My Conficker Note

Sorry for not posting for a bit, my personal life has been busy lately (we moved, hopefully the last time for a long, long time.).

There has been a lot said about the Conficker (downadup, kido, april fools day worm, etc...). I can't really add anything new that hasn't already been said on the Security Bloggers Network. What I would like to say is that I hope that what it does is simply make all the infected computers say "Happy Birthday, Vovo!" because the now infamous April 1st target is my Vovo's birthday and I always for get to call. (If it does do this, I swear, I didn't make it happen...).

(Yes this is my sense of humor, and if you like it then I am your friend for life - nobody gets me :o)
Posted on 12:34 PM by Tim Cronin and filed under | 9 Comments »

"Google Hacking" made easy

sort of...

A lot of people use Google to find information on a "target" or "mark". A lot of times this is either a person, organization or machine. If your mark is a person, there is now a web service that can do this easily, www.pipl.com. The New York Times outlines this with the article When Googling a Person (or Yourself) Isn't Enough.

Okay, so these services have been around and the end of the world didn't show up. This is a typical kind of piece that is important to know about, but not to lose sleep over. The information that Pipl finds is not generated by searching databases that are normally off-limits. It does dig a bit deeper than google does by default, but all the info is still public. The bigger question when you find something about yourself that you didn't expect is how did the original recipient of this information make it public and why did I not know.

I think Pipl is a good thing because it allows average people find information that nefarious people may have found anyways. Thoughts?
Posted on 2:37 PM by Tim Cronin and filed under | 1 Comments »

Really Quickly

I was typing an email to my wife and noticed that MS Outlook knows that Comcast should be capitalized. I wonder what other conglomerate is large enough and to have their name be known to Outlook.
Posted on 7:18 PM by Tim Cronin and filed under | 0 Comments »

Personal Security


In the "Digital Age"

I was driving home tonight and I was listening to "On Point, with Tom Ashbrook" (NPR). Today's topic was on "Cyberbullying", specifically a court case that may have far-reaching effects. Listen here.

The story starts with two Yale law students were harassed and libeled online by an internet community. This harassment and libel may have cost one or both of them job offers (by overly-sensitive prospective employers googleing them and having these nasty posts show first). There were also threats and stalking comments made (there were personal threats that made the individuals fear for their safety as the comments were made by people who had to have physically seen them).

To make matters worse, the host of these threads failed to act in a regulatory manner to take down these threads. Also, they (alegedly) deleted logs and subsequently disabled logging for users that post to threads, making it harder to find the anonymous culprits.

This last part troubles me. I believe in freedom of speech just like all Americans should. That being said, there are certain types of speech that should not be protected. When you feel threatened, you have a right to address that threat to ensure your personal safety and the safety of others. But if you don't know who is threatening you - other than the fact that it is some guy/girl with an internet connection - then what can you do? It is vital that the internet community self regulate certain content. If we, as hosts, don't self regulate then we may have to be regulated by an authority which is potentially far worse.

As a security practitioner, I feel that the failure of the host to pull the threads and put the users that caused this uproar on notice has caused there to be an open door for legislators to mandate certain restrictions on this type of content. This will make hosting less attractive for these new and exciting "Web 2.0" sites we all love (Why get involved in accounting for other people's words? Why become a legal target for lawsuits over content that someone else wrote?) . Also, security professionals will need to concern themselves with accounting for each logged in session. This detracts from the overall secuity of the site. Very bad news, indeed.

I hope this black mark can be sorted out without any far-reaching effects and I hope that hosts can learn to self regulate effectively enough to prevent any future legislation.

-Tim
Posted on 1:40 AM by Tim Cronin and filed under | 0 Comments »

Eating Ubuntu

What?



That's right, there is now a restaurant called Ubuntu in Napa region of CA. Competitor Knoppix seen pulling up with a food-mobile to serve your immediate nourishment needs, but never actually constructing a building. (OK that's a horrible joke)
Posted on 6:24 PM by Tim Cronin and filed under | 0 Comments »

Mobile Devices on the LAN


iPhone Hype, get your iPhone hype here!

Those handsome, intelligent and engaging folks over at Astaro Internet Security have just introduced a very easy IPSec client auto-setup for an iPhone to connect to a protected LAN. This got me thinking. There is a lot of information available on securing your iPhone and other mobile devices from intrusion, but there isn't a lot of information available about securing your LAN from intrusion from your mobile users.

The idea of using a full IPSec tunnel for all network traffic is great for iPhone security. You are no longer sending data in the clear whether it's to your corporate mail server or gmail. This should cut back on some threats at the iPhone level. Because you are also giving access to your LAN, it can also create an all new set of issues on your LAN.

A lot of security types are used to thinking about mobile devices similar to laptops. After all, they are similar: they're mobile, they can hop on and off your local (trusted) wireless link, they have remote access capabilities, etc... I posit that they are, in fact, different in a few key ways. For instance most people turn their laptops off (or at least have them sleep) when they are actively traveling. This is not the case for mobile devices. The chances of a mobile device attaching to a rogue, unsecured or malevolent access point is far greater. Therefore the exposure to all sorts of nastiness is greater. How can you trust something like that on your LAN?

I would like to suggest some ideas (In bullet point goodness):
  • Expect the Worst
    • Always assume that a mobile device is owned and treat it as such, because it will be easier to deal with when it happens
  • Segment Mobile Devices:
    • Whenever possible, limit access to the LAN. Only give access to business critical infrastructure that is in a secure place, preferably segmented from any LAN.
    • Set up different SSIDs, WLANS and access points specifically for mobile users when in the office.
    • Do not allow mobiles to communicate with laptops and other wireless devices.
  • Use Device Level Security
    • Find reputable applications that protect the mobile device from intrusion
    • Use VPNs when possible to ensure no data is sent in the clear. This can often have an effect on your LAN.
  • Make Concise and Enforceable Usage Policies
    • Make sure that anybody that can gain access to your network with a mobile device is subject to a strict usage policy. This can at least allow you to take action when/if an incident occurs. This policy should be different from any other current remote access policy as the concepts are different
    • Training is considered somewhat "controversial" as you can't ensure that people will learn from it and listen. However, it is a good start and most people will be receptive (or face your wrath).
As always I would love to hear some feedback. Let me know if anything I've said has worked successfully. Report bugs in this theory to bugtaq... (or in the comments section)

-Tim
Posted on 1:05 PM by Tim Cronin and filed under , , | 126 Comments »

Adobe Reader Exploit in the Wild

Hi All,

Just passing this info on. I just read on The Register that fully updated and patched Adobe Reader applications running on fully patched Windows systems are vulnerable to a new exploit. The original info from the Reg. article is at Shadow Server but Adobe fully recognizes the Vulnerability here. More info from US-CERT here.

Apparently, this exploit leverages a known vulnerability in the way MS Windows XP/2003 handles URIs. Using that vulnerability, it is possible to open a trojaned pdf file and have your PC injected with arbitrary commands.

The "Fix" stated in that article is to disable Acrobat Javascript (We all have Javascript off already right???). I can assume (but have not tested) that the Firefox NoScript add-on can save you from this. Adobe, on the other hand, "strongly recommends" updating to 8.1.1 of the Adobe Acrobat (Reader) application.

Here is a quote from pdp of GNUCitizen (credited with the find)
http://www.gnucitizen.org/blog/0day-pdf-pwns-windows

I am closing the season with the following HIGH Risk vulnerability:
Adobe Acrobat/Reader PDF documents can be used to compromise your
Windows box. Completely!!! Invisibly and unwillingly!!! All it takes
is to open a PDF document or stumble across a page which embeds one.

The issue is quite critical given the fact that PDF documents are in
the core of today's modern business. This and the fact that it may
take a while for Adobe to fix their closed source product, are the
reasons why I am not going to publish any POCs. You have to take my
word for it. The POCs will be released when an update is available.

Adobe's representatives can contact me from the usual place. My advise
for you is not to open any PDF files (locally or remotely). Other PDF
viewers might be vulnerable too. The issues was verified on Windows XP
SP2 with the latest Adobe Reader 8.1, although previous versions and
other setups are also affected.

A formal summary and conclusion of the GNUCITIZEN bug hunt to be expected soon.

cheers

--
pdp (architect) | petko d. petkov
http://www.gnucitizen.org



-Tim
Posted on 12:22 AM by Tim Cronin and filed under , , | 5 Comments »