Daily Digs – 08.10.2009
Monday, bloody Monday. At least we're in the clear! Some interesting news as of today so with no further announcements let's dig right in.
Our first link is for a tool distributed, for free, from Sophos: Anti-Rootkit software. It's recently been updated to support 64-bit versions of Windows and the upcoming Windows 7 (which, let's hope, brings the majority of Windows users into the 64-bit world). No black-tie release event for this version, but at least Sophos is still putting it out there for "free".
[Sophos Anti-Rootkit Updated]
If you're in the Minneapolis / St. Paul area and you're in, well, pretty much any field you've probably heard horror-stories stories of United Health Group. If we haven't had enough reasons to hate on UHG they're giving us a new one apparently! Let's see here - they're not only selling the marketing data but also mapping risk ratings for health and life insurance purposes. Way to go UHG! You get my swift-kick-in-the-ass award for today. If you can, do business elsewhere, UHG seems to treat their employees badly on top of the shady business practices.
[Your Prescription Data Has Been Sold For Profit]
Next up is some new functionality that will probably find it's way into Metasploit. Max's Remote-Exploit blog has all the details on 'psnuffle' including a screencast of the functionality. Jam out to the techno beats while you watch the module in action!
[Psnuffle Password Sniffer]
I'm all about the Verizon Business Data-Breach Report. That being said I think big vendors / carriers generally have over-hyped and under-performing security services in general. Hopefully the security service doesn't share any of the service provisioning speeds that generally are, shall we say, not break-neck? Anyway, if you're into hiring a big firm to do your due diligence for you Verizon can offer it on a silver-platter with a bill to match I'm sure.
[Verizon Business to Offer Risk-Based Security Service]
I happened to post this one earlier in the day and it got quite a bit more attention than I had expected. The RedTeam blog has some Gimp pwnage fun that shows you how to embed some sneaky PHP in a GIF. That and @hdmoore pointed out to me some extra fun to go along with the 'sploit. Double whammy!
[0wning with Gimp]
All your base are belong to... Committers? Sure. Or just go patch Subversion if you haven't already!
[Holes Closed in Subversion]
One of the more prominent elite when it comes to OS X hacking: Dino Dai Zovi has posted to his blog a new article all about, you guessed it, rootkits! This goes with his recent Black Hat talk and includes the preso, paper and code.
[Advanced OS X Rootkits]
So you want to speak at RSA in 2010? Well, you better get in gear because the call for proposals is quickly coming to a close.
[RSA Call for Speaking Proposals Due August 14th]
SANS has a rockstar intro up to memory forensics today. The write up includes looking at Mantech MDD and Volatility (which we've linked previously). If you're just getting your feet wet in forensics this quick run through definitely won't hurt!
[Memory Forensics: A Practical Example]
I asked myself a couple weeks ago this very question: "Why in the **** is the .NET Framework Extension installed in Firefox?" and now I have a fabulous answer. Wladimir Palant, of Adblock Plus fame, has a very thorough write up with linkage to other articles in the press. If you use Adblock, you'll want to read this. Microsoft up to their shady shenanigans - again.
[The Return of .NET Framework Assistant]
Tsk tsk, reinventing the wheel is BAD. Especially when dealing with crypto. And doing crypto in JS! Don't believe me? Well, you don't have to take my word for it, but how about going back to the link to Nate Lawson's "Crypto Strikes Back!" Google Tech Talk and you'll understand why. The devs themselves even say it's only a "base level of security" (uhhh, there's no auth), so why not just save yourself the trouble and avoid it?
[jCryption 1.0 Released]
Fortinet is, apparently, going for the gold. And in this case "gold" being public shares. El Reg has a story up regarding the rare happening.
[Fortinet IPO]
Put this link out in mainstream C-Level inboxes and you'll have all kinds of heads rolling on Tuesday afternoon. SANS has a post up about the consideration of renewing your A/V solution. If you're not a complete security n00b you probably already knew that A/V is a waste of CPU cycles and whitelisting, not signature based blacklisting, is the only way to really go forward in today's shikata ga nai world. Duh.
[Don't Renew that Antivirus Contract]
Looks like DHS is in the tubes these days. Obama has another catastrophic fail on his hands with the latest being Mischel Kwon putting in her resignation to (shocker) go work in the, much higher paying, private sector. Maybe if I tweet The Prez he'll mention me on Facebook and we can talk about it over Skype later. Or how about this: maybe stop trying so hard with the communications outlets and focus on doing and not talking for a few months. Because, we all know, Cash for Clunkers is really helping out!
[Mischel Kwon Resigns]
We end todays string of ranty-posts with the exclusive in-depth that Tom's Hardware has posted of Charlie Miller on the iPhone SMS exploit. Check it out, I was slightly tickled when I saw reference on the first page to AT commands. GO GO GADGET MODEM!
[Exclusive Interview with Charlie Miller]
We commented all the good articles today so, don't hold your breath, no grab bag for today!
-windexh8er
Daily Digs – 08.06.2009
Well, it's a late post but better than none! I hope everyone's week is winding down nicely and your Friday is more lax than the infrastructure folks had over at Twitter earlier today.
A week or two ago I asked the Twitterverse who Adobe's CSO was and if they didn't have one who was responsible for software security / quality. Either way I'm not sure any professional in the industry today would have very good things to say about the path Adobe has been on recently. That leads us to the CNet article comparing Adobe to Microsoft pre-2002.
[Is Adobe the Next (pre-2002) Microsoft?]
If you market yourself as a "security" company and the majority of your products revolve around securing end user desktops you might just want to be able to pass the VB100 test. El Reg ran an article this afternoon showing how CA and Symantec end up with a big fat fail.
[Top Vendors Flunk Vista Anti-Virus Test]
Dave Lewis posted an article on Liquid Matrix today about Shipley the Troll. OK, so Peter Shipley's not really a troll in the actual sense, but he's sure acting like one.
[Patent Trolls Go After Network Security Vendors]
Sometimes I wonder. Really, I do, if what people write really translates in their head or not to something actually being logically feasible. DarkReading has an article up about "weaponizing" an iPod Touch. They go on to talk about how a researcher has outfitted his Touch with Metasploit and some other tools. Even with Ruby 1.9.x Metasploit takes 5+ minutes to load and the fact that you're limited to wireless access only severely limits your success with regards to LAN race condition attacks. Really guys -- there are better small form factors out there. But, hey, if you like to shove square pegs in round holes for fun go for it!
[Weaponizing Apple's iPod Touch]
TrendMicro has a great review of KOOBFACE over on the blog today. The diagram by itself is worth the click through so head on over and read all about it.
[The Real Face of KOOBFACE]
We'll close out today's (short) post with a little bit of irony. I did a double take when I saw the title of this article and had to visit the actual site to validate it was even true. But, yes, Symantec is suggesting that people use VirusTotal "when in doubt". Yes, BigYellow throwing people over the fence to double check their awesome powers of AV.
[Symantec Says Check VirusTotal]
Well ladies and gents, this particular post has come to a close. Yes, it's a little light, but hopefully the link content is good quality reading! We even spared you one of thousands of links to the Twitter DoS. We know you already know, why bother?
Thanks for stopping by and, as always, feel free to comment!
--windexh8er
