Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, September 24, 2010

ATM Keypad Shielding

If you're not shielding the ATM keypad before entering your PIN number, this video will demonstrate the error of your ways.



With the use of card skimming devices on the rise, and given the public's inability to determine if an ATM has been compromised, shielding the keypad is one of the only defenses available.

Via Gawker





Friday, February 19, 2010

Chart: Choosing a Secure Password

Are you a teen? A douche? A geek? A pro?

The type of person you are directly influences your choice of password strength. At least this chart from Forever Geek wants you to believe that.












































Don't be bringing that weak-ass dictionary attack-prone password into MY house, dog.

Monday, January 11, 2010

BackTrack 4 Final Released

Remote-Exploit has announced that BackTrack4 Final has been released.



BackTrack 4 Final is out and along with this release come some exciting news, updates, and developments. BackTrack 4 has been a long and steady road, with the release of abeta last year, we decided to hold off on releasing BackTrack 4 Final until it was perfected in every way shape and form. With this release includes a new kernel, a larger and expanded toolset repository, custom tools that you can only find on BackTrack, and more importantly, fixes to all (well, most..) major bugs that we knew of.

You can download it at http://www.backtrack-linux.org/




Thursday, January 7, 2010

RSA Encryption 768-bit Keys Broken

Bad news if you're not using the 1024-bit keys for RSA cryptography - the 768-bit keys have been broken. And it's only a matter of time until 1024 bites the dust.



From The Register:

An international team of mathematicians, computer scientists and cryptographers broke the key though NFS, or number field sieve, which allowed them to deduce two prime numbers that when multiplied together generated a number with 768 bits. The discovery, which took about two-and-a-half years and hundreds of general-purpose computers, means RSA keys can no longer be counted on to encrypt or authenticate sensitive communications.

With the quantum increases in computer processing power, what took 2 1/2 years today might take a year in 2011, and 4 months in 2013, so it's only a matter of time before the RSA 1024-bit is also broken. While the article posits a decade, it's more likely to happen sooner.

The real issue is that there are quite a few devices using shorter key lengths than 1024 bits because of their limited processing ability. Keys of 300 characters or less can be broken within hours on a standard personal computer, and 512 bits is easily defeated in weeks on typical hardware configurations.

Current best practice is a key of 2048 bits, and using today's technology, breaking a 4096-bit key seems unlikely. But that only provides additional time to develop more secure algorithms, as processing advances makes this a math problem that will eventually be solved.

It will be interesting to see how vendors react, especially those who market products that rely on the shorter key lengths. RSA encryption is already slower than some other symmetric algorithms, and if the devices already choke on longer keys, moving to 2048 or 4096 will be impractical.



Thursday, December 31, 2009

Feds Recommend Dedicated PC for Online Banking

The FBI and the American Banking Association are recommending that small businesses use a dedicated PC - not used for web browsing, email, or any other purpose - for online banking.


That's ridiculous.

At some point business owners need to begin holding accountable the vendors who provide inadequate security products, software developers and firms that release buggy, vulnerable operating systems, browsers, and applications, and users who don't follow safe computing and web browsing guidelines. And they need to demand more robust authentication and authorization mechanisms from their financial institutions.

It's absurd that money movement practices have not evolved in the face of increased threats and hundreds of successful exploits. From Wired:

The FBI says thieves have stolen about $40 million in this way in more than than 200 cases they’ve investigated in the last two years involving small to mid-size companies and organizations. Such companies generally do not employ dedicated computer security staff or have extensive knowledge about how to protect themselves with firewalls, anti-virus and other measures and policies.

It's a common attack strategy - aim for the weakest point in the system. Why attack a bank directly when the soft underbelly of naive business owners and employees remains exposed, ripe for the picking?

Small businesses need to come to terms with the fact that computer security is a mandatory cost of doing business. It isn't 1982 anymore. You can't ignore information security any more than you can keep a manual ledger or crank out your financials on an adding machine.

So let's say you take the advice of the FBI and ABA and set up a dedicated computer within your network for online banking only. Guess what? You're still connected to the internet, and you're still not 100% safe.

I can redirect your access to your online banking site via DNS cache poisoning. I can compromise another computer (that's not dedicated) within your network and use it to infect and take control of your dedicated PC.

I'm able to conduct IP address spoofs, or perform a man-in-the-middle attack to snag the traffic going between you and your financial institution.

If these don't work, there's always session hijacking, or replay attacks, or compromising weak encryption keys. And a dedicated PC doesn't prevent attacks via social engineering.

Here's a couple of things every small business should consider:

  • Use a non-Microsoft platform for conducting online banking transactions. Since Windows and Internet Explorer continue to have a dominant market share, they attract the most attention from attackers.
  • Don't use wireless for online banking. It's too difficult to secure for those without the correct technical expertise.
  • Use Mozilla Firefox, Opera, or some other browser.
  • Install good antivirus software and keep it updated.
  • Use a tool like Secunia CSI to make you aware of vulnerabilities and end-of-life software installed on your systems
If you're truly concerned about online banking, follow the guidelines I provided in my October 13, 2009 posting, Safer Online Banking Using a Live CD. It's certainly more manageable than setting up a dedicated PC, because a Live CD can be used for banking transactions from any computer.




Wednesday, December 30, 2009

Bruce Schneier Discusses Security Theater on Rachel Maddow Show

I've been reading Bruce Schneier's blog and his books for years because I think he intrinsically understands the psychology of security and the difference between actual and perceived risk.

Check out this clip from the Rachel Maddow Show where the discussion revolves around the recent underwear bomber and our government's subsequent reaction.





Tuesday, October 27, 2009

KFC's Colonel Sanders Breaches UN Security


KFC's quest to make us all buy their damned Kentucky grilled chicken may eventually lead to civil unrest and thermonuclear war. You heard it here first.

It all started with the Oprah free chicken fiasco, where coupons offered for a grilled chicken lunch led to a run on the chicken bank and scores of disgruntled breast-and-thigh aficionados.

Oh, the humanity!

Apparently not content with stirring up the population one restaurant at a time, KFC sent an actor portraying venerable marketing object Harland "Colonel" Sanders to the United Nations headquarters in New York, where a sympathetic (and hungry?) UN security guard violated protocol by escorting the fake colonel through sensitive areas within the UN complex, culminating in a handshake photo-op with UN General Assembly president, Dr. Ali A. Treki of Libya.

UN representatives are downplaying the significance of the security breach, noting that since there was no official meeting with Treki scheduled, the UN isn't to blame. It's all the work of a single rogue security guard.

And the photo-op? Well, it's not really a photo-op, because the visit wasn't official, and besides, Dr. Treki is a polite man. What sort of world diplomat refuses a handshake from a kindly Kentucky gentleman?

World peace has never been closer.

Image via NationalPost.com
 


Wednesday, October 7, 2009

Ministry of Defence Self-leaking

A UK Ministry of Defence document designed to help prevent documents from leaking onto the Internet has itself been leaked onto the Internet.

I question the quality of the advice given in this 2400-page document, for obvious reasons.

Thanks, Wikileaks!

The document lists journalists as threats, along with terrorists, criminals, and foreign intel services. So it's nice to know that the UK Ministry of Defence considers themselves a hammer, and everyone else is a nail.

Via Privacy Digest

Wednesday, August 26, 2009

R.I.P. Security on GSM Phones

A security researcher is launching an open-source project to crack GSM cellular phone encryption that will allow attackers to decode phone calls and any data that happens to be in transit via the device.

If you're on T-Mobile or AT&T in the US, you only have a couple of months until you need to begin worrying.

Cell phone security has been woefully lacking for at least twenty years, mainly due to what I describe as a Microsoft-like approach of delivering cool features first and security second, if at all.

Karsten Nohl claims that he's looking to exploit a vulnerability that's been known for 15 years and affects 3 billion phones as a way to prod cellular phone manufacturers and carriers to get serious about security.

Cracking GSM encryption is nothing new, but previously the tools have been very complex, highly technical, and pretty darned expensive. Nohl hopes to change that via his open-source project. Ah, the joys of distributed computing.

Link via CNET

Image via Silicon Valley Sleuth


Sunday, August 23, 2009

Avoiding Dirty Web Sites - Here's How

I spent some time earlier today helping a friend rid her home computer of a malicious application that kept popping up notices warning that her machine was infected by a virus while advising that if the user purchased their anti-virus program, a portion of the cost would be donated to environmental causes. Green AV is the name of this pernicious app.

So how do people end up with viruses, Trojan horses, malicious code, and other unwanted pieces of software installed and functioning on their machines? Typically by browsing particular types of web sites, accessed directly, via a shortened link (TinyUrl, bit.ly, etc.), or by following a hyper-link embedded in an email, instant message, Twitter post, ad naseum.

Anti-virus and security vendor Symantec has written up a handy survey of the 100 Dirtiest Web Sites with information gleaned by visiting the sites. And here's something that might surprise you - while the average number of threats per site was 23, a number of the offending locations had between 18,000 and 20,000 threats apiece.

It used to be that adult sites made up the vast majority of the threat class, but according to Symantec, only half of their survey sites were comprised of adult content. More innocuous sites are now pressed into service to host malicious content.

The best advice? Use a browser that has a smaller risk footprint, like Opera or Firefox. Microsoft's Internet Explorer is notorious for vulnerability, and its tight integration into both the Windows platform and applications like Microsoft Office means the chance of damage increases.

If you move to Firefox, installing add-ons like NoScript, Ad Blocker, WOT, and others can keep you from ending up on malicious locations or having scripts install software without your knowledge or permission.

Of course, having an updated version of an anti-virus program that gets its signature database updated at least daily is a must, as is using a free program like Secunia PSI to make sure that end-of-life software is identified, and that ancillary programs like JavaScript, Flash, Adobe Reader, and iTunes are maintained with security patches and version upgrades, since many vendors often upgrade to new program versions to fix serious vulnerabilities, leaving prior versions wide open to exploit.

Since even mainstream sites are being compromised by SQL injection attacks or via advertisements piped in from compromised ad servers, simply avoiding particular kinds of web sites no longer offers a measure of protection. Disabling active scripting and taking other defensive measures is now a requirement for safe web browsing.

Questions? Email me at RedGeckoBlog@gmail.com.

Image by SecurityLabs.Websense.com


Wednesday, August 12, 2009

How To Block Those Secret Web Cookies That Track Your Visits

I've written often about the practice of web sites salting your browser with cookies in order to track your movements as you surf here and there on the interweb. I've also suggested some privacy settings and browser tips and tricks to help protect you from the scourge of targeted advertising cookies that continuously invade your privacy, often without your knowledge or consent.

Now comes word that many sites are serving up flash cookies, using Adobe Flash, that aren't affected by your browser's privacy settings and that often evade browser add-ons, like TACO for Firefox.

Behavioral advertising on the web is becoming much more aggressive as the number of people using the Internet rises, and as advertisers look for more effective ways to increase click-throughs to generate ad revenue and hopefully sales down the line.

Rather than showing you random ads and hoping for a 1% success rate, it makes sense for advertisements to be targeted toward your specific interests, where the odds that you'll click on the ad would be much higher.

What better way to determine what you like than to track the kinds of websites you visit and what kind of articles you read. If you add a couple of appliances to your wish list on Amazon, that's valuable information for them to have. Capturing your location, browser type, operating system, and so on from your browser string helps, too. Microsoft users in Michigan using Internet Explorer 8 have different purchasing habits than Linux users in Dallas running Firefox, or Mac users in New York loading pages in Safari, or via an iPhone.

Firefox does have a separate extension that will help with Adobe Flash cookie blocking, called BetterPrivacy. If you're a Firefox devotee, you'll want to check it out.

For more information, it's worth your time to read more about this in Wired.

Friday, August 7, 2009

Overheard at Airport

From Greg Laden's blog, courtesy of Bruce Schneier:

"Here," dad to girl, "Get your ID out and have it with your ticket."
"Excuse me, sir," said the TSA officer, pointing to the young female, "She does not need to have her ID out, she's a minor."
Dad: "How do you know she's a minor if you don't look at her ID?"
.... (silence as everyone waits for answer)....
Dad again: "Kind of a hole in the system, isn't it?"
TSA Officer, voice lowered ... "There are a LOT of holes in the system, sir." ... walks away.
Young girl, "Good one, dad. Now tell her our name is LADEN and see what happens!"


Sunday, July 26, 2009

Firefox Updates to 3.0.12

Firefox has released a version update that closes five critical security issues and also addresses some minor bugs and flaws. If you haven't moved up to the latest release, now would be an excellent time.

Smarter yet would be to move to the 3.5 version, which improves JavaScript performance and adds some privacy tweaks. If you have to stay on the 3.0.x releases, make sure you move to 3.0.12 to lower your risk.

As always, running some of the security-related extensions and add-ons helps even more.


Friday, July 24, 2009

iPhone Encryption Easily Defeated

One of the digs against the use of an iPhone in a corporate environment is the lack of enterprise-level security on the device. With sensitive business and personal information contained within email and documents stored on the phone, it's imperative that there are effective, robust controls in place to keep the data from being breached.

Apple has been touting the encryption solution that's part of the new 3GS model as their answer to those who doubted an iPhone in the enterprise was ready for prime time. It's reported that Apple uses the 448-bit Blowfish encryption algorithm, which provides a measure of cryptographic protection. But does it really keep the bad guys out of your data?

Sadly, it doesn't appear to be very successful. Wired has a report that indicates data can be siphoned off of an encrypted iPhone in minutes using readily-available software, and a complete disk image can be created in less than an hour.

There seems to be a minor issue with the iPhone in that once data starts being extracted, the phone begins decrypting the data on its own. Wow.

This is particularly troubling in light of some recent legislation in Massachusetts and Nevada that requires personal information of state residents be encrypted on any device that is not within the confines of the corporate network. This includes Blackberry devices, smart phones, removable USB drives, and so on. Since it's difficult to discern the legal residence of the customer's data as it gets mixed and mashed with everyone else's data, corporations generally choose to protect all personal information in the same manner, regardless of the domicile.

As a security professional, I would never recommend using the iPhone on a corporate level until Apple matures their security configuration and control environment. It's up to each business to evaluate the level of risk they are willing to accept, and for some, use of the iPhone will fall within acceptable risk parameters. Sooner or later, however, a breach will occur - someone's information will be stolen or use inappropriately - and there will be statutory penalties in addition to the inevitable civil suit.

Apple has an uphill trek to achieve the same security posture as RIM with their series of Blackberry devices. Don't expect Cupertino to reach the peak anytime soon.



Wednesday, July 22, 2009

Teaching Verizon a Security Lesson

Verizon has a checkered history surrounding security of their customer's personal information, but being a huge telecommunications entity, what's a citizen to do?

If you're like the guy in this video, you find out the home address of the Verizon CEO, then go stand in front of his house with a bullhorn and demand his company do a better job.



h/t to BoingBoing




Monday, July 20, 2009

256 GB USB Drive

When I got my Packard Bell 386 computer than ran Windows 3.1, I was amazed at the hard drive space. It was 40 MB, as I recall, and when it started to fill up, I used disk compression software to double it to a spectacular 80 MB.

For most of you, that probably sounds like some oldster retelling a boring tale of walking six miles through the snow to get to school each day, carrying a hot baked potato in his pocket for warmth on the journey, then eating the potato at lunch to have enough energy for the walk home.

Kingston has released a USB drive that weighs in at a staggering 256 GB, more storage than existed on most home computers until the last several years. In the days of my PB 386, you would need the GDP of France to purchase 256 GB of memory. Merde!

This just begs the question - what the heck are we carrying around with us data-wise, and why is it imperative that we're able to lug around such massive amounts of 1s and 0s without giving any thought to securing that data and keeping it out of the wrong hands?

Via Dvice


Friday, July 17, 2009

Nmap 5.0 Released

First released in 1997, Nmap quickly became a go-to tool for network and security practitioners to perform security auditing functions, explore their networks to find anomolies and open ports, and so on.

The newest version, 5.0, has just been released, and it adds a couple of features that could either be extremely beneficial or curiously troubling, depending on who is using them, and why.

Ncat and Ndiff allow for the transfer or redirection of traffic (gasp!) , and the ability to compare and contrast patterns from previous scans. While the latter could be useful to see what has changed (especially if your traffic is generally the same and you suddenly notice peaks and valleys), the former could be somewhat dangerous if used in a malicious manner. Of course, you could say that about nearly all networking and security toolsets.

For more info and to grab a copy, head over to Insecure.org .

Image via Taonas at wikimedia.org


Tuesday, July 14, 2009

Microsoft Security Bulletin for July 2009

In their monthly patch release, Microsoft has included six lovely patches to be rolled out, addressing at least 9 open CVEs. There are a couple that you should get to right away.

MS09-028 deals with multiple vulnerabilities in DirectX, and since it's being actively exploited, you should deploy the fix ASAP.

MS09-032 is a cumulative killbit set for video ActiveX, but be warned that there are additional killbits outside of those included in this release that you'll need to deal with given recently reported exploits. Again, there are active exploits in the wild for this one, so don't dally, Sally.

Several others would be considered critical, which in this case means roll them out quickly after your normal QA processes have validated that they don't render anything inoperable.

For more info, check out the Microsoft Security Response Center .

Tuesday, July 7, 2009

MultiISO LiveDVD v1.0 – BackTrack, Knoppix & Ophcrack

If you're looking for a single Live DVD that runs some of our favorite tools, like BackTrack, Knoppix, and Ophcrack, perhaps this Darknet article on the availability of MultiISO LiveDVD is worthy of your time.

Comprised of a number of tools for pen testing, vulnerability assessment, network mapping and security recon, password cracking, and so on, MultiISO LiveDVD seems to be a nice collection of the following components.
  • Backtrack 3
  • Damn Small Linux (DSL) 4.2.5
  • GeeXboX 1.1
  • Damn Vulnerable Linux (Strychnine) 1.4 edition
  • Knoppix 5.1.1, MPentoo 2006.1
  • Ophcrack 1.2.2 (remastered to contain SSTIC04-5k [720MB] table sets)
  • Puppy Linux 3.01
  • Byzantine OS i586-20040404
Read more and find a link to the torrent here.

Thursday, June 25, 2009

Adobe Re-patches Shockwave, So Should You


Software maker Adobe (motto: security is hard) has announced that they've released a fix for a critical flaw in their Shockwave multimedia player. This flaw could allow remote exploitation of a vulnerable computer.

Adobe claims that the flaw had been fixed in an earlier version of the product, and recommends uninstalling whatever Shockwave version is currently being used, rebooting the machine, then installing the latest version.
"This issue was previously resolved in Shockwave Player 11.0.0.465; the Shockwave Player 11.5.0.600 update resolves a backwards compatibility mode variation of the issue with Shockwave Player 10 content," the company stated.
Adobe is currently unaware of any exploits for this particular vulnerability.

Security Update Available for Shockwave Player