- First you must understand that Austin is not Texas, but Austin is in the heart of Texas. The rest of Texas is defined by two zones-the vaguely scary, inbred country regions, and the extremely scary, urban, conservative mega-cities. In Austin, we respect both zones (they are, after all, in the great state of Texas), but we really don't have much in common with them. You may hear us speak disparagingly of other parts of Texas, but you are not allowed to do the same. The only thing we hate more than people from Houston coming to Austin and trying to turn Austin into Houston is people from outside of Texas coming to Austin and insulting our state.
- You should also understand that it is hot and humid as hell for at least 3 months out of the year. People in Austin know this, and they don't understand people who complain about it. The day lasts 24 hours. There are 7 days in a week. It's hot outside. None of these things are worth mentioning or complaining about.
- Austin has some peculiar conventions when it comes to traffic. First, if there is anything that could potentially distract Austin drivers, they stop dead in the middle of the road. If they see the scene of an accident on the other side of the highway, they stop. If they see rain, they stop. If there is snow, they stop and start sacrificing goats. Get used to stopping on highways. At the same time, you should get over the idea that drivers in Austin will stop at other, more appropriate times. Austin drivers will not even slow down for a pedestrian, even if that pedestrian is clinging for life to the front grill of their Suburban Land Yacht. They also will not stop to talk on their cell phones, and they damn sure will not stop for a red light that is less than 10 seconds old. And, of course in Austin, as in the entire state of Texas, it is against the law to use a turn signal. A turn signal may distract other drivers, causing them to stop in the middle of the road, so it is best to not advertise your intentions to turn or change lanes.
- If you park your car in Austin, it will be towed.
- Getting around Austin requires a bit of training. First of all, it is relatively easy to go north and south in Austin, but not so easy to get east or west. And if you are going north or south, the directions will surely begin with, "Go down MoPac... 'cause you sure as hell don't want to mess with I-35." Of course, this rule is changing as more and more people crowd onto MoPac, so in the future all instructions will begin with, "Actually, it's probably faster to just take Lamar." Lamar is a road with no beginning and no end, and everything is "just off" of Lamar, so it is just a matter of time before it becomes a parking lot similar to I-35 and MoPac. Eventually, a major flood of Shoal Creek will drown all the people parked on Lamar. We call this, "thinning the herd. "There is no point going anywhere during "rush hour," which runs from 6:00 to 10:00 in the morning and from 3:00 to 7:00 in the afternoon every work day except Friday (when rush hour starts on Thursday night and lasts all day). On most days, at least one driver is distracted by something during rush hour, which means that everybody has to stop. You should also make a note that Mopac IS Loop 1 -- they are one and the same. Similarly, Capital of Texas Hwy is 360, and Research is 183. 2222 is Northland or Allendale or Koenig, depending on what part of 2222 you are talking about. 290 is Ben White, but there are two 290 exits on I-35 * one of which is 2222 (which, as mentioned earlier, is Northland, Allendale and Koenig). Don't try to figure it out. Just accept it. If you question the intelligence behind this naming convention, people will simply tilt their heads to the right and stare at you.
- Austin is effectively divided into two worlds. The new "tech" people who live "north" of town (north of 183), and the old "true" Austinites who live in the "middle" of town (although census data will no doubt reveal that the true "middle" of Austin is now well north of 183). South of town is hard to describe, so we'll pretend it doesn't exist, and East of town is embarrassing to describe, so we'll pretend it doesn't exist either. North Austin is a plastic, mass-produced world full of chain restaurants and movie theaters. The houses are huge, the yards are small, and the treeless streets have names like "Oak Forest View Circle." Central Austin, on the other hand,tends to attract the granola eating, deodorant-shunning, aging hippie-types. The houses are small and structurally frightening, but they are no less astonishingly expensive, and the businesses tend to be small, privately owned specialty shops that don't sell anything you'd want to buy.
- There is no dress code in Austin. How you look and what you're worth typically have little do to with each other here. In central Austin, it is quite common to see some scruffy, smelly hippie with dread-locks, tattoos and piercings driving a new Lexus or Mercedes. People in Austin like to look weird. The woman you see walking down the drag with the tattoo of a dragon across her back and the purple hair may be your child's kindergarten teacher. Your congressman might be a leather-clad biker. And the girl in the coffee shop serving you a latte may have a Ph.D. in astrophysics. Don't judge a book by it's cover here. In the extreme, there is Leslie, who is technically a bearded man, but who likes to hang out downtown in a teddy and a tiara. Leslie's nuts, but he personifies Austin, and we're not going to get rid of him.
- Austin has a love-hate relationship with tech companies in general and Dell in particular. We love being progressive, and the tech companies represent "the future." However, they're boring, sanitized, and they tend to treat their employees like cattle. Dell is a nasty machine that uses people like a lubricant, grinding them up and cleaning them out when they get messy or inconvenient. People in Austin are beginning to have a sneaking suspicion that George Orwell was right about everything except the date.
- Austinites are largely a bunch of tree-hugging environmentalists. For example, we're strangely and frighteningly proud of our bats. In the summer, the Congress Avenue Bridge is reminiscent of a Hitchcock film, but Austinites flock down there every night to see the show up close and personal. We have a statue devoted to the bats, and we named our hockey team after them (yes, we have a hockey team). The bats rule. As does our salamander. At one time, money-grubbing developers (Freeport-MacMoRan mostly) were building irresponsibly along Barton Creek, and because the bastards (may they rot in hell) couldn't be bothered with things like proper sewage drainage, our beloved swimming hole, Barton Springs Pool, was being polluted with the sewage from Barton Creek Development residents (a.k.a., "rich scum spoor"). Most of the city council and the Texas legislature were in the pockets of the festering scumbag developers, so it was necessary to bring out the big guns-the Barton Creek Salamander, an endangered species that was being threatened by the development sludge. For some reason, in Texas it is okay to make your citizens swim in crap, but it is illegal to make salamanders do so.
- And of course, there is music. Austin is supposed to be the "music capital of the world." We have a shrine for Stevie Ray Vaughn down on Town Lake (yes, it's a lake-it looks like a river to you, but it's a lake); pay your respects if you come to town. While you're at it, swing by Threadgills and pay your respects to the memory of Janis Joplin, and drop by Antone's and pay your respects to the memory of Clifford Antone. He's not dead, but he's in a Texas prison on drug trafficking charges, and that may be just as bad.
Behind the Internet Wheels of Steel - Recording Live From Somewhere - Mixing the Fresh Beats of Technology, Intelligence, Science & Security together with the occasional bass-heavy break of Humor.
"There is no security on this earth, there is only opportunity"
- General Douglas MacArthur (1880-1964)
Tuesday, February 28, 2006
Humor: Rules for Living in Austin, TX
Monday, February 27, 2006
e-Passports - Are we ready?
The State Department started pilot production of electronic passports earlier this month and plans to roll out e-passports for the general public this summer, officials said.
The senior official in charge of the project also said that technical issues raised recently about e-passport security would not prevent the general distribution of the documents.
Visual Design of the e-Passport
RFID Security
Eariler this month a Dutch security firm broke the security of the Dutch e-Passport pilot. They intercepted the data exchange between the RFID reader and passport, stored the encrypted data, and then cracked the password in just 2 hours on a PC giving full access to the digitized fingerprint, photograph, and all other encrypted and plain text data on the RFID tag.
The United States is suppose to use password protection on the new e-passports as well. They are even suppose to include a radio shield in the front cover, therefore reducing radio leakage when the passport is closed.
What happens if the US government issuse thousands of these RFID passports and then the encryption process is broken by some group? Will they re-design and re-issue new cards to everyone?
Does anyone make RFID blocking backpacks? or computer cases? Someone should...
Man, am I glad I just got my passport...won't need a new one for quite some time.
Friday, February 24, 2006
Announcement - Botnet Reporting & Mitigating Mailing List
The security community has lacked a centrally reporting location and this is finally changing. Read the announcment above and join in the fight if willing.
Also note the private email for reporting off-list.
Good stuff.
Thursday, February 23, 2006
Interview with Solar Designer - Creator of John the Ripper
They discuss the new features in John the Ripper 1.7 and the overall idea of password security.
Google Reader "Preview" and "Lens" Script Improper Feed Validation
---------------------------------
Google Reader "preview" and "lens" script improper feed validation ===================================================================
I. DESCRIPTION
Google Reader (http://www.google.com/reader/) helps organise the contents of those rss or atom feeds for which the user is interested in or subscribed to. The user instead of continuously checking his/her favorite sites or discussion groups for updates, (s)he can let Google Reader do it for them.
From news sites to your friends' blogs, Google Reader helps stay up-to-date with all the online information that matters most to the user.
II. VULNERABILITY DETAILS
Google reader is supposed to display only those contents which the user has subscribed to however two vulnerabilities has been identified which may allow an attacker to entice it's victim (using google reader service) to view unwanted web contents carrying malicious payloads.
a. Google reader "preview" script improper feed validation (without user
authentication)
----------------------------------------------------------------------------
Google feed reader "preview" script: The script
(http://www.google.com/reader/preview/*/feed/) is normally used for displaying the feed contents within the reader.
For example, the following request will display the rss content of the link
http://www.microsoft.com/athome/security/rss/rssfeed.aspx:
http://www.google.com/reader/preview/*/feed/http://www.microsoft.com/athome/
security/rss/rssfeed.aspx
Note: '*' in the above link can be replace with any word of your choice otherwise it can be left as it is.
This 'preview' script is only available to authenticated user but if a direct link is provided it doens't ask for user authentication. It can be very usefull for an attacker to mount an attack on its victim by directing them to view the content of malicious sites (carrying evil payloads).
b. Google reader "lens" script improper feed validation (with user
authentication)
----------------------------------------------------------------------------
Google feed reader "lens" script: The script
(http://www.google.com/reader/lens/feed/) is normally used for displaying contents of only those feeds to which an authenticated user has subscribed to.
However, it is possible to pass any rss / atom feed to the script as parameter to which the user has not subscribed but the un-subscribed feed contents can still be loaded within the user reader page.
For example, the following request will display the rss content of the link
http://www.securityfocus.com/rss/news.xml:
http://www.google.com/reader/lens/feed/http://www.securityfocus.com/rss/news
.xml
This 'lens' script is only available to authenticated user and can be usefull for an attacker to mount an attack on its victim by directing them to view the content of malicious sites (carrying evil payloads) even though the user is not subscribed to.
III. VENDOR
Google.com
IV. HISTORY
30th Jan, 2006 - Bug originally discovered
2nd Feb, 2006 - Vendor Notified
...
...
No vendor response
...
...
22nd Feb, 2006 - Vendor Notified again
22nd Feb, 2006 - Public Disclosre
IV. CREDITS
Debasis Mohanty
www.hackingspirits.com
---------------------------------
It isn't a killer RSS hole but just wait...this is just the beginning.
Wednesday, February 22, 2006
Uncomfirmed - Mozilla Thunderbird 1.0.7 : Remote Code Execution & DoS
--------------------------------
Mozilla Thunderbird : Remote Code Execution & Denial of Service
http://www.sysdream.com/article.php?story_id=230§ion_id=78
Tuesday, February 21, 2006
Nmap 4.01 - Kinda old News
Possible False Positive Detection of OSX/Inqtana-B - UPDATED
SP830Series.plugin/Contents/MacOS/SP830Series
Virus: 'OSX/Inqtana-B' detected in /Library/Printers/EPSON/C43Series.plugin/Contents/PDEs/
PrintSetting.plugin/Contents/MacOS/PrintSetting
Virus: 'OSX/Inqtana-B' detected
in /Library/Printers/EPSON/C44Series.plugin/Contents/PDEs/
PrintSetting.plugin/Contents/MacOS/PrintSetting
Virus: 'OSX/Inqtana-B' detected
in /Library/Printers/EPSON/PM860PT.plugin/
Contents/Utility/UTPM860PT.plugin/Contents/MacOS/UTPM860PT
Virus: 'OSX/Inqtana-B' detected
in /Applications/Microsoft Office 2004/Office/ShMem.bundle/
Contents/MacOS/ShMem
Virus: 'OSX/Inqtana-B' detected
in /System/Library/Extensions/
AppleVADriver.bundle/Contents/Resources/mp2decvbin1
Virus: 'OSX/Inqtana-B' detected
in /Applications/4D Client.app/Contents/4D Extensions/4D Carbon Support.bundle/Contents/MacOS/4D Carbon Support
-----------------------------------------
It would appear that Sophos may have a pretty big false positive issue on their hands....or at least I hope it is a false positive....more information to come.
The Sophos website seems to be running very slow (DoS'd), perhaps caused by this new detection issue.
Inqtana uses a Bluetooth vulnerability that was patched in Mid 2005, therefore most people saw the trojan as "low-risk". If my feelings are correct, the outcome of this false positive will be 100 times worse than the trojan itself.
UPDATE - 11:37AM Central
Sophos has pulled the IDE and confimed it was a false positive. Expect a new IDE within 45 mins.
Feb 2006 - Drone Armies C&C Public Report
While this information only appears to cover botnets that are reported, it does show which networks are willing to actively fight this growing problem and which aren't. Hopefully posting this information regularly will change some views and increase awareness of the issue.
Keep up the good work.
Monday, February 20, 2006
2006 - Year of the OS X Exploit?
In my personal view, Apple made the right move in using BSD code in OS X and in moving to the Intel chipset.
However, a smart man once said that every action has an equal and opposite reaction.
Why use OS X?
Apple’s use of the BSD microkernel code has turned OS X into the system of choice for both hackers and security professionals alike. As a result, many applications commonly used by on BSD/Linux have been ported to OS X. Some are even better on Apple, take KisMac for example. But all this positive attention hasn’t developed without some negative attention as well.
Opposite Reaction
Security Researchers and hackers now seem to have their sights on Apple’s OS gem.
- Just today, a serious vulnerability has been found in Apple Safari on OS X. Attackers can run shell scripts on your computer remotely just by visiting a malicious website.
- Hackers have worked to get the new x86 OS X to run on normal x86 hardware.
- Trojans and viruses designed for OS X seem to be on the rise.
Summary
Will 2006 bring an end to Apple’s current threat immunity? Perhaps - Only time will tell, but the force seems to be strong with those that want to dig in the OS X candy coating.
I have outlined several other security concerns for the Apple world with a good friend and hopefully we can put those all together in a more in-depth blog in the future.
Wednesday, February 15, 2006
Fun: Jamaica
We will have a private tour on the next island, so driving around in a rented car/van should be pretty fun. As I have stated before, I am pretty much out of the internet security loop for the rest of the week. I hope the internet doesn't die on me....keep it going guys.
Tuesday, February 14, 2006
Fun: Haiti
Friday, February 10, 2006
Fun: WebShots Backgrounds
www.mydeskcity.com
Not sure Webshots would like it however.
Security Breach Exposes CC Details of 200,000
Details are still coming to light, but right now it sounds something like this -
A pretty big office-supply retailer was hacked and exposed the credit information over perhaps 200,000 people.
Bank of America, Wells Fargo and other banks were alerted by Visa and MasterCard to take security actions for those card holders.
Let’s remember, this isn't some stolen backup tape or a street thief wanting quick money on a laptop...it sounds like a real hacker that targeted the data storage of this retailer. This is my take on the issue and may not be true, but check these quotes from SFGate.com
1) Banking industry sources said they were notified last month by Visa and MasterCard that the computer system of a prominent merchant had been penetrated by a computer hacker, and that account information for thousands of customers had been endangered.
2) Rosetta Jones, a spokeswoman for Visa USA, acknowledged Thursday that the incident involved a U.S. merchant that "may have experienced a data security breach resulting in the compromise of Visa card account information."
3) Sharon Gamsin, a spokeswoman for MasterCard International, said the credit card company had been informed of "a potential security breach at a U.S.-based retailer."
Sounds pretty serious. Visa, MasterCard, BofA and Well Fargo seem to be reacting as required and expected. Issuing new cards and watching accounts is standard for security breach of this nature and is the correct step for customer protection.
So whats the big deal? The "Unknown" retailer is the deal right now.
Under California SB 1386 - requires an agency, person or business that conducts business in California and owns or licenses computerized 'personal information' to disclose any breach of security (to any resident whose unencrypted date is believe to have been disclosed).
So if the above is true, then we can assume one of the following -
1) The "Unknown" retailer has no business in California and therefore is not bound by SB 1386
2) They are bound by the law but all credit information exposed was encrypted.
3) They are bound by the law and they will disclose this breach in due time.
4) They are bound by the law and not following it as it was intended.
Someone needs to find out...and I would guess that we will all have more information very shortly. Keep your eyes out for this one.
Again, take this whole article with a gain of salt because information is will change.
The Secret 64-bit Life of the Intel Core Duo
More details are sure to be exposed. Is OS X 64-bit? Seriously, I am asking you....
Google Desktop = Security Risk?
February 09, 2006
Google Copies Your Hard Drive - Government Smiles in Anticipation
Consumers Should Not Use New Google Desktop
San Francisco - Google today announced a new "feature" of its Google Desktop software that greatly increases the risk to consumer privacy. If a consumer chooses to use it, the new "Search Across Computers" feature will store copies of the user's Word documents, PDFs, spreadsheets and other text-based documents on Google's own servers, to enable searching from any one of the user's computers. EFF urges consumers not to use this feature, because it will make their personal data more vulnerable to subpoenas from the government and possibly private litigants, while providing a convenient one-stop-shop for hackers who've obtained a user's Google password.
"Coming on the heels of serious consumer concern about government snooping into Google's search logs, it's shocking that Google expects its users to now trust it with the contents of their personal computers," said EFF Staff Attorney Kevin Bankston. "Unless you configure Google Desktop very carefully, and few people will, Google will have copies of your tax returns, love letters, business records, financial and medical files, and whatever other text-based documents the Desktop software can index. The government could then demand these personal files with only a subpoena rather than the search warrant it would need to seize the same things from your home or business, and in many cases you wouldn't even be notified in time to challenge it. Other litigants—your spouse, your business partners or rivals, whoever—could also try to cut out the middleman (you) and subpoena Google for your files."
The privacy problem arises because the Electronic Communication Privacy Act of 1986, or ECPA, gives only limited privacy protection to emails and other files that are stored with online service providers—much less privacy than the legal protections for the same information when it's on your computer at home. And even that lower level of legal protection could disappear if Google uses your data for marketing purposes. Google says it is not yet scanning the files it copies from your hard drive in order to serve targeted advertising, but it hasn't ruled out the possibility, and Google's current privacy policy appears to allow it.
"This Google product highlights a key privacy problem in the digital age," said Cindy Cohn, EFF's Legal Director. "Many Internet innovations involve storing personal files on a service provider's computer, but under outdated laws, consumers who want to use these new technologies have to surrender their privacy rights. If Google wants consumers to trust it to store copies of personal computer files, emails, search histories and chat logs, and still 'not be evil,' it should stand with EFF and demand that Congress update the privacy laws to better reflect life in the wired world."
For more on Google's data collection:
http://tinyurl.com/chxk6
http://tinyurl.com/7wjyg
http://tinyurl.com/d85wt
http://tinyurl.com/aujee
Contact:
Kevin BankstonStaff AttorneyElectronic Frontier Foundation
bankston@eff.org
Posted at 11:04 AM
---------------------------------------------
When the first Google Desktop was released, I pushed up the ranks for this to not be used in the corporate world. People can (and will) do what they want on their personally computers, but in the business world...the "unknown" risk of this software is just unnecessary.
As attackers move away from OS levels, applications security problems will hit center stage. We are seeing this start to happen right now.
Remember the old OS security measure of reducing the number of running services? This reduces your online signature and therefore reduces the attack pathways. The same idea can be applied for system security at the application level.
More Applications = more lines of running code = higher change of security vulnerabilities
Need I say more....
Thursday, February 9, 2006
AOL/GoodMail - The Internet's First Email Tax
Ahh, back in the day. I remember when friends would tell me about how the Postal Service was going to impose a 5 cent surcharge on every e-mail message sent via the Internet. I used to laugh and just say "Ohh that is just an urban legend".
Well, sometimes the truth is scarier than legend. Change "Postal Service" to "AOL/Yahoo" and you are pretty close to truth.
AOL and Yahoo have decided that creating "mail classes" is the next best way to fight spam. They believe that by charging companies just factions of a penny, that they can cut spam. Factions of a penny? That isn't alot? Do you remember "Office Space"? It is alot....really alot.
I am not so sure that I agree with this method. Sounds like a way to make extra money, pretend they are doing something about the spam problem and a great way for other companies to spam directly into your inbox all the time by bypassing spam filters.
It also sounds like a GREAT reason to drop AOL for a better ISP, like you should have done years ago IMHO. If the systems doesn't catch on like expected, AOL may be running their own customers away. Kinda like Sony and the RIAA.
The New York Times had a great article on this very subject earlier this month. "AOL users will become dissatisfied when they don't receive the e-mail that they want, and when they complain to the senders, they'll be told, 'it's AOL's fault,' " said Richi Jennings, an analyst at Ferris Research, which specializes in e-mail.
AOL and Yahoo will be using Goodmail Systems’ processing system to collect the electronic postage and verify the identity of the sender. AOL will be implementing the system in the next two months, while Yahoo will be trying the system out, and has not yet decided how paid vs. unpaid mail will be treated.
Supporters of the system, say it is just like preferred mail classes at your post office. People against the system say it is only going to hurt customers and will be another nail in the "internet e-mail" coffin.
David Stanley, vice president and managing director of messaging security company CipherTrust, said the plan was "a ridiculous idea" and "nothing more than a money-making idea that will not stop spam but will give account holders free reign to send all sorts of 'authenticated' mail."
Umm, I guess the people of the world will have to get together, buy all the dark fiber and create an Open Source Internet. ;)
Wednesday, February 8, 2006
IE7 Beta Breaks Google AdSense
"Considering that by the end of the year, IE7 should be available for almost all versions of Windows, unless Microsoft wants to face the ire of developers everywhere, it had better fix this," Nathan Weinberg of the InsideGoogle Web log wrote Wednesday. Although it is unknown as to why this is occurring, it is suspected it may have to do with how IE7 now handles JavaScript. Microsoft could not be reached for comment.
-------------------------------------------------
Add this little piece of information with the rumors of Vista being released on Dec 1st and you have a adsense money problem in the making. =)
I guess Microsoft can fix this issue when they fix the Remote Code Execution buffer overflow flaw found on several weeks ago.
WMF Vulnerability Returns for IE5
(91333) Vulnerability in Internet Explorer Could Allow Remote Code Execution
This new advisory only relates to the following two cases :
1) Internet Explorer 5.01 SP4 on Microsoft Windows 2000 SP4
2) Internet Explorer 5.5 SP2 on Microsoft Windows Millennium
Note - This is not the same issue as the one addressed by MS06-001
Secunia Advisories (SA18729) - Highly Critical - System Access
Candidate CVE-2006-0020
It would appear that this might be connected to the flaw pointed out by HD Moore on the FunSec mailing list in Jan.
--------------------------------
More where that came from. The fun thing about these is that they DO apply to Windows 96, 98, 2000-2003, Vista. You can trigger it via RTF, directly inside IE, and anything else that loads metafiles. A fun bug you can find in a certain WMF parsing application...:
uint_size = wmf_header.size * 2;
ptr = malloc(uint_size);
read(fd, ptr, uint_size - sizeof(wmf_header));
:-)
-HD
---------------------------------
Upgrading to IE 6 SP1 is the suggested action on Windows 2000 SP4 and Windows ME
No patch for the older IE5. My suggested action would to get off Windows ME as soon as possible. The Win9x kernel is dead as dead...
Science: NASA Appointee Resigns
Mr. Deutsch's resignation came on the same day that officials at Texas A&M University confirmed that he did not graduate from there, as his résumé on file at the agency asserted.
...
Mr. Deutsch, 24, was offered a job as a writer and editor in NASA's public affairs office in Washington last year after working on President Bush's re-election campaign and inaugural committee, according to his résumé. No one has disputed those parts of the document.
According to his résumé, Mr. Deutsch received a "Bachelor of Arts in journalism, Class of 2003."
Yesterday, officials at Texas A&M said that was not the case.
"George Carlton Deutsch III did attend Texas A&M University but has not completed the requirements for a degree," said an e-mail message from Rita Presley, assistant to the registrar at the university, responding to a query from The Times.
Repeated calls and e-mail messages to Mr. Deutsch on Tuesday were not answered.
Mr. Deutsch's educational record was first challenged on Monday by Nick Anthis, who graduated from Texas A&M last year with a biochemistry degree and has been writing a Web log on science policy, scientificactivist.blogspot.com.
--------------------------------------------
All political comments aside, how can a person work for the President and then for NASA and no one checks on their college degree??
Mind-blowing...