Thursday, August 6, 2009

Feds at DefCon Alarmed After RFIDs Scanned

Via Wired.com -

It’s one of the most hostile hacker environments in the country –- the DefCon hacker conference held every summer in Las Vegas.

But despite the fact that attendees know they should take precautions to protect their data, federal agents at the conference got a scare on Friday when they were told they might have been caught in the sights of an RFID reader.

The reader, connected to a web camera, sniffed data from RFID-enabled ID cards and other documents carried by attendees in pockets and backpacks as they passed a table where the equipment was stationed in full view.

It was part of a security-awareness project set up by a group of security researchers and consultants to highlight privacy issues around RFID. When the reader caught an RFID chip in its sights — embedded in a company or government agency access card, for example — it grabbed data from the card, and the camera snapped the card holder’s picture.

But the device, which had a read range of 2 to 3 feet, caught only five people carrying RFID cards before Feds attending the conference got wind of the project and were concerned they might have been scanned.

Kevin Manson, a former senior instructor at the Federal Law Enforcement Training Center in Florida, was sitting on the “Meet the Fed” panel when a DefCon staffer known as “Priest,” who prefers not to be identified by his real name, entered the room and told panelists about the reader.

“I saw a few jaws drop when he said that,” Manson told Threat Level.

“There was a lot of surprise,” Priest says. “It really was a ‘holy shit,’ we didn’t think about that [moment].”

Law enforcement and intelligence agents attend DefCon each year to garner intelligence about the latest cyber vulnerabilities and the hackers who exploit them. Some attend under their real name and affiliation, but many attend undercover.

Although corporate- and government-issued ID cards embedded with RFID chips don’t reveal a card holder’s name or company — the chip stores only a site number and unique ID number tied to a company or agency’s database where the card holder’s details are stored — it’s not impossible to deduce the company or agency from the site number. It’s possible the researchers might also have been able to identify a Fed through the photo snapped with the captured card data or through information stored on other RFID-embedded documents in his wallet. For example, badges issued to attendees at the Black Hat conference that preceded DefCon in Las Vegas were embedded with RFID chips that contained the attendee’s name and affiliation. Many of the same people attended both conferences, and some still had their Black Hat cards with them at DefCon.

But an attacker wouldn’t need the name of a card holder to cause harm. In the case of employee access cards, a chip that contained only the employee’s card number could still be cloned to allow someone to impersonate the employee and gain access to his company or government office without knowing the employee’s name.

Since employee access card numbers are generally sequential, Priest says an attacker could simply change a few digits on his cloned card to find the number of a random employee who might have higher access privileges in a facility.

“I can also make an educated guess as to what the administrator or ‘root’ cards are,” Priest says. “Usually the first card assigned out is the test card; the test card usually has access to all the doors. That’s a big threat, and that’s something [that government agencies] have actually got to address.”"

In some organizations, RFID cards aren’t just for entering doors; they’re also used to access computers. And in the case of RFID-enabled credit cards, RFID researcher Chris Paget, who gave a talk at DefCon, says the chips contain all the information someone needs to clone the card and make fraudulent charges on it — the account number, expiration date, CVV2 security code and, in the case of some older cards, the card holder’s name.

The Meet-the-Fed panel, an annual event at DefCon, presented a target-rich environment for anyone who might have wanted to scan government RFID documents for nefarious purposes. The 22 panelists included top cybercops and officials from the FBI, Secret Service, National Security Agency, Department of Homeland Security, Defense Department, Treasury Department and U. S. Postal Inspection. And these were just the Feds who weren’t undercover.

It’s not known if any Feds were caught by the reader. The group that set it up never looked closely at the captured data before it was destroyed. Priest told Threat Level that one person caught by the camera resembled a Fed he knew, but he couldn’t positively identify him.

“But it was enough for me to be concerned,” he said. “There were people here who were not supposed to be identified for what they were doing … I was [concerned] that people who didn’t want to be photographed were photographed.”

Priest asked Adam Laurie, one of the researchers behind the project, to “please do the right thing,” and Laurie removed the SD card that stored the data and smashed it. Laurie, who is known as “Major Malfunction” in the hacker community, then briefed some of the Feds on the capabilities of the RFID reader and what it collected.

-----------------------------

Ummmm...this isn't exactly a new threat.....hopefully the feds got a little taste of the public concern about the government throwing RFID in everything we own.

Baitullah Mehsud's Wife Killed by UAV Attack in South Waziristan

Via The Long War Journal -

The US may have came close to killing Pakistani Taliban leader Baitullah Mehsud in an airstrike on a compound in South Waziristan today.

Unmanned US strike aircraft fired two Hellfire missiles at a compound owned by Ikramuddin Mehsud, Baitullah's father-in-law, in the village of Zanghra, near Baitullah's home town of Makeen in the Taliban stronghold of South Waziristan.

Baitullah's second wife and two Taliban fighters were killed in the attack; four children were reported to have been wounded. Baitullah was not killed in the attack, his second wife's cousin told Reuters.

It was thought Baitullah was visiting his wife when the strike occurred, a US intelligence official with knowledge of the air campaign in Pakistan told The Long War Journal.

Today's attack in South Waziristan is the first since July 17, when US aircraft killed five Taliban fighters in a region controlled by North Waziristan Taliban commander Hafiz Gul Bahadar.

The US has shifted the focus of its covert air campaign in Pakistan's tribal areas almost exclusively against Baitullah Mehsud in South Waziristan. Of the 32 US strikes carried out in Pakistan this year, 23 of them have taken place in South Waziristan.

Baitullah Mehsud's territory has been hit 15 times and Mullah Nazir's areas have been hit eight times. Both Nazir and Baitullah host al Qaeda training camps and shelter senior leaders of the terror group. Eight of the last 10 attacks have targeted Baitullah's camps and safe houses.

The US is well on its way to exceeding last year's total of 36 airstrikes in Pakistan.

Wednesday, August 5, 2009

EFF Defends Wikipedian's Right to the Public Domain

Via EFF -

As has been widely reported, the National Portrait Gallery of London (NPG) recently sent a legal threat to an American Wikipedian, Derrick Coetzee, over his posting approximately 3,000 photos of public domain paintings to Wikipedia. Because of the importance of this issue for the public domain and the Internet generally, EFF has taken Mr. Coetzee as a client.

Here's the issue at the heart of this dispute: does something have to be in the public domain in every country on the planet before it can be posted to the Internet anywhere?

According to NPG, Mr. Coetzee copied digital photos from NPG's website and uploaded them to Wikipedia (where they are still available). Everyone agrees that the photographs are of public domain paintings in NPG's collection (e.g., this portrait of William Blake painted in 1807). It's also clear under U.S. law that simple reproductions of public domain paintings are themselves not copyrightable, since they lack any "originality" beyond the "sweat of the brow" of the photographer. NPG's lawyers argue that the rule is different under UK copyright law (although there is reason to doubt that it's as clear as NPG suggests) and that Mr. Coetzee is therefore a copyright infringer. NPG also makes several other claims, including that Mr. Coetzee has violated their website's "browsewrap" terms of use, that he violated the NPG's database right by extracting the images from their website, and that he has circumvented a technological measure (apparently Zoomify, which is no longer used on NPG's website) in violation of the UK's version of the DMCA.

As we explained to NPG in a letter sent on July 20, it's quite clear under U.S. law that Mr. Coetzee did nothing wrong -- as far as U.S. law is concerned, the photos are not copyrightable, the NPG website's "browsewrap" contract is unenforceable, there is no "database right," and using Zoomify on public domain images doesn't get you a DMCA claim. It's also clear that everything he's alleged to have done took place on his computer and Wikipedia's computers, none of which are in the UK.

In the offline world, that would certainly be the end of the matter. If Mr. Coetzee had flown to London, purchased posters of the same paintings at the museum store, brought them home, and started making copies for his friends, it's clear he would be well within his rights in doing so.

Why should the answer be different simply because he posted the photos to Wikipedia? NPG seems to think that UK law should apply everywhere on the Internet. If that's right, then the same could be said for other, more restrictive copyright laws, as well (see, e.g., Mexico's copyright term of life of the author plus 100 years and France's copyright over fashion designs). That would leave the online world at the mercy of the worst that foreign copyright laws have to offer, an outcome no U.S. court has ever endorsed.

Russian Subs Patrolling Off East Coast of U.S.

Via NYTimes.com (h/t National Terror Alert) -

A pair of nuclear-powered Russian attack submarines has been patrolling off the eastern seaboard of the United States in recent days, a rare mission that has raised concerns inside the Pentagon and intelligence agencies about a more assertive stance by the Russian military.

The episode has echoes of the cold war era, when the United States and the Soviet Union regularly parked submarines off each other’s coasts to steal military secrets, track the movements of their underwater fleets — and be poised for war.

But the collapse of the Soviet Union all but eliminated the ability of the Russian Navy to operate far from home ports, making the current submarine patrols thousands of miles from Russia more surprising for military officials and defense policy experts.

“I don’t think they’ve put two first-line nuclear subs off the U.S. coast in about 15 years,” said Norman Polmar, a naval historian and submarine warfare expert.

The submarines are of the Akula class, a counterpart to the Los Angeles class attack subs of the United States Navy, and not one of the larger submarines that can launch intercontinental nuclear missiles.

According to Defense Department officials, one of the Russian submarines remained in international waters on Tuesday about 200 miles off the coast of the United States. The location of the second remained unclear. One senior official said the second submarine traveled south in recent days toward Cuba, while another senior official with access to reports on the surveillance mission said it had sailed away in a northerly direction.

The Pentagon and intelligence officials spoke anonymously to describe the effort to track the Russian submarines, which has not been publicly announced.

Unofficial Firefox Shirt - Cash Rules Everything Around Me

http://fat.spreadshirt.com/us/US/Shop/Article/Index/article/CREAM-4899268

Cash Rules Everything Around Me

Tuesday, August 4, 2009

South Korean 'Journalists' Booted from Defcon 17

Via NetworkWorld.com -

Four South Korean journalists were booted from the Defcon hacking conference this week after conference organizers decided their story didn't quite add up.

Conference representatives released few details of the incident. They said Sunday that they'd ejected the journalists two days earlier after deciding that they simply weren't acting like press. They believe that one member of the group was a legitimate journalist, but that the other three were on some sort of intelligence-gathering expedition.

Hackers who the group interviewed at the show said that their questions seemed inappropriate, organizers said. The journalists attended one day of Defcon's Black Hat sister conference before being ejected on Friday.

Defcon did not release the names of the journalists or say who they claimed to work for.

This kind of incident happens nearly every year, said one of the show's senior organizers who goes by the name "Priest."

In the past, they say they've caught members of Mossad, the French Foreign Legion, and other organizations posing as press. By registering as journalists, they can get more time to query researchers and raise no suspicions by asking probing questions.

"When you think about it, being a member of the press is a pretty good cover because you can ask difficult questions, people love to see their names in print and in lights, so they're much more likely to talk to you, so you can get away with a lot more," Priest said.

The French Legionnaires were easy to spot, he said. "There's a certain body type you find with people who are in that type of work," he said. "Broad shoulders, narrow waist, not very tall. I'm looking at these guys, going, 'You're in far, far too good shape to be press.'"

The Legionnaires eventually admitted that they were not press and were allowed to stay at the show as regular attendees. They even went on stage for Defcon's annual "spot the fed" contest where people are invited to pick out government employees from a group of attendees.

Government employees posing as press often move very quickly to technical questions, rarely showing any interest in the motivation behind the research. They get "very technical very quickly," Priest said. "They're much more interested in what the latest is and what the greatest is and how they can use it."

North Korea Pardons US Reporters

Via BBC -

North Korean leader Kim Jong-il has issued a special pardon to two detained US journalists, the country's state news agency reports.

Laura Ling and Euna Lee had been found guilty of entering the country illegally in March.

The pair, arrested by North Korean guards, were sentenced to hard labour.

The news comes on the day that former US President Bill Clinton made a surprise visit to Pyongyang on what was described as a private mission.

-----------------------------

Clearly this was weeks if not months in the making...but it is great news.

According to older new stories, the ladies were being held at a guest house in Pyongyang...and were not exposed to hard labor at all - which was never expected even after the sentencing phase.

Rumors suggest that they reporters will be flying home with Bill Clinton himself.

Scientists Get a Million Linux Kernels to Run at Once

Via tgdaily.com -

Scientists at Sandia National Laboratories in Livermore, have run more than a million Linux kernels as virtual machines.

The technique will allow them to effectively observe behaviour found in malicious botnets, or networks of infected machines that can operate on the scale of a million nodes.

One of the researchers Ron Minnich, said they are often difficult to analyze since they are geographically spread all over the world.

However using virtual machine and a Thunderbird supercomputing cluster for the demonstration, the team was able to run VMS at a similar scale as a botnet.

This allows cyber researchers to watch how botnets work and explore ways to stop them in their tracks said Minnich.

The largest number of kernals that had been run at once was 20,000 kernels. However the more kernels that can be run at once the more effective cyber security professionals can be in combating the global botnet problem.

The hope is one day to emulate the computer network of a small nation, or even one as large as the United States, in order to ‘virtualise’ and monitor a cyber attack.”

“The sheer size of the Internet makes it very difficult to understand in even a limited way,” said Minnich.

It has been estimated that the team will need to run 100 million CPUs by 2018 in order to build a computer that will run at the speeds they need.

Britain To Put CCTV Cameras Inside Private Homes

Via Wired.com -

As an ex-Brit, I’m well aware of the authorities’ love of surveillance and snooping, but even I, a pessimistic cynic, am amazed by the governments latest plan: to install Orwell’s telescreens in 20,000 homes.

£400 million ($668 million) will be spend on installing and monitoring CCTV cameras in the homes of private citizens. Why? To make sure the kids are doing their homework, going to bed early and eating their vegetables. The scheme has, astonishingly, already been running in 2,000 family homes. The government’s “children’s secretary” Ed Balls is behind the plan, which is aimed at problem, antisocial families. The idea is that, if a child has a more stable home life, he or she will be less likely to stray into crime and drugs.

It gets worse. The government is also maintaining a private army, incredibly not called “Thought Police”, which will “be sent round to carry out home checks,” according to the Sunday Express. And in a scheme which firmly cements the nation’s reputation as a “nanny state”, the kids and their families will be forced to sign “behavior contracts” which will “set out parents’ duties to ensure children behave and do their homework.”

And remember, this is the left-wing government. The Shadow Home Secretary Chris Grayling, batting for the conservatives, thinks these plans are “too little, and too late,” implying that even more obtrusive work needs to be done. Rumors that a new detention center, named Room 101, is being constructed inside the Ministry of Love are unconfirmed.

Sin Bins for Worst Families [Sunday Express. Thanks, Annaliza]

Advance Notification of Security Updates for Java SE

http://blogs.sun.com/security/entry/advance_notification_of_security_updates5

On August 4, 2009, Sun will release the following security updates:
  • JDK and JRE 6 Update 15
  • JDK and JRE 5.0 Update 20
  • SDK and JRE 1.4.2_22
  • SDK and JRE 1.3.1_26
The following Sun Alerts corresponding to these updates will be released following the availability of these updates.
  • 263408
  • 263409
  • 263428
  • 263429
  • 263488
  • 263489
  • 263490
  • 264648
---------------------------------

It is assumed this will not include Java for OS X...since Apple creates their own Java packages for some strange reason.

Therefore, Apple will be vulnerable to above stated vulnerabilities...until they get around to fixing it.

The release notes for Java JRE 6 Update 15 have been updated...however, the sun alerts don't appear to be up yet.

Monday, August 3, 2009

MS-13 Smuggles Terrorists into U.S.

Via familysecuritymatters.org -

The situation at the border now poses a grave threat to national security.

Agent Mike Scioli of the U.S. Border Patrol confirms that the Tucson
sector of the Border Patrol is facing a worsening problem with Mara Salvatrucha, a Salvadoran street gang that now controls the flow of arms, drugs, and illegal aliens into the U.S.

Two members of the violent gang were collared last week in Tucson and Nogales.

Twenty have been brought into custody since President Barack Obama assumed the oath of office on January 20, 2009.

But the Salvadoran gang is bringing more than guns, dope, and Mexican peasant workers over the border.

In the wake of 9/11, Mara Salvatrucha attracted the attention of top al Qaeda officials, who realized that the gang could be used to smuggle operatives and weapons into the United States.[1] An agreement was forged between the terrorists and the gang-bangers. In exchange for safe passage across the border, al Qaeda – through its cells in South America – agreed to pay the Maras from $30,000 to $50,000 for each sleeper agent they managed to smuggle into the country with bogus matricula consulars.

[...]

News of the alliance between al Qaeda and Mara Salvatrucha prompted Honduran officials, including Security Minister Oscar Alvarez, to adopt a zero-tolerance law that makes membership in the street gang punishable by 12 years in prison. Mara members responded to this legislation by beheading scores of victims and leaving notes on the bodies for the Honduran government. One note read: “Idiots, the end of the world is approaching.”[3]

According to border patrol officials, including Sheriff D’Wayne Jenigan of Del Rio, Texas, thousands of Special Interest Aliens (SIAs), with the help of Mara Salvatrucha “coyotes,” have made their way across the Mexican border and into the land of the free and the home of the brave.

Such SIAs come from countries that pose national security concerns: Saudi Arabia, Syria, Iran, Pakistan, Afghanistan, Egypt, Somalia, Yemen, Jordan, Lebanon, and even Iraq.

The routes used by illegal aliens to enter the U.S. have become littered with discarded Muslim prayer blankets, pages from Islamic texts, and Arabic newspapers. Law enforcement officials have named such passageways “terrorists’ alleys” and a street leading north from the city of Douglas, Arizona, as “Arab Road.”

Apple Tried to Silence Owner of Exploding iPod with Gag Order

Via Times Online UK -

Apple attempted to silence a father and daughter with a gagging order after the child’s iPod music player exploded and the family sought a refund from the company.

The Times has learnt that the company would offer the family a full refund only if they were willing to sign a settlement form. The proposed agreement left them open to legal action if they ever disclosed the terms of the settlement.

The case echoes previous circumstances in which Apple attempted to hush up incidents when its devices overheated.

Ken Stanborough, 47, from Liverpool, dropped his 11-year-old daughter Ellie’s iPod Touch last month. “It made a hissing noise,” he said. “I could feel it getting hotter in my hand, and I thought I could see vapour”. Mr Stanborough said he threw the device out of his back door, where “within 30 seconds there was a pop, a big puff of smoke and it went 10ft in the air”.

Mr Stanborough contacted Apple and Argos, where he had bought the device for £162. After being passed around several departments, he spoke to an Apple executive on the telephone. As a result of the conversation, Apple sent a letter to Mr Stanborough denying liability but offering a refund.

The letter also stated that, in accepting the money, Mr Stanborough was to “agree that you will keep the terms and existence of this settlement agreement completely confidential”, and that any breach of confidentiality “may result in Apple seeking injunctive relief, damages and legal costs against the defaulting persons or parties”.

“I thought it was a very disturbing letter,” said Mr Stanborough, who is self-employed and works in electronic security. He refused to sign it.

“They’re putting a life sentence on myself, my daughter and Ellie’s mum, not to say anything to anyone. If we inadvertently did say anything, no matter what, they would take litigation against us. I thought that was absolutely appalling.

“We didn’t ask for compensation, we just asked for our money back,” he added.

Last week it emerged that Apple had tried to keep a number of cases where its iPod digital music players had started to smoke, burst into flames and even burned their owners, out of the public eye.

WikiLeaks - Canadian Counter-Insurgency Operations Manual

Confidential Canadian final Counter-insurgency Operations, manual, dated 13 Dec 2008, 249 pages.

http://wikileaks.org/wiki/Canadian_Counter-insurgency_Operations_manual%2C_13_Dec_2008

Malicious ATM Found in Rivera During Defcon

Via Wired.com -

There’s no honor among thieves, nor apparently among hackers.

A malicious ATM kiosk was positioned in the conference center of the Riviera Hotel Casino capturing data from an unknown number of hackers attending the DefCon hacker conference before someone noticed something suspicious about the kiosk.

An organizer for the conference said security authorities seized the device. It’s not known how long the ATM was in the hotel or whether it was placed there by a DefCon attendee to catch his fellow hackers or simply by an outside criminal group trying to target conference attendees.

Witnesses say the kiosk was well-placed to avoid surveillance cameras.

“In any casino anything that is considered that high value has a camera,” said Brian Markus, CEO of Aries Security who saw the machine, “and they placed it where there were no [hotel] cameras visibly watching that exact spot where the ATM was.”

Markus said it was clear to him the ATM was fake when he looked at the smoked glass on the front of the machine and noticed something funny about it. When he beamed a flashlight through the glass, instead of seeing a camera behind it, he saw the PC that was set up to siphon card data.

The ATM had been placed right outside the hotel’s security office.

Photo of the Day - Inside Alaska’s Answer to Area 51


Photo: João Canzani

High Frequency Active Auroral Research Program (Haarp)’s main antenna array consists of 180 silver poles rising from the ground, each a foot thick, 72 feet tall, and spaced precisely 80 feet apart.

Friday, July 31, 2009

Windows 7 Ultimate Activation Cracked with OEM Master Key

Via arstechnica.com -

Windows 7 Ultimate has been cracked. The pirate milestone, reached almost three months before Windows 7 is set to hit General Availability on October 22, 2009, was achieved via OEM instant offline activation that passes Windows Genuine Advantage validation and keeps the operating system permanently activated. Previous cracks weren't as solid: while they may be working now, they can easily be disabled by Microsoft. This one won't be so easy.

Both 32-bit and 64-bit Windows 7 Ultimate can now easily be activated, according to My Digital Life. For Windows 7 Professional, Windows 7 Home Premium, Windows 7 Home Basic, and Windows 7 Starter, the OEM-System-Locked Preinstallation (SLP) keys haven't been leaked, so they cannot be OEM-activated yet. It won't be long before easy-to-use Windows 7 activation toolkits start appearing in the wild.

The story begins with a Windows 7 Ultimate OEM DVD ISO from Lenovo leaking to a Chinese forum. The boot.wim file was then used to retrieve the OEM-SLP product key and OEM certificate for Windows 7 Ultimate. The SLP is a procedure used by Microsoft to preactivate the Windows operating system for mass distribution by major OEMs. Windows 7 and Windows Server 2008 R2 use SLP version 2.1, which is backwards-compatible with version 2.0, the version Windows Vista and Windows Server 2008 use. As such, after the OEM certificate and OEM product key were extracted, it was discovered that Windows 7 uses the same digitally signed OEM certificate, which has an .xrm-ms extension, that Vista uses.

The extracted Windows 7 Ultimate OEM-SLP product key can be used to activate an installed Windows 7 Ultimate system, and since the product key appears to be a master OEM-SLP product key for Windows 7 Ultimate, it can activate Windows 7 Ultimate from any OEM. Furthermore, even if the user already has a retail version of Windows 7 Ultimate installed, it can be converted to an OEM version with two simple commands, and then activated.

This is a major breakthrough for the Windows piracy world and a huge blow to Microsoft. Even if it was imminent, the fact that it has occurred so soon means pirates will have activated copies of Windows 7 a good week before even MSDN and TechNet subscribers get their hands on the RTM build on August 6, not to mention all the other groups Microsoft plans to give the build to. The Windows 7 RTM and Windows Server 2008 RTM build was compiled on July 13, 2009 and the official announcement was made on July 22, 2009.

Al Qaeda’s Training Changes In Response To US Strikes

Via CNN (h/t National Terror Alert) -

The interrogations of two accused Westerners who say they trained and fought with al Qaeda in the Pakistan-Afghanistan border region provide an inside view of the terror group's organizational structures.

Arguably, they shed more light on the state of al Qaeda than any material previously released into the public domain.

The documents reveal training programs and the protective measures the terrorist organization has taken against increasingly effective U.S. missile strikes.

Bryant Vinas -- a U.S. citizen who says he traveled to Pakistan in September 2007 to fight against Americans in Afghanistan -- stated that between March and July 2008 he attended three al Qaeda training courses, which focused on weapons, explosives, and rocket-based or -propelled weaponry.

During these classes, attended by 10-20 recruits, Vinas was taught how to handle a large variety of weapons and explosives, some of them of military grade sophistication, according to his account.

Vinas stated he became familiar with seeing, smelling and touching different explosives such as TNT, as well as plastic explosives such as RDX, and Semtex, C3 and C4 -- the explosive U.S. authorities have stated was used in al Qaeda's attack on the USS Cole in 2000. Vinas also learned how to make vests for suicide bombers.

Vinas stated he was also instructed how to prepare and place fuses, how to test batteries, how to use voltmeters and how to build circuitry for a bomb.

According to his account, al Qaeda also offered a wide variety of other courses including electronics, sniper, and poisons training. Instruction in the actual construction of bombs, he stated, was offered to al Qaeda recruits who had become more advanced in their training.

[...]

Othmani provided interesting new details about the training facilities being used by al Qaeda in the tribal areas.

His group trained in a small mountain shack, a far cry from the large camps al Qaeda had run in Taliban-era Afghanistan, when it had been able to operate with little danger of being targeted by military strikes.

Othmani's account made clear that al Qaeda has had to decentralize its operations in Pakistan in response to the growing effectiveness of U.S. Predator strikes.

However the wide number of training courses described by both Vinas and Othmani suggest that al Qaeda has been able to adapt well to the new security environment.

[...]

Vinas stated that when they completed their training, Al Qaeda instructors did a written evaluation of their performance. Vinas had been judged qualified to participate in missile attacks against U.S. and NATO bases in Afghanistan, according to his account.

That suggests al Qaeda has maintained its capacity for administration and paperwork even in a harsher security environment.

[...]

He is believed to be still at large in the Pakistan-Afghan border area. Vinas was told that the training course that Hafith set up focused on kidnapping and assassination, including instruction on the use of silencers and how to break into and enter a property.

The revelations raise the possibility that al Qaeda was developing a program of targeted assassinations. Though al Qaeda has carried out some assassinations in the past, most of its attacks in the West have not targeted any particular individuals but crowded areas, such as mass transport.

According to Othmani, al Qaeda fighters totaled between 300-500 in Pakistan's Tribal Areas - spread out in groups of 10. Such decentralization was a function of the growing deadliness of U.S. Predator strikes.

Hicham Beyayo, a Belgian jihadist volunteer, said the group moved around a lot because such strikes were known to be "very effective," his lawyer Christophe Marchand, told CNN.

The loss of an increasing number of operatives, stated Othmani, prompted an order from al Qaeda's top command for fighters to remain inside as much as possible. In order to keep in touch jihadists operated a courier service across the region, according to the Frenchman's testimony.

FCC Opens Investigation into Apple's Rejection of Google Applications

Via battellemedia.com -

And they are opening an investigation into it.

According to a Dow Jones Newswire report, on Friday afternoon the FCC sent letters to Apple, AT&T, and Google. The federal inquiry asks Apple why the Google Voice application was rejected from its App Store for the iPhone and iPod Touch, and why it removed third-party applications built on the Google app that had been previously approved. The federal commission also asks whether AT&T was allowed to weigh in on the application before it was rejected, and seeks a description of the application from its creator, Google, according to the report.

For background, see my piece chastising Apple here.

Thursday, July 30, 2009

Algorithm Sought by Air Force to Analyze Insider Behavior

Via Govinfosecuirty.org -

The Air Force is seeking an entrepreneurial innovator to develop technology to analyze the conduct of insiders to determine if they pose a threat to government IT systems.

In a call for proposals aimed at small businesses, posted on Tuesday, the Air Force is asking outside developers to "define, develop and demonstrate innovative approaches for determining 'good' (approved) versus 'bad' (disallowed/subversive) activities, including insiders and/or malware." For their initial efforts, the Air Force will pay up to $100,000.

The proposal says current techniques that monitor illicit activities only address the most blatant violations of policy or the grossest deviations from accepted behavior. Most systems concentrate their resources on repelling attacks at the network borders with little attention devoted to threats that evade detection and/or emanate from within. The proposal states:
"As such, there currently exists a great need across the federal, military and private sectors for a viable and robust means to provide near-real-time detection, correlation and attribution of network attacks, by content or pattern, without use of reactive previously-seen signatures. Many times, these trusted entities have detailed knowledge about the currently-installed host and network security systems, and can easily plan their activities to subvert these systems."
In the first phase, Air Force planners envision the development of a prototype algorithm that incorporates heuristic analysis for determining approved versus disallowed or subversive activities, including insiders and/or malware. The awarded contractor also would propose an architecture and perform a feasibility analysis of the algorithm and architecture during the initial phase.

In the second phase, the contractor would implement the best approach from Phase 1 in an experimental hardware/software environment, representative of the Air Force cyber infrastructure. They'd be asked to correlate Phase 1 analysis with experimental results as well as analyze the prototype system with respect to performance, scalability, cost, security and vulnerability.

Hafiz Mohammad Saeed – India’s Most Wanted Man Free Again in Pakistan

Via The Jamestown Foundation -

The release of Hafiz Mohammad Saeed, founder of proscribed Lashkar-e-Taiba (LeT) and Amir of Jama'at-ud-Da'wa (JuD), from detention last month in Pakistan has raised eyebrows in the West as well as India. He was released from house arrest on June 2 when the Lahore High Court ruled it did not have enough evidence against him on terrorism charges. However, Pakistan's Deputy Attorney General Shah Khawar says that Pakistan's law enforcement and intelligence agencies have enough evidence to suggest that a freed Hafiz Saeed is a continuing security threat. The Punjab provincial government and the federal government of Pakistan have already filed petitions before the Pakistani Supreme Court seeking a reversal of the decision of Lahore High Court. Nevertheless, the federal government continues to struggle to make an adequate case for his preventive detention and the Punjab provincial government has admitted its evidence is insufficient (The News [Islamabad], July 17; Daily Times [Lahore], July 17).

[...]

Hafiz Mohammad Saeed also met with Shaykh Abdullah Yusuf Azzam, an influential Palestinian jihad ideologue and mentor of Osama bin Laden. Azzam influenced him to found the Markaz Dawa-wa’l-Irshad (Center for Call and Guidance) in Muridke, Lahore in 1987. The institution preached jihad and the Wahhabi- Salafi form of Islam. Hafiz Saeed founded LeT in the early 1990s, allegedly with support from Inter-Services Intelligence (ISI), Pakistan's military intelligence agency. LeT then shifted the focus of its jihad from Afghanistan to Indian-administered Kashmir (The Hindu, June 3).

LeT is believed to have been involved in almost all major attacks against India over the disputed territory of Kashmir. Hafiz Saeed stepped down from the leadership of LeT soon after India blamed this group for the terrorist attack on its parliament in December 2001. He handed over leadership of the group to Maulana Abdul Wahid Kashmiri, who is based in Srinagar, part of Indian-administered Kashmir. Shortly after this, Pakistan banned LeT after the United States added it to its list of designated terrorist organizations.

However, Saeed was quick to revive his old Markaz Dawa-wa’l-Irshad organization with a slight modification of its name to Jama'at-ul-Da'wa, beginning as a charity and public welfare organization. It is common practice for militant organizations in Pakistan to rename themselves so as to bypass the law and avoid official bans. The old offices of LeT simply changed the names on their signboards with no significant change to the nature of the activities carried out inside. However, after 9/11, due to changes in Pakistan's policies towards India and pressure from the United States, Hafiz Saeed and his organization stepped back from aggressive jihadi activities in Kashmir. Despite this, several offices of LeT continued to recruit militants for jihad in Pakistan-administered Kashmir (BBC News, June 2).

India has long asked for the extradition of Hafiz Saeed, whom it suspects of being the mastermind behind all major terrorist attacks inside India. However, Pakistan’s government wants him to be tried inside Pakistan. So far, Pakistan has not brought sufficient evidence to punish him for his involvement in terrorist activities (Daily Times, June 5). Since 2001, he has been detained three times, but in every instance he was freed due to the apparent lack of evidence against him. In July 2006, India asked the Government of Pakistan to ban the JuD and arrest its leaders, including Hafiz Saeed, for their alleged involvement in the July 11 Mumbai train bombings that killed over 200 people. Pakistan rejected the Indian claims and put Hafiz Saeed under house arrest. He was released a month later (Hindustan Times, June 2).

The Pwnie Awards 2009 Winners

The Pwnie Awards is an annual awards ceremony celebrating and making fun of the achievements and failures of security researchers and the wider security community.

Pwnie Awards 2009 Winners....

Best server side bug =
Linux SCTP FWD Chunk Memory Corruption

Best client side bug =
msvidctl.dll MPEG2TuneRequest Stack buffer overflow

Best privilege escalation = Linux udev Netlink Message Privilege Escalation

Mass 0wnage = Red Hat Networks Backdoored OpenSSH Packages

Most innovative research = From 0 to 0day on Symbian

Lamest vendor response = Linux / Linus Torvalds

Most overhyped bug = MS08-067 Server Service NetpwPathCanonicalize() Stack Overflow

Best song = Nice Report

Most epic fail = Twitter Gets Hacked and the "Cloud Crisis

Lifetime achievement award
= Solar Designer

------------------------------

Special thanks to @shazzzam for the play-by-play on twitter. I had to run out after the "most epic fail" to catch my reservation @ MESA Grill.

For the curious foodies out there, I had the Fire Roasted Veal Chop with a glass of Voss Estate Pinot Noir...then the toasted coconut layer cake and black coffee for desert. So very good.

Venezuela Increases Military Co-operation with Russia

Via Janes.com -

The televised signing of the 'New Statute on Military-Technical Co-operation' followed an earlier announcement by Venezuelan President Hugo Chávez on 24 July that Venezuela was intending to buy enough Russian tanks to double its fleet.

BIND 9 Denial of Service Attacks in the Wild

Via SANS ISC -

Earlier today Marc posted a short diary about a vulnerability in the Internet Systems Consortium's BIND 9 (all versions). As you almost certainly know, BIND is the most popular DNS service application running on majority of DNS servers today – and DNS is one service that we *really* need.

As the DoS attacks have been seen in the wild, and simple scripts that can be used to reproduce the attack are also easily available, this is not really surprising.

I wanted to draw your attention to this vulnerability (if you are running a BIND DNS server) – although the vulnerability exists in the dynamic update feature of BIND, even installations that have dynamic updates disabled are affected! This makes this vulnerability especially dangerous.

Only servers hosting master zones are vulnerable though, so even if the master DNS servers are down, all slaves should still continue to work (I'm not sure what happens if those slaves are masters for some other zones and they are subsequently taken down).

No workarounds exist – you might be able to create some firewall rules that will drop these packets though. In any case, it is recommended to upgrade your BIND DNS servers urgently from https://www.isc.org/node/474

Apple: Jailbreaking Could Knock out Transmission Towers

Via PC World -

Apple has told the U.S. Copyright Office that modifying the iPhone's operating system could crash a mobile phone network's transmission towers or allow people to avoid paying for phone calls.

The claims are Apple's contribution to the Copyright Office's regular review of the U.S. Digital Millennium Copyright Act (DMCA), a law that forbids the circumvention of copy control mechanisms.

Apple says that modification of the phone's software, a process known as jailbreaking, could lead to major network disruptions. Jailbreaking gets around the copyright control features that prohibit, for example, the installation of applications unapproved by Apple.

Apple's arguments, filed June 23, seek to rebut a request to the agency by the digital rights group Electronic Frontier Foundation (EFF) that modifications to the iPhone's software do not violate the DMCA and should be allowed.

The U.S. Copyright Office holds hearings every three years to consider requests to make exceptions to the nation's copyright law.

Jailbreaking continues to be popular with iPhone users, who can also then use their devices on the networks of operators who have not signed distribution deals with Apple.

Apple argues that the practice constitutes copyright infringement. No one has been prosecuted for jailbreaking, although Apple discourages it.

Apple's latest filing describes potentially severe technical problems operators could face with jailbroken phones.

Since the OS code is accessible on a jailbroken phone, Apple said it would be possible to reprogram one to gain access to the phone's BBP (baseband processor), which controls the connection to the operator's network.

"Because jailbreaking makes hacking of the BPP software much easier, jailbreaking affords an avenue for hackers to accomplish a number of undesirable things on the network," the filing said.

By gaining access to the BPP, hackers could change the phone's ECID (exclusive chip identification), which identifies a phone to the transmission towers, Apple said.

"With access to the BBP via jailbreaking, hackers may be able to change the ECID, which in turn can enable phone calls to be made anonymously (this would be desirable to drug dealers, for example) or charges for the calls to be avoided," Apple said.

While some of Apple's claims may be true, network operators rely on a separate identifier, contained in the phone's SIM (Subscriber Identity Module), to distinguish between customers for billing and authentication purposes.

Apple went on to say that if several phones were modified to have the same ECID, it could cause a transmission tower to malfunction or kick phones off the network. Also, operator limits on data transmission could be circumvented, allowing a hacker to conduct a denial-of-service attack and crash the tower.

"In short, taking control of the BPP software would be much the equivalent of getting inside the firewall of a corporate computer -- to potentially catastrophic result," Apple said.

Technical considerations aside, the EFF has argued that Apple's lock on the iPhone is unmerited from a copyright protection perspective and aims to "suppress competition from independent iPhone application vendors."

The Copyright Office is expected to make a decision in the case later this year.

Data Detailing New York Stock Exchange Network Exposed on Unsecured Server

Via Wired.com (Threat Level) -

Sensitive information about the technical infrastructure of the New York Stock Exchange’s computer network was left unsecured on a public server for possibly more than a year, Threat Level has learned.

The data, which was removed after Threat Level disclosed the situation to the NYSE, included several directories of files containing logs; server names; IP addresses; lists of hardware; lists of software versions running on the network; and configuration and patch histories, including what patches have not yet been installed. It was all available on a publicly accessible, unprotected FTP server maintained by EMC, a company that sells storage systems and managed services to the NYSE and other companies.

“We have discussed the matter with EMC and at this point we believe that there has been no impact on our operations or our customers,” said NYSE spokeswoman Mirtha Medina in an e-mail.

“Unless the NYSE knows that this stuff is out there and has approved for it to be out there (highly doubtful), I see no good reason why EMC is allowing this to happen,” said an information security specialist via e-mail who asked not to be named because he works in the financial industry. “Leaving information like this in a ‘public’ place definitely would make a bad guy’s job somewhat easier.”

The information could allow an intruder to map the NYSE’s network architecture and determine what vulnerabilities exist in the system.

Cheerleader Sues School, Coach After Illicit Facebook Log-in

Via arstechnica.com -

At this point, you would think that most users would be aware that they should keep embarrassing information off of Facebook. Everyone from potential employers to the press regularly check users' accounts on the service, looking for evidence of illicit or debauched behavior, and a number of jobs have been lost due to the information found there. Still, many fail to exercise discretion when using the service, people in positions of power are catching on, and there continue to be problems that result from the blurring of boundaries between public and private.

In what may be the latest example, a suit was filed in Mississippi that alleges a school official—more specifically a teacher acting in her capacity as a cheerleading coach—demanded that members of her squad hand over their Facebook login information. According to the suit, the teacher used it to access a student's account, which included a heated discussion of some of the cheerleading squad's internal politics. That information was then shared widely among school administrators, which resulted in the student receiving various sanctions.

As we noted when Bozeman, Montana attempted to obtain login credentials from anyone applying for a municipal job, it's easy for anyone to view pictures and text that a Facebook user has chosen to make public simply by signing up for an account with the service. By demanding login credentials, authorities gain access to materials that users have chosen to keep private. Whether this is done because people intend to get access to private data or because they are simply unfamiliar with how Facebook operates isn't always obvious, and probably varies from case to case.

According to this suit, the student's login details were requested during school hours, and the teacher accessed the account the same day. The account included the contents of a discussion between the student and a fellow member of the school's cheerleading squad about its internal politics, which was then allegedly shared with other squad supervisors and the school administration. The student was then "publicly reprimanded, punished, and humiliated" due to the contents of that discussion.

The student was allegedly forced to sit out of various school activities and had difficulties arranging her academic schedule to avoid taking classes from any of the individuals who were both coaches and teachers. Her parents claim that attempts to discuss the problem with school administrators brought them no relief.

The Student Press Law Center has more detailed account (via TechDirt) of the events, in which it reports that several other students asked for their logins simply deleted their accounts using their cell phones, preventing this sort of intrusion; the schools apparently have a filter that blocks access to its Web interface from school computers. It also suggests that the initial search of the Facebook accounts was done with the intent of finding pictures of the students smoking or drinking.

In any case, the suit alleges that the school's administration and staff, along with five John Does, violated the student's Constitutional rights to privacy, free speech and association, and subjected her to cruel and unusual punishment. There are also charges of causing emotional distress, defamation of character, and civil conspiracy. In general, courts have concluded that public school students have some constitutional rights, but only a subset of those afforded to the general populace. It may be that the student's lawyers are aiming broadly in order to find some area of constitutional law in which the student is clearly protected.

In any case, the message should be clear: either through malice or cluelessness, people in positions of authority are increasingly demanding complete access to users' personal accounts and, in moments of weakness, many users appear to be giving it to them. If there's information you're not comfortable sharing with the world, Facebook, Twitter, and similar services aren't the place for it.

Monday, July 27, 2009

Vegas Baby! Vegas!

So, I am packing for Blackhat 2009 and Defcon 17. Should be there before 5pm local time tomorrow.

Blog might be a little quiet this week, but I will try to post when I can...when I am not "working" or being social. =)

Russian Navy Accidentally Dummy Shells Vladivostok

Via Moscow Times -

A dummy shell fired from a warship veered off course Friday and landed just feet from a building in a residential area of Vladivostok, less than two months after a similar incident off the Gulf of Finland.

The anti-ship shell was fired during rehearsals for Sunday’s Navy Day celebrations in the far eastern port. For reasons yet to be determined, the projectile changed course after takeoff and landed beside a nine-story building, breaking windows and leaving a 1.5-meter crater, RIA-Novosti reported.

No one was hurt in the incident, and the Navy said it was investigating.

A bomb disposal team from the Pacific Fleet was sent to dig out and remove the shell. Military officials said it was intended only to make a sound effect for the parade.

Pacific Fleet spokesman Roman Martov said experts would evaluate what caused the bomb to deviate from its course. “All the parameters were set right, it was supposed to fall into the ocean,” he said, Interfax reported.

On May 28, a similar incident happened in the Leningrad region, when a Russian warship in the Gulf of Finland fired 14 shells in the direction of a dacha settlement on shore.

Fragments of the shells rained down on the village, but damage was minimal and no one was injured. The Navy later promised the dacha settlement “several tens of thousands of rubles” in damages, Ekho Moskvy reported.

Microsoft Office Visualization Tool (OffVis)

http://www.microsoft.com/presspass/press/2009/jul09/07-27BlackHat09PR.mspx

A free tool designed to help combat file format-based software vulnerabilities and exploits, OffVis will allow customers to better understand and deconstruct Microsoft Office-based attacks. As a result, security vendors can build deeper, more precise malware detection signatures and develop new techniques for analyzing malware. The tool is available for no-charge
download.

Advance Notification for July 2009 Out-of-Band Releases

http://blogs.technet.com/msrc/archive/2009/07/24/advance-notification-for-july-2009-out-of-band-releases.aspx

We have just published our advance notification for an out-of-band security bulletin release, with a target of 10:00 AM Pacific Time next Tuesday, July 28, 2009.

While this release is to address a single, overall issue, in order to provide the broadest protections possible to customers, we’ll be releasing two separate security bulletins:

1. One Security Bulletin for Visual Studio
2. One Security Bulletin for Internet Explorer

While we can’t go into specifics about the issue prior to release, we can say that the Visual Studio bulletin will address an issue that can affect certain types of applications. The Internet Explorer bulletin will provide defense-in-depth changes to Internet Explorer to help provide additional protections for the issues addressed by the Visual Studio bulletin. The Internet Explorer update will also address vulnerabilities rated as Critical that are unrelated to the Visual Studio bulletin that were privately and responsibly reported.

Customers who are up to date on their security updates are protected from known attacks related to this Out of Band release.

Nearly Half Of Companies Lack A Formal Patch Management Process

Via DarkReading -

An open initiative for building a metrics model to measure the cost of patch management found that one-fourth of organizations don't test patches when they deploy them, and nearly 70 percent don't measure how well or efficiently they roll out patches, according to survey results released today.

Project Quant, a project for building a framework for evaluating the costs of patch management and optimizing the process, today also rolled out Version 1 of its metrics model today. Project Quant is an open, community-driven, vendor-neutral model that initially began with financial backing from Microsoft.

"Based on the survey and the additional research we performed during the project, we realized that despite being one of the most fundamental functions of IT, patch management is still a relatively immature, inconsistent, and expensive practice. The results really reinforced the need for practical models like Quant," says Rich Mogull, founder of Securosis, and one of the project leaders of the initiative.

The survey of around 100 respondents was voluntary and participation was solicited mainly via metrics and patch management organizations, so the organizers say the respondents were most likely organizations that take patch management seriously: "The corollary to this interpretation is that we believe the broader industry is probably LESS mature in their patch management process than reflected here," the report says.

Even so, over 40 percent of them have either no patch management process in place, or an informal one. And 68 percent say they don't have a metric for measuring how well they deploy patches, such as the time it takes them to deploy a patch, etc. One-fourth say they don't do any testing before they roll out a patch, and 40 percent rely on user complaints to validate the success of a patch, according to the survey.

And over 50 percent don't measure adherence to policy, including compliance when it comes to patching.

"It's clear we have a very long way to go on something we all assume is a boring, basic task. Considering where the bad guys are shifting attacks to, we desperately need better methods and means of keeping our systems up to date," Mogull says. "My hope is that Quant can help fill this gap."

Patch management for workstation and server operating systems was one of the most mature processes. "What's most interesting is the variation of maturity [of patch management] across platforms. Not that this was totally unexpected, but the least mature areas of patching seem to correlate almost directly with the fastest-growing areas of attacks," Mogull says, such as device drivers, database servers, business application servers, and networking hardware and software.

Meanwhile, Project Quant's survey is ongoing, so if you'd like to participate, visit this link.

--------------------------

As a former patch administrator ...this topic hits home with me.

So many companies are behind the curve on patch management, it is quite shocking.

Kevin Spacey Tries, Fails To Explain Twitter To Letterman

802.11N Becomes Official In September

Via DSLReports.com -

Last Friday, Bob Heile, the chairman of the IEEE 802.15 working group on Personal Area Networks, noted that the 802.11N Wi-Fi standard has finally been sent on to the Standards Review Committee. That means, assuming no further hiccups, that the standard will become finalized by September. The ratification process stems back nearly five years, slowed by a factionalized debate over competing technologies. A draft version of 802.11n was approved in January 2006, and the first wave of 802.11N hardware hit the market -- with all subsequent evolutions (supposedly) applied by firmware update.

Sunday, July 26, 2009

Matasano Hack by Anti-Sec Supporters

http://seclists.org/fulldisclosure/2009/Jul/0388.html

Mirror Screenshot
http://users.volja.net/database/matasano.PNG

Currently the Matasano website appears to be down, which is it a good indication that this is no fake.

PhreakNIC 12 Videos

PhreakNIC is a annual convention for hackers, phone phreaks, cypherpunks, programmers, civil libertarians, ham/scanner enthusiasts, security experts, feds, and culture jammers held in Nashville, TN.

IronGeek.com has put together an index page for all the videos...
http://www.irongeek.com/i.php?page=videos/pn12/phreaknic-12-videos

Defcon iPhone Application

http://www.group6.net/defconapp/

DEFCON® Hacker Conference - The Hacker Community's Foremost Social Network.

After years of misplaced, begged, borrowed, stolen Defcon schedules, we decided to do something to help. Introducing the Defcon iPhone app. Get all the up to date details on the con on your iPhone/iPod Touch. In addition to that, you can view the official Defcon RSS feed and #defcon Twitter posts. Talk and event calendars, speaker and dj bios, and a map of the venue.

Features:

1. Talk Calendar
2. Event Calendar
3. Speaker/DJ Biographies
4. Defcon RSS Feed Reader
5. Twitter #defcon

Status: Available Soon

The app has currently been submitted for Apple’s approval into their store. We’re looking at other options for distribution in case the app does not get approved in time. Follow @dtjedi or @tkimball via twitter for updates or check back here.

Saturday, July 25, 2009

Hacker Says iPhone 3GS Encryption Is ‘Useless’ for Businesses

Via Wired.com -

Apple claims that hundreds of thousands of iPhones are being used by corporations and government agencies. What it won’t tell you is that the supposedly enterprise-friendly encryption included with the iPhone 3GS is so weak it can be cracked in two minutes with a few pieces of readily available freeware.

“It is kind of like storing all your secret messages right next to the secret decoder ring,” said Jonathan Zdziarski, an iPhone developer and a hacker who teaches forensics courses on recovering data from iPhones. “I don’t think any of us [developers] have ever seen encryption implemented so poorly before, which is why it’s hard to describe why it’s such a big threat to security.”

With its easy-to-use interface and wealth of applications available for download, the iPhone may be the most attractive smartphone yet for business use. Many companies seem to agree: In Apple’s quarterly earnings conference call Tuesday, Apple chief operating officer Tim Cook said almost 20 percent of Fortune 100 companies have purchased 10,000 or more iPhones apiece; multiple corporations and government organizations have purchased 25,000 iPhones each; and the iPhone has been approved in more than 300 higher education institutions.

But contrary to Apple’s claim that the new iPhone 3GS is more enterprise friendly (for reference, see Apple’s security overview for iPhone in business [pdf]), the new iPhone 3GS’ encryption feature is “broken” when it comes to protecting sensitive information such as credit card numbers and social-security digits, Zdziarski said.

Zdziarski said it’s just as easy to access a user’s private information on an iPhone 3GS as it was on the previous generation iPhone 3G or first generation iPhone, both of which didn’t feature encryption. If a thief got his hands on an iPhone, a little bit of free software is all that’s needed to tap into all of the user’s content. Live data can be extracted in as little as two minutes, and an entire raw disk image can be made in about 45 minutes, Zdziarski said.

Wondering where the encryption comes into play? It doesn’t. Strangely, once one begins extracting data from an iPhone 3GS, the iPhone begins to decrypt the data on its own, he said.

To steal an iPhone’s disk image, hackers can use popular jailbreaking tools such as Red Sn0w and Purple Ra1n to install a custom kernel on the phone. Then, the thief can install an Secure Shell (SSH) client to port the iPhone’s raw disk image across SSH onto a computer.

To demonstrate the technique, Zdziarski established a screenshare with Wired.com, and he was able to tap into an iPhone 3GS’ data with a few easy steps. The encryption did not pose any hindrance.

Nonetheless, professionals using the iPhone for business don’t seem to care, or know, about the device’s encryption weakness.

“We’re seeing growing interest with the release of iPhone 3.0 and the iPhone 3GS due in part to the new hardware encryption and improved security policies,” Cook said during Apple’s earnings call. “The phone is particularly doing well with small businesses and large organizations.”

Clearly, the gigantic offering of iPhone applications is luring these business groups. Quickoffice Mobile, for example, enables users to access and edit Microsoft Word or Excel files on their iPhone. For handling transactions, merchants can use apps such as Accept Credit Cards to process a credit card on an iPhone anywhere with a Wi-Fi or cellular connection.

Several employees of Halton Company, an industrial equipment provider, are using iPhones for work, according to Lance Kidd, chief information officer of the company. He said the large number of applications available for the iPhone make it worthy of risk-taking.

“Your organization has to be culturally ready to accept a certain degree of risk,” Kidd said. “I can say we’ve secured everything as tight as a button, but that won’t be true…. Our culture is such that our general manager is saying, ‘I’m willing to take the risk for the value of the applications.’”

Kidd noted that Halton employees are not using iPhones for holding confidential customer information, but rather for basic tasks such as e-mailing and engaging with clients via social networking sites such as Facebook and Twitter. Halton also plans to code apps strictly for use at the company, Kidd said.

According to Kidd, a security expert performed an evaluation of Halton, and he said it was possible for any hacker to find an infiltration no matter the level of security. Therefore, Halton has measures in place to respond to an information security threat rather than attempt to avoid it.

“It’s like business continuity,” Kidd said. “You prepare for disasters. You prepare for if there’s an earthquake and the building breaks down, and you prepare for if there’s a crack in [information] security.”

But Zdziarski stands firm that the iPhone’s software versatility isn’t worth the risk for use in the workforce. He said sensitive information is bound to appear in e-mails or anything that can be contained on the iPhone’s disk, which can be easily extracted by thieves thanks to the new handset’s shoddy encryption.

---------------------

Lets get real here, the iPhone was never designed for business. It was born from the hugely popular iPod, which we would all agree wasn't designed with business needs in mind either.

Beyond the weak encryption on the device itself...why would any company want iTunes and Quicktime installed on its laptop, especially if they aren't required for business. Personally, I don't see many business benefits in iTunes anyways.

Every piece of software that is installed on a system increases its possible attack surface. Combined with Apple's lack luster security practices (both on a coding level & a communication level)....you have a recipe for increased risk of data breach...both on the iPhone and the machines used to manage it.

In 2007, Gartner suggested to keep the iPhone out of enterprise...and from a strictly security perception, I see few reason overall to change that suggestion.

Friday, July 24, 2009

Blackhat 2009 Preview - Bypassing IE ActiveX Killbits

Preview Video
http://www.hustlelabs.com/bh2009preview/

Blackhat 2009 - The Language of Trust: Exploiting Trust Relationships in Active Content
https://www.blackhat.com/html/bh-usa-09/bh-usa-09-speakers.html#Dowd

SHA-3 Second Round Candidates

NIST has selected the Second Round Candidates of the SHA-3 Competition. A report summarizing NIST’s selection of these candidates will be forthcoming. A year is allocated for the public review of these algorithms, and the Second SHA-3 Candidate Conference is being planned for August 23-24, 2010, after Crypto 2010.

------------------

Make sure you check out the SHA-3 Zoo as well...good stuff.

Al-Shabaab Takes Over Two United Nations Offices in Somalia

Via Shimron Letters -

The Somali armed rebel group, Al Shabaab, looted two UN compounds and demanded an end to UN relief work in the impoverished Horn of Africa nation, the UN said Monday.

Al Shabaab, which has been trying to overthrow the transitional government in Mogadishu, looted the UN compound in Baidoa of emergency communication equipment, forcing the organisation to evacuate personnel and suspend its operations.

The UN said it was powerless when challenged by the rebels because the compound had no security guards.

In Wajid, protected by a minimum security, the rebels entered the compound of the World Food Programme and drove away with two vehicles and some furniture that did not belong to the UN.

“These two events happened as Al Shabaab broadcast on Monday a message on local Somali radio calling for the closing of offices” of several UN agencies, including the UN Development Programme, the UN said.

“The UN is reassessing the situation on the ground and is optimistic that the minimal conditions on the ground will be restored to allow the critical humanitarian work to resume in Baidoa and continue elsewhere in Somalia,” the UN said.

Russian Navy Declassifies Cold War Close Encounters

Via Wired.com (Danger Room) -

Great catch by Phil Ewing at Navy TimesScoop Deck blog: the Russian navy has just declassified its records of Cold War UFO sightings. Turns out “50 percent of UFO encounters are connected with oceans. Fifteen [percent] more — with lakes. So UFOs tend to stick to the water,” one Russian officer explained.

“On several occasions the instruments gave reading of material objects moving at incredible speed,” a sub commander recalled. “Calculations showed speeds of about 230 knots, or 400 kph. Speeding so fast is a challenge even on the surface. But water resistance is much higher. It was like the objects defied the laws of physics. There’s only one explanation: the creatures who built them far surpass us in development.”

Insert jab about superior U.S. Navy submarine technology, here.

All joking aside, in one alleged incident in 1982, three navy diver trainees reportedly died pursuing what survivors described as “a group of humanoid creatures dressed in silvery suits” in Baikal, the world’s deepest lake.

Heap Spraying with Actionscript

Via FireEyes Malware Intelligence Lab -

As you may have heard, there's a new Adobe PDF-or-Flash-or-something 0-day in the wild. So this is a quick note about how it's implemented, but this blog post is not going to cover any details about the exploit itself.

Most of the Acrobat exploits over the last several months use the, now common, heap spraying technique, implemented in Javascript/ECMAscript, a Turing complete language that Adobe thought would go well with static documents. (Cause that went so well for Postscript) (Ironically, PDF has now come full circle back to having the features of Postscript that it was trying to get away from.) The exploit could be made far far less reliable, by disabling Javascript in your Adobe Acrobat Reader.

But apparently there's no easy way to disable Flash through the UI. US-CERT recommends renaming the %ProgramFiles%\Adobe\Reader 9.0\Reader\authplay.dll and %ProgramFiles%\Adobe\Reader 9.0\Reader\rt3d.dll files. [Edit: Actually the source for this advice is the Adobe Product Security Incident Response Team (PSIRT).]

Anyway, here's why… Flash has it's own version of ECMAScript called Actionscript, and whoever wrote this new 0-day, finally did something new by implementing the heap-spray routine with Actionscript inside of Flash.

Thursday, July 23, 2009

Microsoft Scrambling to Close Stubborn Security Hole

Via Security Fix -

Microsoft may soon be taking the unusual step of issuing an out-of-band security update to address multiple weaknesses that stem from a Windows security flaw that the software giant tried to fix earlier this month, Security Fix has learned.

Last week, on its regularly scheduled Patch Tuesday (second Tuesday of the month), Redmond issued software updates to plug nine security holes. Among those was a patch for a flaw in Windows and Internet Explorer that hackers were exploiting to break into PCs. However, it soon became clear that Microsoft had known about this vulnerability since at least April 2008.

On July 9, noted security researcher Halvar Flake published a blog post suggesting that the reason Microsoft took so long to fix the bug may be because the flaw was caused by a far more systemic problem in Windows.

According to Flake, the problem resides in a collection of code that Microsoft uses in a number of places in Windows. This code "library" is also provided to third-party software makers to help them build programs that can leverage certain built-in features of Windows.

As a result, Flake concluded, Microsoft may have fixed only a subset of the problem on Windows with its patch this month.

"The bug is actually much 'deeper' than most people realize," Flake wrote. "MS might have accidentally introduced security vulnerabilities into third party products."

I reached out to Flake for additional information, but he told me that shortly after he published that blog post he received a 3 a.m. phone call from Microsoft asking him please not to comment further.

Microsoft has not officially responded to requests for comment about Flake's research. But a source within Microsoft said Redmond could issue an out-of-band update prior to next month's Patch Tuesday to address the outstanding flaws.

The decision over whether to do that or wait until next month's Patch Tuesday may hinge upon whether attackers begin exploiting these other vulnerable areas by using Microsoft's patch (and Flake's research) as a guide to locating the flaws. What's more, this bug is almost certain to be discussed at Black Hat and Defcon, the world's largest annual security conferences, being held next week in Las Vegas.

Indonesian Unaware Husband was Noordin Mohammed Top - Jemaah Islamiya's Bomb Maker & Financier

Via Reuters -

The Indonesian wife of Noordin Top, the region's most-wanted militant because of his role in a string of bomb attacks in Indonesia, did not know his real name and thought he was a teacher, her lawyer said on Thursday.

Malaysian-born Top is one of the prime suspects behind last week's near-simultaneous suicide bomb attacks on the JW Marriott and Ritz-Carlton, two luxury hotels in Jakarta's main business district, which killed nine people and injured 53, including Indonesians and foreigners.

Police and security analysts said the attacks bore the hallmarks of Jemaah Islamiah (JI), the militant Islamist group responsible for previous attacks in Jakarta and on the resort island of Bali, or of a splinter group headed by Top.

Arina Rochmah was detained by the police under Indonesia's terrorism law, her lawyer Achmad Michdan told Reuters, adding that she could be charged for harbouring or hiding information about a terror suspect.

Michdan said Rochmah had no knowledge that her husband, Abdul Halim, was Noordin Top, although she admitted he was seldom at home due to his work teaching at an Islamic boarding school in South Sulawesi.

He said that police took Rochmah, 25, her two children and her mother on Wednesday from an Islamic boarding school founded by her father in Cilacap, in central Java.

Michdan added that Rochmah had come to Jakarta and asked for legal protection a few weeks ago, after the police raided the family's house. Police said that a bomb found at the house was identical to those used in Friday's blasts.

Under the terrorism law, police have seven days to declare someone a suspect.

--------------------------------

Having fleeing from Malaysia after the government cracked down on Islamists following the September 11th attacks, he married using an assumed name, Abdurrachman Aufi.

In early 2006, Noordin Top is believed to have drifted away from the main Jemaah Islamiah structure due to a disagreement about attacks on "soft targets", which often kill civilians. Police said he was claiming to lead a previously unknown group called Tanzim Qaedat al-Jihad.

In naming the group "Tanzim Qaedat al-Jihad," or "Organization for the Base of Jihad," Top has intentionally established a clear association with Osama bin Laden's al Qaeda, mimicking early moves by Abu Musab al-Zarqawi as he was seeking to establish his credibility in Iraq.

Wednesday, July 22, 2009

The Economics of Botnets

Via Viruslist.com -

In the past ten years, botnets have evolved from small networks of a dozen PCs controlled from a single C&C (command and control center) into sophisticated distributed systems comprising millions of computers with decentralized control. Why are these enormous zombie networks created? The answer can be given in a single word: money.

A botnet, or zombie network, is a network of computers infected with a malicious program that allows cybercriminals to control the infected machines remotely without the users’ knowledge. Zombie networks have become a source of income for entire groups of cybercriminals. The invariably low cost of maintaining a botnet and the ever diminishing degree of knowledge required to manage one are conducive to growth in popularity and, consequently, the number of botnets.

So how does one start? What does a cybercriminal in need of a botnet do? There are many possibilities, depending on the criminal’s skills. Unfortunately, those who decide to set up a botnet from scratch will have no difficulty finding instructions on the Internet.

---------------------------------

Check out the full article...good stuff.

Apple Backs Down On Bluwiki Threats

Via EFF -

Apple has retracted its legal threats against public wiki hosting site Bluwiki, and, in response, EFF is dismissing its lawsuit against Apple over those threats. The skirmish involved a set of anonymously authored wiki pages in which hobbyists were discussing how to "sync" media to iPods and iPhones using music library playback software other than Apple's own iTunes.

In November 2008, Apple sent a series of legal threats to the operator of Bluwiki, alleging that these hobbyist discussions about interoperability violated copyright law and constituted a violation of the Digital Millennium Copyright Act (DMCA), even though the author(s) of the pages had not yet figured out how to accomplish their goal. In response to Apple's legal threats, Bluwiki took down the wiki pages in question. In April 2009, EFF and the San Francisco law firm Keker & Van Nest sued Apple on behalf of OdioWorks, which runs Bluwiki, asking a court to reject Apple's claims and allow Bluwiki to restore the discussions.

On July 8, 2009, Apple sent letter withdrawing its cease-and-desist demands and stating that "Apple no longer has, nor will it have in the future, any objection to the publication of the iTunesDB Pages." As a result, EFF has moved to dismiss its complaint against Apple.

"While we are glad that Apple retracted its baseless legal threats, we are disappointed that it only came after 7 months of censorship and a lawsuit," said EFF Senior Staff Attorney Fred von Lohmann. "Because Apple continues to use technical measures to lock iPod Touch and iPhone owners into -- and Palm Pre owners out of -- using Apple's iTunes software, I wouldn't be surprised if there are more discussions among frustrated customers about reverse engineering Apple products. We hope Apple has learned its lesson here and will give those online discussions a wide berth in the future."

For more details:
http://www.eff.org/deeplinks/2009/07/apple-backs-down-blu

For more information about OdioWorks v. Apple:
http://www.eff.org/cases/odioworks-v-apple