Friday, September 10, 2010

Hezbollah in the Tri-Border Area of South America

Via Small Wars Journal -

Hezbollah, Lebanon’s Iran-sponsored Shi’i Muslim terrorist organization, has established global networks in at least 40 countries. Its growing presence in South America is increasingly troublesome to U.S. policymakers, yet there are few experts on Hezbollah and fewer still on Hezbollah Latino America. Hezbollah’s operatives have infiltrated the Western Hemisphere from Canada to Argentina, and its activity is increasing, particularly in the lawless Tri-Border Area (TBA) of Brazil, Argentina, and Paraguay. This research was conducted to expose the actions and objectives of Hezbollah in the TBA.

[...]

Hezbollah has a large operational network in the TBA, which generates funds for the party, but its primary mission is to plan attacks and lie dormant, awaiting instructions to execute operations against Western targets. The following is a look at Hezbollah’s modus operandi, an analysis of how operational its networks in the Tri-Border Area are, as well as some possible solutions to this threat. First, is an examination of how Hezbollah traditionally operates to establish the context.


----------------------------------------------------------------------

Full Article (PDF)
http://smallwarsjournal.com/blog/journal/docs-temp/533-miryekta.pdf

Use EMET 2.0 to Block Adobe Reader and Acrobat 0-Day Exploit

http://www.adobe.com/support/security/advisories/apsa10-02.html

Mitigations

Current exploits in the wild target the Windows platform. Customers using Adobe Reader or Acrobat 9.3.4 or earlier on Windows can utilize Microsoft's Enhanced Mitigation Evaluation Toolkit (EMET) to help prevent this vulnerability from being exploited. For more information on EMET and implementing this mitigation, please refer to the Microsoft Security Research and Defense blog. Note that due to the time-sensitive nature of this issue, testing of the functional compatibility of this mitigation has been limited. Therefore, we recommend that you also test the mitigation in your environment to minimize any impact on your workflows.

---------------------------------------------------------------------------

http://blogs.technet.com/b/srd/archive/2010/09/10/use-emet-2-0-to-block-the-adobe-0-day-exploit.aspx

As you probably know there is a new exploit in the wild for Adobe Reader and Acrobat. This particular exploit is using the Return Oriented Programming (ROP) exploit technique in order to bypass Data Execution Prevention (DEP).

[...]

The good news is that if you have the Enhanced Mitigation Experience Toolkit 2.0 (EMET) enabled for AcroRd32.exe, it blocks this exploit. This is happens thanks to two different mitigations:

Mandatory ASLR: On Windows 7, Windows Vista, Windows Server 2008 R2, and Windows Server 2008 this mitigation will force the relocation of non ASLR-aware DLLs. The exploit will then fail to use ROP successfully since it is expecting the DLL to be at a predictable location. Take a look at the below screenshot from Process Explorer to see what this looks like.

Export Address Table Access Filtering (EAF)
: The exploit is also blocked by the EAF mitigation. This is important for Windows XP and Windows Server 2003 because they do not support mandatory ASLR. With this mitigation in place EMET will detect the shellcode accessing the EAT of Kernel32.dll trying to resolve some APIs (e.g. LoadLibraryA). EMET will then raise a STATUS_STACK_BUFFER_OVERRUN unhandled exception and the program will be terminated before the shellcode does anything bad.

[...]

We have been working closely with the Adobe Secure Software Engineering Team (ASSET) on recommending EMET as a mitigation option. Due to the time-sensitive nature of this issue, we have only been able to perform a cursory look at the functional compatibility of this mitigation. Keep in mind, Adobe Reader and Acrobat support broad feature sets, which require extensive testing to fully cover all functionality. Therefore, we recommend that you also test the mitigation in your environment to minimize any impact on your workflows.

Thursday, September 9, 2010

Report: Al Qaeda Disarms Select Taliban Commanders

Via The Long War Journal -

Central Asia Online reports:
Al-Qaeda is blocking Taliban fighters who favour peace talks from negotiating with Kabul.

The terror movement has disarmed two Taliban commanders, Mullah Laal Muhammad and Mullah Alaoddin of the Haqqani network, who were interested in starting peace talks with the Afghan government, Kunduz Provincial Governor Engineer Muhammad Omar said.

“Al-Qaeda has disarmed two prominent commanders of the Haqqani Network in Kunduz in the past two weeks, and nine others in fear of being disarmed have buried their weapons and fled to Pakistan,” Omar told Central Asia Online.
Four observations:

(1) We've been hearing similar reports, so this strikes us as entirely plausible.

(2) Notice that al Qaeda is operating in Kunduz and is strong enough there to disarm select Taliban/Haqqani commanders who are waffling in their commitment to the fight. Kunduz, obviously, is in the far north of Afghanistan -- far away from the tribal belt straddling Afghanistan and Pakistan where al Qaeda and its jihadist brethren are headquartered. This says much about the reach of al Qaeda inside Afghanistan. There have been a number of attempts to downplay the significance of al Qaeda's role in Afghanistan, but its ability to operate so far away from the mothership demonstrates once again that its roots are deep and far-reaching.

(3) Independently, we know that al Qaeda is operating in Kunduz. ISAF is currently hunting Islamic Movement of Uzbekistan (IMU) commanders there. The IMU is one of the core al Qaeda groups. Kunduz Provincial Governor Engineer Muhammad Omar is quoted in the piece as saying that the Uzbeks don't want peace. He is most likely referring to IMU members.

(4) Perhaps the most important observation in the Central Asia Online account is this:
Kunduz representative to the Afghan parliament Moyeen Merastyal confirmed the governor’s statement.

"The groups that are supporting the Taliban from outside don’t want peace talks in Afghanistan as they consider stability detrimental to their interests," Merastyal said. "They want terrorism in the region, not only in Afghanistan, so anyone who looks interested in peace talks is being disarmed or captured," he said, referring to the arrest of some Taliban figures in Pakistan.
In all the talk of the possibility of peace between some elements of the Taliban and the Afghan government, Merastyal's point remains the most important one. The Taliban and other jihadist proxies of the Pakistani ISI are not going to make peace unless the ISI wants them to. It is just that simple. Here we have a good illustration of some Taliban commanders wanting to reconcile and their efforts being blocked by outside forces.

And isn't it interesting that in this case al Qaeda is performing the same function that the ISI does? That is, al Qaeda is neutering commanders in northern Afghanistan who are not as committed to war as they should be, just as the ISI does in Pakistan.


------------------------------------------------------------------------------

This previous post is related and gives some background on the ISI references...
http://djtechnocrat.blogspot.com/2010/08/pakistanis-tell-of-motive-in-taliban.html

Microsoft Security Bulletin Advance Notification for September 2010

http://www.microsoft.com/technet/security/bulletin/ms10-sep.mspx

This is an advance notification of security bulletins that Microsoft is intending to release on September 14, 2010.

-----------------------------------------
 
Looks like nine bulletins (four "Critical" & five "Important") affecting Windows and Office.

Criminals Are Getting Smarter: Analysis of Adobe Acrobat / Reader 0-Day Exploit

http://www.vupen.com/blog/

We would like to share our technical analysis of the recent Adobe Acrobat/Reader 0-Day exploit in the wild (CVE-2010-2883).

Here at VUPEN, we analyse a lot of of critical vulnerabilities and 0days and we design quite sophisticated exploits targeting various applications and operating systems. During the last few months, we have created a large number of Adobe Reader exploits and almost a dozen which bypassed DEP.

So why is this particular 0day exploit so interesting? Because it bypasses DEP and ASLR using a method that we have not seen often in the wild.


--------------------------------------

Looking forward to that Adobe Reader sandbox ;)

Gauging the Threat of an Electromagnetic Pulse (EMP) Attack

Via STRATFOR (Security Weekly) -

Over the past decade there has been an ongoing debate over the threat posed by electromagnetic pulse (EMP) to modern civilization. This debate has been the most heated perhaps in the United States, where the commission appointed by Congress to assess the threat to the United States warned of the dangers posed by EMP in reports released in 2004 and 2008. The commission also called for a national commitment to address the EMP threat by hardening the national infrastructure.

There is little doubt that efforts by the United States to harden infrastructure against EMP — and its ability to manage critical infrastructure manually in the event of an EMP attack — have been eroded in recent decades as the Cold War ended and the threat of nuclear conflict with Russia lessened. This is also true of the U.S. military, which has spent little time contemplating such scenarios in the years since the fall of the Soviet Union. The cost of remedying the situation, especially retrofitting older systems rather than simply regulating that new systems be better hardened, is immense. And as with any issue involving massive amounts of money, the debate over guarding against EMP has become quite politicized in recent years.

We have long avoided writing on this topic for precisely that reason. However, as the debate over the EMP threat has continued, a great deal of discussion about the threat has appeared in the media. Many STRATFOR readers have asked for our take on the threat, and we thought it might be helpful to dispassionately discuss the tactical elements involved in such an attack and the various actors that could conduct one. The following is our assessment of the likelihood of an EMP attack against the United States.

Adobe Reader Zero-Day Attack – Now with Stolen Certificate

Via SecureList.com (Kaspersky) -

Today Adobe put out an advisory for a previously unknown zero-day in its PDF Reader/Acrobat software. This vulnerability is actively being exploited in the wild.

The exploit is pretty basic. What’s interesting about it is that it makes use of Return Oriented Programming to bypass the ASLR and DEP mitigation technologies in Windows Vista and 7.

More widespread usage of ROP for exploits is something I’ve been expecting for a while. Why? Because Windows 7 is gaining more and more traction in both the consumer and corporate space.

While most malicious PDFs download their payload, this time the PDF has malicious content embedded. The PDF drops an executable into the %temp% directory and tries to execute it.

The file it drops is digitally signed with a valid signature from a US-based Credit Union!

Take a close look at the screenshots and you'll see that not only is the certificate valid, but it really does belong to Vantage Credit Union. This means that the cybercriminals must have got their hands on the private certificate. Remind you of anything? If you say Stuxnet (where compromised Realtek and JMicron certificates were used to sign files) then we're clearly thinking on the same lines.

It'll be interesting to see if Stuxnet has started a trend or if these cases are just a flukey coincidence. I suspect they're not - I think the use of valid, stolen certificates to sign malware will really take off in 2011.

Both Verisign and Vantage Credit Union have been notified so that they can take action.


------------------------------------------------------------------------------------------------

hlp.cpl is the file signed with the stolen Verisign certificate issued to secure2.ccuu.com.

Researchers from F-Secure have been making similar remarks for some time.
http://blogs.cisco.com/security/comments/trust_gap_certificate-signed_malware/

Overall, players in the malware industry are saying...

The use of stolen but valid digital certificates to sign malware is only going to get worse. Get ready now.

Wednesday, September 8, 2010

Research Firm NSS Will Launch ‘Exploit Hub,’ An App Store For Hackers

Via Forbes.com (Firewall Blog) -

NSS Labs is about to launch a new project that may seem unlikely for a security research firm: a marketplace for brokering the sale of hacking tools. I’ve just written a short article in the magazine on the Carlsbad, Calif.-based company’s plans for the October launch of a Web-based marketplace, dubbed Exploit Hub, for buying and selling exploits used in penetration tests, the audits aimed at sussing out vulnerabilities in corporate and government networks.

NSS president Rick Moy argues that the new marketplace will help close the gap between penetration testers and the malicious hackers whose intrusion techniques they’re trying to outwit. “A penetration tester is only as good as the exploits he has to work with,” he says.

Exploit Hub will allow any researcher to submit hacking code to the marketplace and name his or her price. NSS will test the quality of those exploits and take a 30% cut of sales. Only authorized buyers will be able to purchase and download exploit code, and only “non-zero-day exploits”–those that already have been patched by the software vendor–will be posted on the site.

[...]

By focusing on non-zero-days, NSS’s Moy hopes to create a useful tool for penetration testers but one that doesn’t invite misuse or controversy. Non-zero-day exploits will sell for far less, but Moy argues that even an exploit that sells for $50 could generate substantial income for a researcher if hundreds of companies buy the exploit for penetration testing purposes, an application where patched exploits are far more useful than unpatched ones. The goal, after all, is to test the security of a client’s systems by finding patchable bugs on their networks, not to gain access through a vulnerability that has no easy fix.

“There’s no cure for zero days,” Moy says. But luckily, he adds, “Zero days aren’t a controversy we need.”

MSF Exploit - Adobe CoolType SING Table "uniqueName" Stack Buffer Overflow

https://www.metasploit.com/redmine/projects/framework/repository/entry/modules/exploits/windows/fileformat/adobe_cooltype_sing.rb

This module exploits a vulnerability in the Smart INdependent Glyplets (SING) table handling within versions 8.2.4 and 9.3.4 of Adobe Reader. Prior version are assumed to be vulnerable as well.

----------------------------------------------------------------------------------------------

Return of the Unpublished Adobe Vulnerability
http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.html

----------------------------------------------------------------------------------------------

Security Advisory for Adobe Reader and Acrobat
http://www.adobe.com/support/security/advisories/apsa10-02.html

A critical vulnerability exists in Adobe Reader 9.3.4 and earlier versions for Windows, Macintosh and UNIX, and Adobe Acrobat 9.3.4 and earlier versions for Windows and Macintosh. This vulnerability (CVE-2010-2883) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild.

Adobe is in the process of evaluating the schedule for an update to resolve this vulnerability.

iPhone Hacker Discovers a New Jailbreaking BootROM Exploit

Via mobilecrunch.com -

The news is good for iPhone jailbreakers everywhere this morning — but for Apple? Not so much.
Just minutes after the iOS 4.1 update became available to all, iPhone hacker pod2g has revealed that they’ve discovered a new bootrom exploit, with all recently released iOS hardware seemingly being vulnerable. In less geeky words: the iPhone 4? the new iPod Touch? If it was built anytime before today, it’s theoretically jailbreakable — and there’s not a whole lot Apple can do to fix that.

[...]

The exploit in question here seems to focus around the boot rom, which, as you might have guessed from the preamble, is one of these non-rewritable components. Apple can patch up this exploit in any new hardware before it leaves the factory (they’ve shipped revised hardware as a result of similar exploits in the past), but once that boot rom is flashed and the phone is assembled, it’s a done deal.
From here, the iPhone Dev Team and the rest of the hacking community should be able to churn out jailbreaking software for just about any recently shipped iOS device. Once the exploit is made public, Apple will almost undoubtedly begin shipping hardware with revised boot roms eventually (last time, it took seven months) — but until then, expect a whole lot of jailbreaking to go down.

ZeroDay - Adobe Reader / Acrobat Font Parsing Buffer Overflow Vulnerability

http://secunia.com/advisories/41340/

A vulnerability has been discovered in Adobe Reader, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error within the font parsing in CoolType.dll and can be exploited to cause a stack-based buffer overflow by e.g. tricking a user into opening a specially crafted PDF file.

The vulnerability is confirmed in versions 8.2.4 and 9.3.4. Other versions may also be affected.

NOTE: The vulnerability is currently being actively exploited.


SOLUTION:
Do not open untrusted files.

PROVIDED AND/OR DISCOVERED BY:
Reported as a 0-day.

ORIGINAL ADVISORY:
http://contagiodump.blogspot.com/2010/09/cve-david-leadbetters-one-point-lesson.html

----------------------------------------------------------------------------------------------

As noted in the Contagio Blog, AV detection for the new PDF and the resulting dropped malware is very poor - about 2-3% (e.g. 1 or 2 out of 43 AVs).

Based on other information that I have seen, I would recommend users disable JavaScript inside Adobe Reader.

1. Launch Acrobat or Adobe Reader.
2. Select Edit>Preferences
3. Select the JavaScript Category
4. Uncheck the ‘Enable Acrobat JavaScript’ option

The author of the Contagio Blog states that Adobe Security had a copy of the new malicious PDF and is analyzing it.

Tuesday, September 7, 2010

More Exploitation of Quicktime 0-day In The Wild

More reports of the Apple Quicktime "_Marshaled_pUnk" vulnerability being exploited in the wild. The first sign of in the wild active exploitation was almost 5 days ago (Sept 2nd).

This alert was released today by Websense.

----------------------------------------------------------------

http://community.websense.com/blogs/securitylabs/archive/2010/09/07/quicktime-0-day-actively-used-in-the-wild.aspx

Following our recent posting of an Apple Quicktime 0-day [“_Marshaled_pUnk”] vulnerability, Websense Security Labs™ ThreatSeeker™ Network has discovered exploitation of this vulnerability in the wild.

----------------------------------------------------------------

Where is the Apple on this? Who knows. Official mitigation recommendations from Apple? There aren't any. Apple continuing to falsely 'save face' over actually protecting their software users? Looks like it.

However, other vendors are more helpful...

Both VUPEN and Secunia, recommend setting the killbit for the affected ActiveX control (02BF25D5-8C17-4B23-BC80-D3488ABDDC6B) or you could just rename the plugin (QTPlugin.OCX) until a patch is released.

Facebook Affects Students’ Grades

Via Times of India -

Students who are logged on to Facebook while studying get significantly lower grades than those who do not, according to psychologists.

A study has found that the exam results of those who used the social networking site while working, even if it was on in the background, were 20 per cent lower than non-users.

According to researchers, the findings put a dent in the theory that young people's brains are better at multitasking on digital gadgets.

"The problem is that most people have Facebook or other social networking sites, their emails and maybe instant messaging constantly running in the background while they are carrying out other tasks," the Daily Mail quoted study author Professor Paul Kirschner as saying.

"Our study, and other previous work, suggests that while people may think constant task-switching allows them to get more done in less time, the reality is it extends the amount of time needed to carry out tasks and leads to more mistakes," he added.

His team studied 219 students aged between 19 and 54 at an American university.

It was observed that the Facebook users had a typical grade point average - a score from zero up to four - of 3.06. Non-users had an average GPA of 3.82.

Those who did not use the site also said they devoted more time to studying, spending an average of 88 per cent longer working outside class.

Three fourth of the Facebook users said they didn't believe spending time on the site affected their academic performance.


--------------------------------------------------------------------------------

The sample size was small and a wide range (219 students between 21 and 54). But overall, the results aren't really shocking...people just aren't good multi-taskers.

The Myth of Multitasking
http://www.thenewatlantis.com/publications/the-myth-of-multitasking

How (and Why) to Stop Multitasking
http://blogs.hbr.org/bregman/2010/05/how-and-why-to-stop-multitaski.html

Monday, September 6, 2010

Cockroach Brains Could Be Rich Stores of New Antibiotics

Via physorg.com -

Experts from the School of Veterinary Medicine and Science have discovered powerful antibiotic properties in the brains of cockroaches and locusts which could lead to novel treatments for multi-drug resistant bacterial infections
. They found that the tissues of the brain and nervous system of the insects were able to kill more than 90 per cent of MRSA and pathogenic Escherichia coli, without harming human cells.

Simon Lee, a postgraduate researcher presented their work at the Society for General Microbiology’s autumn meeting which is being held at The University of Nottingham between the 6 and 9 September 2010. The research has identified up to nine different molecules in the insect tissues that were toxic to bacteria.

Simon Lee said: “We hope that these molecules could eventually be developed into treatments for E. coli and MRSA infections that are increasingly resistant to current drugs. These new antibiotics could potentially provide alternatives to currently available drugs that may be effective but have serious and unwanted side effects.”

USB Stick Containing Anti-Terror Training Found Outside UK Police Station

Via The Register UK -

A memory stick containing anti-terror training manuals and other sensitive material was reportedly found on a street outside a Manchester police station.

The Greater Manchester Police-branded stick, which also held personnel files, was found by an unnamed businessman outside a cop shop in Stalybridge, Greater Manchester, the Daily Star on Sunday reports.

The device was branded with the GMP POTU initials of the Greater Manchester Police Public Order Training Unit and contained 2,000 files including some produced by the National Police Improvement Agency about counter-terrorism tactics. Names and ranks of officers were also found on the reportedly unencrypted device after its finder plugged it into his PC.

Superintendent Bryan Lawton, of GMP's Specialist Operations Branch, told the Press Association: "We are aware of an article relating to the finding of a memory stick belonging to GMP by a member of the public.

"We are currently looking into who this device belongs to, what information is contained on it and the circumstances surrounding its loss."

[...]

Terry Greer-King, Check Point’s UK managing director, said: “This incident shows yet again why data on USB drives must always be encrypted. Guidelines to staff, and security policies don’t stop devices being lost or misplaced, and these simple accidents and human errors will turn into real problems if data isn’t protected.

“Companies should ensure all data copied to USB sticks and CDs is automatically encrypted, and the use of all non-authorised devices controlled."

Nasty Data-Stealing Bug Haunts Internet Explorer 8

Via Threatpost.com -

There's an unpatched vulnerability in Internet Explorer 8 that enables simple data-stealing attacks by Web-based attackers and could lead to an attacker hijacking a user's authenticated session on a third-party site. The flaw, which a researcher said may have been known since 2008, lies in the way that IE 8 handles CSS style sheets.

The vulnerability can be exploited through an attack scenario known as cross-domain theft, and researcher Chris Evans originally brought the problem to light in a blog post in December. At the time, all of the major browsers were vulnerable to the attack, but since then, Firefox, Chrome, Safari and Opera all have implemented a simple defense mechanism. Mozilla was the last to fix the issue, in July.

But Microsoft has not yet implemented a fix for the vulnerability, and Evans on Friday posted a message to the Full Disclosure mailing list pointing out this fact and linking to a benign demo site. Microsoft Security Response Center officials said they are aware of the issue and are investigating it.

[...]

Three researchers at Carnegie Mellon University have published a paper on this attack--to which Evans contributed--and lay out a client-side defense against it. The defense calls for browsers to enforce the content-type checking for style sheets that are loaded from other sites. The authors stipulate that strict enforcement of this policy can break a very small number of sites, so a less-strict version also is detailed in the paper.

The defense has been adopted in one for or another by Google Chrome, Mozilla Firefox, Apple Safari and Opera.

Evans said in his Full Disclosure message that he decided to post it as a way to encourage Microsoft to fix the problem. "I have been unsuccessful in persuading the vendor to issue a fix.," he wrote.

Last month, Evans said that the bug itself might have been known in the attacker community since 2008.

"That's a dangerously long time for such a bug to be live and known by hackers.," he wrote. "Browsers are complicated pieces of software and will always have bugs. Time-to-fix therefore matters for a browser. If security is a factor in your browser choice, I recommend you look at Opera or Chrome. These browsers fixed this bug the fastest."


------------------------------------------------------------------

Mozilla rated the issue "Moderate" (2 out of 4) for Firefox in Security Advisory 2010-46.

Danish computer security, Secunia, has rated the issue as "Less Critical" (2 out of 5). The vulnerability is confirmed in Internet Explorer 6, 7, and 8 on a fully patched Windows XP SP3. Other versions may also be affected - http://secunia.com/advisories/41271

New Self-Assembling Photovoltaic Technology Repairs Itself

Via ScienceDaily.com -

Plants are good at doing what scientists and engineers have been struggling to do for decades: converting sunlight into stored energy, and doing so reliably day after day, year after year. Now some MIT scientists have succeeded in mimicking a key aspect of that process.

One of the problems with harvesting sunlight is that the sun's rays can be highly destructive to many materials. Sunlight leads to a gradual degradation of many systems developed to harness it. But plants have adopted an interesting strategy to address this issue: They constantly break down their light-capturing molecules and reassemble them from scratch, so the basic structures that capture the sun's energy are, in effect, always brand new.

That process has now been imitated by Michael Strano, the Charles and Hilda Roddey Associate Professor of Chemical Engineering, and his team of graduate students and researchers. They have created a novel set of self-assembling molecules that can turn sunlight into electricity; the molecules can be repeatedly broken down and then reassembled quickly, just by adding or removing an additional solution. Their paper on the work was published on Sept. 5 in Nature Chemistry.

Mining Social Networks: Untangling the Social Web

Via economist.com -

Telecoms operators naturally prize mobile-phone subscribers who spend a lot, but some thriftier customers, it turns out, are actually more valuable. Known as “influencers”, these subscribers frequently persuade their friends, family and colleagues to follow them when they switch to a rival operator. The trick, then, is to identify such trendsetting subscribers and keep them on board with special discounts and promotions.

[...]

Companies can spot these influencers, and work out all sorts of other things about their customers, by crunching vast quantities of calling data with sophisticated “network analysis” software. Instead of looking at the call records of a single customer at a time, it looks at customers within the context of their social network. The ability to retain customers is particularly important in hyper-competitive markets, such as India. Bharti Airtel, India’s biggest mobile operator, which handles over 3 billion calls a day, has greatly reduced customer defections by deploying the software, says Amrita Gangotra, the firm’s director for information technology.

[...]

Of course, companies have long mined their data to improve sales and productivity. But broadening data mining to include analysis of social networks makes new things possible. Modelling social relationships is akin to creating an “index of power”, says Stephen Borgatti, a network-analysis expert at the University of Kentucky in Lexington. In some companies, e-mails are analysed automatically to help bosses manage their workers. Employees who are often asked for advice may be good candidates for promotion, for example.

Ellen Joyner of SAS, an analytics firm based in Cary, North Carolina, notes that more and more financial firms are using the software to uncover fraud.

[...]

Last year an American government body called the Recovery Accountability and Transparency Board (RATB) began using network-analysis software to look for fraud within the $780 billion financial-stimulus programme. In addition to the internet, RATB combs Treasury and law-enforcement databases to uncover “non-obvious relationships”, says Earl Devaney, its chairman. The software works very well, he says. It has triggered about 250 ongoing criminal investigations and 400 audits.

[...]

The Army Criminal Investigation Command already sniffs out procurement fraud by scanning text in e-mails. The software, developed by SRA, an American firm, can correlate numbers and phrases written in nine languages with financial databases. If a person discusses a particular Department of Defence payment with an individual not officially linked to the deal, SRA’s software may notice it.

The police department of Richmond, Virginia, has pioneered the use of network-analysis software to predict crimes.

[...]

Party plans turn out to be a particularly useful part of this picture. Richmond’s police have started monitoring Facebook, MySpace and Twitter messages to determine where the rowdiest festivities will be. On big party nights, the department now saves about $15,000 on overtime pay, because officers are deployed to areas that the software deems ripe for criminal activity. Crime has “dramatically” declined as a result, says Mr Hollifield.

[...]

Network analysis also has a useful role to play in counterterrorism. Terror groups are often decentralised, so mapping their social networks is akin to deciphering “a big spaghetti picture”, says Roy Lindelauf of the Royal Dutch Defence Academy, who develops software for intelligence agencies in the Netherlands. It turns out that the key terrorists in a group are often not the leaders, but rather seemingly low-level people, such as drivers and guides, who keep addresses and phone numbers memorised. Such people tend to stand out in network models because of their high level of connectedness. To find them, analysts map “structural signatures” such as short phone calls placed to the same number just before and after an attack, which may indicate that the beginning and end of an operation has been reported.


-------------------------------------------------------

The Telegraph UK has another related article on data mining and its affect on us all...

Makes me wonder, if we will see the development of companies that are designed to predict and tweak the predictive analysis results for an individual willing to pay the money. This would require a sort of personal data warehouse with constant feedback, leading to behavioral adjustments habits (e.g. spending habits, people in your social circle, etc) over time.

JIT Spraying and Mitigations

http://www.piotrbania.com/all/articles/pbania-jit-mitigations2010.pdf
(Mirror Link - http://kryptoslogic.com/download/JIT_Mitigations.pdf)

Abstract

With the discovery of new exploit techniques, novel protection mechanisms are needed as well. Mitigations like DEP (Data Execution Prevention) or ASLR (Address Space Layout Randomization) created a significantly more difficult environment for exploitation. Attackers, however, have recently researched new exploitation methods which are ca- pable of bypassing the operating system’s memory mitigations. One of the newest and most popu- lar exploitation techniques to bypass both of the aforementioned security protections is JIT memory spraying, introduced by Dion Blazakis.

In this article we will present a short overview of the JIT spraying technique and also novel mitigation methods against this innovative class of at- tacks. An anti-JIT spraying library was created as part of our shellcode execution prevention system.


---------------------------------------------------------------------

Hat-tip to HD Moore for the link.

Saturday, September 4, 2010

Viktor Bout Extradition to US Delayed

Via fortmilltimes.com (AP) -

A suspected Russian arms dealer's extradition to the United States will be delayed at least until Oct. 4 to allow a Thai court to review new charges filed as a precaution by Washington, a judge said Friday.

The announcement by the Bangkok Criminal Court is the latest blow to Washington, which had expected Viktor Bout's rapid extradition after a Thai appeals court gave its approval on Aug. 20.

Bout, 43, is reputed to be one of the world's most prolific arms dealers.

His high-profile arrest in a 2008 U.S.-led sting operation in Bangkok ended a decade-long chase for the Russian, who has never been prosecuted despite being the subject of U.N. sanctions, a Belgian money-laundering indictment and a travel ban.

After last month's ruling, the U.S. quickly flew a plane to Bangkok to pick up Bout. The move was publicized in Thailand as the latest evidence of heavy U.S. pressure in a case that has turned into a diplomatic tug-of-war between Washington and Moscow.

Experts say Bout, a former Soviet air force officer, has knowledge of Russia's military and intelligence operations and Moscow does not want him to go on trial in the United States.

Bout has been indicted in the U.S. on four terrorism-related charges and faces possible life in prison. The U.S. indictment alleges Bout agreed to sell weapons to U.S. agents posing as arms buyers for the Revolutionary Armed Forces of Colombia, or FARC, which Washington classifies as a terrorist organization. Bout denies the accusations.