Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Saturday, April 11, 2009
UK Terror Plot Disrupted - Details
Intelligence officials in the UK arrested 12 Muslim men who planned to carry out an attack specifically targeting shoppers for the Christian Easter holiday. The results, according to officials, had the potential to be more devastating than the July 7, 2005 London bombings that killed 52 people. At least ten of the men arrested are Pakistani nationals from the North West Frontier Province who are in the UK on student visas, according to British intelligence sources. The ages of the men range from 18 to 41; at least ten residences in Manchester and Liverpool are currently being searched by police and intelligence officials.
The terrorists had selected at least 3 separate shopping centers, targeting Christian shoppers for the East holiday. Additionally, the photograph of the Birdcage nightclub was found and believed to be a possible target of the terrorists. The Arndale and Trafford shopping centers, and St. Anne’s Square were the other reported targets. Photographs, maps, and other documents relating to those locations were found by police at more than one of the suspects’ residences.
Currently, the BBC and other media outlets are reporting that the terrorist plot was “more inspirational than operational.” The BBC is also reporting that the staff at the shopping centers identified as terrorist targets had not been informed of any threat, and that stores were operating as normal over the Easter weekend.
“That is not exactly how I would characterize the state of their operation,” stated a British intelligence official interviewed by the Northeast Intelligence Network. ”There is evidence that the plans were a go for this weekend, and there is evidence that ’some of the men’ had handled explosives or the components to manufacture explosives,” added this source.
Police are currently looking for a location that served as a bomb factory in the Liverpool area where explosives reportedly were assembled.
Friday, April 10, 2009
US Intel Community Employees Like Their Working Conditions
We don't know much about what they do, but the seem to enjoy it.
Spies and other intelligence community employees rate their agencies well in several categories compared to federal workers in other agencies, according to survey data released by the Office of the Director of National Intelligence.
The 2008 IC (intelligence community) Employee Climate Survey says 73 percent of the employees in 16 intelligence agencies said they were satisfied with their jobs, compared to 68 percent in a government wide survey.
“The Community remains an ‘employer of choice’ among its employees, especially when compared with other federal agencies,” said Ronald P. Sanders, the chief human capital officer in the director's office. “Our employees enjoy their work and realize how important it is to national security. This news is heartening, but we know there is room for improvement – and we’ve taken decisive steps to tackle many of the challenges identified in the latest annual survey, our fourth.”
Sanders acknowledged that one of the areas in need of improvement is the way the employees view their pay for performance system. Only 19 percent agreed with the statement that "in comparison to similar jobs in the private sector, I feel my total compensation is fair." And just 29 percent agreed that "pay raises depend on how well employees perform their jobs."
A summary of the results is here.
France Detains Suspected ETA Leader in Paris
French police said Friday they had detained a top member of the Basque separatist group, ETA, who was carrying a Magnum handgun and false papers when arrested in Paris.
Ekaitz Sirvent Auzmendi was seized after he got off a high-speed train from Bordeaux in Paris, said police.
Auzmendi is believed to be ETA's number two on the logistics side and one of the movement's five top leaders, said Spanish media, citing Spanish anti-terrorist sources.
On the run since 2002, Auzmendi had been under police surveillance during his rail journey from Bordeaux, in southwest France. Spanish police were present during the arrest, police said.
Spain's interior ministry said in a statement that a laptop computer and a large quantity of computer-equipment including USB keys and hard discs were seized during the arrest.
Auzmendi had also been carrying false French and Spanish identity papers, said the statement.
Spanish investigators believed forging documents was part of his duties for the banned separatist group, said the ministry.
The Spanish daily El Mundo said the arrest was the most important blow against ETA's leadership carried out this year.
Saudi Al-Qaeda Leader Outlines New Strategy and Tactics of AQAP
In a statement delivered on Saudi Arabia’s state-owned Al-Ikhbariyah TV, a former leading member of al-Qaeda in Yemen, now in detention in Riyadh, described the revised tactical and strategic approach taken by al-Qaeda in the Arabian Peninsula, a new organization that combines the Saudi Arabian and Yemeni branches of al-Qaeda (Al-Ikhbariyah TV, March 27). Captured in Afghanistan in 2001, al-Awfi was detained as an enemy combatant in Guantanamo under the name Mohamed Atiq Awayd al-Harbi (prisoner no. 333). In November 2007, al-Awfi was transferred to Saudi Arabia, where he entered the Counseling Program run by Saudi Arabia’s Advisory Committee responsible for the rehabilitation of Islamist extremists (see Terrorism Monitor, August 16, 2007; January 25, 2008).
Shortly after entering the program, al-Awfi fled Saudi Arabia along with Sa’id Ali al-Shihri “Abu Sayyaf,” another former Guantanamo Bay prisoner who was transferred to Saudi custody at the same time as al-Awfi. Al-Shihri became the deputy leader of al-Qaeda in Yemen and is a suspect in last September’s car-bombing outside the American Embassy in Sana’a that killed 16 people. The two men headed for Yemen, mainly because it was accessible in comparison to Iraq or Afghanistan.
In January, al-Awfi appeared in a 19-minute video with three other al-Qaeda leaders to announce the unification of the Saudi Arabian and Yemeni chapters of al-Qaeda in a new organization, al-Qaeda in the Arabian Peninsula. Others in the video included Sa’id al-Shihri, Qasim al-Rimi “Abu-Hurayrah” (military commander) and Abu Basir Nasir al-Wuhayshi, the group’s leader (Al-Malahim Establishment for Media Production/al-Fajr Media Center, January 24). Aside from issuing warnings to the “Crusader states” and the Saudi security services, al-Awfi warned “the brothers in prison” against participating in the Saudi rehabilitation program, run by “the ignorant oppressor Muhammad bin Nayif” and “the liar Turki al-Uttayan.” He accused the latter of heading a “psychological investigations delegation” to Guantanamo to help extract confessions from prisoners there.
Al-Awfi now maintains he did not want to appear in the January 24 video and argued with the leadership over this issue. Eventually he was ordered to appear in a certain place to make the video, but objected to the message he was told to read. Al-Awfi, who claims the message did not represent his viewpoint or ideas, was told to read it without changes because the wording in the message was carefully chosen. After careful reconsideration of the takfiri approach taken by his al-Qaeda colleagues, al-Awfi crossed back into Saudi Arabia and surrendered himself to authorities in mid-February after first contacting a shaykh at the Advisory Committee (YemenOnline, February 17).
According to al-Awfi, the organization decided on a major change in tactics and strategy, moving away from the methods of former Saudi Arabian al-Qaeda leader Abd al-Aziz bin Abd al-Muhsin al-Miqrin (killed June 18, 2004 after overseeing a number of terrorist blasts and kidnappings). The group’s assessment of al-Miqrin’s campaign declared al-Miqrin had blundered by concentrating his forces in Riyadh. In the new strategy al-Qaeda would mount attacks in Saudi Arabia from bases in Yemen, leaving only a small group of 30 to 40 individuals in the southern mountains of Saudi Arabia to carry out small-scale operations such as assassinations and sniping attacks. For major operations, a reconnaissance and surveillance team would enter Saudi Arabia to collect detailed intelligence before returning to their base in Yemen, where the operation would be carefully planned. After a major strike the attackers would slip back across the border into Yemen, exhausting Saudi security forces in a fruitless search within Saudi Arabia. Training was to be aimed at producing fighters who could operate on various fronts, including guerrilla fighting, mountain warfare and jungle fighting (Al-Ikhbariyah TV, March 27).
The sincerity of al-Awfi’s latest act of repentance was questioned by some in Saudi Arabia; one daily newspaper asked, “How much can we trust Muhammad al-Awfi? ... It is an embarrassment when terrorists continue to fool us with naïve justifications and stories, then try to destroy us once more” (Jedda al-Madinah, March 30). Noting his rejection of takfiri ideology, a Saudi economic daily noted: "We hope what al-Awfi has revealed would serve as a clear message to those who might think that al-Qaeda was an organization that seeks jihad in the name of God” (Al-Iqtisadiyah, March 28).
-----------------------
AQAP = Al-Qaeda in the Arabian Peninsula
Iraq: Al-Qaeda 'Afghanistan Iraq' Base Discovered
An Iraqi security source has announced the discovery of an Al-Qaeda training base named "Afghanistan Iraq" in the Al-Anbar province.
The base has human skulls positioned at its entrance.
The source said that Abu Mus'ab Al-Zarqawi, commander of Al-Qaeda in Iraq, had been in charge of all operations in this base up until his assassination in June 2006.
Source: Al-Quds Al-Arabi, London, April 10, 2009
----------------------------
The original Al-Quds Al-Arabi article (in Arabic) can be found here.
The following pieces of information are based on a roughly translated version of the article...
- The base was located about 300 miles west of Ramadi.
- Five people (which trained at the camp) were arrested (believed to be Al-Qaeda members).
- All five people were from the Al-Anbar province and were between the ages of 25 and 35.
- According to confessions, people at the camp were trained from 2005 to the end of 2007 in methods of making and planting improvised explosive devices (IEDs), automatic & light weapon use and mortars.
- According to the police in Al-Anbar province, caves in the hills surrounding the camp were used to manufacture IEDs and warehouse information related to the organization - publications, etc.
- Police also discovered mass graves in the vicinity of the camp. Several of the victims are believed to be local police or security officers.
Little Brother Is Watching You
When London's mobile CCTV cameras were shut down by a legal ruling two days before the G20 protests in London, conspiracy theorists suggested that the blackout had been contrived so that the police could be let off the reins. Without CCTV, there would be no record of official wrongdoing.
It was a neat theory, but naively old-fashioned in its assumption that the state had a monopoly on surveillance. The emergence of amateur video showing Ian Tomlinson, the man who had a heart attack on the day of the protests, being pushed to the ground by a police officer soon before he died. It clearly demonstrates that for every camera pointed at you by Big Brother, there are 10 more pointed back by Little Brother — an informed, digitally savvy civilian population that has the tools to record anything, anytime, anywhere.
[...]
We've grown used to the idea that amateur footage will trump the professionals in the moments after air crashes, floods and fires, but we haven't yet grasped what that does to the balance of power between the state, the media and the individual. Surveillance is still talked of as something done to us by them, but increasingly it's something done to everyone by everyone else. What that means for the authorities is that they can no longer control the flow of information about their actions.
They haven't yet stopped trying. Without the camera work of the New York fund manager who captured some of Tomlinson's last moments, the final word on his death would have gone to the police: "[He] suffered a sudden heart attack while on his way home from work."
The week-old footage that emerged today does not contradict that official statement, but it widens the lens through which we see the event, and it changes our perspective. Instead of the sober, considered response of a senior media-trained officer, calmly delivered hours after the event, we're in the thick of the action. It's messy footage of jeering protesters and a policeman lunging at a middle-age man, who stumbles to the ground. It leaves little room for complacency.
[...]
The story brings to mind Cory Doctorow's novel, Little Brother, which examines how smart, tech-savvy individuals can level the playing field against agents of the state by using their own understanding of digital tools to subvert and confront them.
[...]
Google, the owner of YouTube, provoked a flurry of outrage (and plenty of benign curiosity) when it launched Street View in Britain last month, but taking still images of a street every couple of years is even less efficient as a means of surveillance than official CCTV. An individual with a camera and access to a network is a far greater threat to our privacy, and a far more powerful guardian of our liberty.
Little Brother is watching you, and watching over you.
Sabotage Attacks Knock Out Phone Service
Police are hunting for vandals who chopped fiber-optic cables and killed landlines, cell phones and Internet service for tens of thousands of people in Santa Clara, Santa Cruz and San Benito counties on Thursday.
The sabotage essentially froze operations in parts of the three counties at hospitals, stores, banks and police and fire departments that rely on 911 calls, computerized medical records, ATMs and credit and debit cards.
The full extent of the havoc might not be known for days, emergency officials said as they finished repairing the damage late Thursday.
Whatever the final toll, one thing is certain: Whoever did this is in a world of trouble if he, she or they get caught.
"I pity the individuals who have done this," said San Jose Police Chief Rob Davis.
Ten fiber-optic cables carrying were cut at four locations in the predawn darkness.
Residential and business customers quickly found that telephone service was perhaps more laced into their everyday needs than they thought. Suddenly they couldn't draw out money, send text messages, check e-mail or Web sites, call anyone for help, or even check on friends or relatives down the road.
Several people had to be driven to hospitals because they were unable to summon ambulances. Many businesses lapsed into idleness for hours, without the ability to contact associates or customers.
More than 50,000 landline customers lost service - some were residential, others were business lines that needed the connections for ATMs, Internet and bank card transactions. One line alone could affect hundreds of users.
"It was substantial," said John Britton, spokesman for AT&T.
Authorities throughout the area said Thursday night that nobody had sought help from fire or police officials. But only the coming hours, and maybe days, will tell if there were emergencies nobody knows about yet. Officials worried that some people might have become incapacitated before they were able to summon help without a phone.
"We don't know what this has done to people's lives," said Liz Kniss, president of the Santa Clara County Board of Supervisors. "I'm incredibly troubled by it.
"We haven't experienced a major catastrophic emergency today. But we don't know."
FBI agents, phone company managers and local police said they were scouring the vandalism sites for evidence and aggressively searching for the perpetrators. Potential penalties include criminal charges of vandalism, heavy restitution payments and possibly even worse consequences if someone winds up being hurt directly by the outage.
Federal Health Project Releases Open-Source Software Gateway
The Federal Health Architecture project released into the public domain the code for Connect, a software gateway that will let organizations outside the federal government share health information via the National Health Information Network.
Any public or private sector organization can download the Connect software and tie into the NHIN once it goes into full production. The source code and its documentation are available at www.connectopensource.org .
Connect will make the open versions of the core network services of the NHIN available to health information organizations, including identifying the patient, document query and retrieval, audit-log, retrieval, a messaging platform and an authorization framework.
Like most open-source projects, those that opt to use the solution will be responsible for costs associated with its installation and maintenance, noted officials from the Office of National Coordinator for Health Information Technology, which managed the Connect project.
Dr. Robert Kolodner, the national coordinator, said the “software will strengthen our health systems’ ability to share data electronically.” The benefits of NHIN interconnection, he said, include up-to-date records at the point of care, enhanced population health screening, and faster case research collection to facilitate disability claims.
The Social Security Administration became the first federal agency to use the gateway in a production mode in February when it began sharing data with MedVirginia, a health information exchange, to access health records from people applying for health-related SSA benefits.
Other federal agencies now using Connect for health information exchange includes the Department of Defense, the Department of Veterans Affairs, the Indian Health Service, the Centers for Disease Control and Prevention, and the National Cancer Institute.
Vish Sankaran, the program director of the Federal Health Architecture, a collaboration of 20 federal agencies with health care responsibilities, said the potential impact of the Connect program was “enormous,” and would help pave the way toward the “lofty health IT goals” set for the project.
Eight Microsoft Patches Expected on Tuesday
Microsoft plans to ship 8 security bulletins next Tuesday (April 14, 2009) to fix remote code execution and denial of service vulnerabilities affecting Windows, Office and Internet Explorer.
According to the company’s Patch Tuesday advance notice, five of the bulletins will be rated “critical,” meaning they can be exploited by hackers to take complete control of Windows machines.
I’ve been given a heads-up that one of the Internet Explorer vulnerabilities being fixed is the musty old Safari-to-IE carpet bombing blended threat that combined flaws in two browsers into a code execution attack.
The IE flaw was originally discovered and reported by Aviv Raff back in November 2006 (more than two years ago!) but was ignored by Microsoft until the Safari carpet-bombing bug emerged to show how a combo-attack could lead to complete PC takeover.
I’m told Microsoft will actually issue two separate bulletins on this issue — one with a patch that changes several calls to LoadLibrary and SearchPath in Internet Explorer to stop the browser from attempting to load libraries directly from the desktop.
Microsoft will also push out additional defense-in-depth protections and a new API to further limit the damage from hacker attacks but because of application compatibility issues, the protections will NOT be enabled by default.
In addition to the high-priority IE bulletin, next Tuesday’s patch batch will include five different Windows bulletins (four rated critical), a solitary Microsoft Excel update (critical), and an ISA denial-of-service issue that Microsoft rates as “important.”
Thursday, April 9, 2009
Tools of the Trade - Nessus 4 Edition
On to the tools....
On April 9th, Tenable released Nessus 4. This new version boost performance on Windows up to 100%, reduced memory usage and supports XLST transformations of reports.
On April 9th, Sun released VirtualBox 2.2.0. The new release includes a number of performance and feature enhancements, as well as support for the Open Virtualization Format (OVF) specification.
On April 8th, Wireshark 1.0.7 was released. Several bugs have been addressed including security-related bugs in the Profinet, LDAP, and CPHAP dissectors and the Tektronix K12 file format.
On April 7th, Snort 2.8.4 was released. Snort is an open source network intrusion prevention and detection system utilizing a rule-driven language, which combines the benefits of signature, protocol and anomaly based inspection methods. Check the release notes for all the details.
On April 6th, Microsoft released Autoruns 9.41. This utility shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them.
On March 25th, OpenSSL 0.9.8k was released. Three moderate security vulnerabilities were addressed in this release. Shining Light Productions has OpenSSL 0.9.8k installs for those running Windows.
On March 24th, Sun Java SE Runtime Environment JRE 6 Update 13 was released. This release contains fixes for one or more security vulnerabilities - Sun Alerts 254569, 254570, 254571, 254608, 254609, 254610, and 254611. Check out the release notes for all the details.
On March 18th, Jon Rose released Deblaze. Deblaze is a remote method enumeration tool for flex servers. It allows pen-testers to perform method enumeration and interrogation against flash remoting end points. Thanks to my friend @ Trustwave Spiderlabs for the heads up on this release.
Transversal Encoded Quantum Gates May Be Impossible
From a theoretical point of view, work on quantum computing is moving along at a good clip.
The first classical computing machines were envisioned around 1800, long before the introduction of electronics, and it took about 150 years to produce a practical computer even though the theory had long been worked out, said Bryan Eastin, an information theorist with the National Institute of Standards and Technology (NIST).
“In that respect we’re doing pretty good, in that I expect we will have [a quantum computer] in less than 100 years,” Eastin said. “There are no theoretical difficulties, but there are a lot of painful technical difficulties.”
One of those difficulties—the problem of "noise," or errors in calculations introduced by stray energy — turns out to more difficult than thought. Eastin and NIST mathematician Emanuel Knill proved in a paper in the March 20 issue of Physical Review Letters that one promising technique for squelching quantum noise actually is impossible.
The technique, called transversal encoded quantum gates, seemed simple at first (at least to a physicist). “But after substantial effort, no one was able to find a quantum code to do that,” Eastin said. “We were able to show that a way doesn’t exist.”
[...]
Transversal gates were supposed to solve this [error checking] problem by preventing qubits that are going to be error corrected together from interacting, thus squelching the noise of errors. Similar gates have been designed for other purposes, but Eastin and Knill were able to show a mathematical proof that the structure of quantum space is not amenable to this particular technique.
With transversal gates ruled out, scientists now are free to move onto greener fields of research and come up with better solutions, Eastin said.
[...]
Now that he has finished off transversal gates, Eastin has a number of other research irons in the fire, such as quantum discord, a measure of non-classical correlation in quantum systems.
South Korean Finance Ministry Targeted By Chinese Hackers
Chinese hackers targeting South Korean government computers gained access to classified information and financial policies, officials here said Wednesday.
The compromised computers, located at the finance ministry headquarters in Gwacheon, south of Seoul, were attacked in early February. Intelligence authorities are conducting a probe, the officials said.
"The computers were apparently attacked by Chinese hackers," a ministry official said on condition of anonymity. "An investigation is still under way to figure out how much information has been compromised." He quoted a source from the National Intelligence Service as saying that the hackers might be "working for the Chinese government." NIS officials could not be reached for comment.
The incident came before South Korean President Lee Myung-bak and his Chinese counterpart, Hu Jintao, held their first summit talks this year on the sidelines of the G-20 gathering in London last week.
[...]
The hackers reportedly sent an e-mail to an unspecified number of ministry employees that appeared to be from one of their colleagues.
Many of them opened it without any suspicion, activating surreptitious software that allowed the hackers to gain access, the official explained.
The finance ministry has been attempting to strengthen its Internet firewall since late last year by making officials use two separate computers -- one used only for Web access and another for working on documents -- so that information cannot be leaked through the network.
The so-called "network separation" plan has reduced the number of information leaks "significantly," the ministry said.
"(The leak) happened before the project was completed," another ministry official said. "We have enforced the separated use of computers since April 1. It would be difficult for such a case to happen again." However, experts worry that classified information could be leaked even under the tightened security system, as hackers continue to use more sophisticated methods.
Wednesday, April 8, 2009
Researchers To Unleash Backbone-Hacking Tools At Black Hat Europe
A pair of German researchers at next week's Black Hat Europe will release tools that hack backbone technologies used by service providers in some enterprise network service offerings.
More specifically, the tools -- built by Enno Rey and Daniel Mende, both with German security firm ERNW -- automate attacks on Multiprotocol Layer Switching (MPLS) and Ethernet backbone technologies. They exploit similar, inherent security weaknesses in the two networking technologies -- namely, in how they forward traffic.
The lack of security in MPLS and Ethernet is well-known, but until now the exploitation of these network technologies has been only theoretically possible, Rey says. "Our release of the tools closes that gap of these attacks being only theoretical to being practically exploitable now," he says. "These technologies do not provide any security themselves, but just rely on the assumption that the underlying network is secure."
Network infrastructure security has been in the limelight lately, with researchers uncovering big vulnerabilities in the Domain Name System (DNS), the Border Gateway Protocol (BGP), TCP, and in Cisco routers.
MPLS VPNs originally were proprietary networks when they first hit the network scene. But the evolution of service provider networks to Internet-based services has put MPLS, as well as Ethernet, in the hot seat as possible hacking targets, Rey notes. MPLS networks used to have their "own set of switches and management infrastructures, and their own set of surrounding technologies," he says, "and the average attacker could not get his hands on that equipment."
To execute an MPLS or Ethernet carrier network hack, an attacker first must get into the network, either by hacking a router or a management tool. Then Rey and Mende's MPLS hacking tool could be used: It modifies the labels that are added to packets in an MPLS network and determines how those packets are forwarded. This lets an attacker silently redirect traffic to other sites, such as a malicious DNS server or a phony authentication server, Rey says. "The victim doesn't notice anything...and the attacker has both directions of traffic [in his control]," he says. "The whole VPN model of trust is violated."
The attack doesn't target a specific vulnerabilty -- just the way MPLS operates. The story is much the same for Ethernet. VLAN-tagging, for instance, helps carriers separate different customers' traffic across their backbones. "But there's no encryption and no additional security [with Ethernet]," Rey says. "It's just traffic separated by adding some more bits to the traffic, which brings us back to being able to modify those bits [with our hacking tool]."
Rey says enterprises that use these VPN services should be aware they are vulnerable. Perform risk analysis and encrypt your traffic, he says. "Just because it's called MPLS VPN [doesn't mean] you should [automatically] trust it," he says.
Electricity Grid in U.S. Penetrated By Spies
Cyberspies have penetrated the U.S. electrical grid and left behind software programs that could be used to disrupt the system, according to current and former national-security officials.
The spies came from China, Russia and other countries, these officials said, and were believed to be on a mission to navigate the U.S. electrical system and its controls. The intruders haven't sought to damage the power grid or other key infrastructure, but officials warned they could try during a crisis or war.
"The Chinese have attempted to map our infrastructure, such as the electrical grid," said a senior intelligence official. "So have the Russians."
The espionage appeared pervasive across the U.S. and doesn't target a particular company or region, said a former Department of Homeland Security official. "There are intrusions, and they are growing," the former official said, referring to electrical systems. "There were a lot last year."
Many of the intrusions were detected not by the companies in charge of the infrastructure but by U.S. intelligence agencies, officials said. Intelligence officials worry about cyber attackers taking control of electrical facilities, a nuclear power plant or financial networks via the Internet.Authorities investigating the intrusions have found software tools left behind that could be used to destroy infrastructure components, the senior intelligence official said. He added, "If we go to war with them, they will try to turn them on."
Officials said water, sewage and other infrastructure systems also were at risk.
"Over the past several years, we have seen cyberattacks against critical infrastructures abroad, and many of our own infrastructures are as vulnerable as their foreign counterparts," Director of National Intelligence Dennis Blair recently told lawmakers. "A number of nations, including Russia and China, can disrupt elements of the U.S. information infrastructure."
Officials cautioned that the motivation of the cyberspies wasn't well understood, and they don't see an immediate danger. China, for example, has little incentive to disrupt the U.S. economy because it relies on American consumers and holds U.S. government debt.
But protecting the electrical grid and other infrastructure is a key part of the Obama administration's cybersecurity review, which is to be completed next week. Under the Bush administration, Congress approved $17 billion in secret funds to protect government networks, according to people familiar with the budget. The Obama administration is weighing whether to expand the program to address vulnerabilities in private computer networks, which would cost billions of dollars more. A senior Pentagon official said Tuesday the Pentagon has spent $100 million in the past six months repairing cyber damage.
Tuesday, April 7, 2009
Plot To Smuggle Nuclear Materials To Iran Smashed By Manhattan DA Office
A Chinese financier who peddles nuclear weapons material to Iran was indicted Tuesday for illegally running tens of millions of dollars through a half-dozen New York banks.
Le Fang Wei, 37, duped six unwitting banks with an assortment of aliases and phony businesses despite a federal banking ban against him, Manhattan District Attorney Robert Morgenthau said.
The deception allowed Wei and his company to continue banking in U.S. dollars - and to continue selling banned weapons material to the Iranian military, the indictment said.
Wei was charged with conspiracy and falsifying records. The Daily News exclusively reported details of the plot Tuesday.
Although Wei used the same phony aliases for banking and for material sales, authorities made no direct connection between the New York banks and Iran's nuclear program.
"We cannot point to any specific U.S. dollar payment for WMDs, although our investigation suggests there were some," said a Morgenthau spokeswoman.
Morgenthau made it clear that Iran's WMD program was at the heart of the financial finagling.
"There's not much doubt that the use is for weapons," he said. "There is no greater threat to the world today than Iran's efforts to procure nuclear weapons and long range ballistics missiles."
Wei was barred from doing business with any U.S. banks in June 2006 because of his support for Iran's program for weapons of mass destruction.
Prosecutors said he turned to using fake names and non-existent companies to collect money funneled through the banks.
The shipments of illegal materials were made directly from Wei's China-based company, Limmt Economic and Trade Company Ltd.
"We may not be able to shut down Mr. Wei's factory, but we can shine a spotlight on his conduct and the conduct of the foreign banks that permit these types of operations to flourish," Morgenthau said.
The U.S. banks involved were identified as New York Mellon, Citibank, JPMorgan Chase, Wachovia Bank/Wells Fargo, Bank of America and Standard Charter Bank.
Wei remained free in his native country.
"We're going to try to extradite him," Morgenthau said.
Asked if he expected the Chinese government to assist, Morgenthau replied, "We're always optimists."
New Music Station - Dubstep.fm
Dubstep is a genre of electronic music that has its roots in London's early 2000s UK garage scene. Musically, dubstep is distinguished by its dark mood, sparse rhythms, and emphasis on bass.
Dubstep rhythms are usually syncopated, and often shuffled or incorporating triplets. The tempo is nearly always in the range of 138-142bpm.
Enkryption Projekt (from Brooklyn, NY) is live on dubstep.fm right now...
Next-Generation DoD Spy Satellite Network to Be Established
Director of National Intelligence Dennis Blair and Defense Secretary Robert Gates signed a classified memo March 30 that would establish a program to build a multi-billion dollar, next-generation spy satellite network, reports DOD Buzz.
The program would add a further layer of complexity to the administration’s current budget crunch dilemma in which a number of large programs for new weapons systems are forcing government officials to pick and choose which will continue as part of the 2010 budget and which will be sharply cut back or canceled.
The debate between the intelligence community and the military over the configuration of the system has been heated, sources told the online journal. Specific details of the program are scant because of its classified nature.
DNI spokeswoman Vanee Vines confirmed April 2 that the two organizations have approved the electro-optical satellite network. She told the online journal that the decision was based on multiple panels and studies conducted over the last several years that showed a need for a new satellite network. Vines declined to discuss the costs or schedule of the proposed satellite system.
The system might cost $3.5 billion to get started, and potentially would cost up to $10 billion over the next five years, depending on which technical approach is approved and on how many satellites will be built, sources told DOD Buzz.
“Tactics in Counterinsurgency” Again Online
“Tactics in Counterinsurgency” (large pdf), a new Army Field Manual that was published on the website of the U.S. Army Combined Arms Center and then removed from public access, is now available on the FAS website.
The new manual, a substantial addition to the literature of counterinsurgency, was reported last week in the Washington Post and Inside the Army. “After The Post raised questions about its contents last week,” wrote Walter Pincus of the Post on March 31, “it was taken down” from the Army website, even though the document is marked for unrestricted release.
An email inquiry to the Army inquiring why it had been removed was not answered.
See “Tactics in Counterinsurgency,” U.S. Army Field Manual Interim 3-24.2, March 2009 (6.2 MB PDF, 307 pages).
“Setbacks are normal in counterinsurgency, as in every other form of war,” the new manual advises (p. C-5). “You will make mistakes, lose people, or occasionally kill or detain the wrong person…. If this happens, don’t lose heart, simply drop back to the previous phase of your game plan and recover your balance.”
Monday, April 6, 2009
US Expert - North Korea Rocket Launch Partial Success
Via physorg.com -
"It says, first of all, they had successful first staging and (were) able to control the rocket through staging," retired General Henry Obering told CNN television.
"That is a significant step forward for any missile program because often times the missiles become unstable as they go through the staging events," Obering said.
But the following stages failed, with part falling in the Sea of Japan and the rest in the Pacific, he told the US Cable News Network.
"The fact that they did not get apparent separation of the payload from the second or third stage means that they have more work to do there in terms of being able to achieve that," he said.
"The bottom line is they are continuing to advance in their ranges and I think it's why it's important that we have the ability to defend against these types of threats," Obering said.
North Korea launched on Sunday a Taepodong-2 missile, which normally has three stages and an estimated range of 4,100 miles (6,700 kilometers).
On July 5, 2006, North test-fired seven missiles, including a long-range Taepodong-2 which explodes after 40 seconds
He said the other six launches succeeded, which amounted to a good sales pitch.
Anybody who "is willing to buy the missiles they would be willing to sell to," he said
"The one thing in their brochure they have not been able to demonstrate is the long-range missile," he added.
North Korea has sold hundreds of ballistic missiles to Iran, Syria and Pakistan over the last decade in a bid to obtain foreign exchange, according to a study commissioned by Congress in 2007.
In December 2002, 15 North Korean Scud missiles were seized from a ship headed for Yemen.
A number of experts said however that North Korea does not yet have the technology needed to equip a missile with a nuclear warhead.
Bacterium Eats Electricity, Farts Biogas
Bacteria that can convert electricity into methane could help solve one of the biggest problems with renewable energy – its unreliability compared to the steady output of polluting fossil-fuel power stations.
Wind power is capricious, while solar cell output drops off at night or on cloudy days. That fluctuating output poses big problems for electricity grids that rely on steady levels throughout the day. Proposals to deal with the ups and downs of green power supply have included better batteries or redesigning the electricity grid.
An intriguing new idea involves "feeding" surplus power to bacteria instead, which combine it with carbon dioxide to create methane. That could then be stored and burned when needed. The method is sustainable too, as the carbon is taken from the atmosphere, not released from long-term storage in oil or coal.
The new method relies on a bacterium discovered by Bruce Logan's team at Pennsylvania State University in University Park. When living on the cathode of an electrolytic cell, the organism can take in electrons and use their energy to convert carbon dioxide into methane.
[...]
Of the energy put into the system as electricity, 80% was eventually recovered when the methane was burned – a fairly high efficiency. "You don't get all the energy back, but that's a problem with any form of energy storage," says Curtis.
[...]
Logan is optimistic about the method's potential: "Commercial applications could be just a few years down the road," he says.
Curtis is also impressed. "If you have a windmill, say, you need a relatively simple way to store the energy. What I like about this method is it's simple, it's replicable and it's scalable."
Several similar techniques use bacteria to produce hydrogen fuel rather than methane. But the hydrogen economy is not here yet, Logan points out. "These methods are great, but hydrogen doesn't fit into our existing infrastructure. Methane does."
Beating Somali Pirates at Their Own Game
After hitting the headlines last year, successful pirate attacks have been on the wane in the early months of 2009, despite a failed attack on a British cruise ship earlier this month. Experts disagree about what has led to the reduction, with some suggesting that bad weather had played its part, but Rear Adm. Terry McKnight of the U.S. Navy attributes the "dramatic" reduction in the number of attacks to the deployment of a British warship, the Royal Navy frigate HMS Northumberland, and the coordinated task force of which she is part.
To wage today's battles against pirates who took control of 42 ships and captured 815 sailors last year, the Royal Navy is combining machines and methods forged during the Cold War with centuries-old naval warfare skills. The Royal Navy is also hitting back at pirates by using some of the pirates' own tricks.
[...]
To beat pirates in potentially violent showdowns, the Navy has adopted the pirates' tactics of using "mother ships" carrying fast boats to spring on opponents.
[...]
Warships assigned to piracy patrols rarely engage pirates on their own. They deploy specialized search-and-seizure teams, which in the Royal Navy consist of marines armed with rifles and machine guns, traveling in raider craft. It was one such team from the frigate HMS Cumberland that killed three pirates in a firefight last November.
[...]
What the world needed was a stable, democratic country in East Africa, with a stake in the piracy fight and the ability to detain, try and jail pirates. What the world needed, in fact, was Kenya. The United Kingdom, with close ties to its former colony, was the first to draw Kenya into the counter-piracy coalition in a legal capacity. Moses Wetang'ula, the Kenyan foreign minister, and Alan West, the British security minister, met at a piracy conference in Nairobi to initiate the agreement, and none too soon: Eight Somali pirates already were being held in a Kenyan jail, on soft legal grounds, after being captured by a British frigate.
The United States was quick to follow Britain's example. In January, the U.S. State Department signed a similar agreement with Kenya. "The lawyers are at work for the particulars," McKnight said, "and as soon as we get those mechanisms in place, then we will shift our operation." Instead of just reacting to pirates, McKnight's task force would go on the attack.
Sunday, April 5, 2009
Conficker Eye Chart & Open Source Conficker-C Scanner/Detector
Conficker (aka Downadup, Kido) is known to block access to over 100 anti-virus and security websites.
If you are blocked from loading the remote images in the first row of the top table above (AV/security sites) but not blocked from loading the remote images in the second row (websites of alternative operating systems) then your Windows PC may be infected by Conficker (or some other malicious software).
If you can see all six images in both rows of the top table, you are either not infected by Conficker, or you may be using a proxy server, in which case you will not be able to use this test to make an accurate determination, since Conficker will be unable to block you from viewing the AV/security sites.
----------------------------------------
http://isc.sans.org/diary.html?storyid=6130
SRI International's Malware Threat Center has released the code to their scanner/detector for Conficker's "C" version. The official locations are:
Conficker C P2P Detection Modules (SourceFire ported the SRI module to their SO rule interface):
Preprocessor: http://mtc.sri.com/Conficker/contrib/plugin.htmlConficker C Network Scanner:
SO Version: http://www.snort.org/vrt/tools/conficker-so-rules.tar.gz
Source Code: http://mtc.sri.com/Conficker/contrib/scanner.htmlIf any readers have used SRI's tools and want to comment about them, please use our contact form or login and use the comment feature below.
We want to again express our thanks to the team at SRI International for their ongoing analysis of the Conficker worm, as well as to all of the volunteers of the Conficker Working Group who continue to coordinate the mitigation of the worm's effects.
Zimbabwe Internet Taken Down by Diligent Painters
This is a brief update of our considerable downtime today (Monday 16 March) from about 2pm to 5:30pm. We are also announcing emergency maintenance that will take us offline from approximately 8pm to 10pm tomorrow (Tuesday 17th March).
Unfortunately every backup system including generators, UPS and routers were totally flummoxed by 2 painters painting the building where our satellite dish is housed. Being diligent men, they decided to remove a junction box to paint behind it. Unluckily that box belongs to Telecontract and houses a fiber optic cable joint connecting to ZOL. This took down not only ZOL, but many ISP connections on the same fiber.
We are operating on a temporary solution now, but to fully repair this damage Telecontract have advised us that they will have to redo the entire joint. This will take approximately 2 hours, and will be done at 8pm on Tuesday 17th March.
We apologize for any inconvenience caused. Sometimes human brilliance just shines through regardless of the best laid plans!
Best Regards, *The ZOL Crew*
Saturday, April 4, 2009
North Korea Rocket Launched, Debris Falls into the Pacific Ocean
North Korea launched a rocket Sunday, despite warnings from Japan, South Korea and the United States not to proceed.
The rocket, launched at 11:30 a.m. -- 0230 UTC, passed over Japan, with the first stage landing in the Sea of Japan and a booster falling in the Pacific. Japanese officials said no debris fell on its territory.
U.S. State Department spokesman Fred Lash confirmed the launch, saying Washington regarded it as a "provocative act." Washington said it would take immediate steps to let North Korea know it cannot threaten the security of others with impunity.
Japan's ambassador to the United Nations, Yukio Takasu, immediately submitted a letter to the Security Council requesting an urgent meeting. The time and date of the meeting will be announced later.
South Korea condemned the launch, calling it "reckless."
North Korea says it is a communications satellite launch. Pyongyang's neighbors and the United States believe the launch is being used as a test of the North's long-range ballistic missile capability.
Pyongyang missed its first chance at the controversial liftoff Saturday -- a move meteorologists blamed on bad weather conditions.
It had pledged to hold the launch between Saturday and Wednesday.
---------------------------------
At this point, most are reporting that the first stage rocket fell into the Sea of Japan and the second stage rocket fell into the Pacific Ocean..status of final stage / payload is unknown.
Taliban Begins Re-Opening Emerald Mines in Swat Region
Militants have begun reopening lucrative emerald mines which had been closed by the government, since they took full control of the poor but picturesque region in the north of the country under a controversial peace deal last month.
They are using revenue from the sale of the emeralds to help finance attacks on Nato forces in neighbouring Afghanistan, and to support their drive to extend harsh sharia, including public whippings and summary executions, into more regions of Pakistan.
Swat holds one of Asia's two largest-known deposits of high quality emeralds, from where the precious stones are smuggled to Jaipur, India, and transported to Bangkok, Switzerland and Israel. Here they are cut and polished into the lustrous gems that adorn the world's finest jewellery, sold to unsuspecting customers who have no idea that the money they are spending may end up financing the Taliban.
"We receive one third of the profit, the rest goes to the workers," Muslim Khan, the Taliban spokesman in Swat, told The Sunday Telegraph.
"We know that all the minerals have been created by Allah, the mighty and the merciful, for the benefit of his creatures. We should avail the opportunity."
The revelation that the Taliban are making huge profits from the emeralds will heighten fears among Pakistan's middle class that their country is on a slippery slope to religious zealotry and Islamic rule. Millions of ordinary Pakistanis are afraid of the slide towards anarchy that appears to have begun. Evidence of the militants' growing stranglehold emerged last week in a gruesome video showing a 17-year-old girl screaming as she is beaten by Islamic radicals in Swat.
The unlicensed trade in the region's emeralds provides the Taliban with cash to buy weapons for their struggle against Pakistan's secular government, just as the Taliban in Afghanistan has thrived on the proceeds of the opium trade.
Brig Mahmood Shah, the former chief of security for Pakistan's tribal areas, said: "The Taliban use drug money for jihad in Afghanistan. The same thing is now happening in Swat. Money from emeralds is sponsoring their so-called jihad."
The flow of emeralds promise to provide a rising stream of cash as the Taliban open more mines. Abdul Karim Shah, director of the Gems and Gemological Institute in Peshawar, estimated that the Taliban could already earn up to £2 million a year from the mines now operating, with more to come as emerald deposits potentially worth millions are tapped into.
One newly reopened mine, near the Swat capital, Mingora, had been sealed since 1998 because of a legal dispute between the government and a contractor. Now workers use picks and shovels to dig for emeralds, excavating dozens of new pits and creating a cratered landscape. "We have given instructions to workers to lessen the amount of destruction," said Wahidullah Khan, a Taliban soldier at the mine.
About 70 Taliban recently occupied another emerald mine in the Shangla district near Swat, a government mining official said. Taliban gunmen forced out local officials and hired their own workers, who were promised a 50 per cent share of the profits.
"They have engaged 1,000 people and the number is increasing," a Taliban commander said. "It is a great opportunity for the people, as there is so much poverty and unemployment here."
One of the workers who is benefiting, Shad Ali, 24, said: "I earn at least Rs1000 (£8) per day. When I find a stone during digging, I take it to the Taliban's office here. It's weighed there and my share of the price is given to me." He said the mine had proved a "blessing" to poor people in the area.
Emerald mines in Pakistan and Afghanistan are thought to contain nearly 10 per cent of the world total, and during the 1980s the mines of Swat yielded a quarter of a million carats of emeralds - worth £15 million in rough, uncut form.
A government mining official in the area, who is powerless to enforce the government's writ, said: "If the Taliban continue selling the emeralds they will become very strong and it will be impossible for the government to dislodge them."
MEP's Call for a Watch on the Watchers
Organisations tracking net use should themselves be monitored, say MEPs.
The Euro-MPs overwhelmingly backed a statement which called on governments to list internet watching organisations and report on what they do.
The reports would name and shame organisations carrying out illegal or disproportionate amounts of surveillance.
The MEPs want governments to rein in industry and criminal attempts to view digital communications.
The statement backed by the Euro-MPs drew attention to the risks citizens face as their web browsing habits are subject to greater surveillance by either companies or governments.
It recommended a recognition of the "danger of certain forms of internet surveillance and control aimed also at tracking every 'digital' step of an individual, with the aim of providing a profile of the user and of assigning 'scores'."
Those that overstep the permissions users grant, or break laws governing what can be done with personal data, should suffer penalties "proportionate to the infringements committed" said the politicians.
The MEPs also want greater attention paid to the consent agreements users have to click through before using websites. Often these lead to people relinquishing control over their private information, warned the statement.
Websites should also be scrutinised to ensure that requests to delete personal data are carried out thoroughly.
It also wanted governments to draw up well-defined lists of the circumstances in which websites will be asked to hand over personal data to law enforcement organisations.
The statement declared: "the overriding interest of protecting citizens' fundamental rights should determine the limits and precise circumstances under which such technologies may be used by public authorities or companies".
Finally, the text called on governments to do more to protect children from online abuse. It also wants the European Commission to combat hi-tech crime and ID theft.
North Korea Says Satellite Launch Coming 'Soon', But Winds May Cause Delay
Strong winds may have done what a flurry of diplomacy couldn't: stop North Korea from launching a rocket the U.S. and other nations suspect is a cover for a long-range missile test, at least for a day.
Preparations for sending "an experimental communications satellite" into space were complete, North Korea's state-run media said Saturday morning, announcing: "The satellite will be launched soon."
But winds around the launch site in northeastern North Korea were "relatively strong," state radio announced at midday, possibly too high for the launch of the long-range Taepodong-2 rocket, analysts said.
"Apart from being very cautious, North Korea may have put off the launch purely due to weather factors such as strong winds," said Atsuhito Isozaki, an assistant professor of North Korean politics at Japan's Keio University.
With all eyes on the Musudan-ri launch pad — from missile interceptors in the waters, spy planes in the air and war rooms in Tokyo, Seoul and Washington — North Korea may also have wanted to keep the world guessing, said Koh Yu-hwan of Seoul's Dongguk University.
For weeks since North Korea announced its intention to send a satellite into space aboard a long-range rocket, diplomats from five nations seeking to disarm the rogue state of nuclear weapons have pressed the North to refrain from a launch they say violates a U.N. resolution barring Pyongyang from ballistic activity.
Friday, April 3, 2009
Public Search Engines Mine Private Facebook Details
Another reason to be careful what you post on Facebook: All it takes is a simple Google search, and phishers and marketers can glean a treasure trove of private information based on relationships among Facebook "friends," according to new research.
Researchers from the U.K.'s University of Cambridge recently published a paper (PDF) detailing a project in which they developed a software tool to correlate and map Facebook profiles they found via public search engines, such as Google, to build detailed maps of relationships among Facebook members.
"We focused on inferring information about a whole social graph...lists of every person and the connections between them," such as group memberships they had in common or geographic ties, says Joseph Bonneau, one of the project's researchers.
Bonneau says marketers typically look online for the "best-connected" people who can influence others, so this type of information could be used to target them. And phishers or identity thieves could capitalize on this data, as well, according to the Cambridge research.
"You could do targeted phishing attacks if you knew people's [Facebook] friends and claim to be their friend," Bonneau says.
White Stripes Hip-Hop Mashup Concept Album - Free Download
I was late jumping on The White Stripes bandwagon. But, when I heard "Doorbell" a few years back I became an instant fan. That raw, classic sound was so fresh to me. I went straight to iTunes and downloaded the whole album. It wasn't long before I owned everything they'd ever released.
What really got me was that I wanted to sample almost every song. But, I couldn't just shamelessly sample their whole catalog. Plus, I had just decided to move away from sampling and focus on writing original music. So, a remix project seemed like the thing to do, and the idea was born.
I started digging through my collection and fitting all the pieces together. My goal was to use only samples from The White Stripes and a cappellas from classic songs and my favorite emcees. And of course, I had to rap on one of the tracks myself, with my man Brian Jacobs on the hook.
So there it is, hip-hop fans, meet The White Stripes.
Fans of The White Stripes, meet hip-hop.
— Adrian Champion
---------------------------------------
Big props to Adrian. This shit is hot...
Fat Tag - Open Source Tagging for the iPhone
A simple graffiti tagging app with accelerometer based dripping paint.
Will update as soon as it has been approved and is available on the app store.
Double tap to clear.
Hit triangle tab to change paint / background color.
Supports multiple strokes.
Enjoy!
Feedback welcome!
A Free Art & Technology project.
FFFFFAT LABS / Muonics 2009
Made with openFrameworks!
Source Code will be posted soon of course :)
North Korea’s Teapodong-2 Unha Missile Launch: What Might We Learn?
Indications are that North Korea is moving ahead with its planned launch of a missile with the intent of placing a satellite into orbit. The North Koreans are portraying the launch in purely innocuous, civilian terms even naming the rocket “Unha,” which means “Milky Way” in Korean, to emphasize its space-oriented function. In the West, the rocket is called the Taepodong-2 and is thought to be a long-range (but not truly intercontinental range) ballistic missile.
Even if the rocket launches a satellite, and recent news reports say the payload sections seems to be shaped and sized for a satellite, it would be an important step in their military ballistic missile program. In the early days of the Soviet and American space programs, there was little distinction between military and civilian rocket development and the same would be true of North Korea’s upcoming launch. What I want to discuss in this essay is the question of how much can the outside world learn if the North Korean test goes through, what does it tell us about their ballistic missile capability?
-------------------
Check out the full blog via the link above...
OWASP Code Review Guide v1.1
The Code review guide is proudly sponsored by the OWASP Summer of Code (SoC) 2008. For more information please see OWASP Summer of Code 2008.
PowerPoint Unspecified Code Execution Vulnerability (0-Day)
Microsoft is investigating new reports of a vulnerability in Microsoft Office PowerPoint that could allow remote code execution if a user opens a specially crafted PowerPoint file. At this time, we are aware only of limited and targeted attacks that attempt to use this vulnerability.
We are actively working with partners in our Microsoft Active Protections Program (MAPP) and our Microsoft Security Response Alliance (MSRA) program to provide information that they can use to provide broader protections to customers.
Microsoft will take the appropriate action to protect our customers, which may include providing a solution through our monthly security update release process, or an out-of-cycle security update, depending on customer needs.
-------------------------------
CVE Reference: CVE-2009-0556
Secunia Security Advisory - http://secunia.com/advisories/34572/
Thursday, April 2, 2009
Time Warner Cable Bandwidth Caps Coming To More Cities
Bandwidth hogs, beware: Time Warner Cable is rolling out bandwidth caps and overage charges to more cities.
The cable company has been testing 'consumption-based' billing in Beaumont, Texas. And they will expand the program to more cities this year, COO Landel Hobbs said on this morning's Q4 earnings call. (Without offering details.)
This is different than how consumers are overwhelmingly used to paying for Internet access -- all-you-can eat service for a flat monthly fee, whether they use the Internet a little or a lot.
Will consumers put up with this? That depends on what Time Warner Cable decides will be its monthly allotment and how much it plans to charge for overages.
In Beaumont, it'd been testing caps of 40 gigabytes per month. That's less than it sounds, especially as companies like Apple (AAPL) and Netflix (NFLX) increasingly offer hi-def movie services. (A hi-def movie can take up about 4 gigabytes.)
We think Comcast's (CMCSA) caps are more reasonable -- about 250 gigabytes per month. But Comcast is mostly trying to manage its network and weed out pirates. Time Warner Cable seems to be looking for new revenue growth areas as subscriber growth slows.
If it works, that's good news for shareholders. The danger: That ticked-off consumers faced with overage charges for Internet video usage will ditch Time Warner for competitors that don't currently cap bandwidth, such as Verizon (VZ).
Or that regulators will get suspicious that the cable company is squashing competition from online video by giving subscribers an unreasonable disincentive not to use it. (Though they probably can't do anything about it.)
The irony here: Time Warner Cable is the only major U.S. Internet service provider to back Fon, a Spanish wi-fi startup that encourages you to share (or sell) your Internet access. Yet with consumption-based billing, subscribers will have to secure their Internet connection as best as possible to avoid paying overage fees for service that others are borrowing.
---------------------------------
Time Warner Cable Road Runner Bandwidth Cap Petition
http://www.petitiononline.com/nocap/petition.html
Interpol Warns on Use of False Passports
The head of Interpol urged governments to do more checking on lost and stolen passports, warning they could be used to smuggle terrorists into countries in the Americas.
The agency's secretary general, Ronald Noble, told the opening of the Americas Interpol conference that too few passports are reported as lost or stolen — and too few are checked against international databases of missing documents when travelers cross borders.
He said that Central American countries "have become the main transit point for Iraqis being smuggled into the United States," with Interpol tracking 74 cases of Iraqis traveling with fraudulent passports from various European countries. Only 24 of those documents had been reported to Interpol as lost or stolen.
Noble said that only one of every three of travelers entering American nations in 2008 had their passports checked against Interpol's database of stolen or lost travel documents.
"Think about how simple if would be for al-Qaida terrorists to slip into or through your countries in order to plan and carry out the same kind of deadly terrorist attacks that occur far too frequently in Iraq," Noble told the 60 senior police officers from around the Americas attending the three-day conference.
Noble did not specify what sort of Iraqis were being smuggled. Mexican officials say many of those found in their country are Iraqi Christians trying to reach relatives in the United States.
Noble also said it is easy to imagine street gangs and terrorist networks jointly exploiting each others money, manpower and local knowledge, though he said reports of such collaboration have not been confirmed.
He noted that cocaine trafficking is used to finance both the Revolutionary Armed Forces of Colombia and Hezbollah.
New Form of Illegal Self-Expression
A new form of graffiti is popping up around Houston, one that has nothing to do with spray paint.
It's called "wheat pasting," so named because of the paste used to plaster traffic signal boxes and other vertical surfaces with large sheets of paper which are pre-printed with the artist's message.
"That's something new that's just come into Houston," said Martin Chavez, who runs the graffiti abatement program for the Greater East End Management District.
"But we are starting to come across it right now; within the last 6 months we've seen an increase."
A street artist who goes by the name "Give Up" has been putting his message on billboards, often during the middle of the day, in full view of the public and patrolling police officers.
To anyone observing, it looked as if the illegal street artist was supposed to be there, changing out the billboard.
"I don't think they really pay any attention to this," said "Give Up," as he posted one of his recent messages, picturing a huge razor blade over his street name.
FOX 26 News obtained video of "Give Up" in the act of "wheat pasting" from a filmmaker who is producing a documentary on Houston's illegal street art scene.
"Stick Em Up" also interviews a former graffiti artist who calls himself "GONZO247." He told FOX 26 News he no longer does illegal street art, but he won't condemn "Give Up" for doing it.
"I don't want to see a McDonald's billboard," he said. "I'd rather see art on billboards."
But Houston city councilmember Sue Lovell points out that the city spends about a million dollars a year cleaning up graffiti.
"You know the bottom line on graffiti is, if it is not your property you can't do it; you're breaking the law," Lovell said.
-------------------------------------
Stick em Up! - Documentary of Houston's Illegal Street Art Movement -
http://stickemuphouston.blogspot.com/
Wednesday, April 1, 2009
In Pakistan, US Drone Strike on Taliban Kills 12
Two missiles fired from a suspected US drone killed at least 12 people and wounded several more in Pakistan's tribal region yesterday.
The missiles hit a building believed to be a Taliban safehouse in Orakzai, close to the Afghan border. According to reports, militants sealed off the building immediately afterwards.
The attack by an unmanned Predator aircraft was targeted at Hakimullah Mehsud, a commander in the Pakistani Taliban, a Pakistani intelligence official said. But he escaped the American missiles. "He wasn't there, but we wish he was," added the official.
The attack came a day after Baitullah Mehsud, the leader of the Pakistani Taliban, claimed responsibility for Monday's assault on a Lahore policy training facility in which eight police cadets and several militants were killed. Mehsud said the offensive had been in retaliation for Predator strikes
In recent months US forces have targeted al-Qaida and Taliban leaders in their hideouts, mostly in North and South Waziristan and Bajaur tribal agencies, using Predators armed with Hellfire missiles. Since last August an estimated 34 such attacks have killed about 340 people, including some senior commanders.
But the drones have also taken a heavy toll on Pakistani public opinion, causing widespread anger over a perceived breach of sovereignty. About 150 elders protested the strikes in the town of Tank, near South Waziristan yesterday.
The Pakistani government publicly denounces the drone strikes but provides tacit support for their execution, including the use of army bases inside the tribal areas by CIA agents.
Yeast-Powered Fuel Cell Feeds on Human Blood
Yeast cells feeding on the glucose in human blood might one day power implants such as pacemakers. A living source of power that is able to regenerate itself would eliminate the need for regular operations to replace batteries.
Now that reality is a step nearer. A team at the University of British Columbia in Vancouver, Canada, has created tiny microbial fuel cells by encapsulating yeast cells in a flexible capsule. They went on to show the fuel cells can generate power from a drop of human blood plasma.
Such fuel cells would be especially useful for devices, such as intraspinal microelectrodes for treating paralysis, which need to be implanted in places where replacing a battery is tricky, says Mu Chiao, who co-authored the paper with Chin-Pang-Billy Siu, also at UBC.
[...]
The yeast-based fuel cell produces around 40 nanowatts of power, compared to the microwatt a typical wristwatch battery might produce, Chaio says. That might be enough power for some devices if it were coupled with a capacitor to allow energy to be stored. The yeast could also be genetically engineered to boost its power output.
This is a step in the right direction, but huge challenges remain, says Lars Angenent, who works on microbial fuel cells at Cornell University.
For instance, to keep the yeast cells healthy, their waste products will need to be removed without allowing any harmful substances to leach out into the blood stream. "I think people will figure this out. This is a first step," he says.
------------------------
Big heads to my friend, Dubbie Acuña, for the link. Besides being a long-time member of Los Pasteles Verdes, Dubbie enjoys working on other musical projects including Mama Cesta.When not playing music or getting paid for computer nerdery...he can be found eating tofu pho @ Pho 99 in Northern VA on a pretty regular basis.
HP WebInspect 8.0 - Available Now!
What's New
- Flash Static Analysis [ActionScript 2 & 3]
- New Reporting System
- Optional Depth First Crawler
- Java Model View Control (MVC) Support
- Integration with IBM Rational ClearQuest
- Support for 64-bit Vista
- Significantly Improved Script Processing
- Revamped Web Macro Recorder
- Smart Assessment Fingerprinting
- Improvements to Start Page
- Improvements to Scan View
GhostNet or Gh0st RAT: The Cyber Persecution of Tibet
For many members of the non-security research community, the New York Times story this week was big news: "Vast Spy System Loots Computers in 103 Countries". This morning's Google News has more than 750 related articles, and I applaud the work of the University of Toronto's Citizen Lab at the Monk Centre for International Studies at Trinity College for the excellent research and for sharing this story with the general public.
What does it look like to a Security Researcher though? Unfortunately, its a very common story of a very simple case of Spear Phishing that can be accomplished with minimal effort and *IS* being accomplished on a daily basis against various special interests, including government agencies, military contractors, or just people who might have a lot of money to steal. As I've discussed in my presentations on Spear Phishing, including at the 2008 Department of Defense Cyber Crime conference, high-value targets deserve special targeting.
------------------------
Check out his full blog...good stuff indeed.
Attack Of The Mini-Botnets
Via DarkReading -
Big-name botnets like Kraken/Bobax, Srizbi, Rustock, the former Storm -- and even the possible botnet-in-waiting, Conficker -- have gained plenty of notoriety, but it's the smaller and less conspicuous ones you can't see that are doing the most damage in the enterprise.
These mini-botnets range in size from tens to thousands versus the hundreds of thousands, or even millions, of bots that the biggest botnets deploy. They are typically specialized and built to target an organization or person, stealing corporate and personal information, often without a trace. They don't attract the attention of the big spamming botnets that cast a wide net and generate lots of traffic; instead they strike quietly, under the radar.
"There's definitely specialization [in botnets] these days," says Joe Stewart, senior director of malware research for SecureWorks. "There are botnets designed for fraud, and they have been around for a while and don't seem to cross over [with the bigger spamming botnets]," he says.
These mini-botnets specialize in identity theft, fraud, and stealing corporate information, and are much more difficult to spot and infiltrate than a big spamming botnet. "We have to rely on the few anecdotal instances, where we've managed to get a look at the back-end," Stewart says.
[...]
The main goal of specialized botnets is to steal user names and passwords, banking credentials, intellectual property, and other valuable information, he says. "We've seen them target banking credentials used by the enterprise to conduct corporate banking," Cox says. "We've also seen particular executives targeted who are involved in intellectual property development and research activities.
"There's a strong tie there between what information the [targeted] employee has access to and the value that asset has to the attacker."
SecureWorks' Stewart says small botnets are more worrisome than Conficker's next move. These botnets include Clampi (a.k.a. Ligats and Rscan), Torpig (a.k.a. Sinowal, Anserin), Zeus (a.k.a. prg/zbot), Pinch (a.k.a. ldpinch), and SilentBanker Cimuz -- all named after the malware they use -- plus one that has been around for some time, Coreflood (a.k.a. Afcore), which Stewart has studied closely. "I am far more worried about some of the recent Clampi [activities] and some of the other ones," Stewart says. "They have made inroads to affect users and do something malicious, like steal their credentials" for committing identity theft and fraud, he says.
[...]
Steven Adair, a researcher with the Shadowserver Foundation, says his organization has seen targeted botnet attacks that have used anywhere from dozens to hundreds or more machines. "They are often a lot smaller than the spamming and DDoS botnets due to their target selection," Adair says.
These targeted botnet attacks often use spear-phishing email attacks, using malicious PDF attachments or links that appear legitimate because they contain information familiar to the user. Shadowserver has also seen mini-botnets infect Websites that cater to a specific group of users, Adair says. "The sites were specifically chosen due to their audience," he says.