Sunday, June 21, 2009

Senior Al Qaeda & Afghan Taliban Leaders Meet with Baitullah Mehsud

Via The Long War Journal -

Senior al Qaeda and Afghan Taliban leaders are reported to have met with Pakistani Taliban leader Baitullah Mehsud to advise him to move his group's operations into Afghanistan and halt attacks against the Pakistani state.

Several meetings were said to have been held last week after an 11-man delegation of al Qaeda and Taliban heavy hitters arrived in Waziristan to deliver a request from Mullah Omar, the Amir al Mumineen, or the leader of the faithful in Pakistan and Afghanistan, according to a report in The Nation.

The Taliban dispatched Sirajuddin Haqqani, the powerful military commander of the Haqqani Network, and Abdul Hakeem Sharaee and Mir Ahmad Jan Hashemi, two senior deputies of Mullah Abdullah Zakir, the Taliban's senior-most military commander in southern Afghanistan who was released from Guantanamo Bay.

Al Qaeda sent Abu Yahya Al Libi, one of al Qaeda's senior ideologues and a representative of the religious committee, and Abdul Haq Turkistani, the leader of the Eastern Turkistan Islamic Party, an al Qaeda-linked group that is made up of Uighurs who fight the Chinese government. Abdul Haq serves on al Qaeda's Shura Majlis, or executive council.

The joint Taliban and al Qaeda delegation reportedly advised Baitullah to halt the Pakistani Taliban's attacks against the military and government and to focus his energy in Afghanistan. The leaders believe Baitullah's terror attacks against the Pakistani state are putting undue pressure on the Taliban in both Pakistan and Afghanistan and threaten to damage the overall Taliban movement.

The Taliban and al Qaeda leadership are concerned that even a limited Pakistani military offensive in the tribal areas will put their training camps and safe houses throughout the border regions at risk as the Afghan Taliban is gearing up for a major fight with Coalition and Afghan forces.

Baitullah was reportedly advised to dodge the nascent Pakistani Army offensive in South Waziristan and move the bulk of his forces into Afghanistan to carry out attacks against Afghan and Coalition forces.

The Taliban and al Qaeda delegation was also reported to have advised North Waziristan Taliban leader Hafiz Gul Bahadar to provide safe passage for Baitullah and his Taliban army.

Baitullah is said to have rejected the request from Mullah Omar, responding, "Mullah Omar is our Amir but like Afghanistan, they [the Pakistani Taliban] are determined to continue resistance in Pakistan."

Baitullah also met with the shura of the United Mujahideen Council, the alliance with South Waziristan Taliban warlord Mullah Nazir and powerful North Waziristan leader Hafiz Gul Bahadar. Nazir, who is being pressured by the Pakistani government to sit out the operation against Baitullah, is said to have not attended, according to the Islamabad Ausaf, a pro-jihadi Urdu-language newspaper. Bahadar offered Baitullah safe passage through to Afghanistan, as advised by the al Qaeda and Taliban delegation.

------------------------------

All the while, the Pakistani military is continuing ground operations in its South Waziristan offensive against Baitullah's forces.

Heavy fighting has broken out in South Waziristan as the Pakistani Army and paramilitary Frontier Corps have begun moving ground forces forward into tribal areas run by Taliban chieftain Baitullah Mehsud.

More than 30 Taliban fighters have been reported killed in separate engagements in South Waziristan. Pakistani forces, backed by Air Force F-16 fighter-bombers, attack helicopters, and artillery, have begun to engage Baitullah's forces in earnest.

The clashes "should be read as the formal launch of an offensive against Baitullah," Pakistani intelligence officials told AFP.

Read more about the ongoing offensive here.

Tools of the Trade - Tentacled Snake Uses Fish's C-Start in Predictive Attack

Forget the old folk tales about snakes hypnotizing their prey. The tentacled snake from South East Asia has developed a more effective technique. The small water snake has found a way to startle its prey so that the fish turn toward the snake's head to flee instead of turning away. In addition, the fish's reaction is so predictable that the snake actually aims its strike at the position where the fish's head will be instead of tracking its actual movement.

-----------------------

On to the tools....

On June 20th, Foxit Reader 3.0.1817 was released. Foxit Reader is a free PDF document viewer, with incredible small size, breezing-fast launch speed and rich feature set.

On June 17th, Rsnake released the Slowloris HTTP DoS tool. Slowloris helps identify the timeout windows of a HTTP server or Proxy server, can bypass httpready protection and ultimately performs a fairly low bandwidth denial of service. SANS Internet Center has a blog entry describing possible mitigation techniques.

On June 16th, Irfan Skiljan released IrfanView 4.25. IrfanView is a very fast, small, compact and innovative Freeware (for non-commercial use) graphic viewer for Windows. I have been using this viewer on my personal Windows boxes for many years. This release fixes a serious integer overflow vulnerability in the 1BPP Image resampling, so this is a recommended update for all users. Check out the version history for all the other details.

On June 15th, Wireshark 1.2.0 was released. This version has many fixes and improvements, including a Windows 64-bit installer and improved support for OS X. Check out the release notes.

On June 15th, TrueCrypt 6.2a was released. TrueCrypt is a software system for establishing and maintaining an on-the-fly-encrypted drive. Check the version history for change details.

On June 12th, Nmap 4.8.5 BETA 10 was released. This tool needs no introduction and this beta, like most Nmap betas, is pretty stable. Check out the changelog for all the details.

On June 6th, KeePass 1.16 was released. KeePass is a free open source password manager, which helps you to manage your passwords in a secure way. The databases are encrypted using the best and most secure encryption algorithms currently known (AES and Twofish). Check the news release for details on the new version.

On May 31th, OfficeMalScanner was released by OfficeMalScanner is a Microsoft office forensic tool to scan for malicious traces, like shellcode heuristics, PE-files or embedded OLE streams. It supports disassembly and hexview as well as an easy brute force mode to detect encrypted files.

On May 29th, Java JRE 6 Update 14 was released. Check out the release notes for all the details.

On May 29th, Kismet-2009-05-RC2 was released. Kismet-2009-05-RC2 fixes a 1-character bug which led to corrupted logfile names and bad kismet_server launching.

On May 29th, VirtualBox v2.2.4 was released. VirtualBox is a powerful x86 virtualization product for enterprise as well as home use. Check the changelog for all the details.

On May 28th, Technitium MAC Address Changer v5 R3 has been released. Technitium MAC Address Changer allows you to change Media Access Control (MAC) Address of your Network Interface Card (NIC) irrespective to your NIC manufacturer or its driver. Release 3 adds support for Microsoft Windows Vista/Server 2008 Service Pack 2.

On May 28th, CCleaner v2.20.920 was released. CCleaner is a freeware system optimization, privacy and cleaning tool. It removes unused files from your system - allowing Windows to run faster and freeing up valuable hard disk space. Check out the version history for all the details.

On May 27th, Cain & Abel v4.9.31 was released. This version includes:
  • SIPS Man-in-the-Middle Sniffer (TCP port 5061; successfully tested with Microsoft Office Communicator with chained certificates).
  • Added support for RTP G726-64WB codec (Wengo speex replacement ) in VoIP sniffer.
  • X509 certificate's extensions are now preserved in chained fake certificates generated by Certificate Collector.
  • Extended ASCII characters support for SSID in Passive Wireless Scanner.
  • Some bugs in Cain's Traceroute fixed.

Saturday, June 20, 2009

CERN - Large Hadron Collider Restart Delayed Till October

Via Physorg.com -

The Large Hadron Collider was meant to restart in late September, but that will probably be pushed back two to three weeks, a spokesman for the European Organization for Nuclear Research said.

"We're pretty confident about the dates," James Gillies told The Associated Press, adding that scientists believe they understand the error that happened last year and how to prevent it occurring again.

An electrical fault caused by a faulty splice in the wiring shut down the giant machine on Sept. 19, nine days after it was started up with great fanfare.

The 20-nation operator, known as CERN, expects repairs and additional safety systems to cost about 40 million Swiss francs ($37 million) over the course of several years, Gillies said.

Once it is running, scientists will use the machine to smash together protons from hydrogen atoms inside a 27-kilometer (17-mile) circular tunnel under the Swiss-French border near Geneva. By recording what particles are produced by the collisions they hope to better understand the makeup of the universe and everything in it.

Sunbelt: Green Dam = Spyware

Via Sunbelt Blog -

Sunbelt Software has added detections to its products to find and remove Green Dam-Youth Escort, the Internet filtering (and spyware) software that the Chinese government requires on all new computers sold in the country after July 1.

We classify it as a surveillance tool with a rating of “moderate risk” and we recommend that CounterSpy™ and VIPRE® users quarantine it.

We’re going to be reading a lot about Green Dam-Youth Escort in coming weeks (months? years?) The government of China mandated that it be installed on new machines to protect its citizens from obscene and harmful content. Computer users are allowed to uninstall it.

The Chinese Ministry of Industry and Information Technology bought the rights to the application for one year through a no-bid $6 million purchase from Jinhui Computer System Engineering Co. of Zhengzhou. Jinhui also stands to make a mountain of money after one year since users will be required to pay for updates. It was estimated recently that there are 253 million Internet users in China.

Most observers assume it also is to prevent Chinese Internet users from seeing content critical of the government. The Chinese government already operates a “Great Firewall” to filter Internet content (including politically sensitive sites) but it can be bypassed.

Politics aside, there are some serious problems with Green Dam:
-- It has the capacity to monitor keystrokes.
-- It logs the URLs of sites the user has attempted to reach.
-- It uses unencrypted data transfer from clients to company servers.
-- OpenNet Initiative said Green Dam can monitor activities in addition to Web browsing and can shut down applications.
-- The black-list update process is vulnerable to compromise
-- Exploit code has been posted that compromises Internet Explorer on computers running Green Dam. It uses a stack overflow in the browser process triggered by an overly long URL. It works on Microsoft’s latest Vista operating system too.
-- Solid Oak Software Inc. of Santa Barbara, Calif., is bringing a legal action in China, claiming that Jinhui used code from its CyberSitter filtering software. Jinhui denies the allegation.

There have been reports from testers that Green Dam slows browsers and doesn’t filter properly. It uses color-tone filtering to spot pornographic images, but there are reports that it misses images of dark-skinned people and mistakenly filters images of pigs.

The Green Dam black list

Bloggers familiar with China who have read through the Green Dam black list of words to be filtered found that it contains about 2,700 words related to pornography and about 6,500 “politically sensitive” words.

The political blacklist includes:

June 4th (Date of military attack on Tiananmen Square protestors that left 2,500 dead)
democracy
liberty
essence (?)
fallacies and heresies

The porn-related words include:

Cat-III (Hong Kong film industry “adult” rating)
Naked
Homosexuality

And, nobody-knows-what, maybe a typo or a new euphemism for a sex act:

Fanyu (originally a little known word found in a few Buddhist scriptures)

For more, see here.
Or here.

Exploit code here.

iPhone 3.0 PwnageTool & redsn0w Released

Via HackaDay.com -

The iPhone dev-team has released an updated version of PwnageTool. It supports jailbreaking iPhones using the 3.0 firmware. This update does not include the much easier to use QuickPwn, but it should be coming soon. The release also doesn’t include the UltraSn0w unlock which will be coming via Cydia.

----------------------------

Via Dev-Team Blog -


redsn0w is an easy to use, multi-platform, multi-device jailbreaking and unlocking (iPhone 2G only) tool for the iPhone 2G (original iPhone), the iPhone 3G (but not the 3GS) and also the iPod touch (first and second generation). Currently it is available for Windows and Mac OS X (there are some issues using redsn0w with OS X PPC, please use an Intel Mac until we have this problem resolved).

El Chapo: The Most Wanted Man in Mexico

Via News Week International -

The guards at the city club mall in downtown Culiacán refused to talk about the bullet holes in the parking lot. Or about the cross stuck into the pavement, inscribed with three pairs of initials and a melancholy tribute in Spanish: WE WILL LOVE YOU ALWAYS. But almost anyone in this city of 1 million could tell you what happened here a little before 9 p.m. on May 8, 2008: how three men climbed unawares into their white SUV after shopping at the mall; how three other cars zoomed up then unleashed a fusillade of AK-47 gunfire and a single blast from a bazooka. All three men were killed, two of them body-guards for the third, a hulking 22-year-old named Edgar Beltrán Guzman—the son of Joaquín Guzman Loera, better known as El Chapo ("Shorty"), the most wanted man in Mexico.

Culiacán is the bare-knuckle state capital of Sinaloa, laid out between the Pacific Ocean and the Sierra Madre mountains, about 350 miles northwest of Mexico City. I'd come here, as journalists do, in search of El Chapo. If I hung around long enough, I'd been told, I might catch him at one of his famous restaurant drop-bys. (His bodyguards sweep the room, confiscating all mobile phones before his dramatic entrance; he picks up everyone's tab afterward.) But when I arrived in town in early April, El Chapo hadn't been seen in public since his son's murder. He'd gone underground, thanks in part to President Felipe Calderón's all-out war on the drug cartels—2,500 troops were now based in Culiacán and carrying out daily raids—but also because of a bloody feud with a former close ally and boyhood friend, Alfredo Beltrán Leyva, nicknamed Mochomo ("Redhead").

Earlier this month a shootout between Mexican police and Mochomo's gang left 18 people dead in Acapulco. The same gang allegedly killed El Chapo's son—revenge, it's said, after El Chapo betrayed Mochomo to federal authorities. (Javier Valdez, an investigative reporter who looked into Mochomo's arrest for the respected local newsweekly Rio Doce, believes that the federales talked Guzman into giving up his onetime ally. "The government was saying, 'We need somebody, we want somebody,' so to lower the pressure, El Chapo turned in Mochomo," he says.) In revenge, hundreds of narcotraficantes in Culiacán were killed. Victims were found shot dead in parked cars, decapitated, burned, rolled up in bloody blankets and dumped on the roadside. The satirical monthly La Locha ran a helpful glossary of drug-related terminology, including encobijado (a body wrapped up a blanket), ladrillo (a kilo brick of cocaine) and encajuelado (a corpse stuffed in a trunk).

Matters got so bad that at the end of last year, a state official reportedly trekked up to a ranch in Durango state, deep in the eastern Sierra Madre, and got the jefe and Mochomo's men to agree to a truce. (Government officials acknowledge a peace deal but deny any role in it.) Guzman was said to have gone to ground, holed up at one of his tightly guarded haciendas in the mountains. The Sierra is "wild country, the natural place for El Chapo," says Ismael Bojórquez Perea, the editor of Rio Doce. "He feels good and secure up there."

Culiacán's economy has since gone into a tailspin. Nightclubs, discos and restaurants that had catered to the narcos shut down. The downtown street where chirrines—Mexican horn-and-string bands—once waited to be hired for spontaneous fiestas were dark and deserted. Nobody, I was told, felt much like celebrating. And nobody wanted to talk about El Chapo.

-------------------------

There is much more to the article...good read passed to me by a friend.

Spacebook: NASA's Internal Facebook

Via FCW.com -

NASA’s Goddard Space Flight Center has developed a homegrown social-networking application that provides all NASA employees with the types of features found in Facebook but in a secure environment.

Spacebook, which offers user profiles, group collaboration tools and social bookmarking, is available through NASA’s intranet, according to Linda Cureton, Goddard’s chief information officer, who announced the launch, appropriately enough, on her blog.

CIOs are eager to take advantage of the collaboration technologies available through commercial social-networking sites, such as Facebook and Myspace, but they have valid security concerns, Cureton writes. “Launching capabilities like this on internal networks reduces those barriers of entry.”

NASA’s Ames Research Center and Kennedy Space Center have developed their own social-networking applications based on SharePoint, she notes. At some point, the space agency might integrate those with Spacebook.

“One of the most amazing things about these Web 2.0 technologies, and the greatest value to NASA, is the ability to help us create a culture of engagement and collaboration that makes each individual employee much more effective,” Cureton writes.

Somalia Seeks Emergency Military Help

Via VOA News -

Somalia's beleaguered U.N.-supported government says the country is in danger of being taken over by Islamist militants with ties to al-Qaida. It has sent out an appeal for neighboring countries to intervene militarily in Somalia within the next 24 hours.

Speaking to reporters in the capital Mogadishu Saturday, Somali Parliament Speaker Sheik Aden Mohamed Nur "Madobe" made a startling appeal.

The speaker says the government has been weakened by rebel forces and now needs military intervention from Somalia's neighbors - Djibouti, Ethiopia, Kenya, and Yemen - in the next 24 hours.

Echoing remarks made by Somali President Sheik Sharif Sheikh Ahmed in recent days, Madobe says the government is fighting al-Qaida, which has established bases in Somalia and is determined to take over the country.

Reports say two days of heavy fighting in north Mogadishu between government and pro-government forces and Islamist insurgent groups, led by al-Qaida-linked al-Shabab and its ally Hisbul Islam, have prompted thousands of people to flee from the area. The neighborhoods currently under siege once provided refuge for residents fleeing violence in other parts of the capital. Both warring sides are claiming victory, but there has been no independent confirmation.

Late Friday, gunmen kidnapped and killed Mohamed Hussein Adow, a lawmaker close to President Sharif. He was the third government official to be killed violently in as many days. On Thursday, the country's security minister, Omar Hashi Aden, died in a suicide bombing at a hotel in Beletweyne near the border with Ethiopia.

[...]

Despite repeated denials from the government in Addis Ababa, Ethiopia is believed to have already deployed hundreds of troops back into Somalia in recent weeks to counter the growing military strength of al-Shabab. Ethiopia is also said to have given training to pro-government militias now fighting on the frontlines.

Meanwhile, the Somali government and the United States charge that Ethiopia's arch enemy in the region, Eritrea, is fanning violence by providing arms and weapons to Somali extremists as part of a continuing proxy war against Ethiopia.

On Friday, Kenya, which suffered two al-Qaida-related terrorist attacks on its soil in 1998 and 2002, indicated that it was willing to consider sending troops to Somalia. Kenya's Foreign Minister Moses Wetangula said the threat posed by Somali militants was too great to ignore.

"We will not sit back and watch the situation in Somalia deteriorate beyond where it is. We have a duty - a constitutional duty as a country and as a government - to protect our strategic interests including our security," he said.

Horn of Africa analysts and observers have long warned that the conflict in Somalia had the potential to trigger a wider regional war.

Friday, June 19, 2009

BackTrack Pre Final – Public Release and Download

Via offensive-security.com -

The Remote Exploit Team is ecstatic to announce the public release of BackTrack 4 Pre Final (codename “pwnsauce“). A VMWare Image of BT4 will be released in a few days. We have major changes in BackTrack, and have tried to document and summarize them as best as possible. See the BackTrack Guide PDF for more info.

Check out our BackTrack Videos and Resources, our BackTrack PDF, and our Introduction to BackTrack 4” movie.

We’ve opened up new subforums for this release. Please report bugs and suggestions!

As usual, we ask that you do not link directly to our mirrored ISOs. We are trying to get a rough download count for BT4pf.

If you would like to link to our iso, please use :

http://www.remote-exploit.org/cgi-bin/fileget?version=bt4-prefinal-iso

md5sum and sha256sum can be found here, here and here. The Remote Exploit Website News page will be soon updated.

Enjoy!

Remote Exploit Team

One Reason the Taliban Should Hate Linux

Via theinquirer.net -

The recent Paris Air Show revealed a new range of UAVs, which apparently have been using Linux based operating systems to power missions to blow up mostly women, children and old people in Afghanistan and the tribal lands of Pakistan, and occasionally a few Taliban terrorist camps.

According to Flight Global, a look under the bonnet of a Raytheon surveillance KillerBee UAV revealed that the whole beast was under the control of a heavy fuel engine with a Linux-based computer control system.

Raytheon is offering its KillerBee-4 version to the US military with still more open sauce killer goodness.

Clearly whoever designed the code for the KillerBee-4 had no problem finding the right drivers.

It has some impressive requirements. It can track objects both during the day and after dark by using a system of live video and infrared sensors.

It can also fire precision guided munitions by using an on-board laser for target designation.

Either way, there are going to be parts of Afganistan and Pakistan where GLP is going to listed alongside barber shops and music stores as something never to be seen

CDC: Novel H1N1 Flu Situation Update

http://www.cdc.gov/h1n1flu/update.htm?s_cid=tw_flu26

United States H1N1 Flu Update 6/19/09
21,449
Confirmed & Probable Cases of novel H1N1 flu, 87 deaths, 53 states/territories affected

On June 11, 2009, the World Health Organization (WHO) raised the worldwide pandemic alert level to Phase 6 in response to the ongoing global spread of the novel influenza A (H1N1) virus. A Phase 6 designation indicates that a global pandemic is underway.

More than 70 countries are now reporting cases of human infection with novel H1N1 flu. This number has been increasing over the past few weeks, but many of the cases reportedly had links to travel or were localized outbreaks without community spread. The WHO designation of a pandemic alert Phase 6 reflects the fact that there are now ongoing community level outbreaks in multiple parts of world.

WHO’s decision to raise the pandemic alert level to Phase 6 is a reflection of the spread of the virus, not the severity of illness caused by the virus. It’s uncertain at this time how serious or severe this novel H1N1 pandemic will be in terms of how many people infected will develop serious complications or die from novel H1N1 infection. Experience with this virus so far is limited and influenza is unpredictable. However, because novel H1N1 is a new virus, many people may have little or no immunity against it, and illness may be more severe and widespread as a result. In addition, currently there is no vaccine to protect against novel H1N1 virus.

In the United States, most people who have become ill with the newly declared pandemic virus have recovered without requiring medical treatment, however, CDC anticipates that there will be more cases, more hospitalizations and more deaths associated with this pandemic in the coming days and weeks. In addition, this virus could cause significant illness with associated hospitalizations and deaths in the fall and winter during the U.S. influenza season.

Ex-aide Claims Taliban Chief Behind Bhutto Assassinatio

Via CNN -

A close aide to Pakistan's Taliban chief Baitullah Mehsud said he is breaking ties with him and confirmed reports that Mehsud was behind the assassination of former Prime Minister Benazir Bhutto.

Qari Turkestan Bhitaini, a self-proclaimed right-hand man of Mehsud, said Mehsud was behind the December 27, 2007, assassination of Bhutto, Pakistan's Express TV reported.

Bhitaini said he is breaking ties with Mehsud because he blames the Taliban chief for killing scores of innocent Muslims in recent attacks in Lahore.

The Pakistani government and CIA officials have said in the past that Mehsud was responsible for Bhutto's death.

Bhutto, 54, was heading the opposition to then-President Pervez Musharraf when she was assassinated during a campaign rally in Rawalpindi ahead of parliamentary elections.

The Pakistani government, who has struggled to control terrorism, is waging a military offensive against the Taliban in the country's North West Frontier Province.

Terror Groups Looking to Recruit Computer Experts

Via MSNBC.com -

Terrorist groups that have long used the Internet to spread propaganda are increasingly tapping the Web to teach Islamic extremists how to be hackers, recruit techies for cyberwarfare and raise money through online fraud, U.S. officials say.

A senior defense official said intelligence reports indicate extremist groups are seeking computer experts, including those capable of breaching government or other sensitive network systems.

The official, who spoke on condition of anonymity to discuss sensitive information, said the extent and success of those recruiting efforts are unclear.

But jihadists' interest in hacking is evident in forums across the Internet. Law enforcement officials say terrorists are branching out into Internet fraud to raise money for their operations.

One Internet forum, the Mujahedeen Electronic Net, offers hacking instructions in a number of postings. A lengthy posting markets a weekly course and limits it to regular contributors to the Web site who confirm they are committed to Islam. The author of the offer claims the course will be taught by "experts in the electronic jihad," according to a translation of the posting.

Last week, U.S. and Italian authorities broke up an international telephone fraud ring that had roots in Italy and employed hackers in the Philippines. The operation is believed to have funneled thousands of dollars to terrorist groups in Southeast Asia.

Italian officials drew a fragile link to Osama bin Laden. They said one of the men charged with financing the hacking scheme had close ties to members of the International Islamic Efforts Foundation, a Philippines-based group linked to an Islamic charity organization once headed by one of bin Laden's brothers-in-law, Muhammad Jamal Khalifa. Khalifa was reported killed in 2007 during a burglary in Madagascar, where he had a sapphire business.

To date, experts say extremists largely have engaged in "sport hacking" — defacing or taking down Web sites belonging to groups they consider enemies, such as sites featuring Shiite, Jewish or Christian beliefs.

"It's more for propaganda value than for tactical value," said Jarret Brachman, a former West Point researcher who is an expert on jihadist groups.

[...]

But some recent activity suggests there may be an aggressive push among extremists for expertise such as engineering and technical backgrounds that could be used against the U.S. government or other vital systems.

A senior counterterrorism official, who also requested anonymity in order to speak on the sensitive matter, said al-Qaida is known to seek out followers with scientific knowledge, and computer ability is a logical step.

Adam Raisman, a senior analyst at the Washington-based SITE group, an organization that monitors militant Web sites, said he has seen pitches for people adept at photo or flash video programs that can be used to build propaganda Web sites or take down sites considered offensive.

But, he added, "It's very difficult to gauge what they will do if they have the ability to penetrate a network and realize the damage they can create."

Brachman described a growing network of people in the U.S. who go online and "cheer from the sidelines. They will never do anything violent, but they have the skill sets to do low-level hacking and this is a way they can play."

[...]

Terrorist groups lack the skills to match the abilities of sophisticated governments such as the U.S., China and Russia in launching widespread Web attacks, but they could hire someone who does, Steven Chabinsky, assistant deputy director of cyberissues for the Obama administration's director of national intelligence, recently told a technology conference.

Reaching out to hackers with equipment and expertise could enable those groups to transmit viruses or worms to take over computers and direct them to send spam, carry out identity-theft or take down Web sites.

Some officials contend that extremists don't have to take down a critical network or system to have an impact. Even the ability to penetrate and deface a well-trafficked Web site could shake public confidence in the government.

Minor Safari Cross Domain Bug

Via The Spanner UK -

I found this while writing Astalanumerator. Safari allows you to overwrite top and parent with native code and maybe other stuff (I haven’t tried). This allows you to define something on domain A and call it on domain B using the top and parent. I’d email Apple about it but the last time I reported XSS on the Apple store they ignored me.

You could use this in dom based XSS situations when you have control over a link. The attack would work like this:-

PHPIDS

But the remote site would include a iframe to the target page and refining parent/top as setTimeout or eval. You could also use “name” in this instance to provide a XSS payload.

Here is the POC for the cross domain in action, I use subdomains in this instance but any domain could be used:-

Safari poc

BBC Enlisting New Satellites to Broadcast in Iran

Via Google (AP) -

The BBC is using two extra satellites to broadcast its Farsi-language service after days of jamming it blamed on Iran.

The British state-run news organization said the move was meant to help it reach its Iranian audience as the crisis over their country's disputed election deepens. It is also a challenge to Iran's religious government, which has accused foreign broadcasters of stirring unrest, singling out the BBC in particular.

"This is an important time for Iran," BBC World Service Director Peter Horrocks said in a statement. "We hope that by adding more ways to access BBC Persian television, Farsi-speaking audiences can get the high quality news, analysis and debate they clearly desire."

As huge protests have followed the re-election of hardline President Mahmoud Ahmadinejad, Iran has moved to deprive people of independent sources of news.

BBC Farsi, Facebook, Twitter and other sites have been blocked. Text messaging has been cut off for the past week, and cell phone service in Tehran is frequently down. The BBC said the Hot Bird 6 satellite — which it and other broadcasters use to broadcast to the Middle East, North Africa, and Europe — has been subject to aggressive interference.

Even before the presidential election, Iran's supreme leader, Ayatollah Ali Khamenei, blasted foreign broadcasters for their coverage of the campaign, accusing them of demoralizing voters and trying to drive down turnout. Shortly after Ahmadinejad's victory, he accused international media of waging a "psychological war" against the country.

The BBC has covered the protests extensively. Its Farsi service, like that of U.S. broadcaster Voice of America, is followed by many Iranians and has often carried news of clashes with police, attacks on demonstrators and arrests of opposition activists.

Ahmadinejad has bristled at the coverage: His supporters were shown earlier this week wielding signs with "BBC" crossed out in red. The U.K.'s ambassador was summoned to hear complaints from Iranian officials. In a nationally broadcast speech Friday, Khamenei accused Western broadcasters stirring up chaos.

"Some of our enemies in different parts of the world intended to depict this absolute victory, this definitive victory, as a doubtful victory," Khamenei said. "It is your victory. They cannot manipulate it."

The BBC said it was making its Farsi-language service available on satellite Eutelsat W2M, which it said Iranians could tune into by making a small adjustment to their satellite dishes. The BBC also said the service would soon be available on Egyptian satellite Nilesat and it was increasing the length of its Farsi radio program.

U.S.-funded Radio Free Europe/Radio Liberty, based in central Europe, is also working to step up its satellite program, according to spokesman Julian Knapp. He said interference had increased "on all fronts" but said the service used a variety of ways to stream content into the country, including stepping up shortwave broadcasting.

The Voice of America, based in the Washington, did not immediately return a call seeking comment.

U.S.S. John McCain Prepares To Intercept North Korean Ship

Via FoxNews.com -

The U.S. military is planning to intercept a flagged North Korean ship suspected of proliferating weapons material in violation of a U.N. Security Council resolution passed last Friday, FOX News has learned.

The USS John McCain, a navy destroyer, will intercept the ship Kang Nam as soon as it leaves the vicinity off the coast of China, according to a senior U.S. defense official. The order to inderdict has not been given yet, but the ship is getting into position.

The ship left a port in North Korea Wednesday and appears to be heading toward Singapore, according to a senior U.S. military source. The vessel, which the military has been tracking since its departure, could be carrying weaponry, missile parts or nuclear materials, a violation of U.N. Resolution 1874, which put sanctions in place against Pyongyang.

The USS McCain was involved in an incident with a Chinese sub last Friday - near Subic Bay off the Philippines.

The Chinese sub was shadowing the destroyer when it hit the underwater sonar array that the USS McCain was towing behind it.

That same navy destroyer that was being shadowed by the Chinese is now positioning itself for a possible interdiction of the North Korean vessel.

This is the first suspected "proliferator" that the U.S. and its allies have tracked from North Korea since the United Nations authorized the world's navies to enforce compliance with a variety of U.N. sanctions aimed at punishing North Korea for its recent nuclear test.

The ship is currently along the coast of China and being monitored around-the-clock by air.

The apparent violation raises the question of how the United States and its allies will respond, particularly since the U.N. resolution does not have a lot of teeth to it.

The resolution would not allow the United States to board the ship forcibly. Rather, U.S. military would have to request permission to board -- a request North Korea is unlikely to grant.

North Korea has said that any attempt to board its ships would be viewed as an act of war and promised "100- or 1,000-fold" retaliation if provoked.

The U.S. military may also request that the host country not provide fuel to the ship when it enters its port. North Korean merchant ships usually need fuel as they approach Singapore and the ports of eastern India. When tipped off, Indian port authorities are stringent enforcers of UN sanctions against ships carrying contraband.

The U.S. Navy does not need to enforce the sanctions. Instead, it could "poison the host," a move that entails working behind the scenes with Indian Ocean port authorities to inspect and confiscate illegal cargos.

This move worked last year when U.S. officials reportedly warned Indian officials in advance of a North Korean transport aircraft that had requested permission to fly through Indian airspace on the way to Iran after stopping in Burma to refuel. The Indians refused to allow the aircraft to fly through their airspace. The aircraft reportedly was carrying gyroscopes for ballistic missiles.

The Kang Nam is known to be a ship that has been involved in proliferation activities in the past -- it is "a repeat offender," according to one military source. The ship was detained in October 2006 by authorities in Hong Kong after the North Koreans tested their first nuclear device and the U.N. imposed a subsequent round of sanctions.

Thursday, June 18, 2009

NY Poly Institute: Penetration Testing & Vulnerability Analysis Course

Dan Guido (@dguido) posted all the materials from his Penetration Testing and Vulnerability Analysis currently taught at the Polytechnic Institute of New York University.

----------------------

http://pentest.cryptocity.net/

This is the course website for Penetration Testing and Vulnerability Analysis currently taught at the Polytechnic Institute of New York University. The course aims to introduce techniques and skills for identifying, analyzing, and exploiting software vulnerabilities. This course is offered as part of:

$134 Billion In Seized US Bonds Are Fakes

Via National Terror Alert -

U.S. government bonds found in the false bottom of a suitcase carried by two Japanese travelers attempting to cross into Switzerland are fake, a Treasury spokesman said.

“They’re clearly fakes,” Stephen Meyerhardt, a spokesman for the U.S. Bureau of the Public Debt in Washington, said yesterday. “That’s beyond the fact that the face value is far beyond what’s out there.”

Italy’s financial police last week said they asked the U.S. Securities and Exchange Commission to authenticate the seized bonds, with a face value of $134 billion. Colonel Rodolfo Mecarelli of the Guardia di Finanza in Como, Italy, said the securities, seized in Chiasso, Italy, were probably forgeries.

Meyerhardt said Treasury records show an estimated $105.4 million in bearer bonds have yet to be surrendered. Most matured more than five years ago, he said. The Treasury stopped issuing bearer bonds in 1982, Meyerhardt said.

Had the notes been genuine, the pair would have been the U.S. government’s fourth-biggest creditor, ahead of the U.K. with $128 billion of U.S. debt and just behind Russia, which is owed $138 billion.

Source

$134 Billion U.S. Bond Mystery Continues In Italy

2 Japanese Carrying $134 Billion In U.S. Bonds Detained In Italy

Danger Room What’s Next in National Security CSI Somalia: Interpol Targets Pirates

Via Wired.com -

The war on Somali pirates has moved to the bargaining table,to the crime labs, and to Somalia’s white beaches. With the beginning of East Africa’s stormy monsoon season, hijackings at sea are down, giving the coalition of pirate-fighting nations a chance to counter-attack. Their weapons: fingerprints, grassroots anti-piracy leagues… and 500 Somali men, in shorts and t-shirts.

The U.S. Navy, NATO and the other military forces patrolling East African waters, say it’s not hard to fight pirates, once you identify them. But Somali sea bandits blend in with innocent fishermen and toss their weapons over-board when they’re caught, so that nobody can prove they were up to no good. Piracy is a “complex legal issue linked to national law, international law and the law of the high seas,” NATO General Karl-Heinz Lather said, in May. Without good evidence, NATO has been releasing captured pirate suspects on the nearest Somali beach.

Interpol, the international police force, is hoping to change that, by collecting fingerprints of pirate suspects. “Without systematically collecting photographs, fingerprints and DNA profiles of arrested pirates and comparing them internationally, it is simply not possible to establish their true identity or to make connections that would otherwise be missed,” Interpol executive director Jean-Michel Louboutin said yesterday.

Meanwhile, on land in Somalia, the U.S.- and U.N.-backed “transitional government” has recruited 500 men to fill the ranks of an anti-piracy force. The men began training last week, in their “simple uniforms of shorts and white T-shirts.” The force is riding a rising wave of popular opposition to pirates, whose crimes have disrupted international efforts to stabilize Somalia. Some reports have pirate bosses pleading for leniency from incensed imams and elders.

U.S. Navy Tracking Possible North Korean Nuke Shipment

Via NavyTimes.com (h/t National Terror Alert) -

The Navy is tracking a North Korean cargo ship suspected of carrying illegal weapons, equipment or nuclear fissile material that North Korea has been prohibited from transporting by the U.N. Security Council, top U.S. defense officials said Thursday.

Adm. Mike Mullen, chairman of the Joint Chiefs of Staff, told reporters at the Pentagon that “clearly, we intend to vigorously enforce the U.N. Security Council Resolution 1874,” although the Navy cannot use force to stop or board the vessel suspected of carrying the contraband.

A U.S. warship could hail the North Korean ship and ask to search it, and if the ship’s crew didn’t comply, the U.S. sailors could order the vessel to sail to the nearest port and request officials in that port to do the search — although the U.S. ship couldn’t use force for that, either.

“The resolution does not include an option for an opposed boarding or a noncompliant boarding,” Mullen said. “If we get to that point with a vessel we suspect has material which is unauthorized — that’s a report that goes back to the U.N.”

Mullen, who briefed reporters with Defense Secretary Robert Gates, gave few details about how the Navy was tracking the North Korean ship — whether U.S. warships or aircraft were shadowing it — and what led U.S. officials to believe it was carrying contraband material.

The U.N. Security Council voted to place additional strictures on North Korea after the country detonated a nuclear bomb May 25 and launched ballistic missiles into the ocean off Southeast Asia. One of the restrictions was that North Korean ships suspected of carrying nuclear material would be interdicted at sea, but the North has said it would consider the boarding of any of its ships as an act of war.