Wednesday, July 22, 2009

Adobe Reader, Acrobat and Flash Player Vulnerability

Via US CERT -

Adobe has released a blog post indicating that it is aware of reports of a vulnerability affecting Adobe Reader and Acrobat 9.1.2 and Flash Player 9 and 10.

US-CERT encourages users and administrators to review the blog post and implement the following workarounds until the vendor releases additional information:
  • Disable Flash in Adobe Reader 9 on Windows platforms by renaming the following files: "%ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll" and "%ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll".
  • Disable Flash Player or selectively enable Flash content as described in the Securing Your Web Browser Document.
Additional information regarding this vulnerability can be found in the Vulnerability Notes Database.

US-CERT will provide additional information as it becomes available.

Russian Intelligence Granted New Powers Over Citizens

Via Jamestown Foundation -

On July 6, the Russian ministry of communications posted its Order 65, on its official website (www.minkomsvjaz.ru). Effective as of July 21, the order decrees that Russian postal services must make available for inspection on demand to the Federal Security Service (the FSB, the main successor to the Soviet KGB) and seven other Russian security service agencies any private mail or shipments, as well as its exhaustive data on senders and addressees. Special rooms where security officers will be able to open and inspect private mail were decreed to be established at post offices. Order 65 also cancels the privacy of electronic correspondence. Operators will now formally grant the security services access to their electronic databases.

Though Soviet or Russian security services never hesitated to intercept, monitor, inspect or confiscate private correspondence, nothing like Order 65 has ever occurred openly, formally or so blatantly -not even under Soviet rule.

Order 65 is in manifest contravention of the 1966 International Covenant on Civil and Political Rights (ICCPR), a United Nations treaty, based on the Universal Declaration of Human Rights -Russia is a signatory to both. It is also in contravention of Article 23 of the Russian constitution, which proclaims the complete privacy of telephone, postal and other communications and states unequivocally that this privacy can be lifted solely on the authority of the courts.

However, Order 65 contains no reference to making private correspondence available to the security services on the strength of a court decision. The Order leaves such decisions at the discretion of the security services. In 2000 and 2007 the Russian supreme court (and also in 2003 in the constitutional court) upheld Article 23 of the constitution, and ruled that mail operators could not disclose private correspondence or telephone communications to the security services, without first securing a court order (www.newsru.com, July 15).

Yuri Vdovin, a prominent St. Petersburg's based human rights activist, told the Echo Moskvy Radio that Order 65 signifies a decisive step towards a totalitarian state. Unless this is revoked, Vdovin maintains, the next steps will include unlawful detentions and searches. Vdovin believes that the authorities are seeking ways to prevent possible social unrest, and take under their control any structures that might emerge in order "not to let the people speak their mind" (www.newsru.com, July 15).

At the same time as this secret police surveillance of correspondence was openly decreed, the ministry of the interior (the MVD) were setting up special regional task forces to keep track of public attitudes, in an effort to prevent public protests, caused by the worsening economic situation in Russia. Interior Minister Rashid Nurgaliyev told the press that he expected this effort to allow the police and authorities to work preemptively and prevent an escalation of protests during the economic crisis. Nurgaliyev wants incoming evidence of growing social tension to be analyzed. If economic factors are deemed responsible, police will inform local officials and the government in order to launch preventive measures jointly, and keep any potential unrest under control (www.theotherrussia.org, July 15).

To complement this massive gathering of information, the MVD is also strengthening its already considerable forces to act on the basis of the information obtained. In the Moscow suburbs, they are now forming a new elite brigade named "avant-garde," which will specialize in maintaining public order during large-scale demonstrations. The force is expected to deploy across the country at short notice (www.theotherrussia.org, July 15).

These latest steps form a new chapter in Russia's progression towards a totalitarian state, and they logically complement previous punitive measures, launched by the Putin government, previously highlighted by the Jamestown Foundation (EDM, January 5). Some Russian experts now estimate the total strength of the MVD and other security forces at 2.5 million, which are assigned to crush the projected domestic protests. They see this process as a crisis demanding the militarization of the state (www.newsru.com, July 14).

Osama Bin Laden's Son Thought Killed in Predator Strike

Via The Long War Journal -

Sa'ad bin Laden, the son of Osama bin Laden, is thought to have been killed in a US Predator airstrike in Pakistan's tribal areas. The report has not been confirmed.

Sa'ad is thought to have been killed during a strike earlier this year, US intelligence officials told The Long War Journal.

"We're pretty sure but we're not certain," one official said. "We are hopeful."

US intelligence officials want to confirm or deny Sa'ad's death by using DNA testing. But it is unclear if they have recovered a body from the attack site.

The officials would not identify the date or the location of the airstrike that is thought to have killed Sa'ad. The covert US air campaign has focused heavily on North and South Waziristan. Fifty percent of the attacks occurred in South Waziristan, and 38 percent took place in North Waziristan, according to data compiled by The Long War Journal. The US has killed a total of 22 High Value Targets, which include some of the high- and mid-level Taliban and al Qaeda leadership in the tribal agencies since the first strike was reported back in June 2004 [see LWJ report, US Predator strikes in Pakistan: Observations].

Al Qaeda has neither confirmed nor denied Sa'ad's death. Al Qaeda typically issues a martyrdom statement for senior leaders and commanders who have been killed in battle.

Sa'ad is considered a senior leader in al Qaeda. He is an operational commander who was involved in the 2003 bombings in Riyadh, Saudi Arabia. He is known to shelter in Iran and move back and forth across the border with Pakistan.

He is reported to have facilitated communications between Ayman al Zawahiri and Qods Force, the notorious special operations branch of the Iranian Revolutionary Guards Corps, in September 2008 after the deadly attack on the US embassy in Yemen.

Sa'ad made "key decisions for al Qaeda and was part of a small group of al Qaeda members that was involved in managing the terrorist organization from Iran," according to the US Treasury report that designated him as a terrorist on Jan. 16, 2009. "As of September 2008, it was possible that Sa'ad bin Laden was no longer in Iranian custody," the Treasury reported.

Sa'ad is believed to have entered Pakistan’s northwest to meet with Zawahiri in Pakistan sometime in early September, according to Mike McConnell, the outgoing Director of National Intelligence.

NSA Using Cloud Model For Intelligence Sharing

Via InformationWeek -

The National Security Agency is taking a cloud computing approach in developing a new collaborative intelligence gathering system that will link disparate intelligence databases.

The system, currently in testing, will be geographically distributed in data centers around the country, and it will hold "essentially every kind of data there is," said Randy Garrett, director of technology for NSA's integrated intelligence program, at a cloud computing symposium last week at the National Defense University's Information Resources Management College.

The system will house streaming data, unstructured text, large files, and other forms of intelligence data. Analysts will be able to add metadata and tags that, among other things, designate how securely information is to be handled and how widely it gets disseminated. For end users, the system will come with search, discovery, collaboration, correlation, and analysis tools.

The intelligence agency is using the Hadoop file system, an implementation of Google's MapReduce parallel processing system, to make it easier to "rapidly reconfigure data" and for Hadoop's ability to scale.

The NSA's decision to use cloud computing technologies wasn't about cutting costs or seeking innovation for innovation's sake; rather, cloud computing was seen as a way to enable new scenarios and unprecedented scalability, Garrett said. "The object is to do things that were essentially impossible before," he said.

NSA's challenge has been to provide vast amounts of real-time data gathered from intelligence agencies, military branches, and other sources of intelligence to authorized users based on different access privileges. Federal agencies have their own systems for sharing information, but many remain disconnected, while community-wide systems like Intellipedia require significant user input to be helpful.

The NSA effort is part of Intelligence Community Directive 501, an effort to overhaul intelligence sharing proposed under the Bush administration. Current director of national intelligence Dennis Blair has promised that intelligence sharing will remain a priority.

"The legacy systems must be modernized and consolidated to allow for data to actually be shared across an enterprise, and the organizations that collect intelligence must be trained and incentivized to distribute it widely," he said in response to questions from the Senate prior to his confirmation.

The new system will run on commodity hardware and "largely" on commercial software, Garrett said. The NSA will manage the arrayed servers as a pool of resources rather than as individual machines.

Deutsche Bank Fires Two as Possible Inquiry Looms

Via NYTimes -

Two executives have been fired at Deutsche Bank as prosecutors consider whether to open a criminal inquiry into surveillance measures conducted against board members and a shareholder advocate.

The executives fired were Wolfram Schmitt, head of investor relations, and Rafael Schenz, German security chief, a person with direct knowledge of the matter said on Tuesday. The person was not authorized to speak on the record and declined to be named.

The bank had ordered an internal review of possible violations of privacy laws in May, after several cases came to light. On Monday, the data protection agency for Hesse, the state where Deutsche Bank is based, said it had forwarded the case to state prosecutors in Frankfurt, after reviewing a preliminary report by the independent law firm Cleary Gottlieb Steen & Hamilton, which had been hired by the bank to conduct the review.

Doris Möeller-Scheu, a prosecutor and spokeswoman for the Frankfurt prosecutor’s office, said the office had received a “very big dossier” and would need about three weeks to decide whether a criminal investigation was warranted.

Ronald Weichert, head of media relations at Deutsche, said the bank could not comment until the report on its internal investigation was finished.

In May, the bank issued a statement saying that it had “learned about possible violations which occurred in past years of the bank’s internal procedures or legal requirements in connection with activities involving the bank’s corporate security department.”

The dismissal of Mr. Schmitt stems from the case of Michael Bohndorf, a shareholder with a history of litigation against the bank who was known to ask critical questions at its shareholder meetings.

After a shareholder’s meeting in 2006, Deutsche Bank hired private investigators to spy on Mr. Bohndorf, posing as vacationers to rent his house in Ibiza and trying to establish a link between him and Leo Kirch, a media tycoon who had waged a legal battle against the bank accusing it of provoking the collapse of some of his companies.

Around that same time, private investigators tested the security measures that Deutsche’s chief operating officer, Hermann-Josef Lamberti, took to protect himself from being tracked and bugged. Detectives tried to plant a GPS device on his car and to smuggle an inactive listening device into his house with a flower delivery.

Chinese News Sites Go Down After Reports on Gov't Scandal

Via cio.com -

Two of China's most popular technology news Web sites went offline Tuesday after carrying news reports that linked the son of China's president to a corrupt African deal.

The technology news sections disappeared for several hours from major Chinese portals Sina.com.cn and NetEase.com early Tuesday afternoon, when they started redirecting viewers to general news pages. Both tech sections had carried reports on a state-owned company accused of bribing Namibian officials in the last day, but those reports were missing when the Web pages reappeared.

The suspensions appeared to be a government penalty against the companies for reporting on a sensitive political issue.

"I'm impressed by the bravery of Sina and Netease in attempting to report this at all," said Rebecca MacKinnon, a Hong Kong-based expert on the Internet in China, in an online message.

Information on top leaders' children has always been off-limits in Chinese media, though the Internet has made it more difficult to control discussions on such topics, MacKinnon said.

Chinese police heavily patrol the Internet, and Internet companies run rigorous screening to prevent sensitive information from appearing on user forums or in search results on their sites. Companies can be punished if that process fails to catch certain political or pornographic content.

"This is not particularly surprising or different from long-standing censorship patterns," MacKinnon said.

A story posted on the NetEase tech page the night before its suspension cited English broadcaster BBC as saying that Nuctech, a Chinese company, was suspected of bribery in a deal to provide scanners for airports and ports in Namibia. The BBC report had said Namibian authorities wanted to question Hu Haifeng, the former company president and son of Chinese president Hu Jintao, but did not suspect him in the case.

The NetEase story did not mention Hu, but said Namibia wanted to question "relevant" Nuctech executives.

Sina's tech page carried a similar article the next morning, hours before the sites went down. After the tech sections returned to the portals, visiting the URLs of the scandal reports returned messages that they could not be found or had been deleted.

An employee who answered the phone at NetEase Tuesday said its tech section was down for tests. Sina did not respond to a request for comment.

Nuctech's parent company, Tsinghua Holdings, controls a range of other technology companies including Chinese PC maker Tsinghua Tongfang.

Tuesday, July 21, 2009

Vordel SOAPBox is Now Free!

http://www.vordel.com/products/soapbox/

Vordel SOAPbox allows developers to test the performance, scalability, and security of Web Services. Using SOAPbox, a developer can test how Web Services perform under load, how they deal with unexpected input, and what their traffic ceiling is.

Vordel SOAPbox highlights security tokens, XML Signatures, and encrypted content in XML documents. SOAPbox supports established security technologies such as SSL and HTTP-Auth, as well as next-generation security technologies such as WS-Security and SAML.

-------------------------

My team has been using this tool for quite some time...and it was worth the money.

But now it is free. Just input your e-mail...and download.

Vordel has made an attempt to block the use of free e-mail accounts (i.e. Mailinator) but they forgot to include the alternative mailinator domains, like sogetthis.com ;)

GAO: Many Federal Agencies Still Don't Meet Security Standards

Via DarkReading -

Virtually all of the U.S. federal government's key civilian agencies are still falling short of the security marks they have been asked to meet, according to the Government Accountability Office (GAO).

In a report (PDF) issued earlier today, the GAO says of the 24 agencies reviewed, almost all had deficiencies in security controls and management, "leaving them vulnerable to attack or compromise." The GAO says it has made "hundreds" of recommendations to the agencies, yet many have not been addressed.

During the past three years, the number of incidents reported by federal agencies to U.S.-CERT has increased by almost 200 percent -- from 5,503 in 2006 to 16,843 in 2008, according to the report. More than one-third of the incidents are still under investigation, and the sources of the compromises are not yet known.

Of the incidents in which the sources are known, approximately 22 percent were caused by improper use of computers by authorized users, the report states. Eighteen percent of the compromises were caused by unauthorized access, and 14 percent were caused by malicious code. About 12 percent of the breaches were caused by scans, probes, or attempted access by external attackers, the report says.

Of the 24 agencies reviewed, 13 reported "significant deficiencies" in information security, the GAO says. Seven agencies reported "material weaknesses" that still have not been repaired. Only four agencies reported "no significant weakness," the report states.

Indonesian TV Identifies Another Jakarta Hotel Bomber

Via xinhuanet.com -

An Indonesian television on Tuesday evening unveiled identity of another suicide bomber at Ritz Carlton Hotel as Ibrahim, a florist at the hotel, who conducted his action on Friday along with fellow Nurhasbi at JW Marriott Hotel in Jakarta.

Based on the cctv record seconds before the blast at 07:47 at Erlangga restaurant at Ritz Carlton Hotel, a man suspected as Ibrahim of 36, walked unsteadily carrying a black bag which seems very heavy, Metro television said.


The whereabouts of Ibrahim has been unknown since the bombings at the two luxurious hotels which located opposite each other on July 17 that killed nine people and wounded 55 others, half of them foreigners. The police conducted DNA test to make sure the body of Ibrahim.


Based on the hotel presentation list Ibrahim was working on Friday morning, the day of the bombings.


He called his family before the blasts.


After the bombings, his family had looked for him at some hospitals where the victims of the explosions were being treated.


Police are identifying parts of bodies found at the scene, but it is still unknown yet whether one of them is belonging to Ibrahim.


The perpetrators of the bombings assembled the bombs at room 1808 at JW Marriott Hotel. They ordered the room on July 10 and occupied it at 15:01 Jakarta time (0901 GMT) on July 15, two days before conducting their deadly acts. Police found active bomb in a black laptop computer bag after the blasts.


The police have found similarities in equipment and method of the bombs with those detonated in Bali in 2002 and 2005, and that found in recent raid in Cilacap of Central Java, in which the regional militant network of Jemaah Islamiyah was responsible.


Police widens investigation on the group.


The blasts in JW Marriott Hotel and Ritz Carlton Hotel in Jakarta's main business district occurred after four-years absence of major terrorist acts in the country.


Indonesia had been attacked by a series of terrorist attacks from 2000 to 2005, including Bali bombings, the JW Marriott explosion and the Australian embassy bombings in Jakarta that killed more than 250 people.


The police and analysts said that the bombings in the two hotels were led by a breakaway of Jemaah Islamiyah led by Malaysian fugitive Noordin Moh Top, who had organized the major bombings in Indonesia, targeting foreigners and facilities. He has been main target of the police.

Monday, July 20, 2009

U.S. Steps Up Pressure on 'The Company' - Leaders of Los Zetas

Via Yahoo! News (AP) -

The Department of State offered up to $50 million Monday for information leading to the arrests of 10 top Mexican drug suspects accused of key roles in a violent organization estimated to have sold more than $1 billion worth of drugs in the United States.

U.S. Attorney Benton J. Campbell said the reward money and new federal charges were among U.S. efforts to dismantle a powerful drug trafficking organization known as The Company, whose members came from an elite security force called Los Zetas.

The only name on an indictment unsealed in federal court in Brooklyn was Miguel Trevino-Morales, a fugitive charged with operating a continuing criminal enterprise, international cocaine distribution and firearms violations. The indictment also sought the forfeiture of $1 billion in drug proceeds.

Campbell said in a release that Trevino-Morales, who could face life in prison if convicted, was the principal leader of Los Zetas, a group that includes former members of the Air Mobile Special Forces Group of the Mexican military who went into the drug-smuggling business.

In Washington, the Department of State announced it was offering a total of $50 million for tips leading to the capture of the defendants, including four leaders who were designated as narcotics kingpins by the U.S. Department of the Treasury's Office of Foreign Assets Control.

The government said it was offering up to $5 million apiece for information leading to the arrests of 10 people, one of whom has been captured.

Nineteen defendants have been charged in an indictment in federal court in Washington with drug trafficking-related crimes, and others are charged in indictments in federal court in Houston.

"The joint efforts announced today are significant steps in the department's strategy to stop the flow of illegal drugs into our communities and the shipment of drug proceeds back to Mexico," Campbell said.

Assistant Attorney General Lanny A. Breuer said the actions taken Monday will at least make it more difficult for the drug dealers to move cash around.

"We have learned that the most effective way to disrupt and dismantle criminal organizations is to prosecute their leaders and seize their funding," she said in a release. "We stand shoulder-to-shoulder with our brave Mexican colleagues in the fight against these destructive cartels."

The Foreign Narcotics Kingpin Designation Act, which became law in 1999, prohibits all trade and transactions between U.S. companies and individuals and significant foreign narcotics traffickers, their organizations and associates who act on their behalf.

Fewer than 100 people have been designated narcotics kingpins since the first major targets were announced in June 2000.

The indictment unsealed in Brooklyn said the drug organization, formerly known as the Gulf Cartel, had become the dominant force in the drug trade along the Gulf of Mexico, transporting multi-ton quantities of cocaine each month from Mexico to Texas after obtaining it in Guatemala, Colombia, Venezuela and elsewhere.

XMLHTTPReqest “Ping” Sweeping in Firefox 3.5+

Via ha.ckers.org (Rsnake) -

Jeremiah brought my attention to the new Firefox 3.5+ CORS (Cross-Origin Resource Sharing) which is a way to do a cross domain XMLHTTPReqest. Does that sound scary? Well, it is, but there’s been a ton of work into hardening it. It has all sorts of cross domain opt-in verification built into it to limit the abuse. Honestly, if you look at the people who were acknowledged in it’s construction, it’s a who’s who of people who understand cross domain browser security issues. So it wasn’t surprising that it was fairly free of obvious flaws.

Anyway, I was poking around with it and I noticed that it had one fairly strange issue. Although an attacker is not allowed to know if the page was there or not (only if it was allowed to see the content or not), the attacker is still allowed to make an initial request. In doing so that initial request can be used as a pseudo “ping” sweep. You can tell if the site is there or not because it will either return immediately (latency and threading applies) or it will wait around much longer (between 20-75 seconds on the several networks I’ve run this on) before the browser gives up. That timing difference is pretty substantial - and as a result you can enumerate a substantial amount of internal address space behind the victim’s firewall and relatively quickly. I created a demo here (works only in Firefox 3.5+ and you must enable JavaScript globally for this to work). It won’t work if you just whitelist ha.ckers.org you have to globally allow JavaScript if you use Noscript for the demo to work - and you must disable ABE in Noscript as well.

You can read the page for the details, like the fact that basic and digest authentication popups are suppressed which makes this technique ideal for Intranets where those are common and would normally alert a user to the fact that something was wrong in the browser. It also doesn’t matter whether you do or don’t have port 80 open for this to work, I should note that there is a IE8.0 version of Firefox’s XMLHTTPRequest called XDomainRequest, but I didn’t have much time this weekend to try to get it working in both browsers so I have no idea if it has the same issue or not.

Incidentally, Jeremiah and I both gave the thumbs up to the idea of a cross domain XHR several years ago when the Mozilla team first asked us about the concept. Because there are so many other things wrong with the browser Jeremiah and I told them that it wouldn’t change much - the browser is already so broken from a security perspective that it really didn’t matter - a sad commentary thinking back. Of course, it really is all about the implementation.

How to Dismantle a Nuclear Bomb

Via BBC (h/t Tim of ubiwar.com) -

How do you dismantle a nuclear bomb? And how do you verify another country is genuinely disarming without compromising sensitive national security material?

BBC security correspondent Gordon Corera was given exclusive access to a unique exercise run by the UK and Norway to find out.

The nuclear weapon is carefully lifted out of a large container and moved onto the floor.

Two engineers use an electric screwdriver to open up a side compartment and remove the "physics package" containing the sensitive parts of the bomb.

A scientist with a radiation detector beckons me forward as he points his machine towards the box.

It begins to emit an accelerating beeping noise. "The measurement is approximately a hundred times normal background radiation," he tells me.

"But it is not dangerous, I promise," he adds with a smile.

he lack of danger is because the bomb is not real. To inject an element of realism into this experiment, a weak radioactive material - Cobalt 60 - is used.

The dismantlement experiment is a joint exercise between the UK and Norway - the first of its kind - and was held a few miles from Oslo.

The five-day exercise has been keenly anticipated internationally as a way of building trust between nuclear weapons states and non-nuclear weapons states.

It is designed to see if one country can verify the disarmament of another country's nuclear weapon, but without any sensitive information about national security and weapon design being compromised.

In a role reversal, the Norwegians play a nuclear weapons state (called Torland) and the UK team play inspectors from Luvania, a non-nuclear weapons state.

[...]

"The aim is to develop methodologies we could use in inspections of a real nuclear facility but in an environment in which can do trial and error," explains Andreas Persbo of Vertic, which helped organise the event.

It is not an exercise in which the nuclear state is trying to clandestinely divert nuclear material or the inspecting side search for a covert facility.

[...]

In practice no nuclear weapons state has ever allowed a non-nuclear weapons state to verify disarmament. But if there was to be multilateral disarmament in the future, it may well be important to provide such states with confidence over its actions.

Officials on both sides hope that this and any future events will lead to better understanding between nuclear weapons states and non-nuclear weapons states and more collaborations, allowing trust and confidence to be increased.

DC17 Badge Pre-Release Information

https://forum.defcon.org/showthread.php?t=10655

Here are a few useful pieces of information to help you get set up and/or prepare for the DC17 Badge Hacking Contest. Unlike last year, all of the badge design documentation, including development environment, should be on the CD this year, unless there was a last minute change that I'm unaware of. Even still, I'd HIGHLY recommend getting your tools set up in advance so you come to DEFCON ready to rock. Remember, the Badge Hacking Contest is now a BLACK BADGE contest, so the stakes are raised...

* The processor this year is a Freescale MC56F8006 Digital Signal Controller. It's a brand new part, but the DSC family has been around for a while and there is plenty of code samples/examples and application notes on Freescale's site.

Main product page:
http://tinyurl.com/lyorks

Direct link to data sheet:
http://www.freescale.com/files/dsp/d...06.pdf?pspll=1

* The development environment is Freescale CodeWarrior for DSCs. It's a similar IDE to previous badges (sorry, still Windows only AFAIK, but works fine in a VM). I used Processor Expert to help with the device configuration, so you'll probably want to familiarize yourself with that feature.

Link to the tool (free, no license required):

Special Edition: CodeWarrior for 56800/E Digital Signal Controllers
http://www.freescale.com/lgfiles/upd...SSET=Downloads
or
http://tinyurl.com/kuwloq

* There will a serial bootloader on-board to enable you to easily load your own firmware onto the badge (simply requiring a terminal program, like HyperTerminal, and the hex file). However, this year will require a bit more soldering skill to get it up and running and you will need a level shifter to convert the 3V TTL-level serial of the badge to RS232 or USB level. We'll have a few level shifter kits in the Hardware Hacking Village, but I'm sure those will go quickly, so if you're reading this, BRING YOUR OWN LEVEL SHIFTER, buy something like this: http://www.ftdichip.com/Products/Eva...L-232R-3V3.htm or bring components to put one together (an FTDI FT232R)

* In the case of completely bricking your badge during a firmware update via the bootloader, you can completely reprogram it via the MC56F8006 JTAG interface and the USB TAP hardware (I'll have one with me for emergencies).

Information on the USB TAP:
http://www.freescale.com/webapp/sps/...sp?code=USBTAP

* AFAIK, Freescale is sending at least one engineer to come and experience DEFCON, hang out, and offer technical support for hacking/developing with the badge. The Hardware Hacking Village will serve as the Badge Hacking HQ and he'll be located there. I'll try to spend as much time as I can up there, too, but the more help I give, the less likely you'll win the contest :P

Teenager Creates Fake Airline with Some Serious Social Engineering Skills

Via Times Online UK -

A teenage boy from Yorkshire succeeded in persuading British aviation executives that he was a tycoon about to launch his own airline. Using the pseudonym Adam Tait, the smooth-talking 17-year-old told airport and airline executives that he had a fleet of jets.

Tait, who said he was in his twenties, even flew to Jersey to attend a 1½-hour long meeting with the director of its airport. Their talks were considered promising enough for a further meeting to be arranged, which was due to be held next week.

Other air industry bosses found themselves dealing by telephone or e-mail with Tait’s fellow executives, David Rich and Anita Dash, who proposed to launch a cut-price Channel Islands-based airline servicing most of Europe.

What no one realised was that Tait, Rich and Dash were all the same person: an aircraft buff with the gift of the gab and an overactive imagination.

[...]

The Yorkshire teenager’s six-month-long ruse, which included placing articles in industry magazines, foundered only after one publication, Airliner World, became suspicious. It started to unravel the complex network that Tait had set up of fake websites, “virtual offices” complete with a real telephone receptionist and bogus names.

Last Monday he was questioned by Essex police while trying to gain access to a 93-seater jet at Southend airport, having convinced the plane’s marketing agent that his “company” wanted to lease it.

The police, who had intervened after being tipped off by Airliner World, discovered the boy’s true identity. Although no further action was taken, his fantasy was finally grounded.

The Sunday Times has agreed not to use Tait’s real name at the request of his father, who did not know of his son’s exploits until he was contacted last week.

He said that his son suffered from a form of autism and was “a phenomenal individual who is enterprising and creative” with an ability to recall the exact detail of every airline’s flight schedules. But the autism also made his behaviour highly challenging.

“He has been passionate about aeroplanes for about two years and his whole bedroom is plastered with them,” he said.

“Before that he came within two days of bringing the US cast of High School Musical to a 300-seat theatre in Shropshire by cutting and pasting mastheads from one company to another, masquerading as this or that.

“It would have happened, except when booking the hotel some queries were thrown up. I don’t know why he did it. He is not nasty or vindictive or malicious.”

Sunday, July 19, 2009

Mozilla Says Stack Overflow Crash Not Exploitable (CVE-2009-2479)

Via Mozilla Blog -

In the last few days, there have been several reports (including one via SANS) of a bug in Firefox related to handling of certain very long Unicode strings. While these strings can result in crashes of some versions of Firefox, the reports by press and various security agencies have incorrectly indicated that this is an exploitable bug. Our analysis indicates that it is not, and we have seen no example of exploitability.

On Windows, Firefox 3.0.x is terminated due to an uncaught exception during an attempt to allocate a very large string buffer; this termination is safe and immediate, and does not permit the execution of attacker code. In Firefox 3.5.x on Windows, the allocations are more robustly checked and no crash will result.

On the Macintosh in Firefox 3.0.x and 3.5.x, a crash occurs inside the ATSUI system library (part of OS X), due to what appears to be a failure to check allocation results. This issue is likely to affect any application using the recommended text-handling libraries on OS X. We have reported this issue to Apple, but in the event that they do not provide a fix we will look to implement mitigations in Mozilla code. We recommend that other developers who use these libraries consider a similar practice, and we have added mitigations in the past for similar bugs in these libraries.

As a result of our analysis, we do not believe that this represents an exploitable vulnerability in Firefox. Further, we believe that the IBM report is in error, and that the severity rating in the National Vulnerability Database report is incorrect. We have contacted them and hope to resolve the inaccuracies shortly.

Mike Shaver
VP Engineering, Mozilla Corporation

Captured U.S. Soldier in Taliban Video Identified

Via ABC News -

Department of Defense officials confirmed the identity of a captured American soldier in a video posted online Saturday by the Taliban.

Pfc. Bowe Bergdahl, 23, of Hailey, Idaho, went missing from his base in eastern Afghanistan on June 30. On July 3, officials declared him "missing-captured."

Early in the video, a captor holds up the soldier's dog tag to the camera. Later Bergdahl states his name and hometown.

Bergdahl is a member of 1st Battalion, 501st Parachute Infantry Regiment, 4th Brigade Combat Team, 25th Infantry Division, out of Fort Richardson, Alaska.

Taliban Releases Video of Captured U.S. Soldier

Via thestar.com -

The American soldier who went missing June 30 from his base in eastern Afghanistan and was later confirmed captured, appeared on a video posted Saturday to a website by the Taliban, two U.S. defence officials confirmed.

The soldier is shown in the 28-minute video with his head shaved and the start of a beard. He is sitting and dressed in a nondescript, grey outfit. Early in the video one of his captors holds the soldier's dog tag up to the camera. His name and ID number are clearly visible. He is shown eating at one point and sitting on a bed.

The soldier, whose identity has not yet been released by the Pentagon pending notification of members of Congress and the soldier's family, says his name, age and hometown on the video, which was released Saturday on a website pointed out by the Taliban. Two U.S. defence officials confirmed to The Associated Press that the man in the video is the captured soldier.

The soldier said the date is July 14. He says he was captured when he lagged behind on a patrol.

He is interviewed in English by his captors, and he is asked his views on the war, which he calls extremely hard, his desire to learn more about Islam and the morale of American soldiers, which he said was low.

Asked how he was doing, the soldier said on the video:

"Well I'm scared, scared I won't be able to go home. It is very unnerving to be a prisoner."

He begins to answer questions in a matter-of-fact and sober voice, occasionally facing the camera, looking down and sometimes looking to the questioner on his left.

He later chokes up when discussing his family and his hope to marry his girlfriend.

"I have my girlfriend, who is hoping to marry," he said. "I have a very very good family that I love back home in America. And I miss them every day when I'm gone. I miss them and I'm afraid that I might not ever see them again and that I'll never be able to tell them that I love them again and I'll never be able to hug them."

Saturday, July 18, 2009

EPFL Playstation 3 Cluster Cracks 112-bit Elliptical Curve Encryption

Via H-Online.com -

Researchers at the École Polytechnique Fédérale (EPFL) in Lausanne, Switzerland, have succeeded in cracking 112-bit encryption based on elliptical curves (ECCp-112). They calculated the secret key associated with a public key by solving the Discrete Logarithm Problem (DLP) for elliptical curves, which displays a complexity of 260 for the numbers involved. The cracked ECC system is a set of parameters defined by the secp112r1 standard. That puts it at the lower end of the specifications for ECC encryption systems.

The computation required around half a year on the EPFL cluster, consisting of some 200 PlayStation 3s that had already served to calculate the MD5 collision for creating a fake SSL issuer certificate from RapidSSL. The ECC code designed for the cell processor of the PlayStation 3 was optimised several times during the computation period, and the researchers say that, if the optimised code had been running from the start, the computation would only have taken three and a half months. The previous record was set in 2002, when a distributed cluster consisting of around 10,000 PCs cracked an ECC key within 549 days. At that time, researchers at Notre Dame University cracked an ECCp-109 key, three bits shorter than the new record.

Dr. Arjen Lenstra, who took part in the EPFL project, told heise Security that this result isn't actually a threat to the EC encryption systems used in practice. He said the weakest encryption encountered is based on 160-bit ECC and future developments in encryption standards would in any case have to be based on at least 224-bit ECC. According to the NIST transition proposal, ECCp-160, whose encryption strength is comparable with RSA-1024, must be replaced with a stronger variant after 2010 in order to obtain FIPS certification.

See also:

Orwell in 2009: Dystopian Rights Management

Via EFF -

In George Orwell's Nineteen Eighty-Four, the protagonist Winston Smith labors in obscurity to make information appear and disappear at the whims of the Ministry of Truth:

This process of continuous alteration was applied not only to newspapers, but to books, periodicals, pamphlets, posters, leaflets, films, sound-tracks, cartoons, photographs — to every kind of literature or documentation which might conceivably hold any political or ideological significance. Day by day and almost minute by minute the past was brought up to date.

The Ministry of Truth would have truly appreciated DRM and tethered devices. As many owners of Kindle e-books discovered this morning, electronic books that come rigged with DRM "copy protection," stored on e-book readers subject to Amazon remote control, can be made to disappear at the whims of their publishers, as if they never existed in the first place.

David Pogue reports today in the New York Times that books published by MobileReference, including Orwell's Nineteen Eighty-Four and Animal Farm, were remotely deleted from customers' Kindles over night. (Customers had their accounts credited for the value lost.)

This morning, hundreds of Amazon Kindle owners awoke to discover that books by a certain famous author had mysteriously disappeared from their e-book readers. These were books that they had bought and paid for—thought they owned.

But no, apparently the publisher changed its mind about offering an electronic edition, and apparently Amazon, whose business lives and dies by publisher happiness, caved. It electronically deleted all books by this author from people’s Kindles and credited their accounts for the price.

Orwell would have appreciated the irony. But he also would have been the first to predict that this problem would arise when one company sells both the books themselves and the device required to read them, when that company insists on locking up the books with "protection" that prevents them being shifted to any other device, and has the power of "remote deletion" at its fingertips. Big Brother, indeed!

This is Amazon choosing its "content partners" over its customers. There is nothing about copyright law that required these deletions -- if Amazon didn't have the rights to sell the e-books in the first place, the infringement happened when the books were sold. Remote deletion doesn't change that, and it's not an infringement for the Kindle owner simply to read the book. Can you imagine a brick-and-mortar bookstore chasing you home, entering your house, and pulling a book from your shelf after you paid good money for it? (Nor, for that matter, does Amazon reserve any "remote deletion" right the Kindle "terms of service".)

If people want books that won't evaporate on the orders of faceless bureaucrats, if they want their libraries to last, or the right to read privately, or if they want the same ability to share or loan books that they enjoy with printed books, they should avoid buying any book that can't be copied or any e-book reader with "remote deletion" features. Project Gutenberg has e-books that won't disappear at midnight, like a pumpkin coach. Cory Doctorow sells e-books that will live as long as your hard drive and your backups keep them around. They're in unrestricted formats — like plain text, HTML, or PDF — and you can read them on devices without an Amazon Big Brother on board.

Mozilla Firefox 3.5.1 Unicode Data Remote Stack Buffer Overflow Vulnerability

I'm sorry to say, but this vulnerability isn't new. It was released two days before the release of 3.5.1

Various analysts and sites have recently confirmed the vulnerability in FireFox 3.5.1. When exploited, the vulnerability can lead to system compromise or induce a DOS.

http://www.milw0rm.com/exploits/9158
http://www.securityfocus.com/bid/35707
http://isc.sans.org/diary.html?storyid=6829

Friday, July 17, 2009

US, Afghan Forces Overrun Haqqani Network 'Encampment' in Paktia

Via The Long War Journal -

The US and Afghan military have continued attacks against the Haqqani Network in eastern Afghanistan despite a threat from the group that a captured US soldier would be executed if the raids did not cease.

Last night, US and Afghan forces conducted two major raids in Paktia and Logar provinces. The raids were aimed at taking down the leadership of the Haqqani Network and gathering intelligence on the location of the captured US soldier.

The biggest raid took place against an "enemy encampment" situated "in the remote reaches of Paktia province" the US military said in a press release. The operation took place about 20 miles southeast of Gardez City, and was designed to stem the flow of foreign fighters and weapons moving from Pakistan's Taliban-controlled tribal agencies of North and South Waziristan through the Khost-Gardez Pass to the capital of Kabul.

The combined force killed "several" Haqqani Network fighters in firefights and with air support after repeatedly taking fire while moving to assault the Haqqani base. Several massive weapons caches were destroyed after US and Afghan forces overran the base.

Afghan and Coalition forces also conducted a targeted raid against a Haqqani Network safe house near the village of Ebad in Logar province. The compound is known to be used by a Haqqani commander to make roadside bombs. Three suspected Haqqani Network fighters were detained during the raid.

The US military conducted the raids the same day that Mullah Sangeen Zadran, a senior commander in the Haqqani Network, threatened to kill a US soldier unless Coalition forces end operations in two districts in Paktika and Ghazni provinces in eastern Afghanistan. The soldier was captured on June 30 after walking away from his combat outpost in Paktika province.

The US military has issued flyers in Paktia and Ghazni provinces, urging Afghans to provide intelligence on the location of the missing soldier. But the soldier may have already been moved into North Waziristan, a US intelligence official familiar with the search told The Long War Journal.

[...]

Just as the US has finally admitted that Taliban leader Mullah Omar and his senior commanders are running their Afghan operations from Quetta in Pakistan, the Haqqanis have been labeled as operating from Pakistan's tribal areas.

"The Haqqani network remains one of the most lethal Taliban organizations operating out of Pakistan's Federally Administered Tribal Areas," the US military admitted in a recent press release.

New Linux Flaw Enables Null Pointer Exploits

Via ThreatPost.com -

A researcher has published exploit code for a new vulnerability he discovered in the Linux kernel. The vulnerability is an especially interesting one in that the researcher who discovered it, Brad Spengler, has demonstrated that he can use the weakness to defeat many of the add-on security protections offered by SELinux and AppArmor.

The vulnerability is in the 2.6.30 release of the Linux kernel, and in a message to the Daily Dave mailing list Spengler said that he was able to exploit the flaw, which at first glance seemed unexploitable. He said that he was able to defeat the protection against exploiting NULL pointer dereferences on systems running SELinux and those running typical Linux implementations. SELinux is a set of security enhancements to the Linux OS developed by the National Security Agency.

Spengler also said he is able to turn off the auditing processes in SELinux, AppArmor and the Linux Security Module. He posted a video demonstration of the exploit in action on YouTube.

[...]

This code looks perfectly ok, right? Well, it is, until the compiler takes this into its hands. While optimizing the code, the compiler will see that the variable has already been assigned and will actually remove the if block (the check if tun is NULL) completely from the resulting compiled code. In other words, the compiler will introduce the vulnerability to the binary code, which didn't exist in the source code. This will cause the kernel to try to read/write data from 0x00000000, which the attacker can map to userland – and this finally pwns the box.

Until recently, exploiting NULL pointer dereferences was thought to be virtually impossible. But work done by Mark Dowd of IBM ISS last year put the lie to that. Dowd designed his technique to exploit a problem in Adobe Flash, but was able to extend it to exploit similar conditions in other applications.

-----------------------

Prefect example of how you can't find all vulnerabilities by just reviewing source code alone.

While code review is critical to reducing the number of vulnerabilities, it is only part of the overall security puzzle.

Of course, the security puzzle changes so fast...there isn't a real solution...but that is another blog altogether ;)

Firefix 3.5.1 Released

http://www.mozilla.com/en-US/firefox/3.5.1/releasenotes/

Firefox 3.5.1 fixes the following issues:

  • Several security issues.
  • Several stability issues.
  • An issue that was making Firefox take a long time to load on some Windows systems.

Please see the complete list of changes in this version. You may also be interested in the Firefox 3.5 release notes for a list of changes in the previous version.

Deadly Blasts Hit Two Luxury Hotels in Jakarta, Indonesia

Via CNN -

The death toll from bombings at two luxury hotels Friday morning in south Jakarta, Indonesia, has risen to eight, a presidential spokesman said. The number of wounded people was in the 40s, the spokesman said.

Antara News, a state-run agency, quoted a witness as saying he saw four foreigners among the wounded.

The Ritz-Carlton Hotel was to have accommodated soccer players from Manchester United of Britain, who are expected to arrive Saturday in Jakarta on Saturday.

The victims were taken to nearby MMC Hospital and Jakarta Hospital, the agency reported.

Police sealed off the area around both blasts, one of which occurred in the Ritz-Carlton Hotel and the other at the J.W. Marriott Hotel, about 50 meters away, about 7:50 a.m. (8:50 p.m. Thursday ET).

"There was a boom and the building shook, and then subsequently two more," said hotel guest Don Hammer, who was leaving his room in the Marriott when the blast occurred.

"The shocking part was entering the lobby, where the glass at the front of the hotel was all blown out and blood was spattered across the floor, but most people were leaving calmly."

[...]

Greg Woolstencroft had just walked past the hotels and had gone to his nearby apartment when he heard an explosion.

"I looked out my window and I saw a huge cloud of brownish smoke go up," he told CNN in a telephone interview. "I grabbed my iPhone to go downstairs ... and then the second bomb went off at the Ritz-Carlton, so I then ran around to the Ritz-Carlton and I was able to find that there had been a massive bomb that went off in this ... restaurant area and the explosion had blown out both sides of the hotel.

"I found inside the body of of what appears to be a suicide bomber, it looked like someone who had been a suicide bomber or someone who had been very, very close to the explosion.
"I also noticed that there were a number of injured people being taken off to hospital, but I only noticed one dead person at this point and time, that's all I saw. There has been extensive damage to both buildings, and at this point and time of course all the authorities are blocking up all the area and starting an investigation."

He added, "It's obviously targeted establishments where there are Westerners and expats ... I can only assume it's something to try and send a message."

---------------------------------

According to Stratfor....

Militant group Jemaah Islamiyah (JI) is a feasible perpetrator for the attacks.

Thursday, July 16, 2009

Investigation Into Cyberattacks Stretches Around the Globe

Via PC World -

British authorities have launched an investigation into the recent cyberattacks that crippled Web sites in the U.S. and South Korea, as the trail to find the perpetrators stretches around the world.

On Tuesday, the Vietnamese security vendor Bach Khoa Internetwork Security (Bkis) said it had identified a master command-and-control server used to coordinate the denial-of-service attacks, which took down major U.S. and South Korean government Web sites.

A command-and-control server is used to distribute instructions to zombie PCs, which form a botnet that can be used to bombard Web sites with traffic, rendering the sites useless. The server was on an IP (Internet Protocol) address used by Global Digital Broadcast, an IP TV technology company based in Brighton, England, according to Bkis.

That master server distributed instructions to eight other command-and-control servers used in the attacks. Bkis, which managed to gain control of two of the eight servers, said that 166,908 hacked computers in 74 countries were used in the attacks and were programmed to get new instructions every three minutes.

But the master server isn't in the U.K.; it's in Miami, according to Tim Wray, one of the owners of Digital Global Broadcast, who spoke to IDG News Service on Tuesday evening, London time.

The server belongs to Digital Latin America (DLA), which is one of Digital Global Broadcast's partners. DLA encodes Latin American programming for distribution over IP TV-compatible devices, such as set-top boxes.

New programs are taken from satellite and encoded into the proper format, then sent over VPN (Virtual Private Network) to the U.K., where Digital Global Broadcast distributes the content, Wray said. The VPN connection made it appear the master server belonged to Digital Global Broadcast when it actually is in DLA's Miami data center.

Engineers from Digital Global Broadcast quickly discounted that the attacks originated with the North Korean government, which South Korean authorities have suggested may be responsible.

Digital Global Broadcast was notified of a problem by its hosting provider, C4L, Wray said. His company has also been contacted by the U.K.'s Serious Organized Crime Agency (SOCA). A SOCA official said she could not confirm or deny an investigation. DLA officials could not be immediately reached.

Investigators will need to seize that master server for forensic analysis. It's often a race against the hackers, since if the server is still under their control, critical data could be erased that would help an investigation.

"It's a tedious process and you want to do it as quickly as possible," said Jose Nazario, manager of security research for Arbor Networks.

Data such as log files, audit trails and uploaded files will be sought by investigators, Nazario said. "The holy grail you are looking for are pieces of forensics that reveal where the attacker connected from and when," he said.

To conduct the attacks, the hackers modified a relatively old piece of malware called MyDoom, which first appeared in January 2004. MyDoom has e-mail worm characteristics and can also download other malware to a PC and be programmed to conduct denial-of-service attacks against Web sites.

Analysis of the MyDoom variant used in the attacks isn't that impressive. "I still think the code is pretty sloppy, which I hope means they [the hackers] leave a good evidence trail," Nazario said.

Firefox 3.5.1 Due Later This Week

Via MozillaLinks.org -

Mozilla has confirmed that it will release the first update for Firefox 3.5 later this week to address a critical security vulnerability disclosed a couple of days ago that could lead to malicious code execution.

The update will most likely also address a bug related to slow startups due to large Windows temporary folders being scanned for Firefox’s randomness needs. However, some testers report the fix already available in a release candidate doesn’t improve the startup time, so it seems there are other possible causes and the fix may not help all users.

A second update (3.5.2) is already in the works and is expected for late July. This will address some bugs originally targeted for 3.5.1 that got postponed to speed Firefox 3.5.1 update.

Symbian Phone Trojan 'has Botnet Features'

Via ZDNet -

A piece of mobile malware has the capacity to enable a hacker to build a botnet of phones, according to security vendor Trend Micro.

The Symbian Trojan, which Trend Micro detects as SYMBOS_YXES.B, poses as a legitimate application called ACSServer.exe and calls itself 'Sexy Space'. It steals the user's subscriber, phone and network information, and connects to a website to send that information back to a hacker. It can also target the victim's contacts with spam SMS messages, and pull the content in those messages from the malicious website.

"In short, it appears to be a botnet for mobile phones," wrote Jonathan Leopando of the Trend Micro technical communications team in a blog post on Wednesday.

However, the malware itself is classified as low risk, with a low distribution potential, according to a Trend Micro analysis.

Leopando added that there may be a problem with digital signing by the Symbian Foundation. Digital signatures, which are cryptographic security features, are designed to provide a level of certainty that a message or piece of software actually comes from the organisation it appears to have come from.

However, Leopando wrote in the blog post that SYMBOS_YXES.B was similar to another phone malware that Trend Micro detects as SYMBOS_YXES.A, and that both pieces of malware had been signed by Symbian Foundation.

"The signing process — undertaken by the Symbian Foundation itself — is supposed to ferret out instances like this, but somehow this slipped through," wrote Leopando. "It may well be a coincidence, but it does not reinforce confidence in the signing system."

The Symbian Foundation had not responded to a request for comment at the time of writing.

Nmap 5.00 Released

http://nmap.org/5/

Insecure.Org is pleased to announce the immediate, free availability of the Nmap Security Scanner version 5.00 from http://nmap.org/. This is the first stable release since 4.76 (last September), and the first major release since the 4.50 release in 2007. Dozens of development releases led up to this.

Considering all the changes, we consider this the most important Nmap release since 1997, and we recommend that all current users upgrade.

--------------------

Ed Skoudis has a written on his first impressions of this huge release.

XKCD: Sheeple



http://xkcd.com/610/

Taliban Threatens to Kill U.S. Soldier Captured in Afghanistan

Via FoxNews (AP) -

A spokesman for a Taliban commander says a captured U.S. soldier will be executed unless the U.S. military stops operations in two districts of southeastern Afghanistan.

The Taliban said last week they were holding the soldier. The U.S. military earlier said he went missing and may be in enemy hands.

Abdullah Jalali, spokesman for Taliban commander Mawlavi Sangin, told The Associated Press on Thursday the soldier was healthy but threatened to kill him unless the U.S. stops airstrikes in Ghazni province's Giro district and Paktika province's Khoshamand district.

Jalali says Giro has been heavily bombed by international forces but did not otherwise explain why they chose those areas.

Teen Arrested for Upper East Side Starbucks Blast

Via NBCNewYork.com -

A teen arrested in the bombing of an upper East Side Starbucks was inspired to plant the explosive device by the movie "Fight Club," cops said today.

Kyle Shaw, 17, of Chelsea, was charged with arson, criminal mischief and criminal possession of a weapon for placing the bomb at the E. 92nd St. coffee shop, police said.

Shaw was inspired to plant the bomb at the Manhattan eatery by watching the anarchic behavior of Brad Pitt in the film "Fight Club." He picked the site because a Starbucks was a target in the movie, police said.

Shaw formed his own fight club in which boys beat one another in various locales around the city including Central Park, Police Commissioner Ray Kelly said.

At least one member got a broken nose, he said.

Shaw apparently told at least one friend to "watch the news over Memorial Day'' because he was about to launch his own version of "project mayhem,'' Kelly said. Investigators are looking into whether more people might have been involved.

The homemade device exploded at 3:30 a.m. on May 25 and no one was hurt in the attack. The bomb was made out of water bottle and powder used to make fireworks.

Video at the scene showed two teens carrying a plastic container with what cops believed to be explosives.

--------------------------

For more background information, check my May 25th blog entry on the blast...

Pay As You Drive “Black Boxes” Threaten Driver Privacy

Via EFF -

The California Department of Insurance (DOI) is considering regulations that would enable insurance prices to depend on the precise number of miles a car is driven in a given billing period. But in implementing these "Pay As You Drive" regulations, the DOI appears poised to empower insurance companies to require customers' cars to be outfitted with "black-box" devices that could transmit back to the insurance companies all sorts of data about car motion (acceleration, braking, and so forth) as well as driver behavior (steering and seat-belt wearing).

Although DOI has retreated from its prior position that these devices should track your location – a definite improvement – it's still true that every car already has a reliable, tamper-resistant device that verifies actual mileage: an odometer.

Even worse, there appear to be no restrictions on what the insurance companies would do with that data — of course, when you drive on the public street, you lose some privacy. But 10 years ago, someone interested in your whereabouts would have had to decide in advance to follow you and then physically follow you. Black boxes can collect information pervasively, silently, and cheaply for any later use by the insurance company, private parties or the government. There is real danger that this information would not only be used to ascertain the political or associational affiliations of drivers, but also to charge more if you drive and park in neighborhoods with high vehicle theft and crime rates, to impose higher premiums for people who drive at night or to link your health insurance rates with location data that reveals your lunchtime trips to McDonald's.

In comments filed with the DOI this week, EFF has argued that it is unacceptable for insurance companies to coercively require customers to accept such devices in their cars, and that the proposed regulations be amended to permit drivers to participate in any verifed actual mileage program via other means (like your car's odometer). EFF also argued that location privacy requires, at a minimum, that the proposed regulations restrict collection of information to the minimum amount necessary, require that the driver be able to independently verify information collected and require that the insurer have an explicit policy about the use and storage of the collected data.

Interested in protecting driver privacy in California? Consider telling Insurance Commissioner Steve Poizner [contact info] that you agree with EFF's criticisms. Why is the Insurance Commissioner allowing the insurance companies to track drivers? Shouldn't he be tracking insurance companies?

Wednesday, July 15, 2009

CERN LHC Update

Via US LHC Blog -

This message was sent from Director General Rolf Heuer to the CERN community today:

The foreseen shutdown work on the LHC is proceeding well, including the powering tests with the new quench protection system. However, during the past week vacuum leaks have been found in two “cold” sectors of the LHC. The leaks were found in sectors 8-1 and 2-3 while they were being prepared for the electrical tests on the copper stabilizers at around 80 K. In both cases the leak is at one end of the sector, where the electrical feedbox, DFBA, joins Q7, the final magnet in the sector.

Unfortunately, the repair necessitates a partial warm-up of both sectors. This involves the end sub-sector being warmed to room temperature, while the adjacent sub-sector “floats” in temperature and the remainder of the sector is kept at 80 K. As the leak is from the helium circuit to the insulating vacuum, the repair work will have no impact on the vacuum in the beam pipe. However the intervention will have an impact on the schedule for the restart. It is now foreseen that the LHC will be closed up and ready for beam injection by mid-November.

---------------------------

Liquid nitrogen is used to cool 37,000 tonnes of equipment for the Large Hadron Collider (LHC) down to 80 K. Then liquid helium is used to chill some parts of the accelerator to temperatures as low as 1.8 K.

But liquid helium isn't created directly....

The cryoplants produce high-pressure supercritical helium gas at 4.6 K, which will be distributed along the sector to a number of local cooling loops. There, the supercritical helium will be expanded into a lower-pressure environment, which causes it to liquefy at either 4.5 K or 1.8 K. This liquid will then be used to cool the superconducting magnets.

Firefox 3.5 Exploits - Another Exploit Released

The one you have been hearing about....here & here
http://www.milw0rm.com/exploits/9137

and a new exploit one released today...
http://www.milw0rm.com/exploits/9158

Veracode: BlackBerry Spyware Dissected

Via Veracode Blog -

Yesterday it was reported by various media outlets that a recent BlackBerry software update from Etisalat (a UAE-based carrier) contained spyware that would intercept emails and text messages and send copies to a central Etisalat server. We decided to take a look to find out more.

We’re not sure why the software was delivered in both .jar and .cod form. The .cod file is a RIM proprietary format that contains the compiled Java classes along with a signature. Therefore it’s not even necessary to send the .jar, but they did, completely unobfuscated.

[...]

The most alarming part about this whole situation is that people only noticed the malware because it was draining their batteries. The server receiving the initial registration packets (i.e. “Here I am, software is installed!”) got overloaded. Devices kept trying to connect every five seconds to empty the outbound message queue, thereby causing a battery drain. Some people were reporting on official BlackBerry forums that their batteries were being depleted from full charge in as little as half an hour.

The final thing to mention is that the spyware does appear to be installed in a non-running state by default, where it’s not actually exfiltrating data once the initial registration packet has gone out. However, using the command and control mechanism we described earlier, the carrier can remotely start/stop the service at will on a per-device basis.

-------------------------

Check out the full Veracode blog for the detailed technical analysis...cool stuff indeed.

New iTunes From Apple Halts Palm Pre's Access

Via WSJ.com -

The latest version of iTunes from Apple Inc. (AAPL) has cut off rival Palm Inc.'s (PALM) Pre smartphone.

Apple's online music and video bazaar now "disables devices falsely pretending to be iPods," which includes Palm's Pre, an Apple spokesman said.

The Pre smartphone has been able to access iTunes since going on sale in the U.S. in early June. But it was always unclear whether the Pre was doing so with Apple's permission. Given the latest iTunes update, Palm appears to have been acting on its own.

The development is a negative one for Palm, which is counting on Pre sales to turn around the company. With the move, Apple has dramatically limited one of the Pre's key competitive advantages: downloading music and videos from Apple's iTunes.

"If Apple chooses to disable media sync in iTunes, it will be a direct blow to their users who will be deprived of a seamless synchronization experience," Palm spokesman Lynn Fox said,

"However, people will have options," which include using previous versions of iTunes that are still Pre-compatible, she added.

For Apple, the new iTunes underscores its commitment to allow only authorized devices, such as its iPods and iPhones, to access its iTunes music store, which helps it corral more of the profits.

"As we've said before, newer versions of Apple's iTunes software may no longer provide syncing functionality with unsupported digital media players," the Apple spokesman added.

---------------------

If you didn't hear about the Palm Pre Media Sync function and how it gained access to iTunes, check here.

Critical JavaScript Vulnerability in Firefox 3.5

http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/

Issue

A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.

Impact

The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can be mitigated by disabling the JIT in the JavaScript engine. To do so:

1. Enter about:config in the browser’s location bar.
2. Type jit in the Filter box at the top of the config editor.
3. Double-click the line containing javascript.options.jit.content setting the value to false.

Note that disabling the JIT will result in decreased JavaScript performance and is only recommended as a temporary security measure. Once users have been received the security update containing the fix for this issue, they should restore the JIT setting to true by:

1. Enter about:config in the browser’s location bar.
2. Type jit in the Filter box at the top of the config editor.
3. Double-click the line containing javascript.options.jit.content setting the value to true.

Alternatively, users can disable the JIT by running Firefox in Safe Mode. Windows users can do so by selecting Mozilla Firefox (Safe Mode) from the Mozilla Firefox folder.

Status

Mozilla developers are working on a fix for this issue and a Firefox security update will be sent out as soon as the fix is completed and tested.

Credit

Zbyte reported this issue to Mozilla and Lucas Kruijswijk helped reduce the exploit test case.

-----------------------------------

HD Moore has released a MSF module which exploits the vulnerability on Win32 only...support for other platforms is expected in the new future.

Etisalat's BlackBerry Patch Opens Phones to Surveillance

Via ITP.net -

The battery-sapping "performance patch" that Etisalat [Emirates Telecommunications Corporation] sent to its BlackBerry subscribers over the last few days was designed to give the UAE operator the ability to read its customers emails and text messages, a Qatar-based software expert told CommsMEA yesterday.

Last week, Etisalat told its 100,000 BlackBerry subscribers that a "performance enhancement patch" would be sent to them to "provide the best BlackBerry service and ultimate experience". But users who downloaded the software complained of dramatically reduced battery life and slower than usual performance of their devices.

Nigel Gourlay, a Doha-based Sun-certified Java programmer who has been developing open source software for 15 years, analysed the patch after it was posted on BlackBerry’s community support forum and he said that once installed, it potentially gives Etisalat the power to view all emails and text messages sent from the BlackBerry.

“I don’t think it’s been designed for a large scale deployment,” he said. “They have released it as an upgrade across all UAE BlackBerry handsets, all of which have tried to phone home to this one registration server at the same time, and that has effectively brought the server to its knees. When the BlackBerry cannot register itself, it tries again and this causes the battery drain.”

Gourlay pointed out that by default the system is turned off and when it installs the only message that is sent is an initial registration message, and that later on, Etisalat could turn on the systems “one by one”.

Once installed, one of the possible commands that can be sent to the device is "start", which would then cause any subsequent message to be forwarded to an Etisalat website.

Gourlay said the patch was stamped with “SS8.com”, the name of a US-based software developer that describes itself as an electronic surveillance solutions company that develops products that “allow intelligence agencies to recognise, monitor, investigate and prevent criminal activity”.

It appears as though the use of such software is widespread among telecom operators, and according to SS8’s website, its products are used by “some of the largest service providers in the world”.

On Sunday Etisalat issued a two paragraph statement apologising for “a phased software upgrade…that led to extra consumption of the handset battery”. It described the patch as a “routine upgrade process”, but said it had stopped issuing it as a precautionary measure.

At the time of writing the operator had not responded to requests sent yesterday (Monday) for further details about the precise purpose of the patch or Etisalat’s relationship with “lawful interception solutions” firm SS8.

SS8 established its presence in the UAE in February this year when it acquired OCI Mobile, a technology provider that specialised in providing surveillance solutions to government organisations.

Cisco 2009 Midyear Security Report

The Cisco 2009 Midyear Security Report presents an overview of Cisco security intelligence, highlighting threat information and trends from the first half of 2009. The report also includes recommendations from Cisco security experts and predictions of how identified trends will evolve.

As predicted in the Cisco 2008 Annual Security Report, attacks are only becoming more sophisticated and targeted as we move through 2009—and the global recession. However, while cybercrime is more pervasive, there are encouraging signs that increased collaboration among the "good guys" is not only making it more difficult for attacks to take root and grow, but also helping to bring criminals to justice.

Report Highlights
  • Criminals are exploiting "old-school" vulnerabilities because they believe security experts and individual computer users are paying little attention to these types of threats.
  • Compromising legitimate websites for the purpose of propagating malware remains a highly effective technique for criminals.
  • Web 2.0 applications, prized for their ease of use and flexibility, have become lures for criminals.
  • Criminals are targeting people who use online banking with well-designed, localized text message scams—and they're leaving virtually no trail.
  • The Obama administration has made strengthening U.S. cybersecurity a high priority, and looks to leverage technology innovation and partner with the private sector. Other countries are also stepping up efforts to enhance cybersecurity and prevent cybercrime.
In addition, the number of vulnerabilities and discrete threats has been off to a slower start this year compared to 2008, according to research by Cisco-a sign the security community is succeeding in making it more difficult for attacks to take root and grow.

The Cisco 2009 Midyear Security Report (PDF) is now available.