Wednesday, April 9, 2008

Apple Toughens up QuickTime

Via Heise Security -

Only last week, Apple had to patch eleven security vulnerabilities in its QuickTime multimedia software. Quoting "reliable sources", US media now report that Apple also took a number of additional steps in version 7.4.5 to make it harder for vulnerabilities to be exploited.

Microsoft employs Address Space Layout Randomization (ASLR) in Windows Vista to link libraries to addresses that are more or less arbitrary. Any malicious code injected by means of security flaws then has a harder time finding the right static address than in previous versions of Windows (such as in return-to-libc attacks). Such techniques have long been implemented in UNIX operating systems, such as BSD and a Linux (PaX), and Mac�OS�X has also had such a mechanism since version 10.5. Apple has now integrated ASLR in QuickTime so that libraries are no longer loaded to static addresses.

Apple compiled QuickTime with the /GS buffer security check, which detects buffer overflows using special cookies injected onto the stack. Apple also reportedly enabled Hardware No-Execute (NX) protection on Windows Vista. Apple has implemented these mechanisms not only in QuickTime for Windows, but also in QuickTime for Mac�OS�X. The -fstack-protector flag is used to check the stack, for instance.

It is currently not clear why Apple waited until now to implement these mechanisms. Since the end of 2005, Microsoft has been recommending the Security Development Lifecycle (SDL), which explicitly calls for the use of /GS for stack protection in addition to normal planning and checking phases. While these attempts to make QuickTime more secure are praiseworthy, they only make it harder for security flaws to be exploited rather than eliminating them. Information about how to get circumvent these mechanisms is already circulating on the internet.

------------------

Kudos to Apple for being a little more proactive...but it took repeated zero-day attacks to force their hand.

So in the end, I would say these extra measures are a reaction to increased attacks from hacker and the security community. Now this attitude needs to be taken into Safari and the iPhone and OS X.

Apple has been very slow to retro-fit open source patches back into OS X...and that is something that they will need to fix before it bites them big time.

Someone please remind Tom @ at CNET news about the load of OS X computers that were found working a bots back in 2006.

"No security researcher I spoke with could think of an instance of a Mac running Mac OS X that had been exploited in the wild."

We have moved beyond the world of only worrying about network services. These OS X servers were pwn thru PHP applications that were running on the operating system. Like it or not, the users on those systems were exposed and the data stored on those servers was put at risk....they were exploited in the wild. As noted in the article, OS X web servers are commonly defaced....is that isn't exploited, i don't know what is.

This stuff is two years ago..and people still think OS X is bulletproof.

That is some strong kool-aid...

Scientology Threatens Wikileaks with Injunction

Via The Register UK -

The Church of Scientology has acknowledged that Wikileaks is offering the world quick and easy access to the church's top-secret "bibles".

Or should that be formerly top-secret?

On March 24, the swashbuckling truth-seekers at Wikileaks.org published what they referred to as "the collected secret 'bibles' of Scientology," and three days later, church-friendly lawyers threatened the site with legal action if the documents weren't taken down. Calling them "Advanced Technology of the Scientology religion," the lawyers pointed out that the documents are copyrighted works registered to the Religious Technology Center (RIC), a church-related holding company.

Wikileaks did not remove the documents. But it did tell the world their veracity has been verified.

Written by Scientology founder L. Ron Hubbard, these "Operating Thetan" (OT) documents show Scientologists how they can reach the eight different "levels" Scientologists are interested in reaching. That's OT1 to OT8. "A great many phenomena (strange things) can happen while doing these drills, if they are done honestly," reads a handwritten note from Hubbard, as he describes the path to OT1.

...

With an email dated March 27, the Los Angeles-based law firm Moxon & Kobrin said that in publishing such Advanced Technology, Wikileaks has violated US copyright law. "It is unlawful to reproduce or distribute someone else's copyrighted work without that person's authorization," the letter reads. "Indeed, courts have entered numerous permanent injunctions and awarded statutory damages and attorneys' fees regarding infringement of these and similar works."

In an apparent effort to find out who leaked the Advanced Technology in the first place, the lawyers also urged Wikileaks to "preserve any and all documents pertaining to this matter...including, but not limited to, logs, data entry sheets, applications - electronic or otherwise, registrations forms, billings statements or invoices, computer print-outs, disks, hard drives, etc."

Clearly, the Church of Scientology is unaware that Wikileaks preserves almost nothing - and that it isn't frightened of the law. Wikileaks realizes that the Church has often used lawyers and copyrights to prevent public access to its materials, but it sees this as little more than an indictment of the Western media.

"After reviewing documentation on Scientology's endless attacks, legal and illegal, on critics ranging from Time Magazine and CNN, which spent over $3 million defending against just one of their suits, to investigative freelancers who have had publishers pulp their books rather than facing litigation costs, we have come to the conclusion that Scientology is not only an abusive cult, but that it aids and abets a general climate of Western media self-censorship, due to the fear of litigation costs," a representative of the site told us.

"If the West cannot defend its cultural values of free speech and press freedoms against a money making cult like Scientology, it can hardly lecture China and other state abusers of these same values. Such states are quick to proclaim their censorship regime is no mere matter of protecting a cult's profits, but rather of national security."

Companies Struggle as Safari Pops Up on Networks

Via PCWorld -

Network administrators are complaining that Apple's recent decision to offer users its Safari Web browser as part of an iTunes and QuickTime update has made their lives harder, as they struggle to remove the software from PCs on their networks.

For Cody Wilson, the trouble began a few weeks ago, when he noticed that Safari had popped up as a download option with his Apple Software Update, the program that is used to update iTunes and QuickTime.

Wilson, a network administrator with Soy Capital Bank and Trust in Decatur, Illinois, soon found out that many of the users on his network had installed the software without realizing it. "I went into work the next day and I scanned my network, and my inventory software said I have Safari on 30 PCs," he said.

Because of the way Apple had configured the update, anyone who clicked OK automatically installed the company's Web browser. Most users thought that Safari was simply a component of the Apple software they'd already installed, Wilson said.

"This is not good; this is a security risk," he said. "We're a bank."

Wilson said it has taken him the better part of a week to remove Safari from his network and prevent it from being reinstalled.

In an e-mail interview, Susan Bradley agreed that the updates are creating a problem for administrators and making users less secure. "It impacts all of us when more potential attack surface is installed in a group of folks that are vulnerable enough as it is," said Bradley, who is chief technology officer with Tamiyasu, Smith, Horn and Braun, Accountancy Corp.

On Friday, patch management vendor Shavlik Technologies announced that it had updated its Shavlik NetChk Protect software to detect and remove Safari.

Administrators may see more support calls from users who have installed Safari without realizing it, said Eric Schultze, chief technology officer with Shavlik. "I could see administrators saying, 'I approved a standard desktop image, now [Safari is] showing up. I need to remove it.'"

One poster to the Patchmanagement discussion list described the situation more bluntly.

"What's the difference between a malware spreading across a corporate environment and a nagging system tray icon that installs another insecure default browser," wrote the poster, who identified himself as Emin.

---------------------------------------

Just another example that shows that Apple is not ready to protect its corporate users / market share.

Pushing a vulnerability prone browser in an opt-out fashion...is just a bad security decision.

Insisting that Quicktime (i.e. security risk) be installed with iTunes (which is required for the iPhone) is just another example.

In the year past, Apple might have been able to do things like this...and get away with it. Most of their software customers were running Apple OS, and everyone was too busy talking bad about MS security concerns.

But Apple is going to have to get serious about security if they plan on gaining serious market share in the corporate world. It isn't enough for companies to just patch their public flaws anymore. Vendors are expect to proactively test the security of their product before delivery and be more open about vulnerabilities in their products..and to act in a way that encounters customers to have good security behavior.

Adobe Flash Player DeclareFunction2 Invalid Object Use Vulnerability

This vulnerability allows remote attackers to execute code on vulnerable installations of Adobe's Flash Player. User interaction is required in that a user must visit a malicious web site.

The specific flaw exists when the Flash player attempts to access embedded Actionscript objects that have not been properly instantiated. In order for exploitation to occur, an attacker would have to modify a DeclareFunction2 Actionscript tag within an SWF file. Exploitation of this vulnerability can result in arbitrary code execution under the context of the currently logged in user.

http://www.zerodayinitiative.com/advisories/ZDI-08-021/

Tuesday, April 8, 2008

PlayStation Store DRM Hacked

Via G4tv -

A new utility called NPDectyptor makes it possible for users to play games like flOw and Beats on multiple Sony PSPs, essentially breaking the DRM on the games downloaded from the PlayStation Store. The utility has been developed by CipherUpdate, and is apparently pretty effective.

Now you know.

And knowing is half the battle.

Personal Pfizer Data on Stolen Laptop

Via TheDay.com -

Pfizer Inc. has revealed that the theft of a laptop computer in February potentially exposed about 800 current and former employees and contractors to identity theft.

“At this time, Pfizer is not aware that any person has inappropriately used any exposed information, but the company is continuing to monitor the situation,” Pfizer attorney Bernard Nash said in a letter to attorneys general in several states, including Connecticut.


Nash’s letter, dated March 19, said a laptop was stolen Feb. 7 by a burglar from the home of a contractor who helps arrange planning travel and meetings for Pfizer. The laptop was password protected, Nash added.

Information on the laptop included names, credit card numbers and, in some instances, credit card expiration dates, various addresses and phone numbers, hotel loyalty program numbers and other information. It did not appear that any Social Security numbers or PIN codes were exposed, the company said.

Last year, a series of four data breaches at Pfizer exposed the names and personal information of more than 52,000 people.

--------------------

I would assume they mean, Windows password protected?

Which can easily be bypassed with a Linux CD?

When will people learn that this is not enough for mobile devices that contain sensitive data?

Iranian Blogs More Resistant to Government Contro

Via Computerworld -

A newly released Harvard University study dispels the conventional wisdom that says the Iranian blogosphere consists mainly of young writers critical of the ruling Islamic Republic regime. Instead, Harvard 's Internet and Democracy project found that the Iranian blogosphere consists of a variety of groups with both pro- and anti-government beliefs.

The study did find that blogs may be more resistant to government control than other media. In face, the report concluded that blogs may represent the "best hope" for homegrown Democratic change in a country where the press is tightly controlled by religious leaders.

Harvard researchers used computational social network mapping and human and automated content analysis to analyze 60,000 regularly updated Iranian blogs.

The study found that the Iranian blogosphere ranges from sites providing religious conservative messages to bloggers pushing more secular or reform-focused agendas. The blogs studied in Iran span a wide array of topics, including politics, human rights, poetry religion and pop culture, the report said.

The study, called "Mapping Iran's Online Public: Politics and Culture in the Persian Blogosphere," found that the government blocks far fewer blogs than the authors had suspected in a country where the press is controlled by religious conservatives who often are part of the government.

New Attack Kit Targets Seven ActiveX Bugs (Four Unpatched)

Via ComputerWorld -

Hackers are using a new multiple-attack package composed of seven ActiveX exploits, many of them never seen in the wild before, said a security company on Friday.

Fewer than half of the flawed ActiveX controls have been patched.

The attack framework probes Windows PCs for vulnerable ActiveX controls from software vendors Microsoft, Citrix Systems and Macrovision, as well as hardware makers D-Link Corp., Hewlett-Packard, Gateway and Sony, said a Symantec Corp. researcher.

"What's interesting about this attack is that there are so many vulnerabilities in one attack that have not been seen in the wild previously," said Symantec researcher Patrick Jungles, who wrote an analysis of the multistrike package for customers of the company's DeepSight threat service.

According to Jungles, visitors to compromised Web sites are redirected by a rogue IFRAME to a malicious site serving the package. The attack pack tests the victim's PC for each ActiveX control, detects whether a vulnerable version of a control is installed, and then launches an attack when it finds one.

Bugs in ActiveX, a Microsoft technology used most often to create add-ons for the company's Internet Explorer browser, have always been common, but so many serious flaws have been disclosed of late that some security experts have recommended that users do without them.

The seven exploited in the package outlined by Jungles are a mix of old and brand-new flaws. For example, Microsoft's own ActiveX vulnerability -- a bug in IE's Speech API -- was disclosed in June 2007, while the vulnerability in the Citrix Presentation Server Client control harks back even further, to December 2006. Others, such as the ActiveX bugs in D-Link's security webcams and in Sony's ImageStation, are much more recent, having been revealed in February.

Four of the seven ActiveX flaws -- those in the D-Link, Gateway, Sony and Macrovision products -- have not been patched, said Jungles.

Assuming the exploit framework succeeds in compromising a PC, the hackers drop a Trojan on the machine that turns it into a spam-spewing zombie; the Trojan includes a rootkit component to mask the malware from antivirus scanners.

Iran Steps Up Defiance of UN With More Centrifuges

Via Bloomberg -

President Mahmoud Ahmadinejad said Iran is installing 6,000 new advanced uranium-enrichment centrifuges at its Natanz nuclear facility, a move that steps up the Persian Gulf country's dismissal of United Nations sanctions.

Natanz already has 3,000 of an older version of the fast- spinning machines that produce uranium 235, a material that can be used to fuel a nuclear power plant or build a bomb. The UN's International Atomic Energy Agency said in February that Iran was testing a faster, more reliable centrifuge. Iran plans to install 50,000 centrifuges at Natanz, Ahmadinejad said in 2006.

RIP - Geoffrey

Geoffrey (g-unit[at]deussexmachina.org) has passed away. R.I.P.

It is with great sadness and a heavy heart that I report the passing of Geoffrey (Monkey) Bennett who collapsed last night while jogging and couldn't be revived. Geoffrey is survived by his wife Jennifer and daughter Ruth. His funeral will be held in Austin, Texas later this week. Details will be provided when available for anyone wishing to attend. Please let the rest of the security community know. He was a good friend and will be missed.

AHA! will not be the same without him.....goodbye my friend.

Monday, April 7, 2008

Tumbleweed SecureTransport FileTransfer ActiveX BOF Exploit

Versions affected:
SecureTransport FileTransfer ActiveX Control vcst_eu.dll 1.0.0.5 English. Prior versions, and other language editions (vcst_*.dll), are assumed to be vulnerable.

Vulnerability discovered:
Buffer Overflow.

Vulnerability impact:
High - Remote code execution.

Vulnerability information:
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tumbleweed Communications SecureTransport FileTransfer ActiveX Control. User interaction is required to exploit this vulnerability in that the target must visit a malicious page. It may be possible to embed into HTML capable email clients.

Additionally, a Metasploit Framework Module has been written to demonstrate the vulnerability.

References:
aushack.com advisory
http://www.aushack.com/200708-tumbleweed.txt

Credit:
Patrick Webster ( patrick@aushack.com )

---------------------------------------------------

http://www.milw0rm.com/exploits/5398

Kraken Botnet Overtakes Storm

Via DarkReading -

SAN FRANCISCO -– RSA 2007 Conference –- A new botnet twice the size of Storm has ballooned to an army of over 400,000 bots, including machines in the Fortune 500, according to botnet researchers at Damballa. (See The World's Biggest Botnets and MayDay! Sneakier, More Powerful Botnet on the Loose.)

The so-called Kraken botnet has been spotted in at least 50 Fortune 500 companies and is undetectable in over 80 percent of machines running antivirus software. Kraken appears to be evading detection by a combination of clever obfuscation techniques, including regularly updating its binary code and structuring the code in such a way that hinders any static analysis, says Paul Royal, principal researcher at Damballa.

"It's easy to trace but slow to get antivirus coverage. It seems to imply [the creators] have a good understanding of how AV tools operate and how to evade them," Royal says.

Kraken's successful infiltration of major enterprises is a wakeup call that bots aren't just a consumer problem. Damballa and other botnet experts over the past few months have seen an unsettling rise in bot infections in enterprises.

Royal says like Storm, Kraken so far is mostly being used for spamming the usual scams -- high interest loans, gambling, male enhancement products, pharmacy advertisements, and counterfeit watches, for instance. "But given that it updates its binary, there's no reason it couldn't update itself to a binary that does other things," Royal says. "I'm wondering where this thing is going to go."

Damballa predicts that even now that Kraken has been outed, it will continue growing at least in the near-term -- up to at least 600,000 new bots by mid-April. Its bots are prolific, too: The firm has seen single Kraken bots sending out up to 500,000 pieces of spam in a day.

Wanted: Gordon Brown's fingerprints, £1,000 Reward

Via The Register UK -

A £1,000 reward has been posted for the fingerprints of Prime Minster Gordon Brown and Home Secretary Jacqui Smith, both of whom, claim perpetrators No2ID and Privacy International, are "wanted identity felons". In a campaign Wanted Poster the campaign groups claim that their plan to "steal the fingerprints of the entire British population... will be the identity theft crime of the century."

Any fingerprints submitted should, say the groups, be lawfully obtained and provided with corroborating evidence; beer glasses, doorknobs or any object with a hard surface will however be accepted as entries. Should they manage to get hold of the pair's fingerprints, the two groups intend to make them publicly available, following the example of the Chaos Computer Club, which recently open sourced the German interior minister's fingerprints.

Are No2ID and Privacy International doing anything illegal? PI Director Simon Davies was philosophical, telling The Register, "I'm sure they can cook up something if they want to." But he warned of the dangers inherent in the Government's plans: "The government is blindingly ignorant that biometrics in the future will be crucial to personal security. It seems to believe that personal security equates only to the personal security that government offers. Unless government can come up with a framework for secure biometric revocation, it's criminally irresponsible to demand fingerprints. And it would be folly for us to give them away to government without a fight."

No2ID National Coordinator Phil Booth meanwhile challenged Smith and Jones Brown to turn themselves in for the good of the country: "If they truly believe that the ID scheme will 'secure' their personal identities, the best thing Gordon Brown and Jacqui Smith could do would be to surrender their OWN fingerprints and get us to donate the grand to a charity of their choice. Failing to surrender their fingerprints could be seen as tacit acknowledgement that they have no real faith in their own scheme."

Lawmakers Reject NYC Traffic Fee

Via AP -

Lawmakers rejected a proposal on Monday to charge Manhattan motorists an extra fee to drive in the city, a plan advocates hoped would reduce traffic and curb pollution.

Assembly Speaker Sheldon Silver announced the decision after a survey of Democratic Assembly members in a private conference. The decision comes after days of closed-door negotiations, and means the city will forfeit $354 million in federal funding for trying to kick-start the plan.

The concept aimed to cut traffic and pollution by forcing more commuters onto mass transit. It would have charged most drivers $8 to drive below 60th Street between 6 a.m. and 6 p.m. Monday through Friday. Truckers would have paid $21.

The Legislature faced a Monday deadline to act on Mayor Michael Bloomberg's proposal, which was already endorsed by Democratic Gov. David Paterson, the Republican-led Senate and the City Council.

Bloomberg spokesman Stu Loeser did not immediately comment.

The plan ran into strenuous objections from legislators from outer boroughs and New York City suburbs who said it would unfairly target commuters and their constituents.

"The conference has decided that they are not prepared to do congestion pricing," Silver said. "Many members just don't believe in the concept. Many think this proposal is flawed. It will not be on the floor of the Assembly," he said.

Silver said part of the problem with the proposal, which Bloomberg had said could begin next year, is that it doesn't immediately provide funding to the Metropolitan Transportation Authority. He said the agency that runs the city's mass transit is already underfunded and needs to be bolstered before it takes on more commuters.

IPhone Frenzy in Russia Fueled by Smugglers, Jeweler

Via Bloomberg -

Apple Inc. has gained unlikely allies in its bid to boost iPhone sales: Russian smugglers.

The device isn't sold by Cupertino, California-based Apple in Russia and it can't be used legally on local networks. Still, about 250,000 people own one, more than any other country except the U.S. and China, according to Eldar Murtazin, chief analyst at Moscow-based Mobile Research Group.

That popularity has turned into a bonanza for traders who sell the phones in kiosks and on the Internet for $1,000 each, more than twice the U.S. price. Hackers say they charge as much as 2,500 rubles ($105) to ``unlock'' them so they work locally.

"It's an icon for Russians,'' said Timofei Kulikov, a lawyer and buyer of electronic products for X5 Retail Group NV, Russia's largest supermarket chain. "If you see two businessmen at lunch in Moscow, they'll both have iPhones on the table.''

The evolution from Web-surfing, touch-screen gadget to status symbol has been a boon for Peter Aloisson. The jeweler sold a diamond-studded iPhone encased in white gold to a Russian businessman in March for 120,000 euros and is working on a 500,000-euro ($783,000) version that may go to another Russian client.

"There is no doubt that Russia, when it comes to luxury items, is by far the best marketplace,'' Aloisson, 47, said last week from his studio in Vienna.

Notable users include President-elect Dmitry Medvedev, billionaire Alexander Mamut and Boris Yeltsin Jr., grandson of the former president, according to the newspaper Kommersant. Medvedev's spokeswoman declined to comment.

Murtazin says about 20,000 iPhones arrive in Russia each month.

"They arrive in suitcases,'' Murtazin said. "Practically every flight from the U.S. brings new iPhones.''

Saturday, April 5, 2008

Policing Internet 'Not ISP's Job'

Via BBC -

The head of one of Britain's biggest internet providers has criticised the music industry for demanding that he act against pirates.

The trade body for UK music, the BPI, asked internet service providers to disconnect people who ignore requests to stop sharing music.

But Charles Dunstone of Carphone Warehouse, which runs the TalkTalk broadband service, is refusing.

He said it is not his job to be an internet policeman.

BBC technology correspondent Rory Cellan-Jones said that the music industry has been fighting a losing battle to prevent people from swapping songs for nothing on the internet.

Mr Dunstone, whose TalkTalk broadband is Britain's third biggest internet provider, said the demands are unreasonable and unworkable.

He said: "Our position is very clear. We are the conduit that gives users access to the internet.
We do not control the internet, nor do we control what our users do on the internet."

"I cannot foresee any circumstances in which we would voluntarily disconnect a customer's account on the basis of a third party alleging a wrongdoing."

He added the company would fight to protect the rights of its users using the law.

The BPI denied it is asking ISPs to become internet police, saying the firms need to educate their customers not to steal music.

It also says that if they do not help with the fight against music piracy, then the government will bring in legislation to make them cooperate.

-------------------------

Education thru force...is a better term.

Gartner: Open Source Will Quietly Take Over

Via ZDNet -

In a few years' time, almost all businesses will use open source, according to Gartner; even though IT managers may be unaware of it, and prefer to talk about fashions such as software as a service.

Open-source promoters have welcomed the endorsement by what is seen as a conservative commentator, but predict the changes will go further than Gartner assumes.

"By 2012, more than 90 percent of enterprises will use open source in direct or embedded forms," predicts a Gartner report, The State of Open Source 2008, which sees a "stealth" impact for the technology in embedded form: "Users who reject open source for technical, legal or business reasons might find themselves unintentionally using open source despite their opposition."

------------------

Resistance is futile...

The Phorm “Webwise” System

Via lightbluetouchpaper.org -

Last week I spent several hours at Phorm learning how their advertising system works — this is the system that is to be deployed by the UK’s largest ISPs to pick apart your web browsing activities to try and determine what interests you.

The idea is that advertisers can be more picky in who they serve adverts to… you’ll get travel ads if you’ve been looking to go to Pamplona for the running of the bulls, car adverts if you’ve been checking out the prices of Fords (the intent is that Phorm’s method of distilling down the ten most common words on the page will allow them to distinguish between a Fiesta and a Fiesta!)

I’ve now written up the extensive technical details that they provided (10 pages worth) which you can now download from my website.

Much of the information was already known, albeit perhaps not all minutiae. However, there were a number of new things that were disclosed.

Phorm explained the process by which an initial web request is redirected three times (using HTTP 307 responses) within their system so that they can inspect cookies to determine if the user has opted out of their system, so that they can set a unique identifier for the user (or collect it if it already exists), and finally to add a cookie that they forge to appear to come from someone else’s website. A number of very well-informed people on the UKCrypto mailing list have suggested that the last of these actions may be illegal under the Fraud Act 2006 and/or the Computer Misuse Act 1990.

Phorm also explained that they inspect a website’s “robots.txt” file to determine whether the website owner has specified that search engine “spiders” and other automated processing systems should not examine the site. This goes a little way towards obtaining the permission of the website owner for intercepting their traffic — however, in my view, failing to prohibit the GoogleBot from indexing your page is rather different from permitting your page contents to be snooped upon, so that Phorm can turn a profit from profiling your visitors.

Overall, I learnt nothing about the Phorm system that caused me to change my view that the system performs illegal interception as defined by s1 of the Regulation of Investigatory Powers Act 2000.

Apple to NYC's Green Logo: No No No

Via MacObserver.com -

Apple Inc. is not at all sanguine about New York City's efforts to go green, at least when it comes to the logo the city is trying to trademark. Cupertino, CA-based Apple Inc. has filed a challenge against a federal trademark registration effort by GreeNYC, saying the logo (see below) the nonprofit is trying to trademark is too similar to Apple's own logo, which has been in use since 1977.

The International Business Times reported that GreeNYC's position is that the infinity apple symbol and the group's environmental approach were unique, a key word in the area of registered trademarks, and that there was no infringement.

-------------------------

Click the link above and check out the images.

This is clearly a overreaching lawsuit. Then again, this is the company that suits bloggers...

Friday, April 4, 2008

US Nuclear Envoy to Meet DPRK Counterpart

Via VOA News -

U.S. Assistant Secretary of State and chief nuclear negotiator Christopher Hill told reporters in Jakarta Friday he might meet with his North Korean counterpart, Kim Kye Gwan, in the coming days.

"I'm not in a position yet to confirm reports that you've all heard that we will be having meetings with my counterpart in the DPRK [Democratic Peoples' Republic of Korea] except to say that we're obviously looking to try to wrap up the declaration very soon," he said. "We don't have a lot of time; we really need to move on to the next phase if we're going to really achieve our goals."

Hill, who was in Jakarta for a brief visit Friday, told reporters if he meets with Kim Kye Gwan, it will not take place until after his visit to East Timor on Sunday.

The Six Party Talks between North and South Korea, the United States, China, Japan and Russia stalled last December when Washington accused North Korea of failing to keep to a deadline for declaring all of its nuclear programs.

Pyongyang was required to submit a full and accurate declaration of its nuclear programs and materials by the end of 2007.

North Korea maintains it has met its obligations under the terms of the six-party agreement.

The United States also wants Pyongyang to reveal any weapons-grade uranium enrichment programs, and whether it has shared nuclear technology with Syria.

Vermont Ski Resort Reports Hannaford-like Data Theft

Via ComputerWorld -

In a security breach that sounds similar to the one disclosed by Hannaford Bros. Co. last month, the Okemo Mountain Resort ski area in Vermont announced this week that data from more than 46,000 credit and debit card transactions may have been compromised during a system intrusion over a 16-day period in February.

Okemo said in a security advisory released on Monday that the breach may have affected customers who used their payment cards at the resort in Ludlow, Vt., between Feb. 7 and Feb. 22, the time frame when the intrusion took place. The intruder or intruders may also have accessed data from card transactions processed between January and March 2006, according to the advisory.

Bonnie MacPherson, a spokeswoman for Okemo, said today that at least some of the data appears to have been stolen as the recent payment card transactions were being authorized. "We can tell you that this was a real-time theft," McPherson said. "The information was being taken as the cards were being swiped."

If that is actually the case, it could make the breach at Okemo a close cousin to the much larger one announced by Hannaford on March 17. In the Hannaford breach, malware installed on servers in each of the Scarborough, Maine-based company's grocery stores intercepted card data as the information was being transmitted from point-of-sale systems to authorize transactions.

-------------------

POS Systems are scary insecure. Most companies are slow to replace insecure POS systems with more secure versions due to cost.....but this decision is not without its negative side.

FBI Reports Record Financial Losses to Cybercrime

Via DarkReading -

The U.S. economy may be tanking, but the cybercrime economy is booming, according to the latest report from the FBI’s Internet Crime Complaint Center.

Dollar losses to cybercrime increased to $240 million in 2007, a $40 million jump from 2006, according to the IC3's newly released 2007 Internet Crime Report. The IC3 received 206,884 reports of Internet crime last year, 90,000 of which were then picked up by law enforcement, according to the report.

And that’s not including the cybercrimes that went unreported to the IC3.

"The Internet presents a wealth of opportunity for would-be criminals to prey on unsuspecting victims, and this report shows how extensive these types of crime have become," said FBI Cyber Division assistant director James E. Finch in a prepared statement. "What this report does not show is how often this type of activity goes unreported. Filing a complaint through IC3 is the best way to alert law enforcement authorities of Internet crime."

The biggest culprit was online auction fraud. Other fraud includes purchases that were never delivered, credit card and debit card fraud, and computer breaches, spam, and child pornography.

Some interesting demographics: 75.8 percent of the bad guys were men, most from the U.S. Here in the States, California, Florida, New York, Texas, Illinois, Pennsylvania, and Georgia claimed the most offenders. The U.K., Nigeria, Canada, Romania, and Italy were also well represented.

Nearly 60 percent of the victims who reported their losses to the IC3 were men -- half between the ages of 30 and 50, and most from the U.S. And men lost more money than women, according to the report, with $1.67 to every $1 lost per woman. Why the difference? The IC3 speculates in its report that it may be "a function of both online purchasing differences by gender and the type of fraudulent schemes by which the individuals were victimized." (Read: Guys buy more expensive toys.)

Some 73.6 percent of the crimes occurred via email contact, and 32.7 percent via Webpages, according to the report. IC3 is a joint effort between the FBI and the National White Collar Crime Center.

--------------------

Here is the direct PDF link to the 2007 report.

Thursday, April 3, 2008

Radio Controlled Door Opener for Cars and Buildings Cracked

Via Heise Security -

Scientists at the Ruhr-Universität Bochum have defeated the Keeloq immobiliser and door opener used in many cars. Attackers need only intercept two transmissions between the transmitter and receiver in order to clone the digital key and gain access to the car. Microchip Technology's RFID-based KeeLoq process, is used in automobiles manufactured by Chrysler, Daewoo, Fiat, General Motors, Honda, Toyota (Lexus), Volvo, Volkswagen and Jaguar. KeeLoq is also used in building access systems and garage door openers. Signal interception is possible at a range of 100 metres, according to Professor Christof Paar of the School of Electronics and Information Technology. In addition to gaining unauthorised access, the systems can be manipulated, denying the rightful owners access.

Both the KeeLoq transmitter and receiver encrypt their signals. A proprietary, non-linear encryption algorithm is used which encrypts controller commands with a unique code before transmission to the vehicle. A 32 bit initialisation vector together with a 32 bit hopping code is used as a key. An ID unique to each electronic key is added to the calculation.

But there is also a manufacturer's master key for all of the products in a series. This is precisely what Professor Paar's Bochum group was able to retrieve using a procedure known as side channel analysis. To obtain the master key the researchers used differential power analysis (DPA) and differential electromagnetic analysis (DEMA) at both the transmitter and receiver during the transmission. Once the master key is known, only two transmissions are needed in order to obtain the crypto key of a particular KeeLoq remote control. The vulnerability was tested on commercial systems, according the Bochum scientists.

In early February the researchers presented a detailed description of the attack that required them to intercept a number of activation procedures in order to obtain the manufacturer's key. At the CRYPTO 2007 cryptography conference, an international group of researchers presented a method by which the individual keys could be cracked using distributed computing.

Zawahiri: Al-Qaeda Doesn't Kill Innocents

Via smh.com.au -

CAIRO: Al-Qaeda's second-in-charge, Ayman al-Zawahiri, has defended the militant organisation, saying it does not kill innocents, in an audio message.

The 90-minute message was a response to more than 900 questions posted on extremist websites by supporters, critics and journalists in December. "We haven't killed the innocents, not in Baghdad nor in Morocco, nor in Algeria, nor anywhere else," Zawahiri said according to a 46-page English transcript which, like the audio message, appeared on websites linked to the group.

"If there is any innocent who was killed in the mujahideen's operations, then it was either an unintentional error or out of necessity," he said in response to several questions about the group's policy towards taking innocent lives. Zawahiri also denied speculation that al-Qaeda's leader was sick.

"Sheik Osama bin Laden is in good health," said Zawahiri, a doctor. "The ill-intentioned always try to circulate false reports about him being sick."

Al-Qaeda will turn to fight Israel after "winning" the war in Iraq against US-led and government forces, he said, adding that the US had begun to collapse. He went on to say it was al-Qaeda's opponents that killed innocents and said "the enemy intentionally takes up positions in the midst of the Muslims for them to be human shields for him."

A banner bearing the logo of al-Qaeda's media arm, al-Sahab, appeared earlier on websites linked to the organisation to herald this first instalment of answers. Zawahiri said he chose about 100 questions to answer.

Al-Sahab announced in December that Zawahiri would take questions from the public posted on Islamic militant websites and would respond "as soon as possible". The queries were posted on the main Islamist website until the cut-off date of January 16.

Many of the questions, compiled since December, were sharply critical of al-Qaeda and its practices; others sought advice for joining jihad. Zawahiri, who is believed to be hiding in Afghanistan or Pakistan, said he would answer more in a second statement and said the delay in response was partly due to security reasons.

One thing is clear from the questions: self-proclaimed al-Qaeda supporters are as much in the dark about the terrorist network's operations and intentions as Western analysts and intelligence agencies.

--------------------------

Clearly, Al-Qaeda's second-in-charge, Ayman al-Zawahiri must be using a rather unique definition of "innocents".

China Jails Rights Activist Outspoken on Tibet

Via reuters.com -

BEIJING (Reuters) - A Buddhist Chinese dissident outspoken on Tibet and other sensitive topics was jailed for three-and-a-half years on Thursday, a conviction likely to become a focus of international rights campaigns ahead of the Beijing Olympics.

Hu Jia, 34, was found guilty of "inciting subversion of state power" for criticizing the ruling Communist Party, a verdict at which the United States expressed dismay.

"In this Olympic year, we urge China to seize the opportunity to put its best face forward and take steps to improve its record on human rights and religious freedom," the U.S. Embassy said in a statement.

The official Xinhua news agency said Hu had made a "confession of crime and acceptance of punishment", leading the court to issue a relatively light sentence. Hu's two lawyers said he had acknowledged "excesses".

"In the end, I think that he came to accept that some of his statements were contrary to the law as it stands," said defense lawyer Li Jinsong.

"So to some extent he accepted the prosecution's allegations."

Hu has 10 days starting on Friday to decide whether to appeal, but Li said he was unlikely to do so. Hu could apply for medical release to treat a bad liver and other illnesses, the lawyer added.

The "inciting subversion" charge can attract a jail term of five years or longer, and before the hearing lawyer Li Fangping said a long sentence was likely. After the hearing he said he was unaware of any deal in return for the sentence.

Wednesday, April 2, 2008

Phishing Scam Actually an Army Security Test

Via military.com -

ARLINGTON, Va. -- An offer for free tickets to theme parks for servicemembers turned out to be an e-mail scam, which turned out to be a security exercise run by the Army.

But no one apparently told Army Family and Morale, Welfare and Recreation Command that it was part of this charade masquerading as a scam.

The e-mail, sent by MWR-Man ager@mwr.army-support.com, allegedly came from the "Army MWR Office," and directed servicemembers and Defense Department civilians to the following Web site to receive free tickets: http://mwr.army-support.com

As of early Monday, the Web site asked for personal information, such as name, address, phone number and e-mail address.

But it was all a lie, said Bill Bradner, a spokesman for Family and MWR Command.

"This is a scam, a phishing site using our logo, header, and links to our Web site," Bradner said in an e-mail Monday. "It has nothing to do with us."

Family and MWR Command issued a news release Monday afternoon warning servicemembers that the offer for free tickets did not come from the command, but then the story took an unexpected turn.

Late Monday afternoon, the site had a different message:

"This web page was part of an Army Network Security Exercise and is no longer active. No actual data was collected or transmited (sic). Further information about this test is at the following link: TBA"

Bradner said he later learned the Web site was in fact a test to see how soldiers respond to phishing scams.

The test was conducted by U.S Army Intelligence and Security Command (INSCOM) and U.S. Army Network Enterprise Technology Command (NETCOM), said Laurie Pugh, head spokeswoman for Family and MWR Command.

Pugh said Family and MWR Command had no knowledge of the test, which NETCOM told her about on Tuesday.

"We were concerned that we had not been brought into the loop on it," she said. "We understand the need for testing security and wished we had known about it."

She also said she was told the test is part of a larger effort across the Defense Department.

Family and MWR Command expected to issue a news release about the exercise Tuesday afternoon, Pugh said.

Bob Stone, a spokesman for INSCOM, had no information immediately available on the matter Tuesday afternoon, but he said he would look into it.

-----------------------

After thinking about this article for a while, it started to make sense to me.

If you were going to conduct a fake phishing test against a selected target, why would you tell them beforehand?

A real attacker wouldn't give you a heads up before opening a new phishing site. Just ask Paypal and Bank of America.

I have a feeling that this test was more for the MWR, than the service members.

How long would the phish site run before the MWR is alerted? How fast would they react? and in what way?

The DoD has to understand that a certain number of service members will fall for the a free ticket phish and give their information up...that shouldn't be a shocker, but testing the reaction of the MWR to the fake phish....that would seem to be valuable data.

I could be wrong...but...what if.

Hackers Are People Too



The aim of this documentary is to present a portrait of the hacking community to average America. No, hackers are not all evil and out to steal your credit card. Yes, many of them are brilliant and even socially awkward. What makes a hacker a hacker? Find out how the hacking community defines itself in this student film.

http://www.hackersarepeopletoo.com/trailer.html

--------------------

Who are "Cinematic Gold Productions"?

Awesome! I see at least two friends in just the trailer...both from beautiful Austin, TX.

Just FYI, but I was given the greenlight yesterday to attend Blackhat 2008 and Defcon 16....so if you are going to be in Vegas, drop me a line and lets *cough* talk about security *cough*.

You Digg?

Water Warming Up in BT & Phorm Advert Trials

Via BBC -

Trials of an online ad system carried out by BT involving more than 30,000 of its customers were potentially illegal, says a leading digital rights lawyer.

BT has said it trialled a prototype of Phorm, which matches adverts to users' web habits, in 2006 and 2007.

The company did not inform customers that they were part of the trial.

Nicholas Bohm, of the Foundation for Information Policy Research, said tests without the knowledge of users were "an illegal intercept of users' data".

A spokesman for BT said the firm had no comment about the legality or illegality of the 2006 test.

In a statement the firm said the trial was "a small scale technical test of a prototype advertising platform".

"The purpose of the test was to evaluate the functional and technical performance of the platform."

It continued: "It is important for BT to ensure that before any new technologies are deployed, they are robust and fit for purpose. No personally identifiable information was processed, stored or disclosed during this test."

Earlier this month BT told BBC News that before the 2007 test it had taken "legal and other external advice... and on the basis of that advice commenced the small scale technical test in good faith".

Eighteen thousand customers were involved in the 2006 trial and BBC News understands that the 2007 test was on a similar scale.

Virgin Media and Talk Talk are also due to deploy the technology and there is no suggestion that the two companies have trialled the system in the past.

The Foundation for Information Policy Research has written to the Information Commissioner to argue that Phorm contravenes the Regulation of Investigatory Powers Act 2000 (Ripa), which protects users from unlawful interception of information.

Phorm and BT have said the technology does not breach any UK laws.

---------------------

Saying that no PI data was sent, processed or stored, is just silly. Perhaps they are legally right, but in reality...they are wrong.

People can commonly be identified by just the types of Google/Yahoo searches they conducted.

Does no one remember the AOL Search Scandal?
While none of the records on the file are personally identifiable per se, certain keywords contain personally identifiable information by means of the user typing in their own name (ego-searching), as well as their address, social security number or by other means....Although the searchers were only identified by a numeric ID, the New York Times successfully discovered the identity of several searchers, and with her permission, exposed search number 4417749 as Thelma Arnold, a 62-year-old Georgian widow.
From the sound of it, Phorm was given MUCH, MUCH more than just search terms.

So what do you think?

Spam up by 50% in first quarter of 2008

Via securecomputing.net.au -

Worldwide spam volumes have surged by 50 percent in the first quarter of 2008 revealed security vendor Proofpoint today, who now predicts enterprises will see inbound spam more than double this year.

Short term spikes of 60 percent or more have also been seen and some enterprises have witnessed spam volume increases as high as 200% in Q1 2008, claimed Proofpoint.

The rise continues the trend of the last two years.

"Botnets continue to proliferate and are by far the dominant source of spam," said Gerry Tucker, regional head for Proofpoint in APAC.

"The Storm botnet, already the largest network of compromised machines in history, doubled in size during the holiday season alone,” said Tucker.

The massive computing power and network resources associated with these botnets allow spammers and scammers to constantly increase the aggressiveness and scale of their attacks, he added.

Furthermore, the large numbers of new Internet users coming online across the world are fueling the growth of botnets.

“The high volumes of email associated with today's spam attacks can escalate the number of inbound messages between 500 percent and 700 percent within a period of hours. This sudden, exponential growth in spam volumes can easily strain IT network infrastructure to the point of failure,” said Tucker.

U.S. Alarmed as Some Exports Veer Off Course

Via NYTimes -

WASHINGTON — Roadside bombings of American troops in Iraq were occurring with unnerving regularity when military investigators made a disturbing discovery: American-made computer circuits sold to a trading company in the United Arab Emirates had turned up in the bomb detonators.

That finding set off a clash with Washington last year when the Bush administration cited the diversion of the computer circuits to Iran, and eventually Iraq, as proof that the United Arab Emirates were failing to prevent American technology from slipping into the wrong hands. Administration officials said aircraft parts, specialized metals and gas detectors that have a potential military use had also moved through Dubai, one of the emirates, to Iran, Syria or Pakistan.

The diplomatic face-off, which drew little public attention, prompted the United States to threaten tough new controls on exports to the United Arab Emirates, an ally. The nation had invested billions to become a global trading hub and had begun a campaign to burnish its image in the United States after the uproar in 2006 over a proposal to allow a Dubai company manage some American port terminals.

The administration backed down only after the emirates promised to pass their own export control law. But it is unclear that much has changed nearly a year after the confrontation.

Yousef al-Otaiba, an adviser to the crown prince of the United Arab Emirates, said his country was more closely monitoring goods that it re-exported while blocking items that might help Iran build weapons systems. But trade experts and Iranian traders in Dubai said there was little evidence that the new export control law was being broadly enforced.

“It has virtually had no effect, to be honest,” said Nasser Hashempour, deputy president of the Iranian Business Council in Dubai. “If someone wants to move something — get it to Iran — it is easy to be done.”

Tire Pressure Monitoring Systems & Privacy

Via HexView -

There is no shortage of articles discussing privacy issues introduced by new technologies. ReadID, passports, chips in currency bills, and other engineering marvels designed for purposes of tracking and monitoring, always come with a bouquet of questions and privacy concerns. On the other hand, technologies not specifically designed for monitoring can sometimes be used for this very purpose and privacy problems introduced by them are often overlooked. Tire Pressure Monitoring Systems (TPMS) is one of those technologies.

TPMS lets on-board vehicle computers measure air pressure in the tires. If you purchased a new vehicle in the last 2 years, it is very likely that it came with TPMS. If you live in the Unites States, your next vehicle will contain TPMS whether you like or not -- in April 2005, National Highway Traffic Safety Administration issued a rule requiring automakers to install TPMS sensors in all new passenger cars and trucks starting in September 2007.

..

In a typical TPMS, each wheel of the vehicle contains a device (TPMS sensor) - usually attached to the inflation valve - that measures air pressure and, optionally, temperature, vehicle state (moving or not), and the health of the sensor's battery. Each sensor transmits this information (either periodically or upon request) to the on-board computer in the vehicle. To differentiate between its own wheels and wheels of the vehicle in the next lane, each TPMS sensor contains a unique id. The receiver is "paired" to the sensors very much as a Bluetooth device. The vast majority of TPMS sensors transmit information in clear text using one of the assigned radio frequencies (typically, 315MHz or 433MHz).

Here is where privacy problems become obvious: Each wheel of the vehicle transmits a unique ID, easily readable using off-the-shelf receiver. Although the transmitter’s power is very low, the signal is still readable from a fair distance using a good directional antenna.

Remember the paper that discussed how Bluetooth radios in cell phones can be used to track their owners? The problem with TPMS is incomparably bigger, because the lifespan of a typical cell phone is around 2 years and you can turn the Bluetooth radio off in most of them. On the contrary, TPMS cannot be turned off. It comes with a built-in battery that lasts 7 to 10 years, and the battery-less TPMS sensors are ready to hit the market in 2010. It does not matter how long you own the vehicle – transportation authorities keep up-to-date information about vehicle ownership.

Pentagon Is Expected to Close Counterintelligence Field Activity Unit

Via NYTimes -

The Pentagon is expected to shut a controversial intelligence office that has drawn fire from lawmakers and civil liberties groups who charge that it was part of an effort by the Defense Department to expand into domestic spying.

The move, government officials say, is part of a broad effort under Defense Secretary Robert M. Gates to review, overhaul and, in some cases, dismantle an intelligence architecture built by his predecessor, Donald H. Rumsfeld.

The intelligence unit, called the Counterintelligence Field Activity office, was created by Mr. Rumsfeld after the Sept. 11, 2001, terrorist attacks as part of an effort to counter the operations of foreign intelligence services and terror groups inside the United States and abroad.

Yet the office, whose size and budget is classified, came under fierce criticism in 2005 after it was disclosed that it was managing a database that included information about antiwar protests planned at churches, schools and Quaker meeting halls.

The Pentagon’s senior intelligence official, James R. Clapper, has recommended to Mr. Gates that the counterintelligence field office be dismantled and that some of its operations be placed under the authority of the Defense Intelligence Agency, the government officials said.

Pentagon officials said Mr. Gates had yet to approve the recommendation.

Mr. Gates, a former director of central intelligence, has promised to improve coordination of the Pentagon’s intelligence collection with other spy agencies and help rebuild some of the relationships bruised under Mr. Rumsfeld’s tenure. Mr. Rumsfeld and some of his aides had expressed deep suspicion toward the Central Intelligence Agency in particular, and some people accused Mr. Rumsfeld of trying to build an intelligence empire of his own.

Shortly after taking over the Pentagon last year, Mr. Gates ordered a broad review of its intelligence operations and of the Defense Department’s relationships with other spy agencies.

It is unclear whether Mr. Clapper is also recommending tighter restrictions on Pentagon counterterrorism and counterespionage operations in the United States.

-------------------

Reversing the DoD's dislike for the CIA is not going to be easy....that is a idea that runs very deep.

Tuesday, April 1, 2008

RJD2 & Dälek @ Emos this Friday

Dälek (pronounced ’Die-a-leck’) is an alternative hip hop duo from Newark, NJ. The group comprises MC Dälek (vocals) and the Oktopus (production). They have often toured with artists from radically different genres, such as Godflesh, Isis, Prince Paul, The Melvins, De La Soul, and Lovage.

"It’s purely hip-hop, in the purest sense. If you listen to what hip-hop has historically been, it was all about digging in different crates and finding different sounds, and finding different influences to create. If Afrika Bambaataa wasn’t influenced by Kraftwerk, we wouldn’t have ’Planet Rock.’ So, in that sense, what we do is strictly hip-hop."
- MC Dälek

-----------------------------

RJD2 (born Ramble John "RJ" Krohn on May 27, 1976) is an American hip hop producer, singer and musician. RJD2 was born in Eugene, Oregon, and raised in Columbus, Ohio. He currently resides in Philadelphia, Pennsylvania. He was signed to the Definitive Jux label where he released two largely instrumental hip hop albums and has produced tracks for many prominent rappers. However, he has now left Def Jux and has signed with XL Recordings. His latest album, The Third Hand, is a striking departure from his usual style and features RJD2 singing and playing instruments on nearly every track.

----------------------------

Emos in Austin, TX
http://www.emosaustin.com/calendar/show_detail.php?id=6016&date=20080404

Thanks to my friend, Chris, @ Thrity Ghost Records for the tip and the guest list spot ;)

Check out this video by RJD2 - 1976 (Youtube)

Universe's Tiniest Blackhole Discovered

Via newscientist.com -

Astronomers have identified the smallest known black hole. The puny object weighs only 3.8 times the Sun's mass and spans just 24 kilometres across.

The black hole is believed to have formed from the collapse of a massive star when it ran out of fuel.

Astronomers are not sure what the smallest possible mass is for black holes formed this way, but they estimate that it is somewhere between 1.7 and 2.7 times the Sun's mass. Less massive objects are expected to collapse into dense neutron stars instead of black holes.

"This black hole is really pushing the limits," says Nikolai Shaposhnikov of NASA's Goddard Space Flight Center in Greenbelt, Maryland, US, who carried out the study with Lev Titarchuk, also of Goddard. "For many years, astronomers have wanted to know the smallest possible size of a black hole, and this little guy is a big step toward answering that question."

The black hole they studied is part of a binary system called XTE J1650-500, where the black hole and an ordinary star orbit around each other. Gas stolen from the ordinary star heats up and emits X-rays as it spirals into the black hole.

Want to Drive In Manhattan? That'll Be $8, Please

Via Wired.com -

The Big Apple believes charging motorists $8 a pop to enter much of Manhattan is the best way to deal with the city's atrocious congestion, get a handle on greenhouse gas emissions and raise millions for mass transit.

The New York City Council, facing intense lobbying from Mayor Michael Bloomberg and other supporters of the idea, voted 30-20 in favor of the proposal, which must be approved by the Legislature. If lawmakers and Gov. David Paterson sign off, the plan would create a weekday "congestion zone" from 60th Street south. Cars would be charged $8 -- trucks would pay $21 -- to enter between 6 a.m. and 6 p.m.

"It is now completely clear that congestion pricing has the strong backing of the people of New York City," the mayor said after what was one of the closest council votes of his administration.

Well, not all the people.

Lawmakers from the city's outer boroughs and suburbs complained the legislation essentially taxes residents to move around in their own city. They also complained it punishes commuters by making them subsidize subways and buses they don't use.

"This plan, while wrapped up in three incredibly important and laudable goals, is designed to deter people from coming into a part of the city if they can't afford it," Lewis A. Fidler, a Brooklyn city councilman who opposed the plan, told The New York Times. "What's next? We're going to charge a user fee to come into Central Park because it's too crowded?"

The state legislature must approve the proposal by April 7 if the state is to receive $354 million in mass transit aid from the U.S. Department of Transportation. Proponents say the congestion fee would raise $491 million to improve and maintain a mass transit system that carries 4.5 million riders each day, according to Bloomberg.com.

New York's proposal is modeled on a plan London adopted in 2003 to charge motorists about $8 to enter a "congestion zone" that covers eight square miles. London has since gone further, approving a fee of about $49 on luxury vehicles and SUVs entering the congestion zone.

Pirate Bay: Labels Can "Go Screw Themselves"

Via arstechnica.com -

The four main backers of The Pirate Bay could be personally on the hook for 15 million kroner ($2.5 million) after record labels requested the amount in damages from the Stockholm District Court yesterday. Gottfrid Warg of The Pirate Bay responded with the elegance that always characterizes the group's pronouncements, telling Sweden's The Local that "the record companies can go screw themselves."

The proposed damages are based on 24 albums, though the founders are also charged with helping to violate copyright on nine films and four computer games.

The Pirate Bay has long made the argument that it is merely a search engine and hosts no infringing content of its own. Given that reality, it would seem that putting the responsibility on those who actually download infringing material would be the sensible alternative, but The Pirate Bay doesn't like that idea, either. When the Swedish government proposed a plan that would allow ISPs to turn over IP addresses of suspected file-swappers in court cases, The Pirate Bay pitched the move as "a declaration of war on Sweden's youth."

Sweden's youth apparently believe that they have a right to copies of films, music, and even textbooks authored by others. A new site called Student Bay launched late last week to host scans of copyrighted academic books. The group says that "in Sweden it is claimed that education is free," according to a translation in The Local. "Despite this students are forced every term to spend thousands of kronor on books necessary for their education. It is totally unreasonable."

Getting a free education and paying a few hundred dollars a year for textbooks certainly sounds like a good deal, but a representative of Sweden's academic publishing trade group says that even these numbers are often inflated. Stefan Persson told The Local, "I have every sympathy for the financial situation of students, but the costs that are often quoted surprise me. The Student Barometer puts the average student's academic literature expense at 150 kronor ($25) per month, far less than for mobile telecoms, for example."

British Imam: Non-Muslims Deserve to Be Punished

Via FoxNews -

A report posted on Islam Watch, a site run by Muslims who oppose intolerant teachings and hatred for unbelievers, exposes a prominent Islamic cleric and lawyer who support extreme punishment for non-Muslims — including killing and rape.

A question-and-answer session with Imam Abdul Makin in an East London mosque asks why Allah would tell Muslims to kill and rape innocent non-Muslims, including their wives and daughters, according to Islam Watch.

"Because non-Muslims are never innocent, they are guilty of denying Allah and his prophet," the Imam says, according to the report. "If you don't believe me, here is the legal authority, the top Muslim lawyer of Britain."

The lawyer, Anjem Choudary, backs up the Imam's position, saying that all Muslims are innocent.

"You are innocent if you are a Muslim," Choudary tells the BBC. "Then you are innocent in the eyes of God. If you are not a Muslim, then you are guilty of not believing in God."

Choudary said he would not condemn a Muslim for any action.

"As a Muslim, I must support my Muslim brothers and sisters," Choudary said. "I must have hatred to everything that is not Muslim."

-----------------------

I wish I could say that this type of stuff surprises me...but sadly, I can't say that anymore.

England has a real problem on their hands...

Packet Storm Security Pwned? Or April Fools?

Almost every link on the frontpage of Packetstormsecurity.org points to an err0r.txt file?

This file warnings of a MySQL problem and show a list users that look like a dump from a passwd file. Real?

Who knows...but the r00t user seems pretty fake to me. ;)

Strange, but it is April 1st...so anything is possible.

Happy Birthday Mozilla

Mozilla turned 10 years old on March 31st, 2008.

-------------------------

March 31, 1998 is the date that Mozilla was officially launched. It's the date the first Mozilla code became publicly available under the terms of an official open source license and a governing body for the project — the Mozilla Organization — began its public work. It's always been known in Mozilla parlance as "3/31." We'll be celebrating Mozilla's 10 year anniversary throughout 2008. Today I want to look at our first ten years, and a bit at the next ten years.

http://www.mozilla.org/

April Fools Storm Worm Attack Hits

Via PCWorld -

A new storm worm with an April Fool's Day theme is targeting the Web, according to security software firm PC Tools.

"The Storm worm gang has done it again. This time e-mails are being circulated, which are associated with the April Fool's Day theme," said PC Tools chief threat officer, Kurt Baumgartner.

The e-mail messages contain links that direct users to Web sites that contain malware. Once the files are downloaded and executed on the computer it sets a firewall exception rule and then attempts to 'phone home' using various outgoing ports.

According to Baumgartner, the packer and major sections of executable code have changed significantly, indicating that it could be another variant and AV detection for this threat is close to nonexistent.

"The most effective way users can protect against these new threats is with antimalware products that use behavioral technology. Traditional AV products, which use signature detection are simply not equipped with this behavioral technology and the threat is currently evading those users' defenses," he said.

"Always exercise caution and don't just click on random links sent to your account via e-mail. Exercise even more caution when that random link is attempting to download a file to your system," adds Baumgartner.

Laptop With Vista Attack Code Listed on eBay

Via PCWorld.com -

The winner of a recent hacking contest is offering the computer he broke into for sale on eBay, possibly with the Microsoft Vista attack code he used intact.

In a Monday listing, Shane Macaulay is selling the Fujitsu U810 laptop he won last Friday during the CanSecWest PWN 2 OWN contest. His listing claims that exploit code could probably still be extracted from the machine. Although he make no guarantees, he wrote, "My successfull [sic] exploitation of Vista SP1 remotely, is most likely still present."

"This laptop is a good case study for any forensics group/company/individual that wants to prove how cool they are, and a live example, not canned of what a typical incident responce sitchiation [sic] would look like."

Starting bid? $0.01.

Macaulay, a researcher with the Security Objectives consultancy, claims that his Adobe Flash exploit will affect 90 percent of computers worldwide.

...

One hacker who knows Macaulay said that the April 1 listing is "a bit coincidental," but that he may not be worried about forfeiting the $5,000 in prize money TippingPoint paid him for his hack. "He makes good money," said Marc Maiffret, an independent security researcher, in an instant message interview. "It's all just funny to him."

If he's not playing an April Fool's joke, Macaulay may be running afoul of both the PWN 2 OWN contest rules, which prohibit disclosure of bug information prior to a patch. He may also be violating eBay's user agreement, which say that users may not "distribute viruses or any other technologies that may harm eBay, or the interests or property of eBay users."

Macaulay had some funny answers when asked about these issues.

On the eBay terms of service problem, he said that he knew "some highups," at the company and was "confident, when I speak with eBay they will grant me a waiver."

And does TippingPoint know about what he's doing? "I believe at some level," he answered. "I'm sure things might change as the word percolates to the executives. Maybe I shouldn't have sold the [TippingPoint] bag with the laptop!!"

----------------------

The attack code isn't for Microsoft Vista, it is for Adobe Flash. It was used against a Vista machine, but it most likely could have been used against Linux or OS X as well.

So calling this "Microsoft Vista attack code" is a little misleading I believe.

This is a 3rd party cross-platform application vulnerability, an application which happens to be installed on almost all the computers in the world.

Real Player rmoc3260.dll ActiveX Control Remote Code Execution Exploit

written by e.b.

Tested on Windows XP SP2(fully patched) English, IE6, rmoc3260.dll version 6.0.10.45

Thanks to h.d.m. and the Metasploit crew

----------------------------------

http://www.milw0rm.com/exploits/5332

Exploit contains two shellcode functions.

The default function launches calc.exe, but the other binds a shell on port 4444.

Hence the thanks to the Metasploit crew.

Does anyone know if that rmoc3260.dll v6.0.10.45 is from an older unpatched version of Real Player or from the new version just released?

Apple Sued Over 'Inflated' iMac Claims

Via The Channel Register -

Apple, the world's most successful brand, is being sued by a Los Angeles law firm for "deceptively" marketing the new 20-inch iMac

Kabateck Brown Kellner says the monitor is "vastly inferior to the previous generation it replaced", not that you would know it from Apple's "grossly inflated" claims.

According to the law firm, Apple told consumers both the 20-inch and 24-inch iMacs displayed "millions of colors at all resolutions":
Indeed, the new 24-inch iMacs display 16,777,216 colors on 8-bit, in-plane switching (IPS) screens, as did the previous generation of 20-inch iMacs. But the new 20-inch iMac monitors do not even come close, displaying 98% fewer colors (262,144).

While Apple describes the display of both the 24-inch and 20-inch iMacs as though they were interchangeable, the monitors in each are of radically different technology. The 20-inch iMacs feature 6-bit twisted nematic film (TN) LCD screens, the least expensive of its type.

The 20-inch iMac's TN screens have a narrower viewing angle, less color depth, less color accuracy and are more susceptible to washout across the screen.

Why does hundreds of thousands, rather than millions, of colours merit a class action? According to KBK, the new 20-inch iMac, the one launched in August 2007, is:

particularly ill-suited to editing photographs because of the display's limited color potential and the distorting effect of the color simulation processes.

KBK has filed suit in U.S. District Court, Northern District of California in San Jose - in Apple's home turf. Boy are these guys tough, riding shotgun into Silicon Valley, where Apple is a religion, and Steve Jobs is God.

Now for some pleasantly cheap shots from Brian Kabateck of KBK:

Apple is squeezing more profits for itself by using cheap screens and its customers are unwittingly paying the price.

Apple is duping its customers into thinking they're buying 'new and improved' when in fact they're getting stuck with 'new and inferior. Beneath Apple's 'good guy' image is a corporation that takes advantage of its customers. Our goal is to help those customers who were deceived and make sure Apple tells the truth in the future."

All very philanthropic, especially coming from a firm that has trousered $750m, some of it for clients, in plaintiff litigation.

KBK's press release is here.

-------------------------------------

For a company that can do no wrong...Apple doesn't appear to be getting a lot of things right.

Personally, I don't so much care that it is Apple getting suited.

I believe that if a company is selling a product (to make money off customers) and it make claims about said product...the product damn well better have the stated features - little feature, big feature, Apple, Cisco, Dell or HP.

If it doesn't, then it is illegal...

Google Adds Gmail Custom Time Feature






-----------------


April Fools? Perhaps..lol