Posted on June 30th, 2009 by Aviram
Filed under: Web, Commentary, Law, Phishing | No Comments »
A few years ago, the personal blog of the Iran president Ahmadinejad included a special piece of malware code that would only be displayed for Israeli IP addresses, attempting to infect Israeli machines visiting the site while preserving a seemingly harmless appearance for any western visitor that is not an Israeli. I thought that was quite a clever attack at the time.
But now the Iraqis are flexing their cyber-muscles too. According to a Hebrew article in law.co.il (this is not yet available on their English site, but may be soon), several domain names of Israeli government entities and large Israeli institutions have been registered by users outside Israel, some users having addresses in Iraq.
These domains use names with Hebrew characters, which are now available under the IDN. However, the method of typing Hebrew domain names is not in wide use and companies still prefer the English domains with the .il or .com suffix, which is why those Hebrew domains were available for purchase. Some of the domain names that were purchased include the Mossad, the Shabak (the “Shin Bet”), the IDF, Israel Police, Knesset, and several major banks.
Since the domain name is in Hebrew and contains the full name of the company or institution, it is incredibly useful for phishing attacks. law.co.il traced many of the domain names, particularly those of major ministries and public service names to a company called “ICU Agency” with a registered address in Baghdad. I’m sure there are other clever uses for such domains in war time that exceed simple phishing. With the speed in which news travel on the Internet these days, it shouldn’t be difficult to do some psychological warefare if you own “credible” domain names.
Posted on June 25th, 2009 by Aviram
Filed under: Web, Sec Tools | 3 Comments »
I saw a demo of Green SQL today, and during the demo Yuli showed me a cute sql-injection method for mysql that I’ve never seen before.
This will evade some IDS’s and is also a good reply for the web development if they tell you filtering the words “OR” and “AND” is enough as a generic SQL-injection protection.
It’s not “new”, but it was new to me. The idea is to place two equal signs inside the query so that the query becomes:
SELECT * FROM users WHERE column=’b’=’c’
More information and a very detailed explanation here. It seems to be specific to mysql.
Posted on June 16th, 2009 by p1
Filed under: Web, Commentary, Privacy, Culture, OT | 1 Comment »
Over the past few days, both the Vancouver Sun and the Ottawa Citizen have published (basically the same) story about “Toronto-based Ancestry.ca.” From the articles, this appears to be related to such public institutions as the national archive and Library and Archives Canada. And the price is right: “A two-week free trial period that began June 10 allows users to search for and download documents at no charge.”
I tried it out. Giving minimal information about him brought up over 6,000 hits, the second of which was my grandparent’s marriage certificate. Pretty good.
Unfortunately, that is not the whole story. If you want to actually see anything that the search finds, you have to register. And, if you pay attention, and actually read the “Terms and Conditions” (and look at the full screen, not the portion that shows when the box first pops up), you find that you are registering with “an Internet service (the “Service”) owned and operated by The Generations Network, Inc, an American company incorporated in Delaware, USA, and whose registered address is 360 W 4800 N Provo, UT 84604, USA.” In order to register you have to provide a credit card. After 14 days (and it isn’t clear whether that is 14 days after June 10, or 14 days after you register) “[i]f you wish to terminate your subscription you must notify us at least two (2) days before the Renewal Date by calling (800) 958-9073 Member service is available from Monday to Friday 7:00 am to 4:00 pm MST, or by sending an email to cancel@ancestry.ca providing the following information: Given name and surname, Username, Subscription type (UK/Ireland collection, etc.), Email address used when subscribing, Phone number including country code, Country. If you fail to respond to the notice, your subscription will be automatically renewed,” and, of course, your credit card will be charged.
So, read carefully, people. Are you dealing with a public institution, or a private company? Are you dealing with a company in your country, or another? And, is your “free trial” an “opt-out” contract for the company to start billing your credit card?
Posted on June 15th, 2009 by Rafel Ivgi
Filed under: Commentary | 6 Comments »
These days, security is going digital.
From live and automatic event log analysis up to personal “on-key” tokens and remotely controlled security cameras.
These technologies should be used carefully. For example if the token generates 6 digits and there is no password complexity enforcement, users can set their password to “1″ and then we’ll get a 7 character length password. If the data from the log will not be filtered and will be in html format, it may execute code. Even worse, if it is viewed at the command line console, it may execute code using the console color control characters.
When talking about security cameras, a security flaw in the camera’s simple application server may cause the entire video stream to be accessible to an intruder.
While consulting to a big financial customer, I discovered the security cameras installed are easily accessible to anyone thanks to a very simple logical flaw. Not to mention default user accounts, empty password sets, the ability to brute force, directory traversal and some classic authorization bypass vulnerabilities.
Most of the security cameras in my country are bought from Korea, some of the software is written by the vendor and some by the distributer. Both of them should pay much more attention to security so we won’t have the same classic vulnerabilities over and over again.
Attached are a few screen captures:
another white night at work
Clothing Shop
Coffee Shop
Eyes on the ball!!!
How’s that shirt?”
Anyone knows a Safe-Cracker?!
Posted on June 11th, 2009 by jbrown
Filed under: Commentary, Full Disclosure, Culture, Ask the Expert, Corporate Security | No Comments »
0x01 Introduction
0x02 Phrack Prophile on The PaX Team
0x03 Phrack World News
0x04 Abusing the Objective C runtime
0x05 Backdooring Juniper Firewalls
0x06 Exploiting DLmalloc frees in 2009
0x07 Persistent BIOS infection
0x08 Exploiting UMA : FreeBSD kernel heap exploits
0x09 Exploiting TCP Persist Timer Infiniteness
0x0A Malloc Des-Maleficarum
0x0B A Real SMM Rootkit
0x0C Alphanumeric RISC ARM Shellcode
0x0D Power cell buffer overflow
0x0E Binary Mangling with Radare
0x0F Linux Kernel Heap Tempering Detection
0x10 Developing MacOSX Rootkits
0x11 How close are they of hacking your brain ?
You can check it out here.
Now we have something to keep us busy while the net neutrality debates are going on…
Posted on June 10th, 2009 by xyberpix
Filed under: Commentary, Full Disclosure, Corporate Security | 3 Comments »
Following on from the previous 2 posts that have been put up here and here, after seeing the post about the T-Mobile hack on Full-Disclosure, and then T-Mobile admitting that it has happened, really got me thinking.
To the best of my knowledge this will be the third high profile security breach at T-Mobile in the last 4 years, the first one being Paris Hilton’s SideKick getting hacked. Now the SideKick episode was more down to user error that T-Mobile’s fault, but this one could have been prevented by using strong password complexity rules. Which I thought was something that most major organizations would have already picked up on by now, especially the big corporates. Password complexity is not complicated to implement, and it does tend to prevent these little things like brand damage from occurring.
Speaking of brand damage, now that T-Mobile have been hit a second time, where does this leave them with Companies such as Google and Apple?
T-Mobile is currently doing really well with the addition of the Google Android and Apple iPhone handsets to its portfolio, but do Google and Apple really need this sort of publicity? These are the types of incidents that make companies think twice about their partnerships.
I’m completely aware that these type of incidents happen all the time, but most people expect that mobile operators would have stronger security measures in place.
Couple this with the fact that at present T-Mobile is gearing up for a class action law suite due to charging customers termination costs, this is another company that has me wondering how long….
Posted on June 9th, 2009 by Aviram
Filed under: Web, Commentary, Full Disclosure, Culture, Corporate Security | 3 Comments »
The T-mobile data breach that jbrown wrote about has been confirmed by T-Mobile.
I guess not everything you read on Full Disclosure is fake after all…
Posted on June 6th, 2009 by jbrown
Filed under: Commentary, Full Disclosure, Law, Culture, Corporate Security, Insider Threat, Hacked | 5 Comments »

From the looks of it, T-Mobile has been hacked and the goods stolen.
They also seem to love running HP-UX.
Posted on June 6th, 2009 by Aviram
Filed under: Linux, Commentary, malware | No Comments »
The swine flu craze in Asia is almost becoming ridiculous. Flying into Beijing a doctor came on board to check everyone’s temperature before they would let us out of the plane. Before passing immigration we were checked again and filled in forms to prove we are all in top health.
Ironically, on the inbound flight to Beijing I caught the flu from the Chinese girl sitting next to me (I’m talking about the regular flu. No need to call an emergency medical team on me). I spent the week gobbling Chinese medicine herbs which did a great job in preventing me from crashing sick. But the problem is that I am about to fly out back to San Francisco through Tokyo, and I’m trying to think how to convince the Narita officials that my germs are pure and genuine Asian bodies and are were not carried with me from any American pigs (political innuendos not intended).
It seems I’m also a carrier of something else, and again it’s not my fault. All I did was connect my USB stick to a computer on the business center in my Beijing hotel. I just wanted to print a document but didn’t bother locking the stick to ‘read only’. Apparently that was enough to have a Trojan infect the USB stick from the malware infested public computer.
Not that it would matter, really, since my machine runs Ubuntu. In fact, I wouldn’t have noticed it unless someone that borrowed the USB stick from me showed me the Virus warning that popped up as they plugged the stick into their Windows machine. I could have infected dozens of machines by the time I found out about it – all those poor Windows machine, Trojaned just for borrowing my USB stick; I really don’t need that on my conscience.
Once I know the Trojan is there, the cleanup is easy, I will ‘rm’ the files and the stick will be healthy again and stop be a carrier for defenseless Windows machines. Now if only it was that easy to recover from this damn flu.
Posted on June 3rd, 2009 by Juha-Matti
Filed under: Web, Commentary, Culture, Physical Security, Corporate Security | 2 Comments »
Open Security Foundation’s DataLossDB has announced the winners of oldest incident contest.
One of the oldest documented issue is TRW incident from 1984, when the database of credit history of 90 million American citizen was breached.
Link here.
Update: The winner is an incident from August 1953, when SSN’s were lost.