Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, November 30, 2007

Crack Passwords with a PS3

Nick Breese, a senior security consultant at Auckland, Australia-based Security-assessment.com, has come up with a way to drastically increase the processing capability of cracking passwords.

By implementing common ciphers and hash functions using vector computing, Breese has pushed the current upper limit of 10--15 million cycles per second -- in Intel-based architecture -- up to 1.4 billion cycles per second.
Now I really want one of these...

Read more...

Sunday, November 4, 2007

OS X Malware

If you thought using an Apple with Mac OS was safe from all the nasties out there, think again!!! Even though the risk is lower for Mac OS compared to Windows, you still need to take the proper precautions.


In the words of many Windows antimalware developers, OS X users can feel a little less smug about their security after a new piece of OS X malware was discovered circulating on various fake codec sites. As would be expected, this news is beginning to receive fairly widespread coverage across the Internet, though more coverage has been received in recent days on arguments about whether the Leopard firewall is fundamentally flawed or not (probably not).
Read more

Saturday, November 3, 2007

Poor security in Apple's Leopard according to researchers

Security features that Apple Inc. added to Leopard look great on paper, but in practice most are half-baked or useless, experts said Wednesday. And none of those features, good or bad, will make a whit of difference in how safe Mac users are when they hit the Internet.

"If security was the deciding factor, I wouldn’t be using my MacBook. But it’s not [the deciding factor]. The MacBook, and the tools on it, that’s what is."


Read more

Saturday, October 13, 2007

Quantum Crypto to Secure Votes

A new "unbreakable" encryption method will be keep votes safe for citizens in the Swiss canton (state) of Geneva in the country's upcoming national elections, officials said Thursday.

The city-state will use quantum technology to encrypt election results as they are sent to the capital on Oct. 21, said Nicolas Gisin of the University of Geneva.


Read more...

Wednesday, September 26, 2007

Sniffing Fiber Optics!!!

The idea of tapping fiber optic cables aren't new but I was surprised to find out how easy and cheap it was to do from this article. Apparently you can do with less than $1000 of equipment.

The funny thing about it is that I can clearly remember when I did my bachelors degree, lecturers always stress on how secure fibre optics is and that it cannot be tapped like copper wires. This perception sends out a totally wrong message and people tend to forget about the physical security of fibre optics unlike the copper wires. Thus under the wrong assumption, they pay less attention to secure the information sent over fiber channels with encryption.

This articles shows how easy it is to do and also suggests the use of encryption or a fiber intrusion detection device. One particular Fiber Optic IDS stated in the whitepaper is the INTERCEPTOR.

Article: Protect your network against fiber hacks
Whitepaper: Fiber Optic Intrusion Dete ction Systems

Sunday, September 2, 2007

Malware bazaar @ Bank of India Website

Read this article on The Register about how attacker were able to hack the Bank of India website to infect its online customers with malware. You might re-think whether your bank is truly delivering on its promises for safer online banking... go through their policy statements... you might be surprised to find out exactly how much they claim liability if you get compromised while doing an online transaction.

Sunday, August 26, 2007

Just because it's expensive doesn't mean it will work!

The $84 million Internet porn filter implemented just recently by the Australian government has been cracked by a teenager in just 30 minutes :) Read more...

This maybe a lesson to some people that in the world of computer security, big bucks alone can't solve their problems...

Saturday, August 18, 2007

Ubuntu Under Attack

Five of the eight Ubuntu community servers were compromised and used to attack other systems. The servers were shut down to deal with the compromise and are now back online. Canonical, the sponsor and manufacturer of Ubuntu, states the breach was due to more than 15 unpatched web applications running in parallel on the systems, out of date server software being used and the systems using unencrypted FTP.
reported on SANS... read full article.

Wednesday, August 15, 2007

E-Passport Vulnerable to Sabotage!!!

This is an interesting article about e-passports and buffer overflows in e-passport readers.

I think since there are some countries introducing e-passports (Maldives issued its first e-passport to the president and first lady on July 26 this year) it is important to be aware of the security issues involved in them.

There have been a number of security issues (including hacks that were demonstrated to the public) involving e-passports especially in the EU and USA. Some articles talk about how people can actually read the information stored on these RFID chips from a distance without the knowledge of the owner. So imagine someone being able to steal your biometric information such as facial or fingerprint information and store it on his own e-passport and... Well you get the idea!

Original Article: Wired - Scan This Guy's E-Passport and Watch Your System Crash

System Abuse

Recently I came across an interesting post on Schneier's blog on how people can abuse the system, especially if such systems aren't designed in such a way to avoid such vulnerabilities.

I will just quote as it was in the original article which was also quoted no his post.

" Defense lawyers in a number of other terrorism suspect cases accused informants of solely seeking financial boon by creating so-called terrorists that did not exist.

According to court records, Eldawoody was paid $100,000 over a period of 3 years.

Since Siraj's conviction, Eldawoody has his rent covered and receives a monthly stipend of $3,200.

According to The Washington Post, a police spokesman indicated the direct payments to Eldawoody would likely continue "indefinitely."

With such incentives, critics argue, informants are likely to be created out of thin air to join the "inform-and-cash" industry.

Meanwhile, the Muslim community across the country is feeling the heat of being closely watched.

"This is creating mistrust between our community and law enforcement officials," Ayloush said.

In light of their extensive criminal records, Ayloush added, these individuals would neither qualify as police officers nor as FBI agents, yet they are on the payroll of law enforcement agencies and are allowed to do law enforcement work.

"We all respect hardworking law enforcement agents," Ayloush said. "But mercenary informants? Hardly." "

Original Article: Southern California InFocus: Is Big Brother at your mosque?

Saturday, July 14, 2007

Is there a magic pill for security?

I always wonder whether there is or whether there will ever be a magic pill for security. A one shot solution to protect from it all. With the direction the security industry is heading and the emergence of new threats, more intelligent, adaptive, and evolving threats, I do not think such a thing exists in the present or even in the future.

Maybe it is human nature, but we mostly tend to be in a defensive nature. We react only when things go wrong. I am not saying this just in the context of computer security. If there was a guy in the organization who thought differently and proposed ideas that are preventive of some sort, management sometimes fail to see the point and disregard it under the grounds of being wasteful of resources. It may also be that the guy failed to present the point across to the management in an understanding manner in the first place, but thats not the point I am trying to make here.

I have been noticing emergence of new technologies in the security arena, and some although not referred as new technologies, people have been coming up with new approaches to deal with viruses, malware and the like.

There have been several news recently on new startups that are whitelisting companies and I myself have posted and entry on this. The latest I came across is relating to malware.

A new startup by some previous Microsoft employees has released a beta version of a realtime malware blocking tool for the browser. It seems that they have entered a market dominated by big players such as McAfee's SiteAdvisor, Symantec's AntiBot, Exploit Prevention Labs' LinkScanner, and Google.

According to the company website, the tool can protect the user against malware while surfing social network sites and blogs (eg. facebook, blogger), watching embedded flash videos (eg. youtube), viewing sites with banner ads and widgets (eg. almost every site), clicking search engine results that unknowingly point to malicious sites (eg. while googling).

According to article on Techworld.com the tool has a multilayer strategy against the malware. The first layer works at the kernel level by monitoring dozens of windows processes and services amongst the API calls to the kernel and suspicious behavior from the browser. This realtime task is done by the identification and interception of the behavior based profiling algorithm.


The second layer protects by using blacklisting based on a database of malicious links and blocks the site.


As I have said before, these technologies aren't new technologies. Blacklisting and anomaly based malware detection has been around for sometime. And these technologies are being researched by academics even today. However I believe this tool is a one of a kind as there approach is different and obviously the implementation will be different from every other product out there.

It is indeed interesting and hopeful to see such attempts by people in the battle against the threats that exist out there. And such attempts are needed despite the many products that claim to be "the" magic pill to solve all your problems.

All images in this article have been taken from the Haute Secure website.
Original news article is from Techworld.com.

Sunday, June 24, 2007

You-Tubers beware!!!


YouTube is truly the most popular service for sharing and uploading video from people throughout the world. It has become a way of life for some people as they spend hours and hours on channels viewing videos ranging for funny clips to those showing high school students beating up and bullying other kids.

Since this craze has been spreading among the Internet users like an epidemic, some people have been devising ways of using this to their advantage, and these people have alternative motives than to just share a visually appealing video clip.

Yes I am talking about the black hat hackers once again exploiting something that people use because they simply can. Security experts say that those video files that you view can be booby trapped.

A fake video file containing the Zlob Trojan has been planted on the video-sharing site. If selected, the Trojan bombards infected users with ads. It might also be used to upload other forms of malware onto compromised PCs. - The Register


The black hats being one step ahead of the security professionals are not something new. And the key is knowledge and the effective channels by which they freely share information. However, even when there are people willing to give warning about such vulnerabilities and bugs that can be exploited, these services such as Google/YouTube don't pay serious attention or give them enough credit.

There were reports on a white hat who was expressing his frustration when Google / YouTube
developers didn't give any response for his reported security issues in their site.

But ultimately they responded and admitting to 40 plus vulnerabilities that this guy uncovered that could seriously jeopardise the users of the YouTube service.


Sources:

Saturday, June 16, 2007

Bye Bye Anti-Virus?

Recently I read an interesting article regarding Anti-Virus (AV) technology. This article reports that the AV technology is dying and will be replaced by a technology called whitelisting. Some of the trends that we are seeing today is that major AV companies are trying to acquire the whitelisting technology, and the rise of new whitelisting startups. More on this article can be read on The Register.

One of the whitelisting vendors stated in the article was SignaCert. So I did some research on their site. The basis behind the concept of whitelisting is software authentication. According to SignaCert, a whitelist is a repository of identified authentic individual data elements (file signatures generated using cryptographic hashing techniques) that are used to validate the integrity of contents on devices (such as files stored on PCs).

For the whitelists to be effective, it should contain software signatures and metadata of a wide range of commercially available software relavent to an enterprise’s specific needs. These signatures and metadata should be based on the source and from verifiable authentic sources. The signatures and metadata needs to be continually synchronized against the continuous changes to the software by the vendors. It should provide simple and flexible mechanisms to extend the repository for these commercial and also internally developed custom applications. And flexible and easy to use mechanisms for organizing the whitelists.

The goal of all this and other fancy products they have are to ensure the integrity of the IT platform. Whether it is the files stored on the servers/PCs or configuration, registries, etc. Besides this there are other products out their which specializes in file integrity and one of the most widely used and popular one is Tripwire.

With all this, I wonder if the signature based virus detection will get obsolete and whitelist technology will takeover. Or would other technologies will come to surface as they gain more production value such as more adaptive and intelligent techniques in detecting such malware. One such interesting project I came across sometime back is Janus (the intelligent firewall) project by InSeon Yoo. This project has a non-signature based virus detection module.

Whatever the future holds, I believe this battle with viruses and other malware will never end unless more innovative and intelligent solutions are developed.

References:

...