Monday, July 6, 2009

Whitepaper: From 0 to 0Day on Symbian

Being the most widespread smartphone operating system, Symbian OS is a worthwile target for remote attacks. However, the obscurity of the operating system, combined with restrictions placed on end user devices and a lack of tools, make it very difficult for security researchers to work with Symbian based phones.

The goal of this whitepaper is to show that classic vulnerability analysis and exploitation is possible on Symbian OS smartphones. To this end, a set of methods and tools have been developed, and readily available standard software provided by Symbian has been modified to support debugging of memory mapped execute-in-place ROM. In this paper we will:
  1. Show how to statically analyze XIP ROM images (dumping, restoring import export tables, searching for unsafe function calls)
  2. Show how to enable run mode debugging of system binaries running from ROM IDA Pro, by patching the AppTRK debug agent
  3. Show other of the modified AppTRK. As an example, we will show a fully automated multimedia file fuzzer
  4. List and analyze the results of fuzzing the video- and audio codecs shipped with current Nokia smartphones
  5. Discuss further ideas and concepts, such as jailbreak shellcode, and an IRC bot trojan for Symbian
The paper aims to show that it is possible to find and exploit bugs on Symbian phones (even in preinstalled system applications) without having access to special development hardware, and that exploits and worms similar to those found on desktop systems may be possible on Symbian based smartphones.

-----------------------------

https://www.sec-consult.com/files/SEC_Consult_Vulnerability_Lab_Pwning_Symbian_V1.03_PUBLIC.pdf

Sunday, July 5, 2009

Intermediate Class of Black Holes Discovered, Indicating Black Holes Join

Via ScienceAlert.au.com -

The first solid evidence of a new class of medium-sized black holes has been discovered in a distant galaxy by an international team of astronomers.

The black hole is more than 500 times the mass of the Sun, the researchers report in the journal Nature.

Until now, identified black holes have been either super-massive (several million to several billion times the mass of the Sun) in the centre of galaxies, or about the size of a typical star (between three and 20 Solar masses).

The team, led by astrophysicists at the Centre d'Etude Spatiale des Rayonnements in France, detected the new black hole approximately 290 million light years from Earth with the European Space Agency's XMM-Newton X-ray space telescope.

[...]

It had been long believed by astrophysicists that there might be a third, intermediate class of black holes, with masses between a hundred and several hundred thousand times that of the Sun. However, such black holes had not been reliably detected until now.

"While it is widely accepted that stellar mass black holes are created during the death throes of massive stars, it is still unknown how super-massive black holes are formed," says a member of the team, Dr Sean Farrell, who recently completed his PhD studies at the Campus of the University of New South Wales at the Australian Defence Force Academy and now works at the University of Leicester, UK.

"One theory is that super-massive black holes may be formed by the merger of a number of intermediate mass black holes. To ratify such a theory, however, you must first prove the existence of intermediate black holes.

"The identification of HLX-1 is therefore an important step towards a better understanding of the formation of the super-massive black holes that exist at the centre of the Milky Way and other galaxies."

This new source, identified as HLX-1 (Hyper-Luminous X-ray source 1), lies towards the edge of the galaxy ESO 243-49. It is ultra-luminous in X-rays, with a maximum X-ray brightness of approximately 260 million times that of the Sun.

The X-ray signature of HLX-1 and the lack of a counterpart in optical images confirm that it is neither a foreground star nor a background galaxy, and its position indicates that it is not the central engine of that galaxy.

Using XMM-Newton observations carried out on the 23rd November 2004 and the 28th November 2008, the team showed that HLX-1 displayed a variation in its X-ray signature. This indicated that it must be a single object and not a group of many fainter sources. The huge radiance observed can only be explained if HLX-1 contains a black hole more than 500 times the mass of the Sun. No other physical explanation can account for the data.

China's Green Dam Install Requirement is Only a Matter of Time

Via ChinaDaily.com -

Despite a last-minute delay in implementing Green Dam internet-filtering software, China's authorities and its PC manufacturers said Wednesday they expect the tool will end up on new computers.

One day after the Ministry of Industry and Information Technology (MIIT) declared a postponement to the July 1 start date for the mandatory inclusion of "Green Dam-Youth Escort" porn filtering software, an MIIT official said it was only "a matter of time" before the directive took effect.

"The government will definitely carry on the directive on Green Dam. It's just a matter of time," he told China Daily on condition of anonymity.

An earlier directive to all PC makers on May 19 said the pre-installation of the filtering software would be mandatory on July 1 for any new PC produced or sold in China.

The official said issues around potential copyright infringement were not behind the delay - it was simply because some computer manufacturers needed more time.

"What will happen is that some PC manufacturers will have it included with their PC packages sooner than the others," he said. "But there is no definite deadline at the moment."

Domestic PC giants, including Lenovo Group, Tsinghua Tongfang, Founder Technology Group and Haier Group, said Wednesday they will "install the filter as they were told". But some manufacturers have included a disclaimer with new PCs, saying they would not be responsible for damage caused by Green Dam.

Foreign PC makers were not available for comment.

Robert Rains, assistant information officer at the US embassy in Beijing, said the US authorities were "looking forward to engaging in further dialogues with the related Chinese authorities on this matter".

Teams Track People with Bluetooth at Werchter Rock Festival

Via Yahoo! News (Reuters) -

Researchers are using Bluetooth technology to observe the meanderings of tens of thousands of festival-goers at a top European rock festival, hoping their findings will launch a new generation of tracking devices.

The team from the University of Ghent in Belgium believes the research could yield new satellite navigation applications for the retail and security sectors.

"We have installed 36 Bluetooth scanners across the site and along a few surrounding roads, as well as bus stops," the university's Nico Van de Weghe said on Friday of the project at the Werchter festival, northeast of Brussels this weekend.

Within a radius of 30 meters, the scanners track mobile phones equipped with Bluetooth, a type of short-range wireless technology which allows different devices to connect with one another, often to transfer files.

But the masses flocking to see Coldplay, Kings of Leon or Metallica need not worry about their privacy, Van de Weghe said.

The researchers will only track the devices' MAC address -- a number that identifies each device on a network -- which cannot be traced to phone numbers or personal details.

"Werchter is a very interesting case," Van de Weghe told Reuters, adding that this is the first time his team, working on a wider research project using new technology to track moving objects, will collect full data on a live situation.

The team is carrying out research on geographical information systems, such as satellite navigation systems, and is hoping to be able to track moving objects in real time.

"Tracking movements via Bluetooth could become very interesting. It could help retailers keep track of the number of customers numbers at different times, " Van de Weghe said.

The technique could also be used by security services to track suspicious movements, or monitor evacuations at mass events.

Some 80,000 people from across Europe attended a sweltering first day of the festival in the small town of Werchter, 40 km (25 miles) northeast of Brussels, on Thursday, with thousands more expected on Friday and over the weekend.

Pakistan's Nuclear Weapons Face Threat from Insiders

Via Times of India -

Pakistan's atomic weapons face the threat from insiders in the nuclear establishment colluding with outsiders, as authorities there have "a dismal track record" in thwarting such dangers, a former top American intelligence official has warned.

"The greatest threat of a loose nuke scenario stems from insiders in the nuclear establishment working with outsiders, people seeking a bomb or material to make a bomb", said Rolf Mowatt-Larssen, who served as a CIA officer for 23 years.

"Nowhere in the world is this threat greater than in Pakistan. Pakistani authorities have a dismal track record in thwarting insider threats," Mowatt-Larssen said in the July/August issue of Arms Control Today, published by the Arms Control Association.

He underlined that the network run by the father of the Pakistani bomb, Abdul Qadeer Khan, channeled sensitive nuclear technologies to Iran, Libya, and North Korea for years under the noses of the establishment before it was taken down in 2003, to the best of our knowledge.

The Umma-Tameer-e-Nau (UTN), founded by Pakistani nuclear scientists with close ties to al-Qaida and the Taliban, was headed by Sultan Bashiruddin Mahmood, who had been in charge of Pakistan's Khushab reactor.

"It is stunning to consider that two of the founding fathers of Pakistan's weapons programme embarked independently on clandestine efforts to organize networks to sell their country's most precious secrets for profit," Mowatt-Larssen stressed.

NSA Plans Massive Data Center in Utah

Via The Register UK -

The ultra-secretive National Security Agency plans to build a 1-million-square-foot data center in Utah as it seeks to decentralize its computing resources and tap regions with ample supplies of lower-cost electricity.

When completed, the facility will require at least 65 megawatts of power and cost $1.93bn, according to news reports. The 120-acre data center will be located in Utah's Camp Williams, which borders Salt Lake and Tooele counties. Two major power corridors already run through the spot, a major reason the NSA chose it.

The plans help demonstrate how power is emerging as one of the biggest costs in building and running today's data centers. During an initial building phase with a budget of $181m, $52m will be spent in preparatory electrical work, including connecting the two corridors. Later phases will include $340m in electrical work.

The Utah facility will be the NSA's third major data center. In 2006, the Baltimore Sun reported the agency's Fort Meade location maxed out the capacity of the Baltimore area power grid, preventing the installation of new supercomputers that had been planned. In 2007, the NSA announced plans to build a second data center in San Antonio, Texas. The agency is expanding existing intelligence-collection facilities in the UK's North Yorkshire, as well.

The supercomputers will be part of the NSA's signal intelligence program, whose mission is to "gain a decisive information advantage for the nation and our allies under all circumstances," according to The Salt Lake Tribune, which cited Congressional documents. Additional coverage is here, and here.

The articles came around the same time The Washington Post reported that the Obama administration will proceed with a Bush-era plan to use NSA assistance is screening government computer traffic on private-sector networks. The plan is controversial because of the NSA's involvement in warrantless wiretapping of US citizens.

The program will scrutinize only data traveling to or from government systems, but it has provoked debate within the US Department of Homeland Security because of uncertainty about whether private data can be shielded from unauthorized scrutiny.

Friday, July 3, 2009

Syria: Al Assad Removes Military Intelligence Director

Via Stratfor -

Syrian President Bashar al-Assad has removed his brother-in-law Asef Shawkat, who is suspected of involvement in the assassination of former Lebanese Prime Minister Rafik al-Hariri, from his position as military intelligence director, Deutsche Presse-Agentur reported July 3, citing Syrian Web site All4Syria.info. Shawkat has held the post of military intelligence director since Feb. 14, 2005, the day al-Hariri was killed. He has now been appointed deputy chief of staff for the army.

------------------------

As cited above, All4Syria.info outlined the changes in Syrian military intelligence....

See Google's attempt at an English translation.

For some background information on Asef Shawkat, check out BBC's Who's Who in Syria's Leadership.

Air Force: Lockheed's AGM-158 JASSM Program May be Killed

Via Bloomberg.com -

A $6 billion Lockheed Martin Corp. cruise missile program may be terminated if its testing record doesn’t improve, according to the U.S. Air Force.

The weapon was declared combat-ready five years ago and has been deployed even though it has a history of failure in testing. Four of 10 missiles tested during November, January and February didn’t detonate on impact or hit the target -- a reliability rate of 60 percent. The Air Force demands a rate of at least 80 percent and the program is expected to reach 90 percent within four years.

Lockheed, the world’s largest defense company, was told that failure in the next round of testing could have a potentially “significant” impact on funding and the program may be terminated, Air Force spokeswoman Lieutenant Colonel Karen Platt said in an e-mailed statement.

At risk is $4 billion in future orders for as many as 3,847 of the so-called Joint Air-to-Surface-Standoff Missile, Platt said. Lockheed currently has 1,053 missiles on contract.

Platt said a decision to kill the program would be up to the Pentagon’s weapons-buying office and likely would be deferred until after the next round of testing, which is expected to begin “in late summer or early fall.”

-----------------------------------------------



More information about the AGM-158 JASSM cruise missile program...
http://www.fas.org/man/dod-101/sys/smart/jassm.htm
http://en.wikipedia.org/wiki/AGM-158_JASSM

Two Bahrainis Targeted US Navy Ships & Personnel at Mina Salman

Via Military.com -

U.S. Navy ships in Bahrain were the target of an alleged terror attack, prosecutors here claimed in court yesterday.

Two Bahrainis, accused of smuggling weapons into the country, planned to attack U.S. ships and personnel at Mina Salman, say prosecutors.

The two men, aged 22 and 21, were arrested on April 26 -- the day of the Gulf Air Bahrain Grand Prix -- when police allegedly seized machine guns, weapons, computer discs and other evidence from their homes in East Riffa.

Both appeared for the first time yesterday before the High Criminal Court, where they denied plotting terror attacks and smuggling weapons and ammunition into the country.

Police believe the pair had met abroad with members of a terrorist cell, al-Qaeda.

Their arrest came after National Security Agency received information that the 22-year-old unemployed man, of Jordanian origin, had intensified contacts with the cell in Iran.

Officers obtained a search warrant and found tapes, CDs, computers, bank statements and exchange company documents in his house.

He then led police to the other -- a 21-year-old junior customs officer -- who possessed the smuggled weapons.

Police raided his house and found two machine guns, a pistol, bullets, knives and swords, the court heard.

They also seized several books on building missiles, rockets, weapons and explosives, and pictures of the American Base and Navy ships along with research and videos on jehad, alleged prosecutors.

During questioning, the younger defendant confessed to planning an attack on U.S. forces at Mina Salman, said court documents.

[...]

The men allegedly carried out their plans and preparations for the attack during 2007 and 2008, according to trial documents.

They allegedly confessed, during questioning, to smuggling the weapons and ammunition from Jordan to use in a plot against American soldiers.

Hashim earlier claimed the guns, capable of firing 30 bullets per second, were smuggled into Bahrain to defend it from possible attack by Iran.

He told the GDN that the only reason they were acquired was to protect the country after claims that it was a province of Iran.

The GDN reported earlier that an Interior Ministry statement alleged the men were part of a terror network plotting attacks in Bahrain and elsewhere in the Gulf.

It also claimed they had met other members of a terrorist cell abroad.

Interior Minister Shaikh Rashid bin Abdulla Al Khalifa said at the time of the arrest that the men were rounded up after allegedly intensifying contacts with the terror cell abroad, travelling to a neighbouring Arab country, buying weapons and ammunition and smuggling them into Bahrain.

Both men reportedly confessed to plotting terrorist attacks and gave names of accomplices in Arab and foreign countries

Two Centuries On, a Cryptologist Cracks a Presidential Code

Via WSJ.com -

For more than 200 years, buried deep within Thomas Jefferson's correspondence and papers, there lay a mysterious cipher -- a coded message that appears to have remained unsolved. Until now.

The cryptic message was sent to President Jefferson in December 1801 by his friend and frequent correspondent, Robert Patterson, a mathematics professor at the University of Pennsylvania. President Jefferson and Mr. Patterson were both officials at the American Philosophical Society -- a group that promoted scholarly research in the sciences and humanities -- and were enthusiasts of ciphers and other codes, regularly exchanging letters about them.

In this message, Mr. Patterson set out to show the president and primary author of the Declaration of Independence what he deemed to be a nearly flawless cipher. "The art of secret writing," or writing in cipher, has "engaged the attention both of the states-man & philosopher for many ages," Mr. Patterson wrote. But, he added, most ciphers fall "far short of perfection."

To Mr. Patterson's view, a perfect code had four properties: It should be adaptable to all languages; it should be simple to learn and memorize; it should be easy to write and to read; and most important of all, "it should be absolutely inscrutable to all unacquainted with the particular key or secret for decyphering."

Mr. Patterson then included in the letter an example of a message in his cipher, one that would be so difficult to decode that it would "defy the united ingenuity of the whole human race," he wrote.

There is no evidence that Jefferson, or anyone else for that matter, ever solved the code. But Jefferson did believe the cipher was so inscrutable that he considered having the State Department use it, and passed it on to the ambassador to France, Robert Livingston.

The cipher finally met its match in Lawren Smithline, a 36-year-old mathematician. Dr. Smithline has a Ph.D. in mathematics and now works professionally with cryptology, or code-breaking, at the Center for Communications Research in Princeton, N.J., a division of the Institute for Defense Analyses.

[...]

The code, Mr. Patterson made clear in his letter, was not a simple substitution cipher.

[...]

Because frequency analysis was already well known in the 19th century, cryptographers of the time turned to other techniques. One was called the nomenclator: a catalog of numbers, each standing for a word, syllable, phrase or letter. Mr. Jefferson's correspondence shows that he used several code books of nomenclators. An issue with these tools, according to Mr. Patterson's criteria, is that a nomenclator is too tough to memorize.

[...]

To get a sense of language patterns of the era, Dr. Smithline studied the 80,000 letter-characters contained in Jefferson's State of the Union addresses, and counted the frequency of occurrences of "aa," "ab," "ac," through "zz."

Dr. Smithline then made a series of educated guesses, such as the number of rows per section, which two rows belong next to each other, and the number of random letters inserted into a line.

To help vet his guesses, he turned to a tool not available during the 19th century: a computer algorithm. He used what's called "dynamic programming," which solves large problems by breaking puzzles down into smaller pieces and linking together the solutions.

The overall calculations necessary to solve the puzzle were fewer than 100,000, which Dr. Smithline says would be "tedious in the 19th century, but doable."

After about a week of working on the puzzle, the numerical key to Mr. Patterson's cipher emerged -- 13, 34, 57, 65, 22, 78, 49. Using that digital key, he was able to unfurl the cipher's text:

"In Congress, July Fourth, one thousand seven hundred and seventy six. A declaration by the Representatives of the United States of America in Congress assembled. When in the course of human events..."

That, of course, is the beginning -- with a few liberties taken -- to the Declaration of Independence, written at least in part by Jefferson himself. "Patterson played this little joke on Thomas Jefferson," says Dr. Smithline. "And nobody knew until now."

Purple Ra1n - iPhone 3GS Unlocking Tool

Via BetaNews -

In a comically blatant display of bravado this morning, George Hotz -- who gained fame last year as the first to post an unlocking utility for the new Apple iPhone -- has unveiled a new utility that he claims enables iPhone 3G S users to download, install, and utilize the applications of their choice, outside of Apple's and AT&T's control.

In so doing, Hotz -- who uses the handle "GeoHot" -- publicly paraded his prowess in front of Dev-Team, the independent group of iPhone developers who had been racing to produce a similar tool for this latest model. Complete with poor punctuation and curious references to "holes," Hotz wrote, "Normally I don't make tools for the general public, and rather wait for the dev team to do it. But guys, whats up with waiting until 3.1? That isn't how the game is played. We release, Apple fixes, we find new holes. It isn't worth waiting because you might have the 'last' hole in the iPhone. What last hole...this isn't golf. I'll find a new one next week."

The Purple Ra1n tool is currently for Windows users only, though Hotz says a Mac OS X version is on the way. 3G S users need the latest edition of iTunes installed. Although this tool apparently will not go so far as to dissolve the bonds between the 3G S and the AT&T exclusive carrier (which was a key feature of Hotz' last tour de force), a test by CrunchGear's John Biggs appears to verify that a relatively simple process may lead to 3G S users installing the apps of their choice.

Hotz' news came just hours after the Dev-Team, in its own blog, pleaded with its own loyal readers to wait just a little while longer. Its own Ultrasn0w tool (whose symbolism may also have been capitalized upon by Hotz' Purple Ra1n) is reportedly capable of being used with the 3G S without modifications, the team says, after having discovered that an exploit that affected the 3G's ROMs and led to its jailbreak-ability, can also be used with 3G S as well.

Thursday, July 2, 2009

MD6 Withdrawn from SHA-3 Competition

Via Schneier on Security -

In other SHA-3 news, Ron Rivest seems to have withdrawn MD6 from the SHA-3 competition. From an e-mail to a NIST mailing list:
We suggest that MD6 is not yet ready for the next SHA-3 round, and we also provide some suggestions for NIST as the contest moves forward.

Basically, the issue is that in order for MD6 to be fast enough to be competitive, the designers have to reduce the number of rounds down to 30-40, and at those rounds, the algorithm loses its proofs of resistance to differential attacks.

Thus, while MD6 appears to be a robust and secure cryptographic hash algorithm, and has much merit for multi-core processors, our inability to provide a proof of security for a reduced-round (and possibly tweaked) version of MD6 against differential attacks suggests that MD6 is not ready for consideration for the next SHA-3 round.

EDITED TO ADD (7/1): This is a very classy withdrawal, as we expect from Ron Rivest -- especially given the fact that there are no attacks on it, while other algorithms have been seriously broken and their submitters keep trying to pretend that no one has noticed.

U.S. Soldier Captured & Sold to Afghan Militant Clan

Via CNN -

The American soldier abducted in southeastern Afghanistan is now being held by a notorious militant clan, a senior U.S. military official said.

This soldier and three Afghan soldiers were captured by low-level militants and then quickly "sold" to the clan and network led by warlord Siraj Haqqani -- believed to be deeply involved in the action.

The Haqqanis -- who operate on both sides of the Afghanistan-Pakistan border and are well known to the U.S. military -- are assembling shuras, or local councils of leaders, to talk and try to "legitimize" what they have done, the official said.

U.S., Afghan and Pakistani troops are sealing off the area and also are talking to tribal chiefs, village elders and leaders.

They are telling them to "do the right thing and solve this," the official said.

The U.S. military is telling people not to let Haqqani operatives move through their area and to find the American and return him. The military wants to make sure there is "no shelter" for the militants holding him.

"We want to make sure there is no place to hide," the official said.

The soldier, missing since Tuesday, did apparently leave his small outpost on his own with no apparent means of defending himself, and the U.S. military believes a video of him is forthcoming.

The Taliban earlier claimed responsibility for the abduction. The U.S. soldier was kidnapped along with three Afghan soldiers, Taliban commander Mulvi Sangeen said.

Saudi Arabia: Authorities Arrest Al-Qaeda Point Man

Via Asharq Alawest -

Dammam, Asharq Al-Awsat- Saudi security authorities arrested a member of the Al-Qaeda organization whose name was not on the list of 85 wanted persons recently announced by the Saudi Interior Ministry. The security forces faced armed resistance when they arrested the individual and believe that he had an active relationship with the terrorist organization's cadres abroad.

The Saudi Interior Ministry said the monitoring the individual uncovered his direct relationship with the organization abroad. Moreover, information obtained by Asharq al-Awsat indicated that the wanted person was active in smuggling Saudi returnees from Guantanamo and wanted members of the organization in Saudi Arabia into a neighboring country and that the security organs had been pursuing the detainee for the past few months.

Interior Ministry Security Spokesman Major General Mansur al-Turki confirmed to Asharq al-Awsat yesterday that the detainee was not on the list of 85 and had direct contact with the organization abroad. As to the nature of relationship with Al-Qaeda organization outside the country, this will become clear from the investigations that Saudi security are having with the detainees, according to Al-Turki.

Unofficial information obtained by Asharq Al-Awsat yesterday indicates that the detainee is in his thirties and was active in recruiting Saudis, among them returnees from Guantanamo, and members of Al-Qaeda organization who are active in a neighboring country. The information also indicated that the security organs sources have been pursuing him for several months and he was monitored inside a low-income house in Al-Sadah neighborhood, Buraydah city, Al-Qasim region. Maj. Gen. Al-Turki said "the interest of the investigations requires that no information about his activities is given."

Security Guard Charged with Hacking Hospital Systems

Via Computerworld -

The grainy video shows a bleary-eyed young man in a hoodie inside the Carrell Clinic in Dallas. As he hits the elevator button, the theme music from Mission Impossible plays in the background. "You're on a mission with me: Infiltration," he says to the camera.

Then in the course of the next five minutes, the man, who says he hasn't slept in three days, uses a security key to roam the halls of the hospital and install malicious botnet software on a computer there.

He says he's "infiltrated a very large corporate office," but according to the FBI, he was just working the night shift as a security guard, pretending to break into the very building he was supposed to be guarding.

On Friday the federal authorities arrested the man in the video, Jesse William McGraw, on a charge of felony computer intrusion, saying he intended to use the botnet to launch a massive distributed denial-of-service (DDoS) attack on July 4, the day after he was set to stop working there. He'd nicknamed the day "Devil's Day."

McGraw was an employee of a Dallas security company called United Protection Services; he worked the 11 p.m. to 7 a.m. shift at the clinic.

McGraw, who went by the hacker name GhostExodus, allegedly installed malicious software in computers all over the Carrell Clinic, including systems that contained confidential information and others that managed the building's climate-control systems, authorities said Tuesday.

The hacker could have harmed patients or damaged supplies of drugs if he had turned off air conditioning during the hot Texas summer, authorities said.

GhostExodus' Mission Impossible video was one of several that he posted to YouTube. They have since been removed, but copies were seen by the IDG News Service. One video named in court filings that was not deleted shows him skillfully playing a violin.

GhostExodus may have seen his arrest coming.

In a March 14 online journal entry, he said that an enemy was fabricating evidence against him and that he was erasing his tracks, but he did leave some tracks on the Web. For example, there's a May 24 forum post in which he brags about his hacking and posts screenshots of the administrative interface to the hospital's heating, ventilation and air conditioning systems. "Spreading botnets is boring. But sometimes you get a hefty prize for all your hard work and labor," he wrote. "Like this you see below. An HVAC server."

McGraw talks like a big-time spy, but he makes some silly mistakes. In one video he puts on surgical gloves -- presumably to hide his fingerprints -- after typing on the computer he plans to hack. In another, he crops the video so that his face is not visible, but then shows off a fake FBI identity card -- with his picture on it. Then there's the fact that he posted the whole thing on YouTube.

His undoing came when a member of his hacker group, called the Electronik Tribulation Army, boasted to security researcher Wesley McGrew and showed him screen shots of hacked machines. That hacker, who went by the name XXxxImmortalxxXX, claimed to have hacked the Carrell Clinic systems, but McGrew soon linked the crime to GhostExodus and handed over his findings to authorities.

The group also compromised computers used by the Dallas Police and NASA, the FBI said in an affidavit. According to GhostExodus' journal, he appears to have found a cross-site scripting bug -- a common Web programming error -- on NASA's Web site.

Serious SMS Vulnerability Discovered for the iPhone

Via Computerworld.com -

Apple is working to fix an iPhone vulnerability that could allow an attacker to remotely install and run unsigned software code with root access to the phone.

The attack in question exploits a weakness in the way iPhones handle text messages received via SMS (Short Message Service), said security researcher Charlie Miller, during a presentation at the SyScan conference in Singapore on Thursday. He didn't provide a detailed description of the SMS vulnerability, citing an agreement with Apple.

[...]

The SMS vulnerability allows an attacker to run software code on the phone that is sent by SMS over a mobile operator's network. The malicious code could include commands to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet, Miller said.

Apple is working to patch the vulnerability and expects to have a fix ready later this month, before Miller discusses the attack in greater detail during a planned presentation at the Black Hat USA conference in Las Vegas.

[...]

The iPhone also requires applications to run in a sandbox, a security feature that isolates them from other applications and limits their access to the phone's capabilities. But SMS offers a way for attackers to get greater access to the phone's capabilities, Miller said.

"SMS is a great vector to attack the iPhone," he said.

Most often used to send brief text messages between cell phones, SMS can also send binary code to an iPhone, which then processes the code without any user interaction. Each SMS message is limited to 140 bytes, but longer sequences can be sent to the phone as multiple messages that are automatically reassembled.

This feature allows larger programs to be delivered to a phone, Miller said.

In addition, vulnerabilities found in the iPhone's SMS function give an attacker root access to the handset, Miller said. That's not the case for the iPhone's other applications, such as its browser, where vulnerabilities only give an attacker access to the application's sandbox.

----------------------------------

In related news, another couple of researchers plan to release an SMS auditing tool for the iPhone @ Blackhat as part of a talk titled "Attacking SMS".

Green Dam Remote Change System Time Exploit

// GreenDam listens on UDP 1234 & waits for the 4 bytes time value
// We can send some bytes to change the time of the system
// testgreendam[at]gmail.com

http://www.milw0rm.com/exploits/9065

Wednesday, July 1, 2009

National Reconnaissance Office (NRO) Reviewed by Senate Intelligence Committee

Via DoDBuzz.com -

The Senate Intelligence Committee may try to break up the nation’s storied spy satellite agency — the NRO — once a paragon of American technological brilliance and now considered by many a troubled bureaucracy that has had trouble getting the big things right. In parallel, the Director of National Intelligence was briefed June 23 by a panel of distinguished experts about the best path ahead for the National Reconnaissance Office. The panel “considered options to break up NRO or reassign functions but recommended continuation of a single, unified program,” a former senior intelligence official said. The report about the Senate committee came from this same source, a respected insider.

Dennis Blair, director of National Intelligence, has drafted a panel of trusted intelligence experts to revamp the troubled National Reconnaissance Office, builder of America’s multi-billion dollar spy satellites.

The panel, led by Trey Obering, former director of the Missile Defense Agency, includes: Marty Faga, a member of the President’s Intelligence Advisory Board and a former NRO director; Joanne Isham, head of Washington operations for L-1 Identity Solutions and former deputy director of the National Geospatial Intelligence Agency; Paul Kaminski, former undersecretary of Defense for acquisition, technology and logistics who recently penned a study recommending acquisition changes for the NRO; Tom Moorman, a VP at Booz Allen who was named by Space News as one of the 10 most influential space leaders; and Vincent Vitto former president and CEO of the Draper Lab, a private research and development company and vice chairman of the Defense Science Board.

The panel examined every facet of the NRO — its mission, charter, staffing, requirements, organization, funding and relationship to other organizations. One of the key jobs the Obering panel had is drafting a new charter for the NRO. The current charter was drafted 44 years ago and refers to jobs that no longer exist.

The panel’s work “was very well received” by DNI Dennis Blair. In addition to its primary recommendation to essentially keep the NRO structure as is — an amalgam of CIA officials, Air Force officers and some civilians, the panel “made many suggestions on external relationships and internal moves that could make it more effective, the former intelligence official said.

When I asked if this meant a realignment of Air Force and CIA officials, or some changes in how the organization relates to the Defense Department and intelligence community, my source said he was “not sure that relationships will change.”

Terrorist Financing on the Internet

http://www.washingtoninstitute.org/templateC06.php?CID=1302

In response to growing international pressure since the September 11 attacks, al-Qaeda has increasingly relied on the internet to spread its message and gain support throughout the world. In addition, al-Qaeda has used the web's broad reach, timely efficiency, and certain degree of anonymity and security as a conduit for terrorist financing. Unfortunately, al-Qaeda is not the only terrorist group that exploits the internet for financing; groups such as Hamas, Laskhar-e Taiba, and Hizballah also use the internet to raise and transfer funds to support their groups' activities. Although there is broad international agreement that the internet creates serious counterterrorism vulnerabilities and that action is needed to counter this growing threat, there is far less agreement on what steps need to be taken.

Download this article (PDF)

New Attack on AES Encryption Published

Via Schneier on Security -

There's a new cryptanalytic attack on AES that is better than brute force:
Abstract. In this paper we present two related-key attacks on the full AES. For AES-256 we show the first key recovery attack that works for all the keys and has complexity 2119, while the recent attack by Biryukov-Khovratovich-Nikolic works for a weak key class and has higher complexity. The second attack is the first cryptanalysis of the full AES-192. Both our attacks are boomerang attacks, which are based on the recent idea of finding local collisions in block ciphers and enhanced with the boomerang switching techniques to gain free rounds in the middle.

In an e-mail, the authors wrote:

We also expect that a careful analysis may reduce the complexities. As a preliminary result, we think that the complexity of the attack on AES-256 can be lowered from 2119 to about 2110.5 data and time.

We believe that these results may shed a new light on the design of the key-schedules of block ciphers, but they pose no immediate threat for the real world applications that use AES.

Agreed. While this attack is better than brute force -- and some cryptographers will describe the algorithm as "broken" because of it -- it is still far, far beyond our capabilities of computation. The attack is, and probably forever will be, theoretical. But remember: attacks always get better, they never get worse. Others will continue to improve on these numbers. While there's no reason to panic, no reason to stop using AES, no reason to insist that NIST choose another encryption standard, this will certainly be a problem for some of the AES-based SHA-3 candidate hash functions.