck on this bug I discovered in the new Mac OS X system software that Apple's developing. No matter what I tried, nothing worked," Barlow said. "So I thought to myself, what I need to do is turn my whole approach to this problem upside-down. And what better way to do that than by standing on your head?"

In an effort to prevent such incidents of "excessive iconoclasm" in the future, Apple has developed a manual outlining the company's rules and regulations regarding individualism. Permitted will be such unorthodox activities as removing shoes when seated or within four feet of a desk; whistling when given prior written permission from a direct supervisor; and kicking puddles, provided the kicking is conducted during one's lunch hour and the puddle is one of the 35 on the Apple campus specifically designated for such a purpose. Prohibited will be such "gratuitously idiosyncratic" behaviors as singing out loud, flying kites and catching butterflies.

"Of course, we want our employees to be individuals and 'do their own thing,' so to speak," Apple director of corporate communications Michael Landau said. "But Mr. Barlow's behavior consistently crossed the line. If he wants to think that different, he can do it on his own time."

Technology in the Public - Rebooting Airplanes

There are some interesting yet kind of scary stories over at the Risks Digest - Forum on Risks to the Public in Computers and Related Systems.

These two really stood out...


Rebooting Airplanes
<"Douglas W. Jones">
Tue, 28 Nov 2006 13:29:42 -0600


In the last few weeks, I've done quite a bit of flying, and twice, now, I've been on planes where they had to reboot.

The first trip where this happened, as we were scheduled to leave the gate, there was a delay, and then the pilot said over the intercom: "We're having trouble with some of the cockpit instruments, so I'm going to force a hard reboot by switching off all the power for a bit." The lights and all other power on the plane then went off, and after a fifteen second pause, on again. A minute later, the pilot said: "That seems to have fixed the problem," and we were off.

I wasn't impressed. As far as I am concerned, this is clear evidence of a genuine design error somewhere in the system.

The second problem happened on Sunday, on a flight back from Amsterdam. On that flight, they had serious problems with the in-flight video on demand system. They tried a "soft reboot" of some kind, and it didn't work, so they then tried two "hard reboots," their term, and after the second try, it worked fine. Their instructions were "until the system comes all the way up, please don't touch any buttons." That alone suggests poor design. The system ought to come up with interrupts disabled on any devices that it's not ready to listen to, after all.

The reboot process took close to half an hour, and watching the displays in the seat backs that were visible from my seat, I could see that they were being rebooted in sequence, about one per second. Furthermore, as each in-seat display was rebooted, it showed the Linux penguin and then a Linux boot script, revealing that each seat-back display was a little Linux system, suggesting that they were all networked to a video server for the plane.

Again, the need for these global reboots is strong evidence that the systems were not well designed,

I wonder if both of these stories illustrate problems with the kinds of graduates we are turning out these days. CS programs across the country are emphasizing high-level courses in web programming, but fewer and fewer students know anything about the fundamentals of parallel programming that underly things. So, in constructing the kinds of distributed applications that show up in contexts like streaming video and cockpit instrumentation, they are working without the theoretical underpinnings needed to understand the problems they encounter.


Mascalls, Manchester, what's the difference?
<"Mark Brader">
Sat, 2 Dec 2006 04:36:21 -0500 (EST)

A British ambulance crew, transferring a patient to a hospital where they had never gone before, drove 200 miles out of their way before realizing that their satellite navigation device had given them the wrong directions.

These reports mention other incidents of sat-nav gaffes, but don't say what the actual error was this time; this shorter one says that the system showed their destination's address as being in Brentwood in Manchester instead of Brentwood in West London.

The patient was not harmed, and the crew has been told they should have known better.

Friday, December 8, 2006

Tools of the Trade - Increased Flavanol Formula!!

Flavanol is the antioxidant in dark chocolate which lowers blood pressure by neutralizing potentially cell-damaging substances known as oxygen free radicals. Anyways, on to the tools...

1) Nmap 4.20 has broken free of its RC chains and is now free to come outside and play. You might as well, run over to Winpcap.org and grab the new Winpcap 4.0 beta 3 as well. Download it, use it, and then tell Fyodor how cool it is. Improvements made over RC2 include the following:

  • Updated nmap-mac-prefixes to reflect the latest OUI DB from the IEEE as of Dec 7.
  • Integrated the latest OS fingerprint submissions. The 2nd generation DB size has grown to 231 fingerprints. Please keep them coming! New fingerprints include Mac OS X Server 10.5 pre-release, NetBSD 4.99.4, Windows NT, and much more.
  • Fixed a segmentation fault in the new OS detection system which was reported by Craig Humphrey and Sebastian Garcia.
  • Fixed a TCP sequence prediction difficulty indicator bug. The index is supposed to go from 0 ("trivial joke") to about 260 (OpenBSD). But some systems generated ISNs so insecurely that Nmap went berserk and reported a negative difficulty index. This generally only affects some printers, crappy cable modems, and Microsoft Windows (old versions). Thanks to Sebastian Garcia for helping me track down the problem.

2) GnuPG 1.4.6 was recently released. This update version fixes the highly critical vulnerability exposed in early December.

3) On Dec 7th, GooglePath 0.3 was released by Matteo Cantoni. Googlegath is a free open source perl utility to obtain information through Google searches. It could be useful for penetration testing, security scanning, script kiddies stuff etc..

4) On Nov 30th, ModSecuirty 2.0.4 was released. Mod Security is an intrusion detection and prevention engine for Web applications which operates as an Apache module or Java Servlet filter. It should be noted that ModSecurity & Thinking Stone Ltd. were recently acquired by Breach Security, Inc. For more info about ModSecurity, check out this great SecurityFocus interview with Ivan Ristic.

5) On Nov 30th, Stunnel 4.20 was released. Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL available on both UNIX and Windows.

5) On Nov 27th, Matteo Cantoni released Snmpcheck 1.6. Snmpcheck is a free open source perl utility to get information via SNMP protocols. It works fine against Windows, Linux, Cisco, HP-UX, SunOS systems and any devices with SNMP protocol support. Snmpcheck runs on GNU/Linux, *BSD and Windows (Cygwin) systems.

If you are into fuzzers, check out JBroFuzz from OWASP. JBroFuzz is a stateless network protocol fuzzer that emerged from the needs of penetration testing. Written in Java, it allows for the identification of certain classes of security vulnerabilities; by means of creating malformed data and having the network protocol in question consume the data.

Go fuzz some stuff, all the cool kids are doing it. Many software development companies are fuzzing the crap out of their products before release...but security researchers are still finding very serious flaws with simple fuzzers.

In other news, I noticed that my THC Amap install appears to be updating correctly again. There were no updates available, but it wasn't throwing an error anymore. You might remember that THC has some domain issues a while back ago...and this was causing the problem.

Litvinenko Believed Poisoned At Hotel Bar

Via playfuls.com -

Investigators in London said they believe former Russian spy Alexander Litvinenko was poisoned at a hotel bar while meeting with two Russian businessmen.

The investigators said the seven staff members at the Pine Bar in London's Millennium Hotel who were working Nov. 1 -- the night of meeting -- tested positive for polonium-210, the radioactive isotope that poisoned the former spy, The Times of London reported Friday.

Health authorities were working Thursday to contact some 250 customers who visited the bar that night to see if those patrons were also exposed to radioactivity.

Pat Troop, of Britain's Health Protection Agency, told The Times the levels of the isotope found in the bar staff were similar to the level found in Litvinenko's wife. He said the levels posed no short-term danger to the infected staff but there was a "very small" risk that they could later develop cancer as a result of exposure.

Thursday, December 7, 2006

Hollywood Starts to Sell "Fair Use" Rights

Via EFF -

"Apparently, Hollywood believes that you should have to re-purchase all your DVD movies a second time if you want to watch them on your iPod." That's what I said last week, commenting on the Paramount v. Load-N-Go lawsuit, in which Hollywood studios claimed that it is illegal to rip a DVD to put on a personal video player (PVP), even if you own the DVD.

Well, this week the other shoe dropped. According to an article in the New York Times:

Customers who buy the physical DVD of Warner Brothers’ “Superman Returns” in a Wal-Mart store will have the option of downloading a digital copy of the film to their portable devices for $1.97, personal computer for $2.97, or both for $3.97.


So you buy the DVD, and if you want a copy on your PVP or computer, you have to pay a second time. Despite the fact that you bought the DVD, and you have a DVD drive in your computer that is perfectly capable of making a personal-use copy. Imagine if the record labels offered you this "deal" for every CD you bought -- pay us a few dollars extra, and you can have a copy for your iPod. And a few more dollars, if you want a copy on your computer, too!

As LA Times reporter Jon Healey puts it
in his blog: "So from the perspective of the studios and federal officials, consumers have to pay for the privilege of doing the sorts of things with DVDs that they're accustomed to doing with CDs (and LPs and cassettes)."

This latest bitter fruit from Hollywood is brought to you by the
DMCA, which treats "protected" content (like the encrypted video on DVDs), differently from "unprotected" content (like every audio and video media format introduced before 1996). Thanks to the DMCA, Hollywood believes fair use personal-use copies simply do not exist when it comes to DVDs.

Given that the Copyright Office has refused [
PDF, see p. 71-72] to recognize any DMCA exemption for space-shifting, claiming that putting a DVD you own on your iPod "is either infringing, or, even if it were noninfringing, would be merely a convenience," (excuse me, Copyright Office, that's a decision for a court to make) the ball is now in Congress' court. Let's hope Congressman Rick Boucher is listening and will reintroduce his DMCA reform bill first thing next year.

---------------------------------------

This is just twisted...and seems very underhanded, but we are talking about the MPAA.

Polonium: The Terrorists' Perfect WMD

Via the CounterTerroism Blog -

The disclosure that "seven workers at the Millennium Hotel, where former KGB agent Alexander Litvinenko met a contact on the day he fell ill, have tested positive for 'low levels' of polonium" further expands the serious consequences of the investigation into Litvinenko's murder. (UPDATE: A former KGB who met with Litvinenko in London has fallen into a coma from contact with "a radioactive substance.")

A CTB reader who graduated from MIT wrote me recently with the following information on polonium:

Polonium 210 can be manufactured in any small research reactor such as those found in universities around the world. The single poisoning seems to me to be a wakeup call that polonium 210 is probably the best WMD in the world. Wikipedia gives the lethal dose as 0.1 micrograms, think of a Vitamin C tablet divided into 10 million pieces. When dissolved in mild acid, such as is in the gut, a lethal dose will produce about 10 trillion atoms which tend to permeate the body and leak out of the pores. If divided and encapsulated (think time release capsule) a small amount of polonium 210 could be weaponized to float on the breeze like anthrax, it would be undetectable, indestructible and any residue would lose potency after
just a few years.

-------------------------------------

Very interesting idea to say the least...

Microsoft Windows Media Player DoS Zero-Day

Recently a Windows Media Player zero-day was released. The exploit uses the ASX playlist as the attack vector.

eEye and others are researching the issue with the view that remote code execution is highly possible. This could turn ugly on social sites (like Myspace) if someone finds the memory "sweetspot", so keep an eye out on this one.

ASX radio station streaming is done all the time on Myspace.

http://research.eeye.com/html/alerts/zeroday/20061122.html

Shocking Drug Trend - Texas Cheese

I read about this several weeks ago in another article but decided not to post it. It seems the problem isn't as limited as I was hoping...so here you go.

Via ABC News -

A new wave of 10- to 12-year-olds addicted to heroin is washing up at Dallas drug rehab centers and emergency rooms.

The preteens are mixing the powerful opiate with crushed Tylenol PM, a concoction they call "cheese," according to Michelle Hemm, Director of the Dallas Phoenix House drug treatment facility.

As reported in "The Blotter" in May, a few 11-year-olds in Dallas were using "cheese," but now that is a common phenomenon in Dallas schools.

"We've seen a huge increase in referrals for 'cheese,' and a huge decrease in the age of the kids that are being referred," said Hemm. "We've had mostly 11- and 12-year-olds in the last few months."

Hemm says she has had to turn away most of the preteen referrals because they are too young. She is only licensed to treat addicts between 13- and 17-years-old. "The young kids aren't emotionally ready for our program," said Hemm.

An exception was made for one 11-year-old whose mother lied about his age to get him admitted, according to Hemm. "The 11-year-old that we had in here had overdosed several times and had detoxed several times."

A 14-year-old who overdosed on heroin was rushed to the Dallas children's hospital ER last week in critical condition. The teen had been snorting "cheese," according to Dr. Kurt Kleinschmidt, who was on call when the patient arrived. "He should have died; it's amazing he didn't," said Kleinschmidt.

The heroin crosses the Mexican border into Texas, where traffickers sell it to high school and middle school students in Dallas, who mix it up with Tylenol PM into "cheese," according to the Dallas Independent School District Police Department.

The elementary school-aged children often get the "cheese" from older siblings at the middle school across the street from the elementary school, Hemm says her patients tell her.

DEA officials in Washington say they have not seen the "cheese" phenomenon anywhere outside of Dallas.

The TSA and Fake Boarding Pass Generator Drama

Via SlightParanoia -

Dear Christopher,

We were slightly worried that you might spend Christmas relaxing and spending quality time with your family. We can't have that.

Thus, please enjoy the enclosed letter - we're quite confident that it'll occupy your thoughts for the next few weeks. Have fun mulling things over. We expect a reply from you by Christmas day.

Enjoy your holidays!

Love,

Your Friends at TSA.

P.S. We continue to ignore the existence of a different boarding pass generator, written by someone else and which has been online for the past month. It wasn't in the Washington Post, so our bosses haven't seen it yet. Phew!

P.P.S. We don't actually plan on fixing any of the underlying security problems. That'd be far too difficult. We may, however, switch from requiring Ziplock bags to Reynolds Wrap foil pouches for passengers' liquids. The idea of people constructing oragami foil pouches in the security line has been making us crack up at the office, and we think it should do much to spread Christmas Cheer at the Airports.

------------------------------

This is just too rich not to post up...is this really the the mindset that the public wants the TSA to have? Thanks to Fergie for pointing this out to me. Check out the SlightParanoia page for pics of the letter.

Wednesday, December 6, 2006

MS Word Remote Code Execution Zero-Day Alert

Via eWeek.com -

Microsoft on Dec. 5 warned that an unpatched vulnerability in its Word software program is being used in targeted, zero-day attacks.

A security advisory from the Redmond, Wash., company said the flaw can be exploited if a user simply opens a rigged Word document.



Secunia is rating it as "Extremely critical" in SA23232

CVE-2006-5994 has been reserved but contains no additional information at this time.

Inside the US National CounterTerrorism Center (NCTC)

Via BBC -

In a Washington suburb, I am on a journey. No address, no postcode. Just the phone number of a US government official known only as "T".

After months of requests, he has granted us permission to visit one of America's newest and most secret establishments: the National Counterterrorism Center, the NCTC.

It is a nondescript building, but inside is the beating heart of America's counter-terrorism nerve centre.

"This is where we maintain a 24-hours-a-day, seven-days-a-week operational watch in the counter-terrorism intelligence community and monitor situational awareness in the world of counterterrorism," says Vice Admiral Don Loren, one of the watch officers in the Operations Room.

The Operations Room is a large open-plan chamber filled with desks and computer terminals.

It is here in this room three times a day, every day, that America's specialists in counter-terrorism gather to share information.


But today it is almost empty. Because we are media, all the undercover agents from the Federal Bureau of Investigation, the National Security Agency and the Central Intelligence Agency who would normally sit here have been moved out of sight.

But up on the wall is a giant plasma screen showing every plane approaching the United States.

"Right now, you're looking at the Eastern Seaboard air corridor, and we use that to monitor events of special interest and to keep an eye should there be any reports of what we call no-fly activity," Vice Adm Loren says.

A "no-fly" means a plane with a passenger suspicious enough that the flight can even get turned back over the mid-Atlantic.

In everyone's minds is the thought: "9/11, never again."

Tuesday, December 5, 2006

Flatulence, Not Turbulence Forces Plane Landing In Nashville

Via WBIR.com -

Flatulence brought 99 passengers on an American Airlines flight to an unscheduled visit to Nashville early Monday morning.

American Flight 1053, from Washington Reagan National Airport and bound for Dallas/Fort Worth, made an emergency landing here after passengers reported smelling struck matches, said Lynne Lowrance, a spokeswoman for the Nashville International Airport Authority.

The plane landed safely. The FBI, Transportation Safety Administration and airport authority responded to the emergency, Lowrance said.

The passengers and five crew members were brought off the plane, together with all the luggage, to go through security checks again. Bomb-sniffing dogs found spent matches.

The FBI questioned a passenger who admitted she struck the matches in an attempt to conceal body odor, Lowrance said. The woman lives near Dallas and has a medical condition.

The flight took off again, but the woman was not allowed back on the plane."American has banned her for a long time," Lowrance said.

She was not charged but could have been. While it is legal to bring as many as four books of paper safety matches onto an aircraft, it is illegal to strike a match in an airplane, Lowrance said.

Mac OS X ftpd Buffer Overflow Vulnerability

A vulnerability has been reported in Mac OS X, which potentially can be exploited by malicious users to compromise a vulnerable system.

The vulnerability is caused due to a boundary error in ftpd when handling commands with globbing characters (e.g. "*") and can be exploited to cause a buffer overflow.

Successful exploitation may allow execution of arbitrary code.

The vulnerability is reported in Mac OS X 10.3.9 and 10.4.8. Other versions may also be affected.

http://secunia.com/advisories/23178/

Egypt Arrests American, Europeans In Terrorist Cell Case

Via FreeInternetPress.com -

Egyptian authorities said Monday that they had arrested an American and nearly a dozen Europeans after breaking up an international terrorist cell that was recruiting operatives to go to Iraq.

The Egyptian Interior Ministry said the cell was "related to some terrorist organizations abroad" but did not name the network or those arrested. The official Egyptian news agency MENA reported that the suspects included nine French citizens and two Belgians, as well as two Syrians, a Tunisian woman and an undisclosed number of Egyptians.

In Washington, State Department spokesman Sean McCormack said U.S. officials knew the identity of the American and are "seeking consular access to this individual". He said the U.S. suspect was arrested Nov. 26 but declined to name the person, citing federal privacy laws.

A U.S. law enforcement official said the U.S. citizen "was not on our radar at all" before his arrest in Egypt and is not named on the government's voluminous terrorism watch list.

"He was not a known figure to the U.S.," said the official. "There's no record of him in the sense that he would have been a person of concern."

A handful of U.S. citizens have faced charges of engaging in terrorism overseas since the Sept. 11, 2001, attacks.

BinNavi: X-Ray Vision for Mere Security Mortals (with Heavy Pockets)

Via DarkReading -

A new tool for malware researchers and reverse-engineers could make it easier to pinpoint bugs and flaws in commercial, closed-source software.

Sabre Security's
BinNavi product -- which is expected to be released sometime this month -- provides visualization and graphical views of executable code in closed-source software. In essence, it speeds auditing and testing by consolidating the binary code into more digestible and relevant pieces of code.

Think of it as x-ray vision for finding vulnerabilities in closed-source software, says Thomas Ptacek, a researcher with Matasano Security, who has tested BinNavi for auditing software.

Ptacek says the tool lets him see inside compiled binary code with a graphical map of the components. "Instead of reading millions of lines of machine code, I can look at the picture, spot important components, zoom in, and see how they relate to the rest of the program."

With the tool, Matasano has found flaws in an authentication protocol, fixed a bug in a Windows server, and mapped out a proprietary file-transfer protocol, Ptacek says.

[...]

BinNavi, which runs atop a SQL database, lets you quickly see if you can break an application, for instance, he says, or debug and analyze the code running on a network device. It can also help, say, an antivirus malware researcher analyze rogue code.

"It would make sense to folks who do malware analysis...or anyone trying to get a really solid view of how an application works, or trying to decode some gnarly, self-modifying executable," notes researcher HD Moore.

[...]

There are similar tools from F-Secure and Pedram, but F-Secure's tool is focused on malware analysis, and Pedram's
PaiMei doesn't have the graphical browsing and searching that BinNavi does, observers say.

Why should IT security pros who aren't reverse-engineering experts care about a tool like BinNavi? "Because tools like these are erasing the 'security through obscurity' advantage that closed-source software has claimed over open-source," Ptacek says. "Security teams should assume attackers can find bugs in Oracle and IOS as easily as they can in Apache now."

BinNavi's initial pricing is from $4,000 to $48,000.

Canada to Deport 'Russian SVR Spy'

Via BBC -

The man, who used the false name Paul William Hampel, was held at Montreal airport last month with a fake birth certificate, court documents said.

A federal court found the security certificate used to arrest him was "reasonable" and ordered his removal.


The man, whose real identity was not revealed, did not testify in court and did not admit to being a spy.

"My client admits that he is not Paul William Hampel, that he is a Russian citizen, born on October 21, 1961, and that he has no legal status in Canada," Stephane Handfield said.
"He is ready to leave Canada, but he does not admit being a spy," he added.

The intelligence agency said the man had spied on Canada for 10 years and worked for a successor to the Soviet KGB, the Foreign Intelligence Service (SVR), which deals with foreign operations and intelligence-gathering.

Court papers said he had obtained three Canadian passports by fraudulent means.

The Canadian authorities say that when they arrested the man he was carrying more than $5,000 in various currencies and three mobile phones.

The spying charges are the first since 1996, when Canada expelled Dmitriy Olshevsky and Yelena Olshevskaya, who had taken the names of Ian and Laurie Lambert to work as sleeper SVR agents.





I believe this one statement from a UK MoD research report sums up the game best...

There are friendly states but there are no friendly intelligence services.

Monday, December 4, 2006

Tools of the Trade - Now w/High Protein Soy!

1) Insecure.org has released Nmap 4.20RC2. Updates include the following:
  • Integrated all of your OS detection submissions since RC1. The DB has increased 13% to 214 fingerprints. Please keep them coming! New fingerprints include versions of z/OS, OpenBSD, Linux, AIX, FreeBSD, Cisco CatOS, IPSO firewall, and a slew of printers and misc. devices. We also got our first Windows 95 fingerprint, submitted anonymously of course :).
  • Fixed (I hope) the "getinterfaces: intf_loop() failed" error which was seen on Windows Vista. The problem was apparently in intf-win32.c of libcnet (need to define MIB_IF_TYPE_MAX to MAX_IF_TYPE rather than 32). Thanks to Dan Griffin (dan(a)jwsecure.com) for tracking this down!
  • Applied a couple minor bug fixes from Marek Majkowski to IP options support (which he previously added) and packet tracing.
  • Incorporated SLNP (Simple Library Network Protocol) version detection support. Thanks to Tibor Csogor (tibi(a)tiborius.net) for the patch.

2) Oxid.it recently released Cain & Abel 4.2. Updates include the following:

  • Cain's MitM NTLM Challenge Spoofing. (Requires APR to be active and a MitM condition between victim hosts).You can now spoof server challenges in NTLM authentications; this feature enables the use of RainbowTables for cracking network hashes. WARNING !!! Enabling Challenge Spoofing cause users to fail authentications so use it carefully.
  • NTLM Session Security authentications downgrade to LM&NTLMv1. The following protocols are supported: SMB, DCE/RPC, TDS, HTTP, POP3, IMAP, SMTP.
  • LM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
  • HALFLM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
  • NTLM + spoofed challenge Hashes Cryptanalysis via Sorted Rainbow Tables.
  • New types of RainbowTables have been added to Winrtgen v2.3. "lmchall" and "ntlmchall" tables can be used against LM and NTLM response hashes for spoofed challenges (default: 0x1122334455667788). "halflmchall" tables can be used against the first 8 bytes LM response hashes for spoofed challenges to recover the first 7 characters of the original password.

3) Snort 2.6.1.1 was released. Fixed problem with snort using high CPU and potentially reprocessing the same TCP reassembled packets at session end or TCP ACK of only part of a packet.

4) On Nov 16th, VMware Workstation 5.5.3, Build 34685 was released. It fixed a whole heap of bugs related to Linux. Of course, you must already have a license to upgrade, but you know that. =)

5) On Nov 11th, Arley Silveira released TXDNS 2.0.0. TXDNS is a Win32 aggressive multithreaded DNS digger. Capable of placing, on the wire, thousands of DNS queries per minute. TXDNS main goal is to expose a domain namespace trough a number of techniques - Typos, TLD rotation, Dictionary attack & Brute force.

6) On the forensics tool front, Live View 0.5 was release not long ago. Live View is a Java-based graphical forensics tool that creates a VMware virtual machine out of a raw (dd-style) disk image or physical disk. This allows the forensic examiner to "boot up" the image or disk and gain an interactive, user-level perspective of the environment, all without modifying the underlying image or disk. Because all changes made to the disk are written to a separate file, the examiner can instantly revert all of his or her changes back to the original pristine state of the disk. The end result is that one need not create extra "throw away" copies of the disk or image to create the virtual machine.

Sunday, December 3, 2006

Psiphon Released - Free the Internet

Psiphon is a human rights software project developed by the Citizen Lab at the Munk Centre for International Studies that allows citizens in uncensored countries to provide unfettered access to the Net through their home computers to friends and family members who live behind firewalls of states that censor.

Fergie just informed me that it appears to have a problem working on NAT'd addresses.

Hopefully that issue will shows up on the bug fix list soon...regardless, this software will assist those that choose to fight the good fight...against the "Enemies of the Internet".

Simple Energy Conservation Works Best

Via Christian Science Monitor -

When high school science teacher Ray Janke bought a home in Chicopee, Mass., he decided to see how much he could save on his electric bill.

He exchanged incandescent bulbs for compact fluorescents, put switches and surge protectors on his electronic equipment to reduce the "phantom load" - the trickle consumption even when electronic equipment is off - and bought energy-efficient appliances.

Two things happened: He saw a two-thirds reduction in his electric bill, and he found himself under audit by Mass Electric. The company thought he'd tampered with his meter. "They couldn't believe I was using so little," he says.

The War on Drugs - The House of Death

Via the Guardian UK -

When 12 bodies were found buried in the garden of a Mexican house, it seemed like a case of drug-linked killings. But the trail led to Washington and a cover-up that went right to the top. David Rose reports from El Paso.

As noted in the above article, here is the Dallas Morning News article from May 2005.

More information on the case can be found here (March 2006) and here (Oct 2006).

Saturday, December 2, 2006

New MySpace XSS QuickTime Worm

Via Websense Security Labs -

Websense® Security Labs™ has confirmed the existence of a worm spreading on the MySpace network. This worm is exploiting the Javascript support within Apple's embedded QuickTime player (1). This is used in conjunction with a MySpace vulnerability that was announced two weeks ago on the Full-Disclosure mailing list (2). The vulnerabilities are being used to replace the legitimate links on the user's MySpace profile with links to a phishing site.

Once a user's MySpace profile is infected (by viewing a malicious embedded QuickTime video), that profile is modified in two ways. The links in the user's page are replaced with links to a phishing site, and a copy of the malicious QuickTime video is embedded into the user's site. Any other users who visit this newly-infected profile may have their own profile infected as well.

An infected profile can be identified by the presence of an empty QuickTime video or modified links in the MySpace header section, or both.

  1. http://www.gnucitizen.org/blog/backdooring-quicktime-movies/
  2. http://seclists.org/fulldisclosure/2006/Nov/0275.html
  3. http://www.apple.com/quicktime/tutorials/hreftracks.html

MS Windows Spoolss GetPrinterData() 0day Memory Allocation Remote DoS Exploit

Via Milw0rm.com -

# Example:
#
# C:\>python spoolss_dos.py 192.168.0.2 512
#
# [*] MS Windows GetPrinterData() 0day Memory Allocation Remote DoS Exploit
# [*] Coded by h07
# [*] Connecting to 192.168.0.2:445
# [+] Connected
# [+] The NETBIOS connection with the remote host timed out.
# [+] 192.168.0.2: Out of memory
# [+] Done
#
# Exploit --> GetPrinterData(handle, value, 1024 * 1024 * 512) --> MS_Windows
# Spooler service(spoolsv.exe) memory usage: 512 MB

FYI - Note the need for direct access to port 445.

Friday, December 1, 2006

US DHS Banking Security Alert

Via ISC -

A number of major news sites picked up on an alert issued by the US Department of Homeland Security (DHS), suggesting a major pending cyber attack by al Qaeda against US banking interests. The news coverage suggests that the attack will begin tomorrow and last until year's end.

The entire issue is probably best summarized by a quote from a DHS spokes person, published on CNN.com:

"There is no information to corroborate this aspirational threat. As a routine matter and out of an abundance of caution, US-CERT issued the situational awareness report to industry stakeholders,"

My short take on it: Make sure you follow best practices and keep your guard up. Its probably not going to be Al Qaeda, but someone will probe your defense tomorrow as they did today. And whatever helps against them will help if Al Qaeda should launch a cyber attack after all.

The Financial Services Information Sharing and Analysis Center (FS/ISAC) is currently posting a "Low Risk of Cyber Attacks" on its web site.

MoKB: Apple Airport Extreme Beacon Frame DoS

Via Month of Kernel Bugs -

Apple Airport Extreme driver fails to handle certain beacon frames, leading to an out of bounds memory access, resulting in a so-called kernel panic. Other security implications may exist, although this hasn't been verified and no details can be provided until further research is done.

This is issue is being coordinated with Apple, and under common agreement it's been decided to keep the details private until a fix has been made available to end-users.

A proof of concept module for the Metasploit framework may be provided after an official patch and announcement is released by Apple.

This issue has been verified with a Macbook (2GHz Intel Core Duo), running Mac OS X 10.4.8 (8L2127), Apple Airport Extreme Firmware version 0.1.27.

LMH - discovery (6-Nov-2006), reported to Apple (25-Nov-2006, #4849XXX).

NIST Recommends Decertifying Paperless Voting Machines

Via Freedom to Tinker -

In an important development in e-voting policy, NIST has issued a report recommending that the next-generation federal voting-machine standards be written to prevent (re-)certification of today’s paperless e-voting systems. (NIST is the National Institute of Standards and Technology, a government agency, previously called the National Bureau of Standards, that is a leading source of independent technology expertise in the U.S. government.) The report is a recommendation to another government body, the Technical Guidelines Development Committee (TGDC), which is drafting the 2007 federal voting-machine standards. The new report is notable for its direct tone and unequivocal recommendation against unverifiable paperless voting systems, and for being a recommendation of NIST itself and not just of the report’s individual authors.

DHS Assigns Terrorism Rating Number to All Travelers

Via CNN -

Without notifying the public, federal agents have assigned millions of international travelers, including Americans, computer-generated scores rating the risk they pose of being terrorists or criminals.

The travelers are not allowed to see or directly challenge these risk assessments. The government intends to keep the scores on file for 40 years.

The scores are assigned to people entering and leaving the United States after computers assess their travel records, including where they are from, how they paid for tickets, their motor vehicle records, past one-way travel, seating preference and what kind of meal they ordered.

The program's existence was quietly disclosed earlier in November when the government put an announcement detailing the Automated Targeting System, or ATS, for the first time in the Federal Register, a fine-print compendium of federal rules.

Eighty-seven million people a year enter the country by air and 309 million enter by land or sea, the Department of Homeland Security reports.

The government gets advance passenger and crew lists for all flights and ships entering and leaving and all those names are entered into the system for an ATS analysis, said Jayson P. Ahern, an assistant commissioner of Homeland Security's Customs and Border Protection agency.

He also said the names of vehicle drivers and passengers are entered when they cross the border and Amtrak is voluntarily supplying passenger data for trains to and from Canada.

Ahern said that border agents concentrate on arrivals more than on departures because their resources are limited.

Privacy and civil liberties lawyers, congressional aides and even law enforcement officers said they thought this system had been applied only to cargo.

DHS called its program "one of the most advanced targeting systems in the world."

The department said the nation's ability to spot criminals and other security threats "would be critically impaired without access to this data."

Still, privacy advocates view ATS with alarm.

"It's probably the most invasive system the government has yet deployed in terms of the number of people affected," said David Sobel, a lawyer at the Electronic Frontier Foundation, a civil liberties group devoted to electronic data issues.

He continued, "Some individuals will be denied the right to travel and many the right to travel free of unwarranted interference as a result of the maintenance of such material."

A similar Homeland Security data-mining project, for domestic air travelers -- now known as Secure Flight -- caused a furor two years ago in Congress. Lawmakers barred its implementation until it can pass 10 tests for accuracy and privacy protection.

The government notice says ATS data may be shared with state, local and foreign governments for use in hiring decisions and in granting licenses, security clearances, contracts or other benefits.

In some cases, the data may be shared with courts, Congress and even private contractors.

If a traveler is singled out erroneously by ATS data it could cost innocent people jobs in shipping or travel, government contracts, licenses or other benefits, Sobel warned.

But Ahern said the ATS ratings simply allow agents at the border to pick out people not previously identified by law enforcement as potential terrorists or criminals.

DHS agents can then conduct additional searches and interviews.

"It does not replace the judgments of officers," Ahern said Thursday.

This targeting system goes beyond traditional border watch lists, Ahern said.

Border agents compare arrival names with watch lists separately from the ATS analysis.

This week Homeland Security posted a message addressing privacy on its Web site. It said ATS is aimed at discovering high-risk individuals who "may not have been previously associated with a law enforcement action or otherwise be noted as a person of concern to law enforcement."

Ahern said ATS does this by applying the government guidelines to sifting out terrorists and criminals by comparing them with passengers' travel patterns and records.

For security reasons, Ahern declined to disclose any specifics about those guidelines.

In the Federal Register, the department exempted ATS from many provisions of the Privacy Act designed to protect people from secret, possibly inaccurate government dossiers.

As a result, it said travelers cannot learn whether the system has assessed them. Nor can they see the records "for the purpose of contesting the content."

Thursday, November 30, 2006

Happy Computer Security Day!

Computer Security Day is an annual event that is observed worldwide. It was started in 1988 to help raise awareness of computer related security issues. The goal of Computer Security Day is to remind people to protect their computers and information. Officially, Computer Security Day is November 30th. However, some some organizations choose to have functions on the next business day or week if CSD falls on a weekend.

http://www.computersecurityday.org/

YEA!!! WOOHHOOO!

Ok, back to work.

Wednesday, November 29, 2006

Adobe ActiveX Control Remote Code Execution Vulnerability

It would appear that a new remote code execution vulnerability has been discovered today for Adobe Reader and Acrobat ActiveX.

It currently affects the following products:

Adobe Reader versions 7.0.0 through 7.0.8
Adobe Acrobat Standard versions 7.0.0 through 7.0.8
Adobe Acrobat Professional versions 7.0.0 through 7.0.8

The Adobe secuirty team is looking into the issue and currently there is no patch.

Set a kill bit for the CLSID {CA8A9780-280D-11CF-A24D-444553540000} or delete "AcroPDF.dll" will fix the issue for now however.

Adobe -http://www.adobe.com/support/security/advisories/apsa06-02.html
FrSIRT -http://www.frsirt.com/english/advisories/2006/4751

UK Police Ground Airliners For Radiation Testing

Via CNN -

Authorities grounded three British Airways jetliners in London and Moscow on Wednesday and drew up plans to contact thousands of airplane passengers as they broadened their investigation into the radiation poisoning death of a former Russian spy.

Two planes at London's Heathrow Airport tested positive for traces of radiation, a third plane has been taken out of service in Moscow awaiting examination.

Home Secretary John Reid disclosed the search following a meeting with COBRA, the government's emergency committee. Reid said two planes had been tested so far and that another would be tested.

The initial results of the forensic tests had shown very low traces of a radioactive substance onboard two aircraft, British Airways said in a statement.

The company added that the investigation is confined to the three planes, which will remain out of service until further notice.

High doses of polonium-210 -- a rare radioactive element usually manufactured in specialized nuclear facilities -- were found in Alexander Litvinenko's body, and traces of radiation have been found at sites in London connected with the investigation of his death.

The airline said it was contacted by the British government late on Tuesday and told to ground the planes, and allow investigators looking into the death of the former intelligence agent to test them for radiation.

All three planes had been on the London-Moscow route, British Airways said. In the last three weeks the planes had also traveled to routes across Europe including Barcelona, Frankfurt and Athens. Around 30,000 passengers had traveled on 220 flights on those planes, said Kate Gay, a spokeswoman for the airline.

"The airline is in the process of making contact with customers who have traveled on flights operated by these aircraft, which operate within Europe," British Airways said in a statement, adding the risk to the public was low.



British Airways website states that three Boeing 767 short haul airliners are currently grounded and under forensic examination.

Researcher Cancels Week of Oracle Database Bugs

Via Vnunet.com -

Security researcher Ceasar Cerrudo, with the Argentinean security vendor Argeniss, has abandoned his plan for 'a week of Oracle Database Bugs'.

The security vendor was originally planning to release details of an unpatched vulnerability in the Oracle database every day for a period of one week. The event was intended to demonstrate the poor level of security in Oracle's database.

"We have 0-days [zero-day bugs] for all database software vendors but Oracle is "The #1 Star" when talking about lots of unpatched vulnerabilities and not caring about security," the company originally said on its website.

The
page was updated on Tuesday. The original text was struck out and above it a notice explained that the event was suspended "due to many problems". The company declined to comment further.

Publishing details of security vulnerabilities before a vendor has released a patch is considered not-done in the security sector because it can put end users at risk.

Late on Monday Oracle published a posting on its
security blog lashing out against researchers who published details of so-called 0-day vulnerabilities. The vendor also said that it won't credit researchers in the patch documentation if they prematurely disclose vulnerability details of the flaws they discover. Security researchers generally rely on company credits to market their skills.

Although the posting did not mention Argeniss, it claims to respond to "a flurry of articles and blog entries".

Tuesday, November 28, 2006

UK MoD Conducts Semi-Mock Swarm UAV Test

Via NewScientistTech -

A jet airliner was flown over south-west England recently with no pilot in the cockpit, to test technology that might one day be used to control swarms of unpiloted aircraft from a single fighter jet.

The two-hour flight, conducted by the UK Ministry of Defence (MoD) and UK defence firm Qinetiq on 30 October 2006, was designed to assess whether a fighter pilot could someday control several uncrewed air vehicles (UAVs) from their own plane.

"The big burning question at the MoD is how to operate UAVs in attack missions in the future," says Kevin Williams, project manager at Qinetiq. "We wanted to see if a fast-jet pilot, flying a Tornado perhaps, could control a pack of four UAVs in deep, target attack situations while still doing his own job."

To find out, Qinetiq fitted a system called the UAV Command and Control Interface (UAVCCI), to an ageing BAC 1-11 – a 1960s era 100-seat twin-engine jetliner, made by the British Aircraft Corporation.

Under civil aviation law, the pilot controlling the jetliner still had to be on board the aircraft. But he sat at the back of the plane using only the UAVCCI to control the large jet, along with four computer-simulated UAVs on a virtual attack mission.

The UAVCCI uses software agents to control each aircraft under its command, minimising the pilot's workload. This makes each of the UAVs semi-autonomous: they fly straight and level on their own and can be given simple orders using a point-and-click interface on what Williams calls "a simple, flat, moving map".

"The pilot only had to give top level instructions to the UAVs on where to go and what weapons to use, not fly them minute-by-minute," says Ben White, a Qinetiq spokesman.

[...]

Next March, the UAVCCI will face a much harder test. From the cockpit of a Tornado fighter, the pilot will have to fly the Tornado, the unpiloted BAC1-11 and several simulated UAVs.

Controlling multiple uncrewed vehicles and ground robots is a major aim of NATO defence researchers and the US Pentagon wants one-third of its military "assets" to be robotic or remotely controllable by 2015.

Polonium 210 - Easily Obtained in the US via the Internet

Via InformationWeek -

The radioactive material that killed a former Russian spy in Britain can be bought on the Internet for $69.

Polonium-210, which experts say is many times more deadly than cyanide, can be bought legally through United Nuclear Scientific Supplies, a mail-order company that sells through the Web, based in Sandia Park, N.M. Chemcial companies sell the Polonium-210 legally for industrial use, such as removing static electricity from machinery. United Nuclear claims that it's "currently the only legal Alpha source available without a license."

The type of Polonium-210 sold emits alpha radiation, which can't penetrate the skin, but is deadly if swallowed, depending on the amount ingested. The Polonium available on United Nuclear's site can be purchased without a license because the level of radioactivity, 0.1 microcurie, does not pose a danger, a spokesman for the U.S. Nuclear Regulatory Commission said.

"At that level, it's exempt from licenses," NRC spokesman David McIntyre said. "At any exempt quantity, it's not considered a health hazard."



I love this part - "To ensure the longest half-life possible, we do NOT keep isotopes in stock. All isotopes are produced fresh in a Nuclear Reactor and shipped directly to you from the NRC licensed isotope manufacturer."

HackReport: Interview with Lance Spitzner, Founder of the Honeynet Project

The Hack Report has posted a small yet informative interview with Lance Spitzner, founder of the Honeynet Project.

In my mind, Lance is right on the money when he said the following:

"Even with better technology, better OS security, stronger passwords, better policies it just makes it more difficult and time consuming for the bad guys but they can spend all the time since there is no fear of prosecution. So much profit for so little risk. Hacking is just a tool for extortion, fraud, identity theft, things that have been happening for a long time. If we want to make it more difficult for them we have to bump up the risk as a deterrence."

IRC Bot Attacks Symantec Overflow from May 2006

Very good write-up. Thanks to Fergie for pointing this out to me. This is a clear cut case study on why good corporate patch management is important.

Via Arbor Networks -

Back in May of this year, Symantec released an avisory entitled SYM06-010: Symantec Client Security and Symantec AntiVirus Elevation of Privilege. Those that took the time to read it beyond the title noticed that this isn’t just a local privilege elevation exploit. It’s an out and out remote stack overflow using a specific service (TCP port 2967). We started tracking possible exploit activity for this vulnerability in early June using an ATF policy to detect scans and exploit, with our thinking that someone would surely take an interest. Activity for this policy quickly dropped off our radar, buried underneath some juicy Windows and VNC holes that people focused on. We didn’t see many scanners for this service, and only a burst of a scan early last week.

That is, until now, in late November, when we see a bot using an exploit for this (and lots of people are curious). We had a look at the bot, and found that it’s a new exploit plugin for a garden variety SDBot. This thing’s a beast! It’s huge, not unlike a bloated bot that someone’s thrown everything into. A partial list of the capabilities this puppy appears to have:

  • SYMC06-010 exploit (TCP port 2967)
  • NetAPI (MS06-040), TCP port 445
  • DDoS and packet flooding (SYN, ACK, ICMP, UDP floods, for example)
  • Password theft and packet sniffing
  • It can enumerate other installed malware
  • The usual bunch of access capabilities
  • The usual bunch of brute force attacks, downloads, upload, proxy checks, etc

Thirteen Great Mysteries of Science

Via NewScientist.com -

  • The Placebo Effect - Don't try this at home. Several times a day, for several days, you induce pain in someone. You control the pain with morphine until the final day of the experiment, when you replace the morphine with saline solution. Guess what? The saline takes the pain away.
  • The Horizon Problem - Our universe appears to be unfathomably uniform. Look across space from one edge of the visible universe to the other, and you'll see that the microwave background radiation filling the cosmos is at the same temperature everywhere. That may not seem surprising until you consider that the two edges are nearly 28 billion light years apart and our universe is only 14 billion years old. Nothing can travel faster than the speed of light, so there is no way heat radiation could have travelled between the two horizons to even out the hot and cold spots created in the big bang and leave the thermal equilibrium we see now.
  • Ultra-Energetic Cosmic Rays - For more than a decade, physicists in Japan have been seeing cosmic rays that should not exist. Cosmic rays are particles - mostly protons but sometimes heavy atomic nuclei - that travel through the universe at close to the speed of light. Some cosmic rays detected on Earth are produced in violent events such as supernovae, but we still don't know the origins of the highest-energy particles, which are the most energetic particles ever seen in nature. But that's not the real mystery.
  • Belfast Homeopathy Results - Madeleine Ennis, a pharmacologist at Queen's University, Belfast, was the scourge of homeopathy. She railed against its claims that a chemical remedy could be diluted to the point where a sample was unlikely to contain a single molecule of anything but water, and yet still have a healing effect. Until, that is, she set out to prove once and for all that homeopathy was bunkum. In her most recent paper, Ennis describes how her team looked at the effects of ultra-dilute solutions of histamine on human white blood cells involved in inflammation. These "basophils" release histamine when the cells are under attack. Once released, the histamine stops them releasing any more. The study, replicated in four different labs, found that homeopathic solutions - so dilute that they probably didn't contain a single histamine molecule - worked just like histamine. Ennis might not be happy with the homeopaths' claims, but she admits that an effect cannot be ruled out.
  • Dark Matter - Take our best understanding of gravity, apply it to the way galaxies spin, and you'll quickly see the problem: the galaxies should be falling apart. Galactic matter orbits around a central point because its mutual gravitational attraction creates centripetal forces. But there is not enough mass in the galaxies to produce the observed spin.
  • Viking's Mars Methane - July 20, 1976. Gilbert Levin is on the edge of his seat. Millions of kilometres away on Mars, the Viking landers have scooped up some soil and mixed it with carbon-14-labelled nutrients. The mission's scientists have all agreed that if Levin's instruments on board the landers detect emissions of carbon-14-containing methane from the soil, then there must be life on Mars. Viking reports a positive result. Something is ingesting the nutrients, metabolising them, and then belching out gas laced with carbon-14.
  • Tetraneutrons - Four years ago, a particle accelerator in France detected six particles that should not exist. They are called tetraneutrons: four neutrons that are bound together in a way that defies the laws of physics. Francisco Miguel Marquès and colleagues at the Ganil accelerator in Caen are now gearing up to do it again. If they succeed, these clusters may oblige us to rethink the forces that hold atomic nuclei together.
  • The Pioneer Anomaly - This is a tale of two spacecraft. Pioneer 10 was launched in 1972; Pioneer 11 a year later. By now both craft should be drifting off into deep space with no one watching. However, their trajectories have proved far too fascinating to ignore. That's because something has been pulling - or pushing - on them, causing them to speed up.
  • Dark energy - It is one of the most famous, and most embarrassing, problems in physics. In 1998, astronomers discovered that the universe is expanding at ever faster speeds. It's an effect still searching for a cause - until then, everyone thought the universe's expansion was slowing down after the big bang.
  • The Kuiper Cliff - If you travel out to the far edge of the solar system, into the frigid wastes beyond Pluto, you'll see something strange. Suddenly, after passing through the Kuiper belt, a region of space teeming with icy rocks, there's nothing.
  • The Wow Signal - It was 37 seconds long and came from outer space. On 15 August 1977 it caused astronomer Jerry Ehman, then of Ohio State University in Columbus, to scrawl "Wow!" on the printout from Big Ear, Ohio State's radio telescope in Delaware. And 28 years later no one knows what created the signal. "I am still waiting for a definitive explanation that makes sense," Ehman says.
  • Not-so-Constant Constants - In 1997 astronomer John Webb and his team at the University of New South Wales in Sydney analysed the light reaching Earth from distant quasars. On its 12-billion-year journey, the light had passed through interstellar clouds of metals such as iron, nickel and chromium, and the researchers found these atoms had absorbed some of the photons of quasar light - but not the ones they were expecting.
  • Cold Fusion - After 16 years, it's back. In fact, cold fusion never really went away. Over a 10-year period from 1989, US navy labs ran more than 200 experiments to investigate whether nuclear reactions generating more energy than they consume - supposedly only possible inside stars - can occur at room temperature. Numerous researchers have since pronounced themselves believers.

Gingrich Says Govt May Have to Limit Free Speech in the Name of Terror

Via WCSH Portland -

Former House Speaker Newt Gingrich used a New Hampshire event dedicated to freedom of speech to say the United States will have to re-examine that constitutional right as it fights terrorism.

Speaking in Manchester Monday night, Gingrich said the country may need a different set of rules to reduce terrorists' ability to use the Internet and free speech to recruit and get out their message.

The former speaker also said he won't decide whether to run for president until September 2007.

He spoke at the annual Nackey S. Loeb First Amendment award dinner.

Monday, November 27, 2006

(IN)SECURE Magazine - Issue 1.9 Released

(IN)SECURE Magazine is a freely available digital security magazine discussing some of the hottest information security topics. It can be distributed only in the form of the original non-modified PDF document.

This issue includes:
  • Effectiveness of security by admonition: a case study of security warnings in a web browser setting
  • Interview with Kurt Sauer, CSO at Skype
  • Web 2.0 defense with AJAX fingerprinting and filtering
  • Hack In The Box Security Conference 2006
  • Where iSCSI fits in enterprise storage networking
  • Recovering user passwords from cached domain records
  • Do portable storage solutions compromise business security?
  • Enterprise data security - a case study
  • Creating business through virtual trust: how to gain and sustain a competitive advantage using information security

Russian FSB - Friend or Foe?

Via DouglasFarah.com -

What is Russia’s real role in the efforts to combat terrorism? While the Bush administration seems to cling to the notion that Russia is an ally, there are several developments that point in the opposite direction.

The first, of course, is the assassination of Alexander Litvinenko, where the foul play of the Russian security apparatus, closely tied to Mr. Putin, is the prime suspect. The fact that the murder was committed in London and dismissed out of hand as unimportant by Mr. Putin show both a new boldness and the lack of any pretense of accountability by the Russians.

There is also the arming of Iran and help with the Iranian nuclear program, and the close intelligence ties to Hezbollah.

But there is another, barely noticed development in the United States that should be extremely worrisome. A small sporting goods store in rural Pennsylvania was just busted for selling telescopic rifle scopes, binoculars and optics, which need State Department export authorization, to a Russian company that did not have such a license.


As the my colleauge and co-author Stephen Braun write in the Los Angeles Times, the affidavit for carrying out the search states that the Russian company is “Tactica Ltd., a Moscow firm that was described by investigators as ‘a member of the ‘Vympel Group,’ which is a known identifier for an elite counter-terrorism unit that is controlled by the Russian Federal Security Service [formerly the KGB].’”

So, we have Russian intelligence agents illegally buying restricted items in the United States. But it gets better.

A good chunk of the money for the purchases, according to federal officials, came from (hold on Bout fans) Rockman Ltd, a Bulgarian firm owned by Sergei Bout, who has often run Bout companies involved in weapons transactions. As one U.S official told the Times, “Sergei and Viktor’s companies are all under the same umbrella.”

The rest of the money came from Haji Ibrahim, a Pakistani man wanted on federal charges of heroin trafficking. Nice bunch!




The truth is even worse...this happens all the time! We do it to Russia, they do it to us...everyone does it to everyone when possible. Our technology does make us a very very ripe target for this type of activity however.

Big Brother - What Big Ears You Have!

Via TimesOnline -

POLICE and councils are considering monitoring conversations in the street using high-powered microphones attached to CCTV cameras, write Steven Swinford and Nicola Smith.

The microphones can detect conversations 100 yards away and record aggressive exchanges before they become violent.

The devices are used at 300 sites in Holland and police, councils and transport officials in London have shown an interest in installing them before the 2012 Olympics.

The interest in the equipment comes amid growing concern that Britain is becoming a “surveillance society”. It was recently highlighted that there are more than 4.2m CCTV cameras, with the average person being filmed more than 300 times a day. The addition of microphones would take surveillance into uncharted territory.

The Association of Chief Police Officers has warned that a full public debate over the microphones’ impact on privacy will be needed before they can be introduced.

The equipment can pick up aggressive tones on the basis of 12 factors, including decibel level, pitch and the speed at which words are spoken. Background noise is filtered out, enabling the camera to focus on specific conversations in public places.

UK Police Create Criminal Profile Database for 'Future' Suspects

Via TimesOnline -

Criminal profilers are drawing up a list of the 100 most dangerous murderers and rapists of the future even before they commit such crimes, The Times has learnt.

The highly controversial database will be used by police and other agencies to target suspects before they can carry out a serious offence. Pilot projects to identify the highest-risk future offenders have been operating in five London boroughs for the past two months.

The Soham murderer Ian Huntley and the serial rapist Richard Baker have been used as examples of the type of man police will identify.

However, the database will increase concerns at the growth of official surveillance and anxieties that innocent men are being singled out for offences they have no intention of committing.

Experts from the Metropolitan Police’s Homicide Prevention Unit are creating psychological profiles of likely offenders to predict patterns of criminal behaviour. Statements from former partners, information from mental health workers and details of past complaints are being combined to identify the men considered most likely to commit serious violent crimes.

The list will draw comparisons with the Hollywood film Minority Report, in which suspects are locked up before they can commit a predicted crime.

Laura Richards, a senior criminal psychologist with the Homicide Prevention Unit, told The Times: “My vision is that we know across London who the top 100 people are. We need to know who we are targeting.

“It is trying to pick up Ian Huntley before he goes out and commits that murder. Then we have the opportunity to stop something turning into a lethal event.”

The team is concentrating on reducing the risk of those with a history of domestic violence turning into murderers. About a quarter of murders are related to domestic violence.

“There are some pretty dangerous people out there, so you need these risk models to wheedle them out, separate the wheat from the chaff,” she said. “If you add up all the information, it tells us which people are risky.”

Ms Richards said that once an individual had been identified, police would decide whether to make moves towards an arrest, or to alert the relevant social services who could steer those targeted into “management programmes.”

The project will be closely watched by the Home Office. However, civil liberties groups and human rights lawyers will be concerned at the plans to intervene in the lives of men before they actually commit a crime.

Details of the database emerged after Richard Thomas, the Information Commissioner, said that Britain had “sleepwalked” into a surveillance society.

Simon Davies, director of Privacy International, said yesterday: “It is quite right that the police should keep intelligence on suspected criminals, but it is obscene to suggest there should be a ‘crime idol’ list of those who might commit an offence.

“The police are systematically moving the boundaries as to where they can exercise their powers. The Minority Report syndrome is pushing the boundary of criminal intervention further into the general community.”

There was also concern that the database would be ineffective if the authorities continued to fail to act on the information already available to them. Ray Wyre, a sexual crimes consultant, was supportive of the database but said that it would only work if police acted on the information.

“Of course you have to know your enemy, but it is what you do with the data that matters,” he said.




The United Kingdom is proudly leading the push into the "Brave New World". Perhaps I should just take my daily dose of Soma and be quiet.....