Showing posts with label news. Show all posts
Showing posts with label news. Show all posts

2009-07-08

milw0rm is gone

This was on the site before it went down:

Well, this is my goodbye header for milw0rm. I wish I had the time I did in the past to post exploits, I just don’t :(. For the past 3 months I have actually done a pretty crappy job of getting peoples work out fast enough to be proud of, 0 to 72 hours (taking off weekends) isn’t fair to the authors on this site. I appreciate and thank everyone for their support in the past.
Be safe, /str0ke



PS: I'm keeping their link here for historical reasons.

2008-10-26

Importance of verifying vendor's protection claims

One of my favorite fundamental security principles is perfectly summarized by this blog post: "Are you Secure? Prove it.

This is true for any situation more so for high severity issues like the MS08-067 vulnerability. So, one of the big names in enterprise security products came out with couple of signatures in their end user protection product. I won't name which one since it doesn't really matter in this context.

Taking into account that not all organizations can patch immediately, in large enterprises there are many factors which can contribute to the delay, the last resort to protect users is to rely on security software on their workstations. Antivirus can only go so far and it's largely useless these days. However, some HIPS signatures can limit the exposure.

So, this HIPS product rolled out signatures to supposedly detect and prevent the attack. After testing their claims it turned out that it only blocks exploit attempts from the workstation which has this HIPS installed. Any attacks against this workstation will be successful. It is beyond me why this decision was made. It'll stop the worm from spreding but it won't protect the client from being infected by the trojan which can easily be downloaded by the shellcode.

Interestingly, the response from the vendor was that they created detection for the most common exploit vector. I understand that it's not always possible to create signatures for the vulnerability, product has its limitations, thus only specific exploit vectors are detected.

But in this case it wasn't event the most common vector. My tests used the code which was published on milw0rm by stephenl and at that time had just over 10,000 views, currently at over 16,000. I would think that the vector used in that PoC would be the most common since it's quickly copied by many other hacking sites.

Thus, if organizations rely on their security vendor's claims and don't have in-house expertise to verify those claims then they're at a high risk of having a false sense of security. Considering that this product is from a rather large security vendor then the list of those organizations is rather large.

On the upside, vendor was notified and is currently working on updating their detection.

2008-08-22

"Army cyber ops"...

In a Government Computer News article there was an interesting fact mentioned which hints at Army's cyber command centers ability to handle contigency issues.

It was stated that many of their links utilize undersea cables but some also use land based fiber. One of such land links was severed by a garbage truck, disabling service to their northern and southern continental CC for several hours.

Now, I know how difficult it can be to design and run a full contigency operation but one would think that with the budget and resources of a government such a goal should not pose too much of a problem. Apparently, this is not so for Army's cyber ops.

To be honest, it's a big surprise to me. I've seen companies not lose a single tcp connection upon core router/switch failures, cable cuts in server racks, and power outages in data centers and they don't have the same resources as the government can afford.

This isn't a good sign especially in light of more and more talk regarding large scale cyber warefare. Hopefuly, that garbage truck incident served as a lesson. On a bright side, at least the guys at the monitoring consoles got a decent break :)

2007-12-24

Apples for the Army

Forbes Article

In an effort to reduce vulnerability exposure the US Army is adding Mac OS X into the mix of possible targets.  There's nothing wrong with this approach.  These days different organizations apply various methods to reduce the risk of incidents.

In my younger and innocent days I was under the impression that the government utilized custom applications running on custom operating systems designed by them for them.  I guess the government doesn't have enough budget and resources to maintain teams of engineers and support staff to design and implement custom information technology infrastructure.

Most think and will say that this is a complicated issue with many pros and cons.  However, if one really thinks about it then it's not that complicated.  Investment into custom code will outweigh all the cons in the long term.  Look at all the recent reports about cyber warfare attacks and their success.  It was largely due to known vulnerabilities in the common software products.

2007-03-25

Hacking...

Taken from David LeBlanc's blog:
"writing code to explore how things worked (previously known as hacking)."

What's so different about that definition now?

Ahh, is it the kiddies looking for a quick buck or an organized effort to make lots of quick bucks?

I'd say that deep down, fundamentally, it's the same now as it was before. The only difference is that it attracted bigger fish to steal someone else's catch. Evolution, survival of the fittest, has reached the net.

2007-03-16

Bureaucracy or Incompetence?

Quoting HDM:
"Look at how a hacker gets access to the driver: Right now I'm working on Microsoft's automated process to get Metasploit-certified. It [only] costs $500."

Quoting ISN:
"The irony of his statement lies in the idea that Vista trusts Microsoft-certified programsprograms that can include a hacker exploit platform that walks through the front door for a mere $500 and a conveyor-belt approval process."

Imagine the possibilities. I wonder, is this due to bureaucracy or just plain incompetence.

2007-01-17

Wi-Fi leeches, attaching to open wireless networks often without the owner's knowledge or permission in order to access the Internet.

How can one complain about "permission or knowledge" if the access is open?

Incompetent fools?!

2006-12-22

What is a "hacker"?

http://www.itp.net/news/details.php?id=23232

"Its not very expensive to hire a guy whos a certified hacker. The

training is just a couple of thousand dollars"

There's no such thing as a certified hacker. How can one certify a state of mind?