Tuesday, April 22, 2008

Mac Hack Contest Bug Had Been Public for a Year

Via PC World -

When Charlie Miller won US$10,000 for hacking into a Macbook Air laptop last month, he exploited a flaw that had been publicly disclosed nearly a year before the contest.

The flaw, it turns out, lay in an open-source software library called the Perl Compatible Regular Expressions (PCRE) library, which is used by many products including Apache, the PHP scripting language, and Apple's Safari browser, which Miller hacked to win the contest.

Miller won $10,000 and a new Macbook Air last month after hacking into the laptop in a matter of minutes. The PWN2OWN contest invited hackers to try to install unauthorized software on fully patched Mac OS X, Windows and Linux computers using previously undisclosed "zero-day" flaws.

In an e-mail interview, security researcher Chris Evans said he found the bug, which he publicly disclosed in November 2007. PCRE developers fixed the bug months earlier while writing an incomplete fix for the issue in the May 2007 PCRE 6.7 product, Evans said.

Although Apple's Safari browser uses the PCRE software library, the company did not patch its version of the library until late last week. That means that an astute hacker who had noticed the fix in PCRE 6.7 would have been given an early tip on how to hack into Apple's computers.

Discovering a software bug is the first step toward figuring out how to use that flaw in an attack, but not every flaw leads to a successful exploit.

In an e-mail interview, Miller confirmed that the bug he'd exploited was the same one that was patched in PCRE 6.7, but said that researchers at his company, Independent Security Evaluators, had found it "completely independently."

Miller found another PCRE bug that allowed him to be the first hacker to break into the iPhone after it was launched last year.

It is very common for developers to incorporate someone else's software library into their program and then not properly add all the latest bug fixes, said Dragos Rui, one of the organizers of the PWN2OWN contest.

However, Apple should have done a better job of staying on top of the software it was shipping. "This is a black mark on their security team, but it's a common problem," he said. The same kind of issue has popped up frequently with products that use the zlib and JPEG compression libraries, he added.

An Apple representative could not immediately comment for this story, saying that he would have to first research the issue.

Ironically, Miller gave a presentation at the Black Hat security conference last year, arguing that one way to find bugs in Mac OS X would be to look for out-of-date open-source software that ships with the Mac and then to scan that project's files.

I told Apple about this backporting problem then and they didn't listen and I didn't listen either, because we didn't find the bug by looking at changelogs, we found it with source code analysis," Miller said.

Although the focus of the PWN2OWN contest was on zero-day flaws, the fact that Miller exploited a flaw that was unpatched in Apple's products was enough to earn him the prize, conference organizers say.

That's a good thing, because when asked if he planned to return the prize money, Miller shot back the following: "No way. It's not my fault they don't fix their bugs."

----------------------------

This speaks for itself....but clearly, Apple failed to backport a open-source fix into their product. A year later, it is used for pure drive-by download pwnage in its browser.

I have been saying this for some time and so have many many other security professionals. It is only a manner of time before this exact issue takes a bigger bite of Apple - unless they really crack down and get serious about working open source patches back into their products in a timely fashion.

LendingTree Discloses Insider Data Breach

Via NetworkWorld -

Web-based lending exchange LendingTree, which generates leads in the mortgage business by accepting online customer information, yesterday disclosed that it believes several former employees illicitly helped a handful of mortgage lenders gain access to customer data.

"Recently, LendingTree learned that several former employees may have helped a handful of mortgage lenders gain access to LendingTree's customer information by sharing confidential passwords with the lenders," LendingTree stated in a letter sent April 21 to its customers. "When we learned of this situation, we quickly contacted the authorities, and LendingTree is helping with the investigation. We promptly made several system-security changes. We also brought lawsuits against those involved."

LendingTree spokeswoman Allison Vail acknowledged the letter had been sent to customers, but declined to provide further details, such as how many customers would be affected.

LendingTree believes the lenders gained illicit entry to its data systems to access LendingTree’s loan-request forms between October 2006 and early 2008. The Charlotte, N.C.-based firm stated that the loan-request forms contained such customer data as name, address, e-mail address, telephone number, Social Security Number, income and employment information.

LendingTree said it is not aware of identity theft or fraudulent activity resulting from the breach.

Army Engineer Charged For Passing Secrets to Israel

Via AP -

A former U.S. Army mechanical engineer was arrested Tuesday on charges he slipped classified documents about nuclear weapons to an employee of the Israeli Consulate who also received information from convicted Pentagon spy Jonathan Pollard, authorities announced.

Ben-ami Kadish faces four counts of conspiracy, including allegations that he conspired to disclose U.S. national defense documents to Israel and that he acted as an agent of the Israeli government, U.S. Attorney Michael J. Garcia and FBI officials said.

A criminal complaint said the activities occurred from 1979 through 1985 while Kadish worked at the Army's Armament Research, Development and Engineering Center in Dover, N.J.

Kadish, a U.S. citizen, is accused of taking classified documents home several times and letting the Israeli government worker photograph them.

The documents included information about nuclear weapons, a modified version of an F-15 fighter jet, and the Patriot missile air defense system, the complaint said.

According to the complaint, the Israeli government worker on numerous occasions during 1979-1985 gave Kadish lists of U.S. national defense classified documents for Kadish to obtain.

The complaint said Kadish, born in Connecticut, was employed from October 1963 to January 1990 as a mechanical engineer at the Army's Picatinny Arsenal in Dover, where the research center is based.

The complaint said the Israeli worker, whose name was not given, is an Israeli citizen. It said that in the late 1970s, he was employed at Israeli Aircraft Industries in Israel, a defense manufacturing contractor for the Israeli government.

From July 1980 through November 1985, he was the consul for science affairs at the Israeli Consulate General in Manhattan, the complaint said.

There was no immediate response to calls seeking consulate comment Tuesday.

Al Qaeda Officially Hates The Counterterrorism Blog

Via CT Blog -

When I started this website in January 2005, I never envisioned that that Al Qaeda would target us for a hit piece over the Internet. Well, voila, the blessed day has arrived. The wonderful folks at the SITE Intelligence Group found the item below on Al-Ekhlaas, one of Al-Qaida's central messaging forums on the Internet, which has begun a new series in English titled, "Watching and Monitoring the Jihad Media Watchers." They passed along the item below to Evan Kohlmann, who sent it to me, and I want to share it with our readers and contributors. They also passed out a "Badge of Honor" to SITE, Evan Kohlmann, IntelCenter, the NEFA Foundation, and Internet Haganah (my congrats to them).

-------------------

Check out the CT link above for the full details.

Kudos to every site named in this blog. I can say that I have been a reader of each of these sites for many years. They are all well maintained and very informative.

Wherever there are watchers...there will be watchers of those watchers. But who is watching the watchers of the watchers? That is the question. lol

British Police Use Facebook to Gather Evidence

Via CSOOnline -

The Greater Manchester Police force is looking for friends -- on Facebook.

It has created a Facebook application to collect leads for investigations, marking the first use of the social networking site by U.K. law enforcement.

The application delivers a real-time feed of police news and appeals for information. Next to that content is a feature to share a particular story with other friends in a person's network, as well as post comments.

One of the recent updates is an appeal asking for information about four men, one of whom was armed with an axe, who robbed a betting shop.

A "Submit Intelligence" link takes a Facebook user to the police Web site where they can anonymously submit tips. Another link leads to the videos on YouTube featuring information on the police force, ongoing investigations and other advisories.

One video contains closed-circuit TV footage of two men in hooded sweatshirts seen near the place where a 15-year-old, Jessie James, was shot and killed in Manchester in November 2006.

So far about 750 people have put the application on their profile, the police said. They estimate about seven million of the 59 million worldwide Facebook users live in the U.K.

The application has received a universally positive response. "Good thinking GMP [Greater Manchester Police]!" wrote Facebook user Sammie Jane. "This is a sure-fire way to branch out to the younger generation and also to encourage anonymous information."

New Tool Lets Enterprises Manage Security on Multiple Linux Servers

Via DarkReading -

The good news about open source security tools is that they're cheap and don't require much administration. The bad news about open source security tools is that they're cheap and don't require much administration.


That's the problem faced by many computing environments that use a large number of Linux servers. The security tools available in the open source environment are easy to procure, but they don't offer a central method of handling administration across multiple servers.


Trusted Computer Solutions Inc. tomorrow will attempt to jump into this void with the introduction of Security Blanket 2.0 Enterprise Edition, an automated "system lock down" and security management tool for Linux operating systems that can manage all local and remote Linux servers from a centralized Web-based management console.


The idea is to make it easier for larger Linux environments, such as government and educational organizations, to do the "hardening" process required to meet security compliance requirements, says Jamie Adams, senior developer at TCS.


"This will help organizations lock everything down to make assessors happy," Adams says. "It helps you figure out what needs to be configured, and then it helps you do the configuration. Then it helps you enforce the policy, making sure all of your servers are configured consistently and all the patches are up to date."

Currently, the primary open source tool for security administration is Bastille, but Bastille can't configure multiple servers from a central location and doesn't always meet current standards for compliance. "There's no commercial entity working on it," Adams observes. "You're not always getting updates right away."

The Enterprise version enables administrators to easily group Linux servers, associate a lockdown profile with a group of servers, scan all servers within a group to determine compliance, and configure the server operating systems to the lockdown level of the chosen profile.

Security Blanket 2.0 Enterprise includes the security guidelines recommended by the Center for Internet Security (CIS), the Defense Information Security Agency (DISA) Security Technical Implementation Guides (STIGs), and select guidelines from the SANS Institute’s defined risks associated with Linux. It lets administrators group servers, select one of these industry lockdown profiles (or build their own), assess the state of the servers against the profile, and then automatically configure the operating systems to meet those profile guidelines, TCS says.


Automation might increase organizations' interest in server hardening, which many still don't do, said Forrester Research in a report issued last year.


"Although server hardening is a well-established practice, only [45 percent] of interviewees harden all of their servers, and [26 percent] left some Internet-facing servers unhardened," Forrester said. "Why? Perhaps because they feel they can't spare the time -- today, [53 percent] of systems administrators harden their servers manually."

Security Blanket Enterprise Edition starts at $3,000 for a console that supports up to 100 servers. Server licenses start at $198 per server.

uTorrent CSRF Pwnage

Via xs-sniper.com -

A few weeks ago, Rob Carter told me about a few interesting CSRF vulnerabilities that he discovered in a uTorrent plugin (he publicly disclosed them this weekend). Rob was able to chain together the CSRF vulnerabilities and the net result is complete compromise of the victim’s machine! I think this may be the first PURE CSRF vulnerability that I’ve seen that resulted in compromise of a victims machine (there is an argument amongst some of my colleagues as to whether protocol handling/URI vulnerabilities are actually a form of CSRF, but that’s another story). The series of vulnerabilities basically follow this flow:

When a user installs the uTorrent Web UI plugin. the plugin essentially starts a locally running web server on your machine (in order to serve the Web UI). Rob targets the CSRF vulnerabilities associated with this locally running web server.

Once the file is placed, the next time the user restarts their machine, the attacker controlled file will be run… there you have it… compromise of a victim’s system through three CSRFs! Scary stuff… you can read more about the issue on Robs Blog

Google Searches that make you go hmm...



Legal notice to Jswiff? How is Oracle involved?...ummm




Either this is someone trying to find out how to defraud Coinstar machines, or something conducting serious "research".



Looks like a group of "419" scammers is preparing a new e-mail focused around Glass Manufacturers.

Monday, April 21, 2008

Bringing Sexy Back to Indian Cricket

"Sexuality and cricket is the way forward. And it's time India wakes up to the fact that it's a different society. It's a modern society. There's no use keeping it all under wraps."

http://www.washingtonpost.com/wp-dyn/content/article/2008/04/18/AR2008041803577.html

------------------

Thanks to my friend, Kelli C., for the link.

A Good Student's 'Unexpected' Bomb Plot

Via ABC News -

A South Carolina teenager arrested for plotting to bomb his school had designs for an arsenal of explosives including a nail bomb that would have "devastated" students in a crowded hallway, a local police chief said today.

Ryan Schallenberger, 18, called his plot "Columbine III" and laid out details in a "bomb summary" that described the different types of explosives he would use in the suicide attack. He even recorded his expenses.

"I think he was more concerned about a high body count than killing anyone in particular," Chesterfield Police Chief Randall Lear told ABC News.

Schallenberger's "summary" contained details for a nail bomb.

"Inside a school, with confined concrete walls, just a little bit of nails, nuts and bolts, ball bearings and some of these explosives devices, it would devastate the student body," Lear said.

Authorities arrested Schallenberger on Saturday after a package arrived at his family's rural South Carolina home and his parents opened it to find 10 pounds of ammonium nitrate, a substance that can be used as an explosive when combined with diesel fuel or another accelerant.

The teen's parents called the police, and officers recovered the explosives material and found details of the high school senior's plot. Schallenberger, who was not at home at the time, was picked up along a dirt road near his house.

No guns or other weapons were found in the house.

"I can honestly tell you, were I faced with that scenario, I don't know if I could have made that decision," Lear said. "I don't know whether I would have been brave enough to do what these parents did."

Schallenberger, who had recently won a partial scholarship to college, said nothing and appeared agitated during a brief court appearance today, in which he was assigned a lawyer. The county prosecutor said he will ask that Schallenberger undergo a mental health evaluation.

The bomb summary found in the suspect's bedroom laid out a map of the school, the different types of explosives that would be used in the attack and specific materials needed for each.

While there was no date provided for the bombing, Lear said that with the shipment of ammonium nitrate, he had all the materials he would need to carry out the attack at his fingertips.

"This was a legitimate threat," Lear said. "Once that package was in, he had what he needed to formulate these explosives devices."

700K Hoosier ID's Compromised in Computer Theft

Via Pal-item.com -

NDIANAPOLIS -- A computer server containing Social Security numbers and other personal information of 700,000 people was stolen last month from a Southside debt-collection bureau in what appears to be the largest computer security breach ever in Indiana.

The information includes customer-billing records for about 100 Indiana businesses, including Citizens Gas & Coke Utility, St. Vincent Health and Methodist Medical Group.

The exposed data was limited to past-due billing information that had been turned over for debt collection to the Central Collection Bureau, the agency announced Friday. Customers whose accounts were in good standing were not affected.

The bureau collected overdue bills on behalf of dozens of Indiana companies, including hospitals, medical and dental offices, window companies, water-conditioning companies and flower shops.

"We're obviously heartsick about this," said Chet Klene, the collection agency's president. "We've been in business since 1972, and nothing like this has ever happened before."

He said the missing computer server contained personal billing information that was protected by two passwords but was not encrypted. He said the server had been stored behind three locked doors.

Klene said the break-in occurred on Good Friday, March 20. The first employee arriving at work that day noticed the break-in and immediately called the Indianapolis Metropolitan Police Department, which investigated but has not found the server. The collection agency has notified companies whose billing records have been compromised, Klene said.

Joan Antokol, a lawyer specializing in computer security at Baker & Daniels, an Indianapolis-based law firm, said the breach was the largest she had seen in Indiana. No larger breaches in Indiana are included among the hundreds of incidents listed on Privacy Rights.org, a national clearinghouse.

"It's a problem that continues to grow," Antokol said. "There are new cases reported all the time. It's a serious problem."

Still, this breach does not rank among the top dozen or so nationally. Retailer TJ Maxx reported that as many as 100 million accounts were compromised as a result of thefts and hack-ins since last year.

The U.S. Department of Veterans Affairs said information on more than 28 million veterans might have been exposed after a laptop was stolen from an employee's house in 2006. Monster.com, a Web-based job service, said information on more than 1 million job seekers had been stolen last year, containing names, addresses, phone numbers and e-mail addresses.

A spokesman for Citizens Gas said its missing records were past-due billing statements for 51,000 former customers that it was unable to find on its own. The information included names, last known addresses, Social Security numbers, dates of service and amount due.

Citizens has no way of notifying the former customers because their whereabouts are unknown, spokesman Dan Considine said.

"We certainly take this very seriously, any time there is a security breach, and we hope it gets cleared up very soon," he said.

St. Vincent Health said it had not given any billing business to Central Collection in more than three years, so all of the missing billing information is several years old. The stolen information included patient billing information for St. Vincent Hospital and affiliated physicians' practices, spokesman Johnny Smith said.

"We're committed to protecting confidential information of our patients. We regret any inconvenience to them," Smith said.

Billing records of about 62,000 patients of Methodist Medical Group, a physicians' group owned by Clarian Health, also were missing, as are the records of thousands of patients at Howard Regional Health System in Kokomo.

The break-in is being investigated by IMPD and the Indiana attorney general's office.

Space Workers Find Message In A Bottle And Decide To Answer It

Via efluxmedia.com -

What are the chances for a message in a bottle to be answered? Pretty high, if the sea is kind enough to bring it all the way from Bahamas to NASA’s Kennedy Space Center.

United Space Alliance worker Jill Vogel accidentally discovered the bottle while voluntarily cleaning the beach at the space center. The letter wrote “Dear sea penpal” and originated from a 9-year-old girl from Holy Name Catholic School in Bimini.

As it appears, every year on Columbus Day (which celebrates Columbus’ arrival in the Americas), the girl takes part in a class project: she and her classmates send messages in bottles out to sea, hoping someone would find them and answer them.

“What a cool thing for a kid,” said Vogel, as quoted by Local 6 News.

The letter was apparently written in October, but it’s never too late to answer, and the workers at the United Space Alliance decided to surprise her by responding to her wish: “I hope you respond to my letter,” the little girl wrote.

Vogel and his colleagues sent back to Bahamas space memorabilia, including crew photos, pins, stickers and information about astronauts. NASA, Keep Brevard Beautiful and Wildlife Refuge contributed with items as well.

The package was sent by mail (to make sure it gets there) and all those who contributed to it are excited and can’t wait for the package to reach its destination.

Baker College wins National Collegiate Cyber Defense Competition

Via Linux.com -

Baker College of Flint, Mich., defeated defending champion Texas A&M University and four other regional winners from across the country to capture the third annual National Collegiate Cyber Defense Competition, which concluded in San Antonio, Texas, over the weekend. Texas A&M finished a close second, and the University of Louisville took third. Also competing for the championship were the Community College of Baltimore County, Mount San Antonio College of Los Angeles County, and the Rochester Institute of Technology.

Hosted by the Center for Infrastructure Assurance and Security (CIAS) at the University of Texas at San Antonio (UTSA), the event pits six regional winners, each given a similar small enterprise network to protect, against a team made up of experienced security professionals dubbed the Red Team, a.k.a. Team Hilarious.

Teams are scored on how well they protect their identical networks, made up a Cisco router and five servers: Windows 2003 running Internet Information Services, Windows 2000 running DNS, Solaris X86 running Apache and OpenSSL, Gentoo running MySQL and NFS, and BSD running Sendmail. Team workstations can run Vista, Windows, Fedora, or BSD, as the team prefers. Teams are required to provide SMTP, POP3, HTTP, HTTPS,and DNS services throughout the competition, and outages on any of those services result in deductions from their score. At specified times, the teams are also asked to bring up FTP, SSH, RDP, and VNC services, in accordance with the 2008 competition rules.

In addition to the attackers (the Red Team) and the defenders (the Blue Teams), there is also a White Team. The White Team acts as the overall network operations center, observers, and as communications center. All requests for information, assistance, and problem reporting by the competing teams go through the White Team; teams are not allowed direct communication with the outside world except for publicly available information and software available on the Internet. The White Team also delivers in-competition requests for new services and scores the teams' performance.

...

In addition to a few members of the press, the Red Team room was also visited by various federal agents. A contingent from the Secret Service was present all weekend. Three black-suited gentlemen claiming to be from the FBI were present Friday. Defense Information Systems Agency agents were present as part of the competition infrastructure, and among their other duties, helped escort journalists from room to room during the event.

...


Baltimore County Community College, the only team with a female competitor, and Mount San Antonio Community College in Los Angeles, proved that network security skills are not the exclusive domain of larger, better-known institutions. Their presence at this national competition is roughly the equivalent of a community college basketball team making it to the NCAA's Final Four, and both schools and students deserve kudos for going head to head against teams from much larger schools, especially since those schools may include two graduate students on their team.

Dr. Gregory White, director of the UTSA CIAS, one of the founders of the original competition when it was held on a regional basis rather than nationally, explained there is a large network and computer security population in San Antonio, primarily because the Air Intelligence Agency is located there. UTSA was a logical place to become an academic center for computer and network security. That led to it become the first Texas university to be designated as a "Center for Academic Excellence in Information Assurance Education" by both the DHS and the National Security Agency, and it currently offers bachelor and masters-level degrees in information security from several of its schools.

Sponsors for this year's event included the AT&T Foundation, DHS, Cisco Systems, Acronis, Northrop Grumman, Accenture, the Information Systems Security Association, Core Security, our sister site ThinkGeek, Code Magazine, and Pepsi. White said that more sponsors are needed for future competitions in order to do all the things CIAS wants to accomplish.

---------------------------

I agree with my fellow Texan, Joe Barr.

The word "Cyber" does sound very 90s.

Which reminds me, AMC tomorrow night...Wargames is on, 25th years.

Adobe Album Starter 3.2 Unchecked Local Buffer Overflow Exploit

Exploitable issue in various Adobe products
c0ntex (c0ntexb@gmail.com) Scott Laurie
February 2008

Vulnerable applications, tested:
Adobe Photoshop Album Starter
Adobe After Effects CS3
Adobe Photoshop CS3

Not Vulnerable applications, tested:
Adobe Reader
Adobe Flash Player

This bug is related to the parsing of header images, in that the applications do not verify that the image header is valid before trying to render it. This leaves an opportunity to cause an unchecked buffer overflow and allow for the execution of malicious code.

All the issues are standard local overflows whereby an attacker can exploit a machine after sending the malicious image to the user, or by placing the image on a web site or email and waiting for a user to view it in one of the effected products.

One fun thing with Album Starter is that it will run a service which will look for new devices being attached to the system, things like cameras or USB drives and when one is found it will check the device for image files. If some are found, the application will auto-run and import the images and thus allow the attacker to exploit locked workstations.. pretty lame but fun :)

http://www.milw0rm.com/exploits/5479

Microsoft: Finding Flaws On Our Website is OK

Via The Register UK -

In a first for a major company, Microsoft has publicly pledged not to sue or press charges against ethical hackers who responsibly find security flaws in its online services.

The promise, extended Saturday at the ToorCon security conference in Seattle, is a bold and significant move. While researchers are generally free to attack legally acquired software running on their own hardware, they can face severe penalties for probing websites that run on servers belonging to others. In some cases, organizations have pursued legal action against researchers who did nothing more than discover and responsibly report serious online vulnerabilities.

"This is actually really important because online services - that's our stuff," Microsoft security strategist Katie Moussouris told several hundred researchers. "The philosophy here is if someone is being nice enough to point out your fly is down, they're really doing you a favor and you should thank them rather than calling the cops and saying you're a pervert."

Moussouris said she is pushing to get a provision added to a proposed standard that's making its way through the International Organization for Standardization that would protect ethical hackers who responsibly disclose vulnerabilities in other companies' websites. "If I get my way, it'll be in there," she said.

(In a brief exchange after her talk, Moussouris told us she didn't know offhand exactly how the proposed standard was designated. We're guessing it's this one, though we can't be sure.)

The idea is to make websites safer by taking advantage of the legions of independent researchers who stumble upon security bugs. As she put it: "Don't hate the finder, hate the vulnerability. We don't actually want to discourage people who are trying to help us by being iffy about whether we're going to go after them."

As things stand, researchers frequently turn a blind eye to gaping security holes on websites for fear of suffering a fate similar to that of Eric McCarty. The prospective student at the University of Southern California found a flaw in the school's online application system that gave him access to other applicants' records. In 2006, he was charged with computer intrusion after producing proof of his finding.

"There's definitely a lot of trepidation among legitimate researchers to find flaws in public-facing web applications because you never know how [companies] are going to react," said Alex Stamos, a founding partner at iSEC Partners, a firm that provides penetration-testing services. "That hurts us because the only people finding these flaws are the bad guys."

-----------------------

Kudos to Microsoft.

Sunday, April 20, 2008

Why the Flu Vaccine Fizzled

Via NYTimes.com -

Anyone who dutifully got a flu vaccination this year only to come down with a serious fever, chills or cough had plenty of company. An analysis issued last week by the Centers for Disease Control and Prevention estimated that this year’s vaccine formulation was only 44 percent effective. That feeble performance, along with the virulence of one of the strains, made the flu season much worse than the previous three.

Not all of the news is bad. In a separate report, scientists tracked the previously mystifying origins and pathways of influenza viruses. Such information should help them make better vaccines.

What makes flu so hard to prevent is that the virus changes its molecular structure from year to year. Each year, experts try to guess which strains found anywhere in the world are apt to circulate in this country in the next flu season. They then formulate a vaccine to protect against those strains.

When they guess right, as is usually the case, the vaccine can be 70 to 90 percent effective in healthy adults. When they guess wrong, as happened this year, the mismatch leaves many recipients vulnerable.

This year’s vaccine was designed to protect against two strains of influenza A and one strain of influenza B. Based on an analysis in central Wisconsin, the vaccine proved 58 percent effective against the predominant A strain but totally ineffective against the B strain.

In research that could improve the likelihood of picking the right strains, an international team led by British scientists has documented — through molecular and genetic analysis — how seasonal flu strains evolve and sweep around the world. It turns out that new flu strains emerge in several countries in East and Southeast Asia, and are then carried by travelers to Europe and North America some six to nine months later. Several months after that they reach South America, where they die out. Then the whole process starts over.

Although scientists knew generally that influenza strains often emerge from in and around China, the new research expands the area that bears watching and surely bolsters the case for greatly enhanced surveillance in Asia. With any luck, that would lead to better and earlier identification of the strains that will be circulating — the key to making an effective vaccine.

DARPA Seeks Architecture-Aware Compilers

Via GCN.com -

The Defense Advanced Research Projects Agency is looking for smarter compilers — specifically, the agency is looking to fund development of compilers that can dynamically optimize programs for the specific environments in which they will run, according to a broad area announcement just released by the agency.

"The goal of DARPA’s envisioned Architecture-Aware Compiler Environment [AACE] Program is to develop computationally efficient compilers that incorporate learning and reasoning methods to drive compiler optimizations for a broad spectrum of computing system configurations," BAA 08-30 states.

Today's compilers were written under the assumption that the programs they create will run on single-processor systems, the document states. Yet the Defense Department is running programs across an ever-widening array of systems, from small embedded computers to clustered systems with thousands of processors. Tuning a program to run under unusual environments tends to be a lengthy and manual process. DARPA would like to automate much of the work associated with this task.

"An architecture[-]aware compiler should ... be able to significantly reduce the number of feedback loops required to achieve major performance improvements," the BAA states.

What DARPA is seeking is a new generation of compilers that can incorporate performance-tuning modules. When compiling application code, such compilers would consult static files (generated by a characterization program) that describe the environment in which that program will run. This compiler-of-the-future will then optimize its program for that specific environment, using not only this static characterization data but also dynamic data taken directly from the system itself.

"The runtime system will collect performance data in a knowledge database that can be reused by other applications that are executed on the system," the BAA states. DARPA also suggests that the compiler will need reasoning mechanisms in order to know what to do with this static and dynamic performance data.

The BAA only mentioned the C and Fortran programming languages as possible candidates for which compilers could be written. It does, however, encourage work in those languages that support techniques for parallelization of programs, such as the Message Passing Interface and OpenMP interface, and any languages using the Partitioned Global Address Space, such as Parallel C.

DARPA's Information Processing Techniques Office issued the BAA. Companies and research institutions have until June 2 to submit their initial proposals for consideration of funding.

The BAA did not disclose the amount DARPA plans to spend on this effort, stating that the amount will depend on the quality of the proposals received. The BAA does present a road map to fund this work at least through 2011.

US Gov Opens Wireless Systems Testing Lab

Via GCN.com -

Government defense and intelligence agencies have taken the wraps off a lab opened in the first quarter of this year for testing and evaluating wireless systems that transmit classified data.

The lab, developed by systems integrator Lockheed Martin, allows the agencies to test 802.11 Wi-Fi or broadband satellite links on a top-secret/sensitive compartmented information network.

The agencies will be able to test a broad spectrum of wireless networks, including Bluetooth, 802.16 WiMax, cell phones, and Ku- and C-band satellite communications. The lab is sealed and reinforced to ensure that signals from the systems stay within the chamber.

The Wireless Cyber Security Center, based in Hanover, Md., will allow agencies to define and evaluate wireless security strategies, policies and concepts of operation. The facility also will support projects to evaluate next-generation security technologies and assess vulnerabilities. Officials can also use the installation to evaluate mobile ad-hoc networks, which play an increasing role in battlefield communications.

Government agencies already are using the lab to conduct vulnerability testing, said Lockheed Martin spokesman Mattt Kramer. Results from the lab and the processes are secured, and they can potentially be labeled top secret, he said.

“We provide an actual classified environment using those technologies…. You can simulate it, but it’s no substitute for the real thing.” Testing these technologies over an actual network would potentially expose risks, Kramer said.

Wireless networks in use by the government today are not necessarily connected to a classified network, said Kramer. Defense and intelligence agencies are interested in testing these wireless networks to potentially transfer top-secret information over them.

The lab is one of only a handful capable of testing commercial wireless cybersecurity, said Kramer.

ISPs' Error Page Ads Let Hackers Hijack Entire Web

Via Wired.com -

Seeking to make money from mistyped website names, some of the United States' largest ISPs instead created a massive security hole that allowed hackers to use web addresses owned by eBay, PayPal, Google and Yahoo, and virtually any other large site.

The vulnerability was a dream scenario for phishers and cyber attackers looking for convincing platforms to distribute fake websites or malicious code.The hole was quickly and quietly patched Friday after IOActive security researcher Dan Kaminsky reported the issue to Earthlink and its technology partner, a British ad company called Barefruit. Earthlink users, and some Comcast subscribers, were at risk.

Kaminsky warns that the underlying danger lingers on.

"The entire security of the internet is now dependent on some random-ass server run by some British company," Kaminsky said.

At issue is a growing trend in which ISPs subvert the Domain Name System, or DNS, which translates website names into numeric addresses.

When users visit a website like Wired.com, the DNS system maps the domain name into an IP address such as 72.246.49.48. But if a particular site does not exist, the DNS server tells the browser that there's no such listing and a simple error message should be displayed.

But starting in August 2006, Earthlink instead intercepts that Non-Existent Domain (NXDOMAIN) response and sends the IP address of ad-partner Barefruit's server as the answer. When the browser visits that page, the user sees a list of suggestions for what site the user might have actually wanted, along with a search box and Yahoo ads.

The rub comes when a user is asking for a nonexistent subdomain of a real website, such as http://webmale.google.com, where the subdomain webmale doesn't exist (unlike, say, mail in mail.google.com). In this case, the Earthlink/Barefruit ads appear in the browser, while the title bar suggests that it's the official Google site.

As a result, all those subdomains are only as secure as Barefruit's servers, which turned out to be not very secure at all. Barefruit neglected basic web programming techniques, making its servers vulnerable to a malicious Javascript attack. That meant hackers could have crafted special links to unused subdomains of legitimate websites that, when visited, would serve any content the attacker wanted.

The hacker could, for example, send spam e-mails to Earthlink subscribers with a link to a webpage on money.paypal.com. Visiting that link would take the victim to the hacker's site, and it would look as though they were on a real PayPal page.

Finjan Exposes Website Running Crimeware as a Service (CAAS)

Via Register UK -

Security researchers have uncovered a new web-based service containing security credentials for more than 8,700 websites belonging to Fortune 500 companies and government agencies. It allows miscreants to infect some of the internet's most popular destinations with a few clicks of the mouse.

According to security provider Finjan, the service categorizes the list of available sites by a variety of characteristics, including the country where they're hosted and their popularity. After paying a fee, criminals can select the domain they want to compromise and then use it as a means to infect vulnerable machines that later visit the site.

The service provides a menu of malware titles that can be pushed to unwitting visitors. It also allows miscreants to upload custom exploits, according to Yuval Ben-Itzhak, chief technology officer at Finjan.

In a sense, this crimeware as a service (CAAS) was inevitable. According to an earlier report from Finjan, more than 51 percent of websites that pushed malicious content in the second half of 2007 were legitimate destinations that had been commandeered by bad guys. The service is evidence that there's money to be made in automating that process - and one more sign that cyber-crime has grown into a full-fledged business where no opportunity to turn a profit is passed up.

"You can imagine the magnitude of this marketplace now," he said in an interview. "They really commercialize everything in this eco-system."

About 10 of the compromised sites are among the 100 most popular internet destinations as measured by Alexa.com. Another 100 are ranked in the top 100 to 500. Sites include some of the world's more elite organizations, including companies in the financial services, manufacturing and technology industries. They also include government agencies, including at least one belonging to a superior court in the US. Most of the sites are located in the US. Other origins included the Russian Federation, Australia, Ukraine, the Czech Republic and the UK.

Ben-Itzhak declined to identify the sites by name. He said Finjan has so far alerted only about a dozen of the compromised sites. Companies that want to find out if they're on the list can contact a Finjan representative using this link.

The service is able to seamlessly infect the websites because it has a database containing file transfer protocol usernames, passwords and server addresses that are typically used by legitimate webmasters to add, change or delete pages. The credentials were most likely stolen by infecting the PCs of administrators with keyloggers, Ben-Itzhak said.

A site called meoryprof.info has been used to access the service. At te time of writing, it was inaccessible to us. As long as the FTP credentials remain valid, you can bet it's only a matter of time before the service pops up on another site.

Indonesia Arrests Two JI Members

Via Reuters India -

Indonesia has arrested two more members of Islamic militant group Jemaah Islamiah (JI), a senior police official told Reuters, which could lead to the arrest of other key militants wanted for attacks in Southeast Asia.

In particular, the police official said the arrests could help lead to the capture of Noordin Mohammad Top, one of the most senior members of Jemaah Islamiah who is still on the run.

The two men -- Abdul Rohim, who also uses the name Abu Husna, and a man identified only as Agus -- were caught in Malaysia more than two weeks ago and have been transferred to a detention centre in Jakarta, according to the police official in Jakarta, who declined to be identified by name.

Abu Husna "is a member of the markaziah, the central board of the organisation," the police official said, while the man identified as Agus was involved in attacks in Sulawesi and Java, and has close links to Abu Dujana, the military commander of Jemaah Islamiah, he added.

Sidney Jones, a expert on the Jemaah Islamiah at Brussels-based think-tank, the International Crisis Group, said Abu Husna is believed to have replaced Zarkasih as the head of JI, after Zarkasih was arrested last year in Indonesia.

"Abu Husna is a central figure in the organisation and he would know everything about the current activities, command structure and so on," said Jones, who is based in Jakarta.

Abu Husna has previously been the JI central command's head of education, overseeing some two dozen or so JI schools across Indonesia, according to Jones.

The other man who was arrested could be Agus Purwanto, Jones said, adding that he had studied at the famous Islamic boarding school run by the controversial cleric, Abu Bakar Bashir, in Solo, central Java. Bashir was jailed for 30 months for conspiracy over the Bali bombings but was later cleared.

Chinese Troops On The Streets of Zimbabwean City

Via Independent.co.uk -

Chinese troops have been seen on the streets of Zimbabwe's third largest city, Mutare, according to local witnesses. They were seen patrolling with Zimbabwean soldiers before and during Tuesday's ill-fated general strike called by the opposition Movement for Democratic Change (MDC).

Earlier, 10 Chinese soldiers armed with pistols checked in at the city's Holiday Inn along with 70 Zimbabwean troops.

One eyewitness, who asked not to be named, said: "We've never seen Chinese soldiers in full regalia on our streets before. The entire delegation took 80 rooms from the hotel, 10 for the Chinese and 70 for Zimbabwean soldiers."

Officially, the Chinese were visiting strategic locations such as border posts, key companies and state institutions, he said. But it is unclear why they were patrolling at such a sensitive time. They were supposed to stay five days, but left after three to travel to Masvingo, in the south.

China's support for President Mugabe's regime has been highlighted by the arrival in South Africa of a ship carrying a large cache of weapons destined for Zimbabwe's armed forces. Dock workers in Durban refused to unload it.


The 300,000-strong South African Transport and Allied Workers Union (Satawu) said it would be "grossly irresponsible" to touch the cargo of ammunition, grenades and mortar rounds on board the Chinese ship An Yue Jiang anchored outside the port.

A Satawu spokesman Randall Howard said: "Our members employed at Durban container terminal will not unload this cargo, neither will any of our members in the truck-driving sector move this cargo by road. South Africa cannot be seen to be facilitating the flow of weapons into Zimbabwe at a time where there is a political dispute and a volatile situation between Zanu-PF and the MDC."

Three million rounds of AK-47 ammunition, 1,500 rocket-propelled grenades and more than 3,000 mortar rounds and mortar tubes are among the cargo on the Chinese ship, according to copies of the inventory published by a South African newspaper.

Saturday, April 19, 2008

RumorMill: Windows XP Service Pack 3 Coming Soon

Via SANS ISC -

Information Week and Neowin.net are reporting that Windows XP Service Pack 3 may be showing up at the end of this month. OEMs and MSDN/Technet subscribers will apparently have access on the 21st, with release to Windows Update on the 29th.

http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=207200856

This is an unofficial report - we do not have confirmation from Microsoft for this.

Sudanese Gov Continues to Censor Private Media

Via RSF.org -

Reporters Without Borders called on the Sudanese government today to lift its almost three-month censorship of the privately-owned press in Khartoum which has intensified in recent days with the seizure of six daily newspapers.

"These are the most serious press freedom violations since the 2005 peace agreement that was supposed to end emergency laws,” the worldwide press freedom organisation said. “Secret police surveillance of newspaper staff is outrageous and illegal and the national unity government must put a stop to it. The media, one of the better aspects of modern Sudan, is being punished without reason and in violation of the national constitution.”

The National Security Service (NSS) domestic intelligence agency phoned the editors of 10 daily papers on 13 April and ordered them to henceforth submit all their content for prior approval under the censorship illegally reestablished on 6 February. But the papers all refused to comply and printed their editions in the normal way. The police then went to the printers and seized copies of Ajras al-Huriyya, Rai al-Shaab and Al-Ayyam on 15 April.

The editions of Al-Sudani, al-Ahdath, Ajras al-Huriyya, Rai al-Shaab and the English-language daily The Citizen were seized the next day (yesterday) after several tens of thousands of copies had been printed. The four Arab-language dailies had been warned not to report the press conference held the day before by the editors of Ajras al-Huriyya criticising the new censorship, a local journalist told Reporters Without Borders.

One Nation Under CCTV


Tools of the Trade - Happy Birthday Edna Parker

Maybe it was a lifetime of chores on the family farm that accounts for Edna Parker's long life. Or maybe just good genes explain why the world's oldest known person will turn 115 on Sunday, defying staggering odds.

Scientists who study longevity hope Parker and others who live to 110 or beyond - they're called supercentenarians - can help solve the mystery of extreme longevity.

"We don't know why she's lived so long," said Don Parker, her 59-year-old grandson. "But she's never been a worrier and she's always been a thin person, so maybe that has something to do with it." On Friday, Edna Parker laughed and smiled as relatives and guests released 115 balloons into sunny skies outside her nursing home. Dressed in pearls, a blue and white polka dot dress and new white shoes, she clutched a red rose during the festivities. Two years ago, researchers from the New England Centenarian Study at Boston University took a blood sample from Parker for the group's DNA database of supercentenarians.

http://www.physorg.com/news127759556.html

-----------------------------------

On to the tools....

On April 19th, Filezilla 3.0.92 was released. FileZilla is a powerful FTP-client for Windows NT4, 2000 and XP. It has been designed for ease of use and with support for as many features as possible, while still being fast and reliable

On April 18th, Adam Laurie released RFIDIOt-0.1s. RFIDIOt is a open source RFID exploration python library and toolkit. The big news with this release is that by popular demand, there is now a separate Windows distribution.

On April 17th, Microsoft SysInternals released Process Monitor v1.32 & Process Explorer v11.13. Use Process Explorer to find out what files, registry keys and other objects processes have open, which DLLs they have loaded, and more. Monitor file system, Registry, process, thread and DLL activity in real-time with Process Monitor.

On April 12th, KeePass v1.11 was released. KeePass is a free/open-source password manager or safe which helps you to manage your passwords in a secure way. Check the press release for all the change details.

On April 11th, Paint.NET 3.30 was released. Paint.NET is image and photo manipulation software designed to be used on computers that run XP, Server 2003 or Vista.

On April 9th, Adobe Systems released Flash Player v9.0.124.0. This release addressed several security vulnerabilities.

On April 2nd, Mozilla released Firefox 3 Beta 5. Improvements to the JavaScript engine as well as profile guided optimizations have resulted in continued improvements in performance. Compared to Firefox 2, web applications like Google Mail and Zoho Office run twice as fast in Firefox 3 Beta 5.

On March 31st, Pidgin 2.4.1 was released. Pidgin is a multi-protocol Instant Messaging client that allows you to use all of your IM accounts at once. Check out changelog for all the details.

On March 30th, Wireshark 1.0.0 was released. Wireshark (formerly Ethereal) is a network protocol analyzer for Unix and Windows. This new release addresses several DoS vulnerabilities.

On March 28th, Nullsoft released Winamp 5.53. Check the version history for all the changes.

On March 27th, The Honeynet Project and School of Mathematics, Statistics and Computer Science at Victoria University of Wellington released Capture-HPC v2.1. Capture-HPC is an innovative security product that is able to find and investigate the increasing problem of client-side computer attacks. This new software release increases the features and speeds performance allowing anyone to investigate a larger range and quantity of client-side computer attacks. It is written and distributed under the GNU General Public License, v2.

On March 26th, GNU Privacy Guard released GnuPG 1.4.9 & GnuPG 2.0.9. This is a maintenance release to fix a possible vulnerability introduced with 1.4.8.

The Sim Toolkit Research Group

THC is proud to announce the SIM Toolkit Research Project. We are looking for talented people. The goal is to uncover secrets of the SIM card and learn how it really works.

http://wiki.thc.org/gsm/simtoolkit

GSM Cracking: Coming Soon to a Computer Near You via a Web Service

Via O'Reilly Radar -

A web service that will make it easy and inexpensive to crack the GSM A5/1 encryption protocol, quickly enough for a call that is still in progress, is slated to launch at the end of April. Living right at the intersection of open hardware, open source software, software as a service, and cryptography, the service will reduce the cost and effort of cracking GSM call encryption by at least an order of magnitude.

The service is being developed by members of the GSM Software Project and demonstrates just how much things have changed in the world since the GSM system was designed. Various approaches to cracking both A5/1 (the European standard) and A5/2 (the weaker US standard) have been available for some time but this one is unique in that it should be available to researchers and hackers at the end of April in hosted api form instead of pdf.

China Tries to Limit Internet Vitriol Toward the West

Via LATimes.com -

As Chinese nationalism flares across cyberspace, the government is growing concerned that passions could spill over into the real world, and that anger directed against foreigners could turn inward.Critics contend that Beijing has had a role in fanning the xenophobic sentiment to counter international condemnation of its crackdown on Tibetan rioters, but now Chinese officials appear to be trying to rein in the vitriol.

Chinese censors have quietly warned cyber-police and Internet businesses to delete all information related to protests against Western policies, nations or companies that have proliferated in the wake of demonstrations surrounding the global Olympic torch relay and high-level calls to boycott the opening ceremony of the Summer Games in Beijing.

The notice issued this week by China's "Internet Inspection Sector" instructs recipients to reset the keywords used to block access to certain websites, relay the instructions through all Internet distribution channels and delete the notice in a timely manner.

The censors' notice cites the danger that Internet-fueled emotions could lead to unrest."Internet users are in a most intense mood toward Western countries," it said. "Such information has shown a tendency to spread and, if not checked in time, could even lead to events getting out of control as they did with the April 9 incident against Japan."

That was a reference to April 2005, when demonstrators attacked Japan's embassy in Beijing and consulate in Shanghai, burned Japanese goods and beat Japanese citizens because of Tokyo's bid to join the U.N. Security Council and over Japanese textbooks that downplayed Tokyo's World War II aggression.

Notorious eBay Hacker Arrested in Romania

Via The Register UK -

Vladuz, the notorious hacker who repeatedly accessed off-limits parts of eBay's network and then publicly bragged about it, has been arrested, the online auctioneer says.

The hacker was arrested by Romanian law enforcement officials with the help of the US Secret Service, the FBI and eBay's global fraud investigation team, eBay said. The company wouldn't discuss additional details, and representatives from the Secret Service and the FBI couldn't be reached for comment.

According to Romanian news reports
here and here, Vlad Constantin Duiculescu, 20, was arrested in a communist-era housing project in Bucharest. A court in that city remanded the suspect in custody for an initial 29 days.

'Judicial Scandal' in Pirate Bay Case

Via thelocal.se (Sweden) -

A Swedish police officer involved in the investigation of file sharing site The Pirate Bay has been given a job with one of the plaintiffs in the case, film company Warner Brothers.

The officer began working for Warner Brothers job several months after the preliminary investigation was completed. The same police officer is scheduled to appear as a witness in the forthcoming Pirate Bay trial, newspaper Sydsvenskan reports.

Defence lawyer Peter Althin said he would be looking into the matter.

"The question is how long this was under consideration. If it was under consideration at the time of the investigation then it is a scandal," he told Sydsvenskan.

Althin is representing Peter Sunde, one of four men charged charged with being an accessory to breaking copyright law.

"This is a judicial scandal. Talk about a conflict of interests," Sunde told the newspaper.

If the police officer is found to have entered into discussions with Warner Brothers before the end of the investigation, which took a year and a half to complete, it is possible that the prosecution will have to scrap its findings and start again, said Althin.

Token Kidnapping: New Windows Kernel Bug Released in HITB

http://conference.hitb.org/hitbsecconf2008dubai/?page_id=182

Presentation Title: Token Kidnapping

Presentation Details:
This presentation is about a new technique for elevating privileges on Windows mostly from services, this technique exploits design weaknesses in Microsoft Windows XP, 2003, Vista and even Windows 2008. While in Windows vista and 2008 many new security protections have been added, because the weaknesses some of the new protection mechanisms are almost useless.


It will be explained how it’s possible in Windows XP and 2003 to elevate privileges to LOCAL SYSTEM from any process that has impersonation rights, and in Windows Vista and Windows 2008 how to elevate privileges to LOCAL SYSTEM from processes running under NETWORK SERVICE and LOCAL SERVICE accounts demonstrating that running code under NETWORK SERVICE or LOCAL SERVICE is non sense since always it’s possible to end up running code under LOCAL SYSTEM account. It will be showed 0day code for elevating privileges in SQL Server and Internet Information Services.

-----------------------

Compare that to the Windows Advisory release.

Sounds right on the money.

Thanks to K for the heads up.

UPDATE (4/19/2008) 2:23PM CST - Cesar posted the following message on several mailing list today.
Token Kidnapping (Microsoft Security Advisory 951306) presentation available

Presentation is available at:
http://www.argeniss.com/research/TokenKidnapping.pdf

Exploit code won't be released for a while due to
Microsoft request.

Enjoy.

Cesar.

Friday, April 18, 2008

European Union Tightens Anti-Terrorism Laws

Via BBC -

European Union ministers have agreed to punish incitement to terrorism through the internet.

At a meeting in Luxembourg, EU justice and interior ministers tightened existing laws.

Public provocation to commit terrorist attacks, as well as recruiting and training people for terrorism will be punishable offences throughout the EU.

The ministers also agreed on an action plan to prevent terrorist groups from getting explosives.

EU officials said the decision to punish propaganda, recruitment and training for terrorism through the internet filled an important gap in European legislation.

They described the internet as a virtual training camp for militants, used to inspire and mobilise local groups.

Earlier this month, the EU anti-terrorism co-ordinator, Gilles de Kerchove, said the threat of terrorism in Europe had not diminished and about 5,000 internet sites were being used to radicalise young people.

National courts will now be able to ask internet service providers to remove such sites.

Britain, Spain and Italy already punish public incitement to terrorism.

But under pressure from Nordic countries and civil rights campaigners, ministers made clear that the new provisions may not be used to restrict freedom of expression.

In a separate move to combat terrorism, they agreed to establish an early-warning system on stolen explosives and detonators by the end of the year.

UK Police to Hold Suspect Arrested Under the Terrorism Act

Via BBC -

Police in Bristol have been granted a further seven days to question a 19-year-old man arrested under the Terrorism Act.

The extension comes after Avon and Somerset police conducted a controlled explosion early Friday in a cul-de-sac in the Westbury-on-Trym area.

Bomb disposal units returned to the area late Friday.

The suspect was named as Andrew Ibrahim, a British Muslim convert who moved into the area three weeks ago.

The controlled blast was carried out after a raid on the suspect's home in the immediate area.

The materials blown up are to be analysed as part of what police described as a "long and complex" investigation, sparked by an intelligence tip-off.

Residents were evacuated and some were expected to be kept out of their homes until at least Saturday.

Vulnerability in Windows Could Allow Elevation of Privilege

Microsoft Security Advisory (951306)
Vulnerability in Windows Could Allow Elevation of Privilege
Published: April 17, 2008

Microsoft is investigating new public reports of a vulnerability which could allow elevation of privilege from authenticated user to LocalSystem, affecting Windows XP Professional Service Pack 2 and all supported versions and editions of Windows Server 2003, Windows Vista, and Windows Server 2008. Customers who allow user-provided code to run in an authenticated context, such as within Internet Information Services (IIS) and SQL Server, should review this advisory. Hosting providers may be at increased risk from this elevation of privilege vulnerability.

Currently, Microsoft is not aware of any attacks attempting to exploit the potential vulnerability. Upon completion of this investigation, Microsoft will take the appropriate action to protect our customers, which may include providing a solution through a service pack, our monthly security update release process, or an out-of-cycle security update, depending on customer needs.

U.S. to Expand Collection Of Crime Suspects' DNA

Via Washington Post -

The U.S. government will soon begin collecting DNA samples from all citizens arrested in connection with any federal crime and from many immigrants detained by federal authorities, adding genetic identifiers from more than 1 million individuals a year to the swiftly growing federal law enforcement DNA database.

The policy will substantially expand the current practice of routinely collecting DNA samples from only those convicted of federal crimes, and it will build on a growing policy among states to collect DNA from many people who are arrested. Thirteen states do so now and turn their data over to the federal government.

The initiative, to be published as a proposed rule in the Federal Register in coming days, reflects a congressional directive that DNA from arrestees be collected to help catch a range of domestic criminals. But it also requires, for the first time, the collection of DNA samples from people other than U.S. citizens and legal permanent residents who are detained by U.S. authorities.

Although fingerprints have long been collected for virtually every arrestee, privacy advocates say the new policy expands the DNA database, run by the FBI, beyond its initial aim of storing information on the perpetrators of violent crimes.

They also worry that people could be detained erroneously and swept into the database without cause, and that DNA samples from those who are never convicted of a crime, because of acquittal or a withdrawal of charges, might nonetheless be permanently retained by the FBI.

"Innocent people don't belong in a so-called criminal database," said Tania Simoncelli, science adviser for the American Civil Liberties Union. "We're crossing a line."

She said that if the samples are kept, they could one day be analyzed for sensitive information such as diseases and ancestry.

Justice Department spokesman Erik Ablin said the collection of DNA samples "will provide an additional form of biometric identification from persons who would normally be fingerprinted." FBI rules preclude using DNA samples to determine a person's genetic traits, diseases or disorders.

The database expansion was authorized by Congress as an amendment to the Violence Against Women Act and was billed primarily as a way to track down serial rapists, murderers and other offenders. "We know for a fact that the proposed regulations will save the lives of many innocent people and will prevent devastating crimes," said Sen. Jon Kyl (R-Ariz.), a sponsor of the legislation. "These regulations are long overdue -- we should have done this 10 years ago."

The proposed rule applies to all federal agencies with the authority to arrest or detain, including the FBI, the Border Patrol and the Internal Revenue Service. Although details of the policy have not been announced, officials said they expect the bulk of the new DNA samples to be collected through cheek swabs.

-----------------------

So NASA, the IRS and the TSA at the airport can take my DNA?

I wonder if this is going in the Server in the sky?

Wow...bring on the CCTVs.

Information on Thousands of UM Patients Stolen

Via Miami Herald.com -


Computer tapes containing confidential information of 2.1 million University of Miami patients was stolen last month when thieves took a case out of a van used by a private off-site storage company, UM said Thursday morning

'' Anyone who has been a patient of a University of Miami physician or visited a UM facility since Jan. 1, 1999, is likely included on the tapes,'' the university said in a news release. ``The data included names, addresses, Social Security numbers or health information. The university will be notifying by mail the 47,000 patients whose data may have included credit card or other financial information regarding bill payment.''

The information was in a container holding computer back-up tapes. The container was removed from a vehicle in downtown Coral Gables on March 17, the storage company told UM.

''Shortly after learning of the incident, the university determined it would be unlikely that a thief would be able to access the backup tapes because of the complex and proprietary format in which they were written,'' UM said in the statement.

''Even so, the university engaged leading computer security experts at Terremark Worldwide to independently ascertain the feasibility of accessing and extracting data from a similar set of backup tapes,'' UM reported.

A Terremark executive, Christopher Day, said that after a week of trying to extract the data, it couldn't do so. ''Because of the highly proprietary compression and encoding used in writing the tapes, we were unable to extract any usable data,'' Day was quoted as saying in the news release.

UM then asked Alan Brill, senior managing director at Kroll Ontrack, to review the testing. ''While the report shows it is not impossible to access the data, in this case there are many barriers that stand between a thief and being able to actually get usable data from the tapes,'' the report quoted Brill as saying.

In its release, UM said it has created a website for information about the incident: www.dataincident.miami.edu. Patients can also contact a call center at 1-866-628-4492.

Massive Botnets Decried As Imminent National Threat

Via Wired.com -

Gangs of thousands of zombie home computers grinding out spam, committing fraud and overpowering websites are the most vexing net threat today, according to law enforcement and security professionals.

Today's botnet herders have hundreds of thousands of computers at their command and use technically sophisticated ways to hide their headquarters, making it easy for them to make millions from spam and credit card theft. They can also be used to direct floods of fake traffic at a targeted website in order to bring down a rival, extract protection money or less frequently, used to make a political point in the case of attacks on Estonia and the Church of Scientology.

Security pros and government officials are now describing the latter attacks, known as Distributed Denial of Service attacks, as serious threats to national security -- turning packet floods against public websites into the latest face of "cyberwar" hysteria.

Hence, the appearance Tuesday of a panel discussion at the RSA 2008 security conference entitled "Protecting the Homeland: Winning the Botnet Battle," which was marked by a mix of resignation, indignation and post-9/11 rhetoric.

Ronald Teixeira, the executive director of the non-profit National Cyber Security Alliance and the panel's moderator, began the discussion by describing botnets as "one of the largest threats we face on the internet today, and they can be used to attack critical infrastructure."

The Department of Homeland Security's representative Jordana Siegel, who works on public awareness at the National Cyber Security Division, echoed the line that botnets were a imminent threat to the nation's security.

Citing the attacks on Estonia last year by Russian nationalist hackers, Siegel said botnets can "disrupt an internet-reliant society," saying that the temporary takedown of Estonian newspaper and government websites "nearly crippled the country's cyber infrastructure." Earlier in the day, Homeland Security chief Michael Chertoff leaned on Estonia as evidence of the need for a federal government "Manhattan Project" for computer security.

Siegel said the DHS is working at fighting the problem, citing the annual October National Cyber Security Awareness month, which she said helped Americans learn that "all users need to practice safe online behavior."

Thursday, April 17, 2008

Intel Centrino 2200BG Wireless Driver Probe Overflow

This [Metasploit] module exploits a stack overflow in the w22n51.sys driver provided with the Intel 2200BG integrated wireless adapter. This stack overflow allows remote code execution in kernel mode. The stack overflow is triggered when a 802.11 Probe response frame is received that contains multi vendor specific tag and "\x00" as essid and essid length element. This exploit was tested with version 8.0.12.20000 of the driver and an Intel Centrino 2200BG integrated wireless adapter. Newer versions of the w22n51.sys driver are provided from Intel to resolve this flaw.

Since this vulnerability is exploited via probe response frames, all cards within range of the attack will be affected. Vulnerable clients don't need to have their card in a particular state for this exploit to work.

Authors: oveRet & skape

http://www.milw0rm.com/exploits/5461

GSM Researcher Stopped at Heathrow Airport by UK Gov

Via THC Blog -

I was leaving today from the United Kingdom/Heathrow airport. I am about to speak at the HITB IT security conference about GSM security and the USRP (gnu-radio project).

I was searched by the UK government while waiting at the Gate and reading a newspaper. A UK Government employee flipped his badge and said "Let's talk. Come over here".

They detained my USRP (Software Defined Radio), my mobile phone and my personal SIM card.

They did their homework. They knew who I am, where i live, which day I speak at the conference and who I work for.

I'm involved in the GSM software project where we also developed a new attack against the GSM encryption A51. We published our research in February at the Blackhat security conference in Washington DC.

I understand that the government wanted to make sure that I'm not exporting any cryptanalytic device.

I did not. I will not. The USRP is a radio. My mobile phone is a normal nokia 3310 phone and my SIM card is a sim card.

They said they do not know what the USRP is and that I can not take it until they have checked it in the lab. This can take 14 days (1/2 month).

So be it. They have it for 14 days. Guys, enjoy the device! It's fun playing around with it!

I'm uneasy that they took my mobile phone and my sim card. Having a pregnant wife at home and not being reachable complicates my situation.

Is this common practice? Are they allowed to do this?
Any tips how I can get my mobile phone and my sim card back quicker?

Our project: http://wiki.thc.org/gsm
The USRP is available from http://www.ettus.com
The GNU RADIO project: http://www.gnu.org/software/gnuradio


stunning,

THC
---

Appendix: Surprisingly they did not detain my laptop or my paperwork which would be the most likely place to store any information related to cracking A51. They were also not interested in my 160GB harddrive which would have been the obvious place for storing the rainbow tables. Neither were they interested in the high performance FPGA chip.

Instead they took all equipment that could have been used for demonstrating that GSM signals can be received with publicly available hardware for 700 USD.

It does not appear that they were after cryptanalytic information.

I received a yellow paper about my detained goods. They left the field blank that reads
"The goods specified below are detained for the following reason:". What reason?

They also crossed out the field "Agent" of the officer who was in charge of the operation.

Humor: Florida Legalizes Taking Guns To Work

Via TheOnion -

Florida legislators passed a bill allowing citizens to bring their guns to work. Here are some of the other pro-gun laws enacted recently.
  • Alaska—Members of endangered species now permitted to carry concealed firearms for self-protection
  • Louisiana—Now legal for residents to shoot at hurricanes
  • Minnesota—Any resident may fire a single shot every five years, or when Vikings win
  • Idaho—You can have a gun, or a grenade, but not both
  • Virginia—Non-gun-owning residents must apply for a permit to not own and operate a firearm
  • New York—Guest stars on Law & Order may bring their own guns to the set
  • Kansas—Children as young as 8 can bring guns to school on the condition that there's no funny business
  • Texas—That huge cattle gun used by Javier Bardem's character in No Country For Old Men now legally available at Fiesta Mart grocery stores

----------------------------

More real information on this new law passed in FL. Check out these true media sources:

http://www.tampabay.com/news/politics/state/article452031.ece

http://news.yahoo.com/s/nm/20080409/pl_nm/usa_florida_guns_dc

http://www.floridacapitalnews.com/apps/pbcs.dll/article?AID=/20080404/CAPITOLNEWS/804040350

http://www.cnsnews.com/ViewNation.asp?Page=/Nation/archive/200804/NAT20080411a.html

Interbank FX Customers Data Exposed For Almost A Year

Via Cyberinsecure.com -

In April, 2007 an employee posted a file to an insecure server that was accessible via the Internet. The file contained personal information belonging to certain persons who applied for an Interbank FX account prior to April, 2007. Interbank FX became aware of the exposure only on March 28th, 2008.

The incident involved an electronic file dated April 2, 2007, which contained personal information provided by certain individuals who had applied for an Interbank FX account prior to that date. Around that time, an employee uploaded the file to a computer server accessible via the internet. The employee’s action was contrary to Interbank FX policies and procedures and compromised the security of the information in the file.

The file contained the information provided during opening of an account. This may include social security number, driver’s license, and passport information, and may also include Interbank FX account information.

Upon learning on March 28, 2008 that this information was available outside secured computing environment, the Company took immediate steps to secure the information. Interbank FX has thoroughly investigated the matter, has taken immediate steps to protect clients information, and is taking the additional precautions to assist monitoring and guarding the security of personal information. All files containing sensitive personal information were removed from the server and brought within the Company’s firewalls and electronic security controls.

The incident does not affect anyone who applied for an Interbank FX account after April 2, 2007.

As an additional precaution, clients are encouraged to change any password you created for your Interbank FX account prior to April 2, 2007. A toll-free hotline (800-550-1571) is available for questions and assist in signing up for the Equifax Credit WatchTM program.