Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Thursday, April 17, 2008
SQL Injection: Oklahoma Dept of Corrections
One of the cardinal rules of computer programming is to never trust your input. This holds especially true when your input comes from users, and even more so when it comes from the anonymous, general public. Apparently, the developers at Oklahoma’s Department of Corrections slept through that day in computer science class, and even managed to skip all of Common Sense 101. You see, not only did they trust anonymous user input on their public-facing website, but they blindly executed it and displayed whatever came back.
The result of this negligently bad coding has some rather serious consequences: the names, addresses, and social security numbers of tens of thousands of Oklahoma residents were made available to the general public for a period of at least three years. Up until yesterday, April 13 2008, anyone with a web browser and the knowledge from Chapter One of SQL For Dummies could have easily accessed – and possibly, changed – any data within the DOC’s databases.
Wednesday, April 16, 2008
Malicious Microprocessor Opens Doors for Attack
For years, hackers have focused on finding bugs in computer software that give them unauthorized access to computer systems, but now there's another way to break in: Hack the microprocessor.
On Tuesday, researchers at the University of Illinois at Urbana-Champaign demonstrated how they altered a computer chip to grant attackers back-door access to a computer. It would take a lot of work to make this attack succeed in the real world, but it would be virtually undetectable.
To launch its attack, the team used a special programmable processor running the Linux operating system. The chip was programmed to inject malicious firmware into the chip's memory, which then allows an attacker to log into the machine as if he were a legitimate user. To reprogram the chip, researchers needed to alter only a tiny fraction of the processor circuits. They changed 1,341 logic gates on a chip that has more than 1 million of these gates in total, said Samuel King, an assistant professor in the university's computer science department.
"This is like the ultimate back door," said King. "There were no software bugs exploited."
King demonstrated the attack on Tuesday at the Usenix Workshop on Large-Scale Exploits and Emergent Threats, a conference for security researchers held in San Francisco.
His team was able to add the back door by reprogramming a small number of the circuits on a LEON processor running the Linux operating system. These programmable chips are based on the same Sparc design that is used in Sun's midrange and high-end servers. They are not widely used, but have been deployed in systems used by the International Space Station.
In order to hack into the system, King first sent it a specially crafted network packet that instructed the processor to launch the malicious firmware. Then, using a special login password, King was able to gain access to the Linux system. "From the software's perspective, the packet gets dropped... and yet I have full and complete access to this underlying system that I just compromised," King said.
Russian Gov Enacts Byzantine WiFi Regulations
It is often said that the opposite of progress is paperwork. The incomprehensibly self-defeating wastefulness and inefficiency of the legislatosaurus never ceases to depress me, but for once, America's idiocracy has been outdumbed by a Russian government agency which has proposed one of the most breathtakingly inane policies that I have ever had the misfortune of witnessing: mandatory registration of all WiFi devices.
According to Fontanka.ru, a Russian news source, the government agency responsible for regulating mass media, communications, and cultural protection has stated that users will have to register every WiFi-enabled device with the government and receive special permission in order to use the hardware. The agency says that registration could take as long as ten days for standard devices like PDAs and laptops and that it intends to confiscate devices that are used without registration. Users who wish to operate a wireless access point or WiFi-enabled home router are expected to go through an even more onerous process that will involve submitting documentation and obtaining a license. In certain regions, like Moscow and St. Petersburg, users will also have to receive special approval from the Federal Security Service.
The policy, which was explained to Fontanka.ru by the Russian agency's deputy director Vladimir Karpov, could reverse existing policies like a 2004 government panel decision to provide blanket permission for indoor wireless access point operation and a 2007 policy which allowed use of mobile WiFi devices without registration. According to The Other Russia, which provides an overview of the Fontanka.ru article in English as well as some additional details, the Russian government agency which is responsible for issuing the new policy was created when the Russian media and telecommunications regulatory bodies were merged last year.
The policy would likely be impossible to enforce and some question whether the government agency even has the authority to enforce it. WiFi technology is a powerful enabler of mobile connectivity and technological innovation. If regulatory policies broadly erode the availability of connectivity, the results could be disastrous for Russia's tech-savvy population. The policy reflects an abysmal understanding of WiFi's pervasiveness and utility and seems like arbitrary bureaucratic decision with no inherent purpose. Perhaps in Russia, unregulated WiFi is one of those accoutrements of capitalist imperialism that must be opposed with vigorous shoe-banging and similarly vigorous legislative action.
The Fontanka.ru article quotes an industry specialist who points out that the government agency behind the policy is run by a former metallurgic engineer who likely has no clue about many of the technical issues overseen by his organization. In this respect, Russia has much in common with the US, where lack of relevant experience often seems to be a prerequisite for public office, especially when it comes to regulating the series of tubes that make up the interwebs.
Merck Busted For Ghostwriting Vioxx Studies
Drug maker, Merck & Co., has always characterized its conduct as above board and ethically appropriate among pharmaceutical companies.
“We employ rigorous scientific methods to design, conduct, analyze, and report results of clinical trials in the development of innovative drugs and vaccines, with a focus on meeting unmet medical needs and with an ethic that puts the interests of the patient first.”
That’s what the company says in a 2002 paper titled “ The practices of Merck & Co.
But what really goes on is another story.
Authors writing in this week’s issue of The Journal of the American Medical Association (JAMA) reveal how Merck manipulated dozens of publications to promote one of its products, ironically the painkiller Vioxx (rofecoxib).
Based on internal company documents revealed in Vioxx litigation, JAMA authors uncover how the company, without disclosing it, compensated ghostwriters who aren’t even doctors, to create articles for professional journals that have the potential to influence doctors and popularize drugs prescribed to the public.
In the 250 documents reviewed by the authors, Merck employees either working by themselves or in collaboration with a medical publishing company helped create the study on Vioxx.
They would then recruit academics or leaders in the medical field to lend their name as the lead author.
For scientific review papers, Merck would outline the plan for the manuscript then ghostwriters were hired from medical publishing companies, which typically pay about $20,000 per submission to the ghostwriter.
The scientist then recruited to be the named author would be offered “honoraria” for their participation.
This review in JAMA finds that among 96 published articles, 92 percent of clinical trials disclosed Merck’s financial support. But only half disclosed Merck’s involvement in the creation of the publication or whether the author had received compensation.
MiFare RFID Crack Takes Just Seconds
The ubiquitous MiFare Classic RFID chip -- used daily by millions worldwide in access control keys, subway passes and other applications -- is even easier to crack than previously thought, according to security researchers who announced the development Tuesday at EuroCrypt, an international cryptography conference in Istanbul.
Mere seconds are all that is required to crack the chip's security -- not a few hours, as estimated last month. Karsten Nohl, a computer science graduate student and one of the masterminds behind reverse-engineering MiFare security, said in an interview that it now takes only 12 seconds to recover the key on a MiFare Classic card on an ordinary laptop.
On Monday, the Dutch government issued a final report arriving at the decisive conclusion that the chips, used by millions of citizens in the Netherlands, must be replaced. An earlier Dutch report had stated that a security breach on the MiFare cards was possible, but would be too unwieldy for the average attacker to accomplish.
"The attack is really, really cheap," Nohl said. "Before they [the Dutch government] argued that you would need expensive equipment; now we're talking a few seconds on any laptop, so anyone could do it."
Equally worrisome is that there is no need for the attacker to interact actively with the physical card itself. Passive eavesdropping suffices; the attack can take place from a distance. A passive attack from 10 meters away would take a little bit longer than an active attack, Nohl said -- about 200 seconds.
The attack works for any random number generator; it also works against the Crypto-1 cipher in the beefed-up MiFare Plus card.
Many major public transit systems around the world have made the switch from swipe cards to RFID-enabled "tap and go" cards. Switching to these RFID chips for subway passes means that anyone can potentially read a card -- even when the subway rider keeps it hidden in his pocket.
"It seems that all these wireless technologies are hyped for comfort, mostly," said Nohl. "Swiping a card is presented as cumbersome, whereas tapping a card is considered fancy and new. At the same time, these technologies are not really understood in terms of threat models."
The original announcement of the MiFare Classic chip security compromise was presented in December by Nohl and fellow researcher Henryk Plotz at the 24th Chaos Communication Congress hacker conference in Berlin.
Tuesday, April 15, 2008
New Intel on Al Qaeda's Western Recruits
On the heels of CIA Director Gen. Mike Hayden's recent "Meet the Press" appearance, in which he disclosed that Al Qaeda is recruiting and training operatives who "look western" in order to penetrate the U.S., another top spook offered a few additional scraps of information about the new threat on Friday.
"There is attention being given to finding people who can live in the west, have lived in the west, comfortably, and who can appear western, wear western clothing," Charlie Allen, chief of intelligence and analysis at the Homeland Security Department, told reporters. "I'm talking about people who are Caucasian and non-Caucasian."
Allen, who spent decades as a top CIA official, said there was "a shift in Al Qaeda's strategy" after the late 2005 assassination of Al Qaeda's external operations commander, Abu Hamza Rabia.
According to recent congressional testimony by Director of National Intelligence Mike McConnell, it only took Osama Bin Laden's fanatics a mere six months to begin bringing western converts into Pakistan's lawless tribal areas for training. The New York Daily News reported last year that top counterterror officials fear the western-looking operatives can more easily penetrate U.S. security by blending in.
"I would think that you'd believe that Al Qaeda would look to Europe and to North America for such operatives. That's something to which we're very attentive," Allen said.
He also echoed recent comments Homeland Security Secretary Michael Chertoff made to The News, that no Al Qaeda operatives are known to have crossed the southern border from Mexico into the U.S. But, he added, "We do know that going back to 2004, the southern border is something Al Qaeda senior leadership has looked at."
Al-Shabaab Welcomes U.S. Terror Designation, Threatens New Campaign of "Praiseworthy Terrorism"
The NEFA Foundation has obtained and translated a new communiqué released on April 5, 2008 by the Shabaab al-Mujahideen Movement in Somalia. The statement welcomed the recognition of Shabaab as an international terrorist organization by the U.S. government: "As we are a part of the Salafi-Jihadi Islamic trend which opposes the dominance of the crusaders and the aggression led by America, we do not find it unlikely that America would add us to the names of these other honorable men, for whom we are honored to join, at the bottom of their list.” The Shabaab also announced the beginning of a new military campaign inside Somalia under the slogan "Our Terrorism is Praiseworthy": "We swear to Allah that... we will only repeat what our late Shaykh Abu Musab al-Zarqawi once said: ‘we will not compromise on our religion, we will not change the way of jihad, and will not be satisfied with compromises. Between us and the infidels, there is only the sword of Islam.'" On February 29, 2008, the U.S. State Department designated Shabaab al-Mujahideen (a.k.a. the Mujahideen Youth Movement) as a Foreign Terrorist Organization and as a Specially Designated Global Terrorist. According to the U.S. State Department, the Shabaab movement includes “a number of individuals affiliated with al-Qaida. Many of its senior leaders are believed to have trained and fought with al-Qaida in Afghanistan.”
On a related note, the NEFA Foundation is also making available video footage of the "martyrdom will" of "Abu Ayyub al-Muhajir"--an English-speaking Somali national living in Europe, who recently returned to his homeland and executed a suicide car bombing in the city of Mogadishu on behalf of Shabaab al-Mujahideen. The video can be viewed on the NEFA Foundation website.
Gas Gang Uses 'Never-Before-Seen' Device To Hack, Steal From Pumps
An elaborate organized theft ring is using a never-before-seen device to hack gas station pumps and steal unlimited amounts of gasoline in Central Florida, according to investigators in Casselberry.
At least five cars filled with members of the alleged gas-pump hackers were spotted bypassing pumps at a Hess station located on 17-92 in Casselberry late Monday.
"One of the operatives (got) out and used a computerized device to bypass the pumps so they could pump an unlimited amount of gas into the vehicles," Casselberry police Lt. Dennis Stewart said.
Stewart said the officers were noticed watching the crime.
"The group uses spotters and one of the spotters discovered the officers and went over and stuck her head in a window to determine that they were officers," Stewart said.
The woman then signaled the other vehicles, police said.
Investigators said the group scattered, jumping into their vehicles and driving in different directions.
One vehicle remained and tried to run over an officer, police said.
"He wound up striking the officer in the ribs and arm, knocking him backward," Stewart said.
Nearby officers stopped the vehicle as it left the area and arrested Chelsea Harris, 19, and Rhyeen Brinson, 25. Both were charged with felonies.
The other people at the gas station are still missing.
"We'd love to get our hands on the equipment and right now, particularly with one of our officers hit, we'd love to get our hands on the people."
The officer injured in the incident was expected to recover from his injuries.
Casselberry police said they had never seen the device or technology used to steal gasoline.
iPhone's Wi-Fi Positioning System Spoofed Using Laptop
The Wi-Fi Positioning System (WPS) used by Apple's iPhone and iPod Touch and other mobile devices can easily be supplied with false information that makes the mobile think it's somewhere other than its true location. Researchers at the Swiss Federal Institute of Technology Zürich have found that all you need is a laptop, a Wi-Fi access point transmitter and a database of Wi-Fi access point locations.
The MAC address of an active Wi-Fi access point is continuously announced. WPS works by the client detecting the MAC addresses of nearby access points and comparing the cluster of found addresses with a database of clusters referred to geographical locations. The iPhone and iPod Touch apparently make use of the Skyhook Wireless Inc database of Wi-Fi access point locations, as do Nokia Symbian-based phones and PCs equipped with Skyhook's Loki plugin.
Unlike other positioning systems such as GSM, WPS does not triangulate, but instead looks for a specific location-dependent "signature". Professor Srdjan Capkun of the Zürich research team told heise online that WPS may use received signal strength as well, but this has not been confirmed officially. High positional accuracy – claimed to be in the order of 20m – is possible in dense urban locations such as major towns, where the close proximity of numerous Wi-Fi access points results in considerable overlap of their typical 100m radius of access.
But the simplistic WPS location strategy turns out to be its Achilles heel. The Zürich researchers found that they could readily jam the channels carrying real incoming Wi-Fi MAC announcements and substitute others of their own choosing on free channels – there being 13 available channels, not all of which will be in use at any one time and location. By transmitting the MAC address cluster of a distant location, they first fooled the iPhone into thinking they were across town from their real location. However the GSM capability of the iPhone overrides its WPS location capacity, so the researchers had to jam the GSM signal using an additional jammer device before they could carry out their most dramatic demonstration – an iPhone in Zürich that thought it was near the entrance to Holland Tunnel in New York City.
The researchers found that the Apple mobiles were not the only susceptible devices. They repeated the experiment successfully using the Loki plugin on a PC. They also point out that, by transmitting a cluster of MAC addresses belonging to access points that are not in the same geographical area, the localisation algorithm in a mobile device can be confused completely, effectively denying service to the user.
GAO: Stolen U.S. Military Gear Sold on eBay, Craigslist
Stolen and sensitive U.S. military equipment, including body armor, night vision goggles, and gear to protect against nuclear or biochemical warfare, are being sold on Craigslist and eBay, a GAO report says.
The Government Accountability Office found many defense-related items for sale on Craigslist and eBay, according to the report, released last week.
After reviewing the policies and procedures for those Web sites, the GAO determined that there were few safeguards to prevent the sale of military items. Although it is not illegal to buy and sell some defense-related items in the U.S., many items are made solely for military use and are not meant for public use, the GAO said.
From January 2007 to March 2008, GAO undercover investigators were able to buy a dozen sensitive items on eBay and Craigslist to demonstrate how easy it was to obtain them, the agency said. Many of these items were stolen from the U.S. military, it said.
The items GAO investigators were able to purchase online include the following:
- Two F-14 aircraft components, including an antenna, from separate buyers on eBay. The GAO said that "F-14 components are in demand by Iran" and could be used by the Iranian military. "By making these components available to the general public, the eBay sellers provided an opportunity for these components to be purchased by an individual who could then transfer them to Iran," according to the report. "The continued ability of Iran to use its F-14s could put U.S. troops and allies at risk."
- Night vision goggles on eBay containing a sensitive component that allows U.S. service members to identify friendly fighters wearing infrared tabs on the battlefield.
- An Army combat uniform and accessories on eBay that could be used by a terrorist to pose as a U.S. service member.
- Body armor vests and small-arms protective inserts (SAPI) on eBay and Craigslist, including advanced enhanced SAPI plates used by U.S. troops in Iraq and Afghanistan.
Six College Cyber Defense Team Finalists Compete
Texas A&M University looks to defend their National Champions title against five teams when the National Collegiate Cyber Defense Competition (NCCDC) takes place April 18-20 at the Hilton San Antonio Airport Hotel. The 3rd annual NCCDC is being hosted by the University of Texas at San Antonio's Center for Infrastructure Assurance and Security (CIAS), a nationally recognized leader in cyber security education and research.
The CCDC program has grown from five participating schools in 2005 to 56 schools in 2008 with six regional competitions taking place nationwide. The 2008 national competition features the 2007 defending champions, Texas A&M University, along with Baker College of Flint, Michigan, the Community College of Baltimore County, Mt. San Antonio College of Los Angeles County, Rochester Institute of Technology, and the University of Louisville. The participants advanced to the National CCDC after winning regional competitions against opposing teams in the Southwest, Midwest, Mid-Atlantic, Southeast and West Coast Regions.
The CCDC program is sponsored in part through donations from leading businesses in the communications and information technology industries.
"AT&T has always put an emphasis on technology and education," said AT&T president, Western Region, John T. Montford. "We are proud to support the NCCDC's competition that encourages students to find new and innovative ideas that benefit companies like AT&T and partner with UTSA to work toward an ever-advancing field of network security."
Psystar's Mac Clone Still Available For Purchase
A Miami-based system integrator has changed the name of an unauthorized Mac clone it's selling through its Web site from OpenMac to Open Computer -- and was continuing to take orders for the system as of Tuesday afternoon.
One version of Psystar's Open Computer featured Apple's Leopard OS X 10.5 operating system ported onto generic PC hardware that includes an Intel (NSDQ: INTC) Core2Duo processor at 2.66 GHz, a 250 GB hard drive and an Nvidia GeForce 8600 GT graphics card.
The system is priced at $804.99. A similar, Apple-branded computer would cost more than $2,000.
Psystar appears to have changed the name of its Mac clone overnight -- perhaps in response to anticipated legal pressure from Apple. Apple's end user license agreement forbids the installation or use of Leopard on third party hardware.
Business records show that Psystar is a small company operated by Miami residents Rodolfo Pedraza and Roberto Pedraza.
On Monday, a Psystar representative who would identify himself only as "Robert" said the company is not concerned about legal action by Apple. "We're not breaking any laws," Robert insisted in a telephone interview.
Psystar may be willing to have its right to sell Mac clones tested in court, Robert implied. "What if Microsoft (NSDQ: MSFT) said you could only install Windows on Dell (Dell) computers?," he said. "What if Honda said that, after you buy their car, you could only drive it on the roads they said you could?," he added.
Robert also accused Apple of marking up the hardware on which its operating systems run by as much as 80%.
While it's doubtful a small vendor like Psystar could withstand a legal assault by Apple on its own, the company could possibly draw support from interest groups that are opposed to restrictive software licenses and patents, or even from big hardware makers that, no doubt, would themselves relish the opportunity to market a Mac clone -- if only to counter Microsoft's influence on their business.
Psystar's Web site was up and running as of Tuesday afternoon. The site was offline much of Monday as news of the company's Mac clone spread across the Internet.
Exploit the MS08-021 : Stack Overflow on GDI API
Author: Lamhtz
Date: April 14th, 2008
Usage:
Function: Generate a crafted emf file which could automatically run calc.exe in Win2kSP4 CHS Version with MS07-046 patched but no MS08-021 is installed. In Windows XP SP2, explorer.exe will crashed but calc will not be run.
http://www.milw0rm.com/exploits/5442
Bot breaks Hotmail's CAPTCHA in 6 seconds
A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday.
Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) within six seconds, on average. CAPTCHA is the name given to the distorted, scrambled characters that many Web services require users to decipher and type in to create a new account; the tests are meant to block automated account registration by spammers and malware authors.
The bot, Hubbard acknowledged, is similar to one Websense uncovered in February.
"In the past, though, it was kind of questionable whether the CAPTCHA breaking was automated," Hubbard said Friday, noting that there had been some evidence that spammers were paying people to decode and type in the CAPTCHA characters. "But the bot's breaking [CAPTCHA] in six seconds, so it's definitely automated."
In a long post to the Websense blog Thursday, Sumeet Prasad -- "our CAPTCHA expert," said Hubbard -- provided technical details of how the bot automatically registers Live Hotmail accounts and then immediately begins using those accounts to spew spam.
The bot's total response time -- how long it takes the program to grab a CAPTCHA image, analyze it and return with the correct code -- is considerably shorter than that of earlier such bots, said Prasad in the blog.
One in every eight to 10 attempts to create a Live Hotmail account is successful, added Prasad, meaning that the success rate is 10% to 15%. However, the rate is actually meaningless, said Hubbard, since the bot will continue to try to create accounts using a predetermined list of account names until they're all registered.
E-Passport Hacker Designs RFID Security Tool
The team that produced the RFDump research/hacker tool for cloning and altering data stored on radio-frequency ID tags has now come out with a product to thwart RFID hackers.
German security researcher Lukas Grunwald, who made headlines two years ago for uncovering security vulnerabilities in new electronic passports being adopted by the U.S. and other countries, created RFDump with colleague Boris Wolf in 2004.
Now the two have created RF-Wall (shown on the lower shelf in the picture at right) to help thwart RFID fraud and attacks against e-passports, electronic access cards and payment cards -- such as the Mifare Classic card that is used in the London Underground and which security researchers recently cracked.
The device, which Grunwald and Wolf are producing for their new California-based company NeoCatena, is a hybrid firewall and intrusion-detection system that sits between an RFID reader and its back-end system. It's designed to detect counterfeit and cloned RFID chips and prevent an attacker from injecting malware into a back-end system with a rogue RFID chip. They'll be debuting the device this week at the RFID Journal Live conference in Las Vegas but gave me a demonstration of it this weekend.
The box can be loaded with virus signatures to detect known types of attacks and uses heuristics to detect other malicious activity, such as generic SQL-injection attacks (such as the one that appears in the screenshot above right). The device can be restricted to read only RFID cards that have specific serial numbers and reject all others. It also can be used to digitally sign chips so that any chips that are altered after being issued are rejected by the RFID reader. The system uses the HMAC algorithm for the digital signature. Grunwald and Wolf hold a patent on the use of HMAC with RFID technology.
Monday, April 14, 2008
Williamson County Woman Jailed for Cyber Fraud
A Williamson County woman is in jail after police said she stole more than $213,000 in fraudulent reimbursement claims.
Lauri Jean Arrington worked as a software installer for a firm hired by Cadbury Adams. The company said Arrington installed a program to submit reimbursement.
Arrington then hacked the program and directed false claim reimbursements to two personal bank accounts in Williamson County.
Police said Arrington stole the money over three years, from March 2005 to March 2008.
She faces three felony charges.
Sunday, April 13, 2008
E-spionage: Phishing for Classified Data
The e-mail message addressed to a Booz Allen Hamilton executive was mundane—a shopping list sent over by the Pentagon of weaponry India wanted to buy. But the missive turned out to be a brilliant fake. Lurking beneath the description of aircraft, engines, and radar equipment was an insidious piece of computer code known as "Poison Ivy" designed to suck sensitive data out of the $4 billion consulting firm's computer network.
The Pentagon hadn't sent the e-mail at all. Its origin is unknown, but the message traveled through Korea on its way to Booz Allen. Its authors knew enough about the "sender" and "recipient" to craft a message unlikely to arouse suspicion. Had the Booz Allen executive clicked on the attachment, his every keystroke would have been reported back to a mysterious master at the Internet address cybersyndrome.3322.org, which is registered through an obscure company headquartered on the banks of China's Yangtze River.
The U.S. government, and its sprawl of defense contractors, have been the victims of an unprecedented rash of similar cyber attacks over the last two years, say current and former U.S. government officials. "It's espionage on a massive scale," says Paul B. Kurtz, a former high-ranking national security official. Government agencies reported 12,986 cyber security incidents to the U.S. Homeland Security Dept. last fiscal year, triple the number from two years earlier. Incursions on the military's networks were up 55% last year, says Lieutenant General Charles E. Croom, head of the Pentagon's Joint Task Force for Global Network Operations. Private targets like Booz Allen are just as vulnerable and pose just as much potential security risk. "They have our information on their networks. They're building our weapon systems. You wouldn't want that in enemy hands," Croom says. Cyber attackers "are not denying, disrupting, or destroying operations—yet. But that doesn't mean they don't have the capability."
Google Shares its Security Secrets
Google is offering security professionals a look into its security systems.
Scott Petry, director of Google's Enterprise and founder of security firm Postini, explained to attendees at the RSA conference how the company handles constant pressure and scrutiny from attackers.
"Google is a very very high-value target," Petry noted.
"If you have bad intentions and want to get a reputation, hacking Google is the best way to get credibility on the streets."
In order to keep its products safe, Google has adopted a philosophy of 'security as a cultural value'. The programme includes mandatory security training for developers, a set of in-house security libraries, and code reviews both by Google developers and outside security researchers.
"The most important thing that our security team does is educate," Petry explained.
"Educating people is the most important thing a security professional can do. "
Petry contended that in an age where both users and companies are increasingly relying on outside services and applications, it is becoming nearly impossible to fully lock-down a company.
"IT is largely fighting yesterday's battle," he said, in reference to the policy of trying to restrict all user access.
"Start saying okay, if these things are going to happen, do an assessment to try and bound the risk."
Petry noted that in addition to educating its employees, the company also implements software 'guard rails', which warn users when potentially risky actions are taken and later logs them for administrators to archive.
For software developers, Petry also suggested taking a 'neighbourhood watch', approach to vulnerability disclosure. For Google, this means sharing more information with researchers and trusting them to do the right thing with their discoveries.
"If you find a vulnerability, we ask that you share it with us. If you share it with us, we will respond to you with a time we will fix that hole," explained Petry.
"If we do so, that is our responsible response, please don't disclose [the vulnerability]."
That philosophy, combined with a policy of crediting all researchers who report flaws, has been very successful for Google, said Petry.
---------------------------
Security training for developers & code reviews from third-party security vendors.
No secret there, but it works....and it is always shocking to find large corporations that don't take these simple yet effective steps to secure their products and environments.
Basically PCI v1.1 was worded to encourage companies to do code reviews....but most want to ignore the core problems and install loads of application firewalls.
IBM Research Spins 'Racetrack' Nano-Magnetic Memory
A next-generation nonvolatile memory dubbed "racetrack" is expected to initially replace flash memory and eventually hard-disk drives, according to IBM (NYSE: IBM) Corp. fellow Stuart Parkin of its Almaden Research Center (San Jose, Calif.)
Using spintronics--the storage of bits generated by the magnetic spin of electrons rather than their charge--a proof-of-concept shift register was recently demonstrated by IBM. The prototype encodes bits into the magnetic domain walls along the length of a silicon nanowire, or racetrack. IBM uses "massless motion" to move the magnetic domain walls along the nanowire for the storage and retrieval of information.
"We have now demonstrated a current-controlled, domain-wall, shift register which is the fundamental, underlying technology for racetrack memory," said Parkin. "We use current pulses to move a series of domain walls along a nanowire, which is not possible to do with magnetic fields."
IBM's goal, based on spintronic patents filed as early as 2004, is to use the same square micron that currently houses a single SRAM memory bit, or 10 flash bits, and drill down into the third dimension to store spin-polarized bits on a sunken racetrack-shaped magnetic nanowire. Using an area of silicon 1 micron wide and 10 microns high, IBM said its first-generation racetrack would store 10 bits compared to one, thereby replacing flash memory. Eventually, it could store 100 bits in the same area, which is dense enough to replace hard-disk drives.
"Racetrack is essentially the third turn of the crank of this new field of engineering called spintronics," said Parkin. "In current solid-state memory devices you store and control the flow of electrical charge. Here, we store and control the flow of the spin of an electron."
Electronic Voting Experts Tell Vendors to Work with Researchers
Hackers finding flaws, vendors reacting with threats: The relationships between security researchers and voting machine makers resemble the early days of the PC industry and that's not good, e-voting experts said at the RSA Security Conference on Thursday.
Computer scientists and academic security researchers have managed to find numerous and serious holes in the security of electronic voting systems in the past decade, despite the assurances of voting system makers that their machines are secure. It's no surprise then that rather than fostering a partnership between the hackers and the vendors -- as Microsoft managed to do over the past decade -- voting machine makers continue to be hostile to those that find vulnerabilities. That lack of a relationship has to change, a panel of five electronic voting experts told attendees.
"There is so much distrust between the academic community and the vendor community, that no one is working together," said Alec Yasinsac, associate professor of computer science at Florida State University. "I think it is essential for the vendor community to step up and engage the academic community."
A major issue with most electronic voting machines is that there is no way to do a software-independent audit of the election results. In the 2006 midterm elections, many states took extra security precautions after researchers found that Diebold's election systems contained a serious flaw. Another election system failure may have resulted in a loss for the Democratic challenger in a contest for one of Florida's seats in the U.S. House of Representatives, when the configuration of the electronic ballot likely resulted in a large number of people in a Democratic-leaning county failing to vote.
Given their history, vendors and researchers have their work cut out for them in creating a amicable relationship, said panelist David Wagner, an associate professor of computer science at the University of California at Berkeley.
"Voting system vendors are, today, where Microsoft was ten years ago," Wagner said.
And for Microsoft, it required a strong commitment from its CEO Bill Gates and hundreds of millions of dollars to better secure its software.
Friebet - Attacking Your Backend Database from Your Backyard
Just a month ago, we blogged about massive security incidents, relating to SQL injection attacks, that insert iframe links to remote sites that host exploit scripts and malware. Recently, we discovered the Fribet trojan, where the author was riding on both the success of such attacks and the controversy of the Tibet issue. The trojan was discovered on Pro-Tibet sites that were possibly hijacked to host Exploit-MS07-004, which appear to be specifically crafted.
When visitors of the pro-Tibet websites are infected, the Fribet trojan provides remote control and monitoring functions such as creating new files or folders, starting or terminating processes, and sending/receiving additional malware. Additionally, the Fribet trojan loads the “SQL Native Client” ODBC library, and is designed to receive arbitrary SQL statements from a command and control server. In turn, the ODBC library provides the functionality to Fribet to bind SQL connections and run arbitrary SQL commands from the victim machine(s). At the time of our research, the command and control server was not sending us commands. However, our reverse engineering of the malicious code shows it is more than capable of the following:
- Bind and connect to local or remote databases from the victim machine
- Query and steal data from local or remote databases
- Insert arbitrary data into local or remote databases, including web data such as hosting a web exploit
The attacker still needs to find out the information required to connect the database such as DSN, hostname, database name, User and Password, however, that information can be collected via other monitoring functions of Fribet, and it can also enumerate weak and default values.
This trojan apparently can be used as an alternate to SQL Injection attacks, but in a more direct way. Even the administrators of secure web sites, protected against common SQL injection attacks, should ensure database backends are equally secure to defend against such a penetration vector.
----------------------------
Clearly, this is a trojan designed to attack corporate users....
Researchers Uncover Information Black Holes Across the Internet
The reason why you cannot reach a specific web site at any given time can be very simple. Server and hosting issues, maintenance or the plain fact that a site has been discontinued are the most likely explanations why a site just won’t load. But there is another, more mysterious possibility: Black holes. A team at the University of Washington (UW) has begun mapping scenarios where information packets on the Internet simply disappear.
"There's an assumption that if you have a working Internet connection then you have access to all of the Internet," said Ethan Katz-Bassett, a UW doctoral student in computer science and engineering. "We found that's not the case."
Katz-Bassett has been working on a project called Hubble, a system that apparently is able to track what he refers to as information black holes. These are situations where a path between two computers does exist, but messages - a request to visit a Web site or an outgoing e-mail - get lost along the way. Katz-Bassett has published a Hubble map that enables users to monitor such black holes worldwide or simply type in a network address to check its status.
To determine a network status, Hubble sends test messages “around the world” to look for computers that can be reached from some but not the entire Internet, a situation that is described as “partial reachability”. Katz-Bassett said that short communication blips are ignored. However, if a problem surfaces in two consecutive 15-minute trials, it is listed as a “problem”. The research team found that more than 7% of computers worldwide experienced this type of error at least once during a three-week period in fall of 2007.
"When we started this project, we really didn't expect to find so many problems," said Arvind Krishnamurthy, a UW research assistant professor of computer science and engineering and Katz-Bassett's doctoral adviser. "We were very surprised by the results we got."
----------------------
Very interesting....
Saturday, April 12, 2008
Next Version of PCI DSS Due in September
PCI Security Standards Council General Manager Bob Russo said merchants can expect the next revision to the Payment Card Industry Data Security Standard in September.
"I can't really tell you if it's going to be a rev, or a new version number. In my mind, it doesn't really matter if it's a 1.2 or a 2.0; anything that gets changed is something you've got to address," Russo said. "It won't be anything too drastic. It will be based on input we've gotten over the last year and a half from all of our stakeholders."
Russo said some of the areas that will be tweaked or clarified will be around wireless implementations, application security and pre-authorization.
Russo is attending RSA Conference 2008, where thousands of IT security professionals have gathered this week. PCI and compliance issues are among top concerns of conference attendees.
Russo said that the PCI standard lives on a two-year lifecycle, and the next version comes due in September. A beta version of the standard will be released in August to the council's 500 participating organizations, as well as all of the council's qualified security assessors for feedback. They'll have 30-45 days to look it over for a "sanity check," Russo said. "It's a pretty good checks-and-balances system."
Russo said that additional guidance and clarification will be available in May for requirement 6.6, which moves from best practice to mandatory on June 30. PCI 6.6 has been the subject of some confusion for merchants trying to interpret how it's written. . The section, which falls under the main heading of developing and maintaining secure systems and applications, covers the security of Web-facing applications. As of June 30, it will mandate that Web apps be protected against known attacks by either having custom code reviewed by a third party, or by installing an application-layer firewall in front of a Web app.
"There are guidance documents coming out that will clarify a lot of this stuff before June," Russo said.
The council recently posted a new document on its site called Navigating the DSS, which goes through each of the requirements in detail, explaining the intent and how requirements can be met.
The confusion over 6.6 rests in the either-or nature of the wording.
"Personally, I'd love to see everyone go through on OWASP-based source-code review, but certainly, that's not going to happen," Russo said, referring to the expensive and time-consuming process of manual code reviews. "So the application firewall is probably the best thing to do, but there needs to be some clarification around what it needs to do. That clarification is coming; that's been the biggest question."
Friday, April 11, 2008
IBM: Application-Specific Attacks - Leveraging the ActionScript Virtual Machine
The following case study describes a unique exploitation scenario using a recently disclosed flash vulnerability that was reported to Adobe by IBM. At first the vulnerability seemed to offer limited exploitation options, but further analysis uncovered an application-specific attack that results in reliable, consistent exploitation. Achieving the same exploitation with more conventional methods is unlikely. The technique presented leverages functionality provided by the ActionScript Virtual Machine – an integral part of Adobe Flash Player. Further, it will be shown that the vulnerability can be successfully exploited without leaving telltale signs, such as a browser crash following the attack.
Although this document deals specifically with the Win32/intel platform, similar attacks can most likely be carried out on the many other platforms flash is available for. In particular, some of the methodology discussed might be useful for constructing a robust exploit on Unix platforms as well as several embedded platforms. Understanding the specific scenarios used to exploit memory corruption vulnerabilities will help improve protection strategies.
----------------------------
By Mark Dowd
X-Force Researcher IBM Internet Security Systems
http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf
Six Pirates Captured in Hijacking of French Yacht Off Somalia
French officials on Friday said six pirates have been captured in connection with a Somali hijacking.
Pirates earlier had freed 30 hostages held aboard a French tourist yacht off Somalia's coast for the past week, French President Nicolas Sarkozy said Friday.
In a statement, Sarkozy thanked the French army and other French agencies "that allowed a quick end" to the hostage-taking. The statement did not elaborate on the role of the French military, but said the hostages were freed "without incident."
The statement did not say when the hostages were released or where they were. Foreign Minister Bernard Kouchner said France would organize the hostages' return "as soon as possible" and welcomed the "happy ending" to the standoff.
Sarkozy will meet the families of the hostages in Paris on Friday afternoon.
Pirates seized the yacht, called Le Ponant, in the Gulf of Aden on April 4. It was carrying 30 crew members, including 22 French citizens and six citizens of the Philippines.
Does The Future Hold an Algae-Powered Bimmer?
Independent tests conducted by engineers at the U.S. Department of Energy's (DOE) Argonne National Laboratory on the mono-fueled version of the BMW Hydrogen 7 prototype have found that the car's hydrogen-powered engine surpasses the super-ultra low-emission vehicle (SULEV) level, the most stringent emissions performance standard to date.
"The BMW Hydrogen 7's emissions were only a fraction of SULEV level, making it one of the lowest emitting combustion engine vehicles that have been manufactured," says Thomas Wallner, a mechanical engineer who leads Argonne's hydrogen vehicle testing activities.
"Moreover, the car's engine actively cleans the air. Argonne's testing shows that the Hydrogen 7's 12-cylinder engine actually shows emissions levels that, for certain components, are cleaner than the ambient air that comes into the car's engine." It was not an easy task to measure the Hydrogen 7's emissions. "A gross polluter is easy to measure, but the cleaner the car the harder it is to test," says Don Hillebrand, director of Argonne's Center for Transportation Research.
"Most labs test at the SULEV level. Argonne's vehicle testing facilities are unique in that they are able to detect even trace levels of emissions. In this case, it was near-zero emissions."
After an extensive evaluation by BMW, "Argonne's Advanced Powertrain Research Facility was found to be the only public test facility in North America capable of testing hydrogen vehicles at these low emissions levels," says BMW's Wolfgang Thiel, manager, operating support emissions analysis. "Zero is a very small precise number—we are pushing the boundaries of emissions testing."
BMW has put the bi-fueled hydrogen model into limited series production. Although the vehicle is not yet available for sale to the general public, it is being made available to "influential public figures," whose use demonstrate a new era in clean energy, BMW has said. In the meantime, the greatest challenge to widespread use of hydrogen cars is the limited number of hydrogen refueling stations.
Scientists at U.S. Dept. of Energy's Argonne National Laboratory are looking for an alternative to fossil fuels by working to chemically manipulate algae for production of the next generation of renewable fuels—hydrogen gas. "We believe there is a fundamental advantage in looking at the production of hydrogen by photosynthesis as a renewable fuel," senior chemist David Tiede says.
"Right now, ethanol is being produced from corn, but generating ethanol from corn is a thermodynamically much more inefficient process." Some varieties of algae, a kind of unicellular plant, contain an enzyme called hydrogenase that can create small amounts of hydrogen gas.
Tiede said many believe this is used by nature as a way to get rid of excess reducing equivalents that are produced under high light conditions, but there is little benefit to the plant. Tiede and his group are trying to find a way to take the part of the enzyme that creates the gas and introduce it into the photosynthesis process. The result would be a large amount of hydrogen gas, possibly on par with the amount of oxygen created.
"Biology can do it, but it's making it do it at 5-10% yield that's the problem," Tiede says. "What we would like to do is take that catalyst out of hydrogenase and put it into the photosynthetic protein framework. We are fortunate to have Professor Thomas Rauchfuss as a collaborator from the Univ. of Illinois at Champaign-Urbana who is an expert on the synthesis of hydrogenase active site mimics."
Algae has several benefits over corn in fuel production. It can be grown in a closed system almost anywhere, including deserts or even rooftops, and there is no competition for food or fertile soil. Algae is also easier to harvest because it has no roots or fruit and grows dispersed in water. "If you have terrestrial plants like corn, you are restricted to where you could grow them," Tiede says.
"There is a problem now with biofuel crops competing with food crops because they are both using the same space. Algae provide an alternative, which can be grown in a closed photobioreactor analogous to a microbial fermentor that you could move any place." Tiede admitted the research is its beginning phases, but he is confident in his team and their research goals. The next step is to create a way to attach the catalytic enzyme to the molecule.
------------------
http://www.youtube.com/watch?v=uxoFSxM8o8k
RSA: Homeland Security Secretary Outlines Gov Cybersecurity Plans
At RSA 2008 in San Francisco, Secretary of the U.S. Department of Homeland Security Michael Chertoff discusses a new directive focusing on an early warning system to identify cyberattacks before they start.
http://news.zdnet.com/2422-13568_22-196726.html
----------------------------
For those that don't keep up with US government security, Einstein is a new intrusion detection and analysis program that the government plans to install on all ports of entrance into the government network.
While, the steps outlined by Secretary Chertoff are very sensible...most major corporations are ahead of the government.
Given the size of the government network, this project is a huge undertaking...but it is a necessary step and should provide a strong foundation to build upon.
Thursday, April 10, 2008
Dish Network Tells Court News Corp Unit Hacked It
Hackers hired by a News Corp unit stole and posted data that allowed free access to Dish Network's satellite television service, the company said, in a corporate spying trial against its rival that could be worth hundreds of millions of dollars.
Dubbed the "Black Hat Team," the computer whizzes flooded the market with smart cards that allowed free satellite TV access, a lawyer for Dish said on Wednesday. The suit was brought by EchoStar Communications which later split into two companies, Dish and EchoStar Corp.
A lawyer for News Corps's NDS Group denied that the company engaged in spying, saying during opening statements in the trial that it was instead engaged in reverse engineering by obtaining the codes and were monitoring piracy.
"Because this is a competitive business, NDS also monitors competitors," NDS attorney Richard Stone told jurors. "NDS has done nothing to illegally harm or damage EchoStar. All NDS has done is compete hard and fair in the marketplace."
Dish is suing NDS and NDS Americas in a corporate espionage trial that U.S. District Judge David Carter said could bring an award of "hundreds of millions or perhaps billions."
The potential damages are based on claims of lost revenue and the cost of fixing the compromised system.
"(NDS) came up with a plan - take these hackers off the streets and turn them on the competitors," Dish's lead attorney, Wade Welch, told the jury. "They called it the Black Hat Team."
NDS, which provides encryption technology to a global satellite empire that includes News Corp's DirecTV in the United States, "made the calculated decision to hire the worst and most well-known satellite pirates and hackers in the world in an effort to establish and maintain control ... over its competitors' technology" EchoStar claims in its lawsuit.
The spying allegedly began in 1998 when DirecTV was constantly getting hacked and was debating whether to leave NDS and sign on with EchoStar's superior system, Welch said.
Dish is claiming copyright violation, conspiracy, and piracy in a case that is expected to last a month and produce testimony from hackers and top company officials from as far away as Israel, Europe, Switzerland and Canada.
Experts Hack Power Grid in No Time
Cracking a power company network and gaining access that could shut down the grid is simple, a security expert told an RSA audience, and he has done so in less than a day.
Ira Winkler, a penetration-testing consultant, says he and a team of other experts took a day to set up attack tools they needed then launched their attack, which paired social engineering with corrupting browsers on a power company's desktops. By the end of a full day of the attack, they had taken over several machines, giving the team the ability to hack into the control network overseeing power production and distribution.
Winkler says he and his team were hired by the power company, which he would not name, to test the security of its network and the power grid it oversees. He would not say when the test was done, but referred to the timeframe as "now." The company called off the test after the team took over the machines.
"We had to shut down within hours," Winkler says, "because it was working too well. We more than proved that they were royally screwed." In addition to consulting, Winkler is author of the books Spies Among Us and Zen and the Art of Information Security.
Espionage Against Pro-Tibet Groups, Others, Spurred Microsoft Patches
Computer intruders targeting pro-Tibetan groups, U.S. defense contractors and government agencies slipped in through previously unknown security holes in Microsoft Office, prompting Microsoft to issue a flurry of patches to the popular software suite in 2006 and 2007, according to computer security experts.
These attacks, which appeared to have originated in China, began in early 2006 when the attackers started sending e-mails to victims with booby-trapped Word documents and Excel spreadsheets attached.
"We are seeing more and more spying done with Trojans, a shift that has happened in the last two years," Mikko Hyppönen, the chief research officer for software security vendor F-Secure, told RSA conference attendees Thursday morning.
The Pentagon and pro-Tibet groups have previously acknowledged the intrusions, but Hyppönen is the first to link the cyber espionage to a series of patches that Microsoft pushed out without explanation. Microsoft did not immediately reply to a request for comment.
Hyppönen's colleague Patrik Runald notes that from 2005 through early 2006, Microsoft issued few patches for its Office suite. But soon after there was an explosion of patches for critical bugs that could be used to infect a computer, including a record 26 patches in October, 2006, that fixed four critical bugs in Microsoft Office applications.
Those fixes, Runald says, appeared contemporaneously with the rise of targeted attacks on defense companies, nonprofits and government agencies. "They now have an incentive to begin looking for bugs and exploiting them," Runald said. "Bad guys are finding these things fast."
The attackers relied on e-mails tempting the victim to open the attachments, in some cases by presenting them as résumés from job seekers.
But when the target opened the attachment, the application would usually crash, while the embedded code covertly installed a keylogger and data-stealing software that scooped up documents anywhere on the organization's network to which the user had access.
The malware then forwards the stolen information to services called DNS bouncers in China, such as 8800.org, that attackers can use to obfuscate and rapidly change where stolen documents or passwords are sent. Finally, the code opens up what looks to be a legitimate document, in the hopes that the target won't know his or her computer was just infected.
The espionage was highly successful, according to Hyppönen. One multi-billion-dollar defense contractor who went to F-Secure for help found that a single compromised Windows box had been secretly siphoning information to a server in mainland China for 18 months.
"Most attacks go unnoticed and targets don't know they are hit," Hyppönen said.
Hyppönen won't declare that the espionage is the work of the Chinese government or hackers loyal to it, though all the evidence points that way.
"Is it the Chinese?," Hyppönen asked. "It sure looks like it but it could be a smokescreen. We don't know."
Dark Websites and Black PR
By definition, a dark website is a pre-made, non-visible website, that can be activated online when a particular crisis occurs. It is common for most companies to have several ones and all of them are customized according to certain vulnerabilities and corporate risks. They store written-in-advance news releases, pictures, official statements and other background information, as the specific details will only be added right before their release.
The dark site can be placed on a separate domain, be a distinct section of the main website or totally replace the original. It could be saved on any of the corporate servers or be kept safely on a preferred external device.
Because of the significance of dark websites, they have also become targets of many malicious scenarios. Probably the scariest threat for companies is someone intentionally triggering the content of the site online, without the permission of management. The system administrators will soon repair the “mistake”, but the point here is totally different. The actual goal of the attackers is not to create a false appearance of crisis, but to make a destructive buzz and to lower the public trust towards the target. Even if instantly refuted by the corporate crisis team, the situation will still be strong enough to cause a massive confusion among the audience, especially when all of the Web 2.0 applications allow you to achieve that in a matter of minutes. And remember - the information on the Internet always remains cached, so the chances of someone going back to those issues are actually pretty high.
--------------------
Black PR is pretty interesting stuff.
Why attack a huge mega-corporation's firewall, when you could attack their stock price just as easy (perhaps even easier)?
IBM's 'Phantom' to Study Virtual Security
RSA Conference 2008 -- IBM has begun a new research project designed to find and fix security vulnerabilities in virtual computing environments.
The project, a joint initiative between IBM's X-Force security research team and IBM Research, is code named Phantom. It will help identify potential vulnerabilities in virtualized environments and use network and host intrusion prevention technology to guard them.
"There's a lot of momentum behind virtualization out there, but not everyone has thought through the security implications," says Joe Anthony of IBM's Tivoli unit. "Phantom is taking a deeper look at those."
Under Phantom, IBM will develop technology to monitor and disrupt malicious communications between virtual machines. Phantom will also seek out ways to monitor the security state of virtual machines to protect them against known and unknown threats before they occur. "We'll analyze behavioral patterns, not just signatures," Anthony says.
IBM is also looking for ways to secure the hypervisor, which is a central point of control for all machines running on a virtualized platform. "We'll be looking not only at our own platform, but at different hypervisors from different vendors," Anthony says.
The Mac Guru of Damascus in the Case of the Missing Laptops
Before my fiancée and I headed to Syria to study Arabic, we often heard there was one advantage to living in a police state: almost no crime. So it came as a surprise when Sara and I returned to our Damascus apartment one night after a dinner party to find splintered wood in the hallway — wood that had once been part of our front door.
I made a beeline for the living room to check on our most valuable possessions: my MacBook and Sara's MacBook Pro. Both gone.
There's no 911 in Damascus, so we called our landlord, who contacted the cops. Within an hour, a dozen police were on the scene. About half of them sat around fingering unlit cigarettes. (Pushy Americans, we had asked them not to smoke inside.) The others engaged in what could generously be called an investigation. They took fingerprints from the door. They dusted the fridge. "Maybe the robber was thirsty," one said. They did not dust the coffee table where the laptops had been sitting.
The size of the police contingent was itself disconcerting. Damascus' finest had probably come out in force simply because it's not often a foreigner's home gets burglarized. But it's easy to get paranoid in Syria. We wondered whether some of the cops — like the ones wearing dark leather jackets — were "special" police, more interested in us than the crime. (Being a foreign journalist in Syria on a tourist visa can invite extra attention. Also, how to put this delicately, we were returning home from a Shabbat dinner.)
The next morning, our landlord accompanied us to the local police station to press our case. The commander was a friendly, well-fed man with an impressive mustache and the terminal stage of a comb-over. He asked a few questions about the theft and many more about the progress of our studies.
Eager to please, I told him a few Arabic jokes I had learned. ("There's this guy with a monkey, see. Along comes a hash addict ...") When I finished, he sat stone-faced — then burst into thunderous laughter. "I like this man!" he bellowed, pinching my cheeks. Sara would have taken a snapshot had our camera not also been stolen.
A few hours later, our computers were back, but it wasn't the police who found them. A friend had put us in touch with Bassel Al Hassan, apparently the one guy in Damascus who services Macs. A few days later we shared a meal with Hassan, a soft-spoken man in his mid-thirties. "Yours were the seventh and eighth stolen Macs I've recovered," he said. "Nobody knows about Macs here. A few other stores buy Macs, but eventually they all come to me, asking, Is it good? How much is it worth?' Then I check the serial numbers."
When Hassan learned our laptops had been pilfered, he called about 20 computer shops. "I didn't tell the owners I was looking for stolen computers, because then maybe they wouldn't buy them," he said.
Soon Hassan got a call about two newly arrived Macs and hustled over to the shop. He confirmed the computers were ours and told the store owner the machines were hot. The proprietor, who had paid $200 for the pair, gave them back to us without taking a penny in exchange, sheepishly delivering them to us at a street corner in our neighborhood. The only thing Hassan asked was permission to "friend" me on Facebook.
A few months later, after Sara and I returned to the US, I spoke with Hassan by phone. He said that he had corralled another stolen Mac just weeks after rescuing ours. From back here in the States, Hassan's role as the Mac Avenger of Damascus seems improbable. Except that I'm writing this article on my recovered laptop.
---------------------
Awesome story.
Lessons from Cyber Storm II
When things start to go bad on the Internet, communication is the critical element in an effective response, participants in the recent Cyber Storm II exercise said Wednesday at the RSA Security conference.
“There was still a shortfall in information sharing,” said Randy Vickers, assoiate deputy director of the U.S. Computer Emergency Readiness Team (US-CERT), the national center for first response in cybersecurity.
Vickers was part of a panel of government and industry participants in the recent exercise who shared their lessons. The discussion was short on specifics because participants signed nondisclosure agreements to ensure that sensitive data about systems and vulnerabilities is not leaked. An after-action report is expected to be published this fall, but among the preliminary lessons discussed, the need for communication was the one recurring theme.
“Cyber Storm II was fundamentally about identifying and responding to a fast-breaking cyber epidemic,” said Greg Garcia, assistant secretary for cybersecurity and communications at the Homeland Security Department.
The weeklong exercise held last month was the product of 18 months of planning and involved 18 U.S. federal agencies, five countries, nine states, 40 companies, and 10 information sharing and analysis centers. The scenario involved disruptions of telecommunications, the Internet and control systems.
“One of the things we learned was how important vendors are in a crisis,” Garcia said. They are the ones who know what the products are and how they work. Agencies and companies need to establish strong relationships with vendors of critical systems well in advance of a crisis, he added.
Vickers said US-CERT had learned the need for effectively gathering and disseminating information in the original Cyber Storm exercise and built on that in preparation for the second Cyber Storm. “We’re doing things right,” he said. “It is still better than it was,” but there are improvements to be made.
Playing Dead Works For Young Fire Ants Under Attack
Pretending to be dead is an effective self-defense strategy adopted by young fire ant workers under attack from neighboring colonies. This tactic makes them four times more likely to survive aggression than older workers who fight back. As a result, these young workers are able to contribute to brood care and colony growth to ensure the survival and fitness of their queen.
These findings were made by Dr. Deby Cassill from the Biology Department at USF Petersburg in Florida and her team from USF Tampa in Florida.*
Feigning death is a method of self-defense used by a wide range of species - mammals, birds, amphibians, lizards, dragonflies, and beetles - in response to threats by predators. Cassill and colleagues studied the death feigning behavior of the highly territorial fire ant, Solenopsis invicta, during attacks by ants from neighboring colonies in the laboratory.
They showed that the age of the victims was a significant predictor of their response to their aggressors. Days-old workers responded to the attacks by pretending to be dead. Weeks-old workers responded by fleeing and months-old workers fought back. By feigning death, young workers were four times more likely to survive the attack than were the older workers who ran away or fought back. The researchers also found that sustained movement from the victims was necessary to trigger a physical attack – known as a kinetic cue.
The authors offer two possible explanations for the death feigning behavior of the young fire ants. The external skeleton of days-old workers is relatively soft. Not only are these young workers prone to injury, they are ineffective in battle as their mandibles and stingers are not sufficiently hardened to penetrate the external skeleton of their aggressors. It may be that young workers pretend to be dead to avoid physical aggression at a time when they are vulnerable to injury and certain to fail. Another explanation is that by feigning death, young valuable workers are spared, allowing them to increase colony growth, which is essential to the survival and fitness of the colony queen.
NextGen Nuclear Fuel May Be Too Hot To Handle
New high-efficiency nuclear fuel meant to burn longer and stronger may prove unstable in an emergency and hard to dispose of, according experts cited in a report published Wednesday.
By further enriching the uranium used to power nuclear reactors, operators have been able to extract more electricity from a given amount of fuel, a measure expressed in gigawatt-days per tonne of uranium (GWd/tU).
Ramping up fuel efficiency has worked especially well in the pressurised water and boiling water reactors used in the United States and elsewhere.
The objective has been to extract more power from fuel and produce less radioactive waste, one of the most vexing problems associated with nuclear energy.
A new generation of nuclear plants in the United States and Britain is poised to use reactors designed for "burn-up rates" of 60 GWd/tU, according to the British weekly New Scientist, which canvassed experts.
"At these rates, uranium fuel rods should burn for around a year longer than today's best burn-up fuel," the magazine said.
But tests conducted by Michael Billone at Argonne National Laboratory in Illinois, presented last month at a conference in Washington, showed that burn-up rates above 45 GWd/tU would violate US Nuclear Regulatory Commission's (NRC) safety standards unless new methods were devised for packaging the fuel, the magazine reported.
A sudden loss of cooling water -- as happened during the partial meltdown of a reactor core in 1979 at Three Mile Island in Pennsylvania -- would pose such a danger, according to the simulations.
The US nuclear energy's Electric Power Research Institute says that such a loss of coolant is not possible in modern reactors, but the NRC has still launched a three-year review of its safety standards.
"We are actively preparing to revise NRC's safety criteria to account for the burn-up effect," a commission spokesman told New Scientist.
Disposal is also a potential problem because the new, high-efficiency fuel is up to 50 percent more radioactive than fuel currently in use, thus generating far more heat during storage.
Traffic Jams Happen, Get Used to It
Ever wondered what causes those inexplicable traffic jams on open stretches of highway, the ones without any accidents, construction, or other obvious bottlenecks? A Japanese group has an answer: It's pure physics. A simple experiment shows that when the density of vehicles on a road passes a certain threshold, traffic jams emerge because of fundamental instabilities inherent in multiparticle interactions. In other words, just a few mildly inconsistent drivers on the road will eventually cause a wave of backups.
The cause of so-called phantom traffic jams has been quite controversial, says Dirk Helbing, who studies the physics of social interactions at the Swiss Federal Institute of Technology in Zürich, Switzerland. One camp of traffic researchers believes that even phantom jams have external causes, be they merging traffic, curves, hills, or even a few bozos abruptly changing lanes. But other researchers contend that jams will spontaneously appear simply if the vehicle density exceeds a certain critical value. Yuki Sugiyama, a physicist at Nagoya University in Japan, says the predictions of these models have matched observations of highway traffic.
UMG Says Throwing Away Promo CDs is Illegal
In a brief filed in federal court yesterday, Universal Music Group (UMG) states that, when it comes to the millions of promotional CDs ("promo CDs") that it has sent out to music reviewers, radio stations, DJs, and other music industry insiders, throwing them away is "an unauthorized distribution" that violates copyright law. Yes, you read that right -- if you've ever received a promo CD from UMG, and you don't still have it, UMG thinks you're a pirate.
This revelation came in a brief for summary judgment filed by UMG against Troy Augusto. Augusto (aka Roast Beast Music Collectibles, eBay handle roastbeastmusic) buys collectible promo CDs at used record stores around Los Angeles and resells them on eBay. UMG sued him last year, claiming that the "promotional use only" labels on the CDs mean that UMG owns them forever and that any resale infringes copyright. EFF took Augusto's case to fight for the proposition that a copyright owner can't take away a consumer's first sale rights just by putting a label on a CD (after all, the Supreme Court first recognized the first sale doctrine when a book publisher tried the same thing with a label stating "may not be sold for less than one dollar," and we've seen patent owners trying the same trick on printer cartridges). In other words, EFF believes that if you bought it, or if someone gave it to you, you own it.
UMG seems to think that the "promotional use only" label somehow gives it "eternal ownership" over the CD. While this might make sense to a goblin living in Harry Potter's world, it's not the law under the Copyright Act. According to the first sale doctrine, once a copyright owner has parted with ownership of a CD, book, or DVD, whether by sale, gift, or other disposition, they may not control further dispositions of that particular copy (including throwing it away). It's thanks to the first sale doctrine that libraries can lend books, video rental stores can rent DVDs, and you can give a CD to a friend for their birthday. It's also the reason you can throw away any CD that you own.
For EFF's view of the reality of "promo CDs," and why it's absurd for UMG to claim to still own them, years after they mailed them out and deleted all records of who they were sent to, read our summary judgment brief on behalf of Augusto, also filed yesterday.
Wednesday, April 9, 2008
Lessons From the Accidental Nuke Flyby
A great inside look at a Pentagon after-action report on that embarrassing nuke flub where the Air Force flew a couple doomsday weapons across the US without even knowing it.
Let's hope this report doesn't just collect dust on some general's shelf and that the recommendations are actually implemented.
From our friends at Popular Mechanics:
One might think that the United States' nuclear weapons -- the cornerstone deterrent in the country's arsenal -- would be treated with the utmost precision.
This comfortable illusion was shaken on Aug. 31, 2007, when crews loaded six live nuclear warheads onto a B-52 bomber and flew from Minot Air Force Base in North Dakota to Barksdale Air Force Base in Louisiana, cruising over the nation's heartland. Each warhead was 10 times more powerful than the atomic bombs dropped on Hiroshima and Nagasaki during World War II.
During the analysis of the incident by the Defense Science Board (DSB), released this month, the ugly truth came out: America's nukes are so neglected that they are stored alongside conventional missiles, with nothing but an 8.5 x 11-in. sheet of paper to differentiate the two. The last day in August, Air Force personnel loaded the nuclear warheads on a routine repositioning of weapons stocks, believing them to be cruise missiles.
The system of checks and balances has degraded to a point that six of the planet's most powerful weapons were missing for 36 hours -- and no one noticed until they had landed in Louisiana. "The process and systemic problems that allowed such an incident have developed over more than a decade and have the potential for much more serious consequences," the report warns.
Remote Enumeration and Fingerprinting of RFID Passports
Security researchers have discovered a technique for reliably detecting the presence and nationality of a nearby e-passport.
Most newly issued passports carry an embedded RFID containing digitally signed biometric information. Access to this chip is wireless, which introduces a security risk, the possibility that an attacker might be able to access data on a person’s passport without the owner knowing.
Security precautions ought to prevent unauthorised access to data held on a next-generation e-passport. But a trio of researchers from Lausitz University of Applied Sciences, Germany and Radboud University, in The Netherlands, have shown that its trivial to at least remotely detect the presence of a passport and determine its nationality. "Although all passports implement the same international standard, experiments with passports from ten different countries show that characteristics of each implementation provide a fingerprint that is unique to passports of a particular country," the researchers explain.
To frustrate wireless reading of passport content without an owner’s consent, e-passports use a mechanism called Basic Access Control (BAC). The approach means that in order to read data from the RFID chip you need to optically read a key, printed in passports. This key is based on a passport serial number. Subsequent communication between a passport and a reader is then encrypted to prevent eavesdropping. All EU passports implement BAC.
Weaknesses in the encryption mechanism used in BAC in withstanding brute force attacks have already been reported.
The latest research uncovers a different shortcoming - the possibility that thieves could use technology to detect the presence and nationality of passports in a crowd, the sort of information that might be useful for a hi-tech pickpocket.
"This turns out to be surprisingly easy to do," the researchers report. "Although passports implement the same standard, there are differences that can be detected, especially by sending ill-formed requests, before Basic Access Control takes places."
The attack works because ICAO (International Civil Aviation Organization) specs do not prescribe a standard response to particular malformed requests, leaving room for diversity among implementations. If the ICAO specs did require a standard response for commands not listed in the specs and all malformed requests, this would make distinguishing passport nationalities much harder or even impossible, the researchers note.
Using this scanning approach the team was able to reliably detect the nationality of passports from 10 different countries: Australia, Belgium, France, Germany, Greece, Italy, the Netherlands, Poland, Spain, and Sweden. E-passports from other countries implementing BAC might also be vulnerable.
Eavesdropping on e-passports has been shown to be possible from up to nine meters for passive eavesdropping. Scanning passports involves generating a stronger magnetic field, creating practical problems for would-be thieves. Even so previous researcher suggests a device capable of scanning up to 25cm can be made for around $100.
The researchers - Wojciech Mostowski and Erik Poll, both from Radboud University, and Henning Richter of Lausitz University - argue their findings strengthen the case for metal shielding to prevent communication between a reader and a passport while the identity document is closed. This safeguard is already used in US passports as an alternative to Basic Access Control.