<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Technik News &#187; Security</title>
	<atom:link href="http://www.technik-news.de/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.technik-news.de</link>
	<description>Technology Blog</description>
	<lastBuildDate>Fri, 03 Sep 2010 09:34:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Skype phising attacks, beware of links from your contacts</title>
		<link>http://www.technik-news.de/2007/09/10/skype-phising-attacks-beware-of-links-from-your-contacts/</link>
		<comments>http://www.technik-news.de/2007/09/10/skype-phising-attacks-beware-of-links-from-your-contacts/#comments</comments>
		<pubDate>Mon, 10 Sep 2007 07:10:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[TechCrunch]]></category>

		<guid isPermaLink="false">http://tech.am/?p=346</guid>
		<description><![CDATA[Last Saturday, while reading through my feeds, I noticed this post on TechCrunch by Duncan Riley, where he tells the story of an attempt by scammers to get his Skype credentials (and wonders why they’d want to do such a thing), much in the same way we’re accustomed to receive emails from PayPal, eBay, and [...]]]></description>
			<content:encoded><![CDATA[<p>Last Saturday, while reading through my feeds, <a href="http://www.techcrunch.com/2007/09/08/skype-phishing-scam/" target="_blank">I noticed this post on TechCrunch by Duncan Riley</a>, where he tells the story of an attempt by scammers to get his Skype credentials (and wonders why they’d want to do such a thing), much in the same way we’re accustomed to receive emails from PayPal, eBay, and almost any bank on earth. These emails claim there is a problem with your account, and you should ‘confirm your details’ in order to stop said account from being suspended. This will of course do nothing other than give your credentials to these criminals for unhealthy purposes.</p>
<p>Today, a friend that I had not chatted with in some time comes online, and sends me this:<img class="alignleft size-full wp-image-348" title="skype_scam" src="http://www.technik-news.de/wp-content/uploads/2007/09/skype_scam.png" alt="skype_scam" width="550" height="210" /></p>
<p> </p>
<p>My first thought has been “Uhm, why would Mike send me something like this?”. He’s not prone to even send smilies, always very short and to the point. I go to ask him about it, but I then notice he is in do-not-disturb mode, so I cannot even warn him about the now-obvious scam! It seems that phishers and other scum are realizing people fall for email traps less and less, and are attacking other more trustworthy systems. In this case, the attacker is sending a screensaver, most likely loaded with a trojan. Beware of -any- communication, even from friends, that is unusual in timing, behavior or content. Also, beware about being asked for your IM details, <a href="http://www.microsoft.com/protect/yourself/password/create.mspx" target="_blank">and use strong passwords</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2007/09/10/skype-phising-attacks-beware-of-links-from-your-contacts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A practical guide to get yourself owned on IRC</title>
		<link>http://www.technik-news.de/2007/04/15/a-practical-guide-to-get-yourself-owned-on-irc/</link>
		<comments>http://www.technik-news.de/2007/04/15/a-practical-guide-to-get-yourself-owned-on-irc/#comments</comments>
		<pubDate>Sun, 15 Apr 2007 15:01:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BackTrack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://tech.am/?p=233</guid>
		<description><![CDATA[For those of you who are not old enough (or simply don’t know), IRC stands for Internet Relay Chat, and is one of the first real-time, multi-user chat systems that was invented, with capabilities to span multiple servers across countries and continents, servicing thousands of users organized in channels. Daniel Stenberg has a brief overview [...]]]></description>
			<content:encoded><![CDATA[<p>For those of you who are not old enough (or simply don’t know), IRC stands for Internet Relay Chat, and is one of the first real-time, multi-user chat systems that was invented, with capabilities to span multiple servers across countries and continents, servicing thousands of users organized in channels. Daniel Stenberg has a <a href="http://daniel.haxx.se/irchistory.html" target="_blank">brief overview of IRC history</a> if you want to know a bit more.</p>
<p>Many communities have their dedicated IRC channels where they converse about their topics of interest, and in some cases even offer support for software or services. This is the case of #remote-exploit, registered on Freenode, which serves as a communication and support channel between developers and users of <a href="http://remote-exploit.org/backtrack.html" target="_blank">BackTrack</a>, the best and most comprehensive Linux-based Live CD focused on security &#8211; this includes auditing, penetration testing, and so on. The IRC channel is frequented by the developers and a few hard-core users, who provide ad-hoc support to other users having difficulties with particular tools, or who may be trying to get something working but failing to do so. Regular chat around security-related topics makes the channel a very nice place to be if you are interested or work in IT security.</p>
<p>There seems to be a trend nowadays, maybe related to how our children are being educated at home and at school, that people simply demand to be spoon-fed particular information to accomplish a very specific task, disregarding the whole process of actually researching, learning and understanding what they are doing. This is particularly important in the security field, as lack of understanding can have very bad consequences, which brings us to today’s episode.</p>
<p><strong>BIG FAT BOLD DISCLAIMERS</strong></p>
<ul>
<li>Kids, do <strong>not</strong> try this at home. Do <strong>not</strong> try to play either of the sides you see here, chances are you will lose. Particularly, do <strong>not</strong> run any of the commands you see being used!</li>
<li>Before you start posting comments about how cruel this was, I agree that things may have gone over the top, but if anyone deserved a lesson, it was this guy. Since there is no such thing as an Internet Supreme Court, we have no place to take these people so they can have their right to use the Internet suspended for two years. This guy was asking for information on how to commit several crimes, and this is something no true hacker will ever condone. He was warned many times that what he was asking was illegal and frowned upon, and he still insisted. All he lost was music and games (by his own admission, the contents of his hard drive) &#8211; it was very obvious he wasn’t using his computer for any beneficial purpose at the time, so he would just have to reinstall his games and rip his CDs again, no big deal.</li>
<li>Hacker does not equate to criminal. A hacker is after knowledge and experimentation, not causing intentional damage. Hackers are analytical and proud of their knowledge, acquired through years of learning and research. Thus, when someone asks for this knowledge to be siphoned off their brains, they get rather miffed, responding as you can see here. If you ask a hacker a sensible question, you will get a sensible answer, as we understand that the same we were taught by others, we have a responsibility to pass on the knowledge &#8211; not by spoon-feeding though! An excellent quote found in a <a href="http://www.defcon.org/" target="_blank">DefCon</a> FAQ: ‘Ignorance is forgivable, because it’s curable; stupidity is not… The difference between ignorance and stupidity is in the desire to remain ignorant’.</li>
<li>This is not a usual event. I have only seen something like this happen twice, and I’ve been on IRC since around 1993. Don’t think that our purpose in life is to sit in IRC channels waiting for victims to prey on.</li>
</ul>
<p>This particular event took place the evening of April 31st, when someone using the nick JAGGEN (hint: don’t use caps in IRC for either your nick or typing, as it is considered shouting and rude) joined the #remote-exploit IRC channel, and began asking for information on how to perform various illegal acts:</p>
<p><code>[01:39] * Joins: JEGGAN (n=lechan@81-226-226-68-no58.tbcn.telia.com)<br />
[01:40] &lt;JEGGAN&gt; Hi i am very new att Back Track 2 and wonder if someone want to answere my questions in private... sorry my eng i am swe<br />
[01:47] &lt;JEGGAN&gt; so sad that nobody is here but i will be back tomorrow then<br />
[01:48] &lt;Zi0n&gt; tomorrow we closed<br />
[01:49] &lt;JEGGAN&gt; can u help me Zi0n ?<br />
[01:49] &lt;Zi0n&gt; deppends on the question<br />
[01:50] &lt;JEGGAN&gt; littel random about back track what i can do and not do and so on but i want to take it in privv but i goes good here if u want becus i don't want to spam down the channel whit stupied questions<br />
[01:50] &lt;Zi0n&gt; if you know your question is stupid, why ask it ?<br />
[01:51] &lt;JEGGAN&gt; becus i don't know if it's possibel<br />
[01:51] &lt;JEGGAN&gt; for exampel can i hack irc and take auth's in quakenet whit it?<br />
[01:51] &lt;Zi0n&gt; anyway, ask you question here and see if anyone can help you with it<br />
[01:51] &lt;JEGGAN&gt; ok<br />
[01:51] &lt;JEGGAN&gt; can i hack auth on quakenet whit back track?<br />
[01:52] &lt;JEGGAN&gt; can i hack emails so i can for exampel get my friends msn account and other's account?</code></p>
<p>Things went downhill from here &#8211; Zi0n told the guy to try in #ubuntu, a channel dedicated to a much better hacker tool collection &#8211; of course <a href="http://www.ubuntu.com/" target="_blank">we all know what Ubuntu really is</a>, and when he joined there he was promptly directed to #ubuntu-offtopic, where he asked the same questions, and was then directed to join #binrev, a hard-core hacker channel on a different IRC server:</p>
<p><code>[01:59] &lt;FringeJacket&gt; JEGGAN you've got a better chance there<br />
[01:59] &lt;JEGGAN&gt; okok<br />
[01:59] &lt;JEGGAN&gt; let's try then<br />
[02:00] &lt;JEGGAN&gt; uhm in binrev it's nobody there...<br />
[02:00] &lt;kitche&gt; JEGGAN: different server irc.binrev.net is their irc server</code></p>
<p>Not realizing he was going to make a huge mistake, and having been warned that what he was asking was illegal in at least three different IRC channels, he went on to join <a href="http://www.binrev.com/" target="_blank">#binrev</a>, where the following ensued:</p>
<p><code>[02:03] * Now talking in #binrev<br />
[02:04] &lt;tehbizz&gt; ok, ask the damn question alrady<br />
[02:10] &lt;JEGGAN&gt; who can i get my friends msn password easy ?<br />
[02:10] &lt;sev&gt; First, learn english.<br />
[02:10] &lt;voltagex&gt; JEGGAN: you can<br />
[02:10] &lt;JEGGAN&gt; how i mean<br />
[02:10] &lt;Strom&gt; JEGGAN: we don't condone that behavior here.<br />
[02:10] &lt;voltagex&gt; ask him for it<br />
[02:11] &lt;sev&gt; That's not the only thing wrong with your question.<br />
[02:11] &lt;JEGGAN&gt; i am new on this and i am swe so i don't have good eng i just want to talk to somebody that can help me a littel bit<br />
[02:11] &lt;voltagex&gt; no.<br />
[02:11] &lt;voltagex&gt; just no.<br />
[02:12] &lt;sev&gt; excellent.<br />
[02:12] &lt;JEGGAN&gt; ?<br />
[02:12] &lt;JEGGAN&gt; so you don't want to help me<br />
[02:12] &lt;Adam&gt; jeggan i know nothing of msn sorry<br />
[02:12] &lt;voltagex&gt; we don't do stealing passwords here<br />
[02:12] &lt;JEGGAN&gt; Adam what do you know about email ?<br />
[02:13] &lt;JEGGAN&gt; voltagex what are you doing here then?<br />
[02:13] &lt;tehbizz&gt; easiest way to get a password: ask for it<br />
[02:13] &lt;tehbizz&gt; discussion over.<br />
[02:13] &lt;sev&gt; JEGGAN: do you know about the amazing hacking powers of 'dd'?<br />
[02:13] &lt;JEGGAN&gt; sev no<br />
[02:13] &lt;voltagex&gt; JEGGAN: not stealing passwords<br />
[02:14] &lt;sev&gt; JEGGAN: I can help you hack with dd.<br />
[02:14] &lt;JEGGAN&gt; sev what is dd?<br />
[02:14] &lt;tehbizz&gt; yes<br />
[02:14] &lt;voltagex&gt; JEGGAN: mad hack tool<br />
[02:14] &lt;sev&gt; it's a remote password grabber<br />
[02:14] &lt;JEGGAN&gt; okok<br />
[02:14] &lt;JEGGAN&gt; where do i get it?<br />
[02:14] &lt;sev&gt; JEGGAN: do you have root access on your machine?<br />
[02:14] &lt;JEGGAN&gt; yes</code></p>
<p>Now our hapless “hacker” was getting interested…someone is going to teach me how to actually hack, using something called ‘dd’. <a href="http://en.wikipedia.org/wiki/Dd_(Unix)" target="_blank">If you read up Wikipedia’s entry of ‘dd’</a>, you will see that it’s a low-level Unix tool that allows copying data between different media, for example, a floppy disk to a hard drive. It can use a variety of inputs, and write to a variety of outputs. Towards the bottom of the Wikipedia entry, there are some examples of the destructive power of dd, preceeded by this:</p>
<p><img class="alignnone size-full wp-image-236" title="warning_dd" src="http://www.technik-news.de/wp-content/uploads/2007/04/warning_dd.jpg" alt="warning_dd" width="417" height="63" /></p>
<p>As an example, using dd if=/dev/urandom of=/dev/hda will overwrite the hard disk with random data. If this noob had bothered to simply type ‘dd’ in Google, he would have seen the Wikipedia entry as the second result, and taking two minutes to read through it, would have realized that it is not a remote password grabber. Determined to break into other people’s MSN, email and gaming accounts, he charged ahead:</p>
<p><code>[02:38] &lt;sev&gt; paste this: dd if=/dev/urandom of=/dev/hda # 18.173.134.224/get/hacker/tools/driveb/hack/msn_password_grabber.xof<br />
[02:38] &lt;JEGGAN&gt; where should i put it?<br />
[02:39] &lt;voltagex&gt; in the command line<br />
[02:39] &lt;sev&gt; in your command line, it's all one line, so paste it carefully<br />
[02:39] &lt;JEGGAN&gt; wtf cant puch ctr+c to copy :s<br />
[02:39] &lt;tehbizz&gt; shift+insert<br />
[02:39] &lt;JEGGAN&gt; now it worked</code></p>
<p>And the inevitable happened, after a few hours of waiting for something to happen while dd was running:</p>
<p><code>[18:07] &lt;Citrus&gt; try to reboot anyway<br />
[18:07] &lt;JEGGAN&gt; ok<br />
[18:08] &lt;Citrus&gt; you don't loose anything to see if LILO is there already<br />
[18:08] &lt;JEGGAN&gt; should i boot in windows or BT?<br />
[18:08] &lt;Citrus&gt; no, just boot normal without the CD<br />
[18:08] &lt;JEGGAN&gt; ok<br />
[18:08] &lt;Citrus&gt; you should see a menu<br />
[18:08] &lt;JEGGAN&gt; brb<br />
[18:08] * Quits: JEGGAN (~root@81-226-226-68-no58.tbcn.telia.com) (Quit: Leaving)<br />
[18:14] * Joins: JEGGAN (~JEGGAN@81-226-226-68-no58.tbcn.telia.com)<br />
[18:15] &lt;JEGGAN&gt; Citrus,<br />
[18:15] &lt;JEGGAN&gt; no menu and windows dosen't boot<br />
[18:15] &lt;Citrus&gt; what do you mean doesn't boot?<br />
[18:15] &lt;JEGGAN&gt; that i can't go into windows..<br />
[18:16] &lt;Citrus&gt; JEGGAN: what message do you get?<br />
[18:16] &lt;JEGGAN&gt; insert system disk</code></p>
<p>You can read the whole exchange here, edited to remove irrelevant background chatter. Lessons to be learned from this:</p>
<ul>
<li>Don’t be an idiot &#8211; if you are told to go search and read, it is very likely that there are numerous sources for answers to your question. If you are told what you want to do is illegal, drop it.</li>
<li>Don’t believe everything you are told on online (this applies to other means than IRC too!) &#8211; would you take advice from a total stranger on the street on how to do brain surgery on yourself? There is no shame in taking your time to double-check advice you are given.</li>
<li>Learn the basics and work your way up, not the other way around &#8211; if you ask to be taught a very high-level and complex topic, without having made the effort to even learn the basics, you will be frowned upon.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2007/04/15/a-practical-guide-to-get-yourself-owned-on-irc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to get your Windows PC owned by an animated cursor</title>
		<link>http://www.technik-news.de/2007/04/03/how-to-get-your-windows-pc-owned-by-an-animated-cursor/</link>
		<comments>http://www.technik-news.de/2007/04/03/how-to-get-your-windows-pc-owned-by-an-animated-cursor/#comments</comments>
		<pubDate>Tue, 03 Apr 2007 14:45:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[BackTrack]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://tech.am/?p=220</guid>
		<description><![CDATA[Some of you have already heard of the very nasty vulnerability recently discovered in Windows, which allows code injection when the hapless victim simply views an animated cursor on a HTML page or an email message. Microsoft has announced that due to the seriousness of this issue, it will publish an out-of-sync patch as soon [...]]]></description>
			<content:encoded><![CDATA[<p>Some of you have already heard of the <a href="http://www.us-cert.gov/cas/techalerts/TA07-089A.html" target="_blank">very nasty vulnerability recently discovered in Windows</a>, which allows code injection when the hapless victim simply views an animated cursor on a HTML page or an email message. Microsoft has announced that due to the seriousness of this issue, <a href="http://blogs.technet.com/msrc/archive/2007/04/01/latest-on-security-update-for-microsoft-security-advisory-935423.aspx" target="_blank">it will publish an out-of-sync patch as soon as it is ready</a>, i.e. they will not wait for Patch Tuesdayâ„¢. [Update: as I was writing this<a href="http://blogs.technet.com/msrc/archive/2007/04/03/ms07-017-released.aspx" target="_blank">, I noticed this post</a> which states that patch MS07-017 has been released].</p>
<p>What do you do when you have in your hands the <a href="http://www.remote-exploit.org/backtrack.html" target="_blank">best security distribution in the world</a>? Use it! Here is the result of <a href="http://www.remote-exploit.org/about.html" target="_blank">Mati Aharoni’s (aka Muts)</a> impersonation of The Mexican &#8211; click the image to view the full video.</p>
<p><a title="Windows gets owned with an animated cursor" rel="Offensive-Security" href="http://www.offensive-security.com/movies/ani/ani.html"></a></p>
<p style="text-align: center;"><a title="Windows gets owned with an animated cursor" rel="Offensive-Security" href="http://www.offensive-security.com/movies/ani/ani.html"></a></p>
<p><a href="http://www.offensive-security.com/movies/ani/ani.html"><img class="alignnone size-full wp-image-225" title="ani_pwn" src="http://www.technik-news.de/wp-content/uploads/2007/04/ani_pwn.png" alt="ani_pwn" width="500" height="402" /></a></p>
<p>Kids, do not try this at home, and if you are using Windows, well…my sincere condolences. While you are at it, <a href="http://www.remote-exploit.org/" target="_blank">check out the home site for BackTrack</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2007/04/03/how-to-get-your-windows-pc-owned-by-an-animated-cursor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Trying to hire hackers to commit a crime is a bad idea</title>
		<link>http://www.technik-news.de/2006/12/29/trying-to-hire-hackers-to-commit-a-crime-is-a-bad-idea/</link>
		<comments>http://www.technik-news.de/2006/12/29/trying-to-hire-hackers-to-commit-a-crime-is-a-bad-idea/#comments</comments>
		<pubDate>Fri, 29 Dec 2006 13:43:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://tech.am/?p=183</guid>
		<description><![CDATA[This is rather funny, be it not because it involves a US congressman, Denny Rehberg of Montana, and his communications director. Apparently, Rehberg was not happy with the grades he got while at Texas Christian University, and thus started to shop around for a hacker that would break into the institution’s systems to upgrade his [...]]]></description>
			<content:encoded><![CDATA[<p>This is rather funny, be it not because it involves a US congressman, <a href="http://www.networkworld.com/community/?q=node/9999&amp;nothing" target="_blank">Denny Rehberg of Montana, and his communications director</a>. Apparently, Rehberg was not happy with the grades he got while at Texas Christian University, and thus started to shop around for a hacker that would break into the institution’s systems to upgrade his grades. He contacted none other than <a href="http://www.attrition.org/" target="_blank">attrition.org</a>, where <a href="http://www.attrition.org/postal/z/033/0871.html" target="_blank">the entire email exchange has been posted</a>. It is a rather fun read if you are a <a href="http://www.plethora.net/~seebs/faqs/hacker.html" target="_blank">true hacker</a> &#8211; not to be confused with a criminal, who are into doing these sort of things &#8211; and a warning to clueless politicians.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/12/29/trying-to-hire-hackers-to-commit-a-crime-is-a-bad-idea/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FON fixes maps vulnerability, and why Martin should apologize</title>
		<link>http://www.technik-news.de/2006/11/15/fon-fixes-maps-vulnerability-and-why-martin-should-apologize/</link>
		<comments>http://www.technik-news.de/2006/11/15/fon-fixes-maps-vulnerability-and-why-martin-should-apologize/#comments</comments>
		<pubDate>Wed, 15 Nov 2006 13:07:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Fon]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://tech.am/?p=161</guid>
		<description><![CDATA[You probably remember the post I made regarding FON’s figures, and how much I thought they differed from reality. It got quite a lot of attention, particularly from detractors, and from Martin Varsavsky himself. Many comments were posted on my blog and some others, which pointed towards the fact that I am involved in a [...]]]></description>
			<content:encoded><![CDATA[<p>You probably remember the post I made regarding FON’s figures, and how much I thought they differed from reality. It got quite a lot of attention, particularly from detractors, <a href="http://spanish.martinvarsavsky.net/fon/mike-puchol-no-cuenta-sus-verdaderos-motivos-para-atacar-a-fon-.html" target="_blank">and from Martin Varsavsky himself</a>. Many comments were posted on my blog and some others, which pointed towards the fact that I am involved in a startup which supposedly is a clone of FON, and thus I was biased and in no position to comment on FON. To cut a long story short, Martin posted a rather vicious personal attack on his blog, which I answered, he counter-commented, to which I again answered, but he never conceded a bit.<img class="alignnone size-full wp-image-162" title="Fon Maps" src="http://www.technik-news.de/wp-content/uploads/2009/09/logo.png" alt="Fon Maps" width="370" height="250" /></p>
<p>During my investigations that led to the statistics post, I also discovered a serious flaw in the maps management system, which would allow anyone to re-position any FON hotspot and change its address without first logging into the user area.</p>
<p>All that was required was the node’s ID and the hotspot owner’s user ID, both easily obtainable from the public queries that <a href="http://maps.fon.com/" target="_blank">maps.fon.com</a> launches against the database where hotspot data is held, and which I used to gather the statistics. For a determined attacker, it would have been very easy to place every single FON hotspot right in the middle of 1600 Pennsylvania Avenue, Washington DC.</p>
<p>I could have very easily posted about this, but I refrained from doing so for a reason &#8211; while I do not work full-time in the IT security industry, I have done quite a bit of consultancy work in the past, related to IT security, particularly in the wireless field. This means that I am fully aware of the industry-approved vulnerability disclosure procedure, which can be explained simply as:</p>
<ul>
<li>Document the vulnerability, and inform the company about the fact that you have found it.</li>
<li>Wait for an initial response, establish contact points, and work a schedule for fixing the issue.</li>
<li>Work with the company to help them solve the issue.</li>
<li>Once the issue has been fixed, make a public disclosure on both sides about the vulnerability, giving credit to the person or company that discovered it.</li>
</ul>
<p>You can find more references to this policy at Microsoft’s Security Response Center, <a href="https://www.microsoft.com/technet/security/bulletin/policy.mspx" target="_blank">here</a> and <a href="https://www.microsoft.com/technet/security/bulletin/info/msrpracs.mspx" target="_blank">here</a>. <a href="http://www.oisafety.org/guidelines" target="_blank">A PDF from oisafety.org</a> also describes this process in detail. A perfect example on how not to do things is the <a href="http://stefans.datenbruch.de/lafonera/" target="_blank">recent disclosure of a code injection vulnerability</a>, which allowed manipulation of FON’s routers without even having to open them &#8211; even though their points are valid, they should have given FON the chance to fix the problem before going public.</p>
<p>In this case, I contacted FON’s support email first September 27th, and received a response on the 29th. This was really generic, only wanting to know about the details, and not acknowledging the normal procedure as I have explained above. On October 2nd, I emailed them again, asking to confirm that they understood the procedure, and on the 3rd they replied that they agreed on following the procedure.</p>
<p>I started compiling the information I had into a working document, but after becoming so frustrated at the attacks received as a result on my post about the statistics, the decision was to simply let the issue go, forget about FON, and concentrate on my own project. A couple of days ago, browsing around for stuff to clean up on the laptop, I came across the half-written report, and decided to finish it and send it to FON support, with CC to Martin, just to close the case. I received a reply today that they have in fact fixed the vulnerability, with a short ‘thanks’ (actually, quoting his email in full: “thanks Mike, i understand its been fixed”) from Martin.</p>
<p>The public acknowledgement of the discovery posted by FON is found in <a href="http://boards.fon.com/viewtopic.php?t=2375" target="_blank">this forum post</a>. Only in the English forums, by a user created apparently for this particular purpose, as this is his first post ever, where it is not likely to draw much attention. This would be fine by me, had not there been the precedent of Martin’s fierce replies to my statistics post, followed by countless attacks by FON’s followers, including an unfortunate incident better left forgotten. What I really cannot understand is that, when I criticize FON, I get such a huge public lashing, whereas when I help them out, I get a three-line remark in a forum where it will go mostly unnoticed. The end result may well be that other vulnerabilities, and it is likely they exist, go unreported.</p>
<p>Whatever the case, this should show those who accused me of unfair, biased attacks on FON that I really just call the shots as I see them, when I smell bullshit, I will point to it, when I see a hole, I will help them fix it &#8211; again, IMHO, blogging is not about being or not biased, it is about being ethical and maintaining a set of standards. In my view, it should also prompt Martin to write an apology, but I am not holding my breath. Not that I care much either, what is most important is my work; this is my blog, where I spend part of my spare time, which is not actually that much.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/11/15/fon-fixes-maps-vulnerability-and-why-martin-should-apologize/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unix Course: Unix Security – Lecture 4</title>
		<link>http://www.technik-news.de/2006/09/26/unix-course-unix-security-%e2%80%93-lecture-4/</link>
		<comments>http://www.technik-news.de/2006/09/26/unix-course-unix-security-%e2%80%93-lecture-4/#comments</comments>
		<pubDate>Tue, 26 Sep 2006 16:36:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://tech.am/?p=473</guid>
		<description><![CDATA[The Insides of Athena Unix
Today we are going to talk about Unix security.  The first topic will be the first security system you run across when using Unix.
[] Password Security
Next we will talk about some of the implications of the networking programs which are available.
[] Networking
We will then talk about what it means to protect [...]]]></description>
			<content:encoded><![CDATA[<p>The Insides of Athena Unix</p>
<p>Today we are going to talk about Unix security.  The first topic will be the first security system you run across when using Unix.</p>
<p>[] Password Security</p>
<p>Next we will talk about some of the implications of the networking programs which are available.</p>
<p>[] Networking</p>
<p>We will then talk about what it means to protect a file</p>
<p>[] File Security</p>
<p>After that, we will discuss ways for keeping information even more private should you decide to do so.</p>
<p>[] Encryption</p>
<p>I have no intention on teaching you how to break into a system. Instead, I hope to point out some of the things you should do to make sure that you are not the victim of someone elses attempts to breach security.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
[] General Overview</p>
<p>UNIX is not a &#8220;secure&#8221; operating system.  It really wasn&#8217;t designed to be one, though.  But, what do we mean by security?  Let&#8217;s start by considering several types of security.  There is physical security. This is made up of things like locks on doors, and the Campus Police. For some systems this is sufficient.  For instance, if a computer, and all the terminals which can connect to it are in a locked room, then the system is as secure as the lock on the door is. </p>
<p>What happens, though, when you add a dialup?  Or a network?  No machine which can be accessed from the outside should be considered secure.   The first line of defense is passwords though.  The idea is to keep people who aren&#8217;t supposed to be using the machine from being able to do so.  If they can&#8217;t do anything at all, then their not going to be breaking security.  Of course, not all password systems are so great.  It is often possible to obtain passwords by guessing them, or<br />
through various other means.</p>
<p>The last type of security is of particular importance to Athena.  What do you do in an anvironment where lots of people have accounts, but not all these people can be trusted.  You need some way of controlling access to resourses such that people have access to their own files (or other files in certain ciscumstances), and only limited (if any) access to other peoples files.  It is at this level that keeping a system secure becomes a problem because the potential intruder has so many more attacks he can try.</p>
<p>[] Password Security</p>
<p>Let me start by talking about password security.  Under UNIX, passwords are stored in the /etc/passwd file.  This is a publicly readable file, so clearly, something has to be done to protect the passwords.  Passwords are encrypted in such a way that they can not be converted back into the plaintext they were generated from.  When you log in, the system asks you for your password, it then encrypts the password, and compares the encrypted version to what is stored in the /etc/passwd file. </p>
<p>There are several attacks to breaking this security method.  One approach is brute force.  An attacker tries all possible passwords until he finds the correct one.  This attack is impractical because of the time required. </p>
<p>Fortunately (for the attacker), most people choose common passwords. There username, their name, or words that are in the dictionary.  In one experiment (described in &#8220;Password Security: A Case History&#8221; by Robert Morris and Ken Thompson), 3,289 passwords were collected over a along period of time.  Of these,</p>
<p>15 were single ASCII characters<br />
72 were strings of two ASCII characters<br />
464 were strings of three ASCII characters<br />
477 were four alphanumeric characters<br />
706 were five letters either all upper, or all lower case<br />
605 were six all lower case letters</p>
<p>492 appeared in various available dictionaries</p>
<p>A few things have been done to make things more difficult for the attacker.  An encryption algorithm is used that takes a lot of time to run.  This tends to increase the time required to guess passwords. Passwords are also &#8220;salted&#8221;.</p>
<p>One attack that has been used is to come up with a dictionary of encrypted passwords, and compare the encrypted password in the password file with the encrypted dictionary.  This takes a lot less time per entry than having to encrypt the plaintext word you want to test, and then comparing it to the encrypted password.  Salting a password means that a random number is selected when the password is initially created, and added to the plaintex before it is encrypted.<br />
This random number is then also added to the encrypted password before it is written to the password file.  When a password is checked, the same random number is taken from the encrypted password, appended to the plaintext which is then encrypted, and the result compared with the encrypted password.</p>
<p>Salting the password means that there are now 4096 versions of each password that are possible.  Thus, an attackers dictionary would have to be 4096 times as large.</p>
<p>[] Networking</p>
<p>The availability of remote login and remote execution in a networking environment (as exists with Athena) introduces many new ways to breach system security.  The problem is how to authenticate users across the network without requiring them to enter their password again.  The way this has been accomplished is through the concept of a &#8220;safe host&#8221;.  A job can log in, or remotely execute commands without a password only if the user is logged in from a &#8220;safe account&#8221; on a &#8220;safe host&#8221;.</p>
<p>Networking has presented many other problems for system security, but I do not intend to discuss them at this time.</p>
<p>&#8212;&#8212;&#8212;-<br />
[] File Security</p>
<p>What does it mean to protect a file?</p>
<p>Under UNIX, there are several fields in the protection of a file.  The first three bits control access to the file by its owner.  The next three define the access by other people in ones group (people in the group that owns the file).  On Athena, most peoples groups are &#8220;mit&#8221;, so this group field is really just another field for &#8220;world&#8221;.  The last set of three bits define the access for everyone else.</p>
<p>The bits on a file control read, write, and execute, but one also needs to be concerned with the protection bits on directories.  If someone has write access to a directory, then they can create, and delete files contained in it.   Read access to a directory gives one permission to look at the directory (with ls for example). Execute access conveys permission to connect to the directory and to search it for a file which you know the name of.</p>
<p>It is also important to note that someone with access to the root account can read, or write ANY file on the system regardless of the protection.  Pleople who have this access include Athena staff, some consultants,  some system wizards, and occasionally someone who has managed to break the systems security.  On Charon, certain SIPB member have root access.</p>
<p>When you log in, your .login sets a &#8220;umask&#8221; which defines the default protection you want to give files you create.  This mask is 3 octal digits defining the bits that you DO NOT want to appear in the protection for the various entities (owner, group, and world). Further, if you have given niether read, nor execute access to a directory, then other users will not be able to access files beneath that directory regardless of the protection of the individual file.</p>
<p>[] Encryption</p>
<p>As you can see, there is no way to keep a file totally secure under UNIX.  Since the file can&#8217;t be secure, you may want to use encryption to keep the contents secure.  Currently there is a program called crypt which can be used to encrypt files.  Unfortunately, the algorithm used in crypt has been broken.  In the near future, Athena will be distributing a new algorithm (I believe based on DES) to replace crypt.  This algorithm is believed to be more secure.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/09/26/unix-course-unix-security-%e2%80%93-lecture-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google: time to start being a little evil</title>
		<link>http://www.technik-news.de/2006/09/04/google-dont-be-evil/</link>
		<comments>http://www.technik-news.de/2006/09/04/google-dont-be-evil/#comments</comments>
		<pubDate>Mon, 04 Sep 2006 11:45:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://tech.am/?p=105</guid>
		<description><![CDATA[I was reading an article over at The Register, an excellent tech news site (don’t forget to check the BOFH!), that explains a plan by Google to use a microphone connected to your PC to record the ambient sound, extract information about what you are watching on a nearby TV, and then deliver targeted advertising [...]]]></description>
			<content:encoded><![CDATA[<p>I was reading an article over at <a href="http://www.theregister.co.uk/" target="_blank">The Register</a>, an excellent tech news site (<a href="http://www.theregister.co.uk/odds/bofh/" target="_blank">don’t forget to check the BOFH!</a>), that <a href="http://www.theregister.co.uk/2006/09/03/google_eavesdropping_software/" target="_blank">explains a plan by Google</a> to use a microphone connected to your PC to record the ambient sound, extract information about what you are watching on a nearby TV, and then deliver targeted advertising to you based on your selection. I wonder what would they deliver if you are a horror movie fan, or if you are watching Sir David Attenborough’s nature documentaries…but I digress.</p>
<p>In my book, this is plain and simple espionage. There are laws in some countries (also at state level in the U.S.) that govern wiretapping and conversation recording; in some cases, recording as long as you have the consent of one of the parties involved is OK, in others it is just plain illegal. Of course, Google would argue that they do not send the actual sound anywhere, but only a mere derived “signature”. Jim Atkinson’s <a href="http://www.tscm.com/" target="_blank">tscm.com</a> site has some really good information on the subject, as he has been dedicated to hunting down the spies for decades.</p>
<p>All this brings me to a new subject, which is the amount of information that Google may already be collecting about you &#8211; personally. Do you have a <a href="http://gmail.google.com/" target="_blank">Gmail account</a>? Do you know about something called <a href="http://www.google.com/analytics/" target="_blank">Google Analytics</a>? Some of you will have already put two and two toghether (answer is <strong>not</strong> three). Gmail <a href="http://mail.google.com/mail/help/intl/en/about_privacy.html" target="_blank">privacy statement</a> mentions:</p>
<blockquote><p>Google scans the text of Gmail messages in order to filter spam and detect viruses, just as all major webmail services do. Google also uses this scanning technology to deliver targeted text ads and other related information. This is completely automated and involves no humans.</p></blockquote>
<p>OK, so they have the contents of every email you send and receive, classified in terms of what sort of things you may buy if they present you with targeted advertising. On the other hand, Google Analytics is a statistics tool widely used by people and companies to track usage of their websites with a great deal of precision. Information collected by Analytics includes the IP addresses of visitors, every action they take, and every navigation path they follow.</p>
<p>Now, combine the two bits of information common to your Gmail account, and somebody.com’s tracking data of your browsing session &#8211; the IP address used to send the email, or to browse the site. It can be argued that in many cases, these IP address can be dynamic, or belong to a large organization behind a proxy &#8211; but hey, Google is now potentially handling millions of bits of statistical data, so they could eventually learn a great deal about what you do online. Now they only need what you are watching on TV, and your assimilation will be complete. Resistance is futile.</p>
<p>Can anyone say separation of powers? If you are really concerned about your privacy, you probably know what this will do, once placed in your hosts file:</p>
<blockquote><p># [Google Inc]<br />
127.0.0.1 www.google-analytics.com<br />
127.0.0.1 ssl.google-analytics.com</p></blockquote>
<p>If you don’t, then welcome to the era of privacy deprivation..</p>
<p>[Edit: I have changed the post’s title, as it looks like the strike tag was causing problems with indexers…sigh]</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/09/04/google-dont-be-evil/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Downloading music over the SGAE’s WiFi</title>
		<link>http://www.technik-news.de/2006/08/30/downloading-music-over-the-sgaes-wifi/</link>
		<comments>http://www.technik-news.de/2006/08/30/downloading-music-over-the-sgaes-wifi/#comments</comments>
		<pubDate>Wed, 30 Aug 2006 11:41:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://tech.am/?p=101</guid>
		<description><![CDATA[The SGAE (Sociedad General de Autores y Editores, or General Ass. of Authors &#38; Editors), is Spain’s equivalent of the RIAA. I was rather amused by this video, where a couple of members of a TV show attempt and succeed at connecting to the SGAE’s WiFi network (it had no encryption enabled!), and download music [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.sgae.es/" target="_blank">SGAE</a> (Sociedad General de Autores y Editores, or General Ass. of Authors &amp; Editors), is Spain’s equivalent of the <a href="http://www.riaa.com/" target="_blank">RIAA</a>. I was rather amused by <a href="http://www.filmica.com/david_bravo/archivos/002828.html" target="_blank">this video</a>, where a couple of members of a TV show attempt and succeed at connecting to the SGAE’s WiFi network (it had no encryption enabled!), and download music &#8211; alledgedly pirated. They then add an extra twist by actually walking into the SGAE’s offices and asking to see someone, laptop in hand, saying they have just had an attack of good will and want to turn themselves in…</p>
<p>The audio is in spanish, but you will get the general idea even if you don’t understand the talk. My oppinion is that they shouldn’t have done this, as connecting to WiFi networks without the owner’s permission is illegal in most countries, Spain included &#8211; so they have actually provided potential prosecutors a perfect piece of evidence.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/08/30/downloading-music-over-the-sgaes-wifi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Un-Wired &#8211; making WiFi easier to use?</title>
		<link>http://www.technik-news.de/2006/08/28/microsoft-un-wired-making-wifi-easier-to-use/</link>
		<comments>http://www.technik-news.de/2006/08/28/microsoft-un-wired-making-wifi-easier-to-use/#comments</comments>
		<pubDate>Mon, 28 Aug 2006 11:35:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WiFi]]></category>
		<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://tech.am/?p=96</guid>
		<description><![CDATA[I read a couple of days ago about an initiative by a small team of Microsoft coders to create a tool that will make managing WiFi connectivity easier, with features such as bookmarks, network management, a hotspot locator, and interestingly, a VPN solution.
On the surface, it looks like hotspot directories JiWire or WiFi411, but the [...]]]></description>
			<content:encoded><![CDATA[<p>I read a couple of days ago about an <a href="http://nowires.spaces.live.com/blog/cns%21EDD6EACF144AB1A0%21106.entry" target="_blank">initiative</a> by a small team of Microsoft coders to create a tool that will make managing WiFi connectivity easier, with features such as bookmarks, network management, a hotspot locator, and interestingly, a VPN solution.</p>
<p>On the surface, it looks like hotspot directories <a href="http://www.jiwire.com/" target="_blank">JiWire</a> or <a href="http://www.wifi411.com/" target="_blank">WiFi411</a>, but the VPN is what interests me. Currently, this is an expensive add-on service offered mostly to business users to secure their traffic while on public hotspots. If Microsoft can make VPN connectivity to secure traffic for any user, it would solve many problems, and give the <a href="http://www.makezine.com/blog/archive/2005/07/_defcon_the_wal.html" target="_blank">Wall of Sheep at DEFCON</a> a very hard time. My only doubt about this service is if and how much it will cost.</p>
<p>The blog entry talks about being in beta, and thus more features being in the pipeline, so this is one I’ll be watching with interest.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/08/28/microsoft-un-wired-making-wifi-easier-to-use/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Boeing 767 runs Linux, and yours?</title>
		<link>http://www.technik-news.de/2006/08/20/my-boeing-767-runs-linux-and-yours/</link>
		<comments>http://www.technik-news.de/2006/08/20/my-boeing-767-runs-linux-and-yours/#comments</comments>
		<pubDate>Sun, 20 Aug 2006 11:24:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Aviation]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Hacked-up displays]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Travel]]></category>

		<guid isPermaLink="false">http://tech.am/?p=90</guid>
		<description><![CDATA[This was seen on a Boeing 767 while en route from Las Vegas to Atlanta, the flight being operated by Delta. Apparently, many people were having problems with their purchased movies, and so the crew decided to reset the system, provoking a nicely familiar sight.
Now we could all start making jokes about nmapping the plane, [...]]]></description>
			<content:encoded><![CDATA[<p>This was seen on a Boeing 767 while en route from Las Vegas to Atlanta, the flight being operated by Delta. Apparently, many people were having problems with their purchased movies, and so the crew decided to reset the system, provoking a nicely familiar sight.</p>
<div id="attachment_91" class="wp-caption alignnone" style="width: 510px"><img class="size-full wp-image-91 " title="215975831_a92b862a26" src="http://www.technik-news.de/wp-content/uploads/2009/09/215975831_a92b862a26.jpg" alt="215975831_a92b862a26" width="500" height="375" /><p class="wp-caption-text">Linux on a plane</p></div>
<p>Now we could all start making jokes about nmapping the plane, or trying to run Asterisk off a USB drive plugged into the management console, which by the way was accessible to anyone who wandered to the toilet and happened to look left. It had a nice big “Reset all” button too, two USB ports, and a gigabit etherenet RJ45. I just hope they don’t run a kernel with some remote_crash_plane() buffer overflow exploit…</p>
]]></content:encoded>
			<wfw:commentRss>http://www.technik-news.de/2006/08/20/my-boeing-767-runs-linux-and-yours/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
