Thursday, October 29, 2009

Ubuntu 9.10 Released: Why do I care?

If your cyber-jutsu is to become great, you must become aware of Linux. This is not to say that you must use Linux to be a great cyber-jutsu master. There have been and will be cyber-jutsu masters using all types of operating systems. But, using a Linux Operating System will undoubtedly improve your cyber-jutsu.

Some of the newer cyber-jutsu practitioners among you may wonder, "Whatever are Operating Systems?".

I will tell you. The words you read here will be a reflection of the truth, but true enough to start you on your path or keep you from falling off the edge. An Operating System (OS) is an interface to the hardware which makes up the physical portion of a computer system. The physical portion of the system includes, but is not limited to: the housing or case of the system, the fans that help maintain the temperature of the system, the random access memory (RAM) - or 'memory' of the system, the hard drive - or long term storage, the central processing unit (CPU), and every other printed circuit board, chip, microprocessor, graphics card, etc. It is what you would see if you took a sledge hammer to your computer. (Not recommended until the rank of black-belt)

The Operating System (OS) interfaces with the BIOS (Basic Input/Output System), which is itself a piece of hardware that facilitates communications with all the other hardware assembled within your computer housing or case. The BIOS is really the piece of hardware that pulls it all together. In fact, it was the only proprietary component of the original IBM Personal Computer. Compaq reverse-engineered the IBM BIOS, and started the PC Clone Revolution. Some might argue that the BIOS is a hybrid component composed of part hardware (the actual chip) and part software (the programmed Read Only Memory). The Operating System allows other computer programs or 'applications' that you use on a daily basis to function in concert with each other and the system as a whole. To try and give you a dependency mapping, think of it like this: Hardware -> BIOS -> OS -> Applications. Or, to think about it in the reverse order: Applications require an Operating System, which requires a BIOS, which requires hardware to function.

Microsoft Windows is an Operating System. Apple Macintosh is an Operating System. Microsoft Windows 7 would be a particular release (the current release) or version of the Microsoft Windows Operating System, just as Mac OSX Snow Leopard is the current release of Apple's Macintosh Operating System. A striking difference between the Microsoft Windows Operating System and the Apple Mac OSX Operating System, is that with each new release, the Microsoft Operating System gets larger, and requires more hardware resources (such as RAM and Hard Drive space) to run effectively; while, this most recent Apple OSX release improved performance while actually using less space. But this post isn't about which OS is better between the Microsoft and Apple brand of commercial Operating Systems. This post is about Ubuntu Linux, which just released version 9.10 of their free, open source software.

Before we can effectively talk about Ubuntu, we needed to understand what an OS was in terms that most computer users would understand. Now that you understand what an OS is, you can contemplate how much that OS costs you, when you purchase a new computer. Then you can also think about how much you have to spend every few years to upgrade to the latest version. While the recent Apple upgrade from Leopard to Snow Leopard was insanely inexpensive, most Microsoft upgrades are not. Even after paying the piper (Micro$oft), often times the casual computer user comes to find that upgrading the OS isn't a simple process, and worse, they come to find that the hardware they currently own can't operate the new OS with the same level of performance that the previous OS maintained. This leaves many users "behind the times" as new OSs are rolled out to feed the cyber-economy. Eventually, the old OS is no longer supported, and the user has no choice but to operate a system riddled with security holes, or pay to upgrade.

Enter Linux. Linux might better be termed GNU/Linux; but, Linus Torvalds, the father of the monolithic Linux Kernel, isn't a fan of that notion. Yet without the GNU Project's developed software that was a direct result of the efforts of Richard Stallman and the Free Software Movement, Linux wouldn't be of much value to the average computer user. In fact, Linux came along at just the right moment to take advantage of a large amount of software developed as a part of the GNU Project which was waiting on the completion and refinement of their own kernel (called Herd).

GNU, which is a recursive acronym that stands for "GNU Not Unix", was working on a more complex kernel type called a micro-kernel, which differs fundamentally from a monolithic kernel in its structure and functioning. As fortune would have it, the GNU Project's micro-kernel (Herd) wasn't ready for prime-time - so the Linux monolithic kernel filled the gap.

There are subtle differences between the Free Software Movement, and the Open Source Movement - but for the average person, they both mean powerful, maintained software, that doesn't have a cost associated with its acquisition or redistribution. Luckily the two camps are more similar than not, and continue to produce and promote free, open source software with the benefits of a huge community dedicated to peer-review. However, for a long time, using Linux was not for the casual user. The average Linux user was either a computer hacker, soon to become a computer hacker, or at least a person who would learn the meaning of the phrase: "F-disk, Format, Reinstall".

Enter Ubuntu Linux. Ubuntu Linux is a 'flavor' of linux, or perhaps more clearly stated - a particular distribution of Linux. It happens to be a very easy version of Linux to obtain, install, and use. There are several versions of Ubuntu which have been further customized for groups of people like educators, musicians, and people who like to record their television shows.

There are freely available CD and DVD disk images that one can download and "burn" from what is called an "iso" image or file, which will allow you to boot your computer from the resulting media, run the OS from within RAM, and leave your original OS in tact. This method of "live" CDs or DVDs allows one to explore the power and functionality of Ubuntu Linux without committing to replacing their current OS.

If you have enough free disk space, you can also install a free program such as VMWare Server, and then install Ubuntu as a Virtual Machine. For Macintosh users, a commercial product called VMWare Fusion works very well for this purpose. This option allows you to run your original OS, and simultaneously run Ubuntu Linux within a window on that system. This is a very powerful way to go, and is recommended for all serious cyber-justu practitioners.

For those of you who are inclined to experiment and even program, please go to http://www.ubuntu.com and download the latest version, 9.10. You can burn an installation disk, and run this new Operating System on one of your older systems. Not only are there massive free software resources awaiting you, but some of the best security tools made. For those of you who have no intentions on re-purposing your old computer hardware, I suggest you donate the computer hardware.

As we have stated, Ubuntu is Free Software. It is also Open Source, which means that the "Source Code" or lists of computer instructions that make it function, is available for download, use, and modification. CyberCede.org (the website of which is still under construction) is accepting donations of your old computer hardware. We are taking versions of Linux (Ubuntu when the minimum hardware requirements are met) and installing the Open Source Operating System onto the donated hardware, and making these re-purposed systems available to those in need. For more information about the program, please send an email to metajunkie at my google mail address (gmail dot com) with the subject header of cybercede.org charity division. We are not currently accepting large, CRT monitors; but, will happily accept functional flat screen monitors of all sizes. All donated systems will have their hard drives thoroughly and securely wiped of any and all data prior to the Ubuntu Linux installation.

So, why do we care that Ubuntu 9.10 has been released? Because, unless you are running OSX, or have some real need to run Windows (such as specific games or financial applications) - you can set yourself free through embracing the Open Source Revolution! OSX users can actually already take advantage of many GNU Project applications. OSX, after all, has a Mach Micro-kernel with a BSD subsystem at its core. For those willing to pay, I recommend the Apple line of computers running OSX. For everyone else - it is time you took a look at this Linux thing. It isn't just for computer geeks anymore.

The Ubuntu distribution really is easy to use, and brings the power of Linux to even the less gifted of cyber-jutsu practitioners. Had I not converted my Mom to being a very satisfied OSX user, she would be using Ubuntu Linux this year. She wouldn't be using Ubuntu Linux because her cyber-justsu is ready to take her into the depths of the Bourne Again Shell (BASH) - she would be running it because it is ready for her to use it without her needing to know what BASH is. Likewise, the default shell on OSX is BASH - and my mother is blissfully unaware of this fact too. ;)

Sensei Metajunkie


PS
If you would like to learn more about the origins of Linux and GNU, you might want to check out a movie called "Revolution OS" which was released in 2002. It is available as a streaming media title on Netflix.

You might also enjoy reading "The Cathedral and the Bazaar" by Eric Steven Raymond.



Tuesday, October 27, 2009

Security Warning: Facebook Fishing Attempt



All students of cyber-jutsu should be on guard against a recent fishing attack received by CyberCede Corporation.

The email looks official at first glance; but, we know Facebook would never send out such a message that was not at least first requested by the end user (you). The fishers are hoping that we open the attachment they have sent us, which is pretending to be a new password for us.

A closer examination of this email, in fact shows us that it is bogus. Here we are using Apple's Mail program. Within that application we can view the "long headers" as an option off of the "View" menu, by following the "Message" delta which opens a sub-menu. Users of other email programs should have some similar way to view more details regarding the transmission and receipt of the message.

We've blacked out some of the address particulars so as not to add to the amount of spam we are already processing, and I've circled the "Reply to" and "Return Path" fields in red. (see below)



We can see that the "Reply to" and "Return Path" fields are not consistent with the facade that this email is from Facebook.

We call this a "fishing attack", because the malicious agents are sending this email to potentially hundreds of thousands or more people in hopes that someone will "bite". Just like fishing, many fish may pass by the bait. All it takes is one big one on the hook to make the day pay off.

Exactly what the payload is, has not yet been determined. The payload is the file that they have sent. Since it is in "zip file" format, it could be a buffer overflow attack against a popular "unzip" program. Or the zipped file could be a less creative trojan horse or other malicious executable.

Regardless of what the payload is - we know this is not from Facebook. We all know to just delete the mail without replying to it or opening the attachment.

Stay safe,

Sensei Metajunkie

Thursday, October 22, 2009

Reports of Chinese Cyberspying against U.S. Corporations

Today the Wall Street Journal ran a story about a report that the US-China Economic and Security Review Commission contracted Northrop Grumman Corp. to create. The report, which I have not yet read, was supposed to have been released today.

The report indicates that Chinese espionage operations via cyberspace are on the rise, and that the People's Liberation Army (PLA) has been recruiting members for cyber-warfare militia units.

According to the article, Chinese Cyber-spies steal $40 - $50 billion per year in intellectual property from US organizations.

I have two fundamental questions:

1. Can we trust a company like Northrop Grumman Corp. to create such a report, since they are a part of our Military Industrial Complex, and have launched an advertising campaign describing themselves as "the face of cyber-security"?

2. If the reports are accurate - shouldn't we be building our own cyber-warfare militia units?


I think it is proper to hope for the best, but be prepared for the worst. So...

CyberCede is now accepting applications for participants in its cyber-warfare militia. Please send an e-mail with "cybercede cyber-warfare militia" in the subject line to "metajunkie at gmail.com" to express interest.

Sensei Metajunkie

Google AdSense Account Disabled

Some of you may have noticed that the cyber-justsu dojo walls seem a little bare. The Google Advertisements are missing.

Google has disabled our AdSense account.

In an email, they have asserted that our "AdSense account has posed a significant risk to [their] AdWords advertisers".

This would appear to happen frequently enough, that they have a FAQ established to provide more information.

From the FAQ:

"Because we have a need to protect our proprietary detection system, we're unable to provide our publishers with any information about their account activity, including any web pages, users, or third-party services that may have been involved.

As you may know, Google treats invalid click activity very seriously, analyzing all clicks and impressions to determine whether they fit a pattern of use that may artificially drive up an advertiser's costs or a publisher's earnings. If we determine that an AdSense account may pose a risk to our AdWords advertisers, we may disable that account to protect our advertisers' interests.

Lastly, please note that as outlined in our Terms and Conditions, Google will use its sole discretion when determining instances of invalid click activity."

So, we really have no idea why our account was disabled. If any of our readers have been randomly or blindly clicking on advertisements, you have not helped us. In fact, you may have shut down what might have been a great source of passive income for our blogs.

We have petitioned google to reinstate our account. If that happens, I encourage you all to only click on advertisements which are of interest to you. Don't be afraid to click on advertisements, that is why they are there - but please refrain from just clicking because you know it is generating revenue for us.

I don't usually cross-post between these blogs - but I will put this message on all of the blogs.

Thank you for your understanding and cooperation.

Sensei Metajunkie


Wednesday, October 21, 2009

Metasploit acquired by Rapid7

Metasploit has been acquired by an information security company called Rapid7. Rapid7 is the self-proclaimed leading provider of vulnerability management, compliance and penetration testing solutions.

Well... if they weren't before, acquiring Metasploit will certainly give them a boost.

Let us hope that what is free today stays free tomorrow, and that new features won't be withheld from the open source community, and reserved for "paying customers only". While I'm happy for the founder of Metasploit, HD Moore, who will be hired as the CSO (Chief Security Officer) of Rapid7, I can't help but think we've lost another great free tool. I hope they prove me wrong.

You can read more details about the acquisition here.

I'm glad I told you all to install this last week. There is no telling if there will be any lapse in the ability to download the framework software.

Friday, October 16, 2009

Utility: Google Translate for International Communications

During a recent viewing of the developer video of Google Wave - which is going to change the way we all communicate and collaborate online, I saw them use an application with a Wave for translation between English and French.

I am happy to say, we don't need to wait for Google Wave to be released to translate in-between various languages.

You can check out Google Translate at:

http://translate.google.com

This can be important to your cyber-jutsu. Especially if you are working with cyber-jutsu practitioners in other countries.

Thursday, October 15, 2009

Green Belt Exercise: Install Metasploit


Metasploit is an amazingly powerful and free security tool that must be on the weapons rack of the penetration tester. For the casual cyber-jutsu practitioner, who is not seeking to engage in hard core hacking, contract penetration testing, or cyber-warfare, Metasploit is not a required tool. However, we'll be looking at this tool in detail. Green belts interested in becoming CyberCede Samurai should understand what Metasploit is, and learn to execute reconnaissance and attacks to deliver payloads from within the framework.
To emphasize the importance of your familiarity with this tool: Green Belts seeking their Black belts, and ultimately the title of CyberCede Samurai, will endeavor to write their own exploit in Ruby for use within the Metasploit Framework (msf) or modify/enhance a previously written Metasploit exploit for use against a particular target. Actual Ruby code should be posted in the applicable hacking code blog, when the time comes.

You should download and install Metasploit if you have not already done so.

Don't forget to breathe!