Thursday, July 9, 2009

Milw0rm is Back Up and Running - For a While

http://www.milw0rm.com/

st0ke said the following on twitter just 5 mins ago...
milw0rm's back up & posting will start once again, I can't let all of the emails in my submit box to just sit there.
How long it will be up is unknown...and while I have seen some chatter about possible groups taking it over (and running it as it is)...no solid news has been made at this point.

Wednesday, July 8, 2009

Growing Presence in the Courtroom: Cellphone Data as Witness

Via NYTimes -

The pivotal role that cellphone records played in these two prominent New York murder trials this year highlights the surge in law enforcement’s use of increasingly sophisticated cellular tracking techniques to keep tabs on suspects before they are arrested and build criminal cases against them by mapping their past movements.

But cellphone tracking is raising concerns about civil liberties in a debate that pits public safety against privacy rights. Existing laws do not provide clear or uniform guidelines: Federal wiretap laws, outpaced by technological advances, do not explicitly cover the use of cellphone data to pinpoint a person’s location, and local court rulings vary widely across the country.

In one case that unsettled cellphone companies, a sheriff in Alabama told a carrier he needed to track a cellphone in an emergency involving a child — she turned out to be his teenage daughter, who was late returning from a date.

For more than a decade, investigators have been able to match an antenna tower with a cellphone signal to track a phone’s location to within a radius of about 200 yards in urban areas and up to 20 miles in rural areas. Now many more cellphones are equipped with global-positioning technology that makes it possible to pinpoint a user’s position with much greater precision, down to a few dozen yards.

To determine where a suspect’s phone was in the past — as in the Mallayev and Littlejohn cases — investigators use company records that show a phone’s approximate location at the beginning and end of a call.

To track suspects in real time, law enforcement officials must ask a phone company to “ping,” or send a signal to, a phone; for the effort to succeed, the phone must be turned on, though it does not have to be in use. The police can then use a vehicle with signal-tracking equipment to narrow down the location.

The frequency and ease with which law enforcement agencies access cellphone data to track people is difficult to assess. Civil liberties groups recently obtained data from the Justice Department through a lawsuit showing that in some jurisdictions, including New Jersey and Florida, courts often allow federal prosecutors to track the location of cellphone users in real time without search warrants.

Investigators seeking warrants must provide a judge with probable cause that a crime has been committed. But investigators often obtain cell-tracking records under lower standards of judicial review — through subpoenas, which are granted routinely, or through an intermediate type of court order based on an argument that the information requested would be relevant to an investigation.

In what would be the highest-level court decision on the issue so far, a federal appeals court in Pennsylvania is expected to rule this summer on whether search warrants are required for the most basic cellphone tracking data — the electronic footprints that cellphone users leave behind in company records, often without realizing it.

In March, Google announced that it would require search warrants before releasing GPS data that pinpoints the movements of customers who use its mapping applications — like Latitude, which lets people see where their friends are — on their phones.

But phone and Internet companies want Congress to clarify the laws so that they are clear about their legal responsibilities.

Civil libertarians do not oppose using cellphone surveillance to solve crimes or save people in emergencies, but they worry that the legal gray area is enabling it to happen without much scrutiny or discussion.

“The cost of carrying a cellphone should not include the loss of one’s personal privacy,” said Catherine Crump, a lawyer for the American Civil Liberties Union, which filed a lawsuit along with the Electronic Frontier Foundation after the Justice Department did not respond to a Freedom of Information request for data. Federal and local law enforcement officials argue that people who obey the law have nothing to fear from cellphone tracking.

Firefox Stability to Get a Boost with Multiprocess Browsing

Via arstechnica.com -

Mozilla has launched a new project called Electrolysis that aims to bring multiprocess browsing to Firefox. According to Mozilla, splitting up the page rendering workload into multiple processes will improve the browser's performance, security, and stability. The developers have already assembled a prototype that renders a page in a separate process from the interface shell in which it is displayed.

Mozilla has explored the possibility of adopting a multiprocessing approach for Firefox in the past, but the idea didn't gain serious traction in the Firefox developer community until it was implemented by Google and Microsoft in their respective web browsers. Google's Chrome browser uses a separate process for each page, an architectural approach that facilitates much more effective security sandboxing and prevents page-specific rendering glitches from crashing the entire browser. Chrome even includes a process manager tool that can be used to see the status and resource consumption of each page.

[...]

Jones says that his prototype represents the work that the Electrolysis developers have done to meet the requirements specified by "phase I" of Mozilla's multiprocess roadmap. To bootstrap the development of the IPC system, Mozilla is using some code from Chromium, the open source development version of Google's browser. The developers are contemplating the possibility of replacing existing Firefox components, such as the browser's network stack, with additional code from Chromium.

The experimental development work that is being done by various contributors on the Electrolysis project was recently consolidated into a single version control repository. The developers hope to have nightly builds ready for developer testing soon, but they caution that it will not yet work on Mac OS X. They are looking for volunteer Mac developers to participate in the project.

Electrolysis is going to be a truly enormous project. It's not clear yet if it will be ready in time for the next release of Firefox, which is codenamed Namaroka. The work on Electrolysis will be done parallel to Namaroka development, so it will not impede other plans to improve the browser. The early Electrolysis prototype and other parts that have been implemented so far are highly impressive. The project is off to a very promising start and has the potential to bring a lot of value to the Firefox browser and its users.

Milw0rm Closes Up Shop

http://209.85.229.132/search?q=cache:UB9G4tPVbxoJ:www.milw0rm.com/+milw0rm.com&cd=1&hl=es&ct=clnk&gl=es

Well, this is my goodbye header for milw0rm. I wish I had the time I did in the past to post exploits, I just don't :(. For the past 3 months I have actually done a pretty crappy job of getting peoples work out fast enough to be proud of, 0 to 72 hours (taking off weekends) isn't fair to the authors on this site. I appreciate and thank everyone for their support in the past.
Be safe, /str0ke

--------------------------

Clearly this is a sad day, but I hope stroke the best...and thank him for all the great information thru the years. Milw0rm will be sorely missed.

Dino Dai Zovi on Mac OS X Rootkits, Mac Exploitation & Hacking Contests

Via Threatpost (Digital Underground Podcast) -

Dennis Fisher talks with security researcher Dino Dai Zovi about his upcoming Black Hat talk on Mac OS X rootkits, exploiting the Mac and the value of hacking contests and internal code reviews.

http://www.threatpost.com/sites/default/files/digital_underground_23.mp3

GAO Smuggles IED Materials in Federal Buildings, Citing Security Gaps

Via FoxNews -

Government investigators smuggled bomb-making materials into federal buildings past the police agency charged with protecting those buildings and found numerous other gaps in security, according to a congressional report.

The Government Accountability Office said investigators carried bomb-making materials past security at 10 federal buildings. Security at these buildings and a total of about 9,000 federal buildings around the country is provided by the Federal Protective Service, a target of the probe.

Once GAO investigators got the materials in the buildings, the report said, they constructed explosive devices and carried them around inside. For security reasons, the GAO report did not give the location of the buildings.

The report was made available to The Associated Press in advance of a hearing scheduled Wednesday of the Senate Homeland Security and Governmental Affairs Committee.

--------------------------------

GAO-09-859T - Preliminary Results Show Federal Protective Service's Ability to Protect Federal Facilities Is Hampered By Weaknesses in Its Contract Security Guard Program (PDF)

Here are some of the juicy highlights which I found interesting....
  • A guard was caught using government computers, while he was supposed to be standing post, to further his private for-profit adult website.
  • A guard failed to recognize or did not properly x-ray a box containing semi-automatic handguns at the loading dock at one federal facility we visited. FPS only became aware of the situation because the handguns were delivered to FPS.
But the details of the covert IED testing show the real threat...
We identified substantial security vulnerabilities related to FPS’s guard program. Each time they tried, in April and May 2009, our investigators successfully passed undetected through security checkpoints monitored by FPS’s guards, with the components for an IED concealed on their persons at 10 level IV facilities in four cities in major metropolitan areas.

The specific components for this device, items used to conceal the device components, and the methods of concealment that we used during our covert testing are classified, and thus are not discussed in this testimony. Of the 10 level IV facilities we penetrated, 8 were government owned and 2 were leased facilities. The facilities included field offices of a U.S Senator and U.S. Representative as well as agencies of the Departments of Homeland Security, Transportation, Health and Human Services, Justice, State and others. The two leased facilities did not have any guards at the access control point at the time of our testing.

Introducing the Google Chrome OS

Via the Official Google Blog -

It's been an exciting nine months since we launched the Google Chrome browser. Already, over 30 million people use it regularly. We designed Google Chrome for people who live on the web — searching for information, checking email, catching up on the news, shopping or just staying in touch with friends. However, the operating systems that browsers run on were designed in an era where there was no web. So today, we're announcing a new project that's a natural extension of Google Chrome — the Google Chrome Operating System. It's our attempt to re-think what operating systems should be.

Google Chrome OS is an open source, lightweight operating system that will initially be targeted at netbooks. Later this year we will open-source its code, and netbooks running Google Chrome OS will be available for consumers in the second half of 2010. Because we're already talking to partners about the project, and we'll soon be working with the open source community, we wanted to share our vision now so everyone understands what we are trying to achieve.

Speed, simplicity and security are the key aspects of Google Chrome OS. We're designing the OS to be fast and lightweight, to start up and get you onto the web in a few seconds. The user interface is minimal to stay out of your way, and most of the user experience takes place on the web. And as we did for the Google Chrome browser, we are going back to the basics and completely redesigning the underlying security architecture of the OS so that users don't have to deal with viruses, malware and security updates. It should just work.

Google Chrome OS will run on both x86 as well as ARM chips and we are working with multiple OEMs to bring a number of netbooks to market next year. The software architecture is simple — Google Chrome running within a new windowing system on top of a Linux kernel. For application developers, the web is the platform. All web-based applications will automatically work and new applications can be written using your favorite web technologies. And of course, these apps will run not only on Google Chrome OS, but on any standards-based browser on Windows, Mac and Linux thereby giving developers the largest user base of any platform.

[...]

We have a lot of work to do, and we're definitely going to need a lot of help from the open source community to accomplish this vision. We're excited for what's to come and we hope you are too. Stay tuned for more updates in the fall and have a great summer.

US & German Intel: Al Qaeda Plots Multiple Attacks on US & Israel-bound Airliners

Via Debka.com -

Western anti-terror agencies have warned that a large group of 15-20 al Qaeda terrorists, trained in Pakistan and Algeria to hijack and blow up airliners, deployed secretly in at least six European and Middle East countries in early July. They are standing ready to carry out multiple terrorist attacks.

The terrorists are believed to have landed in Britain, Germany, France, Italy, Turkey and Egypt.

The dates to watch, local authorities were warned, were July 4, July 7, the fourth anniversary of the 7/7 attacks on the British transport system in which 52 people died, and July 8-9, when the G8 summit meets in the Italian town of L'Aqila. US president Barack Obama will fly in from talks with Russian leaders in Moscow.

Al Qaeda planners, say the Western sources, know it is extremely hard to break through the massive security cordons protecting summit leaders. They are therefore planning to hijack passenger planes of airlines belonging to the targeted states and blow them up in mid-air.

DEBKAfile's counter-terror sources report the first specific red alert on Saturday, July 4, referred to the possible hijack of Turkish Airways planes taking of from Turkish airports for US destinations or Tel Aviv. Special precautionary measures were put in place at both ends of their routes.

The alert is still in force.

Taliban Launches Operation ‘Iron Net’ Against US Marines in Afghanistan

Via Daily Times (Pakistan) -

The Taliban said on Monday they have launched a guerrilla operation to thwart a major assault by the newly-deployed US Marines on their Helmand strongholds.

Operation Foladi Jal would teach the Marines “a lesson”. Taliban spokesman Yousuf Ahmadi told AFP by telephone from an unknown location.

About 4,000 Marines poured into the southern province on Thursday in an operation called Khanjar (dagger) to tackle the Taliban in the region.

“In response to Operation Khanjar by the invading forces, we have launched the operation,” Ahmadi said. The operation would include improvised bomb explosions and “hit-and-run guerrilla attacks”, Ahmadi said.

“We will not engage them in front battles. We would rather hit them by mines and guerrilla attacks,” he said

Interior Ministry Officials in Pakistan Arrested‏ for Weapons Scam

Via Dawn.com (Pakistan) -

ISLAMABAD: Three officers from the interior ministry were arrested on Tuesday for illegally issuing weapons licenses, DawnNews reports.

The officials have been charged with issuing 161 weapons licenses despite a legal ban on the sale of arms.

Interior Ministry Secretary Syed Kamal Shah told a Senate sub-committee that these three officers pocketed Rs7.5 million by issuing the licenses illegally.

Meanwhile, a top security official also told the committee that they have intelligence a terrorist may strike Islamabad in the next forty eight hours.

Federal Websites Knocked Out by DDoS Attack

Via Google (AP) -

A widespread and unusually resilient computer attack that began July 4 knocked out the Web sites of several government agencies, including some that are responsible for fighting cyber crime, The Associated Press has learned.

The Treasury Department, Secret Service, Federal Trade Commission and Transportation Department Web sites were all down at varying points over the holiday weekend and into this week, according to officials inside and outside the government. Some of the sites were still experiencing problems Tuesday evening. Cyber attacks on South Korea government and private sites also may be linked, officials there said.

U.S. officials refused to publicly discuss details of the cyber attack. But Amy Kudwa, spokeswoman for the Homeland Security Department, said the agency's U.S. Computer Emergency Readiness Team issued a notice to federal departments and other partner organizations about the problems and "advised them of steps to take to help mitigate against such attacks."

The U.S., she said, sees attacks on its networks every day, and measures have been put in place to minimize the impact on federal Web sites.

It was not clear whether other federal government sites also were attacked.

Others familiar with the U.S. outage, which is called a denial of service attack, said that the fact that the government Web sites were still being affected three days after it began signaled an unusually lengthy and sophisticated attack. The officials spoke on condition of anonymity because they were not authorized to speak on the matter.

Web sites of major South Korean government agencies, banks and Internet sites also were paralyzed in a suspected cyber attack Tuesday. Ahn Jeong-eun, a spokeswoman at the Korea Information Security Agency, said the U.S. and South Korean attacks appeared to be linked.

The South Korean sites included the presidential Blue House, the Defense Ministry, the National Assembly, Shinhan Bank, Korea Exchange Bank and top Internet portal Naver. They went down or had access problems since late Tuesday, Ahn said.

Kudwa had no comment on the South Korean attacks.

Two government officials acknowledged that the Treasury and Secret Service sites were brought down, and said the agencies were working with their Internet service provider to resolve the problem.

Ben Rushlo, director of Internet technologies at Keynote Systems, called it a "massive outage" and said problems with the Transportation Department site began Saturday and continued until Monday, while the FTC site was down Sunday and Monday.

Keynote Systems is a mobile and Web site monitoring company based in San Mateo, Calif. The company publishes data detailing outages on Web sites, including 40 government sites it watches.

According to Rushlo, the Transportation Web site was "100 percent down" for two days, so that no Internet users could get through to it. The FTC site, meanwhile, started to come back online late Sunday, but even on Tuesday Internet users still were unable to get to the site 70 percent of the time.

"This is very strange. You don't see this," he said. "Having something 100 percent down for a 24-hour-plus period is a pretty significant event."

He added that, "The fact that it lasted for so long and that it was so significant in its ability to bring the site down says something about the site's ability to fend off (an attack) or about the severity of the attack."

Novel H1N1 Flu Situation Update

http://www.cdc.gov/h1n1flu/update.htm
Data reported to CDC by July 2, 2009, 11:00 AM ET.

33,902 confirmed and probable cases with 170 deaths in 53 US states / territories (including the District of Columbia, Puerto Rico and the U.S. Virgin Islands)

NOTE: Because of daily reporting deadlines, the state totals reported by CDC may not always be consistent with those reported by state health departments. If there is a discrepancy between these two counts, data from the state health departments should be used as the most accurate number.

---------------------------------

WHO Pandemic (H1N1) 2009 - update 58
6 July 2009 09:00 GMT

The breakdown of the number of laboratory-confirmed cases is given in this map.

Cumulative number of global laboratory-confirmed cases = 94,512 (440 deaths)

Check out the July 7th virtual press briefing with Dr Keiji Fukuda, Assistant Director-General ai, Health Security and Environment [mp3 16Mb]

WHO has a very cool interface map as well...which requires Flash. The numbers are a little behind, but it gives a very cool overall.

----------------------------------

It is important to remember that the US CDC number includes both lab-confirmed cases and probable cases...the WHO only counts lab-confirmed cases.

Monday, July 6, 2009

Facebook's Own Estimates Show Declining Student Numbers

Via readwriteweb.com -

How fickle are kids these days? Just when all the grown ups started figuring out Facebook, college and high school users have declined in absolute number by 20% and 15% respectively in a mere six months, according to estimates Facebook provides to advertisers that were archived for tracking by an outside firm. Facebook users aged 55 and over have skyrocketed from under 1 million to nearly six million in the same time period. There are more Facebook users over 55 years old today than there are high school students using the site.

Grandma and Grandpa showed up to have a conversation, but Billy and Sally were gone. Facebook cannot be excited about this.

The dramatic change in user demographics was picked up by iStrategyLabs today. Anyone can go through Facebook's self-serve advertising program and see the user demographics numbers the company estimates now, iStrategyLabs captured that data six months ago and saved it for comparison. The changes have been dramatic.

According to this data, from Facebook's own ad platform, there are actually fewer high school and college users on Facebook today than there were six months ago.

Hizb ut-Tahrir Plotting Against the Pakistan Government

Via Times Online UK -

Followers of the fundamentalist group Hizb ut-Tahrir (HT) have called for a “bloodless military coup” in Islamabad and the creation of the caliphate in which strict Islamic laws would be rigorously enforced.

Members of the group, which describes itself as the Liberation party in Britain but is banned in Pakistan, revealed last week that it had targeted the country as a base from which to spread Islamic rule across the world.

The Sunday Times has obtained the names of a dozen British Hizb ut-Tahrir activists based in Lahore and Karachi, or commuting between Britain and Pakistan. There are believed to be many more.

Tayyib Muqeem, an English teacher from Stoke-on-Trent, said he had moved to Lahore to convert Pakistanis to the movement.

At Lahore’s Superior College, where Muqeem has set up a Hizb ut-Tahrir student group, he said the organisation’s aim was to subject Muslim and western countries to Islamic rule under sharia law, “by force” if necessary.

In a caliphate, “every woman would have to cover up” and stoning to death for adultery and the chopping off of thieves’ hands would be the law, he said.

He added that Islamic rule would be spread through “indoctrination” and by “military means” if non-Muslim countries refused to bow to it. “Waging war” would be part of the caliphate’s foreign policy.

One of Hizb ut-Tahrir’s strategies in Pakistan is to influence military officers, he revealed.

Shahzad Sheikh, a Pakistani recruit and the group’s official spokesman in Karachi, talked openly about persuading the army to instigate a “bloodless coup” against the present government who, he said, were “worse than the Taliban”.

“It is the military who hold the power (in Pakistan) and we are asking them to give their allegiance to Hizb ut-Tahrir,” he said. “I can’t explain to you in detail how we are trying to influence the military . . . We never disclose our methodology of change. You may say it’s a coup.”

-------------------

Hizb ut-Tahrir (Arabic: Ø­ِزْبُ التَØ­ْرِير‎; English: Party of Liberation) is an international pan-Islamist, Sunni, vanguard political party whose goal is to combine all Muslim countries in a unitary Islamic state or caliphate, ruled by Islamic law and with a caliph head of state elected by Muslims.

HT is not designated as a terrorist organization in the United States, however many consider it to be a stepping stone to more militant organizations.

GlobalSecurity.org - Hizb ut-Tahrir al-Islami

Jamestown - Hizb-ut-Tahrir's Activities in the United States

CT Blog - Hizb ut-Tahrir America (HTA) Enters Public Stage

Official Hizb ut-Tahrir website (English)

Synthetic-aperture Radar Might Perform Double Duty as High-Speed Data Links

Via DefenseSystems.com -

Synthetic aperture radars have used radio frequency technology to give aircraft, ships and ground troops highly detailed tracking data. Now, they might provide a way to share that data in real time. Contractors Raytheon and L-3 Communications have combined efforts in a joint development program that might turn synthetic aperture radar systems into nodes on a high-speed, mobile ad hoc network.

Using the radar’s antennas simultaneously for radar sensing and as a high-speed data link, fighter aircraft would be able to transmit full sensor data — previously only available within the aircraft — to other aircraft and ground stations more than 100 miles away. If successful, the capability that Raytheon and L-3 are developing might transform fighter aircraft and other vehicles equipped with Active Electronically Scanned Array (AESA) radars into powerful intelligence, surveillance and reconnaissance (ISR) platforms, sending synthetic aperture radar images at speeds as fast as 4 gigabits/sec.

“The data that [fighter aircraft have] gathered, which is extremely valuable, has been limited to use in that cockpit because there was no way to offload that amount of data,” said Lucas Bragg, Raytheon’s senior manager of advanced programs. “By now enabling their radar to act as a communications device, you're now able to offload this highly valuable data that's been gathered on the aircraft.”

“The big thing with this technology is that fighters have been limited in getting large amount of data off the vehicle, because you'd have to add an aperture, an antenna,” said James Perry, L-3's director of international business development.

“With the sleek skin of the aircraft, there's no way to add an antenna that will give you the throughput to do wideband communications.”

When a Parent Steals Your Identity

Via MSN Money -

Danielle, 28, thought her credit was pretty good when she went to buy a new car a couple of years ago. And it would have been, had her credit report not been littered with unpaid accounts opened by her mother in Danielle's name.

Now Danielle, a graduate student who also works full time, is struggling to pay off more than $20,000 in credit card debt her mother incurred. The older woman, who survived a bout with cancer, insists she would have been able to pay the bills had she not become ill and gets angry when Danielle mentions the debt.

"I feel bad bringing it up," Danielle said. "I feel like the bad guy."

Parents are supposed to protect their children from harm, but some inflict long-lasting financial and emotional damage by using them to commit identity theft.

Some, such as Danielle's mother, victimize offspring who are old enough to establish credit in their own right. Others use the Social Security numbers of their minor children to set up fraudulent accounts that the victims might not discover for years.

"When we first started hearing about it, we were shocked and horrified," said Beth Givens, the head of the Privacy Rights Clearinghouse in San Diego. "It turns out it is more common than you might think."

Linda Foley, the founder of the Identity Theft Resource Center, also in San Diego, said she almost never heard about parent perpetrators when she and her husband established the center a decade ago. These days, though, they get several complaints a week from victims or from other adults who have uncovered the crimes.

"It just keeps getting bigger," said Foley, who fears the recession and rising unemployment will tempt more parents to cross the line.

Insider Arrested For Stealing Critical Code From Financial Services Company

Via DarkReading.com -

Wall Street is abuzz today with news that a computer programmer has been arrested for stealing top-secret application code that drives his former company's high-speed financial trading platform.

According to an affidavit (PDF) filed by the arresting FBI officer and subsequently posted by news media, the programmer, Sergey Aleynikov, copied "proprietary trade code" from his company and uploaded it to a Website in Germany. He later quit his job at the New York firm and moved to a new company in Chicago that "intended to engage in high-volume automated trading" -- and paid him around three times his old salary of $400,000, according to the affidavit.

The financial institution, which is not named in the affidavit, allegedly saw via routine monitoring that Aleynikov's machine was used at least four times to send some 32 megabytes of data to an external site last month. The institution then recovered Aleynikov's bash history -- a record of commands used on his desktop -- to identify his specific actions, the affidavit says.

In a blog, Reuters columnist Matthew Goldstein reported that the New York firm in the affidavit is Goldman Sachs, and that Aleynikov may have stolen the "secret sauce" that has allowed the financial services firm to consistently perform better than many of its competitors. Several other publications have picked up on Goldstein's story, although Goldman Sachs has yet to make a public comment.

The affidavit does not address Goldstein's report, but it does say that "certain features of the [code], such as speed and efficiency by which it obtains and processes market data, gives the Financial Institution a competitive advantage among other firms that also engage in high-volume automated trading. The Financial Institution further believes that, if competing firms were to obtain the [code] and use its features, the Financial Institution's ability to profit from the [code]'s speed and efficiency would be significantly diminished."

Security experts, meanwhile, are saying that Aleynikov's actions should have been caught before the proprietary data got out. According to the affidavit, the downloads took place during four different sessions, and the data was encrypted before it was uploaded to the German Website. The downloads took place less than a week before Aleynikov announced his resignation. Aleynikov attempted to delete the encryption software and his bash history before transferring the files to his own computers, the affidavit says.

According to Goldstein's blog, Aleynikov told the FBI when he was arrested that he "only intended to collect 'open source' files on which he had worked, but later realized that he had obtained more files than he intended." Aleynikov's attorney reportedly is saying that her client will be proved innocent of the single charge of theft of trade secrets.

Wall Streeters, meanwhile, are wondering what might have been done with the secret software, which may have been available to others for several weeks now. The affidavit does not name the new firm that Aleynikov allegedly was prepared to join, nor does it say who had access to the data on the German site. Some financial experts expressed concern that Goldman Sachs' stock might suffer as a result of the reports, and others said they believe the financial institution in question should disclose the potential security breach and its potential impact on the company's ability to compete in the market.

Researchers: SSNs Can Be Guessed

Via Washington Post -

Researchers have found that it is possible to guess many -- if not all -- of the nine digits in an individual's Social Security number using publicly available information, a finding they say compromises the security of one of the most widely used consumer identifiers in the United States.

Many numbers could be guessed at by simply knowing a person's birth data, the researchers from Carnegie Mellon University said.

The results come as concern grows over identity theft and lawmakers in Washington push legislation that would bar businesses from requiring people to supply their Social Security number when purchasing a good or service.

"Our work shows that Social Security numbers are compromised as authentication devices, because if they are predictable from public data, then they cannot be considered sensitive," said Alessandro Acquisti, assistant professor of information technology and public policy at Carnegie Mellon University, and a co-author of the study.

A Social Security Administration spokesman said the government has long cautioned the private sector against using a Social Security number as a personal identifier, even as it insists "there is no fool proof method for predicting a person's Social Security Number."

"For reasons unrelated to this report, the agency has been developing a system to randomly assign SSNs," which should make it more difficult to discover numbers in the future, Mark Lassiter, a spokesman for the Social Security Administration, said by e-mail.

[...]

The researchers at Carnegie Mellon set out to see if they could discover people's numbers by first exploiting what is publicly known about how the numbers are derived.

The Social Security number's first three digits -- called the "area number" -- is issued according to the Zip code of the mailing address provided in the application form. The fourth and fifth digits -- known as the "group number" -- transition slowly, and often remain constant over several years for a given region. The last four digits are assigned sequentially.

As a result, SSNs assigned in the same state to applicants born on consecutive days are likely to contain the same first four or five digits, particularly in states with smaller populations and rates of birth.

[...]

Privacy and security experts praised the Carnegie Mellon study, saying it should be a wake-up call to policy makers and industry leaders, many of whom have resisted switching to a more secure consumer authentication system due to the sheer cost of changing the current system.

[...]

Ross Anderson, a professor of security engineering at Cambridge University, said the findings suggest that businesses using SSNs as a password are being negligent, and should find other ways of verifying the claims to identity that are being made by their customers.

"Sure, the study says that if you were born in a big state on a busy day you're probably still safe," from having identity thieves guess your entire SSN, Anderson said. "Still, I think many people would find it unacceptable that a system continues in use which in effect exposes tens of millions of Americans to fraud and other kinds of harm."

Linda Foley, founder of the Identity Theft Resource Center, a San Diego based nonprofit, cited another potential problem. She said many businesses have errantly rely upon or have moved to redact all but the last four digits of a person's SSN, the very digits that are most unique to an individual.

"Because of the way the SSN has been designed, asking for the last four numbers of the SSN puts people at risk because those are the only numbers that are unique to you and cannot be guessed easily by someone who might want to use your identity," Foley said.

The National Science Foundation, the U.S. Army Research Office, Carnegie Melon Cylab, and the Berkman Faculty Development Fund provided support for the research. The study, which will be presented July 29 at the BlackHat 2009 security conference in Las Vegas, is available at this link.

Microsoft DirectShow MPEG2TuneRequest ActiveX Control Buffer Overflow

http://secunia.com/advisories/35683/

Description
:
A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error in the ActiveX control for streaming video (msvidctl.dll) and can be exploited to cause a stack-based buffer overflow via specially crafted image content.

Successful exploitation allows execution of arbitrary code when a user e.g. visits a malicious website.

NOTE: The vulnerability is currently being actively exploited.

Solution:
Set the kill-bit for the affected ActiveX control.

Provided and/or discovered by:
Reported as a 0-day.

Changelog:
2009-07-06: Added additional information from Microsoft. Added Windows Server 2003 as affected.

Original Advisory:
Microsoft:
http://www.microsoft.com/technet/security/advisory/972890.mspx

KingSoft Internet Security Blog:
http://blog.duba.net/read.php/225.htm
http://blog.duba.net/read.php/226.htm

CVE reference:
CVE-2008-0015

------------------------------------

PoC Exploit can be found over @ carnal0wnage -
http://carnal0wnage.attackresearch.com/node/370

Germany's Biggest Bank Admits Hiring Detectives to Spying on Staff

Via breitbart.com -

Germany's biggest bank, Deutsche Bank, admitted Monday it had spied on a former member of its supervisory board, suspected of disclosing 2001 third quarter results before their official publication.

A bank spokesman said the target was Gerald Herrmann, who represented the union Verdi on the board that year.

German magazine Der Spiegel had reported over the weekend that the bank hired detectives to spy on its employees including a member of its supervisory board, managers and a shareholder.

The bank launched an internal inquiry at the end of May into potential breaches of data privacy law in connection with the affair, Spiegel said.

The spokesman confirmed the investigation and said the financial market regulator Bafin had also been contacted.

Herrmann told the Handelsblatt business newspaper on Monday Deutsche Bank informed him of the case a couple of days ago.

He denied the allegations against him and said he suspected he was spied on because Deutsche Bank did not appreciate his criticism of a redundancy compensation scheme.

The bank apologised to Hermann but the union member said he wanted a personal apology from chief executive Josef Ackermann who promised a "zero tolerance" approach over the affair at an annual general meeting of the bank.

According to Der Spiegel detectives "kept an eye on the movements of these people, and made inquiries as to who they were meeting and when".

In 2006, managers were spied on because of their suspected links to media mogul Leo Kirch, who was involved in a legal battle with Deutsche Bank, the magazine said.

Spiegel also said minority shareholder Michael Bohndorf, a lawyer living in Ibiza, Spain, was spied on.

Several detective agencies may have been involved in the affair.

Among the agencies is one led by a former agent of the Stasi, the notorious secret police in the former East Germany, who was also implicated in a scandal at German phone giant Deutsche Telekom.

Deutsche Bank even used "female bait" to find "personal weaknesses of certain shareholders", the magazine added.

Scandals over violations of privacy law have rocked the German corporate world in recent months, notably at railway company Deutsche Bahn and Deutsche Telekom.