Category: hacking

  • Is China trying to hack the US DoD?

    Many penetrations at the Department of Defense traced to China.
    Analysts have code named the attacks Titan Rain and are divided as to
    whether or not they are a coordinated effort by the Chinese government.
    I think the more interesting question is why would the DoD release this
    information to the press?
     
    “Hi China we know what your doing?”

    I don't think this should come as a surprise to anyone.  Nations
    have been spying on each other (friendly or enemy) from the begining of
    nations.  I think that these kind of cyber attacks will get much
    more complex and clandestine in the near future.

    A few month ago the U.S. military annouced the assembling of  the world's most formidable, multimillion-dollar weapons grade hacker unit program in order to launch bloodless cyberwar against enemy networks — from
    electric grids to telephone nets.

    Talk about cyberpunk and sci-fi come to life!  This all sounds
    like Tom Clancy's NetForce.  Not my favorite Tom Clancy book but
    great concept.

    read more | digg story

  • 6 Dumbest Ideas in Computer Security – Revisited

    Markus Ranum’s popular “6 Dumbest Ideas in Computer Security” is apparently accepted by many. I agree with a couple of his points, but have serious issues on the others.

    Here is what Mark had to say in a nutshell:

    1) Default Permit –

    Allow everything except bad processes and/or users.

    I Agree.

    There is a lot of this going around and it is dumb. And I say its dumb in total humility, we all do dumb things from time to time. With Windows XP service pack 2, which is basically a firewall implemented on top of the OS and though it is not perfect, I believe that more people are beginning to see the importance of DENY ALL.

    2) Enumerating Badness

    Listing a concentrating on the thousands of malware as opposed to concentrating on accounting for the legitimate software and getting rid of the rest. It’s a ploy by the man to keep security corporations afloat.

    I Agree and Disagree with this.

    I agree that it is important to have accountability for what is going great on your system and running as it should. You should know and maintain your “known good” baseline configuration. But it is like protecting your home. Shouldn’t you know what recent rash of crimes are going on in your neighborhood?

    Shouldn’t you keep note of those crimes and have a method or practice of protecting yourself. Although it is impractical to seek out every possible type of attack a criminal will use against your home, you should at least have protection against the MOST LIKELY methods that might be used against your home. I believe that being aware of some of the most possible known threats to your system and taking action is like personal insurance.

    3) Penetrate and Patch –

    Systems should be designed better so they don’t have to be patched.

    WTF (What the f*#@!!)

    Of course systems should be designed better… and humans should be designed so that we don’t go to war! And there shouldn’t be hunger anywhere on planet earth. Could have, Should have, would have. In a perfect world, I.E. WOULD HAVE been ABORTED. But Internet Explorer was released to all and controlled 95% of the browser for years. Mark, there are systems that need patches. Security isn’t just proactive its reactive. I understand and agree with what you are saying but in the real world millions of people by millions of badly designed and even hazardous products.

    4) Hacking is Cool

    Mark insists that saying “hacking is cool” or having popular series of “hack” books (i.e. Google Hacks, Mind Hacks) is glorifying criminals.

    I Strongly Disagree.

    This is yet another example of someone ignorant of what hacking actually is.

    I’ve had numerous arguments about this. I don’t care what you say Mark (or anyone else) hacking is and always will be cool. NO!… I don’t believe CRIME is not cool. Hackers are not always criminals. You would have to go to the Defcon to realize this. But Mark seems like the type that would look down his nose at Defcon and everyone there. Many of the vulnerabilities that are discovered before criminals exploit them are discovered by gray hats, hackers who actively or accidentally discover security holes. Many times these gray hats actually warn the companies and are told to sit down and shut.

    Even if you did believe that every hacker is a criminal and ALL hacking is a crime, would it not make sense to know your enemy and what he/she does? Criminal Profilers must not only know the tactics of criminals they have to UNDERSTAND them. I was a cop for five years. In my experience, the best cops & investigators understood not only how and why people commit crimes but also how they try and get out of it.

    Mark calls hacking “social problem.”

    Even TLC (the learning channels) does not take this stance on hacking. Check out their list of the famous & Infamous hackers.

    Hackers included on the TLC page:

    Steve Wozniak (co-founder of Apple)

    Richard Stallman (creator of GNU)

    Dennis Ritchie/Ken Thompson (created UNIX)

    TSutomu Shimomura (caught Kevin Mitnick)

    Linus Torvalds (creator of Linux)

     

    This is a good definition of what a hacker is:

    http://en.wikipedia.org/wiki/Hacker#History

    Most Information Security professionals (or those claiming to be) either completely understand what “hacking” is or do not understand it at all.

    5) Educating Users

    Users should be kept dumb.

    I disagree.

    Social Engineering is the best example of what happens when your users are blind. The biggest threat to any system is the people using them. Kevin Mitnick said, “There is no patch for stupidity.” Really funny, but I disagree the patch is Security Awareness. Check out what the folks at Security Awareness for MA PA and the Corporate clueless blog had to say. 

              6) Action is Better Than Inaction

    It really is easier to not do something dumb than it is to do something smart.

    I agree. Very well put.

     

    I would also add a seventh, brought up by Par Kris Buytaert at x-tend.be:

    7) Security Can be sold in a Box

             Everyone wants a push button solution to all their security issues.  The truth is that it does not exist.  The only way to beat the game is stay ahead of it.  That is not to say everyone should be security geeks, but they should have some understanding of spyware, malware and other filth (that is if they value there accounts, privacy and data).

     

    Over all, I feel that article has a lot to give to computer security community.  Its great that there are professionals that put that much thought on what they feel  is right.

     

     

  • First potential virus risk for Windows Vista found

    “Virus writers are targeting a new Microsoft tool that will be part
    of Windows and is set to ship as part of the next Exchange e-mail
    server release.” – C|Net

    F-Secure has already found a possible flaw in the Windows Vista
    (code named Longhorn) command Shell called Monad also know as MSH.

    Representatives of F-Secure stated that if Microsoft released Windows
    Vista with MSH enabled, it could cause and outbreak of scripting
    viruses.  Examples of Scripting viruses include Macrovirues, the
    ILOVEYou VB scripting virus and the Melissa virus.

    The exploit aiming at MSH is discussed here.

    Microsoft my chose to disable MSH by default or simply add it as a plugin. 

  • Home made Homemonkey: HoneySpider

    In my quest to find more viruses, trojans, and worms (which I find fastinating)  I started building my own HoneyMonkey server which I call a “HoneySpider.”

    What the hell is a HoneyMonkey?

    You've heard of HoneyPots, right?  A server that is set up to trick and track potential malicious hackers who think they have found the goods but have in fact been seduced by a decoy.  Brilliant defense however it is very passive as you must wait for the bastard hackers to come to your decoy system.  The HoneyMonkey is active in that it actively locates sites, pages and weblinks that seek to exploit systems.  The Microsoft's Strider HoneyMonkey Exploit Detection system is great evolutionary step for a proactive method of Internet security (something I've been waiting for a while).  It actually crawls the web to locate these evil boxes and maps out there location on the Web.

    I thought the concept seems pretty self explanatory:  set up a server that crawls the web specifically looking for offending sites.  This can be down with and old box you happen to have laying around and a web crawler like Zeus.

     

    I'm still working on it.  I'll keep you posted.

     

  • CISCO LEAP (lightweight Extensible Authentication Protocol) Weak?

    Light weight EAP is Cisco's proprietary version of Extensible Authentication Protocol (EAP, used mainly for wireless LANs).  Cisco graciously allowed vendors to support LEAP using Cisco Certified Extenstion (CCX). 

    Cisco owns about 60% of the wireless market with 46% of those using Light Weight Extensible Authentication Protocol according to the research group nemertes. 

    HAZZAAA!! Cisco is secure…

    (except against Dictionary Attacks)

    With such a large piece of the wireless market using LEAP, Cisco had sucessfully advertised LEAP as a secure protocol.  Unfortunately, LEAP is weak against Dictionary Attacks (Brewin).

    At DEFCON 11, on August 1, 2003, Joshua Wright did a presentation on the weakness of LEAP

     

    Here is Cisco's response to Leap Dictionary attacks:

    To help our customers respond to the possibility of dictionary attacks, Cisco strongly recommends that all of our customers to review their security policies and institute the previously published best practices that are outlined below and in the Cisco SAFE White Papers.

    Use a strong password policy (as detailed below) and periodically expire user passwords (recommended at least every three months) giving users advanced warning to change passwords before they expire.

    If unable to implement a strong password policy, consider migrating to another EAP type like EAP-FAST, PEAP or EAP-TLS whose authentication methods are not susceptible to dictionary attacks:

    EAP-FAST is an authentication protocol that creates a secure tunnel without using certificates.

    PEAP is a hybrid authentication protocol that creates a secured TLS tunnel between the WLAN user and the RADIUS server to authenticate the user to the network.

    EAP-TLS uses pre-issued digital certificates to authenticate a user to the network.

     

    FINAL NOTE:

    “1 month of audits by l33t security companies: No vulnerabilities
    1 month of architecture research by CCIE's: No vulnerabilities
    2 days of hacking by DaBubble, Bishop, and Evol: Root.
    There's some things that fackers should audit (WEBAPPS) for everything else, get a real hacker.” — SecurityFocus

    Why doesn't Cisco become more hacker friendly.  They pissed off the Security Profesionals and Hackers alike with that CiscoGate fiasco, don't have any cool hacker parties at the Defcon.. I mean what is the deal, John Chambers?! 

    John, I doubt you will ever read this blog, but here goes anyway, I think that Cisco has great products.  I believe in Cisco's amazing engineering, but if you guys don't aggressively attack security issues PROACTIVELY, you will drop from first class to third class quickly.  I'm not trying to tell you how to run cisco, I'm just saying, why not use hackers and their finding to your advantage. 

    Take the IE browser as an example: they used to own 95% of the market, consumners got so fed up with its lack of security that now Firefox (co-created by Blake Ross Intern/Hacker) is doing something not even Netscape could do.  

     

    Reference:

    EAP. RFC 2284. Extensible Authentication Protocol.

    EAP, Extensible Authentication Protocol Wiki. Wikipedia.org

    George C. Ou. Leap: A looming disaster in Enterprise Wireless LANs.  Lanarchitecture.net

    nemertes, Cisco Warns its WLAN Security can be Cracked. nemertes.com

    Brewin, Bob. Cisco Warn its WLAN Security can be Cracked. computerworld.com

    Cisco, Abusing 802.11: Weaknesses in LEAP Challenge/Response. Defcon 11/2003

    Cisco. Cisco Response to Dictionary Attacks on Cisco Leap.

  • Hackers vs terrorists: online anti-jihad

    MI5 and patriotic hackers have formed an unlikely alliance to close down their sites.

    Its about time.  The best Defense is a good offense.  I agree with Bruce Schreier.  Their are too many soft targets to protect.  We need to find the source and deal with these murderers.  That is where the money should be spent.  Don't want to get too political on this blog but its something I feel strongly about.

    read more 

  • Computers Hacking People ver 1.0

    I honestly think you ought to calm down; take a stress pill and think things over. – Hal, 2001 Space Odyssey
     
    Information Systems will eventually have the infrastructure and ability to “socially engineer” its creators.  This is far fetched science fiction blooming before our very eyes being created by our own hands.
    It will happen when three criteria are in place: 1) The creation of laws that can completely disregard the privacy and sovereignty of human beings.  2) The advancement of Information Awareness System and 3) Smart Artificial Intelligence
     
     
    LAWS
    Lets discuss the situations that will give governments the pretext to implement laws to track their citizens.  This is happening now.  Laws and systems are being created for unchecked monitoring of individuals under the guise of security, safety and prosperity.  Systems such as national ID cards. 
    They were implemented after the Sept 11 attacks on the World Trade Center and in the U.K. after the 7 July attacks in London. 

    It was 19th Century philosopher Samuel T. Coleridge who said, “In politics, what begins in fear usually ends in folly.” 

    Imagine it: The PATRIOT ACT IV is passed as a result of recent Critical Infrastructure cyber-terrorism attacks.  International terrorists implement a globally synchronized Distributed Denial of Service Attack against the worlds Root nameservers and successfully cripple the Internet for three days.  The impact is devastating as corporations lose billions. 

    Domestic Cyber Terrorists infiltrate hospitals by becoming apart of the staff only to socially engineer and infecting HIPPA protected networks with virus’ that wipe out databases and actually scramble prescriptions causing an array of death by misdiagnosis.

    Local police and security personnel repeatedly thwart numerous attempts by religious fundamentalists to detonate suit case sized tactical nuclear weapons inside major United State cities but security professionals predict that it is only a matter of time before at least one slips through the cracks.  All the enemy needs is one.
    Patriot Act IV is the patron saint of lawmakers who have been screamed at by constituents to “DO SOMETHING NOW!”  The new Patriot Act is eventually internationally accepted and allows for unrestricted Data Mine into commercial and state owned databases worldwide (US-EU).  It of course has deferent names and variations world wide but its application is the same.  In the United Kingdom it is called the Civil Contingencies Bill.  The data mining would tap into the “transaction space” by accessing hospital, financial transaction and legal databases world wide to be shared by all law enforcement agencies (county, federal, city local and international).  The system works like a global Amber Alert system that can track criminals anywhere in the world and notify the respective local agency immediately.  The system works very, very well.
     
     
    Information Awareness Systems

    The system, developed under the direction of John Poindexter, then-director of DARPA’s
    Information Awareness Office, was envisioned to give law enforcement access to private data without suspicion of wrongdoing or a warrant. — Electronic Privacy Information Center.
     
    Government funded unrestricted Data Mining and Information Awareness programs develop and run revolutionary Information Awareness Systems.  Despite public opinion, these National Security systems continue to work to protect the nation against enemies foreign and domestic.  The system extracts data from its transactional databases and recognizes patterns of behavior that would fit that of a terrorist.  The system is so exhaustive that is works with 70% accuracy and seamlessly in conjunction with systems such as Next Generation Facial Recognition systems and Activity, Recognition Monitoring for enhanced surveillance. 
     
               
    Artificial Intelligence
    Within thirty years, we will have the technological means to create superhuman intelligence. Shortly after, the human era will be ended. – Vernon Vinge, 1993, What is the Singularity?
     
    Artificial Intelligence has been in use for many years.  It is greatly relied upon for businesses, hospitals, military units and even in forms of entertainment such as video games.  However Strong Artificial Intelligence, the development of cognitive systems simulating the human brain, have been developing quietly in research labs around the world under programs dedicated to the “scientific understanding of the mechanisms underlying thought and intelligent behavior and their embodiment in machines. (AAAI)” 
     
    Smart Information Awareness is Strong Artificial Intelligence merged with Information Awareness Systems.  Smart Information Awareness seems to go beyond merely recognizing patterns of behavior as it predicts the future actions of a given psychological profile with over 75% accuracy allowing Law Enforcement to be like an all seeing eye with incredible new methods of forensics and counterterrorism.  Crime as a whole will be greatly reduced.  System that recognize criminal patterns have been around for some time, Smart Information Awareness systems are a new trend.
     
     
    The Smart Information Awareness system is so accurate in determining human behavior trends that it is used to track and manipulate consumer buying habits for corporations.  With its accuracy, the system will be able to determine what marketing tools can be used to influence the behavior of buyers. 
     
    With unfettered access to consumer’s personal transactions, buying habits, methods of payment, and credit history a system would be able to pin point buyers who demonstrate interests in certain products and offer “special deals” a specific group of highly interested buyers.
     
      
    Inevitably the very system (laws, practices and technologies) that successfully protects humanity from itself is used to manipulate and exploit humanity.
     
    Perhaps you believe that there is nothing wring with this level of target marketing.  If so, I submit to you these questions:  What will separate humanity from cattle if every man, woman and child is seen as nothing but a number and a consumer to the system that we rely on to survive?  Since we are already regarded as merely numbers and consumers by the corporate beast, how much control and information will we allow them to have?
     
     
    Perhaps this is a bit much.  Perhaps I exaggerate the technology and extent of fear that will breed it.
     
     
     
     
     
    http://www.p2pnet.net/issue03/page1.html
     
    http://www.epic.org/
     
    http://www.jbholston.com/weblog_discussion.php?post_id=74
    Statewatch.com – Secret EU-US agreement being negotiated. http://www.statewatch.org/news/2002/jul/11Auseu.htm
    http://www.eff.org/Privacy/TIA/20030523_tia_report_review.php
     
    http://www.aaai.org/

  • Use Google To Find Passwords

    Google hackers have been doing this for a while now. Here is a tutorial on finding passwords using google. This could be used to secure your own web server.

    Security Professionals charged with protecting IT infrastrutures would do well to become the most aggressive hacker of their own networks. This would help them to proactively seek out new exploits on their network, webserver, or IS they protect.

    read more | digg story

  • Google Hacking Explained

    What is Google hacking? How is Google used by hackers as a tool? Read this article for more information.

    Johny Long, author of the official Google Hacking book will be at the Las Vegas, NV Defcon 13 Convention signing books. 

    read more | digg story

  • Whax How to (formerly known as whoppix)

    The WHAX Live CD OS (formerly known as WHOPPIX) has a useful knowledgebase of growing information on how to use its very modular features.

    I notice a few people coming to my blog to find tutorials on WHAX/Whoppix, but where you really want to go is here:

    http://iwhax.net/modules/xoopsfaq/

    If there is something you want to know just ask the WHAX gurus on their interactive site.  The Whoppix webpage looked nice but the creators of this incredible tool made a briliant move in this new interactive, blog howto structure.

    If you Whax guys read this, I suggest getting some trackbacks.

    read more | digg story