Wednesday, September 16, 2009

Timeline - SMB2 Remote Exploit for Vista & 2008 (CVE-2009-3103)

On Sept 7th, Laurent GaffiƩ released a security advisory and a Proof of Concept code on his blog that generated a B.S.O.D in Windows Vista, Server 2008 array indexing error in the srv2.sys kernel driver. This can be exploited to dereference out-of-bounds memory via a specially crafted SMB packet.

On Sept 8th, Microsoft released Security Advisory (975497) indicating they were investigating new public reports of a possible vulnerability in Microsoft Server Message Block (SMB) implementation. Microsoft listed the following affected software: Windows Vista (Gold, SP1 & SP2); Windows 2008 SP2. Windows 7 is listed as not affected...interestingly enough. It appears Microsoft fixed the flaw in Windows 7 build ~7130, just after RC1.

On Sept 8th, CVE-2009-3103 was assigned to the bug and security researchers begin to see that this wasn't just a simple DoS...but was much more.

On Sept 10th, Pusscat posted an analysis on her VRT Sourcefire blog summarizing her and HD Moore's initial work on exploiting the vulnerability.

During Sept 10th - 11th, you have what my friend |)ruid calls '"how many ways can we open a socket" PoC rewriteathon' - java, perl, python, ruby, c, bash, expect, wget-to-netcat...you get the idea...then it turns into a race...who can get remote execution first?

On Sept 14th, security company Immunity released a local privilege-escalation attack module for its CANVAS pen-test tool.

On Sept 15th, Kostya Korchinsky, a senior security researcher @ Immunity stated on his blog that he has created a remote SMB2 exploit (translated to English). CANVAS is a commercial tool, therefore the remote exploit code is not currently public....but if Kostya can do it, we can be certain that a number of blackhats can get it to work (and they may already have a working remote exploit). According to Dave Aitel, the exploit works for Vista and 2008!

Fast forward to today, Sept 16th, and we all are awaiting Microsoft's next move...many are expecting an out-of-band patch release...and given the current situation, it would seem like a smart thing to do. Sadly for Microsoft, out-of-band patches are become more and more of a necessity to properly protect customers...

At this point, if you are running Windows Vista or Windows 2008, it is recommended to evaluate the workaround choices outlined by Microsoft...and implement them if possible.

------------------

Big thanks to Druid & Todb for helping me fill in some of the timeline....

Tuesday, September 15, 2009

China’s Green Dam Interferes with School Computers

Via SunBelt Blog -

Schools in Beijing, China, are removing the government-mandated Green Dam Internet censorship software because it interferes with educational software.

The technology director of Beijing Number 50 High School posted a note on the school’s web site that Green Dam “…has strong conflicts with teaching software we need for normal work."

In May, China’s Ministry of Industry and Information Technology had ordered the Green Dam Youth Escort filtering software to be installed on all computers sold in China after July 1, but rescinded the order for the general public after a flurry of controversies, although schools and Internet cafes were told to install it.

The problems included:

-- Green Dam is clearly spyware since it monitors key strokes and Sunbelt and other major anti-virus companies classified it as a surveillance tool.

-- A flawed patch for Green Dam was issued, but it left the software vulnerable to exploitation for more than a week after a buffer overflow was discovered that could be exploited by an overly-long URL.

-- The Chinese government said it was to block pornography and “unhealthy” content, but activists found that two thirds of the key words it filtered had political significance.

-- Solid Oak Software of Santa Barbara, Calif., said June 12 that code from its CyberSitter software was used extensively in Green Dam-Youth Escort. It sent cease-and-desist letters to U.S. PC manufacturers who were expecting to install it for the Chinese market. Solid Oak brought lawsuits in the U.S. and China.

-- China’s fiat that the censorship software was to be installed drew protests from the U.S. (as a violation of China’s agreement with the World Trade Organization), the leaders of 22 international business groups and the European Union.

Jinhui Computer System Engineering Co. of Zhengzhou, the company that won the Chinese government’s contract to write the application, got $6 million, late night harassing phone calls and some death threats.

Latest story here.

On the road again....

So the time has finally come...I am moving out of the great state of Texas. I will miss it and I will return one day, until then I need to go down the road [of life]...and take it turn by turn.

I am in the process of moving to North VA, so the post might be spotty for about a week. Hoping to get internet at the new place by this weekend.

Sunday, September 13, 2009

Venezuela to Buy Short-Range Rockets from Russia

Via GlobalSecurity.org -

Venezuelan President Hugo Chavez says he has signed an arms deal with Russia for short range missiles.

The missiles have a range of 300 kilometers. The weapons are a part of a series of arms deals with Moscow. Mr. Chavez made the announcement on Friday after returning from a ten-day tour of Africa, Asia and Europe and he insists the weapons are for defense only.

Mr. Chavez says the rockets will arrive in Venezuela soon and he says his country is not going to attack anybody with them. He says the weapons will help defend his country from any threat no matter where it comes from. Venezuela is currently involved in a dispute with neighboring Colombia over that country's agreement with the U.S. to allow American troops access to seven Colombia bases for anti-drug operations.

Moscow says it is willing to sell Venezuela whatever weapons it is willing to buy. Venezuela is currently negotiating the purchase of 100 T-72 and T-90 tanks from Russia.

Russia has already sold the country 24 fighter jets, dozens of helicopters and assault rifles. This after the United States barred the South American country from buying U.S. equipment. In recent years, Venezuela has spent more than $4 billion on Russian weapons.

In addition to the arms deals, President Chavez recently acknowledged the independence of the Russian-supported breakaway regions of Abkhazia and South Ossetia. The U.S. and the European Union consider the areas part of Georgia and have repeatedly asked Russia to respect Georgia's territorial integrity. Nicaragua is the only other country, besides Russia, that recognizes the regions.

------------------------------------

Based on the range data and the big demand...the missiles might be the Iskander-E.

Iskander-E is the export version of the Iskander M (9M72) short-range ballistic missile currently in service with the Russian Armed Forces (known by NATO designation SS-26)

Operational Range of the Iskander-M = 400km
Operational Range of the Iskander-E = 280km

Malware Using Private Google Group as Command & Control Channel

Via eWeek.com -

Symantec has uncovered a scheme to use a Google Groups newsgroup to sneak commands to malware on compromised computers.

The move is another example of attackers looking for covert ways to communicate to their bots. Earlier this year, attackers were found using Twitter as a command and control (C&C) mechanism. By integrating their messages with legitimate communications, attackers make it more difficult to identify and shut down their C&C, according to Symantec.

“This technique is analogous to the use of encoding messages in newspaper ads that were commonplace in spy novels,” Zulfikar Ramzan, technical director of Symantec Security Response, told eWEEK. “What attackers are taking advantage of are online mediums that allow pretty much anyone to post content and are both highly available as well as readily accessible from the outside. I believe they are going down this route, since it represents a very easy and inexpensive avenue for setting up command and control.”

“One noteworthy aspect of this attack is the use of the RC4 stream cipher to encrypt the messages being passed back and forth,” Ramzan explained. “While encrypting communication is a conceptually simple thing to do, it demonstrates that attackers are trying to take extra measures to avoid detection and also to potentially avoid having their botnet overtaken by some other rogue party.”

The method has some drawbacks for the attacker, however, as every response is stored as a posting in the newsgroup, making it possible to backtrack the Trojan’s activity in detail. Symantec researcher Gavin O. Gorman speculated that given the relatively low amount of activity by the Trojan—some 3,000 newsgroup posts since November 2008—and an examination of its code, this may be a prototype implementation to test the Web-based newsgroups as C&Cs.

“It is most likely Taiwanese-based since the newsgroup language is Chinese [simplified], with several references to .tw domains in commands,” Gorman blogged. “The low numbers imply this is a discreet Trojan, used to subtly gather information and potentially determine future attack targets. In addition, there is no attempt within the DLL to maintain persistence on the attacked computer, further evidence of a Trojan attempting to remain undiscovered. Such a Trojan could potentially have been developed for targeted corporate espionage where anonymity and discretion are priorities.”

By going this route, attackers don’t have to incur the costs of setting up an explicit command and control server, Ramzan added.

“I expect that we’ll continue to see these types of attacks, and that attackers will develop more refined approaches as sites like Google and Twitter develop better detection and containment mechanisms,” he said.

Saturday, September 12, 2009

Information Leakage in Cloud Computing

Via SANS Internet Storm Center -

An interesting paper was published this last week discussing ways of determining the physical system your VM is residing on and influencing that placement. This creates interesting potential for data leakage and discovery of information about the systems that are co-resident on the same hardware.

Yes, I know this is a small step and I'm not arguing that this alone shows that you should never use cloud computing again. However, I would argue that this is exactly the kind of attack that you need to be concerned about as more and more systems are virtualized and put into a cloud. In addition, since most people are used to not thinking about these sorts of attacks, there is a high likelihood that this will be a blind spot in the development of virtualization technology and cloud infrastructure.

The actual paper: http://cseweb.ucsd.edu/~hovav/dist/cloudsec.pdf

A nice summary article about it: http://www.computerworld.com/s/article/9137507/Researchers_find_a_new_way_to_attack_the_cloud

Friday, September 11, 2009

Annual Jihadi Cyberbattle Sees Return of Ikhlas

Via jihadica.com -

Like last year, this year’s 9/11 anniversary is the occasion of a major cyberbattle over jihadi forums. At least three of the top jihadi discussion forums - Faloja, Shouraa, Shumukh - have been down for the past couple of days, and I bet my left arm they have been hacked for the occasion. Other big forums such as Ana Muslim and Ansar were reportedly down for a while (though I didn’t see it and they are back up again now). Minor forums such as Tamkin, Madad al-Suyuf and al-Tahaddi seem to have been untouched.

The other fascinating development, which must be connected in some way to the former, is that the good old Ikhlas forum is back up again after an absence of - guess what - a year. The old passwords are still working. The return of Ikhlas is being presented by the administrators as “Usama bin Ladin’s Ramadan gift to the Umma”. The online jihadi community is suspicious, and people are warning against using Ikhlas. Frankly, I would be suspicious too - something fishy is going on.

Naturally, Haganah is on the ball and I am counting on Aaron to solve this mystery for us.

PS: FFI’s excellent researcher Cecilie Finsnes helped me with this post.

PPS: You will see that for once I have included direct links to all the forums. It is my departure gift to our readers as I leave the stage for a while.

Haqqani Network Commander Killed in Strike

Via The Long War Journal -

A covert US airstrike in a Taliban controlled-tribal agency in Pakistan killed a Haqqani Network military commander in the Haqqani Network.

The Sept. 8 airstrike in the the village of Dargamandi in the Tabi Saidgai area killed 12 people, including Maulvi Ismail Khan, a US military intelligence official told The Long War Journal.

Khan is said to be a mid-level military commander who operates in North Waziristan and also conducts attacks in Afghanistan, the official said.

The official would not comment if Khan was the target of the airstrike or if higher level Haqqani Network, Taliban, or al Qaeda leaders were the focus of the operation.

Early reports of the airstrike indicated the compound that was hit was owned by Khan, however a conflicting report in Dawn indicated the compound was owned by a Maulvi Taib Shah, who was described as a local tribesman.

The Haqqani Network is run by Jalaluddin and his son Siraj. The family controls large swaths of North Waziristan, and runs a parallel administration with courts, recruiting centers, tax offices, and security forces.

The Haqqanis are closely allied to the Afghan and Pakistani Taliban, al Qaeda, and Pakistan's military and intelligence service. Siraj Haqqani is a senior figure in the extensive web of al Qaeda and Taliban groups that operate along the Afghan and Pakistani border.

Photo of the Day - Never Forget


Photo © Daniel Stein / iStockPhoto

Aluminum and steel lattice formed the facade of the New York World Trade Center. This black and white photo was taken in 1982.

iPhone Anti-Phishing Protection Goes AWOL

Via The Register UK -

An anti-phishing feature hyped by Apple marketers has gone AWOL from the iPhone, according to two independent researchers who say the feature simply does not work.

Apple rolled out the feature in iPhone OS 3.0 for the device and once again called attention to it in Wednesday's update to the iPhone operating system. The feature is designed to warn users when they try to browse a page that's known to phish their login credentials for PayPal or some other sensitive online service.

Except that it doesn't. Michael Sutton, vice president of security research for Zscaler, says here that he plugged known phishing sites into both Safari and Safari Mobile and found the difference in responses to be stark.

The sites "were generally blocked by Safari, but none were blocked by Safari Mobile," he writes. "In fact, I have yet to identify a single phishing page blocked on the iPhone." He signs off by imploring users to notify him if they can find a single rogue site that's flagged on the iPhone.

Researchers at Mac security provider Intego report the same finding. "We find it interesting that Apple has added this feature, but we're confused as to why it simply does not work," they write.

To be fair, the iPhone isn't the only smartphone that fails to warn users when they're about to visit a phishing site. But as far as we can tell, Apple is the only manufacturer claiming to protect users from the threat. The issue here is the empty promise of a phishing filter, which gives users a false sense of security.

Thursday, September 10, 2009

Fraud Commission Excludes Ballots in Afghan Vote

Via VOA News -

The commission investigating reports of vote fraud in Afghanistan's presidential election is invalidating the ballots from polling stations in two provinces.

The U.N.-backed Electoral Complaints Commission announced Thursday that it is excluding votes from 32 polling stations in Ghazni and Paktika provinces.

In a statement explaining its decision, the ECC cited "clear and convincing evidence of fraud," including unfolded ballots, uniformity of markings and lists of voters with fictitious card numbers.

The commission has also ordered recounts for ballots from some polling locations.

Afghan President Hamid Karzai has welcomed the partial returns from the country's controversial August 20 presidential elections, which gave him 54 percent of the vote.

But his main challenger, former Foreign Minister Abdullah Abdullah who has 28 percent of the vote, said his campaign will not accept the results because they have been tallied in violation of election laws.

The U.S. Embassy in Kabul has called for patience as the electoral process continues. It also called on both commissions to rigorously carry out their legal mandate to count all votes and to exclude all fraudulent ones.

The Obama administration has said that a "legitimate" election process is vital to the future of U.S.-Afghan relations.

A credible election is also deemed crucial to the reputation of the mission by 42 nations and their 100,000 troops fighting the Taliban and attempting to preserve Afghanistan's fledgling democracy.

With iTunes 9, Apple Again Disables Palm Pre Sync

Via AppleInsider.com -

The tug of war between Apple and Palm continues, as the latest update to iTunes has once again blocked the Palm Pre from syncing with a users' iTunes library.

When the Palm Pre was first released, it, by default, would transfer media from iTunes by incorrectly identifying itself as an iPod. Apple struck back in July with iTunes 8.2.1, which broke sync capabilities, but only temporarily.

A week later, Palm fired back with webOS 1.1, a software update that again enabled the Pre to access media from iTunes. In a jab at Apple, Palm announced the fix at the end of a blog post by stating "Oh, and one more thing," just as the iPod maker often does when it introduces new products at a keynote.

According to Precentral.net, when sync initially worked, the Pre identified itself as a "mass storage device" called an iPod. Then, to get it working the second time, Palm had the device identify itself as a "mass storage device manufactured by Apple" called an iPod.

Given the back-and-forth nature of the ongoing dispute, it's likely safe to assume that Palm will once again issue a webOS update and circumvent Apple's latest blocking method. The latest update, webOS 1.2, was expected to be released this week, but has been quietly delayed.

In other Palm news, the handset maker this week unveiled the Pixi, the second smartphone built on the webOS platform. It is coming to Sprint later this year.

The timing of Palm's announcement has once again seen the company overshadowed by Apple, with the iPod maker announced new media players this week. Earlier this summer, the Pre launched just as Apple announced the iPhone 3GS.

DuPont Alleges Second Insider Breach In Two Years

Via DarkReading.com -

Just two years after discovering an insider breach that might have cost it $400 million, DuPont is alleging theft of trade secrets by another one of its employees

According to an article in DuPont's home state of Delaware, DuPont has filed a lawsuit against -- and fired -- a Chinese-born employee who was allegedly about to leave Delaware and return to China with company trade secrets.

The suit, filed in late August in the Delaware Court of Chancery, accuses Hong Meng of breach of contract and misappropriation of trade secrets -- specifically, research into a paper-thin computer display technology called an "organic light-emitting diode," or OLED.

The suit alleges Meng was planning to take the proprietary information to his alma mater, Peking University in Beijing, which is involved in research on OLED technology, the report says.

DuPont issued a brief statement Friday, indicating Meng, a Chinese national with permanent residency status in the United States, was fired after an internal investigation, and the lawsuit was filed "to ensure that he not use or disclose DuPont trade secrets," according to the report.

"As a science company, DuPont acts to protect our unique and confidential technologies," the statement said. "These events underscore our unwavering commitment to protect the integrity of our proprietary science and technology for the benefit of DuPont shareholders, employees and customers."

DuPont says it spotted Meng's actions when it reviewed his hard drive prior to transferring him to China. Meng had downloaded a number of proprietary files about the OLED, the company alleges.

The chemical giant faced a similar problem two years ago, when former employee Gary Min was found to be in possession of thousands of files relating to the company's trade secrets. The estimated value of the information was assessed at around $400 million.

In that case, Min -- who also has ties to China -- downloaded thousands of documents without authorization from company systems. He also made paper copies of thousands more documents and stored them in an apartment he had rented for that purpose.

Min received a sentence of 18 months in jail and a $30,000 fine.

SQL Injection Exposes Sensitive Details on Military Personnel

Via The Register UK -

Programming errors on a website that helps commuters carpool to work are exposing sensitive information of workers for hundreds of employers in Southern California, including at least one military installation.

The bugs, discovered last month on RideMatch.info, allow hackers access to a variety of personal information, including individuals' names, home addresses, phone numbers, the times they commute to and from work, and in some cases employee numbers. The SQL injection vulnerability remained active at time of writing, more than two weeks after it was reported to a developer who runs the website.

"There's sensitive data there that definitely shouldn't be on the internet," said Kristian Hermansen, a security researcher who identified the vulnerability after receiving an email from his employer saying he was required by law to provide the information. "The reason I am bringing this to your attention is that the issue is not being fixed by the admins and most companies don't even know that their employees' personal and corporate information, like employee ID [number and] login ID, may have been compromised."

The form Hermansen was required to complete asked for a wealth of personal information, including his typical work hours, the times he begins work on each workday, and his employee ID. "The state can impose monetary penalties on companies that fail to complete this survey," an email sent by Hermansen's employer warned.

The website is a joint project developed by transit authorities in five regional governments in Southern California. Individuals enter their work and home addresses and the time they leave from each, and the website pairs them up with others with home and office locations and commute times that are suitable for carpools. Hermansen said virtually all of the data is accessible to anyone who knows how to exploit the vulnerability.

His tests revealed that at least one military institution was among the employers that used the website. The Register agreed to withhold the institution' identity because of the potential sensitivity of the matter.

NSA-Intercepted E-Mails Helped Convict Would-Be Bombers

Via Wired.com -

The three men convicted in the United Kingdom on Monday of a plot to bomb several transcontinental flights were prosecuted in part using crucial e-mail correspondences intercepted by the U.S. National Security Agency, according to Britain’s Channel 4.

The e-mails, several of which have been reprinted by the BBC and other publications, contained coded messages, according to prosecutors. They were intercepted by the NSA in 2006 but were not included in evidence introduced in a first trial against the three last year.

That trial resulted in the men being convicted of conspiracy to commit murder; but a jury was not convinced that they had planned to use soft drink bottles filled with liquid explosives to blow up seven trans-Atlantic planes — the charge for which they were convicted this week in a second trial.

According to Channel 4, the NSA had previously shown the e-mails to their British counterparts, but refused to let prosecutors use the evidence in the first trial, because the agency didn’t want to tip off an alleged accomplice in Pakistan named Rashid Rauf that his e-mail was being monitored. U.S. intelligence agents said Rauf was al Qaeda’s director of European operations at the time and that the bomb plot was being directed by Rauf and others in Pakistan.

The NSA later changed its mind and allowed the evidence to be introduced in the second trial, which was crucial to getting the jury conviction. Channel 4 suggests the NSA’s change of mind occurred after Rauf, a Briton born of Pakistani parents, was reportedly killed last year by a U.S. drone missile that struck a house where he was staying in northern Pakistan.

Although British prosecutors were eager to use the e-mails in their second trial against the three plotters, British courts prohibit the use of evidence obtained through interception. So last January, a U.S. court issued warrants directly to Yahoo to hand over the same correspondence.

It’s unclear if the NSA intercepted the messages as they passed through internet nodes based in the U.S. or intercepted them overseas. If the former, it’s possible the interception was part of the Bush administration’s warrantless surveillance program — a surveillance program aimed at intercepting foreign correspondence as it passed through domestic internet switches. Such interception was previously illegal unless conducted with a warrant from the Foreign Intelligence Surveillance Court. After news stories revealed that the NSA was conducting such surveillance without a warrant, however, Congress legalized such collection activities last year in its passage of the FISA Amendments Act.

Tuesday, September 8, 2009

AQAP Claims Responsibility for Attack On Saudi Arabia's Prince Muhammad bin Nayif

Via Janes.com -

Al-Qaeda in the Arabian Peninsula (AQAP) has claimed responsibility for the failed attempt to kill Saudi Arabia's Prince Muhammad bin Nayif on 27 August. The bomber exploited the kingdom's efforts to persuade wanted jihadists to surrender to get close to the prince. AQAP is unlikely to get another such opportunity.

The group, which is a merger of the Saudi and Yemeni branches of Al-Qaeda, released a statement to jihadist websites dated 27 August claiming it had "carried out a quality intelligence operation which removed from the path of Muslims a tyrant among the tyrants of Al-Saud inside his palace in Jiddah".

In a subsequent statement dated 29 August, the group acknowledged that Prince Muhammad had survived the attack.

-------------------------------

This new is a little old in CT terms...but I felt it was important to highlight this AQAP claim. It shows that the new consolidated group is capable of high-level attacks. The group formed in early 2009 when Al Qaeda in Yemen announced its merger with Saudi Arabia's al Qaeda organization.

Senior Al-Qaeda Leaders Reported Killed in North Waziristan UAV Strike

Via The Long War Journal -

Two senior al Qaeda leaders are among those thought to have been killed in the Sept. 8 Predator strike in Pakistan's Taliban-controlled tribal agency of North Waziristan.
Ilyas Kashmiri and Mustafa al Jaziri may have been killed during the strike in the village of Machi Khel near Mir Ali. Unmanned US strike aircraft are reported to have hit a car and a madrassa in the attack, The News reported.

[...]

Mustafa al Jaziri is a senior military commander for al Qaeda. "Jaziri sits on al Qaeda's military shura [council]," a senior US military intelligence official told The Long War Journal. "He is an important and effective leader." Jaziri is an Algerian national.

Ilyas Kashmiri is "one of al Qaeda's most dangerous commanders" the official said. He is the operational commander of the Harkat-ul Jihad Islami (HuJI), an al Qaeda-linked terror group that operates in Pakistan, Kashmir, India, Afghanistan, and Bangladesh. Kashmiri was recently listed as the fourth most wanted terrorist by Pakistan's Interior Ministry.

Kashmiri is thought to have played a major role in the multi-pronged suicide attack against government and security installations in the eastern Afghan province of Khost in May, the military intelligence official said.

Last year, Kashmiri reportedly drafted a plan to assassinate General Ashfaq Pervez Kiyani, Pakistan's top military officer, but the plan was canceled by al Qaeda's senior leadership, according to a report in the Asia Times.

Harkat-ul-Jihad-al-Islami, Laskhar-e-Jhangvi, Lashkar-e-Taiba, Jaish-e-Mohammed, and several other Pakistani terror groups have merged with al Qaeda in Pakistan, and operate under the name of Brigade 313. This group is interlinked with Pakistan's Taliban and also recruits senior members of Pakistan's military and intelligence services, a senior US official told The Long War Journal.

Brigade 313 has been behind many of the high-profile attacks and bombings inside Pakistan, including multiple assassination attempts against former President Pervez Musharraf and Prime Minister Gilani. Brigade 313 is one of the six known units in the Lashkar al Zil, al Qaeda's paramilitary Shadow Army.

"If we got Kashmiri, this would be the most successful strike against al Qaeda this year," the official said. Kashmiri's death would be on par with that of Osama al Kini, al Qaeda's operational leader in Pakistan, who was killed during a New Years Day airstrike, the official noted.

US intelligence officials contacted by The Long War Journal would neither confirm nor deny that Kashmiri and Jaziri had been killed in the airstrike.

----------------------------

The town of Mir Ali is a known stronghold of al Qaeda leader Abu Kasha al Iraqi, an Iraqi national who is also known as Abu Akash. He has close links to the Taliban, a senior US intelligence official told The Long War Journal in January 2007. He serves as the key link between al Qaeda's Shura Majlis, or executive council, and the Taliban.

DNSSEC Secures Another Domain (.edu)

Via DarkReading.com -

Education and academic community domain .edu is about to become the next top-level domain adopt the Domain Name Systems (DNS) security protocol.

Domains ending in .edu will be able to digitally sign their domains with DNSSEC by the end of next March. DNSSEC is basically an extra layer of authentication that helps protect the DNS translation process from being compromised by attackers.

DNSSEC has been gaining momentum during the past year in the wake of researcher Dan Kaminsky's finding of a major DNS cache poisoning flaw. The .org domain is signed, federal agencies must adopt DNSSEC by December for their .gov domains, and new FISMA regulations call for agencies to sign their intranet zones with DNSSEC by the middle of next year. And VeriSign plans to sign .net with DNSSEC by the end of 2010, and .com in early 2011.

While .edu's move to DNSSEC will allow institutions to digitally sign their domain names, security experts and officials say just when or if the registrants themselves will go DNSSEC is unclear. "The first step is to make the necessary changes in the zone so that individual registrants can take advantage of it," says Steve Worona, director of policy and networking programs for EDUCAUSE, which operates the .edu domain. "And it's [their] decision of when and whether they will sign their [domain]."

The .edu domain is one of the smallest, with about 6,000 registrants, but its adoption of DNSSEC could serve as a case study for the larger domains, Worona says. "This is quite a technologically savvy community [as well]. People understand what DNSSEC is and what its value would be," he says.

New Remote Flaw Found in SMB2 in Windows Vista and Windows 7

Via Threatpost.com -

Researchers have found a new vulnerability in the SMB2 protocol in Windows Vista and Windows 7 that enables an attacker to remotely crash vulnerable machines. There is proof-of-concept exploit available for the vulnerability, as well.

There is no patch available for the vulnerability, which affects fully updated machines running all versions of both 32-bit and 64-bit Windows Vista and Windows 7. SMB2 is a newer version of the venerable Server Message Block protocol. The suggested workaround for defeating the exploit is to disable SMB2 until a patch is available.

From the vulnerability bulletin:
SRV2.SYS fails to handle malformed SMB headers for the NEGOTIATE PROTOCOL REQUEST functionality. The NEGOTIATE PROTOCOL REQUEST is the first SMB query a client send to a SMB server, and it's used to identify the SMB dialect that will be used for further communication.
In order for the attack to work, file sharing must be enabled on the target machine. The researcher who discovered the flaw, Laurent Gaffie, said that he has contacted Microsoft and notified them of the vulnerability. News of the flaw comes on the monthly Patch Tuesday for Microsoft, a day on which the company will be releasing five critical fixes for its products.

SMB2 was designed by Microsoft as a more efficient and modern version of the original SMB protocol, which was designed by IBM. SMB is used for sharing resources such as printers, files and ports across a network.

Patch Tuesday: Microsoft Plugs Windows Worm Holes & TCP Flaws

Via Threatpost.com -

Microsoft today released a peck of patches to cover at least seven documented worm holes in the Windows operating system.

The most serious of the vulnerabilities addresses could lead to remote code execution complete system takeover attacks. The September batch of patches does not address the FTP in IIS vulnerability that is currently being exploited in the wild.

Here are the raw details on 7 flaws in this month's critical bulletins:

  • MS09-045: A remote code execution vulnerability exists in the way that the JScript scripting engine processes scripts in Web pages. The vulnerability could allow remote code execution if a user opened a specially crafted file or visited a Web site that is running a specially crafted script. When the JScript scripting engine attempts to load the decoded script into memory in order to run it, a memory corruption can occur that may either cause Internet Explorer to stop responding, or lead to code execution. This flaw affects Windows 2000, Windows XP, Windows Server 2003, Windows Vista and Windows Server 2008.
  • MS09-046: A remote code execution vulnerability exists in the DHTML Editing Component ActiveX Control. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When the Microsoft DHTML Editing Component ActiveX Control is instantiated in Internet Explorer, the control may corrupt the system state in such a way that an attacker could run arbitrary code. This update is rated "critical" for all supported editions of Microsoft Windows 2000 and Windows XP and Moderate for all supported editions of Windows Server 2003.
  • MS09-047: This bulletin includes fixes for two different vulnerabilities in Windows Media Format. Either vulnerability could allow remote code execution if a user opened a specially crafted media file. A malicious hacker could use booby-trapped MP3 of ASF files to launch code execution attacks. The update is rated critical for Windows Media Format Runtime 9.0, Windows Media Format Runtime 9.5, Windows Media Format Runtime 11, Microsoft Media Foundation, Windows Media Services 9.1, and Windows Media Services 2008.
  • MS09-049: Covers a serious vulnerability in the Windows Wireless LAN AutoConfig Service. The vulnerability could allow remote code execution if a client or server with a wireless network interface enabled receives specially crafted wireless frames. Systems without a wireless card enabled are not at risk from this vulnerability. The vulnerability is caused by lack of validation of part of a specific malformed frame transmitted by a remote wireless transmitter. This could lead to a heap overflow situation that may result in arbitrary code execution.
  • MS09-048: This update patches three different vulnerabilities in Transmission Control Protocol/Internet Protocol (TCP/IP) processing. The vulnerabilities could allow remote code execution if an attacker sent specially crafted TCP/IP packets over the network to a computer with a listening service. Microsoft suggests that businesses use firewall best practices and standard default firewall configurations to help protect networks from attacks that originate outside the enterprise perimeter. Best practices recommend that systems that are connected to the Internet have a minimal number of ports exposed.

Separately, Cisco also released its own patch for one of the TCP/IP bugs covered by Microsoft here.

---------------------------

The TCP flaws were identified several years ago and were made public last year by two researchers at Outpost24, Jack C. Louis and Robert E. Lee. Louis, who has since died, developed a tool called Sockstress which tested for the flaw and was able to maintain extremely long-term TCP connections with remote machines using very little bandwidth. Louis and Lee notified vendors about the problems in 2008, but the process of fixing the vulnerability was a long one, given the huge number of vendors and products affected.

Sunday, September 6, 2009

Novel H1N1 Flu Situation Update

Some 2,000 students at Washington State University have reported symptoms of swine flu, university officials said, in one of the largest reported outbreaks of the virus on a US college campus. Washington state's Whitman County, where the school is located said that tests at a state laboratory late last week "confirmed that the influenza outbreak at Washington State University (WSU)... is indeed caused by the novel 2009 H1N1 Influenza A."

---------------------------

On August 7, 2009, President Obama’s Council of Advisors on Science and Technology (PCAST) has released a report assessing H1N1 preparations. The full text of the report can be found here (pdf).

---------------------------

CDC - http://www.cdc.gov/h1n1flu/update.htm & http://www.cdc.gov/flu/weekly/

During week 34 (August 23-29, 2009), influenza activity increased in the United States.

Since mid-April to August 30, 2009, a total of 9,079 hospitalizations and 593 deaths associated with 2009 influenza A (H1N1) viruses have been reported to CDC an increase from 8,843 hospitalizations and 556 deaths from the prior week.

[...]

Almost all of the influenza viruses identified were the new 2009 H1N1 influenza A viruses. These 2009 H1N1 viruses remain similar to the viruses chosen for the 2009 H1N1 vaccine and remain susceptible to antiviral drugs (oseltamivir and zanamivir) with rare exception.

---------------------------

WHO Pandemic (H1N1) 2009 - update 64

30 August 2009

Tropical regions of South and Southeast Asia continue to experience geographically regional or widespread influenza activity (represented by countries such as India, Bangladesh, Myanmar, Thailand, Cambodia, Sri Lanka, and Indonesia). Many countries in the region are reporting increasing or sustained high levels of respiratory disease, and a few (Thailand and Brunei Darussalam) have begun to report a declining trend in the level of respiratory diseases.

[...]

Pandemic (H1N1) influenza virus continues to be the predominant circulating virus of influenza, both in the northern and southern hemisphere. All pandemic H1N1 2009 influenza viruses analysed to date have been antigenically and genetically similar to A/California/7/2009-like pandemic H1N1 2009 virus.


The breakdown of the number of laboratory-confirmed cases is given in this map.

Number of global laboratory-confirmed cases = Over 254,206 (At least 2,837 deaths)

The laboratory-confirmed cases represent a substantial underestimation of total cases in the world as many countries focus surveillance and laboratory testing only in persons with severe illness.

Pakistan Raids Unravel Taliban Drugs Link

Via Times of India (Aug 25, 2009) -

Pakistani authorities arrested 13 Islamist militants in separate raids that police said on Monday foiled major terrorist attacks and provided clues to how drug sales help fund the Taliban.

Police seized heroin and bomb-making material in one bust in Karachi, the country’s commercial center. A Taliban recruiter of suicide bombers was also captured in the eastern city of Sargodha, where terrorists were planning to launch strikes next week.

Police in Karachi arrested seven members of the banned Lashkar-e-Jhangvi movement in a raid on Sunday in the teeming port city, police officer Fayyaz Khan said. The al-Qaida-linked movement is blamed for the beheading of Wall Street Journal reporter Daniel Pearl.

The Karachi cell was planning attacks on government officials, police and offices of intelligence agencies, cops said. Police seized 2kg of heroin, three suicide vests and 15kg of explosives in the raid.

How Team of Geeks Cracked Spy Trade

Via WSJ.com -

From a Silicon Valley office strewn with bean-bag chairs, a group of twenty-something software engineers is building an unlikely following of terrorist hunters at U.S. spy agencies.

One of the latest entrants into the government spy-services marketplace, Palantir Technologies has designed what many intelligence analysts say is the most effective tool to date to investigate terrorist networks. The software's main advance is a user-friendly search tool that can scan multiple data sources at once, something previous search tools couldn't do. That means an analyst who is following a tip about a planned terror attack, for example, can more quickly and easily unearth connections among suspects, money transfers, phone calls and previous attacks around the globe.

Palantir's software has helped root out terrorist financing networks, revealed new trends in roadside bomb attacks, and uncovered details of Syrian suicide bombing networks in Iraq, according to current and former U.S. officials familiar with the events. It has also foiled a Pakistani suicide bombing plot on Western targets and discovered a spy infiltration of an allied government. It is now being used by the Central Intelligence Agency, the Pentagon and the Federal Bureau of Investigation.

Yet Palantir -- which takes its name from the "seeing stones" in the "Lord of the Rings" series -- remains an outlier among government security contractors. It rejected advice to hire retired generals to curry favor with the agencies and hired young government analysts frustrated by working with slow-footed technology. The company's founders knew little about intelligence gathering when they started out. Instead, they went on a fact-finding mission, working with analysts to build the product from scratch.

"We were very naive. We just thought this was a cool idea," says Palantir's 41-year-old chief executive Alexander Karp, whose usual dress is a track-suit jacket, blue jeans, and red leather sneakers. "I underestimated how difficult it would be."

Technology like Palantir's is increasingly important to spies confronting an information explosion, where terrorists can hide communications in vast data streams on the Internet. Intelligence agencies are struggling to identify and monitor such information -- and quickly send relevant data to the analysts who need it. U.S. officials say the software is also crucial as the country steps up its offensive in difficult theaters like Afghanistan. There, Palantir's software is now being used to analyze constantly shifting tribal dynamics and distinguish potential allies from enemies, according to current and former counterterrorism officials familiar with the work.

"It's a new way of war fighting," says former Assistant Secretary of Defense Mary Beth Long. While there are many good systems, Ms. Long says, with Palantir's software "you can actually point to examples where it was pretty clear that lives were saved."

Palantir's chief rivals are I2 Inc., a 20-year-old software company with offices in McLean, Va., and a handful of defense contractors who have been building software for intelligence agencies for years. I2's general manager, Todd Drake, dismisses his upstart competitor as "the new sexy thing," saying that Palantir won't be able to make lasting inroads in a government market that prizes the stability of established companies. Palantir CEO Mr. Karp says such criticism doesn't trouble him. He says the company is already expanding rapidly.

Friday, September 4, 2009

New Versions of Firefox Will Prompt for Adobe Flash Updates

Via SunBelt Blog -

Mozilla has had a good idea: checking for outdated Adobe Flash installations during the Firefox update process.

The mechanism hasn’t been announced by Mozilla, but a researcher found that the upcoming releases of the Firefox browser (3.5.3 and 3.0.14) will keep track of Adobe Flash plug-ins and prompt users when updates are available. The check will occur when users update their browser.

Currently, Firefox users can check for updates by checking Tools | Add-ons. A yellow “update” arrow icon will appear in the pop-up window if any updates are available for any add-ons they are running.

It’s been estimated that four out of five web surfers are using an unpatched version of Flash. In July, a Trojan was found that targeted the code used by Adobe Flash (vs. 9 and 10) and Adobe Reader and Acrobat (9.1.2). The malcode was embedded in PDF files.

Story here “Mozilla to protect Adobe Flash users – Update

Israelis Offer Unmanned Smart Missile 8-Pack Box

Via The Register UK -

Israel appears to have stolen a march on America in the matter of multipack unmanned cruise missile-in-a-box packages. An Israeli maker is exhibiting its "Jumper" robo missile pack as ready for sale, while the rival US "Netfires" system is still in development.

The idea of such weapons is simple. A large box (looks like a festival toilet to us) contains several vertically-launched missiles, along with its own communications and power. It's generally light enough to be driven about by a Humvee or similar, parachuted down from a transport plane, dropped off by helicopter, tied down on the deck of a ship or barge etc. It needs no crew in operation.

Once the box is in place, it awaits orders. A soldier far off, or an aircraft or UAV, can mark a target using map coordinates - and light it up with a laser pointer for extra precision if required. As soon as firing authority is given - perhaps by a remote command post, or by the commander on the ground - a missile leaps up out of the box and flies to the designated coordinates using GPS satnav and inertial navigation.

On arrival, it plunges out of the sky and strikes as precisely as a smart bomb - even hitting moving targets if laser pointing is available. Scratch one tank, pickup truck, building or whatever.

So far, so blah - anyone with air or modern artillery support can do this already.

But that's the point, in fact. Keeping aircraft overhead - even unmanned ones - costs a lot of money and ties up a lot of people. Having a battery of guns or normal bombardment rockets to hand is even worse: more people, on the ground this time, and all the ammo and fuel etc has to be shipped all the way into the field.

With things like Jumper or the American Netfires/Non Line Of Sight Launch System (NLOS-LS), you might not need mortar platoons, artillery regiments and strike air nearly so much. And with any soldier packing a targeting laser able to knock out tanks by the dozen, you might not bother with them so much either.

In short, if smart-missile multipack boxes catch on, there could be a serious change to the way armed forces are organised. They'd contain, potentially, a lot more combat troops, as the business of providing fire support would be automated and becomes merely an offshoot of logistics - moving boxes about.

Until now, the main visible contender in the field was the slowly-gestating NLOS-LS. But yesterday Israel Aerospace Industries announced that Jumper is ready to go. IAI say their box holds 8 missiles as opposed to the NLOS-LS' 15*. Jumper is said to offer range of 50km, "several possible warheads", "pinpoint accuracy and short time of flight ... regardless of weather and visibility".

It'll be interesting to see how all this pans out.

DARPA Seeks Surgical Digital Signal Jamming

Via The Register UK -

US military researchers are looking to build networks of small, low-power transmitter boxes which together can perform "surgical jamming" of digital signals - shutting down cellphones and sat nav receivers within an area "on the order of a city block corner".

The new initiative is called Precision Electronic Warfare (PREW). It comes, of course, from our old friends at DARPA, where it's their goal to give every double-edged sword a bleeding edge.

According to DARPA, in hardware terms PREW would consist of "an ad hoc sparse array consisting of multiple airborne and/or ground nodes... robust, low cost, small size, weight and power distributed platforms".

Each PREW node would be equipped with a highly-accurate clock synchronised with those aboard its fellows, perhaps one of the tiny ones developed for the Chip-Scale Atomic Clocks programme, and would probably be able to communicate with them as well. It would also have "localisation" - ie a good idea of its location, presumably from GPS sat nav or some similar tech.

All these would merely be enabling accessories, however, allowing the PREW radio-cloud to use its "energy transmission" capabilities with unusual precision. The 40-plus nodes would be able to point and focus their jamming power on an area perhaps 100m across - as DARPA says, a street corner - from as far as 20km without affecting reception in adjacent areas.

Exactly what frequencies the PREW should be able to target is a secret, but DARPA offer a broad hint by saying that "target signals were chosen as representative of a range of signal classes, to include navigation, digital infrastructure-based communications, and digital non-infrastructure communications". Or in other words GPS sat nav, cellphone and CB-type radio bands.

[...]

In other words, the system would be able to lock onto your cellphone and hold you within a bubble of jamming no matter how you moved about, denying you any communications or navigation services. If you weren't carrying a suitable marker beacon, one could be planted on you. Presumably in time DARPA will also be able to make the street lights switch off as you pass, then switch on again once you move on.

Another application could see a bubble of sat nav denial wrapped around an enemy missile or autonomous vehicle, without affecting nearby US units; or a given cell tower suddenly blotted out; or you name it.

Interesting stuff, with the usual caveat that not many DARPA projects ever succeed. There's more from the federal warboffins here (pdf).