|
Planet Security - http://planetsecurity.bacarospo.net/ Tue, 07 Oct 2008 18:02:45 +0200 This white paper discusses how Amanda compares to other backup products. It will help you understand some key Amanda differences and how to evaluate and transition to Amanda.
Tue, 07 Oct 2008 17:00:49 +0200 While political polls may show Sens. Barack Obama and John McCain locked in a close race for the White House, junk e-mail purveyors have a clear favorite. According to research by Secure Computing, spammers are seven times as likely to invoke Obama’s name in a subject line in a bid to trick [...]
Tue, 07 Oct 2008 16:49:22 +0200 I think it’s a cyclical thing: start your career as a corporate slave, break free of the shackles to go out on your own, a few years later go back to the corporate job for a steady paycheck. Lather, Rinse, Repeat. It’s a pretty standard formula, base at least in part on the ‘grass is always greener’ syndrome. Well, this week’s victim of corporate re-assimilation is none other than Security Mike, aka Mike Rothman. Mike has abandoned his role as industry curmudgeon and taken on the role of SVP of Strategy and Chief Marketing Officer at eIQnetworks. Mike will continue to blog some, but considering he’s now one of the bad guys (aka ‘vendor’), his blogging will lack some of the objectivity he’d so carefully cultivated over the last couple of years. And since a large part of his work will be in the dreaded and vilified ‘marketing’ arena, you can guarantee that a lot of his writing will be around eIQ and all the wonderful things they can do for your network. Not that Mike will totally lose touch with reality, but he’ll probably have to don the peculiar rose-tinted glasses that allow marketers to only see the good their company can do. Good luck with the new gig, Mike. I hope you’re able to keep some of your objectivity until the grass on the consulting side of the fence becomes green again. Like maybe after the economy stabilizes again in a couple of years. Tue, 07 Oct 2008 16:48:25 +0200
October 7, 2008 - Volume 3, #80
Good Morning:
Incite 4U
Please be patient as I evolve the format of TDI to something
that will work, given I can spend a lot less time on it during the
week. Having a day job kind of puts a crimp on these fun, little
hobbies. Today I'm going to try a hybrid format. Let me know if you
think it sucks.
Tue, 07 Oct 2008 16:45:02 +0200 Thanks to Ed and his fellow bloggers for welcoming me to the blog. I'm thrilled to have this opportunity, because as a law professor who writes about software as a regulator of behavior (most often through the substantive lenses of information privacy, computer crime, and criminal procedure), I often need to vet my theories and test my technical understanding with computer scientists and other techies, and this will be a great place to do it. This past summer, I wrote an article (available for download online) about ISP surveillance, arguing that recent moves by NebuAd/Charter, Phorm, AT&T, and Comcast augur a coming wave of unprecedented, invasive deep-packet inspection. I won't reargue the entire paper here (the thesis is no doubt much less surprising to the average Freedom to Tinker reader than to the average lawyer) but you can read two bloggy summaries I wrote here and here or listen to a summary I gave in a radio interview. (For summaries by others, see [1] [2] [3] [4]). Two weeks ago, Verizon and AT&T told Congress that they would monitor for marketing purposes only users who had opted in. According to Verizon VP Tom Tauke, "[B]efore a company captures certain Internet-usage data for targeted or customized advertising purposes, it should obtain meaningful, affirmative consent from consumers." I applaud this announcement, but I'm curious how the ISPs will implement this promise. It seems like there are two architectural puzzles here: how does the user convey consent, and how does the provider distinguish between the packets of consenting and nonconsenting users? For an ISP, neither step is nearly as straightforward as it is for a web provider like Google, which can simply set and check cookies. For the first piece, I suppose a user can click a check box on a web-based form or respond to an e-mail, letting the ISP know he would like to opt in. These solutions seem clumsy, however, and ISPs probably want a system that is as seamless and easy to use as possible, to maximize the number of people opting in. Once ISPs have a "white list" of users who have opted in, how do they turn this into on-the-fly discretionary packet sniffing? Do they map white-listed users to IP addresses and add these to a filter, or is there a risk that things will get out of sync during dhcp lease renewals? Can they use cookies, perhaps redirecting every http session to an ISP-run web server first using 301 http status codes? (This seems to be the way Phorm implements opt-out, according to Richard Clayton's illuminating analysis.) Do any of these solutions scale for an ISP with hundreds of thousands of users? And are things any easier if the ISP adopts an opt-out system instead? Tue, 07 Oct 2008 16:44:39 +0200 Host-based IDS can be a powerful tool for identifying potential incidents. There are some major advantages in host-
based IDS over network-based IDS such as target-specific knowledge, identifying file modifications, and identifying rootkits that use encrypted network communication channels. However, the additional features usually result in additional maintenance and alerts. How do you use host-based IDS to identify suspicious activity? Is there any organizations that rely solely on host-based IDS while ignoring network-based IDS? Since host-based IDS should be able to provide more concrete evidence that a host has been compromised - do you sometimes move straight to a forensic evaluation of the host upon receiving alerts from a host-based IDS? Is anyone using honeypots (or known-vulnerable hosts) anymore as an input to their host-based IDS systems for identifying targetted attacks? Please send us your thoughts and comments via our contact page. We will update the diary as new submissions come in. Tue, 07 Oct 2008 16:02:29 +0200
Gadi Evron, (founder of the Zero Day Emergency Response Team) via his blog, comments (philosophically) on the recent shutdown of Atrivo, cybercriminals and their ilk. His post is today’s MustRead, and is highly recommended. Related Posts Tue, 07 Oct 2008 15:51:00 +0200 CA announces its acquisition of identity management company IDFocus, in a move to bolster its security offerings.
Tue, 07 Oct 2008 15:49:38 +0200 VMWare issues updates for all its virtualisation products - but only for 64-bit editions of Windows and FreeBSD
Tue, 07 Oct 2008 15:44:42 +0200 Justin reports that Cogent is having peering problems, which seem to be confirmed here: http://www.internetpulse.net/. We will keep an eye on it and update this story as the day progresses.
Tue, 07 Oct 2008 15:32:33 +0200 Charlie Rose interviews Warren Buffett:
Its effectively the job of leadership to know when to take the punch bowl away and to have the credibility to do this. This is also the risk-reward balance that infosec must try to strike, part of the answer is differentiating risk and uncertainty. As our current financial situation shows, its a hard thing to pull off
And this is why its hard to pull off. There is a lot of human emotion and envy (*). I think the point Buffett raises about innovators, imitators and idiots is a useful one for infosec. We see all kinds of new projects and technologies that have risks and rewards associated with them, its helpful to categorize these under innovation (high risk but possible game changer), imitators (so called best practices), and idiots (sheep mode - blind risk acceptance). We can get some traction here to use these concepts to understand what to do when assessing say the architectural and oeprational risk of a system. Finally, we should always spend some time to consider infosec decisions in a broader long term economic context and this is also true of our current financial crisis
Again, we want to look at risk events in a broader, long term context. In Buffett's words its - "be fearful when others are greedy and greedy when others are fearful." As the world panics and Jim Cramer is melting down on TV, Buffett is quietly writing checks with both hands, buying $3B of GE, $5B of Goldman, $6.5 of Wrigley/Mars and so on. Uncertainty is one thing, it could be 6 months it could be 5 years until this thing turns around, but risk is another - you hedge your risk with price and long term advantages, i.e. moats. People will still eat candy in a bad economy. * Buffett's partner Charlie Munger calls envy the stupidest of the seven deadly sins, because only you feel bad, there is an upside to all the others. He said you can pay someone on Wall St $2 million a year and they will be perfectly happy until they find out someone across the hall is making $2.1 million and then they will be miserable. Which is an insane way tolive. Tue, 07 Oct 2008 15:29:01 +0200 Critical update resolves heap overflow vulnerabilities in eDirectory 8.7 on Windows and Linux - with bizarrely different download sizes
Tue, 07 Oct 2008 14:48:17 +0200 Want to ride the subway for free without having to jump the turnstiles? Well, as of Monday, you'll be able to do that by making a fake transit card. A scientific paper detailing the security flaws in the Mifare Classic wireless smart card chip used in transit systems around the world is being published by the Radboud University Nijmegen. And a researcher at Humboldt University in Berlin has published a full implementation of the algorithm (PDF). "Combining these two pieces of information, attacks can now be implemented by anyone," RFID researcher Karsten Nohl told CNET News. "All it takes is a $100 (card) reader and a little software." Armed with the information in the papers, someone could steal the secret key from a Mifare Classic-based transit card and create a clone of it. As seen in a demonstration, data was collected wirelessly by merely brushing a card reader past someone carrying a card. The data was then used to create a fresh transit card that permitted free access to the London subway. Subway systems in Amsterdam, Boston, Bangkok and Delhi, among other cities, are also susceptible, as are building access control systems in Europe. "That's just the tip of the iceberg," said 3ric Johanson, a Seattle-based security consultant. "It's my estimation that approximately 3.5 billion cards have been issued using the Mifare Classic protocol, all subject to financial fraud. There are at least 60 or so major citywide RFID implementations that rely on Mifare Classic." Nohl, who worked with others to break the Mifare crypto last year and received a Ph.D. in computer security from the University of Virginia, suspects that "hobby hackers who ride the metro everyday and are curious about this technology" will be the first to exploit the vulnerability, "more for fun than profit." For the less technologically savvy among us, there could soon be mass produced devices that make it easy to forge Mifare Classic cards, Johanson said. Johanson, an expert in RFID technology, said he has reached out to transit systems to offer help improving their security, but received mixed responses. There are options for transit authorities who don't want to replace their entire systems. For instance, they can use intrusion detection-type systems that register when a particular card has had a change in value or been cloned, according to Johanson. "I'm highly dubious about a lot of these claims because it's hard to do it right," he said of such measures. NXP, the company that developed the Mifare Classic chip, could not be reached for comment Monday. The company sued to block publication of the Dutch University paper but a judge ruled in July that the paper could be published. The Massachusetts Bay Transit Authority (MBTA) took legal action in August to prevent three MIT students from presenting their research on how to "hack" the Boston subway system at the Defcon hacker confab in Las Vegas. A judge later lifted the gag order in that case. Representatives from the MBTA could not be reached for comment. Security systems like the Mifare Classic that are not peer reviewed are not as trustworthy as systems that can be openly analyzed by researchers looking for flaws, Johanson and Nohl said. "Developing your own proprietary security mechanisms and not getting public scrutiny on it does not work," Nohl said See original article and other great stories at: Tue, 07 Oct 2008 14:33:01 +0200 As a security pro, it’s important to periodically stop, take a break, and refuel your brain. Once per month, Core Security Technologies does the same thing and invites industry thought leaders to share their insights through educational webcasts offering security testing tips, tricks and strategies.
Tue, 07 Oct 2008 14:20:45 +0200 You've got me all wrongUK victims of identity fraud are being urged to use the Data Protection Act as a tool to restore their credit rating.… Tue, 07 Oct 2008 14:13:30 +0200 SANTA BARBARA, CALIF. -- Wireless technologies like WiMAX and LTE are supposed to bring us the speed of Wi-Fi (or better) with something approaching the range of existing wireless broadband, which could replace the need for Wi-Fi hotspots. Now, Wi-Fi back at the office is under threat, too: from light bulbs!
Tue, 07 Oct 2008 14:02:30 +0200 My guest for this week’s Innovators podcast is Howard Bloom. He’s written several books, one of which — Global Brain: The Evolution of Mass Mind from the Big Bang to the 21st Century — is the main topic of our conversation. There’s no easy way to summarize this show, but here are some notes that I took while reading the book, and used to guide the discussion:
If these themes resonate, you’ll love hearing Howard elaborate them. ![]() Tue, 07 Oct 2008 13:51:00 +0200 From Canada to Turkey: CeBIT Eurasia in Istanbul
Tue, 07 Oct 2008 13:48:53 +0200 Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place. Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf. If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections. Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a paper published this year in International Security that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers: Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved. Abrahms has an alternative model to explain all this: People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States. The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida. For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist. All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion. This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups. We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge. This essay previously appeared on Wired.com. Tue, 07 Oct 2008 13:32:37 +0200 How does an emergency call to 9-1-1 or 1-1-2 (or whatever your local emergency number may be) work in a world of voice-over-IP? It’s not a topic we cover hardly at all here on this blog, yet it’s definitely one of the security and social/cultural aspects of our migration to IP that we definitely have to get right. If we as an industry don’t, people can die. (Or the migration to VoIP will be significantly delayed.) To that end, a number of emergency services experts are meeting to discuss ongoing work on IP-based emergency services in Vienna, Austria on 21st to 23rd October 2008. The first workshop day is focusing on tutorials to help those interested in the classical 1-1-2 (or 9-1-1) emergency call to get up-to-speed with architectures and standards developed for next generation emergency calling. During the second day various recent activities of standardization organizations around the world will be presented. The third workshop day is dedicated to early warning standardization efforts and the outlook to future emergency services activities. Participation from those working in standardization organizations as well as persons with interest into the subject is highly appreciated. The event is open to the public and anyone may attend. More information about the workshop can be found behind the following link: This page also points to previous workshops that took place in New York, Washington, Brussels and Atlanta. (Thanks to Hannes Tschofenig for providing the majority of this text.) Tue, 07 Oct 2008 12:48:01 +0200 Zlob Trojan Distributing site: Tue, 07 Oct 2008 12:27:36 +0200 Fraud reporting recommendations ignoredMembers of the House of Lords Science and Technology Committee will this Friday call on ministers to do more to battle security threats online.… Tue, 07 Oct 2008 11:29:38 +0200 LinuxSecurity.com: Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.21 (Version 3.0, Release 21). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy. In distribution since 2001, EnGarde Secure Community was one of the very first security platforms developed entirely from open source, and has been engineered from the ground-up to provide users and organizations with complete, secure Web functionality, DNS, database, e-mail security and even e-commerce.
Tue, 07 Oct 2008 11:06:05 +0200 REMEBER WHEN WE said AMD was going to split into a fab company and design company? Word has it that it will be announced in a few hours, likely before the opening bell tomorrow.
The story is basically what we first told you about in March, Arab, likely Abu Dhabi money will finance the split. The overview is remarkably simple, there will be two companies, basically a foundry and a design house. The deal is greased by billions of dollars, the number we hear is more than one, less than ten, all from bartered SUV go juice.
The OOo Impress version is quite simple, but the deal is likely shatteringly complex, which explains the year plus gestation, and why it took six months after we heard it was basically done. There are a lot of bits to tie up, and a lot of moneyed and politically connected asses to kiss. Better phrase that as egos to stroke while placating fears.
Tue, 07 Oct 2008 11:05:13 +0200 There have been some indications lately that Apple is taking a less rigorous approach to secrecy. Once the company went to great lengths to conceal its future plans; in recent months there has been a marked increase in the number of leaks that have since proved genuine - take the MacBook Air, Snow Leopard and the newest iPod nanos for instance.
This has not escaped the notice of Nicholas Ciarelli, who as Nick dePlume was the source of many an inside story on Apple as author of the now defunct Think Secret website and the subject of an Apple lawsuit after he leaked details of two new products that proved to be iWork and the Mac mini. At the same time Apple was suing two other websites, all in an attempt to find the source of the leaks and to prevent the sites from publishing “trade secrets”.
But as Ciarelli points out for The Daily Beast, Apple’s litigation was futile. Mac “rumours” have moved from a few small sites to mainstream tech media and beyond.
Tue, 07 Oct 2008 11:03:48 +0200 Online retailer EBay Inc., which is trying to reverse years of slowing growth in its auction business amid rising competition and a spreading financial crisis, said Monday that it would cut 10% of its global workforce even as it spends $1.3 billion to buy three Web businesses.
Even after announcing the largest reduction in its 13-year history, which EBay said would save $150 million in annual operating costs, the San Jose company saw its shares tumble by as much as 12% to their lowest level in more than five years. They recovered to close at $17.89, down 5.5%.
Investors are concerned that EBay's bread and butter, online auctions, is showing increasing vulnerability to slowing consumer spending, the slumping U.S. housing market and high fuel prices.
Tue, 07 Oct 2008 10:45:13 +0200 LinuxSecurity.com: The Tokeneer project was commissioned by the NSA from Praxis High Integrity Systems as a demonstrator of high-assurance software engineering. Developed using Praxis' Correctness by Construction (CbyC) methodology it uses the SPARK Ada language and AdaCore's GNAT Pro environment. The project has demonstrated how to meet or exceed Evaluation Assurance Level (EAL) 5 in the Common Criteria thus demonstrating a path towards the highest levels of security assurance. Have you heard the NSA has released their security research project called Tokeneer as open source? I found interesting about the project is that it uses the SPARK Ada programming language. What do you think about this project?
Tue, 07 Oct 2008 10:44:00 +0200 Together with Jose Nazario, I published a paper about fast-flux botnet observations at the 3rd International Conference on Malicious and Unwanted Software (Malware 2008). The paper contains information about different aspects of fast-flux service networks collected with the help of ATLAS, Arbor's Active Threat Level Analysis System. Since several months, ATLAS has the capability to monitor fast-flux service networks and a live view of the collected information is available at http://atlas.arbor.net/summary/fastflux.
Abstract: While botnets themselves provide a rich platform for financial gain for the botnet master, the use of the infected hosts as webservers can provide an additional botnet use. Botnet herders often use fast-flux DNS techniques to host unwanted or illegal content within a botnet. These techniques change the mapping of the domain name to different bots within the botnet with constant shifting, while the bots simply relay content back to a central server. This can give the attackers additional stepping stones to thwart takedown and can obscure their true origins. Evidence suggests that more attackers are adopting fast-flux techniques, but very little data has been gathered to discover what these botnets are being used for. To address this gap in understanding, we have been mining live traffic to discover new fast-flux domains and then tracking those botnets with active measurements for several months. We have identified over 900 fast-flux domain names from early to mid 2008 and monitored their use across the Internet to discern fast-flux botnet behaviors. We found that the active lifetimes of fast-flux botnets vary from less than one day to months, domains that are used in fast-flux operations are often registered but dormant for months prior to activation, that these botnets are associated with a broad range of online fraud and crime including pharmacy sites, phishing and malware distribution, and that we can identify distinct botnets across multiple domain names. We support our findings through an in-depth examination of an Internet-scale data continuously collected for hundreds of domain names over several months. The full paper is now available. Unfortunately I can not attend MALWARE'08 which takes place today and tomorrow, but I hope everyone has a good time at the conference! Tue, 07 Oct 2008 10:37:59 +0200 THE MAC BLOGOSPHERE is all a flutter with rumours that a new Macbook could soon be on its way, complete with an Nvidia graphics chipset.
A cryptic promo pic on Nvidia’s site and whispers that certain NV employees have actually seen some is sending fanboys into a frenzy. The chipset in question seems to be the MCP7A-U, integrated into Mac’s GPU for the MacBook and possibly even the MacBook Air.
Nvidia declined to comment on the matter. If the rumours are true, however, it could be less about Apple "embracing gaming" and more about not having to use a CPU to decode HD video anymore, being able to transcode on the IGP instead.
Tue, 07 Oct 2008 10:33:24 +0200 AhnLab(CEO Hongsun Kim www.ahnlab.com), a global integrated security service provider, announced that the first 'Hacker’s Dream (Hacker's Dream) 2008,’ the first international reverse engineering contest for diverse information security technologies in Korea, for 15 days from October 1.
Being one of the biggest events of 'POC (Power of Community) 2008,' which is an international hacking/security conference, 'Hacker’s Dream 2008' is characterized by the competition in comprehensive abilities, such as analysis of malicious codes like viruses and Spyware, reversing, network packet analysis and analysis of malicious scripts, unlike existing hacking contests characterized by attacks and defenses. AhnLab formed the organizing committee consisting of experts in the aforementioned areas, who will present problems and serve as judges in the contest.
In particular, 'Hacker’s Dream 2008' is characterized by the fact that the participating information security experts compete with one another on the basis of the pure hackers’ spirit, and more emphasis is placed on honor than on material compensation.
Tue, 07 Oct 2008 10:03:16 +0200 Keep a close eye on your laptop, folks; if you're not careful it may become one of the 12,000 laptops a Ponemon Institute and Dell Computer study shows get stolen each week at U.S. airports. Most laptops go missing at security checkpoints or at the departure gates, the places where you're most likely to be distracted. Only 30 percent of travelers are ever able to recover their laptops. What's worse, nearly half of the people in the study say their laptops contain customer data or confidential business information. Translation: we are all affected by laptop thievery.
Unfortunately, even if you guard your laptop with your life, there's no sure-fire way to prevent someone from snatching your data or laptop. Thankfully, there are software and hardware solutions on the market to make your laptop more secure. Here are 10 ways, from notebook locks to privacy screens to security alarms, to safeguard your laptop.
Tue, 07 Oct 2008 10:00:56 +0200 Researchers at Trend Micro, an online security firm, has cautioned about a spam mail which declares World War III. Also, the mail contains a link to fake site appearing like the news agency CNN.
Trend Micro claims that the video attached with the mail cannot be played. For playing the video, the user clicks on the link and a message pops up asking to install the ActiveX Object. Also, the ActiveX Object is harmful malware, which the Trend Micro identified as TSPY_BANCOS.JN. TSPY_BANCOS.JN. It matches to the BANCOS variants, an information stealer that monitors the browser of the attacked computer.
The security firm warns against clicking on the link. If the user clicks on the link, he or she starts installing the banking Trojan on to the system. Trend Micro said that the Trojan looks for the moment when the user access the bank related sites. When he uses access the site, it shows the login page of the online bank and steals the user's private details.
Tue, 07 Oct 2008 10:00:01 +0200 How to implement a VOIP solution whilst abiding by a security framework, and the challenges that we can expect when implementing VOIP.
Tue, 07 Oct 2008 09:56:42 +0200 The guys at Laptop Mag got to spend some time with MSI's US sales boss Andy Tung, who gave them the lowdown on the hot little Wind netbook, past, present and future, including customers' mass rejection of the Linux version and the real reason for Windows continued success (people are used to it).
First, there will be a Wind 2, officially called the U120 (the current one is called the U100). It will sell alongside the popular, hackable netbook and come in at under $600. The Wind 2 will be a complete redesign -- new case, new hard drive and SSD options and a 3.5G mobile card inside. Ostensibly aimed at the business market, we can see this being a huge modder's hit (just put Broadcom compatible Wi-Fi inside for us OS X hackers, please, MSI). The Wind 2 will ship by the end of the year.
The next big news is that MSI have worked out a deal with a "a major U.S. retailer". Tung is keeping quiet on the details, but the official announcement should come this week. Guesses: Best Buy. A Wal Mart Wind?
Tue, 07 Oct 2008 09:51:02 +0200 Want to ride the subway for free without having to jump the turnstiles? Well, as of Monday, you'll be able to do that by making a fake transit card.
A scientific paper detailing the security flaws in the Mifare Classic wireless smart card chip used in transit systems around the world is being published by the Radboud University Nijmegen. And a researcher at Humboldt University in Berlin has published a full implementation of the algorithm (PDF). "Combining these two pieces of information, attacks can now be implemented by anyone," RFID researcher Karsten Nohl told CNET News. "All it takes is a $100 (card) reader and a little software."
Armed with the information in the papers, someone could steal the secret key from a Mifare Classic-based transit card and create a clone of it. As seen in a demonstration, data was collected wirelessly by merely brushing a card reader past someone carrying a card. The data was then used to create a fresh transit card that permitted free access to the London subway.
Tue, 07 Oct 2008 09:50:07 +0200 A global e-business and security certification organisation is warning that the many commercial applications being produced across the globe are creating new opportunities for malicious attacks on commercial and government institutions.
The International Council of E-Commerce Consultants (EC-Council) says that each day new and stronger attacks are being launched. To coordinate protection and defence against this cyber crime epidemic, the EC-Council says it will host an inaugural roundtable in Kuala Lumpur called Asia Pacific (APAC) Roundtable Forum (EC|RF), which will be co-chaired by Dr Lech J Janczewski, an associate professor of the University of Auckland and chairman of the New Zealand Information Security Forum.
The EC-Council is a member-based organisation that certifies individuals in various e-business and security skills. It is the owner and developer of Certified Ethical Hacker (C|EH), Computer Hacking Forensics Investigator (C|HFI) and EC-Council Certified Security Analyst (E|CSA)/Licence Penetration Tester (L|PT) programmes, which are offered in more than 60 countries.
Tue, 07 Oct 2008 09:49:17 +0200 Users should be on guard for spam touting the guilty verdict of former professional football star O.J. Simpson, a security company warned today.
"Anytime there's a big news story, spammers latch on to it to get people to click on a link and download their malware," said Sam Masiello, vice president of information security at MX Logic Inc.
Although MX Logic has not yet spotted any Simpson-related spam, Masiello said that company researchers have found evidence of an impending campaign. "We've seen poisoned search results on [Microsoft Corp.'s ] Live Search that lead to some Live Spaces hosting fake video codecs," said Masiello. The tactic, dubbed "search engine poisoning," is frequently used alongside malware spam.
Tue, 07 Oct 2008 09:46:41 +0200 Most U.S hotels are vulnerable to malicious attacks and are "ill prepared" to protect their guests from internet security problems, claims a study published by Cornell University.
The study, “Hotel Network Security: A Study of Computer Networks in U.S. Hotels” examined the security of 147 hotels through surveys, interviews and on-site testing. “Many hotels have flaws in their network topology that allow for exploitation by malicious users, thereby resulting in the loss of privacy for guests,” the study says.
One of the study authors, Josh Ogle, a Cornell University graduate and founder of IT services company TriVesta, performed on-site testing at 46 hotels in Virginia, North Carolina, Texas, Maryland, Tennessee and Pennsylvania - making sure to hit both tourist and business travel destinations.
Tue, 07 Oct 2008 09:40:26 +0200 The US Federal Bureau of Investigations (FBI) has gone on the hunt for two Europe-based hackers who have made several attacks against online retailers, it has emerged.
According to the BBC, Lee Graham Walker from the UK and Axel Gembe from Germany are being investigated in connection with hacks perpetrated on a website selling satellite equipment in 2003.
The men are accused to denial of service attacks, which overloaded servers with traffic and resulted in service outages on multiple online retail sites – acts which strengthen the case for effective website monitoring software to respond to such events. According to the FBI, the men are wanted for "one count of conspiracy and one count of intentionally damaging a computer system". If convicted these men could expect to face up to 15 years in prison.
Tue, 07 Oct 2008 09:38:28 +0200 Hackers may have hit the Australian Telecommunications User Group (ATUG) Web site, according to Google which has placed security threat warnings across all pages displayed in searches.
The flag — which reads “this site may harm your computer” — underscores all ATUG Web pages and documents generated in Google searches. Google's badware security warning page advises users to avoid the site. ATUG was unaware of the label when contacted by Computerworld magazine this morning.
The blacklists are produced by an alliance of online consumer protection groups, telcos and security vendors including AOL, VeriSign and Google, and stored in a clearinghouse maintained by StopBadware.org, a security watchdog used by Google to identify and evaluate malicious Web sites.
Tue, 07 Oct 2008 09:16:30 +0200 They don’t give out a video blog on Kremlin.ru just to anybody. Russian President Dmitry Medvedev started an official video blog, addressing Russians regarding his upcoming trip to an economic forum in France. The video is Flash-encoded, supports embeds, but is also downloadable as Windows Media Video file. A few more things about Medvedev’s office:
attached file: type: video/x-ms-wmv size: 4.65 MB here Tue, 07 Oct 2008 09:15:59 +0200 ![]() Hi folks. As you may have already noticed, posting to the blog was rather light yesterday, due my feeling rather poorly. I'm hoping that I'll feel better tomorrow, but as it stands right now, I figure it might be a repeat of today. I'll post when I can, but in the meantime, apologies for the scarcity of posts to the blog. Cheers, - ferg Tue, 07 Oct 2008 06:30:26 +0200 Tue, 07 Oct 2008 06:00:00 +0200 With an eye to virtualization management, CA today released new data center automation tools and nine other products. Like HP, CA is trying to position itself as a Switzerland for virtualization management tools, neutral to the battle between VMware and Microsoft. CA's CEO talked with CIO.com about the company's vision for the virtualized data center.
Tue, 07 Oct 2008 06:00:00 +0200 An ambitious project is under way in Wales to build one of the most advanced and secure data centers in Europe.
Tue, 07 Oct 2008 06:00:00 +0200 Pramati Technologies will release new software widgets for the enterprise by January that will allow users to collaborate from within the business applications that they are using.
Tue, 07 Oct 2008 06:00:00 +0200 Bull is acquiring German high-performance computing company science + computing, and at the same time selling its Medicaid solutions business, it announced on Tuesday. The deals continue Bull's transformation into a high-end server company.
Tue, 07 Oct 2008 06:00:00 +0200 The Tokyo Game Show is a big event in the calendar for anyone in the gaming industry and for Hirokazu Hamamura, president of Enterbrain, the company that publishes Japan's leading game magazine 'Famitsu', it represents a chance to gauge development at each company and gather clues to future market developments.
Tue, 07 Oct 2008 05:55:00 +0200 New advances in wireless technologies have given voice to a once-silent drone: the business machine.
Tue, 07 Oct 2008 05:37:00 +0200
Wi-Fi attraction for students: Nearly half of students surveyed would prefer Wi-Fi over beer at school. Three-quarters think Wi-Fi makes helps them get better grades. Take that, Lakehead University! MetroFi antennas won't fall like autumn leaves: Portland, Ore., must wait until April 2009 to declare MetroFi's Wi-Fi nodes abandoned and take them down. While MetroFi gave the city a deposit, it will cost the Oregon metropolis $36,000 of its own cash to remove them, although the city's wireless go-to guy says they'll try to recover cash from MetroFi. To my knowledge, MetroFi has not filed for bankruptcy, even though the company no longer has working phone lines and hasn't returned comments. Copyright ©2008 Glenn Fleishman. All rights reserved. Please notify us if you find this content anywhere but at wifinetnews.com or wimaxnetnews.com. Reproduction of full articles from RSS feeds is prohibited without permission.
attached file: type: image/jpeg size: 3.37 KB here Tue, 07 Oct 2008 04:55:00 +0200 Learn how and why some businesses are turning to CDN vendors for delivery of rich media to consumers.
Tue, 07 Oct 2008 04:01:04 +0200 MessageLabs has released their Intelligence Report for September 2008. A press release summarizing the report is here. The full report is here. Tue, 07 Oct 2008 03:59:02 +0200 Boxee, the social XBMC, is now easy to install on your Apple TV. We first covered Boxee in June when the alpha was released. It’s great to see how much the project has advanced to this point. To install on the Apple TV, you first download a USB “patchstick” creator. The program puts a mac partition on the drive and copies over the necessary files. You reboot the Apple TV with the stick installed and it patches in both Boxee and XBMC. When you restart the the device it will have two new menu items and the rest of the system will be intact. [Dave Mathews] shows the entire process in the video above. He notes that they’re currently not taking advantage of the GPU, so 1080p is a little too much for the system. ![]() Tue, 07 Oct 2008 03:55:00 +0200 Learn how balancing the benefits of convergence against its associated security risks can be tricky.
Tue, 07 Oct 2008 03:43:09 +0200 Symantec released a SyKnApps update last week for Symantec Endpoint Protection 11. The update notice I received didn't say much, just that "The new revision of I had been wondering if the update would reach SEP clients who get their updates from a corporate SEPM server. By comparing file versions, I found that it appeared my internal clients did get c:\documents and settings\all users\application data\symantec\syknapps\syknapps.dll updated. A Symantec KnowledgeBase article confirms this belief. It specifically says running liveupdate on SEPM will update the clients. It also confirms that this update fixes the cosmetic bug where the SEP client GUI displays the Proactive Threat definitions as July 30th. Tue, 07 Oct 2008 03:33:49 +0200 Jonathan Blow tries to port Braid to Linux. "Yes, I have been using OpenGL for 12 years. Please understand that I am a professional game developer and not a newbie of some kind." Classic.
Tue, 07 Oct 2008 02:35:00 +0200 Dutch scientific paper and German research provides enough information for someone to make fake transit cards by exploiting a vulnerability in RFID smart card technology.
Tue, 07 Oct 2008 02:08:02 +0200 Novell released an update to eDirectory last week and this morning US-CERT recommends updating as soon as possible. To quote the advisory, US-CERT encourages users to review Novell document 3477912 and apply any necessary patches to help mitigate the risks. Thanx, Roseman for alerting us to this one..
References: http://www.us-cert.gov/current/current_activity.html#novell_releases_edirectory_version_8 http://www.novell.com/support/viewContent.do?externalId=3477912 http://download.novell.com/index.jsp?tab=patchespage_num=1families=2597date_start=06%20Oct%202008product_id=keywords=version=14798date_range=y=8 Tue, 07 Oct 2008 02:00:00 +0200 Symantec plans to release updated versions of its antispam gateway and data-loss-prevention agent.
Tue, 07 Oct 2008 02:00:00 +0200 |