Thursday, September 3, 2009

Pakistani Nuclear Forces 2009

Via FAS Strategic Security Blog -

Pakistan’s nuclear weapons stockpile now includes an estimated 70-90 nuclear warheads, according to the latest Nuclear Notebook published in the Bulletin of the Atomic Scientists. The estimate is an increase compared with the previous estimate of approximately 60 warheads due to Pakistan’s pending introduction of a new ballistic missile and cruise missiles.

The increase in the warhead estimate does not mean Pakistan is thought to be sprinting ahead of India, which is also increasing its stockpile.

Modernizations

The nuclear-capable Shaheen-II medium-range ballistic missile appears to be approaching operational deployment after long preparation. The Army test-launched two missiles within three days in April 2008, and the U.S. Air Force National Air and Space Intelligence Center (NASIC) reported in June 2009 that the weapon “probably will soon be deployed.”

Two types of nuclear-capable cruise missiles are also under development; the ground-launched Barbur and the air-launched Ra-ad. The development of cruise missiles with nuclear capability is interesting because it suggests that Pakistan’s nuclear weapons designers have been successful in building smaller and lighter plutonium warheads.

Warhead Security Concerns

An article published in the July issue of the CTC Sentinel news letter of the Combating Terrorism Center at the U.S. Military Academy at West Point gained widespread attention for describing terrorist attacks against three of Pakistan’s rumored nuclear weapons facilities: Wah Ordnance Facility, Kamra Air Base, and Sargodha Weapons Storage Facility. Although the incidents had been reported before, the article triggered the predictable rejection from a Pakistani military spokesman but with the additional claim that neither facility stored nuclear weapons. “These are nowhere close to any nuclear facility,” he said. Yet the official would most likely not disclose the location of the nuclear weapons, even if he knew where they were.

While the CTC Sentinel article says “most” of Pakistan’s nuclear sites might be close to or even within terrorist dominated areas, senior U.S. officials said the weapons were secure and mostly located south of Islamabad.

Regardless of the actual location of the weapons, there have, of course, been many more terrorists attacks against other facilities that have nothing to do with Pakistan’s nuclear weapons program, and so far no pattern has emerged in public of a concerted terrorist effort against nuclear sites – much less an attempt to steel nuclear weapons. A U.S. intelligence official commented to the New York Times that it was unclear whether the attackers knew what the facilities contained. “If they were after something specific, or were truly seeking entry, you’d think they might use a different tactic, one that’s been employed elsewhere – such as a bomb followed by a small-arms assault.”

Pakistani and U.S. statements about the Pakistani nuclear arsenal, and the basis for our estimate, are included in the Nuclear Notebook.

Publication: Pakistani Nuclear Forces, 2009

SAP Security - Attacking SAP Clients

http://milw0rm.com/papers/380

Business applications security is one of the most important tasks in complex information security process. Nowadays SAP platform is the most widespread platform for managing enterprise systems and store the most critical data.

None the less people still don’t attend much on a technical side of SAP security. There are some well-known problems about access control, SoD matrix and maybe SAP router security. But there are also many problems on all levels of SAP system such as: network level, operation system level, database level, application level and presentation level i.e. SAP clients.

As for SAP server security there you can give some information from Cybsec presentations on BlackHat 2007 and Blackhat 2009 where u can see how insecure SAP servers and RFC protocol.

But there is still so few information about SAP client security which can be the weak point in your company even if it has secure SAP server environment.

In this article I will be talking about basic problems in SAP client’s security. Here will be described a problem with description of basic attacks to SAP clients which can be exploited from corporate network and even from public network with getting access to corporate network and users workstation which is one step closer to the SAP servers and critical business data.

Taliban Target Pakistan's Religious Minister

Via The Long War Journal -

The Taliban nearly assassinated Pakistan's outspoken religious minister in a shootout in the capital of Islamabad today.

Two gunmen on a motorcycle opened fire on a car carrying Hamid Saeed Kazmi, the Federal Religious Minister. The gunmen, who were riding a motorcycle, sprayed Kazmi's car with automatic fire, killing the driver. Kazmi took a bullet in the leg and is being treated at a hospital in Islamabad.

Kazmi has been outspoken in his opposition to the Taliban and supports operations against the extremists in the tribal areas. He is a member of the Barelvi sect of Sunni Islam, which is in opposition to the Deobandi and Wahabbist strains of Islam that preach violent jihad.

In June, the Taliban killed another prominent Barelvi cleric in a suicide attack. Dr. Sarfraz Naeemi and four other people were killed when a suicide bomber detonated his vest at a mosque in Lahore. An Arakzai-based Taliban group under the command of Hakeemullah Mehsud group took credit for the Lahore attack.

Hakeemullah has taken control of the Movement of the Taliban in Pakistan, an alliance of Taliban groups based in the tribal areas and the greater Northwest Frontier Province, after Baitullah Mehsud was killed in an Aug. 5 airstrike in South Waziristan.

Hakeemullah threatened to avenge Baitullah's death and has ordered several suicide attacks, including a strike at the main border crossing in Khyber that killed 22 border guards and an attack at a police training center in Swat that killed 15 recruits.

----------------------------

According to Janes...

Local newspaper Dawn reported that the attackers chased Kazmi's car for about 50 m and continued firing after the driver tried to speed away.

Belgian National Arrested on Charges of Arms Sales to Iran

Via NEFA Foundation -

http://www.nefafoundation.org/miscellaneous/US_v_Monsieur_indictment.pdf

Federal prosecutors in Alabama announced that “Jacques Monsieur, a Belgian national and resident of France suspected of international arms dealing for decades, has been arrested on charges alleging that he conspired to illegally export F-5 fighter jet engines and parts from the United States to Iran.” A six-count indictment charged Monsieur, 56, and co-defendant Dara Fotouhi, aka Dara Fatouhi, 54, an Iranian national currently living in France, with conspiracy, money laundering, smuggling, as well as violations of the Arms Export Control Act (AECA) and the International Emergency Economic Powers Act (IEEPA). Monsieur was arrested by federal agents last Friday upon his arrival in New York. Fotouhi remains at large…The indictment alleges that "in February 2009, Monsieur contacted an undercover agent seeking engines for the F-5 (EIF) fighter jet or the C-130 military transport aircraft for export to Iran. Thereafter, Monsieur began having regular e-mail contact with the undercover agent regarding requested F-5 engines and parts.”

Northern Virginia Rap Battle - Arlington vs. Fairfax

Arlington, VA is super gangsta...



But Fairfax County wasn't going to just stand by and sit on the sidelines....



The only thing missing is Loudoun Country...which in 2007 had the highest median household income in the United States at $107,207, beating neighboring Fairfax County at $105,241.

Where's my Loudoun crew at??

Big ups to Chris Rasmussen (@ckras) for the links....

Operation: Epsilon Featuring DJ Trace

http://covert-operations.org/trace/trace.mp3 (132MB MP3)

DSCI4 on Myspace - http://www.myspace.com/dsci4records

Big ups to boy, @tmanning, for the link....

Flaw In Sears Website Left Database Open To Attack

Via DarkReading.com -

A newly discovered vulnerability on Sears.com could have allowed attackers to raid the retail giant's gift card database.

Alex Firmani, owner of Merge Design and a researcher, this week revealed a major security hole on Sears.com that could allow an attacker to easily steal valid gift cards -- a heist he estimates could be worth millions of dollars. Firmani says he alerted Sears about the flaw, and that Sears has since "plugged" the hole by removing the feature that let customers verify and check their gift-card balances.

The vulnerability was a business logic flaw in a Web application that handles gift card account inquiries; Firmani was able to stage a brute-force attack that could grab all valid, active Sears and Kmart gift cards from the company's database.

Firmani says the site wasn't auditing verification requests, which allowed him to verify gift card and PIN combinations using a homegrown PHP script that automatically submitted the requests. "I wrote a PHP script to hammer their verification server. It happily replied with thousands of verification responses per minute," he says.

The Sears application relied on client-side cookies to halt brute-force verification attempts, which Firmani says wasn't effective. "They should know where the verification requests come from, log them all, and be able to disable the verifications when they have a malicious attack," he says. "It doesn't appear to me that they had any server-side control over how many verifications were done."

[...]

Firmani, who says he discloses Website flaws to site owners in order to highlight common Web application security issues, suggests that Sears require a valid user account login before allowing a verification request to be sent. "You could then record the number of verification requests and lock out any offending accounts automatically and without relying on client-side cookie," he wrote in his disclosure paper. "Recording requests server-side would be a more reliable way of handling repeat request offenders."

Another option is recording to a server-side database IP addresses of users verifying their gift cards, he said, as well as using a "number-used once" scheme in the verification form or logging all verification requests and using a script to shut down the response server if more than a specifically designated number of requests arrive per minute, he said.

"Security these days is less about what version of Apache you're running and more about custom-written Web applications. With Web apps given unfettered database access, it becomes a simple matter of exploiting less-than-solid Web application programming," Firmani says. "Finding holes in home-brewed Web app code is much easier than exploiting a root-escalation bug on a Linux server, but both often have similar database access."

-------------------------------------

Definitively, a lack of anti-automation protection controls as well....which is one of those things that isn't pointed out enough in security audits.

Breach Security has a whitepaper on Anti-Automation...but sadly, you have to sign up to get it.

Apache Shows How to Handle a Network Compromise

Via ThreatPost.com -

The Apache Software Foundation last week was the victim of a serious network attack in which a number of its Web servers and other machines were compromised by attackers who were able to gain root privileges and jump from machine to machine. The incident was embarrassing and a serious problem for the foundation, but instead of making excuses and hiding behind the veil of confidentiality, Apache officials have published the gory details of the attack.

Not only did the foundation detail which machines were compromised, but it also discusses exactly what tactics the attackers used and how they were able to break into the Apache network in the first place.

Our initial running theory was correct--the server that hosted the apachecon.com (dv35.apachecon.com) website had been compromised. The machine was running CentOS, and we suspect they may have used the recent local root exploits patched in RHSA-2009-1222 to escalate their privileges on this machine. The attackers fully compromised this machine, including gaining root privileges, and destroyed most of the logs, making it difficult for us to confirm the details of everything that happened on the machine.

The attackers attempted unsuccessfully to use passwords from the compromised ApacheCon host to log on to our production webservers. Later, using the SSH Key of the backup account, they were able to access people.apache.org (minotaur.apache.org).

Even in the open-source world, this kind of detail in the report of an attack is incredibly rare. Most private and public companies are understandably reluctant to release anything close to this amount of data, even if they're not prevented from doing so by some regulation. It's not in the best interest of the company or its shareholders (if it has them) to release anything but the most basic information after a data breach or other attack. In fact, an attack like this in which no sensitive data was compromised likely would have elicited no response at all from a public company.

But the Apache Software Foundation obviously is in a far different position. As a not-for-profit corporation, the foundation can call its own shots. And in this case, the group chose to act in the best interests of the Internet community as a whole by airing its dirty laundry. Granted, the foundation will get some residual benefit from a large community of security experts analyzing its tactics and suggesting changes.

But most of the benefits will accrue to the wider Internet community in the form of rare forensic data on a major compromise. We need much more of this, but what Apache has done is a great start.

Snow Leopard Ships with Vulnerable Flash Player

Via ZDNet -

Apple’s new operating system comes with an outdated version of Flash Player that exposes Mac users to hacker attacks.

The initial release of Mac OS X 1..6 (Snow Leopard) includes Flash Player 10.0.23.1, which is very much out of date. The fully patched version of Flash Player for Mac is version 10.0.32.18.

Even worse, Intego reports that the vulnerable version of Flash is included even if the Mac user was fully patched before upgrading the operating system.

The current version of Flash Player for Mac is 10.0.32.18, but if you go to the Flash Player version test page after installing Snow Leopard, you’ll find that you have version 10.0.23.1, even if you were up-to-date before the upgrade. It seems that Apple is shipping an outdated, even dangerous version of Flash Player.

Adobe has also spotted the hiccup and released a security alert to warn of the problem.

The initial release of Mac OS X 10.6 (Snow Leopard) includes an earlier version of Adobe Flash Player than what is available from Adobe.com. We recommend all users update to the latest, most secure version of Flash Player (10.0.32.18) — which supports Snow Leopard and is available for download from http://www.adobe.com/go/getflashplayer.

-----------------------------

Why the hell is OS X installing flash (which is a 3rd party add-on) in the first place?

Even if there is a valid reason, why the hell is it installing over a newer version already in place?


In other "why the hell does Apple do this crap" news....they released a updated version of Java for Mac...which fixes several serious security vulnerabilities.

Wednesday, September 2, 2009

iPhone's False Sense of Security in the Enterprise

Via ComputerWorld -

As an IT security professional, I was tasked with evaluating the iPhone's security features for the enterprise (more iPhone management tests here). Over the past few weeks, I have been testing different aspects of the new iPhone 3GS, particularly the interaction with Exchange ActiveSync (EAS) and device password policies. During my testing, I discovered some strange behaviors with how the iPhone handles device password policies, as well as passwords altogether.

[...]

It has already been proven that the passcode on an iPhone can be removed. The purpose of this article is to point out the false sense of security delivered through Apple's marketing of iPhone features for the enterprise. My testing has revealed that the enterprise security features do not behave correctly and I will point out three flaws with how passwords are handled with the iPhone and EAS.

[...]

Bug 1 -- iPhone does not handle EAS Policies as expected

[...]

Bug 2 -- Passcode Prompt Reveals Too Much Information

[...]

Bug 3 -- Changing your iPhone Passcode

[...]

The iPhone is a great device and is arguably the best mobile device from a usability perspective. Unfortunately, the security features are not quite ready for the enterprise and contain various bugs. In order to safeguard against such bugs, data encryption has to be considered for any type of data protection, but that is another article. Enterprises considering the iPhone for corporate use need to be aware of how the iPhone security features behave and the different ways that data can be breached in the event that the device is lost or stolen.

New Languages in Google Translate

Via Google Operating System Blog -

Google's machine translation service added new languages: Afrikaans, Belarusian, Icelandic, Irish, Macedonian, Malay, Swahili, Welsh, Yiddish. Some of these languages have a small number of speakers: for example, according to Wikipedia, only 320,000 people speak Icelandic.

Swahili is a language spoken in Eastern Africa, Afrikaans is spoken in South Africa and Namibia, Yiddish has 3 million speakers in the Orthodox Jewish communities, Malay is an official language in Brunei, Malaysia, and Singapore. Welsh is spoken in Wales, England and Argentina, Irish is spoken by a small minority of the Irish population, Macedonian has less than 3 million speakers and many enemies, while Belarusian has 9 million speakers.

The number of languages supported by Google Translate is 51, which is impressive, but there are still many popular languages that aren't supported. At least not yet.

Afghan Spy Boss Killed in Suicide Attack

Via Military.com -

A Taliban suicide bomber attacked officials leaving a mosque east of the capital Wednesday, killing the country's deputy intelligence chief and 23 other people in a major blow to Afghanistan's security forces.

The brazen assault occurred as tensions are running high after last month's divisive presidential election and a sharp rise in U.S. casualties - events that have already raised alarm in Washington over the future of President Barack Obama's strategy to turn the tide of the war.

A Taliban spokesman claimed responsibility for the bombing, which happened as Afghan dignitaries were leaving the main mosque in Mehterlam, 60 miles (100 kilometers) east of Kabul, after ceremonies marking the Islamic holy month of Ramadan.

Microsoft IIS FTP 5.0 Remote SYSTEM Exploit

Via Offensive-Security.com -

A remote Microsoft FTP server exploit was released today by Kingcope, and can be found at http://milw0rm.com/exploits/9541,

A quick examination of the exploit showed some fancy manipulations in a highly restrictive environment that lead to a”useradd” type payload. The main issue was the relatively small payload size allowed by the SITE command, which was limited to around 500 bytes.

After a bit of tinkering around, we saw that the PASSWORD field would be most suitable to shove a larger payload (bindshell). A quick replacement of the original “user add” shellcode with a secondary encoded egghunter – and a bind shell was presented to us! I wonder how long this 0day has been around…As Rel1k would say to logan_WHD…”it’s OK, it’s OK…”.

The exploit can be downloaded from our exploit archive. To entertain the masses, we also made “Microsoft IIS 5.0 FTP 0 Day – The movie

------------------------------

HD Moore also has added Kingcope's IIS FTP exploit to the Metasploit trunk: [ msf> use exploit/windows/ftp/microsoft_ftpd_nlst ] http://pastie.org/601730

Tuesday, September 1, 2009

The Hunt for Russia’s Super New Anti-Aircraft Weapon (SA-24)

Via Wired.com (Danger Room) -

One of the most prized acquisitions for the U.S. military could be a Russian-made missile.

At last month’s Moscow air show, Russia proudly displayed the Igla-S, its latest generation man-portable air defense system, or Manpads, which it is selling to foreign customers. The shoulder-fired missile is proving a hot commodity on the international market, and a major concern to the U.S. government because of the threat it poses to commercial and military aircraft. The irony is that the United States is desperately afraid that other countries will get their hands on the Igla-S (also known as the SA-24), even though the United States is having problems acquiring one for itself.

The Pentagon and the intelligence community rarely talk about their efforts to acquire foreign weapons, which they use to understand adversaries’ capabilities and to develop countermeasures. Going under the innocuous sounding name of “Foreign Materiel Acquisition,” the Pentagon essentially funds arms dealers to go forth and find foreign technology for the U.S. military — and acquire it by whatever means necessary.

In an article coming out this month in Defense Technology International, I look at BAE Systems’ Jam Lab, which builds systems designed to defend against shoulder-fired missiles. An important component of building such systems is getting a hold of an actual threat missile. That’s easy to do if it’s the U.S.-built Stinger, but it can be much harder if it’s a Russian weapon. Paul Squires, a senior principal physicist at the Jam Lab, told me that there was one modern shoulder-fired missile that the United States has not been able to “beg, borrow or steal.” (Though Squires declined to name the specific weapon, the SA-24 is generally regarded as the latest and greatest foreign Manpads threat.)

One of the reasons the SA-24 may be so hard to come by is that Russia keeps relatively close hold on its latest technology. (It’s also highly possible that the U.S. government has, in fact, acquired an SA-24, and is simply keeping quiet about it.) But Venezuela, for its part, proudly displayed its SA-24s in a military parade earlier this year, and Syria is suspected of purchasing the missile from Russia, although neither side has yet to acknowledge it.

Backblaze's Custom 67 Terabyte Storage 4U Server

Via Backblaze Blog -

At Backblaze, we provide unlimited storage to our customers for only $5 per month, so we had to figure out how to store hundreds of petabytes of customer data in a reliable, scalable way—and keep our costs low. After looking at several overpriced commercial solutions, we decided to build our own custom Backblaze Storage Pods: 67 terabyte 4U servers for $7,867.

In this post, we’ll share how to make one of these storage pods, and you’re welcome to use this design. Our hope is that by sharing, others can benefit and, ultimately, refine this concept and send improvements back to us. Evolving and lowering costs is critical to our continuing success at Backblaze.

[...]

The result is a 4U rack-mounted Linux-based server that contains 67 terabytes at a material cost of $7,867, the bulk of which goes to purchase the drives themselves.

[...]

A Backblaze Storage Pod is a self-contained unit that puts storage online. It’s made up of a custom metal case with commodity hardware inside. Specifically, one pod contains one Intel Motherboard with four SATA cards plugged into it. The nine SATA cables run from the cards to nine port multiplier backplanes that each have five hard drives plugged directly into them (45 hard drives in total).

[...]

A Backblaze Storage Pod isn’t a complete building block until it boots and is on the network. The pods boot 64-bit Debian 4 Linux and the JFS file system, and they are self-contained appliances, where all access to and from the pods is through HTTPS.

Pakistani Military Launches Operation in Khyber Tribal Agency

Via The Long War Journal -

The Pakistani military has launched an operation against extremists operating in the Khyber tribal agency. The operation was launched after a suicide bomber killed 22 border guards at the Torkham crossing last week.

More than 40 extremists were killed, including two commanders, and another 43 were captured, according to Tariq Hayat, the Political Agent for Khyber. Three "militant bases" were destroyed, according to a press release by the paramilitary Frontier Corps, while an indefinite curfew has been imposed in the region.

The military is relying heavily on artillery and Cobra helicopter gunships instead of engaging the extremists on the ground, according to reports received by The Long War Journal. Only three soldiers have been wounded during the operation, claims the military.

The military would not name the group or groups that are the target of the operation. According to Geo News the operation "is being carried out against miscreants not against any specific person or a group."

The operation was launched in the Bara region in Khyber, the stronghold of the Lashkar-e-Islam, a pro-Taliban group led by Mangal Bagh Afridi. He is reported to be listed by the interior ministry as one of the top ten most-wanted extremist leaders. During the operation, the father of a Lashkar-e-Islam commander was detained, and a spokesman for the group has called for the military to end the offensive.

Two other extremist groups are known to operate in the region. The Ansar-ul-Islam, a rival extremist group, operates in Khyber, as does the Movement of the Taliban in Pakistan. Hakeemullah Mehsud, the new leader of the Movement of the Taliban in Pakistan, commanded forces in Khyber and was behind many of the attacks against NATO supply convoys moving through the region.

NIST Draft - Secure Domain Name System (DNS) Deployment Guide

http://csrc.nist.gov/publications/drafts/800-81-rev1/nist_draft_sp800-81r1-round2.pdf

NIST has drafted another revision of the document “Secure Domain Name System (DNS) Deployment Guide" (SP 800-81) . This revision addresses all the comments and feedback received for the first revision through public comments in March 2009, in addition to adding 3 more subsections described below. After addressing the public comments received in this round, it will be published as NIST SP 800-81r1. Federal agencies and private organizations as well as individuals are invited to review this draft and submit comments to NIST by sending them to SecureDNS@nist.gov before September 30, 2009. Comments will be reviewed and posted on the CSRC website. All comments will be analyzed, consolidated, and used in revising the draft Guidelines before final publication.

IEEE-2600 - New IEEE Printer Security Standard

http://www.xerox.com/downloads/usa/en/c/cert_P2600_Security_Group.pdf

The Institute of Electrical and Electronics Engineers created the P2600: Hardcopy Device and System Security Working Group to develop security standards. The focus of the Working Group is to identify and document security issues and threats, and then provide recommendations to manufacturers on how to mitigate these security risks.


The goals of this activity are to:

• Define security requirements that include all aspects of security for manufacturers, users and others on the selection, installation, configuration and usage of hardcopy devices and systems including printers, copiers, and multifunction devices and the computer systems that support these.

• Identify security exposures of hardcopy devices and systems and instruct manufacturers and software developers on appropriate security capabilities to include in their devices and systems and instruct users on appropriate ways to use these security capabilities.

--------------------------------------

Get the IEEE-2600.1-299 Standard - http://standards.ieee.org/getieee/2600/index.html

Check out this Dark Reading article for more details...

Al-Qaeda 'Coordinator' Killed in South Russia

Via GlobalSecurity.org (Aug 31st) -

One of two militants killed in a shootout with security forces in the Russian North Caucasus republic of Dagestan late on Sunday was an Algerian-born member of al-Qaeda, a security official told RIA Novosti.

The militants were killed in an operation carried out by the local Federal Security Service near the town of Khasavyurt, close to the border with Chechnya. Two officers were injured in the clash, the FSB official said on Monday.

"A foreign mercenary killed in the special operation has been identified. He is an Algerian national, al-Qaeda's coordinator in Dagestan, known among the militants as Doctor Muhammad," the official said.

Another security source in Dagestan said the Al-Qaeda militant held French citizenship.

Doctor Muhammad had arranged for infiltrations of militants into Dagestan and neighboring Ingushetia from Georgia and Azerbaijan, another FSB spokesman said.

He is known to have arrived in Russia's North Caucasus in 1999 via Georgia. He was a member of the international terrorist Hattab's group until 2007, responsible for organizing a terrorist network in Chechnya.

"In 2007, he was sent to Dagestan with instructions to bring the local gangs under control, to ensure their funding from abroad and arrange for channels for militants to infiltrate into the republic," an FSB official said.

In the republic's capital, Makhachkala, gunmen killed in the early hours of Monday an OMON special police officer. "The criminals knocked at the door where the police officer lived and shot him five times," a police spokesman said.

Militant attacks on troops, police and other officials have been reported almost daily in Dagestan and Russia's other mainly Muslim North Caucasus republics in recent months.

On August 17, Ingushetia was rocked by a suicide bombing which killed at least 24 police officers and injured 136.

Following the blast, Ingushetia's president, Yunus-Bek Yevkurov, returned to the republic after spending two months in Moscow recovering from serious injuries sustained in a car bomb attack on his motorcade.

Zeus Trojan Uses IM Speed Distribution Of Stolen Data

Via DarkReading -

Social networking has become so popular that even Trojan horses are doing it these days.

Researchers at RSA's FraudAction Research Lab say they have discovered a new online attack method that uses instant messaging to speed the delivery of compromised online credentials to cybercriminals.

According to RSA's latest fraud report, issued today, research of several Zeus Trojan variants reveals that some online criminals have begun using the Jabber IM open protocol as a quick delivery mechanism of stolen user information. Using Jabber, stolen data is sent to these particular fraudsters as soon as it is collected from computers infected with the Zeus Trojan, RSA says.

"The Jabber IM modules that have been built into these particular Trojans were configured to extract stolen user credentials from the Zeus Trojan's 'drop' server database -- and then immediately send those credentials to the online criminal, wherever he may be," RSA says.

However, stolen credentials that reside on the drop server are not necessarily available in real-time to the online criminal, the researchers say. The criminal may reside within a region in another part of the world, or may not be connected to the server all the time. The Jabber IM module simply lets the criminals automatically forward and receive stolen credentials as soon as they are collected.

"In this case, online criminals use two Jabber accounts; one for sending select, compromised user credentials from the drop server's database; and the other for receiving those credentials," RSA says.

Each of the Jabber IM modules that RSA discovered was configured to perform a different set of actions and was "customized" according to the criminals' preferences, the researchers say. Some Trojans have also been configured to send stolen credentials via email.

The use of IM for receiving notification of newly collected compromised accounts or customers' login attempts is not a new cybercrime technique, RSA observes. The Sinowal gang, for example, was known to have employed a Jabber module as early as 2008.

Amygdala Believed to Play Role in Defining Personal Space

Via ScienceNow -

In a famous episode of the TV show Seinfeld, a "close talker" makes others uncomfortable by standing mere centimeters from their faces while speaking. What makes this invasion of our personal space so uncomfortable? A new study fingers the amygdala, a region of the brain that acts like a warning bell when someone gets too close for comfort.

Psychologists have studied personal space since the 1960s. They've found that Americans and northern Europeans prefer a larger personal space than southern Europeans, for example, whereas people with autism tend to unknowingly invade others' personal space. Studies in monkeys have hinted that the amygdala, an almond-shaped region in the middle of the brain that helps us recognize threats, plays a role in personal space. But the theory proved hard to test in humans.

Then, about 15 years ago, neuroscientists at the California Institute of Technology in Pasadena met a 42-year-old woman with a rare genetic disorder that destroyed both sides of her amygdala. In early experiments, the scientists discovered that the woman, referred to as SM, couldn't spot fear in other people's faces; she also rated people as more trustworthy than an average person did. And she was extremely outgoing, "almost to the point where it isn't normal," says team member Daniel Kennedy. Even if she's only just met someone, he says, SM will invade their personal space--touching their arm as she talks or poking their stomach.

In the new study, Kennedy and his colleagues more rigorously tested SM's sense of personal space. They compared her with 20 healthy subjects in a series of experiments. In one test, an experimenter slowly walked toward a subject until the subject felt uncomfortable and told the experimenter to stop. SM let experimenters get about twice as close as other subjects did, 0.34 meters versus 0.64 meters, the team reports online this week in Nature Neuroscience. She even felt fine standing nose to nose with an experimenter.

Further experiments revealed why. Kennedy and his colleagues placed eight healthy subjects, one at a time, inside a functional magnetic resonance imaging scanner, which measures brain activity. Then an experimenter stood either about 4.5 meters away from the machine or right next to the machine's opening. The subjects' amygdalas lit up with significantly more activity when the stranger stood close by. "Our findings support the idea that the amygdala functions as the brakes in social interactions," Kennedy says. "If you take away the amygdala, it seems like you are less tuned to ... social [behaviors] that can cause discomfort."

The study is "a novel piece of research" that is the first to identify a neural source of personal space in people, says Richard Davidson, a neuroscientist at the University of Wisconsin, Madison. "It's also part of a growing series of studies that underscore the importance of the amygdala in human social interactions," he says.

Microsoft Internet Information Services (IIS) FTP Service Vulnerability

Via US CERT -

Microsoft Internet Information Services (IIS) FTP Service Vulnerability

US-CERT is aware of a public report of a vulnerability affecting the Microsoft Internet Information Services (IIS) FTP service. This vulnerability may allow a remote attacker to execute arbitrary code.

US-CERT encourages administrators to disable anonymous write access to the FTP server to help mitigate the vulnerability, although a proper impact analysis should be performed prior to taking defensive measures.

US-CERT will provide additional information as it becomes available.

---------------------------

Exploit posted on Milw0rm by Kingcope - http://www.milw0rm.com/exploits/9541

HD Moore is working to add the exploit to the Metasploit Framework as well.

Emerging Threats have released a signature for the milw0rm IIS-FTP
exploit. It's available in the signature tarballs and a history is available in CVS.

Sunday, August 30, 2009

UAE Seizes North Korean Weapons Shipment to Iran

Via Bloomberg (Aug 28th, 2009) -

The United Arab Emirates has seized a ship carrying North Korean-manufactured munitions, detonators, explosives and rocket-propelled grenades bound for Iran in violation of United Nations sanctions, diplomats said.

The UAE two weeks ago notified the UN Security Council of the seizure, according to the diplomats, who spoke on condition they aren’t named because the communication hasn’t been made public. They said the ship, owned by an Australian subsidiary of a French company and sailing under a Bahamian flag, was carrying 10 containers of arms disguised as oil equipment.

The council committee that monitors enforcement of UN sanctions against North Korea wrote letters to Iran and the government in Pyongyang asking for explanations of the violation, and one to the UAE expressing appreciation for the cooperation, the envoys said. No response has been received and the UAE has unloaded the cargo, they said.

The UAE and Iranian missions to the UN didn’t immediately respond to requests for comment. The Financial Times reported the weapons seizure earlier today.

The Security Council voted on June 12 to adopt a resolution that punishes North Korea for its recent nuclear-bomb test and missile launches through cargo inspections and enforcement of restrictions on financial transactions. The measure calls for the interdiction at seaports, airports or in international waters of any cargo suspected of containing arms or nuclear or missile-related materials going to or from North Korea.

Saturday, August 29, 2009

Trend Micro Whitepaper - A Cybercrime Hub

http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/a_cybercrime_hub.pdf

Tartu, Estonia is the hometown of an Internet company that, from the outside, looks just like any other legitimate Internet service provider (ISP). On its website, the company lists services such as hosting and advertising. According to publicly available information, it posted more than US$5 million in revenue and had more than 50 employees in 2007.

In reality, however, this company has been serving as the operational headquarters of a large cybercrime network since 2005. Its employees administer sites that host codec Trojans and command and control (C&C) servers that steer armies of infected computers from its office in Tartu. The criminal outfit uses a lot of daughter companies thatoperate in Europe and in the United States. These daughter companies’ names quickly get the heat when they become involved in Internet abuse and other cybercrimes. They disappear after getting bad publicity or when upstream providers terminate their contracts. This does not cause much harm to the operation as a whole, however, as the same cybercriminal just continues its business under a new name. In fact, constantly changing names is part of the company’s business model with a few constants, one of which is the mother company in Tartu.

Although explicit evidence exists that the Estonian company is heavily involved in cybercrime, the company could also be just another façade of a bigger cybercriminal gang whose investors reside in another country like Russia or the United States. In fact, it is not at all unlikely that foreign criminal investors put their money into the Estonian company so they do not have to do the dirty work themselves. This paper provides detailed data on some of the cybercrimes that this Estonian company has been involved with. It also provides advertising fraud statistics committed on legitimate websites. Furthermore, it explains the backend structure of fraud with Google search queries and shows that around 100,000 unique Internet users per day get a bogus message saying, “You are infected with a virus, please download this piece of free antivirus software,” whenever they attempt to access high-traffic pornography websites. Finally, it also briefly discusses the internal network of the Estonian company, which shows how all of its activities relate to one another.

Source Code of Skype Covert Tap Released

Via H-Online -

On his website Megapanzer.com, Ruben Unteregger, a Swiss software developer has released the source code of a program for tapping into encrypted Skype conversations. The program can be injected into a PC as a trojan. According to the Unteregger, the successfully injected trojan hooks into active Skype processes, secretly records the audio data of conversations and transmits it to an external server as MP3 files.

Back in 2008, the CCC published a letter claiming that the Bavarian legal authorities and police had used a similar program made by a company called DigiTask; despite requests for clarification, the allegation was never denied. In Switzerland, a program made by vendor ERA IT Solutions has reportedly been used for the same purpose. Unteregger claims that he was employed with this very vendor for several years, working predominately on "malware stuff". Unteregger says that by making the spying software available under the GPL, he hopes to cast light onto this dark subject.

Riccardo Gubser from ERA explained to The H's associates at heise Security that "the know-how for this development was introduced to the company by R.U. and it disappeared with his exit from the company." Apparently Ruben Unteregger, was not only a developer at ERA IT, but one of the main shareholders and member of the management at the company.

Apache.org Hacked Via Compromised SSH Key

Via Apache.org Blog -

This is a short overview of what happened on Friday August 28 2009 to the apache.org services. A more detailed post will come at a later time after we complete the audit of all machines involved.

On August 27th, starting at about 18:00 UTC an account used for automated backups for the ApacheCon website hosted on a 3rd party hosting provider was used to upload files to minotaur.apache.org. The account was accessed using SSH key authentication from this host.

To the best of our knowledge at this time, no end users were affected by this incident, and the attackers were not able to escalate their privileges on any machines.

While we have no evidence that downloads were affected, users are always advised to check digital signatures where provided.

minotaur.apache.org runs FreeBSD 7-STABLE and is more widely known as people.apache.org. Minotaur serves as the seed host for most apache.org websites, in addition to providing shell accounts for all Apache committers.

The attackers created several files in the directory containing files for www.apache.org, including several CGI scripts. These files were then rsynced to our production webservers by automated processes. At about 07:00 on August 28 2009 the attackers accessed these CGI scripts over HTTP, which spawned processes on our production web services.

At about 07:45 UTC we noticed these rogue processes on eos.apache.org, the Solaris 10 machine that normally serves our websites.

Within the next 10 minutes we decided to shutdown all machines involved as a precaution.

After an initial investigation we changed DNS for most apache.org services to eris.apache.org, a machine not affected and provided a basic downtime message.

After investigation, we determined that our European fallover and backup machine, aurora.apache.org, was not affected. While the some files had been copied to the machine by automated rsync processes, none of them were executed on the host, and we restored from a ZFS snapshot to a version of all our websites before any accounts were compromised.

At this time several machines remain offline, but most user facing websites and services are now available.

We will provide more information as we can.

---------------------------------------

F-Secure has a screenshot of the basic downtime message that was shown for a short time.

FBI Investigating Laptops Sent to US Governors

Via ITWorld.com -

There may be a new type of Trojan Horse attack to worry about.

The U.S. Federal Bureau of Investigation is trying to figure out who is sending laptop computers to state governors across the U.S., including West Virginia Governor Joe Mahchin and Wyoming Governor Dave Freudenthal. Some state officials are worried that they may contain malicious software.

According to sources familiar with the investigation, other states have been targeted too, with HP laptops mysteriously ordered for officials in 10 states. Four of the orders were delivered, while the remaining six were intercepted, according to a source who spoke on condition of anonymity because of the ongoing investigation.

The West Virginia laptops were delivered to the governor's office several weeks ago, prompting state officials to contact police, according to Kyle Schafer, the state's chief technology officer. "We were notified by the governor's office that they had received the laptops and they had not ordered them," he said. "We checked our records and we had not ordered them."

State officials in Vermont told him they've received similar unsolicited orders, Schafer said. Representatives from that state could not be reached for comment Thursday.

Schafer doesn't know what's on the laptops, but he handed them over to the authorities. "Our expectation is that this is not a gesture of good will," he said. "People don't just send you five laptops for no good reason."

The computers are now being held as evidence by state police, who are working with the FBI to figure out how the machines were sent to the governor's office, said Michael Baylous, a sergeant with the West Virginia State Police.

The West Virginia laptops were delivered Aug. 5, according to the Charleston Gazette, which first reported the story.

The laptops sent to the Wyoming governor's office arrived in two separate shipments on Aug. 3 and Aug. 6, according to Cara Eastwood, a spokeswoman for Governor Freudenthal.

"We received one package, opened it and realized that it was an error since no one in our office had ordered them," she said. "The next day we received another package. At this point we realized that they needed to be turned over to law enforcement."

Friday, August 28, 2009

Norwegian Minister for Justice Tells ISPs to Censor Web

Via Wikileaks -

The file, a letter from the Norwegian Minister for Justice, Knut Storberget, asks all Norwegian Internet Service Providers (ISPs) to create a nation wide censorship system on a "voluntary basis" or face the passage of laws compelling them to do so.

The letter was sent to internet providers in Norway.

It was leaked because this such a move should be debated in the Parliament rather than implemented without debate behind closed doors. It has been leaked because secret censorship lists are inherently unjust and undemocratic. And it has been leaked because other countries with secret blacklists such as Australia (mandatory, unimplemented), Thailand (mandatory, implemented), Finland (voluntary, implemented) and Denmark (voluntary, implemented) have been exposed including material on their lists that they promised not to.

See also Norwegian secret internet censorship blacklist, 3518 domains, 18 Mar 2009
DOWNLOAD/VIEW FULL FILE FROM
fastest (Sweden), current site, slow (US), Finland, Netherlands, Poland, Tonga, Europe, SSL, Tor

Abu Zubaydah - His Job Is To Lie

Via Complex Terrain Lab (CT Lab) -

NEFA Foundation posted several newly declassified, redacted US intelligence reports (linked at the top of its home page) related to the interrogations of senior al-Qaeda members such as Khalid Sheikh Mohammed and Abu Zubaydah. A 2002 psychological assessment of Abu Zubaydah stands out for its surreal qualities. Initially, it reads like a typical CV of a white collar professional, complete with "action verbs":
"Served as senior Usama bin Laden lieutenant and played key role in the movement and training of operatives..."

"Directed the start-up of a Bin Laden cell in Jordan that was disrupted in Amman in 1999..."

"Managed a network of training camps, safehouses, and mujahedin-related offices in Peshawar..."
And then shifts into an assessment of personality traits that reads like a job recommendation or annual performance appraisal:
"Subject is a highly self-directed individual who prizes his independence... He is intellectually curious, skeptical...possesses excellent self-discipline and readily sets aside his own interests to meet his responsibilities."

"Subject has excellent social skills and social [redacted]..."
To be fair, it is a formal psychological assessment and is intended to describe Zubaydah, not analyze him. However, it is a fascinating peek at the kind of intelligence counterterrorism officials had at their disposal soon after September 11th.

Perhaps the most telling passage describes Zubaydah's (and by extension al-Qaeda's) approach to interrogations:
"Subject recognizes that his duty as a solldier/warrior/mujahid is to delay, mislead, and lie to protect what is most critical to the success of his cause. He assumes that we understand this. Thus, he is not likely to be intimidated or weakened by being 'caught' in lies. His job is to lie."

Breaking WPA TKIP in 60 Seconds

Via ZDNet -

Computer scientists in Japan have developed a way to break the WPA (Wi-Fi Protected Access) encryption system used in wireless routers in just one minute.

The attack, which reads encrypted traffic sent between computers and certain types of routers that use the WPA encryption system, was devised by Toshihiro Ohigashi of Hiroshima University and Masakatu Morii of Kobe University.

The scientists plan to discuss further details at a technical conference on 25 September in Hiroshima.

Security researchers first showed how WPA could be broken last November, but the researchers have accelerated theory into practice, taking the proven 15-minute Becks-Tews method developed by researchers Martin Beck and Erik Tews, and speeding it up to just 60 seconds.

Both attacks work only on WPA systems that use the Temporal Key Integrity Protocol (TKIP) algorithm. They do not work on newer WPA 2 devices or on WPA systems that use the stronger Advanced Encryption Standard, or AES, algorithm.

According to their report, the limits of the man-in-the-middle attack are fairly restrictive. However, the development should spark users to drop WPA with TKIP as a secure method of protection.

The process of securing routers has been a long one. The WEP (Wired Equivalent Privacy) system introduced in 1997 is now considered to be insecure by security experts. Then came WPA with TKIP, followed by WPA 2.

However, users have been slow to upgrade to the latest secure methods.

Increased Safeguards at Natanz: What Does It All Mean?

Via FAS Strategic Security Blog -

A much anticipated IAEA report on Iran’s nuclear activities was leaked today. The report indicates that, among other things, Iran has conceded to additional safeguard at Natanz. This is a welcome development but occurring amidst a contested Iranian election, European threats of increased sanctions, continuing oblique hints of Israeli military action, and US talk of cutting off Iranian gasoline imports if nuclear talks are rejected. How important are these increased safeguards? Do they represent a change of course for Iran?

[...]

Some have suggested that Iranian compliance with IAEA requests is a sign that Teheran is preparing the ground for negotiations. Iranian officials themselves have stated that they are open to talks without preconditions and there was even a domestic proposal for an enrichment halt. The statement was quickly corrected making Iranian intentions as ambiguous as ever.

From a technical perspective, we believe that Iranian concessions on enhancing safeguards at Natanz do no present a fundamental change nor do they cause Iran much inconvenience. The changes are proportionate with the continued build up in the number of centrifuges and failure to implement them would have soon amounted to a violation of Iran’s Safeguards Agreement.

We should not read much political significance into Iran’s acceptance of additional safeguards. Whether Iran is cooperating with inspections because of, or in spite of, the threat of increased sanctions, their centrifuge program is continuing. Indeed, cooperation with the IAEA helps to weaken international political support for sanctions against Iran because of its nuclear program. We could say that Iran would rather have IAEA inspections than violate its Safeguards Agreement and suffer greater international sanctions, but we believe that agreeing to additional safeguards monitoring is not, by itself, an indication that Iran is willing to sit down at the negotiating table, let alone give up its centrifuge program.

Thursday, August 27, 2009

Somali Pirates Fire on US Navy Helicopter

Via Google (AP) -

Somali pirates holding a hijacked ship off the coast of Somalia fired at a U.S. Navy helicopter as it made a surveillance flight over the vessel, the first such attack by pirates on an American military aircraft, the Navy said Thursday.

The helicopter, which is based on the USS Chancellorsville, was not hit and there were no injuries, the Navy said.

The copter was flying on Wednesday over a Taiwanese-flagged fishing vessel, the Win Far, which pirates seized along with its 30-member crew in April and were holding south of the Somali port town of Hobyo.

The helicopter was about 3,000 yards (meters) away from the ship when the pirates opened fire with "a large caliber weapon," the Navy said in a statement. The helicopter did not return fire, it said.

Since seizing the Win Far in the Gulf of Aden, the pirates have used the vessel as a base for attacking other commercial ships, including the U.S.-flagged Maersk Alabama. Four pirates seized the Maersk Alabama in April, taking its captain Richard Phillips hostage. He was held for five days in a sweltering lifeboat off the coast until U.S. Navy snipers shot three of his captors dead.

Lt. Nathan Christensen, a Bahrain-based spokesman for the Navy's 5th Fleet told the Associated Press that Wednesday's shooting marks the first time pirates shot at U.S. Navy helicopters conducting daily surveillance flights over areas where pirates anchor hijacked vessels and await ransom.

Christensen said four other merchant ships and 105 crew members are currently being held by pirates near the Win Far. They are anchored along Somalia's coast, between port towns of Hobyo and Eyl, Christensen said in a phone interview on Thursday.

Piracy has increased in the Gulf of Aden — a crucial shipping route in and out of the Suez Canal — and elsewhere off the coast of Somalia, fueling a more than doubling of pirate attacks in the first half of 2009, according to an international maritime watchdog. Somalia has had no effective central government since 1991, and the country's interim government is embroiled in a struggle with Islamist extremists with suspected al-Qaida links.

Facebook Changes Privacy Policy

Via BBC -

Facebook has agreed to make worldwide changes to its privacy policy as a result of negotiations with Canada's privacy commissioner.

Last month the social network was found to breach Canadian law by holding on to users' personal data indefinitely.

Facebook has now agreed to make changes to the way it collects and handles this information.

It will also make it clear to users that they have the option of either deactivating or deleting their account.

"These changes mean that the privacy of 200 million Facebook users in Canada and around the world will be far better protected," said Canadian privacy commissioner Jennifer Stoddart.

"We're very pleased Facebook has been responsive to our recommendations."

The decision could also have implications for other social networking websites, she said.

Elliot Schrage, vice president of global communications and public policy at Facebook said he believed the new policies set a new standard for the industry."


As well as updating the privacy policy, Facebook has said it will make changes that will give users more control over the data they provide to third-party developers of applications, such as games and quizzes.

There are around 950,000 developers in 180 countries who provide applications for the site.

Specifically, the changes will require applications to state which information they wish to access and obtain consent from the user before it is used or shared.

"Application developers have had virtually unrestricted access to Facebook users' personal information," said Ms Stoddart.

"The changes Facebook plans to introduce will allow users to control the types of personal information that applications can access."

The social network has said work on the changes will begin immediately but they would take around 12 months to implement.

Photo of the Day - Mike Perham


(Credit: REUTERS/Pickthall/PPL/Handout)

British sailor Mike Perham, 17, holds flares as he celebrates his arrival into Falmouth, southern England August 27, 2009. The British teenager became the youngest person ever to sail solo around the world after crossing the finishing line off Land's End on Thursday.

http://www.reuters.com/article/lifestyleMolt/idUSTRE57Q2V220090827

Interpol Issues Notices Against Two More in Connection to Mumbai Terror Attacks

Via The Times of India -

Hours after Pakistan rejected India's 6th dossier on the Mumbai terror attacks, sources on Wednesday told Times Now that the Interpol has issued more Red Corner Notices against two more 26/11 accused. This comes a day after they issued RCNs against Lashkar-e-Taiba founder chief Hafiz Saeed and mastermind of Mumbai terror strike Zaki-ur-Rehman Lakhvi.

Sources have said that the Interpol has issued notices to Zarar Shah and Abu al-Qama for their involvement in the November 26, 2008 Mumbai terror attacks, which killed over 180 people.

India had earlier sent proof and requested for issuing a similar warrant against Lashker commander Zarar Shah and Abu Al Qama, to which the Interpol has said that it was analysing the evidence against them.

The Interpol has issued these notices after a Mumbai court issued a non-bailable warrant against the LeT operatives for their role in the November 26, 2008 attacks.

Besides Saeed and Lakhvi, two other top leaders of LeT -- Haji Muhammad Ashraf and Zaki-ur-Bahaziq -- have also been declared as terrorists by UNSC. India had sought a ban on JuD after LeT was blamed for the terrorist attacks in Mumbai.

The United States had sought a ban on Lakhvi, operations leader of LeT, who is suspected to have planned the Mumbai attacks, Ashraf, a JuD financier, and Bahaziq, an India-born Saudi national who was suspected of collecting funds for the banned organisations in Saudi Arabia.

----------------------------------

According to an Interpol Press Release dated August 6th 2009...
INTERPOL’s National Central Bureau (NCB) in Islamabad, Pakistan, has issued a global alert for 13 individuals wanted by police authorities in Pakistan in connection with the ongoing investigation into the Mumbai terror attacks of November 2008.

China: All Your Rare Earth Metals Belong to Us

Via Wired.com (Danger Room) -

Rare earth metals are the key to 21st Century technology: Without them, we wouldn’t have smart phones, hybrid cars or precision weapons. And China, which mines most of the world’s rare earth metals, may be starting to catch on to their strategic value.

According to this
alarming story in U.K. Telegraph, China’s Ministry of Industry and Information Technology is weighing a total ban on exports of terbium, dysprosium, yttrium, thulium, and lutetium — and may restrict foreign sales of other rare earth metals. But don’t panic yet: U.S.-based Molycorp Minerals is preparing to resume mining of rare earth ore deposits at a California facility, pictured here.

Still, it’s a reminder of the role that strategic resources play, especially for the high-tech military of the United States. As I reported a few years back in the
Financial Times, the Pentagon has become increasingly concerned over Chinese demand for specialty steels and titanium, which are key to armor plating, aircraft design and other high-end weaponry. Finding new, affordable sources of military-grade titanium has been a top priority of Darpa, the Pentagon’s far-out research arm.

Of course, China is not the only country that’s figuring out how to play the mineral wealth hand in geopolitics. For several years now, Russia has used natural gas supply as a way to exert less-than-subtle pressure on its neighbors. Energy, the Kremlin found, is a
more effective instrument than an aging nuclear weapons stockpile: You can actually turn the gas taps off when you feel like punishing someone.

As an old piece of wisdom from Strategic Air Command
put it: “When you have them by the balls, their hearts and minds will follow.”

---------------------------------

The race for limited global resources is on...and its on full force.

This reminds me of a great special report in the June 2008 edition of Fast Company...

Special Report: China Storms Africa

Those on the ground in the sub-Sahara don't call it "the Great Chinese Takeout" for nothing.

Wednesday, August 26, 2009

Malicious CD ROMs Mailed to Banks - UPDATED

Via SANS Internet Storm Center -

The National Credit Union Administration (NCUA) published an interesting advisory here:

http://www.ncua.gov/news/press_releases/2009/MR09-0825a.htm

Member credit unions evidently are reporting receiving letters which include two CDs. The letters claim to originate form the NCUA and advertises the CDs as training materials. However, it appears that the letter is a fake and the CDs include malware.

We have not heard about this scheme affecting any other targets, but please let us know if you see something like this. Malware delivery via USPS has certainly been suggested before.

------------------------

As it turns out, the CDs were part of an authorized pen-test......
Security assessment firm MicroSolved posted a statement on their site on Friday, confirming that they had been the firm conducting the penetration test.

"This was a controlled exercise in which the process worked," the company said in a blog post on Friday. "The social engineering attack itself was unsuccessful and drew the attention of the proper authorities. Had we been actual criminals and attempting fraud, we would have been busted by law enforcement."

Baitullah Mehsud Dead; Hakeemullah New Leader of Pakistani Taliban

The Long War Journal -

Two senior Pakistani Taliban leaders thought to have been at odds have confirmed that the former leader of the Movement of the Taliban in Pakistan is dead. The leaders also confirmed that Hakeemullah Mehsud is now the new leader of the Movement of the Taliban in Pakistan, dispelling the rumors of rampant infighting to choose Baitullah’s successors.

Hakeemullah and Waliur Rehman Mehsud said that Baitullah died on Sunday night from wounds suffered in the Aug. 5 US Predator strike in South Waziristan. The two Taliban leaders spoke via the phone from the same room to an The Associated Press reporter.

"He was wounded. He got the wounds in a drone strike and he was martyred two days ago," Hakeemullah Mehsud told The Associated Press. Waliur repeated the statement to confirm that Baitullah had been killed.

Both leaders stated that Hakeemullah is now the leader of the Movement of the Taliban in Pakistan. Waliur would take command of the Taliban in South Waziristan.

----------------------------------

Not surprisingly, Hakeemullah Mehsud threatened to strike back at the US for killing Baitullah Mehsud in a Predator attack earlier last month.

"We will take revenge and soon," Hakeemullah Mehsud, who was chosen to lead the Movement of the Taliban in Pakistan last weekend, told AFP. "We will give our reply to this drone attack to America."

Twitter Fails to Block Cross Site Scripting (XSS) Flaw

Via H-Online.com -

A vulnerability in the way Twitter handles the URL of client applications that post to the microblogging service can allow for cross site scripting attacks. Twitter maintains an index of client applications that are able to post messages to Twitter that authenticate with OAuth. This allows developers to register an application name, description and URL of their application and when Twitter messages posted by their application are viewed on the web, the application name is displayed as a link to the application URL underneath each message. David Naylor, a UK based SEO expert, discovered that the URL field was unfiltered and demonstrated the problem. In comments on Naylor's blog, a Twitter representative says that the problem has been patched.

Naylor, after finding his demonstration account had been disabled, checked the issue with a new demonstration account (since also disabled) and found that, rather than filtering the field for HTML elements and ensuring it was a valid URL, Twitter's developers had just filtered the URLs on spaces. This allowed the exploit to continue working as he was able to craft a new application URL which pops up an alert in the browser on the Twitter account @apifail2. Naylor says that this could be maliciously exploited and lead to spamming or credential theft if left uncorrected, and suggests users use a desktop Twitter client as they are not generally vulnerable to this attack. Twitter has now closed the @apifail2 account.

Cracking the GSM A5/1 Encryption Via Distributed Computing

Via CNET -

If you are using a GSM phone (AT&T or T-Mobile in the U.S.), you likely have a few more months before it will be easy for practically anyone to spy on your communications.

Security researcher Karsten Nohl is launching an open-source, distributed computing project designed to crack the encryption used on GSM phones and compile it into a code book that can be used to decode conversations and any data that gets sent to and from the phone.

He hopes that by doing this it will spur cellular providers into improving the security of their services and fix a weakness that has been around for 15 years and affects about 3 billion mobile users.

"We're not creating a vulnerability but publicizing a flaw that's already being exploited very widely," he said in a phone interview Monday.

"Clearly we are making the attack more practical and much cheaper, and of course there's a moral question of whether we should do that," he said. "But more importantly, we are informing (people) about a longstanding vulnerability and hopefully preventing more systems from adopting this."

This weakness in the encryption used on the phones, A5/1, has been known about for years. There are at least four commercial tools that allow for decrypting GSM communications that range in price from $100,000 to $250,000 depending on how fast you want the software to work, said Nohl, who previously has publicized weaknesses with wireless smart card chips used in transit systems.

It will take 80 high-performance computers about three months to do a brute force attack on A5/1 and create a large look-up table that will serve as the code book, said Nohl, who announced the project at the Hacking at Random conference in the Netherlands 10 days ago.

Using the code book, anyone could get the encryption key for any GSM call, SMS message, or other communication encrypted with A5/1 and listen to the call or read the data in the clear. If 160 people donate their computing resources to the project, it should only take one and a half months to complete, he said.

Participants download the software and three months later they share the files created with others, via BitTorrent, for instance, Nohl said. "We have no connection to them," he added.

Once the look-up table is created it would be available for anyone to use.

Distributed computing, which has long been used for research and academic purposes, like SETI@home, and which companies have built businesses around, not only solves the technical hurdle to cracking the A5/1 code, but it could solve the legal ones too.

A few years ago a similar GSM cracking project was embarked upon but was halted before it was completed after researchers were intimidated, possibly by a cellular provider, Nohl said. By distributing the effort among participants and not having it centralized, the new effort will be less vulnerable to outside interference, he said.

Nohl wasn't certain of the legal ramifications of the project but said it's likely that using such a look-up table is illegal but possession is legal because of the companies that openly advertise their tables for sale.

A T-Mobile spokeswoman said the company had no comment on the matter.

AT&T spokesman Mark Siegel said, "We take extraordinary care to protect the privacy of our customers and use a variety of tools, many technical and some human approaches. I can't go into the details for security reasons." He declined to elaborate or comment further.

The New Threat to Oil Supplies: Hackers

Via ForeignPolicy.com -

Earlier this year, a sullen, 28-year-old contractor in California was charged in federal court with sabotaging the computerized controls on oil-rig sitting off the coast, allegedly out of spite for not being hired full time. Prosecutors say the contractor hacked into a shore-to-rig communications network that, among other functions, detected oil leaks. He caused thousands of dollars worth of damage, they charge, though, fortunately, no leaks.

A research team from the SINTEF Group, an independent Norwegian think tank, recently warned oil companies worldwide that offshore oil rigs are making themselves particularly vulnerable to hacking as they shift to unmanned robot platforms where vital operations -- everything from data transmission to drilling to sophisticated navigation systems that maintain the platform's position over the wellhead -- are controlled via wireless links to onshore facilities.

The usual threat of a takeover of the massive oil platforms is in the form of seaborne raiders; Britain's Royal Marines commandos still regularly train for hostage rescue on rigs that dot the North Sea. But now, according to SINTEF scientist Martin Gilje Jaatun, with the advent of robot-controlled platforms, a cyberattacker with a PC anywhere in the world can attempt to seize control of a rig, or a cluster of rigs, by hacking into the "integrated operations" that link onshore computer networks to offshore ones. "The worst-case scenario, of course, is that a hacker will break in and take over control of the whole platform," Jaatun said. That hasn't happened yet, but computer viruses have caused personnel injuries and production losses on North Sea platforms, he noted.

Today, most new oil-field discovery, such as off the coasts of Brazil and Nigeria, occurs in deep ocean waters. Work on the massive metal platforms towering hundreds of feet above the ocean is notoriously dangerous for the "roughnecks," and specialized labor costs, not to mention feeding, providing care, and keeping fleets of helicopters and boats on standby to evacuate rig crews in the event of fire or hurricanes, is hugely expensive for oil companies; hence, the move to robot-operated platforms.

Although the newest oil rigs, which cost upward of $1 billion apiece, might be loaded with cutting-edge robotics technology, the software that controls a rig's basic functions is anything but. Most rely on the decades-old supervisory control and data acquisition (SCADA) software, written in an era when the "open source" tag was more important than security, said Jeff Vail, a former counterterrorism and intelligence analyst with the U.S. Interior Department. "It's underappreciated how vulnerable some of these systems are," he said. "It is possible, if you really understood them, to cause catastrophic damage by causing safety systems to fail."

The list of potential cyberattackers includes ecowarriors aiming to jack up an oil firms' production costs, extortionists drawn to oil firms' deep pockets, and foreign governments engaging in a strategic contest for ever more scarce global oil reserves, Vail said. Insurgents, such as Nigeria's Movement for the Emancipation of the Niger Delta, which is waging a war against oil firms operating in that country's waters, could hire mercenary cyberwarriors to mount full-scale assaults on rigs in the delta. Despite obvious network vulnerabilities, oil firms have not made security a priority, said SINTEF's Jaatun, "leaving many of us feeling like 'chicken little' chirping on that the sky is about to fall."