Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Friday, September 25, 2009
Al-Qaida and the German Elections
Usama Bin Ladin has just released a new audio statement to the European peoples. It is relatively short (under 5 minutes) and basically tells the Europeans to get out of Afghanistan. The statement is subtitled in German and is clearly timed to coincide with the German elections this coming Sunday.
Bin Ladin’s statement comes in addition to a series of three statements from Bekkai Harrach threatening Germany. I have not seen this kind of jihadi media offensive in connection with any other non-US election. Of course, I, like everyone else, can’t help thinking of the Spanish elections in 2004.
Peter Neumann at FREEradicals has a good analysis where he reveals that German intelligence are very nervous. Should they be?
Personally I think al-Qaida would not issue all these messages if something really big was in the making in the next few days, precisely because media offensives put intelligence services on high alert.
My guess is that these messages are primarily intended to influence German public opinion at a crucial juncture in the Western campaign in Afghanistan. Germany is a pivotal player in the coalition; her withdrawal could initiate a vicious (or virtuous, depending on one’s preferences) circle of European withdrawals from the Afghanistan enterprise. Al Qaida is focusing the weakest link in the coalition, just as the Madrid bombers were advised to do.
Another function of messages such as this is to set the stage for attacks that may be several months away. By warning Germans before the elections, al-Qaida can punish them afterwards for not doing as he said.
Finally, Bin Ladin and Harrach are probably also hoping that these messages will inspire some independent initiatives from grassroots jihadists in Europe. Today’s arrest of a man in Stuttgart suspected of distributing the video suggests there are people inside Germany who are thus inclined. On a related note, Leah at All Things CT has a post about forum reactions to the Bin Ladin message.
In short, there are good reasons for German analysts to be working some overtime this weekend.
Jordanian Arrested Over Dallas Bomb Plot
A Jordanian man was arrested and charged with attempting to blow up a skyscraper in Dallas on Thursday, the latest in a series of alleged bomb plots disclosed by U.S. officials.
A U.S. Justice Department statement said Hosam Maher Husein Smadi, 19, was arrested after planting an inert bomb at Fountain Place, a 60-story glass tower in downtown Dallas following an undercover FBI operation.
Details of Smadi's arrest were disclosed hours after authorities in Illinois revealed a broadly similar case in Springfield.
Smadi was described as a Jordanian citizen staying in the United States illegally who had "repeatedly espoused his desire to commit violent Jihad," the Justice Department said.
"The highest priority of the FBI and the Department of Justice remains the prevention of another terrorist attack within the United States," said James Jacks, U.S. Attorney for the Northern District of Texas.
"The identification and apprehension of this defendant, who was acting alone, is a sobering reminder that there are people among us who want to do us grave harm," he added in a statement.
Officials stressed however that Smadi's arrest was unrelated to an ongoing investigation in Colorado and New York involving an Afghan-born airport worker accused of plotting a bombing campaign.
The Justice Department statement said Smadi had declared his willingness to serve as a "soldier for Osama Bin Laden and Al Qaeda" and to conduct Jihad.
He is alleged to have told undercover FBI agents posing as members of an Al Qaeda sleeper cell that he had come to the United States specifically to commit "Jihad for the sake of God."
Smadi has been charged with attempting to use a weapon of mass destruction.
Iran on Defensive Over Undeclared Enrichment Site - Near Qom
The announcement of a second uranium enrichment site puts Iran on the defensive as it tries to head off further sanctions.
The site - said to be near Qom - was acknowledged by Iran in a letter to the International Atomic Energy Agency (IAEA) on Monday, only just pre-empting an announcement by US President Barack Obama. Western intelligence agencies discovered the site some time ago, according to the New York Times.
In its letter to the IAEA, Iran sought to downplay the site's importance, saying that it was a pilot plant still under construction.
The announcement about this site is an embarrassment to Iran, which has said that it is cooperating with the IAEA.
The problem for Iran is that this will increase the suspicions many governments have about its secrecy and its intentions. Under the terms of its agreement with the IAEA, it should have told the agency at the planning and design stage. Iran has tried to repudiate this agreement, so might argue that it did not yet have to report the plant, but the IAEA says that such repudiations are not permitted.
Some fear that Iran is developing at least a nuclear-weapon capacity, with a view to making a bomb one day. Iran says it is against nuclear weapons and is simply making fuel for nuclear power.
Iranian ambitions for this site are not known. It could be that they wanted a back-up in case their main plant at Natanz was attacked. But another fear is that they intended to enrich uranium more highly at the secret plant, to a level suitable for a nuclear explosion.
President Obama said that its size and scope was "inconsistent" with a peaceful programme.
Mark Fitzpatrick of the International Institute for International Affairs said the 3,000 centrifuges estimated to be at the plant would not be enough to make any nuclear fuel but could be used to enrich enough uranium to the higher level needed for a nuclear explosion.
He said that Iran did appear to be in violation of its IAEA safeguards agreement.
"Common sense also dictates that at this time Iran would have been open if it had nothing to hide," he added. "This shows it is far from being on the up-and-up."
The discovery will strengthen the demands by the US and its allies for further sanctions to be imposed on Iran unless it suspends all enrichment, as required by the Security Council.
This might help explain why this week Russia appeared to soften its opposition to further sanctions.
The US wants Iran's oil and gas industries to be targeted. Current Security Council sanctions aim principally at its nuclear and ballistic missile work.
President Obama demanded that the new site be opened immediately to IAEA inspection.
--------------------------------
According to CNN...
The second nuclear facility, on a military base near the Shia Muslim holy city of Qom, is thought to be capable of housing 3,000 centrifuges, not enough to produce nuclear fuel to power a reactor, but sufficient to manufacture bomb-making material, a U.S. diplomatic source who read the letter told CNN.
Honda's Unveils U3-X Unicycle for Robots
It's basically a robotic unicycle.
The device is able to readjust itself so that instead of riders having to constantly balance themselves, the robotic unicycle does the compensating.
Honda pointed out in its unveiling video that the U3-X's seat is slightly higher than an average person's waistline, forcing riders to jump up slightly to sit on it and place their feet on a foot rest. This elevated height of the robotic unicycle leaves riders at relative eye level with passing pedestrians while in motion, according to Honda.
It's a nice touch. A common complaint among people in wheelchairs are the social and psychological effects of literally being looked down upon while traveling the world in a sitting position. But requiring the rider to be able to hold upright while on a backless seat clearly disqualifies the U3-X as a wheelchair substitute for many.
And in this age of rising obesity, who among the fitness-conscious is really going to ride the streets on a robotic stool when they can get a little chance at some exercise during their busy day by walking?
It's just one of those things you know no one is really going to buy. So why, then, did Honda unveil the U3-X robotic unicycle?
Like the Segway, the U3-X is more about showing off an engineering breakthrough than selling an actual product. In this case, Honda contributes to the ongoing discourse on mobility among roboticists.
[...]
Honda's HOT Drive System (Honda Omni Traction Drive System), the omni-directional wheel Honda claims is the "world's first wheel structure which enables movement in all directions" adds to this ongoing discourse on mobility.
Note Honda's word choice in describing their system.
The U3-X is not the first multi-directional rolling robot and Honda knows this. Carnegie Mellon, for example, unveiled the Ballbot in 2006. But the method Honda uses--which includes synchronizing small motor-controlled wheels to make the U3-X multi-directional--is unique.
Honda's U3-X also includes balance control technology that allows the device to respond to how its load shifts and readjust balance accordingly while on the go.
"The incline sensor detects the incline of the device based on the weight shift of the rider and determines the rider's intention in terms of the direction and speed. Based on the data, precise control is applied to return the device to an upright position, which achieves smooth and agile movements and simple operation by weight shift only," Honda said in a statement.
MMS Debuts for the iPhone
http://www.macworld.com/article/142962/2009/09/att_mms.html?lsrc=top_3
http://www.pcworld.com/businesscenter/article/172624/how_could_iphone_mms_crash_atandts_network.html
Plea Deal Clears NGA Intelligence Analyst of Felony Hacking
Federal prosecutors dropped a felony hacking charge Thursday against a Defense Department intelligence analyst who poked around in a system involved in a national terrorism investigation.
The analyst, Brian Keith Montgomery, pleaded guilty to a misdemeanor charge instead, settling the case and making prison time unlikely.
Montgomery held a top secret clearance while working on a covert program at the National Geospatial-Intelligence Agency — the spy agency in charge of satellite and aerial image collection. On April 9, while stationed at an NGA facility on Fort Belvoir in northern Virginia, the 10-year agency veteran saw a message that “provided significant detail about a classified operation” that was unrelated to his job, according to a court affidavit filed by a Pentagon investigator.
The analyst twice logged in to a system involved in the terrorism investigation: first on April 9, when he stayed on for two hours, and then on April 14. He’d gotten the password from another classified message to which he also had legitimate access. Montgomery later told investigators that he hadn’t noticed a warning in the message advising that only personnel participating in the classified operation were authorized to use the password.
Court records say little about the system Montgomery logged into, except that it was was being used from around the United States, and was being monitored by the FBI and other law enforcement agencies at the time of Montgomery’s access.
By accessing the system, Montgomery endangered the terrorism investigation, and “caused harm to the U.S. Army and the FBI,” according to an affidavit by Dexter Wells, an agent with the Defense Criminal Investigative Service.
Federal prosecutors in the Eastern District of Virginia charged Montgomery on Sept. 11 with a single felony count under a provision of the Computer Fraud and Abuse Act that covers intrusions in which damage is done or public safety is jeopardized.
The charge was dropped in a plea deal on Wednesday. Montgomery pleaded guilty to new, lesser charge of exceeding his authorized access to the NGA computer on which he read about the terrorism operation and obtained the password to the unnamed system. The misdemeanor carries up to a year in prison, but sentencing guidelines suggest probation for a first offense.
In an interview with Threat Level last week, Montgomery said he was being made a scapegoat for a security slip-up that sent the password to thousands of analysts without the need-to-know.
“In my opinion, go after the person who provided me with that information,” he told Threat Level last week. “I was just a consumer. I wasn’t the person who put that username and password out there for tens out thousands of analysts to see.”
The United States’ Attorneys office has not returned a phone call on the case. Montgomery and his attorney did not immediately return phone calls Thursday.
Al-Qaida Declares New "Cabinet Roster" for its "Islamic State of Iraq" (ISI)
Al-Qaida's "Islamic State of Iraq" (ISI) has issued an updated leadership "cabinet roster." The roster reads as follows:
- Deputy Emir and Minister of War: "Abu Hamza al-Muhajir, Abdel Moneim al-Badawi"
- Minister of Shariah Councils: "Shaykh Abdul Wahab al-Mashhadani"
- Minister of Public Relations: "Shaykh Mohammed al-Dulaimi"
- Minister for Prisoners and Martyrs: "Shaykh Hassan Jubouri"
- Minister of Security: "Professor Shaykh Abdul Razzaq al-Shammari"
- Minister of Health: "Dr. Shaykh Abdullah Qaisi"
- Minister of Information: "Shaykh Professor Ahmad al-Tai"
- Minister of Petroleum: "Shaykh Osama Laheebi"
- Minister of Finance: "Shaykh Professor Yunis al-Hamdani"
First Draft of a Framework for Building a Smart Grid Unveiled
Commerce Secretary Gary Locke has unveiled the first draft of a Smart Grid framework that lays the foundation for a secure, interoperable, next-generation power distribution system.
The report, titled "Framework and Roadmap for Smart Grid Interoperability Standards, Release 1.0" and developed by the National Institute of Standards and Technology, identifies about 80 existing standards that apply to the development of the new grid infrastructure, and outlines steps to address key gaps remaining to be addressed.
“The Smart Grid will ultimately require hundreds of standards,” the framework says. “Some are more urgently needed than others,” because equipment such as smart meters that can monitor residential power use and provide data back to the utility, already are being deployed. The current report “is only the beginning of an ongoing process that is needed to create the full set of standards that will be needed to manage their evolution in response to new requirements and technologies.”
The framework is the product of the first phase of an aggressive three-phase program by NIST to establish Smart Grid standards by the end of the year.
[...]
NIST’s three-phase approach to standards development is:
- Develop a consensus among utilities, equipment suppliers, consumers, standards developers and other stakeholders on needed standards; and producing a Smart Grid architecture, an initial set of standards to support implementation and plans for developing remaining standards by early fall;
- Finalization of today’s report after a 30 day comment period will complete this phase;
- Launch formal partnerships to develop the remaining needed standards; and
- Develop a program for testing and certification to ensure that Smart Grid equipment and systems comply with standards;
Thursday, September 24, 2009
Contractor Pleads Guilty to SCADA Tampering
A former IT consultant for an oil and gas exploration company has pleaded guilty to tampering with the company's computer systems after he was turned down for a permanent position with the company.
Mario Azar, 28, pleaded guilty on Sept. 14 to one count of damaging computer systems and faces a maximum of 10 years in prison. News of his plea was announced Wednesday by the U.S. Federal Bureau of Investigation.
According to court records, Azar accessed Supervisory Control and Data Acquisition (SCADA) computer systems belonging to Pacific Energy Resources of Long Beach, California, and caused the company to lose control of its computer systems around May or June of 2008.
Only a handful of SCADA computer intrusions have been reported, but because the systems are used to control large-scale industrial systems in manufacturing plants, public utilities and the chemical industry, security experts worry that tampering with them could lead to a large-scale power outage or environmental disaster.
Azar played a role in setting up a system that helped the company communicate between its headquarters and oil platforms, and which was also used to detect leaks on the company's oil platforms. He had several user accounts on company systems, authorities said.
His actions caused thousands of dollars in damage, authorities said, but did not cause oil leaks or
otherwise harm the environment.
He is due to be sentenced on Dec. 7 in United States District Court for the District of Los Angeles.
United Nations Adopt US-Drafted Resolution on Nuclear Weapons
The United Nations Security Council has unanimously approved a resolution to increase efforts to eventually rid the world of nuclear weapons.
U.S. President Barack Obama presided over a special session of the Security Council Thursday.
The leaders of all 15 Security Council member nations voted for the U.S.-drafted resolution.
The plan sets a framework for dealing with nuclear arms reduction, disarmament and the threat of nuclear terrorism.
It calls for states to set up specific goals on nuclear arms reduction and disarmament, bolsters the Nuclear Non-proliferation Treaty, and calls for greater security of nuclear weapons materials to prevent them from falling into the hands of terrorists.
The resolution singles out Iran and North Korea as "major challenges" to the Security Council's efforts on non-proliferation.
Mr. Obama is the first U.S. president to chair a summit-level meeting at the council.
Also Thursday, U.S. Secretary of State Hillary Clinton will give the opening speech of a two-day conference on the Comprehensive Test Ban Treaty. This is the first time a U.S. delegation has participated in the biennial conference since 1999.
Clinton's husband, former U.S. President Bill Clinton, signed the treaty in 1996, but the U.S. Senate rejected it three years later.
US Charges Najibullah Zazi with Bomb Plot
An Afghan-born man detained in the United States as part of a terror investigation has been charged with conspiring to detonate bombs in the U.S.
The indictment unveiled Thursday in New York alleges Najibullah Zazi spent more than a year plotting the attack with others.
The government says Zazi "received detailed bomb-making instructions in Pakistan, purchased components of improvised explosive devices and traveled to New York City on September 10, 2009" to move forward with his plans.
Zazi was detained in the midwestern U.S. state of Colorado Saturday along with his father, Mohammed Wali Zazi, on charges of lying to counterterrorism investigators. A third Afghan man, Ahmad Wais Afzali, was detained in New York City the same day on the same charges.
All three men are legal permanent residents or naturalized citizens of the United States.
The U.S. Department of Justice says the government wants Zazi to be transferred to New York to face this new charge.
Zazi has denied any links to terrorism.
The 24-year-old was born in Afghanistan and moved to Pakistan as a boy before relocating with his family to the U.S. about 10 years ago.
------------------------------
Check out this LATimes article for more details....
"Zazi remained committed to detonating an explosive device up until the date of his arrest, as exemplified by among other things, traveling overseas to receive bomb-making instructions, conducting extensive research on the internet regarding components of explosive devices, purchasing -- on multiple occasions -- the components necessary to produce TATP [Triacetone Triperoxide] and other explosive devices, and traveling to New York City on September 10, 2009 in furtherance of the criminal plan," a Justice Department detention memo states.
Wednesday, September 23, 2009
Metasploit Unleashed - Mastering the Framework
This free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework.
This is the free online version of the course. If you enjoy it and find it useful, we ask that you make a donation to the HFC (Hackers For Charity), $4.00 will feed a child for a month, so any contribution is welcome. We hope you enjoy this course as much as we enjoyed making it.
The "full" version of this course includes a PDF guide (it has the same material as the wiki) and a set of flash videos which walk you though the modules. You may purchase these materials from the Offensive Security Training page. All proceeds from this course go to HFC.
DoD Preparing To Lift USB Ban
The ban on USB drives that began late last year in the U.S. Defense Department will be lifted, but with a caveat: Only DoD-approved or procured devices will be allowed.
Robert Cary, CIO for the U.S. Navy, in a recent blog post said Defense officials are hashing out the final policy for allowing USBs back into the department. The Commander of the U.S. Strategic Command in November suspended the use of all USB flash and removable storage devices and camera flash cards from all DoD networks after a worm infection spread across some DoD networks.
"In the future, we expect that a government-owned and procured USB flash media that is uniquely and electronically identifiable for use in support of mission-essential functions on DoD networks will be permitted for use by authorized individuals," Cary said in his blog. "The bottom line is, the days of using personally owned flash media or using flash media collected at conferences or trade shows are long gone. What we connect to our home PCs is very different from what is and will be allowed to occur on DON [Department of Navy] networks."
The Navy is also reducing its reliance on USB flash media, Cary said. "...we are working on moving our access to information to the use of collaborative workspaces, file shares and portals within our protected enclaves. This will reduce our reliance on USB flash media, mitigate unnecessary risk to the GIG, and protect our data and information by keeping it stored within our network boundaries," he said.
Meanwhile, the DoD Removable Storage Media Tiger Team is coordinating a Defense USB policy that will be incorporated into USSTRATCOM guidelines, and the Navy and Marine Corps are working on their own organization-specific operational orders for when the ban is lifted.
Among other things, the Navy is upgrading its antivirus and malware detection, alerting, and remediation, Cary said, and improving controls that deny unauthorized USBs from the network.
Cary noted that although the DoD previously had policies in place for using USBs safely, "they were not being followed."
"Unfortunately, it was our bad IT hygiene that resulted in the ban of this all too flexible use of storage media," he said.
Suppressed Texas Instruments Cryptographic Signing Keys
The file here presents the Operating System signing keys for different Texas Instruments calculators. The key for the TI-83 calculator was first published by someone at the unitedti.org forum. He or she needed several months to crack it. The other keys were found after a few weeks by the unitedti.org community through a distributed computing project. The keys make it possible for people to create new OS software to be used on Texas Instruments calculators.
Texas Instruments contacted several people with DMCA notices to take down the keys from their websites. Some of the websites which got a DMCA notice are: unitedti.org, brandonw.net and reddit.com. One of these DCMA notices can be found here: http://brandonw.net/calcstuff/DMCA_notice.txt
--------------------------
http://wikileaks.org/wiki/Suppressed_Texas_Instruments_cryptographic_signing_keys,_28_Aug_2009
--------------------------
More TI signing keys are on Wikileaks as well...
http://wikileaks.org/wiki/Talk:Suppressed_Texas_Instruments_cryptographic_signing_keys,_28_Aug_2009
NRC Report: Technology, Policy, Law, and Ethics Regarding U.S. Acquisition and Use of Cyberattack Capabilities
----------------------------------
Report looks to have been put together by the Committee on Offensive Information Warfare & the Computer Science and Telecommunications Board (CSTB)
http://books.nap.edu/openbook.php?record_id=12651&page=R1
Somalia's Al-Shabab Releases Video Vowing Allegiance to Osama Bin Laden
An Islamic insurgent group that controls much of lawless Somalia has released a video showing its members vowing allegiance to Osama bin Laden, training in dusty camps and slamming Somalia's U.S.-backed president as a traitor.
The tape was released late Sunday by al-Shabab, an insurgent group that last week hit the African Union peacekeeping base with suicide car bombs, killing 21 people in the deadliest single attack on peacekeepers since they arrived in 2007.
Al-Shabab announced the Thursday attack at Mogadishu's airport was in retaliation for a U.S. commando raid on Sept. 14 that killed al-Qaida operative Saleh Ali Saleh Nabhan in southern Somalia.
The United States has become increasingly concerned that al-Qaida insurgents are moving into anarchic Somalia, where they can mobilize recruits without interference.
The video showed the Shabab militia in training, leaping over piles of sandbags, crawling on the ground and shooting at targets. White-skinned bearded trainers could be seen moving among the Somalis. The video also showed crowds chanting: "At your service Osama!"
Sheik Hassan Ya'qub, a spokesman for al-Shabab, said the video is "aimed at showing how the youth are well-trained and ready to the defend their holy land." Shabab means "youth" in Arabic.
Bin Laden has declared his support for Somali insurgents before. The new video shows the mutual affection is strong as ever — a growing concern for U.S. and other governments. Al-Qaida bombed the U.S. embassies in Kenya and Tanzania in 1998, killing more than 200 people, and one of the alleged plotters is believed to be hiding out in Somalia. Stronger ties between al-Qaida and al-Shabab could pose greater threats to Western interests in the region.
The video features periodic commentary from a voice purported to be bin Laden's, criticizing the administration of Somali President Sheik Sharif Sheik Ahmed as un-Islamic for its ties to America. Sharif met last month with U.S. Secretary of State Hillary Rodham Clinton, who pledged to expand American support for Somalia's government.
The comments from the al-Qaida leader echo comments of support he made in March. It was not immediately clear if they were from the same recording.
---------------------------------
The segment of video that is dedicated to Osama bin Laden and Mullah Omar can be seen over @ The Long War Journal. The tape appears to be Shabaab's signal that it has joined Al Qaeda.
A Stick Figure Guide to the Advanced Encryption Standard (AES)

Check out the AES's full story....
http://www.moserware.com/2009/09/stick-figure-guide-to-advanced.html
Addendum to SRI's Conficker C Analysis Published
Via SANS ISC -
SRI recently updated their Conficker C analysis with another addendum, this one covers Conficker C's P2P protocol and implementation. Here's the abstract of the new addendum:
This report presents a reverse engineering of the obfuscated binary code image of the Conficker C peer-to-peer (P2P) service, captured on 5 March 2009 (UTC). The P2P service implements the functions necessary to bootstrap an infected host into the Conficker P2P network through scan-based peer discovery, and allows peers to share and spawn new binary logic directly into the currently running Conficker C process. Conficker's P2P logic and implementation are dissected and presented in source code form. The report documents its thread architecture, presents the P2P message structure and exchange protocol, and describes the major functional elements of this module.
As always, this is a GREAT report from the Malware Threat Center at SRI.
Apple iTunes ".pls" Processing Buffer Overflow Vulnerability
DESCRIPTION:
A vulnerability has been reported in Apple iTunes, which can be exploited by malicious people to compromise a user's system.
The vulnerability is caused due to a boundary error in the processing of ".pls" files and can be exploited to cause a buffer overflow.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in version 9 for Windows and Mac.
SOLUTION:
Update to version 9.0.1.
PROVIDED AND/OR DISCOVERED BY:
The vendor credits Steven Woolley at Oogli LLC.
Original Advisory:
http://support.apple.com/kb/HT3884
CVE reference:
CVE-2009-2817
Tuesday, September 22, 2009
New ICSA Labs Service Certifies Security Of Printers, Copiers & ATMs
If a toaster can be hacked, then there ought to be a way for toaster manufacturers -- and the enterprises that use them -- to find out whether their toasters are safe to use.
This simple idea is behind a pair of security certification and assessment services launched today by ICSA Labs, an independent division of Verizon Business. The new services are designed to test the security of nonmainstream networked devices, such as printers, copiers, faxes, security cameras, and point-of-sale systems.
ICSA Labs is offering a vendor certification program and comprehensive enterprise assessment service that are designed to test the security of devices that connect directly to a network, but are not part of the network infrastructure itself. This list includes ATM machines, digital signs, proximity readers, and facility management systems for power, lighting, and HVAC systems, ICSA says.
Numerous proofs-of-concept have been demonstrated on nonmainstream devices at various conferences during the years. This year's Black Hat conference, for example, featured a demonstration of hacks on networked parking meters, while previous years' conferences included hacks of toasters, soda machines, and even medical implants.
"There is a growing base of networked devices out there, everything from those multifunction devices that do printing, faxing, and scanning to specialized devices that are used in specific industries," says George Japak, managing director at ICSA Labs. "Any one of these could potentially be a threat to your network, or a vulnerability in one of these devices could cause you to fall out of compliance with standards like PCI or HIPAA."
ICSA Labs is offering Network Attached Peripheral Security (NAPS) certification, which helps manufacturers identify and remediate existing and potential vulnerabilities in their networked devices. The second new offering, NAPS assessment, helps enterprises determine through a one-time evaluation whether network-attached devices are installed securely and protected from exploitation.
A new white paper from ICSA Labs, Living on the Edge" (PDF), examines network-attached peripherals and the security risks they pose.
"This will be an even greater issue down the road, as companies deal not only with older networked devices, such as printers and copiers, but with next-generation technology that takes advantage of wireless and remote networks," Japak says.
Al-Qaeda Threatens German Post Election Attack
A senior al Qaeda leader has threatened to attack Germany just days before the nation will go to the polls to choose a new Chancellor.
Bekkay Harrach, alias Al Hafidh Abu Talha al Almani, resurfaced Friday in a chilling new video produced by al Qaeda's al Fajr Media Center and distributed across the major jihadi Web forums.
Dressed in an ill-fitting black blazer, blue tie, and shoulder-length greased hair - looking more like a teenager dressed for his first job interview - he slammed Germany for its military presence in Afghanistan and warned that if Chancellor Angela Merkel is reelected on Sept. 27, Germany will be directly attacked.
His previous warning to Germany, on Jan. 17, 2009, coincided with a massive car bomb attack on the heavily guarded German embassy in Kabul that was orchestrated by the notorious Haqqani Network. Four Afghan civilians and an American soldier died in the attack.
"The vote on September 27 is more than a choice between a man and a woman," he warned in the new video, which was acquired by the Long War Journal.
"As an old aphorism says, 'Security is foremost.'
In the democratic system, only the people can return the soldiers to their homeland. If the people insist on continuing the war (in Afghanistan), they sentence themselves to retaliation and clearly show the world that civilians in the democratic system are not innocent people."
He addressed Germany's Muslim community and said
"(S)tay clear of all that is not necessary in the two weeks of the elections if the German people did not decide to withdraw its soldiers from Afghanistan.
Keep your children near you at this time. Ask God to bless you and your children."
"The city of Kiel," he continued inexplicably, "will remain a safe city no matter how long the conflict in Germany. This is a promise from me."
--------------------------
More on this story and Bekkay Harrach can be found over at The Long War Journal...
Harrach is a 32-year-old Moroccan whose family emigrated to Germany when he was two years old; he became a naturalized German citizen in 1997.Harrach has become a rising star in al Qaeda's new generation and is reportedly on its shura council for global strikes. Reports suggest that his travels are tracked by intelligence agencies, however, according to Spiegel Online, he is directly protected by Siraj Haqqani and his deadly network.
Monday, September 21, 2009
In Memory of DJ Roc Raida
X-Ecutioner member and Busta Rhymes' personal deejay, Anthony "DJ Roc Raida" Williams, has passed on.....Williams passed away on Saturday September 19, 2009, due to complications from a mixed-martial-arts accident, according to a statement released by his family. He had been released to an inpatient physical therapy facility at the time of his death.
Busta announced the unexpected news via his Twitter account Saturday afternoon.
"I am sorry 2 say that on this day at 2:05 Sept 19th we lost another incredible life...Dj Roc Raida died 2day my personal Dj is gone... I just wanna thank everyone 4 ur love and support and ur prayers...We will never let ur name die Roc...We love u and will 4ever miss u...RIP." (Busta Rhymes' Twitter)-------------------
RIP Roc Raida
Update on the SMB Vulnerability Situation
We’d like to give everyone an update on the situation surrounding the new Microsoft Server Message Block Version 2 (SMBv2) vulnerability affecting Windows Vista and Windows Server 2008.
[...]
Easy way to disable SMBv2
Until the security update is released, the best way to protect systems from this vulnerability is to disable support for version 2 of the SMB protocol. The security advisory was updated yesterday with a link to the Microsoft Fix It package that disables SMBv2 and then stops and starts the Server service. (This initial Fix It might prompt you to also restart the Browser service.)[...]
Disabling SMBv2 may slow down SMB connections between Windows Vista and Windows Server 2008 machines.
First exploit for code execution released to small number of companies
We are not aware of any in-the-wild exploits or any real-world attacks.
However, we are aware of exploit code developed by Immunity Inc. and released to customers who subscribe to the CANVAS Early Updates program. We have analyzed the code ourselves and can confirm that it works reliably against 32-bit Windows Vista and Windows Server 2008 systems. The exploit gains complete control of the targeted system and can be launched by an unauthenticated user.
The exploit can be detected by intrusion detection systems (IDS) and firewalls that have signatures for the vulnerability being targeted (CVE-2009-3103).
This exploit code from Immunity is only available to a small group of companies and organizations who will use it to determine the risk to their own networks and systems, or those of their customers. (We are aware that other groups are actively working on exploit code which is likely to be made public when it is completed).
Sunday, September 20, 2009
Convergence: The Challenge of Aviation Security
[...]
The airline security paradigm changed on 9/11. In spite of the recent statement by al Qaeda leader Mustafa Abu al-Yazid that al Qaeda retains the ability to conduct 9/11-style attacks, his boast simply does not ring true. After the 9/11 attacks there is no way a captain and crew (or a group of passengers for that matter) are going to relinquish control of an aircraft to hijackers armed with box cutters — or even a handgun or IED. A commercial airliner will never again be commandeered from the cockpit and flown into a building — especially in the United States.
Because of the shift in mindset and improvements in airline security, the militants have been forced to alter their operational framework. In effect they have returned to the pre-9/11 operational concept of taking down an aircraft with an IED rather than utilizing an aircraft as human-guided missile. This return was first demonstrated by the December 2001 attempt by Richard Reid to destroy American Airlines Flight 63 over the Atlantic with a shoe bomb and later by the thwarted 2006 liquid-explosives plot. The operational concept in place now is clearly to destroy rather than commandeer. Both the Reid plot and the 2006 liquid-bomb plot show links back to the operational philosophy evidenced by Operation Bojinka in the mid-1990s, which was a plot to destroy multiple aircraft in flight over the Pacific Ocean.
The return to Bojinka principles is significant because it represents not only an IED attack against an aircraft but also a specific method of attack: a camouflaged, modular IED that the bomber smuggles onto an aircraft in pieces and then assembles once he or she is aboard and well past security. The original Bojinka plot used baby dolls to smuggle the main explosive charge of nitrocellulose aboard the aircraft. Once on the plane, the main charge was primed with an improvised detonator that was concealed inside a carry-on bag and then hooked into a power source and a timer (which was disguised as a wrist watch). The baby-doll device was successfully smuggled past security in a test run in December 1994 and was detonated aboard Philippine Air Flight 434.
The main charge in the baby-doll devices, however, proved insufficient to bring down the aircraft, so the plan was amended to add a supplemental charge of liquid triacetone triperoxide (or TATP, aptly referred to as “Mother of Satan”), which was to be concealed in a bottle of contact lens solution. The plot unraveled when the bombmaker, Abdel Basit (who is frequently referred to by one of his alias names, Ramzi Yousef) accidentally started his apartment on fire while brewing the TATP.
[...]The biggest difference between Bojinka and more recent plots is that the Bojinka operatives were to smuggle the components aboard the aircraft, assemble the IEDs inside the lavatory and then leave the completed devices hidden aboard multi-leg flights while the operatives got off the aircraft at an intermediate stop. The more recent iterations of the jihadist airplane-attack concept, including Richard Reid’s attempted shoe bombing and the 2006 liquid-bomb plot, planned to use suicide bombers to detonate the devices midflight. The successful August 2004 twin aircraft bombings in Russia by Chechen militants also utilized suicide bombers.
The shift to suicide operatives is not only a reaction to increased security but also the result of an evolution in ideology — suicide bombings have become more widely embraced by jihadist militants than they were in the early 1990s. As a result, the jihadist use of suicide bombers has increased dramatically in recent years. The success and glorification of suicide operatives, such as the 9/11 attackers, has been an important factor in this ideological shift.
One of the most recent suicide attacks was the Aug. 28 attempt by al Qaeda in the Arabian Peninsula (AQAP) to assassinate Saudi Prince Mohammed bin Nayef. In that attack, a suicide operative smuggled an assembled IED containing approximately one pound of high explosives from Yemen to Saudi Arabia concealed in his rectum. While in a meeting with Mohammed, the bomber placed a telephone call and the device hidden inside him detonated.
--------------------------
The section above is only a small part of the article...worth a full read, follow the link above.
Tools of the Trade - NOVA Edition
Northern Virginia (colloquially referred to as "NOVA") consists of several counties and independent cities in the U.S. state of Virginia in a widespread region generally radiating southerly and westward from Washington, D.C. Notable features of the region include the Pentagon and the Central Intelligence Agency, and the many companies which serve them and the federal government. The area's attractions include various monuments and Colonial and Civil War-era sites such as Mount Vernon and Arlington National Cemetery.
Northern Virginia's data centers currently carry more than 50% of the nation's Internet traffic, and by 2012 Dominion Power expects that 10% of all electricity it sends to Northern Virginia will be used by the region's data centers alone.
----------------------------------
On Sept 16th, Adam Laurie, known as Major Malfunction in the hacker community, released RFIDIOt 0.1z. RFIDIOt is a python library for exploring RFID device. It currently drives a couple of RFID readers made by ACG, called the HF Dual ISO and the LFX. Includes sample programs to read/write tags and the beginnings of library routines to handle the data structures of specific tags like MIFARE(r). Check his announcement e-mail for all the change details.
On Sept 16th, Snort 2.8.5 was released. Here are some highlights from the release notes:
- Ability to specify multiple configurations (snort.conf and everything it includes), bound either by Vlan ID or IP Address. This allows you to run one instance of Snort with multiple snort.conf files, rather than having separate processes.
- Continued inspection of traffic while reloading a configuration.
Add --enable-reload option to your configure script prior to building. - Rate Based Attack Prevention for Connection Attempts, Concurrent Connections, and improved rule/event filtering.
- SSH preprocessor is no longer experimental
- Multiple performance improvements
On Sept 15th, Wireshark 1.2.2 was released. This release fixes the following vulnerabilities:
- The GSM A RR dissector could crash. (Bug 3893) - Versions affected: 1.2.0 to 1.2.1
- The OpcUa dissector could use excessive CPU and memory. (Bug 3986) - Versions affected: 0.99.6 to 1.0.8, 1.2.0 to 1.2.1
- The TLS dissector could crash on some platforms. (Bug 4008) - Versions affected: 1.2.0 to 1.2.1
On Sept 11th, Harald Scan 0.31 was released. Harald Scan is a Bluetooth discovery scanner written in Python. It determines Major and Minor device classes according to the Bluetooth SIG specification and attempts to resolve a device's MAC address to the largest known vendor/MAC address list. This Linux-only release adds a -u option to update MACLIST to the most recent version, adds a proper GPLv3 disclaimer and license and fixes other minor bugs (mostly not noticed by users).
On Sept 10th, PDFResurrect 0.8 was released. PDFResurrect is a tool aimed at analyzing PDF documents. This tool attempts to extract all previous versions while also producing a summary of changes between versions. This tool can also "scrub" or write data over the original instances of PDF objects that have been modified or deleted, in an effort to disguise information from previous versions that might not be intended for anyone else to read. This release is mainly just a bug-fix.
On Sept 9th, VirtualBox 3.0.6 was released. VirtualBox is a general-purpose full virtualizer for x86 hardware. Targeted at server, desktop and embedded use, it is now the only professional-quality virtualization solution that is also Open Source Software. Check the changelog for all the details.
On Sept 8th, CDBurnerXP 4.2.5.1541 was released. CDBurnerXP is a free application to burn CDs and DVDs, including Blu-Ray and HD-DVDs. It also includes the feature to burn and create ISOs, as well as a multilanguage interface. This version added a verification method for the file count of the disc to detect broken file system structures.
On Sept 8th, Aircrack-ng 1.0 was released. Aircrack-ng is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the all-new PTW attack, thus making the attack much faster compared to other WEP cracking tools. Check out the official Aircrack-ng blog for changelog highlights.
On Sept 4th, GnuPG 2.0.13 & 1.4.10 were released. The GNU Privacy Guard (GnuPG) is GNU's tool for secure communication and data storage. It can be used to encrypt data, create digital signatures, help authenticating using Secure Shell and to provide a framework for public key cryptography. Check the announce notes for both 2.0.13 & 1.4.10 for all the change details.
On Sept 3rd, CCleaner v2.23.999 was released. CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. This version has improved Opera 10 support. Check the version history for all the change details.
On Sept 3rd, Foxit Reader 3.1.1.0901 was released. Foxit Reader is a free PDF document viewer, with incredible small size, breezing-fast launch speed and rich feature set. Its core function is compatible with PDF Standard 1.7. This released fixes at least two issues:
- The reported issue of Foxit Reader 3.1.0.0824 crashing when users are viewing certain PDF files has been updated and is no longer a problem.
- Fixed an issue where Foxit Reader may not be launched in the system without installing Microsoft Visual C++ 2005 Redistributable.
On Sept 1st, OpenOffice 3.1.1 was released. OpenOffice.org 3 is the leading open-source office software suite for word processing, spreadsheets, presentations, graphics, databases and more. This version is mostly just a bug-fix and did not include a host of new features....but it does address two highly critical Word Document Table Parsing Vulnerabilities. Check the release notes for all the change details.
Saturday, September 19, 2009
Photo of the Day - First Detailed Photos of Atoms

http://insidescience.org/research/first_detailed_photos_of_atoms
For the first time, physicists have photographed the structure of an atom down to its electrons.
The pictures, soon to be published in the journal Physical Review B, show the detailed images of a single carbon atom's electron cloud, taken by Ukrainian researchers at the Kharkov Institute for Physics and Technology in Kharkov, Ukraine.
[...]
To create these images, the researchers used a field-emission electron microscope, or FEEM. They placed a rigid chain of carbon atoms, just tens of atoms long, in a vacuum chamber and streamed 425 volts through the sample. The atom at the tip of the chain emitted electrons onto a surrounding phosphor screen, rendering an image of the electron cloud around the nucleus.
Indonesian Police: DNA Confirms Noordin Top Dead
Indonesian police say they have DNA evidence identifying the man they killed this week as Noordin Top, the nation's most-wanted terror suspect.
"We have matched this Malaysian man's DNA against his family and it's 100 percent match," Nanan Soekarna, a national police representative said Saturday.
The police will coordinate with Malaysian authorities to return the body to his country.
Noordin was killed in a raid in Central Java early Thursday morning, authorities said.
Friday, September 18, 2009
Pakistani Carder Forum Drop Offline After 'Whitehat' Hack Attack
Via The Register UK -
A Pakistan-based carder site has dropped off the net, after white hat hackers broke into the forum and posted details of the hack on a full disclosure mailing list.
Pakbugs.com provided a forum for ne'er do wells to discuss hacking tactics and trade malware, bank logins details and stolen credit card credentials. However this activity was interrupted after login details for the forum and email addresses were posted online following a break-in.
A previously unknown group called War Against Cyber Crime claimed credit for the hack. The group expressed the hope that law enforcement agents will begin an investigation against individuals named on the leaked list.
Meanwhile, the Pakbugs.com site remains unavailable. Net security firm F-Secure, which was among the first to record the takedown hack, said it reckons the forum is unlikely to reappear.
More details of the hack, including screenshots, can be found in a blog entry by F-Secure here.
STRATFOR Podcast: An Al-Qaeda Assessment
Authorities believe that Noordin Mohammed Top, Indonesia’s most-wanted militant, is dead — a loss that would come as a significant blow to the global al Qaeda network. In the second part of an interview with Marla Dial, STRATFOR tactical analyst Scott Stewart explains why al Qaeda still poses a threat to aircraft and certain parts of the world.
--------------------------
Scott Stewart also talks about the recent AQIM body cavity / cellphone attack against Saudi Prince Mohammed bin Nayef.
IETF Forges Botnet Clean-up Standard for ISPs
The IETF is developing a standard for how ISPs should go about cleaning up subscriber botnet infections.
A draft standard from the net standards body covers techniques for identifying compromised machines, how to notify affected customers and what advice to give them on the best way to clean-up infections - a sometimes tricky process. The IEFT's Recommendations for the Remediation of Bots in ISP Networks can be found here.
The document covers such thorny subjects as best practices for botnet detection and how to direct users towards an infection clean-up portal containing disinfection tools and information. As a technical standard, the proposals omit consideration of how clean-up operations might be financed. Possible punishments for users who leave their machines infected despite clean-up advice is also outside the scope of the standards. The IETF is inviting feedback on its proposals.
The initiative ploughs much the same ground as an independent proposal by Australia's Internet Industry Association (IIA), also in the draft stage, on how to purge spam-relaying zombie clients from ISP networks Down Under.
Thursday, September 17, 2009
Indonesian Police Kill Alleged Terror Mastermind - Noordin Muhammad Top
Indonesian commandos raided a house in central Java, killing Noordin Muhammad Top, the fugitive Islamist leader and the suspected mastermind of bombings in Bali and Jakarta, security officials said Thursday.
The National Police commander, Gen. Bambang Hendarso Danuri, confirmed at a news conference that Mr. Noordin had been killed. He was identified using fingerprint tests, the commander said.
Mr. Noordin, 41, a Malaysian-born extremist, was once a senior leader and fund-raiser with the regional terrorist group Jemaah Islamiyah. In a video in 2005 he claimed to be Al Qaeda’s representative in Southeast Asia, although he later broke from Jemaah Islamiyah to form his own group, Tanzim Qaidat al-Jihad, or Organization for the Base of Jihad.
A spokesman for the national police, Maj. Gen. Nanan Soekarna, said weapons, explosives and hand grenades were seized after the six-hour siege in which three other suspected terrorist were killed and three captured. He also said one trooper had been wounded.
The raid, which began late Wednesday night, was part of a regional dragnet for Mr. Noordin and other militants whom law enforcement agencies blame for bombings in Bali in 2005 that killed more than 20 people. He was also implicated in the coordinated suicide attacks on two luxury American hotels in Jakarta. Those bombings in July killed seven people, six of them foreigners, as well as the two bombers. More than 50 people were wounded.
Videotape from MetroTV early Thursday showed commandos from Densus 88, or Special Detachment 88, the counterterrorism unit of the national police, gathered outside the house after the raid. Later, the station broadcast images of two black coroner’s vans pulling away from the house, which was outside the city of Solo, on the main island of Java.
Police and security forces had been searching for Mr. Noordin for nearly 10 years.
The Indonesian police thought they had trapped him in a farmhouse in central Java last month. After a 16-hour firefight, however, they recovered only one body. It remains unclear whether Mr. Noordin had been in the besieged house, or whether he had managed to escape the firefight, as he had done before when apparently cornered. Forensic tests later confirmed that the dead man was named Ibrohim, an associate of Mr. Noordin who had worked as a florist at both Jakarta hotels. They said Mr. Ibrohim had planned and directed the hotel bombings under the tutelage of Mr. Noordin.
------------------------------
For some background on the last standoff....
July 20th - Indonesia Arrests Two JI Members
July 21st - Indonesian TV Identifies Another Jakarta Hotel Bomber
July 23rd - Indonesian Unaware Husband was Noordin Mohammed Top - Jemaah Islamiya's Bomb Maker & Financier
August 8th - Noordin Mohammed Top Commits Suicide During Standoff
Wednesday, September 16, 2009
Two Al-Qaeda Leaders Reported Killed in North Waziristan Strike
Two senior al Qaeda commanders are thought to have been killed in the most recent airstrike in Pakistan's tribal areas.
Ilyas Kashmiri and Nazimuddin Khilalof are said to have been killed during the Sept. 14 airstrike in the village of Turikhel near the town of Mir Ali in Taliban-controlled North Waziristan, according to a report in Geo News. The report has not been confirmed, and US intelligence officials contacted by The Long War Journal would not comment on the status of Kashmiri and Nazimuddin.
Ilyas Kashmiri is considered by US intelligence to be one of al Qaeda's most dangerous commanders. He is the operational chief of the Harkat-ul Jihad Islami (HuJI), an al Qaeda-linked terror group that operates in Pakistan, Kashmir, India, Afghanistan, and Bangladesh. Kashmiri was recently listed as the fourth most wanted terrorist by Pakistan's Interior Ministry.
Kashmiri is thought to have played a major role in the multi-pronged suicide attack against government and security installations in the eastern Afghan province of Khost in May, the military intelligence official said.
Last year, Kashmiri reportedly drafted a plan to assassinate General Ashfaq Pervez Kiyani, Pakistan's top military officer, but the plan was canceled by al Qaeda's senior leadership, according to a report in the Asia Times.
New Apple iPhone Jailbreaking Tool Hits the Street
The iPhone-Dev team has released a new tool to enable users to jailbreak and unlock Apple iPhone OS 3.1.
With Pwnage Tool 3.1 for Mac OS X, users can jailbreak both iPhone 3G and the first editions of the iPhone and iPod Touch. The tool, however, does not support iPhone 3GS or the second or third generation of the iPod Touch.
Jailbreaking allows iPhone and iPod Touch users to run applications that are not available through Apple's App Store. The unapproved applications can then be installed through programs such as Cydia and Icy.
Intelligence Analyst Charged With Hacking Top Secret, Anti-Terror Program
An analyst at a Defense Department spy satellite agency faces federal hacking charges after allegedly poking around in a top-secret system used in a classified terrorism investigation involving the FBI and the U.S. Army.
Brian Keith Montgomery worked on a covert program for the National Geospatial-Intelligence Agency — the spy agency in charge of satellite and aerial image collection. On April 9, he was carrying out his duties when he saw a message that “provided significant detail about a classified operation” that was unrelated to his job, according to an affidavit filed by a Pentagon investigator.
The operation is not detailed in the affidavit (.pdf), but there is a reference to the 902nd Military Intelligence Battalion, an Army counterintelligence unit based at Fort Meade in Maryland, with a presence at more than 50 other locations inside and outside the United States. The 902nd faced controversy in 2005, when NBC News published documents showing the the unit had been spying on American anti-war protesters. Under the guise of fighting terrorism, the group had filed intelligence reports on legal demonstrations, including a weekly protest at an Atlanta recruiting station, and a protest at the University of California at Santa Cruz.
[...]
Curiously, just by accessing the system, Montgomery endangered the terrorism investigation, and “caused harm to the U.S. Army and the FBI,” according to the affidavit by Dexter Wells, an agent with the Defense Criminal Investigative Service.
Montgomery’s alleged motives are unclear, but he told DCIS that he was very interested in the information in the program, Wells wrote. Montgomery also told investigators that he thought he was allowed to log in to the system, and hadn’t noticed a warning saying that only officials participating in the operation were allowed to use the password.
“It was not until I was called on the carpet, that I went back and read the warning notice in the message traffic,” Montgomery allegedly told DCIS.
The nature of the system at issue is not clear, but it was used from all around the United States as part of the terrorism investigation, and was being monitored by the FBI at the time of his alleged access. That’s evidently what led to the probe of Montgomery, who worked at a National Geospatial-Intelligence Agency facility at Fort Belvoir in northern Virginia.
There are no allegations that Montgomery did anything with the information he obtained.
He’s charged with a single count of gaining unauthorized access to a protected computer or exceeding authorized access, and obtaining classified information. Prosecutors in the Eastern District of Virginia, where Montgomery was charged Friday, did not return a phone call.
The Other iPhone Lie: VPN Policy Support
It turns out that Apple's iPhone 3.1 OS fix of a serious security issue -- falsely reporting to Exchange servers that pre-3G S iPhones and iPod Touches had on-device encryption -- wasn't the first such policy falsehood that Apple has quietly fixed in an OS upgrade. It fixed a similar lie in its June iPhone OS 3.0 update. Before that update, the iPhone falsely reported its adherence to VPN policies, specifically those that confirm the device is not saving the VPN password (so users are forced to enter it manually). Until the iPhone 3.0 OS update, users could save VPN passwords on their Apple devices, yet the iPhone OS would report to the VPN server that the passwords were not being saved.
The fact of the iPhones' false reporting of their adherence to Exchange and VPN policies has caused some organizations to revoke or suspend plans for iPhone support, several readers who did not want their names or agencies identified told InfoWorld. One reader at a large government agency describes the IT leader there as "being bitten by the change," after taking a risk to support the popular devices. "I guess we will all have to start distrusting Apple," said another reader at a different agency.
Last week's iPhone OS 3.1 update began correctly reporting the on-device encryption and VPN password-saving status when queried by Exchange and VPN policy servers, which made thousands of iPhones noncompliant with those policies and thus blocked from their networks. (Only the new iPhone 3G S has on-device encryption.) Apple's document on the iPhone OS 3.1 update's security changes neglected to mention this fix, catching users and IT administrators off-guard. Worse, it revealed that Apple's iconic devices have been unknowingly violating such policies for more than a year.
"My guess is the original decision to emulate hardware encryption was made at a level where there wasn't much awareness of enterprise IT standards. After all, this is a foreign language for Apple," says Ezra Gottheil, an analyst at Technology Business Research. "However, once the company realized the problem, it made a spectacularly dumb choice. The change was necessary and inevitable, but Apple could have earned some points by coming clean at the earliest opportunity. Instead, it allowed itself to be seen in the worst possible light. This is the result of a colossal clash of cultures. Even when it is trying, Apple cannot force itself to think like an enterprise vendor."
Apple's advice to users on addressing the Exchange encryption policy issue is to either remove that policy requirement for iPhone users or replace users' devices with the iPhone 3G S.
IT organizations can also consider using third-party mobile management tools that enforce security and compliance policies; several now support the iPhone to varying degrees, including those from Good Technology, MobileIron, and Zenprise.
Russian S-300 Missiles Captured in Route to Iran
A cargo ship that vanished in the Channel was carrying arms to Iran and was being tracked by Mossad, the Israeli security service, according to sources in both Russia and Israel.
The Arctic Sea, officially carrying a cargo of timber worth £1.3m, disappeared en route from Finland to Algeria on July 24. It was recovered off west Africa on August 17 when eight alleged hijackers were arrested. The Kremlin has consistently denied that the vessel was carrying a secret cargo. It claims the ship was hijacked by criminals who demanded a £1m ransom.
The official version was challenged by sources in Tel Aviv and Moscow who claimed the ship had been loaded with S-300 missiles, Russia’s most advanced anti-aircraft weapon, while undergoing repairs in the Russian port of Kaliningrad.
Mossad, which closely monitors arms supplies to Iran, is said to have tipped off the Russian government that the shipment had been sold by former military officers linked to the underworld.
[...]
The Kremlin then ordered a naval rescue mission which involved destroyers and submarines. Any evidence that the Kremlin had let advanced weaponry fall into the hands of criminals or be sold to Iran would be highly embarrassing, so military officials believe a “cover story” was concocted.
- “The official version is ridiculous and was given to allow the Kremlin to save face,” said a Russian military source.
- “I’ve spoken to people close to the investigation and they’ve pretty much confirmed Mossad’s involvement.
- It’s laughable to believe all this fuss was over a load of timber. I’m not alone in believing that it was carrying weapons to Iran.”
The alleged hijackers, four Estonians, two Russians and two Latvians, will go on trial in Moscow. According to the Kremlin’s account, they boarded the Arctic Sea in the Baltic by claiming their inflatable craft was in trouble and then took over the ship at gunpoint.
Sources in Moscow suggested Mossad may have played a part in the alleged hijacking by setting up a criminal gang, who were unlikely to have known anything about a secret cargo. “The best way for the Israelis to block the cargo from reaching Iran would have been to create a lot of noise around the ship,” said a former army officer.
“Once the news of the hijack broke, the game was up for the arms dealers. The Russians had to act. That’s why I don’t rule out Mossad being behind the hijacking. It stopped the shipment and gave the Kremlin a way out so that it can now claim it mounted a brilliant rescue mission.”
According to Israeli military sources, Israel received intelligence that weapons bound for Iran were being loaded in Kaliningrad, a port notorious for gun runners. “A decision was then taken to inform the Kremlin,” said the source.
Had the S-300 missiles been delivered, Iran would have significantly strengthened its air defences. An Israeli air force source said that in the event of an attack on Iranian nuclear installations, such missiles could increase Israeli casualties by 50%.
Since the Arctic Sea was retaken, Russia has imposed a security blackout. The hijackers, the crew and two investigative teams were flown back to Moscow in three Il-76 air freight planes. For more than a week after being freed the crew were not allowed to talk to their families. The captain and three crew are still on board the ship, which has resumed its voyage to Algeria, but they have not been able to call home.
Last week Mikhail Voitenko, an outspoken piracy expert who disputed the Kremlin’s original version of events, fled Russia, claiming he had received threats from an official angered by his statements.
Admiral Tarmo Kouts, former commander of Estonia’s armed forces and the European Union’s rapporteur on piracy, has infuriated Moscow by saying the only plausible explanation of the mystery is that the ship was transporting weapons. A spokesman for the Finnish owners denied that missiles could have been secretly loaded onto the ship.
Sources who suspect Mossad’s involvement point to a visit to Moscow by Shimon Peres, the Israeli president, the day after the Arctic Sea was rescued. Peres held four hours of private talks with Dmitry Medvedev, the Russian president.
Although the Israeli foreign ministry would not be drawn on the Arctic Sea, it confirmed that the two leaders had discussed the sale of Russian weapons to countries hostile to Israel. According to Israeli officials, Peres received verbal guarantees from the Russians that they would not sell advanced weapons systems to Iran or Syria.
“Clearly the Israelis played a role in the whole Arctic Sea saga,” said a Russian military source. “Peres used the incident as a bargaining chip over the issue of arms sales to Arab states, while Israel allowed the Kremlin a way out with its claims to have successfully foiled a piracy incident.”
-----------------------------------------
According to the JPost.com -
If Russia goes through with the sale of its most advanced anti-aircraft missile system to Iran, Israel will use an electronic warfare device now under development to neutralize it and as a result present Russia as vulnerable to air infiltrations, a top defense official has told The Jerusalem Post.
The Russian system, called the S-300, is one of the most advanced multi-target anti-aircraft-missile systems in the world today and has a reported ability to track up to 100 targets simultaneously while engaging up to 12 at the same time. It has a range of about 200 kilometers and can hit targets at altitudes of 27,000 meters.
Al Qaeda Bomber Saleh Ali Saleh Nabhan Killed in Somalia
U.S. military officials say American special forces staged an attack in southern Somalia Monday and killed a Kenyan-born terrorist suspect.
Witnesses in the area said soldiers in at least two helicopters fired on a vehicle near the southern town of Barawe, killing at least two passengers and wounding two others.
Kenyan terror suspect Saleh Ali Saleh Nabhan talks to a relative on a mobile phone in the Nairobi High Court (2004 File)U.S. officials say the attack killed Saleh Ali Saleh Nabhan, whom authorities have linked to al-Qaida.
Nabhan was wanted by U.S. intelligence for questioning about attacks against a hotel and a plane in Mombasa, Kenya, in 2002.
- Authorities say special forces troops have taken his body into U.S. custody.
- Earlier reports said those involved in Monday's raid appeared to be French, but the French military has denied staging a raid in Somali territory.
- The Barawe area is controlled by the insurgent group al-Shabab, which is fighting to topple the Somali government.
The US has been after Saleh Ali Saleh Nabhan for quite some time....On March 2, 2008, a U.S. Navy vessel fired two missiles in an attack on an Al Qaeda training camp in southern Somalia. The attack reportedly targeted Nabhan.
Tethering, MMS Hack Broken By iPhone 3.1 Update
A popular tethering hack that allows your computer to access the internet via your iPhone’s cell connection is broken with the iPhone 3.1 update. The update also disables MMS messaging enabled by the same hack.
The hack is enabled by changing iPhone’s AT&T carrier file. It’s easily enabled by visiting sites like BenM.at using mobile Safari on the iPhone, and appears under the Network settings. The option is removed under 3.1.
AT&T will roll out multimedia messaging for the iPhone on Sept. 25, but hasn’t given a release date for tethering, saying only it will be available “in the future.”
---------------------------------
The following update is on help.benm.at....
/Update 10.09.09: I’m working on an update for Firmware 3.1. Stay tuned.
UK Post Code Database Mirrored on Pirate Bay
The file has literally tens of thousands of potential applications from ecology and political campaigns to medical statistics and courier services.
Selected parts of the database can be licensed, for a fee, from the Royal Mail, but the full database has been denied to the public domain, probably as an effort by the Royal Mail to undermine competition in the postal sector.
The database is structured as a plain text file, with each entry taking one line and with distinct fields seperated by commas. The very first line specifies the order of the 17 fields of information about each post code.
The original file is 241Mb. It has been compressed down to 20Mb with the free "bzip2" program, which is needed to uncompress the file to its original state.
http://thepiratebay.org/torrent/5090599/UK_government_database_of_all_1_841_177_post_codes
