Monday, June 20, 2011

The Rich Seize Internet Name-space!

ICANN (the controlling authority for the Internet) will accept applications ($185,000) for new root domain names (i.e. website suffixes like .com and .net), for 90 days, beginning Jan 12, 2012.  Winners awarded their domain name (e.g.: .ipod, .apple, .cisco, .pepsi, .democrat, .republican, .healthcare, .books, .worldbank, etc.) must pay $25,000 annually.  These new root domain names can be in "nearly any word in any language, including in Arabic, Chinese and other scripts", this was decided at a meeting today in Singapore.  (Source:  Associated Press)

What does this mean?  It means that .com just became a "second class" root domain.  I'm not sure that this is good for small businesses in any way - but, that obviously isn't a concern for ICANN.  Anyone who can afford the process can apply for any root domain name they want.  If two people or entities want the same domain name, they can bid on it - so who ever has more money wins.  If, for example, Pepsi and Coke, in addition to applying for .pepsi and .coke, both wanted .drink or .beverage or .pop or .soda - they could fight it out in good ol' greenbacks via public auction.

That is all well and good for Pepsi and Coke; but, what about a small Information Security Company, like CyberCede Corporation?  What are the chances that web traffic going to cybercede.com will decrease in favor of being directed to whomever owns .infosec, or .security?

The face of the Internet is about to change - perhaps more drastically than it has changed since its inception.

This also means that there are sites you just won't be able to reach without knowing a foreign language, or without having a modification to your keyboard to allow you to type in non-Romanic characters.  I think this is significant.  Up until this point, the Internet has been a global unifying movement.  Sure, you can find pages that have foreign language content today - but you can at least read the address of that page in English.  I would go so far as to believe that Internet use could have been contributing to the adoption of English as a global standard language for international communication.

While some might scream "mono-culture" - that simply isn't what I'm talking about here.  It is a well documented fact that a national language goes far in unifying a people.  In the same way, English has unified many people around the world via the Internet.  In some very small way, we were, in my humble opinion, rolling back the damage done by the Biblical tale of the Tower of Babylon.  The world has been "getting smaller", and in large part that has been because of the Internet.  I think this move will reverse that perception.

To sum it up - we can expect big money to create great domain space names, and attempt to market .com into obscurity; and, using a US English keyboard, where previously it was a gateway to information in every corner of the world, will now become a limiting factor - barring entrance to foreign sites for the average American.  But hey - who cares, right?  Most Americans don't actually get world-wide information from the Internet.  Their computers are the little brother to their massive television sets, that broadcast 'truth' directly into their subconscious minds.  After all - TV is only meant for mindless relaxation and reassurance; and, the Internet is just for Facebook games and Porn, right?  As long as I can order my pizza online - I don't care what they do.  Mmmm pizza and sitcoms - the American Dream.  Go back to sleep .... go back to sleep.  OH?! incoming facebook message on my phone!  Oh it's just a someone using facebook to promote their blog... go back to sleep.... go back to sleep.  zzzzz



Wednesday, March 23, 2011

Cyber Attack From Iran

A well prepared attacker with an IP address originating in Tehran, Iran (212.95.136.18) compromised a user account in an RA (Registration Authority) at comodo.com, created themselves a new userID, and quickly generated CSRs (Certificate Signing Requests) for nine certificates.  Comodo is a certification authority present in the Trusted Root Certification Authorities Store on Microsoft Windows, as well as all modern web browsers such as Mozilla Firefox and Google's Chrome.

Given proper circumstances, the resulting certificates could be used to spoof content, conduct phishing attacks, and/or perform man-in-the-middle attacks against all popular browsers, across many platforms.  Using these certificates, the attacker could redirect a victim to a forged Firefox plug-in download page, and deliver them malicious add-ons to install.  The certificate would appear valid to the the browser, so there would be no warning to the user that something was amiss.  At that point, the attacker could control the lion's share of computer's in American homes.

However, upon discovery, all certificates were revoked.  This will make using the forged certificates much more difficult, and much less far reaching (unless other key components of our Internet infrastructure are also compromised, namely our DNS systems).  Comodo could only verify that one of the certificates generated was actually received by the attacker.  Comodo reported, "Our systems indicate that when this one certificate was first tested it received a 'revoked' response from our OCSP responders.  The site in Iran on which the certificate was tested quickly became unavailable."


It is believed that "this was likely to be a state-driven attack".

At least it looks that way.  Of course - in cyberspace - things aren't always what they seem.  The attack could have just as easily been conducted by an American Warhawk, who compromised a system in Iran, and launched the attack from there.  However, Comodo reported that, "The Iranian government has recently attacked other encrypted methods of communication."

In order to use these certificates maliciously, there would have to be additional DNS tom-foolery.  Do the attackers already have that piece of the attack 'in the bag'? 

You may recognize some of these domain names.  It looks like this was an attack against communications, as opposed to banks or online-shopping sites, as a criminal might attempt.


In any event - even though the certificates in question were revoked, Microsoft released a patch.  If you are running windows, you should apply that patch.


From the comodo release:

Fraudulently issued certificates

9 certificates were issued as follows:
Domain:  mail.google.com    [NOT seen live on the internet]
Serial:  047ECBE9FCA55F7BD09EAE36E10CAE1E

Domain:  www.google.com  [NOT seen live on the internet]
Serial:  00F5C86AF36162F13A64F54F6DC9587C06

Domain:  login.yahoo.com  [Seen live on the internet]
Serial:  00D7558FDAF5F1105BB213282B707729A3

Domain:  login.yahoo.com    [NOT seen live on the internet]
Serial:  392A434F0E07DF1F8AA305DE34E0C229

Domain:  login.yahoo.com     [NOT seen live on the internet]
Serial:  3E75CED46B693021218830AE86A82A71

Domain:  login.skype.com     [NOT seen live on the internet]
Serial:  00E9028B9578E415DC1A710A2B88154447

Domain:  addons.mozilla.org     [NOT seen live on the internet]
Serial:  009239D5348F40D1695A745470E1F23F43

Domain:  login.live.com     [NOT seen live on the internet]
Serial:  00B0B7133ED096F9B56FAE91C874BD3AC0

Domain:  global trustee     [NOT seen live on the internet]
Serial:  00D8F35F4EB7872B2DAB0692E315382FB0

Thursday, March 10, 2011

New Definition: TMH is Too Much Help

 TMH:  Too Much Help

Every now and again we need to come up with new words to describe something in our ever-changing world.  In the Digital Age, we often use abbreviations.  Some abbreviations, such as "LOL", for "Laughing out Loud" and "BRB", for "Be Right Back" have moved from what we might call "geek-space" into everyday use.  Cell phones, and their ability to send text messages have spread these sort of practices far and wide.  This new abbreviation is derived from an already popular abbreviation used in verbal communications: "TMI", which stands for "Too Much Information".

Because many of us have become very impatient, as well as very reliant upon spell checkers, some "auto-correct" features have been built into many mobile phone text message clients.  The "auto-correct" features, as anyone who has used them will attest, sometimes offer "too much help". 

It is because of this shortcoming that I have the distinct honor of bringing you a new abbreviation.  TMH

TMH stands for too much help.  The reason it is a useful abbreviation is because the person who has become a victim of the helpful auto-correct feature is often oblivious to the fact that their text messages was auto-corrected into obscurity.

Here is an example text message session to illustrate the point:

Bridget:  we'd paper

Metajunkie: tmh

Bridget:  We need paper

Metajunkie: OK, I'll pick some up on way home

Here is another example text message:


Bridget:  Innuendo and her husband can't come out on Friday
Metajunkie:  Who is innuendo?
Bridget:  Bonnie
Metajunkie:  why do you call her innuendo?
Bridget:  tmh
Metajukie: oic

and one last one for good measure:

Bridget:  pick up milk
Metajunkie:  tmh?
Bridget: ha ha. no - really - pick up milk

I think we will all be able to put the abbreviation "tmh" to good use.

Happy texting!

Metajunkie

Friday, January 28, 2011

Qwiki Entries for some Malware related terms

Rather than searching with Google, to get an understanding of some key terms regarding cyber-jutsu, and the threats to your computer, check out these links to Qwiki.com articles.


Qwiki.com is a new way to learn about a topic quickly. Perhaps best of all, for many of us who have tired eyes from reading our computer screens all day – or those of us who are just plain lazy... Qwiki.com reads the entry to you. It should be noted that the pronunciation of all words is not quite “spot on” yet. The site is very cool – but unquestionably - “in the works”.


Some terms all computer users should be familiar with:


http://www.qwiki.com/q/#!/Malware


http://www.qwiki.com/q/#!/Botnet


http://www.qwiki.com/q/#!/Trojan_horse_%28computing%29


http://www.qwiki.com/q/#!/Keystroke_logging


http://www.qwiki.com/q/#!/Rootkit




Thursday, September 2, 2010

Book: Professional Penetration Testing (Purchased)

I'm reading a book I recently purchased, called Professional Penetration Testing.  I'm using this as a first try at using the tools available for Amazon Associates on Blogspot.  Feel free to hover over the image/link, and click for more information on the book.  I believe I only generate some sort of commission, when there is a sale.

I pledge to my readers never to offer products that I don't own myself.  I hope to give meaningful reviews of these products as well.

So far, my experience with Professional Penetration Testing is a positive one.  While I admit that the price tag is a little steep, you should understand that it comes with a DVD that contains not only instructional video, but also some system images to be used in training.  These images are suitable for loading into VMWare for example.

Another thing about the book that put it onto my "buy it now" list, is that in addition to covering the technical aspects of Penetration Testing, it also covers ethics as well as "the business" of Penetration Testing.

I hope you all don't get sick of this advertisement, but I'll keep posting it while I'm going through this book.  I know there is an awful lot of information that is redundant for me, personally.  That happens when you are at the stage of your career that I am in (I think they call it getting old).  There aren't many books I can pick up and not have to go through some amount of information that I'm already familiar with.  But this is as much a part of Cyber-Jutsu as anything else.  One needs to learn to dig through the proverbial weeds, in order to find the gems that will be useful.

Another really good reason for me to pick up this book, is that I expect that CyberCede, my company, will be hiring within the year.  I think this might be a great tool for my new recruits.  If you are in college and looking for a co-op position or if you recently graduated and desire a position as a entry/junior level information security analyst, drop me an email and/or shoot me your resume.  If you are eager to get started on this path - you might want to purchase this book (and keep your receipt).

The State Of The Current SNAFU vs. The Good Old Days

I sit and write this post, which is long overdue, and slightly off topic, while I watch my HP Pavilion dv9000 "running" Windows Vista Ultimate "welcome" me forever.  It is just sitting there with its very stylish shining circle spinning like its grandfather, the hourglass used to do.  I'll be honest.  It is still spinning - and spinning, and I'm getting the sinking feeling that this system isn't going to come back up without a hard boot.  Luckily, I'm barefoot right now.

While I enjoy the many terabytes of storage that store movies, pictures, and other data of all kinds in my home and home office, there is a part of me that longs for "the good old days".  Which good old days might those be?  How about a time when, if I had a problem with my operating system disk, I reached over and grabbed one the the other copies that I had in a pile of 5.25" floppy disks.

That was the way my first IBM clone worked.  It didn't come with a hard drive, it didn't even have a pre-established space to mount one.  I had the deluxe model, it had not one, but two five and a quarter inch floppy drives.  This allowed me to boot the computer off of the MS DOS disk, and leave it in the drive while I put my application floppy disk in the second drive.

Others, who didn't have this deluxe model would have to, from time to time, pull out their application disk, and re-insert their Operating System disk for a required file.  One of my most-used applications in those days was a word processor called "Word Star", another was dBase, a database I taught myself to use (it may have been dBase II). Ah, the time I saved by having that second floppy drive was well worth the price. :)

I purchased that first IBM clone while I was in the US Air Force, and stationed in Japan (1987-1989).  It was a Commodore PC10.  The "10" stood for the speed.  It ran at an amazing 10Mhz.  This was a vast improvement over the actual IBM PC computers I had the opportunity to use in the Artificial Intelligence lab at the on-base satellite-campus for the University of Maryland.  Those beasts were running around 4.77 Mhz as I recall, and the speed difference while running the expert system I had written in Prolog was significant. I recall my first reaction to seeing the IBM logo on those systems.  I was ecstatic.  "Oh man," I had said, "real IBMs!"  My instructor asked me if I had a computer back in my dorm, and I told him what I had.  "You will want to use that when you can," he advised; and, he was right.

While I was very skeptical at first, tinkering (or hacking) with the computer hardware started almost immediately. I had a friend who was disgusted by the notion that I was only using two floppy drives to run my system; and he helped me upgrade my IBM clone to include a hard drive.  It was the first time I had ever taken the cover off of a computer.  I was shocked and appalled when my friend pulled a drill out of his bag.  "This is a computer," I said, as if he was not aware of that obvious fact.  "It is a delicate piece of electronics," I continued as he moved closer to the system and plugged the drill in.  He spun the drill's motor up and grinned at me.  "I don't think this is the way it should be done," I pleaded.  He was mildly amused at first, but quickly annoyed.  I was perhaps 18 or 19 years old, and my friend was probably in his mid to late 30s.  He was perfectly content not to use the drill.  But he advised me, if we didn't, he couldn't help me install the hard drive I had just purchased with his help.

I bought the hard drive at the same location I bought the PC.  There was an electronics shop on base that had all of the wonders of the world, most of which would not be seen in the Continental United States for about four years.  Most Americans aren't aware of the consumer technology lag between Japan and the United States which is still around four years.  I think that is an effect produced by the unquestionable pseudo-truth that all Americans grow up with; namely, that the United States is the best country in every way.  But I digress.

My friend had suggested that I purchase the 10, or 20 Megabyte hard drive.  "You will probably only ever use ten megabytes," he advised.  "You might use ten, you probably won't ever even need more than ten," he continued as I held the forty megabyte box in my hands.  "You will never in your life use forty megabytes.  You are wasting your money," he urged.  I bought the 40MB hard drive, and never looked back.

Having been pushed up against the cliff of not getting that monster hard drive installed if I refused to allow my evil computer-doctor friend to use his barbaric drilling instrument, I gave the go-ahead.  He did an outstanding job.  That hard drive, a Seagate, is still mounted securely in that 8088 system to this day - and the last time I spun it up, it was still working.

While I've been typing away - my HP laptop did finally boot, and I was able to log into my desktop. However, Internet Explorer refuses to run.  Only God knows what the system was doing for all the time it took it to boot.  I'm attempting to remove Windows Live Once Care (which was a really good Microsoft offering that is no longer supported).  It refuses to be removed in Safe-Mode, and everything is just hanging (or taking unbelievable lengths of time to complete).

There were updates that seem to have failed to load - but kept trying each time I shut down. I've been round and round with this system now for longer than I care to admit.  Is it a virus?  Perhaps.  An intermittent drive failure?  Perhaps.  A heat issue?  Perhaps.  Is it a pain in the arse?  Definitely.  Can I easily swap out some parts to troubleshoot?  Definitely not. :(

Until next time,

Metajunkie

Tuesday, March 2, 2010

Accumulated Permissions

One thing that every company should look at is the effect called "Accumulated Permissions". This is often caused by individuals within a company moving from one department to another. The knowledge worker has permissions to do job A, and when they are promoted, or transferred into a new role (job B), the permissions to create, read, update, and/or delete information concerning job A might not be removed.

If a person works for an organization long enough, they can accumulate quite a large quantity of technically unnecessary permissions. This obviously creates a potential for abuse from such accumulated permissions, if they belong to a disgruntled, malicious, or unscrupulous employee. Even when under the control of the most loyal and trustworthy employee, such accumulation of permissions are still a danger to the organization because of accidental use of permissions no longer expected to be active, or in the event of an account compromise by someone who means the organization harm.

A yearly, or quarterly, manual review of all roles within an organization, and the actual permissions associated with each account is the only fool-proof way of handling Accumulated Permissions. Such a review requires a joint effort between managers, data owners, data custodians, and information security professionals.

Information Security Companies such as CyberCede Corporation, can assist an organization with internal permission reviews.