Saturday, August 14, 2010

H1N1 Pandemic is Over

Via Virology.ws Blog -

The World Health Organization has declared the end of the pandemic caused by H1N1 influenza virus. According to Director-General Margaret Chan,

The world is no longer in phase 6 of influenza pandemic alert. We are now moving into the post-pandemic period. The new H1N1 virus has largely run its course.

As we enter the post-pandemic period, this does not mean that the H1N1 virus has gone away. Based on experience with past pandemics, we expect the H1N1 virus to take on the behaviour of a seasonal influenza virus and continue to circulate for some years to come.

According to the Director-General, levels and patterns of H1N1 transmission are now different from those observed during the pandemic. Out-of-season outbreaks are no longer being reported, and their intensity is similar to that seen during seasonal epidemics. In addition, multiple influenza viruses are being isolated in many countries, a pattern typical of many recent seasonal epidemics.

I take particular interest in what the Director-General believes did not happen:

This time around, we have been aided by pure good luck. The virus did not mutate during the pandemic to a more lethal form. Widespread resistance to oseltamivir did not develop. The vaccine proved to be a good match with circulating viruses and showed an excellent safety profile.

I continue to wonder why the Director-General, and many others, feel that influenza virus must change to a more lethal form. Although the four previous influenza pandemics occurred in multiple waves of increasing lethality, there is no evidence that they are a consequence of viral mutation.

[...]

I believe that a major selective force for viral evolution is the need to maintain efficient transmission among hosts. This may be achieved by any number of phenotypic changes, such as increases in stability and virion production. Changes in lethality might also lead to more effective transmission – for example, by inducing more severe coughing, the virus could be better transmitted among humans. But there is no genetic evidence that such changes have occurred during influenza virus pandemics.

How has the idea that influenza virus mutates to greater lethality permeated our popular culture? I don’t know the answer, but John Barry’s The Great Influenza is a prime suspect.

Adobe Reader Users Remain Vulnerable to Flash Exploits After Upgrading Flash Player

Via Softpedia News -

A large number of users, who regularly upgrade their Flash Player installations, remain exposed to Flash-based attacks, because the Flash plug-in bundled in Adobe Reader is not updated at the same time.

Since version 9.0, which was released a little over two years ago, in July 2008, Adobe Reader is capable of natively playing SWF (Shockwave Flash) files embedded in PDF documents.

This functionality is provided through a version of Flash Player bundled in Adobe Reader installations as a file called authplay.dll.

The immediate implication of this is that most, if not all, zero-day vulnerabilities discovered in Flash Player also affect Adobe Reader.

In fact, this has happened several times already and in at least one case rogue PDF documents with malicious SWF files embedded into them were used to infect users with malware.

But, according to Carsten Eiram, who works as chief security specialist at vulnerability research vendor Secunia, there's also another serious problem.

The researcher points out that authplay.dll is not patched during a standard Flash Player upgrade. Instead, this file only gets updated along with Adobe Reader.

However, while Flash Player patches are released at random, whenever they are necessary, Adobe Reader updates ship according to a quarterly schedule.

This means that, for example, the multiple remote code execution vulnerabilities addressed by the newly released Flash Player 10.1.82.76 and 9.0.280 are still exploitable via the latest version of Adobe Reader (9.3.3), which contains authplay.dll (Flash Player) 10.1.53.64.

And since the advisories accompaning Flash Player releases also disclose vulnerabilities reported privately to Adobe by security researchers, this update discrepancy has even more security implications.

It means that hackers could theoretically reverse engineer changes in new Flash Player versions and create exploits for flaws that were previously unknown to them. Once this is done, they would have plenty of time to attack users via authplay.dll.

[...]

Fortunately, the company will issue an out-of-band update next week, in order to address a vulnerability publicly disclosed at Black Hat in July.

"According to Adobe, this also includes an updated version of the bundled Flash Player, but one has to wonder how long we would have had to wait if they weren't forced to issue the out-of-band release," Mr. Eiram, writes on the Secunia blog.

-----------------------------------------------------------------

The best way to protect yourself from vulnerabilities in Adobe products, is not to use Adobe's products. =)

However, in the business world, that just isn't an option in some cases.

In that case, I would suggest you read and review the security settings recommended by AVG.
http://thompson.blog.avg.com/2010/08/how-to-secure-adobe-reader.html

If you want to take it even further, you can do what US-CERT suggested in VU#660993.
http://www.kb.cert.org/vuls/id/660993

Flash and 3D & Multimedia support are implemented as plug-in libraries in Adobe Reader. Disabling Flash in Adobe Reader will only mitigate attacks that use an SWF embedded in a PDF file. Disabling 3D & Multimedia support does not directly address the vulnerability, but it does provide additional mitigation and results not in a crash but in a more user-friendly error message.

Disabling these plug-ins will reduce functionality and will not protect against SWF files hosted on websites [because those are executed by the Flash Player in your browser]. Depending on the update schedule for products other than Flash Player, consider leaving Flash and 3D & Multimedia support disabled unless they are absolutely required.

NATGEO: The Hackers Life – My Weekend at Defcon

Via NATGEO's Assignment Blog -

I’m walking with Nico through the hallways of the convention area of the Riviera Hotel in Las Vegas. There is a distinct old school feeling at the Riviera that reminds one of the days when Las Vegas was run by the family. Walking swiftly Nico tells me that we might see security expert Chris Paget get arrested during his presentation.

“Arrested?”

As we get closer to the hall where Paget is presenting, I can hear someone yelling, “if you have a GSM cell phone, your call may be intercepted. If you do not want this to happen, then turn off your cell phone.” The vociferous warning is supported by the flyers I see haphazardly taped to the walls.

[...]

This is an example of what happens every year at the DefCon hacker conference in Las Vegas. Passionate hackers present their knowledge and capabilities, often times skirting the very fringes of legality. However, if you think that this is a convention for geek criminals, then you’ve been watching too much NBC.

Have you ever locked yourself out of your home and had to try to break in? There is sense of accomplishment in succeeding. Then there’s the slightly disturbing revelation that if you can break into your place as an amateur, a professional could do five times faster – so you look at your exploit and fix the breach. DefCon is like that.

[...]

Walking around the halls are people in dark clothes, ripped jeans and mohawks talking to people in golf shirts and khakis. Its is a welcome antidote from the Hollywood environ where I live. Social status here is based on knowledge and accomplishment and not on clothing labels or car marques.

That is not to say you shouldn’t watch your back here. There are unwritten rules like; don’t ask anyone where they work, and don’t use any ATMs within a two block radius of the Riviera hotel. There are government agents here, as well as white collar criminals. If you are press, you are asked to be obvious in displaying your credential, and to ask permission before shooting pictures of anyone.

[...]

If you’re one who dismisses the DefCon attendees as group of misfits and social pariahs then you probably have the same password for ninety percent of your online existence. Which means you are doomed. Because as clever as you think you’re being by using your dog’s birthday backwards as a secure key, you’re no match for the people that I’ve met. There is no more greater ignorance online than that of an average internet user who believes what the mainstream media says about hackers and internet security.

[...]

You may argue that these hackers have a proclivity to criminal behavior which is why they do what they do. I’ll tell you are wrong. Yes there are criminal intentions to be found at DefCon, but so are there to be found in your office. Every niche of society has a dark element. But that’s not the majority of what you see in society, or here at DefCon. The sense of community and public education is overwhelming, as is the need to share, albeit anonymously, successful hacks that reveal weaknesses in the various security infrastructures that affect all of our lives.

Recently in the news there have been a number of stories telling of various governments, including our own, that are lobbying to try and get more access to the data of our personal online habits. This is an unconscionable thought to me and to probably many of you reading this. Sadly we have very few tools to protest such agendas should they be advanced. But I know a group of people who are passionate about online freedom and have the means to make a stand against insurgencies into your private online life. Many of them can be found at DefCon.

Thursday, August 12, 2010

A Deductive Proof About RIM And Government Monitoring

Via The Firewall Blog (Forbes.com) -

If you want to get to the truth about government monitoring of BlackBerry consumer and enterprise customers by foreign governments, here’s a simple way that doesn’t require you to be an expert in encryption, a network architect or even a technologist. Just follow the numbers:

1. The government of (________) mandates that all communications services be monitored and supervised.

2. Research In Motion sells communications services in (__________).

3. Therefore, Research In Motion’s customers in (________) are subject to supervision and monitoring.


You may fill in the blank with the state of your choice. Deductive reasoning stipulates that if the premises of an argument are true (1 and 2), then the conclusion must also be true (3). Everything else is a moot point (BES encryption hacks, the existence of back doors, compromised third party applications, etc.).

So when the executives at Research In Motion send a statement like this one to their customers (“RIM respects both the regulatory requirements of government and the security and privacy needs of corporations and consumers“), you can call it for what it is – a logical impossibility.


---------------------------

That about sums it up.

Fixing Oil Wells: The Price of Staying in the Game

Via The Economist -

With 500 barrels of hard-set cement now gumming up the Macondo well, a number of inquiries are looking back at the loss of the Deepwater Horizon rig and the subsequent spilling of 5m barrels of oil. How much of the fault is found to lie with the well’s design, how much with the way the design was implemented and how much with the way the rig was run will determine how such ventures will be regulated from now on. It will also settle whether BP, the well’s operator, was grossly negligent—a finding that could be worth well over $10 billion in fines and liabilities.

Meanwhile, the oil industry is already getting to grips with the question of what to do if such a thing should happen again. This is in part prudent politics: credible assurances that a future blowout could be better dealt with will be vital to restoring the industry’s fortunes in the Gulf of Mexico. It is also a matter of economic self-interest. The costs facing BP would have been far smaller if it had been possible to shut the well down a lot quicker.

The position taken by ExxonMobil, Chevron, ConocoPhillips and Shell, which are clubbing together to put $1 billion into creating and equipping a new not-for-profit firm, the Marine Well Containment Company, is that the capability to do much better than at Macondo depends on having hardware designed for the job and available from day one. The companies outlined their plans at a public meeting held in New Orleans on August 4th by the Bureau of Ocean Energy Management.

[...]

If this equipment had all been available in April, its proponents say it might have capped Macondo in weeks. The companies also say the system should never be needed if wells are properly designed and operated, and that they hope their billion-dollar backstop will never have to be used. The various reports into the Deepwater Horizon disaster will doubtless say the same, while endorsing the newly planned capabilities, or some variant thereof, and making some further drilling conditional on having them in place.

Perhaps it is not too much to hope, though, that some of those reports might shed light on two deeper questions: why did such a technologically astute industry not see fit to develop such useful equipment before it was needed, rather than after? And how might that underlying and disastrous lack of foresight be corrected?

Founder of CarderPlanet Arrested in France

Via The Register UK -

A Russian accused of being one of the “most prolific” sellers of stolen credit-card data has been arrested in France, following a nine-month manhunt.

Vladislav Anatolievich Horohorin, 27, was taken into custody in Nice, France, as he was attempting to board a flight bound for Moscow, federal prosecutors in Washington said. He is being detained by French authorities pending extradition to the US.

A founder of CarderPlanet — a notorious clearinghouse for credit-card fraudsters — Horohorin belongs to one of the world's most sought-after online crime networks, authorities said. An indictment unsealed on Wednesday claimed he used the forum and others like it to sell huge “dumps” of stolen credit-card data to people around the world. Using the moniker “BadB,” he brazenly advertised the pilfered information. He directed purchasers to pay for it using a website he operated that automated payments using online currencies such as Webmoney.

A citizen of Israel and Ukraine, Horohorin's undoing began when a member of the US Secret Service using an undercover identity negotiated the sale of “numerous” stolen credit-card dumps, officials said.

If convicted, Horohorin faces a maximum sentence of 10 years in federal prison and a $250,000 fine on a charge of access-device fraud. He also faces an additional two years and $250,000 in fines for a count of aggravated identity theft. Prosecutors' press release in the case is
here.

Dangerous iPhone Exploit Code Goes Public

Via NetworkWorld.com -

Minutes after Apple issued a security update Wednesday, the maker of a 10-day-old jailbreak exploit released code that others could put to use hijacking iPhones, iPod Touches and iPads.

"Comex," the developer of JailbreakMe 2.0,
posted source code for the hacks that leveraged two vulnerabilities in iOS and allowed iPhone owners to install unauthorized apps.

Apple patched the bugs earlier Wednesday.

[...]

"Impressive. And dangerous," said
Mikko Hypponen, chief research officer at antivirus company F-Secure, on Twitter early today of the exploit code.

It may not be long before comex's work is turned into a weapon for attacks that gain "root" access, or complete control, of iPhones and iPads.

"@comex thanks, using it to make malicious s*** now," bragged someone identified as "
MTWomg" on Twitter shortly after comex published the source code.

Noted Mac vulnerability researcher Dino Dai Zovi, co-author of
The Mac Hackers Handbook, chimed in with a warning of his own. "Now that @comex released his jailbreak source, any bets on how long before it is ported to Metasploit?" Dai Zovi tweeted Wednesday.

[...]

Also possibly at risk: Mac OS X. Like iOS, Apple's desktop operating system includes the FreeType font engine, which may be vulnerable to the same or a similar exploit.

Hezbollah, Radical but Rational

Via STRATFOR (Security Weekly) -

When we discuss threats along the U.S./Mexico border with sources and customers, or when we write an analysis on topics such as violence and improvised explosive devices along the border, a certain topic inevitably pops up: Hezbollah.

We frequently hear concerns from U.S. and Mexican government sources about the Iranian and Hezbollah network in Latin America. They fear that Iran would use Hezbollah to strike targets in the Western Hemisphere and even inside the United States if the United States or Israel were to conduct a military strike against Tehran’s nuclear program. Such concerns are expressed not only by our sources and are relayed not only to us. Nearly every time tensions increase between the United States and Iran, the media report that the Hezbollah threat to the United States is growing. Iran also has a vested interest in playing up the danger posed by Hezbollah and its other militant proxies as it tries to dissuade the United States and Israel from attacking its nuclear facilities.

A close look at Hezbollah reveals a potent capacity to conduct terrorist attacks. The group is certainly more capable and could be far more dangerous than al Qaeda. An examination also reveals that Hezbollah has a robust presence in Latin America and that it uses its network there to smuggle people into the United States, where it has long maintained a presence. A balanced look at Hezbollah, however, shows that, while the threat it poses is real — and serious — that threat is not new and it is not likely to be exercised. There are a number of factors that have limited Hezbollah’s use of its international network for terrorist purposes in recent years. A decision to return to such activity would not be made lightly, or without carefully calculating the cost.

Wednesday, August 11, 2010

JailbreakMe: Apple Issues Emergency iPhone/iPad Security Patch

Via Graham Cluley’s Blog -

Apple has kept true to its promise, and released a security patch for users of iPhones, iPads and the iPod Touch, closing the door on a vulnerability that could have exposed them to malware and other malicious attacks.

The vulnerability first came to the public's attention after it was used by a website, JailbreakMe.com, which made it simple for iPhone and iPad users to jailbreak their devices.

As I reported earlier this month, the drive-by jailbreak exploited a vulnerability in the way that the mobile edition of Safari (the default browser used in the iOS operating system) handles PDF files - specifically its handling of fonts. Therefore, just visiting the JailbreakMe website could run code on the visitor's iPhone, iPod Touch or iPad.

Such a vulnerability, if left unpatched, leaves open opportunities for hackers to spread malicious code to Apple's mobile products.

-----------------------------------------------

Apple clearly doesn't want to see a worm spreading across the large community of standard iPhones/iPads/iPods. That would be bad for their "secure by design" image and would be very bad for their users.....but Apple also doesn't want their users to have the ability to jailbreak their devices either.

Alternative motive? Perhaps.

Especially when there hasn't been any word on the current zeroday in the latest version of Quicktime.

US Military Finds New Target: Moore's Law

Via BBC -

The Defence Advanced Research Projects Agency (Darpa) has awarded the first grants to firms it wants to build so-called exascale computers.

These will be far more powerful than current top supercomputers which manage just over one petaflop - 1000 trilliion calculations per second.

Darpa expects the first prototypes to be working by 2018.

An exaflop is the equivalent of one million trillion calculations per second.

Darpa said its research project was needed to help analyse the tidal wave of data that military systems and sensors are expected to produce.

The research project, dubbed the Ubiquitous High Performance Computing (UHPC) program, would attempt to create hardware that "overcomes the limitations of current evolutionary approach".

That approach is characterised by Moore's Law which says the number of transistors that can fit on a given piece of silicon will double every 18-24 months.

The limitations of that approach are the mushrooming power, management and structural issues that crop up as components shrink.

[...]

Chip giant Intel, graphics card maker Nvidia, MIT and the Sandia National Laboratory are all recipients of the first grants to be used to create prototype exascale machines.

Tuesday, August 10, 2010

Patch Tuesday - Microsoft & Adobe Flash

Adobe: Security Update Available for Adobe Flash Player (v10.1.82.76)
http://www.adobe.com/support/security/bulletins/apsb10-16.html

Looking at six (or more) memory corruption remote code execution vulnerabilities and one click-jacking vulnerability. So patch already.

For me, the easiest way to ensure you have the latest version of Flash [on Windows] is just uninstall it from the "Add/Remove" panel and then re-install. Remember, if you use Flash in Mozilla or Opera, you will have two versions on the PC. An ActiveX version for Internet Explorer and a plug-in version for Mozilla or Opera. Uninstall both and then re-install for both browsers.

After you have installed the new version, double check by browsing to the Adobe Flash Version Test website and ensure 10.1.82.76 is listed your player version.

-------------------------------------------------------

Microsoft: August 2010 Security Bulletin Release
http://blogs.technet.com/b/msrc/archive/2010/08/10/august-2010-security-bulletin-release.aspx

Microsoft:Assessing the Risk of the August Security Updates
http://blogs.technet.com/b/srd/archive/2010/08/10/assessing-the-risk-of-the-august-security-updates.aspx

Symantec: Microsoft Patch Tuesday - August 2010
http://www.symantec.com/connect/blogs/microsoft-patch-tuesday-august-2010

--------------------------------------------------------

Patch'em if you got'em.

Special Forces’ Robocopter Spotted in Belize

Via Wired.com -

Watch out, humans, the U.S. military has released an all-seeing, unmanned helicopter into the wild, according to Aviation Week. The Boeing A160T Hummingbird was photographed in Belize, where it was test flying a tree-penetrating Darpa radar called FORESTER. Locals were given a heads-up thanks to a press release from the U.S. Embassy. There’s no sign of the document on the website, but local reports say that the the Belize government invited the U.S. to test the Hummingbird in a mountain range 25 miles from the Guatemalan border. A few dozen military personnel – both Belizean and American – are involved in the testing, which will last until September.

-------------------------------

Some background on the A160T Hummingbird...
http://djtechnocrat.blogspot.com/search?q=A160T+

DHS Building Teams to Test Power Plant Cybersecurity

Via ComputerWorld.com -

The Department of Homeland Security (DHS) is quietly creating specialized teams of experts to test industrial control systems at U.S power plants for cybersecurity weaknesses.

According to an Associate Press report today, DHS has so far created four teams to conduct such assessments, according to Sean McGurk, director of control system security. McGurk told the news service that 10 teams are expected to be in the field next year as the program's annual budget grows from $10 million to $15 million.

McGurk did not immediately respond to a Computerworld request for an interview. However a DHS spokeswoman this afternoon confirmed the DHS plan as detailed in the Associated Press story.

She said the special teams are part of an Industrial Control Systems Computer Emergency Response Team (ICS CERT) that DHS has been building over the past year in response to worldwide cybersecurity threats against industry control systems.

The teams are being set up to help companies in critical infrastructure industries respond to and mitigate cyber incidents affecting industrial control systems, she said.

Each DHS team is said to be equipped with forensic tools, cables, converters and data storage equipment to be used to probe for and fix security vulnerabilities in control systems.

According to the report, the specialized DHS teams conducted 50 security assessments at power plants in the past year. In addition, teams were dispatched 13 times to investigate cyber incidents -- nine were found to be cyber intrusions and four were caused by operator error.

-----------------------------------------

First-Reaction: It's about damn time....

Second-Reaction: Cybersecurity is good and assessing and protecting SCADA systems is long overdue. But let's remember, these critical infrastructure systems have a big physical presence and can have direct physical consequences on the public, if attacked. And good old bombs can still work...

Radical Indonesian Cleric Arrested in Terror Plot

Via MSNBC (AP) -

A radical Islamic cleric was back in jail Monday after police said they had evidence he not only inspired al-Qaida linked militants with his fiery sermons but helped set up a new terror cell that was plotting attacks on hotels and embassies in Indonesia's capital.

They said they found a bomb-making laboratory and evidence of at least two powerful test blasts in a nearby mountain range.

Abu Bakar Bashir, who has been arrested twice before and spent several years in jail, was heading home after preaching in the West Java town of Ciamis when the anti-terror unit swooped, breaking the rear window of his van after his bodyguards tried to obstruct them, officials and family members said.

[...]

The 71-year-old is best known as one of the co-founders and spiritual head of Jemaah Islamiyah, the al-Qaida-linked network responsible for a string of suicide bombings in the world's most populous Muslim nation, including the 2002 attacks on Bali island that killed 202 people, most of them Western tourists.

[...]

Bashir was accused of providing funds for a new terror cell in westernmost Aceh province and playing "an active role in preparing the initial plans for their military struggle," he said, without elaborating.

The cleric also allegedly helped appoint its leaders, including Dulmatin, an alleged mastermind of the Bali bombings, who was killed in a March raid, and "routinely received reports from their field coordinator."

Police have one week to file official charges.

More than 100 suspects have been rounded up — including five on Sunday — since authorities discovered Al-Qaida in Aceh's jihadi training camp in February. Several large caches of assault weapons, ammunition and explosives also have been seized.

[...]

Recently, Bashir formed a new radical movement, Jemaah Ansharut Tauhid, or JAT, described by the Brussels-based International Crisis Group as an "ostensibly above-ground organization" that embraced individuals with known ties to fugitive extremists.

Bashir came under renewed police scrutiny in May after three JAT members were arrested for allegedly raising funds for al-Qaida in Aceh.

----------------------------------------

Wikipedia: Jemahh Islamiyah (JI)
http://en.wikipedia.org/wiki/Jemaah_Islamiyah

More information can be found over @ LWJ...
http://www.longwarjournal.org/archives/2010/08/jemaah_islamiyah_fou.php

UK Blocks Sanctions Against Suspected Somali Pirates

Via BBC (Aug 9, 2010) -

It's emerged that the British government is blocking a move at the UN to take action against two suspected pirate organisers.

This is despite tough British language condemning pirates and the paying of ransom, and its contribution of warships to the anti-pirate operation run by the EU, known as EU Navfor.

The EU operation has itself been reduced to near farce in the last week, with a Spanish ship having to send pirates back to Somalia, after catching them red-handed, because the problems of prosecuting them are too great.

A look first at the British position.

The Foreign Office in London confirmed a story in the Financial Times that the UK is blocking an American proposal to add the names of two alleged pirate leaders to a UN sanctions list.

[...]

The reason, I am told, is that the paying of ransom is not a criminal offence in the UK. This has made it possible for ransom to be paid for dozens of ships and their crews, and many of the negotiations go through London.

But, the argument is, if the suspected pirate leaders, named by the Foreign Office as Abshir Abdillahi and Mohamed Abdi Garaad (with numerous variants) are put on the UN sanctions list, then ransom in effect becomes an offence in the UK and might put an end to many ransom deals.

According to British officials Abdillahi and Garaad are "high-profile pirate leaders involved in hijacks in the Gulf of Aden".

Indeed, they are alleged to be so influential that almost all ransoms are said to involve them in some way.

[...]

Britain has applied the technical hold because it is under pressure from ship-owners and seafarers who prefer the present system. This system is basically one of doing business, not waging war. The ship is taken, negotiations take place, the money is paid and the ship and its crew are released.

[...]

Gavin Simmons of the London Chamber of Shipping told the FT: "To discontinue payments or make them illegal would jeopardise the safety of seafarers held captive."

This is something of an embarrassment to the British government. Foreign Office officials told me it was being discussed "at the highest level" and something might develop "in the next few months".

[...]

Pirates caught in the act cannot easily be prosecuted and in this case were simply sent back home.

Kenya has taken about 100 pirate suspects and has imprisoned about 20 of them. But Kenya is now threatening to withdraw its co-operation, saying that it is not being given enough support.

Both examples show how far the international community is from solving a problem that in the 19th Century would have been dealt with in somewhat shorter order.

---------------------------------------------

Beyond Kenya, there are other nations in the area that are working with the international community to jail pirates caught in the action - i.e. Seychelles.

But this latest technical hold by the British is an interesting Catch-22.

More and more ships are being armed with anti-pirate countermeasures (e.g. water cannons, armed guards while at sea, wire & railing protection, etc)...but at the same time, if a ship is hijacked, the ship-owners [understandably] want to pass the ransom and just get their crew back safely.

But as the anti-pirate measures increase, so do the actions of the pirates...and thus there is a greater chance of harm coming to the crew during the hijack. Therefore, at what point will companies decide enough is enough and stop paying. After two crew members are killed during each hijack attempt? Three? After more proof is found that groups are working with organized crime rings??

And without putting a clear legal framework in place now for holding and jailing these pirates...how can we move forward after that threshold is reached?

Saturday, August 7, 2010

Unpatched Kernel-Level Vuln Affects All Windows Versions

Via The Register UK -

Researchers have identified a kernel-level vulnerability in Windows that allows attackers to gain escalated privileges and may also allow them to remotely execute malicious code. All versions of the Microsoft OS are affected, including the heavily fortified Windows 7.

The buffer overflow, which was originally reported here, can be exploited to escalate privileges or crash vulnerable machines, IT research company Vupen said. The flaw may also allow attackers to execute arbitrary code with kernel privileges.

The bug resides in the “CreateDIBPalette()” function of a device driver known as “Win32k.sys.” It is exploited by pasting a large number of color values into an improperly allocated buffer, potentially allowing attackers to sneak in malicious payloads, vulnerability tracking service Secunia warned.

It affects fully patched installations of every supported Windows platform, from Windows XP SP 3 to Windows Vista, 7, and Server 2008. The latter three versions contain several defenses designed to lessen the effect of security vulnerabilities. It wouldn't be surprising if code execution attacks were possible only on earlier versions that don't have the defenses, which include DEP, or data execution prevention, and ASLR, short for address space layout randomization.

There are no reports of the vulnerability being exploited in the wild. Microsoft said it is investigating the reports but didn't have additional information. Microsoft is scheduled to issue a record 14 security bulletins during next week's Patch Tuesday.

Next HOPE Videos and Audio Now Available

http://www.2600.com/news/view/article/11995

Less than three weeks after the end of The Next HOPE, we're happy to announce that video and audio from the conference talks is now available. The audio is online for free at http://thenexthope.org/talks-list/ while more than 100 DVDs of the talks can be found at http://store.2600.com/nexthopevideos.html for half the price than they went for at the last conference. This year, the talks were especially interesting, provocative, engaging, and enlightening. This is a great way to comfort yourself if you didn't make it to this historic conference and a means of seeing even more talks if you did happen to make it this time. Please help us spread the word so that more people have the HOPE experience!

Thanks to everyone who helped make The Next HOPE such a success! You're the people who make it all possible.

Questions and Answers on the Jailbreakme Vulnerability

http://www.f-secure.com/weblog/archives/00002004.html

Q: What is this all about?
A: It's about a site called jailbreakme.com that enables you to Jailbreak your iPhones and iPads just by visiting the site.

[...]

Q: But I thought only jailbroken iPhones were at risk!
A: You're confused. All iOS devices, including plain vanilla iPhones, are at risk.

[...]

Q: Does the PDF vulnerability affect Adobe PDF Reader?
A: No. Adobe PDF Reader on Windows and other platforms is not affected by this vulnerability.

Q: Is the PDF reader on my iPhone made by Adobe?
A: No, it's made by Apple. And there is no separate Reader application, PDF support is built in to the OS.

[...]

Q: So there's no risk?
A: There's no risk, at the moment. The potential for risk, however, is big.

Q: What's your best guess, when will we see an iPhone worm spreading via this vulnerability?
A: Within a week or so.

[...]

Q: How could such a worm replicate further?
A: It could replicate further from your phone by sending itself as a text message to all people listed in your phone book. For example.

Q: What could such a worm do on my phone?
A: Anything. It could do anything you can do on your phone, and more. So it could destroy or steal all of your data. Track your location. Spam your friends. Listen to your phone calls. Dial the presidents of every country in the world. Anything. And you would pay for all the charges it would create, too.

Alleged RBS WorldPay Hacker Extradited to U.S.

Via ComptuerWorld.com -

One of the alleged masterminds of a 2008 precision strike on payment processor RBS WorldPay has been extradited from Estonia to face U.S. justice.

Sergei Tsurikov, 26, of Tallinn, Estonia, was arraigned Friday in federal court in Atlanta. He faces a variety of hacking and fraud charges connected to one of the most successful computer crimes ever.

Prosecutors say that Tsurikov was one of the leaders of a gang that managed to hack into the RBS WorldPay network, and then clone payroll debit cards -- used by employees to withdraw their salaries from debit and ATM machines on payday. They distributed the cards to a worldwide network of cashiers, who were instructed to withdraw money within a 12-hour window. Hitting 2,100 ATMs, they took in $9.4 million, prosecutors say.

"In November 2008, in just one day, an American credit card processor was hacked in perhaps the most sophisticated and organized computer fraud attack ever conducted," U.S. Attorney Sally Quillian Yates said in a statement.

RBS WorldPay is the payment processing division of the Royal Bank of Scotland Group.

As the money was leaving the network, Tsurikov and the group's mastermind, Victor Pleshchuk, monitored the RBS WorldPay systems and then attempt to cover their footsteps by destroying data, prosecutors say.

Pleshchuk was arrested earlier this year in Russia, along with Tsurikov and a third leader, Oleg Covelin, according to news reports.

Tsurikov and five other members of the gang have already been convicted of fraud in Estronia, but now Tsurikov has been brought to the U.S. to face additional charges. He is one eight people, including Pleshchuk, who were indicted on U.S. charges relating to this fraud, and the first to be extradited to the U.S.

Friday, August 6, 2010

US State Department: Iran Supports Taliban, Iraqi Militants

Via The Long War Journal -

The State Department released its Country Reports on Terrorism for 2009 on Thursday. The analysis, which details terrorist events in the previous calendar year, was supposed to be provided to Congress by April 30. But this year the report was not published until August.

As expected, Iran “remained the most active state sponsor of terrorism” in 2009. In particular, Tehran continues to sponsor terrorists who kill American servicemen in Iraq and Afghanistan.

According to the State Department, Iran trains and arms the Taliban, does the same for Iraqi militants targeting US forces, and provides safe haven for al Qaeda members. The State Department does not use the term 'safe haven' to describe Iran's sheltering of al Qaeda leaders and members, however.

Much of the State Department’s reporting on Iran remained unchanged from the year before -- with one noteworthy difference. Only in its reporting on the relationship between the Iranian regime and al Qaeda did this year’s report differ substantively from last year’s analysis.

[...]

The bottom line is that Iran is still supporting the Taliban in Afghanistan and militants in Iraq in their attacks on civilians and US-led forces.

End of Net Neutrality Negotiations Good News for Internet

Via PC World -

The FCC has called off negotiations with major Internet industry players to arrive at a compromise for net neutrality. The meetings were an attempt to come to an amicable agreement over net neutrality rules and dodge political pressure over FCC jurisdiction and authority--but asking the fox how to protect the henhouse is generally unwise.

Reports of a secret deal between Verizon and Google for preferential treatment of Google traffic on Verizon's networks may have been a catalyst to the breakdown of negotiations. But, whether that is true or not, the end of the negotiations is great for the future of the Internet. The FCC is supposed to provide guidance and oversight of these Internet industry stakeholders--not the other way around.

Andrew Jay Schwartzman, Senior Vice President and Policy Director of Media Access Project, had this to say about the rumored Google-Verizon deal. "What is good for Google and Verizon is not necessarily good for innovation and competition on the Internet. What the two companies have in common is that both are incumbents with dominant positions in their markets. It's no wonder they are prepared to strike a deal that protects their market position at the detriment of the next Verizon and the next Google."

Schwartzman added this advice for the FCC. "The Commission should complete what it has started by bringing broadband services back under its jurisdiction as soon as possible, instead of pursuing its fruitless efforts at a short-term backroom compromise on net neutrality. A regulatory agency like the FCC should not be making deals with the biggest companies any more than it should countenance private side deals that achieve the same outcome. These arrangements could sacrifice successful implementation of the National Broadband Plan as well as broader free speech, privacy, disability, public safety, and consumer protections."

[...]

We don't expect the USDA (US Department of Agriculture) to let farmers dictate what quality of meat is good enough for Americans to consume. We don't expect the DEA (Drug Enforcement Administration) to check with Columbian drug cartels to negotiate how much cocaine should be allowed into the country. And, we don't expect DHS (Department of Homeland Security) to talk to Al Qaeda to select which individuals should be closely monitored for terrorist activity. Why should the FCC consult with the industry it is supposed to police?

According to its Web site, "The FCC was established by the Communications Act of 1934 and is charged with regulating interstate and international communications by radio, television, wire, satellite and cable." It should simply fulfill that mission--without asking for permission or apologizing to the industry it is tasked to regulate.

Iran Says It Has S-300 Missiles

Via The St. Peterburg Times (Russia) -

Iran has obtained four S-300 surface-to-air missile systems despite Russia’s refusal to deliver them to Tehran under a valid contract, a semi-official Iranian news agency claimed Wednesday.

The Fars news agency, which has ties to Iran’s elite Revolutionary Guard, Iran’s most powerful military force, said Iran received two S-300s from Belarus and two others from another, unspecified source. Fars did not elaborate, and there was no official confirmation of the report.

Russia signed a 2007 contract to sell the S-300s but so far has not delivered. The powerful, long-range missiles would significantly boost Iran’s defense capability, and Israel and the United States have strongly objected to the deal.

A spokesman for Belarus’ state military trade committee, however, denied there were any missile deliveries.

“Talks with the Iranian side about the delivery of such systems have not taken place and, consequently, no deliveries to Iran have taken place, neither of these systems or elements of them,” said Vladimir Lavrenyuk. “The Belarussian side strictly observes all international agreements on export control.”

Moscow said in June that the latest round of UN sanctions would prevent it from delivering the S-300s to Iran. But last month, Russian Technologies head Sergei Chemezov said the contract to deliver the S-300s to Iran had not been annulled yet pending a decision by President Dmitry Medvedev.


--------------------------------------------

Searches of the FARS News Agency website pulled up no recent discussion of S-300 missiles.

Thursday, August 5, 2010

Mexico's Juarez Cartel Gets Desperate

Via STRATFOR (Security Weekly) -

On Aug. 3, the U.S. Consulate in Juarez, Mexico, reopened after being closed for four days. On July 29, the consulate had announced in a warden message that it would be closed July 30 and would remain closed until a review of the consulate’s security posture could be completed.

The closure appears to be linked to a message found on July 15, signed by La Linea, the enforcement arm of the Juarez cartel. This message was discovered at the scene shortly after a small improvised explosive device (IED) in a car was used in a well-coordinated ambush against federal police agents in Juarez, killing two agents. In the message, La Linea claimed credit for the attack and demanded that the U.S. Drug Enforcement Administration (DEA) and FBI investigate and remove the head of Chihuahua State Police Intelligence (CIPOL), who the message said is working with the Sinaloa Federation and its leader, Joaquin “El Chapo” Guzman Loera. The message threatened that if the intelligence official was not removed by July 30, La Linea would deploy a car bomb with 100 kilograms of high explosives in Juarez.

The deadline has now passed without incident and the consulate has reopened. Examining this chain of events provides some valuable insights into the security of U.S. diplomatic facilities as well as the current state of events in Juarez, a city that in recent years has experienced levels of violence normally associated with an active war zone.

[...]

One other intriguing point about the security at the U.S. Consulate in Juarez and its closure due to La Linea’s VBIED threat is that the incident did not occur at a diplomatic post in a far-away terrorist hotspot like Yemen, Iraq or Pakistan. The U.S. Consulate in Juarez is located less than seven miles from downtown El Paso, Texas.

Poland: Alleged Israeli Agent to be Extradited to Germany

Via CNN -

An alleged Israeli agent will be extradited to Germany to be tried for spying, the Polish court of appeals press officer told CNN Thursday.

The alleged agent "is accused of helping to get false documents for the man who is thought to have killed the Hamas leader in Dubai," the officer said.

The man was arrested in Poland two months ago on a European warrant in connection with the procurement of a false German passport, as part of an investigation into the killing. German authorities then requested the man's extradition.

Mahmoud al-Mabhouh, a founding member of Hamas' military wing, was found dead in January in his hotel room in Dubai. Police believe he was killed the night before and suspect the Mossad, Israel's foreign intelligence unit, was behind the assassination.

Several countries such as Ireland, the United Kingdom and Australia have kicked out Israeli diplomats after concluding Israel had probably forged their countries' passports as part of the operation.

Israel has maintained there is no proof linking it to the doctored passports or the killing of al-Mabhouh.


---------------------------------------------

For those needing a refresher on the Mahmoud al-Mabhouh assassination....
http://djtechnocrat.blogspot.com/search?q=Mahmoud+al-Mabhouh

U.S. Indicts 14 on Charges of Supporting Al-Shabaab

Via LATimes.com -

The U.S. government on Thursday announced 14 people have been indicted on charges they provided support to the Somali terrorist group Shabab, shedding light on "a deadly pipeline" that has routed funding and fighters to the group from cities across the United States, Atty. Gen. Eric Holder said.

Most of those charged were U.S. citizens of Somali descent. It has long been known that young, disaffected Somali immigrants were leaving their homes in Minnesota and other states to fight for Shabab, a Somali Islamist army whose several thousand fighters are battling Somalia's weak transitional government. Today's indictments represent the U.S. government's most significant public response to that problem.

Shabab, which routinely beheads its enemies, has been branded a terrorist group by the U.S. and other nations, and in turn has declared war on the United Nations and humanitarian organizations in Somalia. The group claimed responsibility for a bombing last month that killed scores of fans who were watching a World Cup soccer match in Uganda's capital.

[...]

The U.S. government designated Shabab a foreign terrorist organization in March 2008, and said it has ties to al-Qaida.


------------------------------------

It isn't just the US government that has stated Al-Shabaab has ties to AQ....leaders in Al-Shabaab said it early this year.

http://news.bbc.co.uk/2/hi/africa/8491329.stm (Feb 2010)

Somali Islamist rebel group al-Shabab has confirmed for the first time that
its fighters are aligned with al-Qaeda's global militant campaign.

Microsoft Security Bulletin Advance Notification for August 2010

http://www.microsoft.com/technet/security/bulletin/ms10-aug.mspx

This is an advance notification of (14) security bulletins that Microsoft is intending to release on August 10, 2010.

(8) Critical Severity
(6) Important Severity

----------------------------------------

Looks like Microsoft is maintaing their big/small patch rotation.

Microsoft released just four bulletins in July, ten in June. two in May, eleven in April, three in March, thirteen in February, etc.

You get the idea...

Adobe Confirms Remote Code-Execution Flaw in Reader; OOB Patch Expected

Via The Register UK -

A security researcher has uncovered yet another vulnerability in Adobe Reader that allows hackers to execute malicious code on computers by tricking their users into opening booby-trapped files.

Charlie Miller, principal security analyst at Independent Security Evaluators, disclosed the critical flaw at last week's Black Hat security conference in Las Vegas. It stems from an integer overflow in a part of the application that parses fonts, he said. That leads to a memory allocation that's too small, allowing attackers to run code of their choosing on the underlying machine. There are no reports of the flaw being targeted for malicious purposes.

[...]

Brad Arkin, senior director of product security and privacy at Adobe, said members of the company's security team attended Miller's talk and have since confirmed his claims that the vulnerability can lead to remote code execution. The team is in the process of developing a patch and deciding whether to distribute it during Adobe's next scheduled update release or as an “out-of-band” fix that would come out in the next few weeks.

Key to the decision is determining whether there are enough details available from Miller's talk for the vulnerability to be exploited in real-world attacks.

“Certainly, there's some information in the slides and screenshots of some of the crash information,” Arkin told The Register. “As we evaluate what's the right response, we're going to look in and decide is that information sufficient and if so, how long would it take for someone with malicious intent to convert that into an exploit.”

Miller's discovery is the latest to document a vulnerability in Adobe Reader that puts its users at risk of attacks that can surreptitiously install malware that steals passwords or other sensitive information. The vulnerability affects versions for Windows, Unix, and Mac OS X.

Miller discussed the unpatched bug during a demonstration of a security software tool called BitBlaze, which helps researchers analyze crash bugs. The tool, was also instrumental in helping Miller gain insights into two exploitable bugs in OpenOffice that remain unpatched. Slides from his talk are here, and the white paper is here.

------------------------------------------------------

Sadly, this vulnerability hasn't been getting the attention it desires, perhaps due to the iPhone jailbreak / exploits.

However, Adobe has just released a security advisory and a out-of-band update prenotification for Adobe Reader and Acrobat.
The updates will address critical security issues in the products, including CVE-2010-2862 which was discussed at the Black Hat USA 2010 security conference on Wednesday, July 28, 2010. Adobe expects to make these updates available during the week of August 16, 2010.
The CVE above is currently in RESERVED status, but given that Charlie Miller's talk was on July 28th, this is a good indication that this update will fix the released vulnerability.

Adobe Reader/Acrobat Font Parsing Integer Overflow Vulnerability
http://secunia.com/advisories/40766

UK StreetWars: Water Pistol Fights for Grown-ups

Via BBC -

On a street corner, an assassin waits in silence for his victim.

Dressed all in black, face covered except for his eyes, he looks menacing as he steadies his weapon and prepares to shoot with the cold-blooded eyes of a killer.

But not everything is as it seems. His weapon is bright green and it is water rather than bullets that blasts the hapless, screaming, victim as he fumbles - too late - for his own pistol.

The assassin laughs silently as he lets his soaking-wet prey through the door he was guarding.

He is taking part in StreetWars, a water "assassination" contest that started in London on Monday and which lasts until 29 August.

Kicked off in New York in 2004, the tournament has since visited cities including Vancouver, Vienna, Los Angeles and Paris, and organisers say it attracts between 125 and 300 players. The first London contest took place in 2006 and it returns this month for the first time in three years.

It is a water fight for grown ups where, they say, the entire city is your playground.

However, some city authorities criticise it as "irresponsible" and suggest it might spark security alerts.

The exact rules are kept under wraps, except to those who pay the £40 to sign up.

Players are called to the headquarters of the "Shadow Government" - as the organisers like to be known - to be given details of their target, including home address, work address, phone number and a photo, and then set the task of shooting them in any way they can.

Participants are buzzed through a door and then led to the basement with a gun - well, water pistol - shoved into their back.

Men in trilby hats hand out manila envelopes before players are thrust, disorientated, back into the real world in the knowledge someone with their photo is hunting them down.

iPhone JailbreakMe Patch Coming Soon

Via H-Online.com -

According to US media reports, Apple already has a fix for the 'JailbreakMe' security issue, which it plans to distribute as part of a forthcoming update. However, the company remains coy about when exactly this will happen. It can only be hoped that it will be soon, as it's without doubt the biggest threat to iPhone users since the device was released. It is also unclear whether Apple is going to fix both vulnerabilities or just one. On Wednesday of this week the German Federal Office for Information Security (BSI) warned (German language link) of the potential for attacks.

The vulnerabilities relate to a bug in processing Compact Font Format (CFF) data embedded in PDF files and to a kernel vulnerability. The CFF vulnerability can be exploited to inject and execute code on an iPhone using crafted PDF files. This appears to be how the JailbreakMe exploit is able to outwit the iPhone's data execution prevention functionality. The exploit then uses the kernel vulnerability to break out of the sandbox and run on the iPhone with elevated privileges, allowing it to unlock the device.

To date, the JailbreakMe exploit is alone in utilising the vulnerabilities to open PDF files tailored to the user's iPhone version when the JailbreakMe website is opened in Safari. However, other apps can be used to open PDFs and other web sites, which utilise the exploit to infect the phone with malware rather than just unlocking it, may also be on the horizon.

Security specialists are currently having a hard time publishing further information on the vulnerabilities, partly because the exploit is equipped with protective measures to hinder debugging and analysis. As a result no malicious exploits have been seen to date. Users should, however, be careful what links they follow and what sites they visit in Safari.

-------------------------------------------------------

Awesome, so Apple has a fix for the exploits used to jailbreak the iPhone...but what about the new Quicktime SMIL Zero-day that basically affects all Windows users?

http://discussions.info.apple.com/thread.jspa?messageID=12039587

This guy has it right......

"So i guess we wont hear anything from Apple until they (hopefully) release a fixed version in a couple of months. I don't see how that protect the customers... "

Wednesday, August 4, 2010

UK Government: We're Sticking with Internet Explorer 6

Via Graham Cluley’s Blog (Sophos) -

Gulp. At the end of last week, along with thousands of other Brits, I received an email from the UK Government telling me that they had responded to a petition I had signed urging the Prime Minister to encourage government departments to upgrade from Internet Explorer 6.

You can read the UK Government's response
here.

In a nutshell, Her Majesty's Government says it is more cost-effective to stick with Internet Explorer 6 (which has been dogged with security issues) rather than switch to an alternative browser or a more up-to-date version.

Too expensive, huh?

You have to wonder if that's going to be considered an acceptable excuse by the general public when there's a serious security breach that exploits a creaky old browser that's been around since 2001.

Where's the wisdom in sticking with IE 6 when Microsoft itself has urged users to upgrade to a more secure version, many websites are
dropping support for it, and security professionals advise that installations of Internet Explorer 6 should be taken outside and beaten with a heavy stick.

Of course, we have to be realistic. Upgrading and switching browsers isn't something that a government department can do overnight. IT teams responsible for network management have to ensure that their PCs can properly handle the new version of the browser, and that existing web applications work properly.

But doing nothing is not acceptable from the point of view of security, and sends the wrong message to consumers and businesses across the country. IE 6 simply isn't a safe place to be anymore, and should be ditched as soon as possible.

Stuxnet Attack Shows Signs of Nation-State Involvement, Experts Say

Via Threatpost.com -

The Stuxnet attack has been making headlines for several weeks now, thanks to the fact that includes a pair of zero-day vulnerabilities and also has drivers signed by a stolen digital certificate. However, the real story of this novel malware attack may not be its tactics but its creator, which security experts say is likely a nation-state.

[...]

Attackers and malware writers have become very adept at finding new ways to make money over the years, and the risk of prosecution is very low in most cases. That's one of the reasons that the Stuxnet malware stands out: there's no clear immediate financial gain for its creators. The Stuxnet attack is designed to be as stealthy as possible and targets mainly SCADA systems, some of the highest value machines in the world.

[...]

Stuxnet's sophistication and its lack of any real money-making component are leading experts to believe the attack is likely the work of a national government or intelligence agency.

"This is the most sophisticated attack that we have seen to date, by far," Roel Schouwenberg, a malware researcher at Kaspersky Lab, said at the company's Virus Analyst Summit here Tuesday. "The evidence points to involvement by a nation-state. This is a highly advanced attack."

The topic of national governments and intelligence agencies being involved in offensive attacks online has been a touchy one for years, and while many security experts and analysts say that it's simply a fact of life in the modern world, there has been little in the way of evidence of actual attacks.

[...]

Schouwenberg, who has been researching Stuxnet for several weeks, said that although the first public reports of the malware's existence only appeared in recent weeks, he now believes the malware itself is much older.

"We went back and looked at our samples and found Stuxnet samples from 2009," he said. "No one knows what it was doing before it became public a few weeks ago."

-----------------------------------------------------------

Symantec released a blog on July 29th which outlined several different variants of the Stuxnet malware. The reached a very similar conclusion:
Analyzing the different types of samples we have observed to date has shed some light on how long this threat has been under development and/or in use. The development of the threat dates back to June of 2009 at least. The threat has been under continued development as the authors added additional components, encryption and exploits. The amount of components and code used is very large, in addition to this the authors ability to adapt the threat to use an unpatched vulnerability to spread through removable drives shows that the creators of this threat have huge resources available to them and have the time needed to spend on such a big task; this is most certainly not a “teenage-hacker-coding-in-his-bedroom” type operation.

Reflections on “Hole 196″

Via Will Hack for Sushi Blog -

Last week at BlackHat, AirTight Networks security analyst Md Sohail Ahmad presented his findings on a vulnerability dubbed "hole196". Affecting WPA/WPA2 Enterprise networks, this issue allows an authenticated user to manipulate other clients on the network to establish ARP spoofing attacks, to impersonate data frames from the AP or to create a DoS attack against other users. This is all through leveraging a key shared among all of the authorized clients in a wireless LAN known as the Group Temporal Key (GTK). The "hole196" bit refers to page 196 of the IEEE 802.11-2007 specification indicating that the GTK does not prevent packet forgery attacks (from an insider).

The BlackHat presentation slides were distributed on the BlackHat conference CD, and since the slides lack any kind of a copyright notice, I think it's OK for me to mirror them here.

Initially, this flaw had some people concerned, since an early article published by Network World and Joanie Wexler indicated:
Clients who receive the message see the client as the gateway and "respond with PTKs", which are private and which the insider can decrypt, Ahmad explains.
If this attack could get a client to reveal their PTK, even requiring that the attack start from an insider perspective, then I'd be coding up an exploit tool instead of writing this post. This, however, appears to be a misquote by Wexler, or a misunderstanding by Ahmad. No-one has clarified this quote as far as I have seen.

The truth behind this issue is that, well, it's a non-issue for most organizations. Instead of mounting an ARP spoofing attack to implement a man-in-the-middle (which a wired IDS could detect), it can be done using this technique within the encrypted wireless network, evading network IDS detection. The best way to detect this attack is through a wireless IDS, of which AirTight is a leading vendor ("Yay, Capitalism!").

When significant wireless attacks emerge, I call my customers to remind them that I do get let out of my cave every now and then, and to help them understand their exposure to the attack. I don't believe "hole196" falls into the category of significant wireless attack, so it's back to the cave I go.

For a 2nd perspective, and an excellent technical write-up, please see Glenn Fleishman's article over at Ars Technica.

--------------------------------------------------------

For more information, check out AirTight's Hole 196 FAQ.
http://airtightnetworks.com/wpa2-hole196

I was lucky enough to be sitting on the floor near the front of this talk for Defcon.

Josh's blog entry basically matches my take away as well. Use Wireless IDS and be suspect of wireless client sending broadcast traffic (i.e. GTK encrypted traffic) to other clients.

Also, if you currently use Wireless IDS, you can ask your vendor for configuration suggestions or possible steps that can be used to detect the attack.

Do that and get on with the other issues in your network....because you have bigger holes ;)

Adobe vulnerabilities anyone? lol

New Critical Vulnerability in Adobe Reader and Nobody Wants to Know

Via H-Online -

Some things have become so commonplace that nobody even takes much notice of them anymore. Security expert Charlie Miller found this to was the case when presenting a gaping hole in Adobe's Reader product at the Black Hat conference one week ago. After his presentation, Miller said: "Adobe security is so bad that […] not a single person tweeted it. Sad."

Adobe has since confirmed the hole which affects the current version of Adobe Reader for Windows, Mac OS X and Unix and can be exploited to inject arbitrary code into a system and execute it there. Whether older versions are also vulnerable remains unclear. Adobe said they are working on a patch and are currently determining whether the information disclosed by Miller warrants an out-of-schedule update or whether to fix the flaw on the next scheduled patch day. So far, there have been no signs that the hole is being exploited in the wild.


---------------------------------------

For more information on the new Adobe Reader vulnerability....
http://secunia.com/advisories/40766

This vulnerability should not be confused with the PDF exploit that is being used to jailbreak the iPhone 4. The exploits works by taking advatage of a hole in the Apple's Mobile Safari browser. Then another local privilege esclation vulnerability (in the kernel) is used to faliciate the jailbreak.

Apple iOS Security Bypass and PDF File Processing Vulnerability
http://secunia.com/advisories/40807/

However, the PDF used to jailbreak the iPhone was found to cause crashes in Foxit Reader. Foxit reader has since released Foxit Reader v4.1.1.0805 to address the crash issues.

Tuesday, August 3, 2010

Project Grey Goose: Identify Governments with RIM Encryption Keys

http://greylogic.us/2010/08/03/new-project-grey-goose-task-identify-governments-with-rim-encryption-keys/

I recently wrote a post for Forbes.com on how Research In Motion has quietly been making deals to provide encryption keys to the Russian and Chinese governments, with India in the queue for a set as well, while the UAE and Saudi Arabia are threatening to kick RIM out of their respective countries unless they get the same access.

My issue with this is not that RIM is abiding by the laws of the nation within whose borders they want to conduct business. That’s what companies do – Google’s dealings with China being the latest example. The issue that has prompted this Project Grey Goose investigation is RIM’s lack of transparency regarding which governments have the ability to monitor their customers message traffic and which do not. That is a critical bit of data for enterprise blackberry users to know who, by virtue of their place of employment, are high value targets for cyber attacks including espionage by state or state-sponsored actors.

Research In Motion executives are invited to provide an accurate accounting at any time. In the meantime, if you’d like to participate in discovering which other countries have the ability to decrypt your Blackberry’s email or other encrypted messages, please let me know via the Contact button on this website.

ZDI Disclosure Deadline: Putting Pressure on Tardy Software Vendors

Via ZDnet.com -

Looking to put pressure on software vendors who procrastinate of fixing security flaws, the world’s biggest broker of vulnerability data is drawing a line in the sand.

Starting tomorrow (August 4, 2010), TippingPoint’s Zero Day Initiative (ZDI) will enforce a six-month deadline for patches on all vulnerabilities bought from the security research community and reported to software vendors.

TippingPoint, a program that purchases the rights to vulnerability information in exchange for exclusivity to broker fixes with affected vendors, says the new six-month deadline will apply to all currently outstanding issues.

“We have about 31 outstanding issues that are more than a year old. We believe that’s an unacceptable window of exposure [to risk],” says Aaron Portnoy (left), manager of the security research team at TippingPoint Technologies.

For example, according to ZDI’s public upcoming advisories listing, there are at least a half-dozen high-risk vulnerabilities affecting IBM software that are more than 600 days outstanding.

Microsoft, RealNetworks, Symantec, CA and Novell are also among the most tardy vendors, according to ZDI’s list.

There are about 90 vulnerabilities in TippingPoint’s queue that are more than six months old.

Portnoy says the company may extend the six-month deadline “on a case-by-case basis” if there is evidence that there are technical complications to shipping patches within that time frame. In cases where extensions are granted, ZDI will publicly document the entire communication process with the affected vendor to ensure there is transparency with affected users.

However, once the deadline expires, ZDI plans to publish a limited advisory with details about the vulnerability and affected software to help the defensive/security community come up with applicable mitigations. ”We want to make sure this window of risk is reduced and help people protect their systems.

ZDI won’t be releasing full technical details of the flaws or proof-of-concept/exploit code.

We think this will push vendors in the right direction,” Portnoy said in an interview.

------------------------------------

Releasing limited information about the vulnerability to help simulate discussion on possible threat mitigation is a very positive thing. Kudos to ZDI for putting the security of the community first.

Debunking Seven Myths About Zero Day Vulnerabilities

Via ZDNet -

Another month, another zero day flaw has been reported, with malicious attackers logically taking advantage of the window of opportunity, by launching malware serving attacks using it. With vendor X putting millions of users in a “stay tuned mode” for weeks, sometimes even longer, the myths and speculations surrounding the actual applicability of zero day flaws within the cybercrime ecosystem, continue increasing.

Are zero day flaws what the bad guys are always looking for? Just how prevalent are zero day flaws within their business model? Are zero day flaws crucial for the success of targeted attacks attacks?

Let’s debunk seven myths about zero day flaws, using publicly obtainable data, an inside view of the cybercrime ecosystem, and, of course, common sense like the one malicious attackers seem to possess these days.

-----------------------------------

Pretty good write-up.

Malware is more likely to be installed using an old (aka patches exist, not just installed) Java, Adobe, Quicktime, Realpayer or Microsoft vulnerability then any zero-day.

New Safari Bug Being Used to Jailbreak iPhone 4

Via Threatpost.com -

A Web site set up to help iPhone users jailbreak their devices is using a flaw in the way that the iPhone handles PDF files to escape the phone's sandbox security function and enable users to load applications that aren't in Apple's official App Store. The same flaw could easily be used to install malicious software in drive-by download attacks, experts say.

The Jailbreakme.com site is designed to help users jailbreak their phones, which gives them the ability to circumvent Apple's process for approving iPhone apps and load apps from any source they choose. Such sites are not new, but the new service on Jailbreakme.com appears to use a previously unknown vulnerability in the iPhone. Initial reports indicated that the vulnerability was in the mobile version of Apple's Safari browser. But it now appears that the problem is in a component meant to be used for displaying PDFs.

The iPhone doesn't have a mobile version of the Adobe Reader software and instead reads PDF files natively. So the technique that Jailbreakme.com is using likely is exploiting a new bug in the iPhone itself, experts say. The iPhone has several security protections in place that are designed both to prevent malicious code from running on the device and also to stop users from loading unapproved apps on the phone.

Adobe security and privacy chief Brad Arkin said that the company does not have any evidence to indicate that Reader is involved in the exploit.


---------------------------------------------------------------------

http://www.f-secure.com/weblog/archives/00002002.html

The iOS drive-by jailbreak available at jailbreakme.com utilizes a PDF exploit. The PDF files, 20 of them, for various combinations of hardware/firmware, are located in a subdirectory off the root of the website.
----------------------------------------------------------------------

Adobe Security & Privacy Chief Brad Arkin said the following on twitter yesterday...
The jailbreakme PDF appears to exploit a flaw in mobile Safari. Quick testing indicates Adobe Reader 9.3.3 is not vulnerable.
----------------------------------------------------------------------

In a fun twist of faith, those users that have jailbroken their phones can install the "PDF Loading Warner" app from Cydia and help mitigate the vulnerability by canceling any PDF load.

As Attacks Escalate, Microsoft Ships Emergency Windows Patch

Via Threatpost.com -

Microsoft has rushed out and emergency patch for all supported versions of Windows to cover a gaping -- and under attack -- security flaw in the way shortcuts are displayed by the operating system.

The out-of-band update, rated “critical,” comes less than 20 days after the discovery of a sophisticated malware attack that combined the Windows zero-day flaw with security problems in SCADA systems and used stolen signed drivers to bypass security software.

Copycat attackers also added exploits for the Windows vulnerability into malware families, putting pressure on Redmond to release today’s emergency fix.

-------------------------------------------------------

http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx

This security update resolves a publicly disclosed vulnerability in Windows Shell. The vulnerability could allow remote code execution if the icon of a specially crafted shortcut is displayed. An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

-------------------------------------------------------

Windows 2000 and Windows XP Service Pack 2 are vulnerable, but are no longer officially supported by Microsoft. Upgrading is the only protection option for those older operating systems.

QuickTime Player Streaming Debug Error Logging Buffer Overflow

http://secunia.com/advisories/40729/

Krystian Kloskowski has discovered a vulnerability in QuickTime Player, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in QuickTimeStreaming.qtx when constructing a string to write to a debug log file. This can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into viewing a specially crafted web page that references a SMIL file containing an overly long URL.

Successful exploitation allows execution of arbitrary code.

The vulnerability is confirmed in version 7.6.6 (1671) for Windows. Other versions may also be affected.


-----------------------------------------

Reports indicate that removing the QuickTimeStreaming.qtx file is an effective mitigation, however it will kill your ability to watch streaming content in QT.

Sunday, August 1, 2010

Saudi Telco Regulator To Ban BlackBerry Messenger Service

Via WSJ.com -

Saudi Arabia's telecom watchdog has ordered telecom firms operating in the kingdom to stop BlackBerry messenger services later this month, an official said Sunday, hours after regulators in the United Arab Emirates said they would prohibit some BlackBerry services from October.

The Communications and Information Technology Commission, or CITC, issued a memo to operators asking them to block the service, the official, who asked not to be named, told Zawya Dow Jones. He declined to give a reason for the ban.

The United Arab Emirates telecom regulator said earlier Sunday it would prohibit BlackBerry instant messaging, email and Internet-browsing services starting Oct. 11 amid an ongoing dispute between Canada's Research In Motion (RIMM, RIM.T), the maker of the device, and U.A.E. officials over the monitoring of data.

Abdulrahman Mazi, a board member of state-controlled Saudi Telecom Co. (7010.SA) confirmed the watchdog's action to Dubai-based Al Arabiya television, adding that he hoped the move is "only a kind of pressure on [Blackberry maker] Research In Motion to take steps to provide information when needed."

Saudi Telecom alone has about 400,000 Blackberry users in the kingdom, while its other two rivals have about 290,000 customers in total. "CITC is adding its voice to the growing concerns over monitoring Blackberry Messenger service," said Asim Shuja Bukhtiar, senior investment analyst at Riyad Capital.

"The broader issue is regulatory concerns around email and web browsing--this in our view can impact operators' corporate customers and business travelers to the region. Eventually, RIM may come around to providing some sort of monitoring mechanism," he said.

------------------------------------------------------

Basically SA and UAE are unhappy because they are unable to break the RIM encryption and spy on their citizens...errr, I mean monitor the mobile activity of their citizens. ;)

Blackhat 2010 & Defcon 18

As many of you may know, this week was Blackhat 2010 and Defcon 18 - hence the recent silence.

Both conference has tons of great talks...some of which I was able to attend and many I was not. I won't re-hash those talks here, as the general security media is all over them. I was personally in Barnaby Jack's ATM talk..and it was awesome, to say the last.

Here is a video of the other machine booted on a custom firmware [using a USB stick] and ordered to empty the machine - http://www.youtube.com/watch?v=fS3Z8Xv-vUc

Luckily I was able to catch up with some friends and share beers as well.