Thursday, July 16, 2009

Taliban Threatens to Kill U.S. Soldier Captured in Afghanistan

Via FoxNews (AP) -

A spokesman for a Taliban commander says a captured U.S. soldier will be executed unless the U.S. military stops operations in two districts of southeastern Afghanistan.

The Taliban said last week they were holding the soldier. The U.S. military earlier said he went missing and may be in enemy hands.

Abdullah Jalali, spokesman for Taliban commander Mawlavi Sangin, told The Associated Press on Thursday the soldier was healthy but threatened to kill him unless the U.S. stops airstrikes in Ghazni province's Giro district and Paktika province's Khoshamand district.

Jalali says Giro has been heavily bombed by international forces but did not otherwise explain why they chose those areas.

Teen Arrested for Upper East Side Starbucks Blast

Via NBCNewYork.com -

A teen arrested in the bombing of an upper East Side Starbucks was inspired to plant the explosive device by the movie "Fight Club," cops said today.

Kyle Shaw, 17, of Chelsea, was charged with arson, criminal mischief and criminal possession of a weapon for placing the bomb at the E. 92nd St. coffee shop, police said.

Shaw was inspired to plant the bomb at the Manhattan eatery by watching the anarchic behavior of Brad Pitt in the film "Fight Club." He picked the site because a Starbucks was a target in the movie, police said.

Shaw formed his own fight club in which boys beat one another in various locales around the city including Central Park, Police Commissioner Ray Kelly said.

At least one member got a broken nose, he said.

Shaw apparently told at least one friend to "watch the news over Memorial Day'' because he was about to launch his own version of "project mayhem,'' Kelly said. Investigators are looking into whether more people might have been involved.

The homemade device exploded at 3:30 a.m. on May 25 and no one was hurt in the attack. The bomb was made out of water bottle and powder used to make fireworks.

Video at the scene showed two teens carrying a plastic container with what cops believed to be explosives.

--------------------------

For more background information, check my May 25th blog entry on the blast...

Pay As You Drive “Black Boxes” Threaten Driver Privacy

Via EFF -

The California Department of Insurance (DOI) is considering regulations that would enable insurance prices to depend on the precise number of miles a car is driven in a given billing period. But in implementing these "Pay As You Drive" regulations, the DOI appears poised to empower insurance companies to require customers' cars to be outfitted with "black-box" devices that could transmit back to the insurance companies all sorts of data about car motion (acceleration, braking, and so forth) as well as driver behavior (steering and seat-belt wearing).

Although DOI has retreated from its prior position that these devices should track your location – a definite improvement – it's still true that every car already has a reliable, tamper-resistant device that verifies actual mileage: an odometer.

Even worse, there appear to be no restrictions on what the insurance companies would do with that data — of course, when you drive on the public street, you lose some privacy. But 10 years ago, someone interested in your whereabouts would have had to decide in advance to follow you and then physically follow you. Black boxes can collect information pervasively, silently, and cheaply for any later use by the insurance company, private parties or the government. There is real danger that this information would not only be used to ascertain the political or associational affiliations of drivers, but also to charge more if you drive and park in neighborhoods with high vehicle theft and crime rates, to impose higher premiums for people who drive at night or to link your health insurance rates with location data that reveals your lunchtime trips to McDonald's.

In comments filed with the DOI this week, EFF has argued that it is unacceptable for insurance companies to coercively require customers to accept such devices in their cars, and that the proposed regulations be amended to permit drivers to participate in any verifed actual mileage program via other means (like your car's odometer). EFF also argued that location privacy requires, at a minimum, that the proposed regulations restrict collection of information to the minimum amount necessary, require that the driver be able to independently verify information collected and require that the insurer have an explicit policy about the use and storage of the collected data.

Interested in protecting driver privacy in California? Consider telling Insurance Commissioner Steve Poizner [contact info] that you agree with EFF's criticisms. Why is the Insurance Commissioner allowing the insurance companies to track drivers? Shouldn't he be tracking insurance companies?

Wednesday, July 15, 2009

CERN LHC Update

Via US LHC Blog -

This message was sent from Director General Rolf Heuer to the CERN community today:

The foreseen shutdown work on the LHC is proceeding well, including the powering tests with the new quench protection system. However, during the past week vacuum leaks have been found in two “cold” sectors of the LHC. The leaks were found in sectors 8-1 and 2-3 while they were being prepared for the electrical tests on the copper stabilizers at around 80 K. In both cases the leak is at one end of the sector, where the electrical feedbox, DFBA, joins Q7, the final magnet in the sector.

Unfortunately, the repair necessitates a partial warm-up of both sectors. This involves the end sub-sector being warmed to room temperature, while the adjacent sub-sector “floats” in temperature and the remainder of the sector is kept at 80 K. As the leak is from the helium circuit to the insulating vacuum, the repair work will have no impact on the vacuum in the beam pipe. However the intervention will have an impact on the schedule for the restart. It is now foreseen that the LHC will be closed up and ready for beam injection by mid-November.

---------------------------

Liquid nitrogen is used to cool 37,000 tonnes of equipment for the Large Hadron Collider (LHC) down to 80 K. Then liquid helium is used to chill some parts of the accelerator to temperatures as low as 1.8 K.

But liquid helium isn't created directly....

The cryoplants produce high-pressure supercritical helium gas at 4.6 K, which will be distributed along the sector to a number of local cooling loops. There, the supercritical helium will be expanded into a lower-pressure environment, which causes it to liquefy at either 4.5 K or 1.8 K. This liquid will then be used to cool the superconducting magnets.

Firefox 3.5 Exploits - Another Exploit Released

The one you have been hearing about....here & here
http://www.milw0rm.com/exploits/9137

and a new exploit one released today...
http://www.milw0rm.com/exploits/9158

Veracode: BlackBerry Spyware Dissected

Via Veracode Blog -

Yesterday it was reported by various media outlets that a recent BlackBerry software update from Etisalat (a UAE-based carrier) contained spyware that would intercept emails and text messages and send copies to a central Etisalat server. We decided to take a look to find out more.

We’re not sure why the software was delivered in both .jar and .cod form. The .cod file is a RIM proprietary format that contains the compiled Java classes along with a signature. Therefore it’s not even necessary to send the .jar, but they did, completely unobfuscated.

[...]

The most alarming part about this whole situation is that people only noticed the malware because it was draining their batteries. The server receiving the initial registration packets (i.e. “Here I am, software is installed!”) got overloaded. Devices kept trying to connect every five seconds to empty the outbound message queue, thereby causing a battery drain. Some people were reporting on official BlackBerry forums that their batteries were being depleted from full charge in as little as half an hour.

The final thing to mention is that the spyware does appear to be installed in a non-running state by default, where it’s not actually exfiltrating data once the initial registration packet has gone out. However, using the command and control mechanism we described earlier, the carrier can remotely start/stop the service at will on a per-device basis.

-------------------------

Check out the full Veracode blog for the detailed technical analysis...cool stuff indeed.

New iTunes From Apple Halts Palm Pre's Access

Via WSJ.com -

The latest version of iTunes from Apple Inc. (AAPL) has cut off rival Palm Inc.'s (PALM) Pre smartphone.

Apple's online music and video bazaar now "disables devices falsely pretending to be iPods," which includes Palm's Pre, an Apple spokesman said.

The Pre smartphone has been able to access iTunes since going on sale in the U.S. in early June. But it was always unclear whether the Pre was doing so with Apple's permission. Given the latest iTunes update, Palm appears to have been acting on its own.

The development is a negative one for Palm, which is counting on Pre sales to turn around the company. With the move, Apple has dramatically limited one of the Pre's key competitive advantages: downloading music and videos from Apple's iTunes.

"If Apple chooses to disable media sync in iTunes, it will be a direct blow to their users who will be deprived of a seamless synchronization experience," Palm spokesman Lynn Fox said,

"However, people will have options," which include using previous versions of iTunes that are still Pre-compatible, she added.

For Apple, the new iTunes underscores its commitment to allow only authorized devices, such as its iPods and iPhones, to access its iTunes music store, which helps it corral more of the profits.

"As we've said before, newer versions of Apple's iTunes software may no longer provide syncing functionality with unsupported digital media players," the Apple spokesman added.

---------------------

If you didn't hear about the Palm Pre Media Sync function and how it gained access to iTunes, check here.

Critical JavaScript Vulnerability in Firefox 3.5

http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/

Issue

A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.

Impact

The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can be mitigated by disabling the JIT in the JavaScript engine. To do so:

1. Enter about:config in the browser’s location bar.
2. Type jit in the Filter box at the top of the config editor.
3. Double-click the line containing javascript.options.jit.content setting the value to false.

Note that disabling the JIT will result in decreased JavaScript performance and is only recommended as a temporary security measure. Once users have been received the security update containing the fix for this issue, they should restore the JIT setting to true by:

1. Enter about:config in the browser’s location bar.
2. Type jit in the Filter box at the top of the config editor.
3. Double-click the line containing javascript.options.jit.content setting the value to true.

Alternatively, users can disable the JIT by running Firefox in Safe Mode. Windows users can do so by selecting Mozilla Firefox (Safe Mode) from the Mozilla Firefox folder.

Status

Mozilla developers are working on a fix for this issue and a Firefox security update will be sent out as soon as the fix is completed and tested.

Credit

Zbyte reported this issue to Mozilla and Lucas Kruijswijk helped reduce the exploit test case.

-----------------------------------

HD Moore has released a MSF module which exploits the vulnerability on Win32 only...support for other platforms is expected in the new future.

Etisalat's BlackBerry Patch Opens Phones to Surveillance

Via ITP.net -

The battery-sapping "performance patch" that Etisalat [Emirates Telecommunications Corporation] sent to its BlackBerry subscribers over the last few days was designed to give the UAE operator the ability to read its customers emails and text messages, a Qatar-based software expert told CommsMEA yesterday.

Last week, Etisalat told its 100,000 BlackBerry subscribers that a "performance enhancement patch" would be sent to them to "provide the best BlackBerry service and ultimate experience". But users who downloaded the software complained of dramatically reduced battery life and slower than usual performance of their devices.

Nigel Gourlay, a Doha-based Sun-certified Java programmer who has been developing open source software for 15 years, analysed the patch after it was posted on BlackBerry’s community support forum and he said that once installed, it potentially gives Etisalat the power to view all emails and text messages sent from the BlackBerry.

“I don’t think it’s been designed for a large scale deployment,” he said. “They have released it as an upgrade across all UAE BlackBerry handsets, all of which have tried to phone home to this one registration server at the same time, and that has effectively brought the server to its knees. When the BlackBerry cannot register itself, it tries again and this causes the battery drain.”

Gourlay pointed out that by default the system is turned off and when it installs the only message that is sent is an initial registration message, and that later on, Etisalat could turn on the systems “one by one”.

Once installed, one of the possible commands that can be sent to the device is "start", which would then cause any subsequent message to be forwarded to an Etisalat website.

Gourlay said the patch was stamped with “SS8.com”, the name of a US-based software developer that describes itself as an electronic surveillance solutions company that develops products that “allow intelligence agencies to recognise, monitor, investigate and prevent criminal activity”.

It appears as though the use of such software is widespread among telecom operators, and according to SS8’s website, its products are used by “some of the largest service providers in the world”.

On Sunday Etisalat issued a two paragraph statement apologising for “a phased software upgrade…that led to extra consumption of the handset battery”. It described the patch as a “routine upgrade process”, but said it had stopped issuing it as a precautionary measure.

At the time of writing the operator had not responded to requests sent yesterday (Monday) for further details about the precise purpose of the patch or Etisalat’s relationship with “lawful interception solutions” firm SS8.

SS8 established its presence in the UAE in February this year when it acquired OCI Mobile, a technology provider that specialised in providing surveillance solutions to government organisations.

Cisco 2009 Midyear Security Report

The Cisco 2009 Midyear Security Report presents an overview of Cisco security intelligence, highlighting threat information and trends from the first half of 2009. The report also includes recommendations from Cisco security experts and predictions of how identified trends will evolve.

As predicted in the Cisco 2008 Annual Security Report, attacks are only becoming more sophisticated and targeted as we move through 2009—and the global recession. However, while cybercrime is more pervasive, there are encouraging signs that increased collaboration among the "good guys" is not only making it more difficult for attacks to take root and grow, but also helping to bring criminals to justice.

Report Highlights
  • Criminals are exploiting "old-school" vulnerabilities because they believe security experts and individual computer users are paying little attention to these types of threats.
  • Compromising legitimate websites for the purpose of propagating malware remains a highly effective technique for criminals.
  • Web 2.0 applications, prized for their ease of use and flexibility, have become lures for criminals.
  • Criminals are targeting people who use online banking with well-designed, localized text message scams—and they're leaving virtually no trail.
  • The Obama administration has made strengthening U.S. cybersecurity a high priority, and looks to leverage technology innovation and partner with the private sector. Other countries are also stepping up efforts to enhance cybersecurity and prevent cybercrime.
In addition, the number of vulnerabilities and discrete threats has been off to a slower start this year compared to 2008, according to research by Cisco-a sign the security community is succeeding in making it more difficult for attacks to take root and grow.

The Cisco 2009 Midyear Security Report (PDF) is now available.

Embedding and Hiding Files in PDF Documents

Via Didier Stevens' Blog -

My corrupted PDF quip inspired me to program another steganography trick: embed a file in a PDF document and corrupt the reference, thereby effectively making the embedded file invisible to the PDF reader.

The PDF specification provides ways to embed files in PDF documents. I’m releasing my Python program to create a PDF file with embedded file (I used make-pdf-embedded.py to create my EICAR.pdf).

[...]

Of course, once you know the stego trick, it’s easy to recover the embedded file: edit the PDF document with an hex editor and change the case back to /EmbeddedFiles.

But if you want to make it harder to detect, use PDF obfuscation techniques. Or embed the file twice with incremental updates. First version is the file you want to hide, second version is a decoy…

The PDF language offers so many features to hide and obfuscate data!

Download: make-pdf_V0_1_2.zip (https)

MD5: 305D57692C27DD3CD91D8C85A3932948

SHA256: A030BBCB8B54137D8047A4CB5C350725599383A4B113CABBA8871AC221378C5B

China Stops Clinic Treating Internet Addiction With Electroshock

Via WSJ's China Journal Blog -

Chinese authorities have put to a stop one clinic’s extreme effort to wean youngsters away from the Internet — a practice that highlights the skepticism surrounding China’s approach to Internet addiction, as well as the existence of the condition itself.

The Ministry of Health ordered that the clinic in Shandong province stop using electroshock as a form of punishment, according to Chinese media. Electroshock therapy was administered as a punishment for violating any number of the center’s rules. But the government said the treatment hasn’t been proven safe, while outsiders questioned whether the practice was effective in getting young people away from their compulsion to spend significant time online.

In what might be an indication of the clinic’s effectiveness, its practices came to light when former patients went online to complain. They described restrictive living conditions — including being allowed to talk only about their addiction and being forced to kneel in front of their parents in obedience — that scarcely squared with the clinic’s way out, which for them merely meant declaring they had overcome their addiction.

China claims the world’s largest online population, and a visit to an Internet cafe in most mainland cities would show what a major share of young people like do to with their free time. That’s given rise to fears that many in China suffer from Internet addiction. While not officially recognized as a malady by China’s medical establishment, the issue has drawn concerns from both the public and some officials, which have sanctioned treatment facilities and issued guidelines on how to deal with Internet addiction.

But sizable chunk of China’s online population is skeptical of the claims. Their doubts are reflected within the professional community, where the concept of Internet addiction has gained traction but still faces doubters who point to a lack of hard data.

Tuesday, July 14, 2009

Russia Tests 2nd Sub-launched Ballistic Missile

Via CBSNews.com (AP) -

News agencies say Russia has successfully tested its second submarine-launched ballistic missile in as many days.

RIA-Novosti and Interfax quote the head of Russia's joint chief of staff as saying a Sineva-type missile was fired Tuesday from the submarine Bryansk near the White Sea.

Gen. Nikolai Makarov was quoted as saying it was a short-range test for the Sineva.

Russia is struggling to introduce the newer, more-sophisticated Bulava missile into service, but it has failed in five of 10 launches.

Russian leaders say the Bulava will be able to penetrate missile defenses and will be a key part of the military's future nuclear arsenal.

----------------------

According to RIA-Novosti (July 14th, 2009),

The RSM-54 Sineva (NATO codename SS-N-23 Skiff) is a third-generation liquid-propellant intercontinental ballistic missile that entered service with the Russian Navy in July 2007. It can carry four to 10 nuclear warheads, depending on the modification. Russia is planning to equip its Delta IV class submarines with at least 100 Sineva missiles.

Navy commander Adm. Vladimir Vysotsky recently said Russia would carry out the next test of a Bulava sea-launched ballistic missile in late July, one of a total of four or five launches this year.

Offensive-Security WPA Rainbow Tables

http://www.offensive-security.com/wpa-tables/

Cowpatty WPA tables, SSID Specific, using a 49 Million WPA optimised password dictionary file

Each Table is 1.9 GB. Please help by seeding these files

Pepper Spray-Armed ATM Misfires, Shoots Workers

Via Wired.com -

A South African bank has outfitted its ATMs with pepper spray to prevent criminals from bombing or tampering with the machines. But the system still has some bugs: One of the machines released its stinging payload on three maintenance workers last week.

Absa Bank, one of South Africa’s largest, installed the spray on 11 machines after someone bombed several of its ATMs last year, according to local news outlet Independent Online. They were installed in a region where authorities say they retrieved 40 skimmers from card machines last year.

If a camera on the machine detects someone tampering with the card slot in an attempt to install a skimming device or explosives, a mechanism installed at the ATM kiosk releases a cloudspray.

The hope is that the spray will disorient the culprit long enough to allow authorities to arrive at the scene. But during routine maintenance on one of the machines, three workers were maced instead and had to be treated.

The spray was installed on machines in the Western Cape, a popular tourist area.

-------------------------

Speaking of ATMs, it looks like they found some more malware infected ATMs in Belarus.
All of the ATMs thus confirmed infected belong to banks which have contracts with Belorussian Processing Center (BPTs), which would lead one to conclude the insider had access there. This is impossible to confirm, however, as the banks are silent and BPTs denies their machines are infected at all, insisting instead that the missing funds were caused by a "technical failure," and subsequently "defective software". BPTs went so far as to tell reporters on June 5th that these technical issues had been resolved, but victims continue to report lost funds.

First Zero Day Exploit for Firefox 3.5

Via h-online.com -

The exploit portal Milw0rm has published an exploit for Firefox 3.5. The exploit demonstrates a security vulnerability by starting the Windows calculator. In testing by heise Security, the exploit crashed Firefox under Vista, but security service providers Secunia and VUPEN confirmed that attackers using prepared websites can infect PCs. The cause of the problem is a buffer overflow when processing specially prepared Font tags.

The Mozilla Foundation has been informed about the problem, but so far has not responded to queries by heise Security. An update does not currently exist. So far there are no reports of sites on the internet being first to use the hole for active infections and exploitation of Windows PCs. Since the published exploit uses PC heap spraying under JavaScript, disabling JavaScript should act as a stop gap. When the exploit was tested with Windows 7 RC1, after a short time, the browser displayed a dialogue offering to abort the script.

See also:

Taliban: Mullah Fazlullah, Swat Leadership Safe

Via The Long War Journal -

Swat Taliban leader Mullah Fazlullah and the rest of the group's most senior commanders have escaped the Pakistani government's operation, a Taliban spokesman said.

Mullah Omar, a spokesman for the Movement of the Taliban in Pakistan, denied reports from the government and the military that Mullah Fazlullah had been gravely wounded during airstrikes in his home town of Imam Dehri.

"Fazlullah is safe and the government claim is totally baseless," Omar told Pakistani journalists. He also said the Taliban leadership had gone underground "as part of their overall strategy" once the Army launched operations in Buner, Dir, and Swat, Daily Times reported.

An unconfirmed report in the BBC seemed to corroborate the government's claims that Fazlullah is near death.

"He is now stranded in Imam Dehri without any access to medical assistance and is close to death," a local Swati with purported connections to the Taliban told the BBC. He also stated that Shah Doran, Fazlullah's second-in-command, who, like his boss, is infamous for his radical sermons and death threats issued on illegal FM radio channels, had been killed. But Doran's death has not been confirmed, either.

Omar's statements were made as Fazlullah released an audiotape to the Pakistani media. Fazlullah also stated that the Taliban leadership is intact and his forces would continue to fight for the imposition of sharia, or Islamic law.

So far, the government has failed to kill or capture Fazlullah, Doran, Ibn Amin, Muslim Khan, and 17 other most senior lieutenants who have bounties on their heads for information leading to their capture.

And although the military claims that the Swat Taliban's second and third tier leaders have been wiped out, strong resistance remains in the district despite the military's declaration that the operation has been completed. The military has also said, however, that its forces will remain in Swat as the Taliban remains strong in some pockets.

While efforts to kill or capture the Swat Taliban's senior leaders falter, the government recently released Sufi Mohammed, the pro-Taliban cleric behind the Malakand Accord, who is also Fazlullah's father-in-law. The Malakand Accord amounted to an admission of the government's defeat and emboldened the Taliban to seize more territory in the northwest.

Graffiti Taxonomy: Paris, 2009…

Graffiti Taxonomy: Paris, 2009 from Evan Roth on Vimeo.

A study depicting the stylistic diversity found in Parisian graffiti tags. Now on display at Fondation Cartier’s Born In The Streets - Graffiti exhibition until November 29, 2009.

http://fffff.at/graffiti-taxonomy-paris-2009/

Two French Security Advisers Kidnapped in Somalia

Via BBC -

Two French security advisers helping the Somali government have been kidnapped in the capital Mogadishu, French officials have said.

Gunmen who were wearing police uniforms entered the hotel where the two were staying and took them away, eyewitnesses said.

The abductions took place in a government-held part of Mogadishu.

Islamist rebels are battling troops from the UN-backed interim government for control of the city.

The French foreign ministry said the two advisers were in Mogadishu on an official mission to provide help to the government.

They were seized at the Sahafi Hotel, which has often accommodated foreign journalists and Somali government ministers.

Hotel workers told BBC Somali that the two had checked in as journalists. A Somali official later told Reuters new agency they had done so for their own protection.

The kidnappings come two days after government troops forced Islamist militants from positions around the presidential palace.

Some of the 4,300 African Union peacekeepers in Mogadishu helped push back the insurgents.

The radical rebel group al-Shabab and its allies have been trying to topple the fragile interim government, led by moderate Islamist President Sheikh Sharif Sheikh Ahmed.

Monday, July 13, 2009

Al Qaida: Western Spies Multiply “Like Locusts”

Via FAS Secrecy News Blog -

From the point of view of an al Qaida military leader, Western intelligence agents are now ubiquitous in the lands of Islam, and their operations have been extraordinarily effective. The Western spies are unfailingly lethal, leaving a trail of dead Islamist fighters behind them. Worst of all, they have managed to recruit innumerable Muslims to assist their war efforts.

“The spies… were sent to penetrate the ranks of the Muslims generally, and the mujahidin specifically, and [they] spread all over the lands like locusts,” wrote Abu Yahya al-Libi, an al Qaida field commander in Afghanistan, in a new book called “Guidance on the Ruling of the Muslim Spy” (pdf).

“The spies are busy day and night carrying out their duties in an organized and secret manner… How many heroic leaders have been kidnapped at their hands? How many major mujahidin were surprised to be imprisoned or traced? Even the military and financial supply roads of the mujahidin, which are far from the enemy’s surveillance, were found by the spies.”

Al Qaida operations have been severely impeded by the intelligence war against them, al-Libi said. “As soon as the mujahidin get secretly into an area on a dark night, they are confronted by the Cross forces and their helpers. Many are killed or captured.”

Western spies are found under every conceivable cover, al-Libi wrote. “They have among them old hunchbacked men who cannot even walk, strong young men, weak women inside their house, young girls, and even children who did not reach puberty yet. The spy might be a doctor, nurse, engineer, student, preacher, scholar, runner, or a taxi driver. The spy can be anyone….”

“The occupation armies completely rely on recruiting spies and informants from the Muslim lands they usurped and conquered… The spy lives among Muslims, being one of them: living their life, wearing their dress, eating what they eat… Therefore, he can access what the armed soldiers of the occupation cannot put hands on.”

In the new book, published in Arabic (pdf) on jihadist websites on June 30, al-Libi ruminated at length on the religious and legal problem of the Muslim spy. Can there be a Muslim who spies against other Muslims or, since such a person would by definition be an apostate, is a Muslim spy a contradiction in terms? May such a person be killed? (It depends.) To convict a spy nowadays is it necessary to rely on the traditional two witnesses? (Again, it depends.) What about a person who is mistakenly executed as a spy? (God will reward him.)

Pervading the book is a sense of the overwhelming impact of U.S. and Allied intelligence operations on jihadist forces, and the willingness of indigenous Muslims to act with Western intelligence against those forces.

[...]

“Guidance on the Ruling of the Muslim Spy” by Abu Yahya al-Libi was translated, rather clumsily, by the DNI Open Source Center. A copy was obtained by Secrecy News.

The book cited the use of electronic homing devices to guide air-launched missiles to their targets and images of several such devices were included in the original Arabic version of the book (at page 146). The purported use of the devices was discussed in “CIA Drone Targeting Tech Revealed, Qaeda Claims” by Adam Rawnsley, Wired Danger Room, July 8, 2009. Memri.org also prepared a proprietary translation of the new Al-Libi book, which was reported by Fox News last week.