Wednesday, March 25, 2009

Around The Horn vol.1,70

Prelude as a Hybrid IDS Framework

Category: Security Awareness

Paper Added: March 24, 2009

PSYB0T: A MIPS-device (mipsel) IRC Bot , (Tue, Mar 24th)

(Thanks to several readers for writing in to the ISC and noting how some eMedia outlets have now pic ...

China Becoming the World's Malware Factory (PC World) (Yahoo Security)

Brief: Smart-grid firms need security education (SecurityFocus News)

The First Linux Botnet (E-Week Security)

Eliminating the Mobile Security Blind Spot (TechNewsWorld.com) (Yahoo News)

Hacking The Router Patching Conundrum

New research demonstrating how Cisco routers indeed can be hacked in multiple has put the pressure on for enterprises to set router-patching policies and procedures

ProxyStrike v2.1 Released - Active Web Application Proxy Tool

By Darknet on XSS

In April last year we wrote about ProxyStrike, recently the developer has released a couple of new versions - the latest being v2.1. ProxyStrike is an active Web Application Proxy, is a tool designed to find vulnerabilities while browsing an application. It was created because the problems we faced in the pentests of web applications that [...]

Microsoft 24 hours late with IE8 pwn protection

What a difference a DEP makes

Just one day after a little-known hacker dazzled his peers by exploiting the latest version of Internet Explorer 8 beta, Microsoft added an important protection to the browser that probably would have prevented the attack.…

Newfangled rootkits survive hard disk wiping

BIOS attack targets PC nether region

Researchers have demonstrated how to create rootkits that survive hard-disk reformatting by injecting malware into the low-level system instructions of a target computer.…

Kiwi telecom inks contract with convicted hacker

Akill's killing

New Zealand's No. 2 telecommunications company has hired a 16-year-old botnet herder less than 12 months after he pleaded guilty to six computer hacking and fraud charges following an international investigation.…

PGP email marketing gaffe creates message storm

Aren't you supposed to be experts at this stuff?

PGP irritated its security conscious customers on Tuesday by making the schoolboy error of sending out an email marketing message to a list of around 300 recipients without using the bcc field.…

Romanian hacking group downs tools

HackersBlog crew weary of the road

A controversial Romanian hacker group famous for exposing security shortcomings on corporate and anti-virus websites has disbanded.…

eCard scammer avoids jail

Phishing scam targeted AOL subscribers

A US fraudster who used fake electronic greetings cards to spread malware has avoided a jail sentence for his crimes.…

London health authority put on notice over data breach

ICO fumes over dumped PCs with patient records

A north London health authority has been given until the end of the month to improve its information security policies following an embarrassing information security blunder last year.…

Following a bouncing Waledac

By Pedro Bueno on waledac

You know that your malware investigation day will be a pain when you reach the first iframe on the webpage… This one was pointing: iframe src=”http://[REMOVED].cn/in.cgi?[REMOVED] This iframe is a redirect to: http:// [REMOVED].hostindianet.com/index.php?[REMOVED] Now it gets interesting. This url contains a script that will send a PDF file, called readme.pdf. As an additional note, this pdf looks like part [...]

Brief: No more bugs for free, researchers say

No more bugs for free, researchers say

Brief: Smart-grid firms need security education

Smart-grid firms need security education

More companies seek third-party Web app code review, survey finds

By Robert Westervelt

Companies are taking a closer look at software code to find critical vulnerabilities, according to a new survey conducted by the OWASP foundation.

HP patches critical OpenView flaws

By SearchSecurity.com Staff

The remote network software contains flaws that could be exploited to gain access to critical files.

ModSecurity Denial of Service

ModSecurity is "the most widely-deployed web application firewall in the world, with more than 15,000 users. It runs as a Apache web server module and is developed by Breach Security, it's avaliable with GNU GPL and many other comercial licenses". The multipart processor of modsecurity does not sanitize the user supplied input sufficiently. Therefore, an attacker can send a crafted post request of type multipart/form-data which will lead in a remote denial of service.

Autonomy KeyView Word Perfect File Parsing Buffer Overflow Vulnerability

Autonomy KeyView SDK is "a commercial SDK that provides many file format parsing libraries. It supports a large number of different document formats, one of which is the Word Perfect Document (WPD) format. It is used by several popular vendors for processing documents". Remote exploitation of a stack-based buffer overflow in Autonomy Inc's KeyView SDK allows attackers to execute arbitrary code with the privileges of the current user.

8 Great Free Security Tools

Your PC is under attack on all fronts.

    Free Utilities to Speed Up and Tweak Your PC

    You have a good system, but you can always improve a PC's performance.

    Enterprises still neglecting WLAN security

    Most European enterprises are neglecting their wireless LAN security, with an alarming number using only the most basic security protection for their wireless networks.

    In poor economy, IT pros could turn to e-crime

    Enterprises increasingly feel their employees will be more willing to steal data or sell insider knowledge due to the poor economy, according to an annual security survey conducted by KPMG.

    German police: Two-factor authentication failing

    A two-factor authentication system widely used in Germany is failing to stop cybercriminals from draining bank accounts, a top German law enforcement official said Tuesday.

    Pethia: InfoSec's Challenges, Changes

    A lot has changed in the 20 years since Rich Pethia first took the reigns as director of Carnegie Mellon University's Computer Emergency Response Team (CERT). CERT, which was initially launched as the first Internet security response organization has evolved over the years to focus more on research and training role. Pethia, a CSO Compass Award winner, spoke with CSO about how much IT security and vulnerabilities have changed in two decades.

    BIOS-level rootkit attack scary, but hard to pull off

    By jhruska@arstechnica.com (Joel Hruska) on rootkit

    A pair of Argentinean researchers has demonstrated a BIOS-level exploit that allowed the duo to potentially run a great deal of invisible code—which could remain installed even if the hard drive was wiped. Much has been made of this last bit, but malware attacks against the Basic Input Output System are anything but new.

    The CIH (Chernobyl) virus that first appeared in 1998 was capable of bricking a system by rewriting critical boot information in the computer's BIOS with garbage output. Even if you dodged this bullet, CIH's primary payload rewrote the first 1MB of the hard drive. If Chernoybl successfully activated on D-day, the best outcome a user could hope for was an apparently wiped hard drive. At worst, system repair involved physically pulling the BIOS chip and installing another.

    Put More IT Spending in Stimulus Plans, Obama Advisor Says

    Governments will get better economic returns from investments in technology than other kinds of stimulus programs.

    IPod Touch Generates More Traffic Than Most Phones

    Data released by AdMob ranks devices based on how often they access the Internet

    The Planet Bundles Hosted NAS, Cloud Storage

    A partnership with Nirvanix is designed to combine high-speed access with worldwide availability

    Macs: Not as Secure as We Thought?

    When it comes to technology, security is a relative term.

    Solid-State-Drives: The Fastest Storage Eve... Wait a Second

    AnandTech digs deep into solid-state storage to discover a punishing result: once you fill your solid-state drive with data, performance suffers!

    SB09-083: Vulnerability Summary for the Week of March 16, 2009

    Vulnerability Summary for the Week of March 16, 2009

    Tuesday, March 24, 2009

    Around The Horn vol.1,69

    Thinking about Cost-Per-Application and VM Density

    By vmtn@vmware.com (VMTN) on Technical Information

    We announced a new calculator today, one that helps you start to look at the "cost per application" view of virtualization. This particular application isn't designed to measure total cost of ownership or total ROI, just what it costs you...

    CanSecWest Pwn2Own: Would IE8 have been exploitable had the event waited one more day?, (Tue, Mar 24th)

    Safe Internet web browsing experiences - a concept that tends to sometimes get

    Software Maker Helps Companies Thwart Computer Security Threats (Investor's Business Daily) (Yahoo Security)

      Stuck In The Middle, Security Departments Turn To Outsourcing

      Studies say more corporations are outsourcing security as a way to fight myriad threats, lower overall costs

      Charlie Miller Does It Again At PWN2OWN

      By Darknet on tipping point

      You right remember in March last year we posted about Charlie Miller at the PWN2OWN contest owning the MacBook Air in under 2 minutes. Guess what? He’s done it again! This time though he’s even faster clocking in at under 10 seconds. No one else stood a chance. He walked off with the prize again, $5000 [...]

      Worm breeds botnet from home routers, modems
      More than 100,000 hosts invaded

      Security researchers have identified a sophisticated piece of malware that corals consumer routers and DSL modems into a lethal botnet.…

      Government Keeping Its .Gov Domain Names Secret

      Despite a presidential promise of openness in government, GSA officials decline to release the full list for fear of cyberattack.

      Time To Get Serious About HIPAA

      If your company qualifies as a covered entity under HIPAA, now is a good time to review your compliance efforts and fill in any gaps -- before the feds come calling.

      Mandiant Appliance Accelerates Incident Response

      MIR gets to the heart of system compromises, but its forensic tools are limited.

      Napera N24 Offers Turnkey NAC For SMBs

      Appliance provides a range of security features for Microsoft nets, but lacks in-depth reporting.

      Facebook's New Openness Exploited By Scammers

      The rogue message leads to a Facebook application link that spams a victim's friend list with the same warning message, and possibly harvests personal information.

      Hack An iPhone, Win $10,000

      In TippingPoint's DVLabs contest, hackers also have the option of trying to execute a successful exploit against a Web browser.

      Facebook Opens Site Rules To User Voting

      "The Facebook Principles" and "Statement of Rights and Responsibilities" may signal a shift in social networking best practices.

      Spy Agency May Get More Cybersecurity Duties

      The National Security Agency should assume a greater role in defending the nation against cyberattacks, President Obama's intelligence chief told Congress Wednesday.

      Marvell Unveils 'Plug Computing' Platform

      The tiny SheevaPlug computer provides always-on home network services, such as backup and file sharing, for a tenth of the power used by a regular desktop.

      Microsoft Warns Of Zero-Day Excel Exploit

      The vulnerability in Excel could allow an attacker to execute malicious code, if a user opens a specially crafted Excel file.

      Meraki Launches 802.11n Access Point

      The networking startup is trying to differentiate its products by having a lower price point and offering a hosted solution for network management.

      VMware Adds To Data Center Operating System

      vCenter Server Heartbeat and vShield, launched at VMware's user group meeting, bring the company closer to supplying the data center operating system via its virtual machine management capabilities.

      IT Security Remains Top Government CIO Priority

      Those surveyed by TechAmerica say they'd also put IT infrastructure and management at the top of the list, including improvements in governance and standardization.

      Top 20 Cybersecurity Defenses Proposed

      The government-private organization guidelines are expected to become baseline best practices for computer security.

      Five Years On, Can-Spam Gets Help

      The right mix of technical measures can keep most unwanted e-mail out of customers' in-boxes.

      Music, TV Industries Call For Stronger Intellectual Property Protections

      A trade group found that Russia, China, and other countries aren't adequately protecting copyrights in the global digital distribution of music and video.

      Adobe Warns Of Critical Vulnerability In Acrobat, Reader

      Users are advised to disable JavaScript until Adobe releases a patch, which may not occur for more than two weeks.

      'Sexy View' Malware Targets Symbian

      The worm targets Symbian OS S60 3rd Edition handsets, and it can send a user's contacts, phone number, and other sensitive information to a remote server.

      Black Hat: Google Gears Offline Data Vulnerable

      Google defends its product after a demonstration of a Web service-based attack using a cross-site scripting vulnerability.

      Black Hat: Security Pro Shows How To Bypass SSL

      Moxie Marlinspike captured 16 credit card numbers, seven PayPal logins, and 300 other miscellaneous secure login sessions in only 24 hours.

      Forensic Science System In U.S. Needs Overhaul

      Digital evidence examiners have no agreed-upon certification program or list of qualifications, in addition to other issues, a report to Congress points out.

      Microsoft Internet Explorer 7 Vulnerability Being Exploited

      Cyber criminals are using a malicious Microsoft Word file distributed through spam to attack an exploit Microsoft patched last week.

      Sun Delivers Open Source Protocol For Encrypted Devices

      The communications protocol aims to help Sun's users and business partners more flexibly handle encryption keys while sidestepping costly licensing fees.

      Google Wins Street View Privacy Lawsuit

      A Pennsylvania judge said Google didn't violate the Boring family's privacy rights by taking pictures of their residence from a private road and publishing the images online.

      About-Facebook: Zuckerberg Relents On Privacy Rules

      Social networking site's CEO reverses course on new polices that drew fire from users.

      Cisco Adds Security Apps To Home Wireless Routers

      The hardware includes an antivirus application and can provide reports on user control violations.

      Three Arrested For Using Stolen Heartland Credit Card Numbers

      Heartland Payment Systems, which handles about 100 million payment transactions per month, reported in January that its network was compromised by malware in 2008.

      Facebook's Terms Of Use Draw Protest

      Mark Zuckerberg clarifies for users that once they delete their accounts, friends will still retain their posts.

      Prosecutors Reduce Charges Against The Pirate Bay

      Prosecutors acknowledge that the file-sharing site on trial in Sweden for allegedly infringing on film and music copyrights didn't copy files.

      C-Level Executives Weigh In On Information Security

      Our survey results show CXOs "get it." Here's how to turn that common focus into stronger security.

      Android Security Vulnerability Exposed

      The bug lies in the media server of the browser, and it could potentially enable hackers to gain control of the audio and video function of an Android handset like the T-Mobile/HTC G1.

      25 Things Facebook Couldn't Keep Secret In Court

      Redacted portions of a PDF transcript from a court hearing to determine Facebook's settlement with ConnectU were revealed.

      Microsoft Offers $250,000 Bounty For Worm Authors

      The company has formed a cybersecurity posse with technology companies, academic organizations, and Internet infrastructure firms to dismantle the Conficker/Downadup worm's infrastructure.

      FAA Computers Hacked, Employee Data At Risk

      Two of the 48 files on the compromised server held the personal information of more than 45,000 individuals, the agency said.

      Stimulus Bill Will Stimulate Health IT Adoption, Jobs

      The $21 billion for health IT programs in the U.S. economic stimulus bill will create career opportunities and fuel educational programs for professionals to acquire a mix of technology and clinical expertise.

      Identity Thieves Face Pay Cut

      While the number of fraud incidents is rising, criminals are earning less for each crime they commit.

      BlackBerry Maker Acquires Certicom For $106 Million

      Certicom's cryptography software has been adopted by the U.S. National Security Agency for government communications.

      RIM Issues BlackBerry Security Advisory

      Vulnerabilities in the BlackBerry Application Web Loader ActiveX control could allow an attacker to execute code remotely or cause Microsoft Internet Explorer to crash.

      Microsoft Patch Tuesday Brings Four Fixes For Eight Flaws

      The updates address vulnerabilities in Internet Explorer, Microsoft Exchange, SQL Server, and Visio.

      Obama's Plans For Cybersecurity Draw Praise

      Tech industry leaders say the administration "gets it" when it comes to protecting nation's computing infrastructure.

      Social Networking Sites Ink Safety Pact

      The online communities will work together to protect the interests of minors.

      Windows Worm Didn't Ground French Planes, Official Claims

      The planes had been grounded following a Conflicker worm infection that had spread last month throughout the French nonsecured internal naval network called Intramar.

      What is Nortel up to?

      In all the bankruptcy noise surrounding Nortel, it's easy to miss that the company has bought up the intellectual property of Identity Engines, whose portfolio adds up to a NAC package.

      Cold-boot attacks change the data leakage landscape

      Until 2008, the consensus had been that there would be no practical way to remove a RAM chip from a computer system without losing all contained data. However, last July, researchers published a paper about something quite amazing: most RAM chips maintain their data for several seconds without any power, thus allowing a channel for data leakage from any computer to which an attacker has physical access.

      Slack audits facilitate corporate fraud

      Up to 70 percent of corporate fraud is committed by employees and occurs because of broken processes, according to consulting firm Deloitte.

      Conficker's next move a mystery to researchers

      Security researchers are in the dark about what will happen next week when the newest variant of Conficker, 2009's biggest worm by a mile, begins trying to contact its controllers.

      White collar crimes burnt by extreme fingerprinting

      Corporate crime scenes could be cleaned up in minutes, not hours, thanks to locally developed technology that uses extreme heat to reveal fingerprints.

      Worm breeds botnet from home routers, modems

      Posted by InfoSec News on Mar 24

      http://www.theregister.co.uk/2009/03/24/psyb0t_home_networking_worm/

      By Dan Goodin in San Francisco
      The Register
      24th March 2009

      Security researchers have identified a sophisticated piece of malware
      that corals consumer routers and DSL modems into a lethal botnet.

      The "psyb0t"...

      Nearly all firms suffer losses after cyber attacks

      Posted by InfoSec News on Mar 24

      http://www.techworld.com/security/news/index.cfm?newsID=113225

      By Joan Goodchild
      CSO (US)
      24 March 2009

      Nearly all organisations have been hit by cybercrime with some 98
      percent reporting tangible loss after being hit by criminals. In
      addition, 46 percent have experienced downtime as a...

      Senator says his office computers were hacked

      Posted by InfoSec News on Mar 24

      http://fcw.com/articles/2009/03/23/web-cybersecurity-legislation.aspx

      By Ben Bain
      FCW.com
      March 23, 2009

      Three lawmakers are writing a bill designed to expand the cybersecurity
      workforce and bolster collaboration between the public and private
      sectors. Authors include Sen. Bill Nelson...

      Monday, March 23, 2009

      Around The Horn vol.1,68

      Making the most of your runbooks, (Fri, Mar 20th)

      To perform effective security incident handling, a standard model is often used. SANS throug ...

      Updates to ISC BIND, (Sat, Mar 21st)

      Internet Systems Consortiumhave released a new version of their popular DNS implementation.

      BBC says U.K. credit card information for sale in India (NetworkWorld Security)

      CVE-2009-1028 (ezipwizard) (Natl. Vulnerability Database)

      CVE-2008-6500 (aspshoppingcart) (Natl. Vulnerability Database)

        iWonder Surf offers managed browsing on iPhone, iPod touch (NetworkWorld Security)

          Bugtraq: SECURITY DSA 1749-1 New Linux 2.6.26 packages fix several vulnerabilities (SecurityFocus Vulnerabilities)

          From Microsoft Internet Explorer 8 to Mozilla Firefox, Web Browsers Tighten Security (E-Week Security)

          CVE-2008-6494 (aspuserengine.net) (Natl. Vulnerability Database)
          Power grid is found susceptible to cyberattack

          An emerging network of intelligent power switches, called the Smart Grid, could be taken down by a cyberattack, according to researchers with IOActive, a Seattle security consultancy.

          Online Fraud Hits Airlines Hard

          A report finds airlines worldwide lost more than $1.4 billion to fraudsters in 2008.

          Dealing with Security Challenges, (Sun, Mar 22nd)

          Do you ever feel like you are the lone gunman? Taking pot shots into the dark while trying to ...

          Vuln: POP Peeper 'From' Mail Header Remote Buffer Overflow Vulnerability (SecurityFocus Vulnerabilities)

          Brief: Cybercriminals optimize search for cash (SecurityFocus News)

          Zinf Audio Player 2.2.1 (.pls) Universal Seh Overwrite Exploit (milw0rm)

          Mac OS X xnu < 1228.3.13 (zip-notify) Remote Kernel Overflow PoC (milw0rm)

          Bugtraq: SECURITY DSA 1751-1 New xulrunner packages fix several vulnerabilities (SecurityFocus Vulnerabilities)

          Fear and the Availability Heuristic (Schneier blog)

          Apple says sorry for Mac Perl breakage (The Register)

          Finjan: Bogus Anti-virus Is Big Business (E-Week Security)

          Former gov't worker sentenced for passport snooping (NetworkWorld Security)

          Microsoft releases !exploitable crash evaluation tool (CGISecurity.com)

          Scareware affiliates playing search engines (The Register)

          NetWitness Launches Online Intelligence Service Enabling Customers to Protect Against Emerging Threats (Business Wire via Yahoo! Finance) (Yahoo News)

          Research in Explosive Detection (Schneier blog)

          CVE-2008-6502 (prochatrooms) (Natl. Vulnerability Database)

          Pin Down Your Passwords (NetworkWorld Security)

          CVE-2009-1038 (Natl. Vulnerability Database)

          CVE-2009-1040 (Natl. Vulnerability Database)

          CVE-2009-1029 (poppeeper) (Natl. Vulnerability Database)

          sqlsus 0.2 Released - MySQL Injection & Takeover Tool

          By Darknet on sqlsus

          sqlsus is an open source MySQL injection and takeover tool, written in perl. Via a command line interface that mimics a mysql console, you can retrieve the database structure, inject a SQL query, download files from the web server, upload and control a backdoor, and much more… It is designed to maximize the amount of data gathered [...]

          Securing the Smart Power Grid from Hackers

          Posted by InfoSec News on Mar 23

          http://www.businessweek.com/technology/content/mar2009/tc20090320_788163.htm

          By Katie Fehrenbacher
          BusinessWeek
          GigaOm
          March 23, 2009

          Imagine if the havoc caused by Internet viruses and worms - downed web
          sites, snatched credit card data, and so forth - were unleashed on the
          power...

          Defense Firms Pursue Cyber-Security Work

          Posted by InfoSec News on Mar 23

          http://online.wsj.com/article/SB123733224282463205.html

          By AUGUST COLE and SIOBHAN GORMAN
          The Wall Street Journal
          MARCH 18, 2009

          WASHINGTON -- The biggest U.S. military contractors are counting on
          winning billions of dollars in work to protect the federal government
          against electronic...

          Mildenhall personnel information compromised

          Posted by InfoSec News on Mar 23

          http://www.stripes.com/article.asp?section=104&article=61487

          By Charlie Reed
          Stars and Stripes
          European edition
          March 21, 2009

          RAF MILDENHALL, England - British authorities are still looking for a
          stolen computer containing the personal information of thousands
          assigned to the base.
          ...

          A bill to shift cybersecurity to White House

          Posted by InfoSec News on Mar 23

          http://news.cnet.com/8301-13578_3-10200710-38.html

          By Stephanie Condon
          Politics and Law
          CNET News
          March 20, 2009

          Forthcoming legislation would wrest cybersecurity responsibilities from
          the U.S. Department of Homeland Security and transfer them to the White
          House, a proposed move that...

          Hong Kong information security watchdog heads APCERT

          Posted by InfoSec News on Mar 23

          http://www.cw.com.hk/content/hong-kong-information-security-watchdog-heads-apcert

          By Search SMB Asia
          March 18, 2009

          The Hong Kong Computer Emergency Response Team Coordination Centre
          (HKCERT) has been elected as the chair of the APCERT (Asia-Pacific
          Computer Emergency Response Team)...

          Internet Explorer 8 gets hacked, already

          Posted by InfoSec News on Mar 23

          http://blog.seattlepi.com/microsoft/archives/164680.asp

          By Andrea James
          The Microsoft Blog
          Seattlepi.com
          March 20, 2009

          A 25-year-old German graduate student who goes only by Nils has hacked
          Internet Explorer 8, along with Safari and Firefox, at CanSecWest's
          hacking competition. ...

          Re: Stimulus Package Includes New HIPAA Security Rules

          Posted by InfoSec News on Mar 23

          Forwarded from: Caspian Kilkelly <Caspian (at) random-interrupt.org>

          RE: HIPAA security rules-
          These rules are basically a bare minimum for compliance, and don't
          usually end up passing muster for other standards (IHE, HITTSP, HL7, the
          various ISOs, etc) which most hospital and care...

          Been In An Ambulance Lately? Your Identity May Be At Risk

          Posted by InfoSec News on Mar 23

          http://www.wbbm780.com/Been-In-An-Ambulance-Lately--Your-Identity-May-Be-/4051123

          By Steve Miller
          WBBM780.com
          19 March 2009

          CHICAGO (WBBM) -- The city of Chicago now says more than 60,000 people
          may be at risk of having their identities stolen - after a laptop
          computer was stolen from an...

          Apple says sorry for Mac Perl breakage

          Fix on the way

          Apple has apologized for breaking Perl with its latest Mac OS X security update, saying it will distribute a solution to the problem with a future update.…

          Cybercrime server exposed through Google cache

          UK and US IDs exposed to world

          A reported 22,000 card records have been exposed through cached copies of data stored on a defunct cybercrime server.…

          Russian spy agencies linked to Georgian cyber-attacks

          Follow the bear prints

          More circumstantial evidence has emerged linking the Russian authorities to cyber-attacks on Georgia that coincided with a ground war between the two countries in July and August last year.…

          Scareware affiliates playing search engines

          Scam gets results

          The growing trade in rogue security software is being driven by the gaming of search engines to direct surfers to sites peddling scareware.…

          SWFScan - Free Flash Security Tool

          By Robert A. on Security Tools

          "HP SWFScan is a free security tool to developers find and fix security vulnerabilities in applications developed with the Adobe Flash Platform. The tool is the first of its kind to decompile applications developed with the Flash platform and perform static analysis to understand their behaviors. This helps developers without security...

          Microsoft releases !exploitable crash evaluation tool

          By Robert A. on Tools

          "Aiming to better identify bugs that could lead to security issues, Microsoft announced on Wednesday that it planned to release a tool to help developers classify and assess program crashes. The tool, known as !exploitable and pronounced "bang exploitable," is a plugin for the Windows debugger that categorizes crash information using...

          Cloud on the horizon

          By Igor Muttik on Testing

          Guys from AV-Comparatives have just posted a new scanners’ review on their Web site - http://www.av-comparatives.org/comparativesreviews/main-tests: AV-Comparatives is a non-profit independent test organization based in Austria and they have been running comparative tests for many years but this last one in February 2009 was different for two reasons: Firstly, the criteria for getting awards were more stringent than ever. [...]

          Breaking the Codec…

          By Kevin Beets on Scams

          I ran across a new twist on the by-now well known FakeAlert series. Just in case you have been lucky enough not to have dealt with this malware, it goes roughly like this: You get an email from what looks to be a legitimate source, or visit a legitimate looking website that is offering the [...]

          Brief: Cybercriminals optimize search for cash

          Cybercriminals optimize search for cash

          Free HP SWFScan tool detects Adobe Flash flaws

          By Erin Kelly

          SWFScan analyzes Adobe Flash to identify dozens of source code errors.

          Managed security services gain as companies seek expertise

          By Neil Roiter

          Enterprises are shifting key security functions to service providers, according to a new survey. Companies cited the need for outside expertise and 24/7 coverage.

          Visa Slaps Payment Firms On Breaches, Defends PCI

          Two payment processors that recently disclosed data breaches have been dropped from Visa Inc.'s list of companies that comply with the PCI data security rules. But analysts said the move may be more about Visa protecting itself than about improving the security of payment card data.

          Skype to run beta of VoIP for business over SIP, IP switches

          Skype Technologies SA announced Monday a beta version of its popular voice-over-IP service for businesses that have IP-based switches running on the Session Initiation Protocol.

          Spam filters block legitimate email, finds test

          Many anti-spam products still block an inconvenient amount of legitimate email, a new test of leading products has suggested.

          iCABLE combats TV piracy with Cisco tools

          Cisco announced Friday that Hong Kong-based pay TV operator i-CABLE is deploying Cisco's set-top boxes and video system to fight pirated TV viewing.

          10 IE Browser Settings for Safer Surfing

          Ask a room full of security practitioners for a list of security settings that'll make Internet Explorer (IE) safe to use and you'll either hear laughter or advice to get a new browser like Mozilla Firefox, Opera, Safari or Google Chrome.

          Free tool from HP scans for Flash vulnerabilities

          Hewlett-Packard has released a free development tool that finds vulnerabilities in Flash, Adobe System's widely used but occasionally buggy interactive Web technology.

          Former gov't worker sentenced for passport snooping

          A former employee at the U.S. Department of State has been sentenced to 12 months of probation and ordered to perform 100 hours of community service for illegally accessing more than 150 confidential passport applications files, the U.S. Department of Justice said.

          Ex-Sun ID wizards unveil the UnboundID Directory Server

          While I was writing this newsletter last week the press was rampant with rumors of an IBM buyout of Sun. Such a deal would dramatically change the identity management landscape, but it's not what I want to talk about today. Instead, we'll look at news from a group of former Sun employees in Austin, Texas. Surprisingly, though, this isn't about SailPoint.

          Symantec's last ManageFusion conference was full of high points

          Marking the end of an era, Symantec held its last-ever ManageFusion user conference in early March. This conference will be rolled into Symantec's other user conferences in the future. Meanwhile, there were lots of high points at ManageFusion, including the long-awaited general availability of Altiris Client Management Suite 7.0 and Altiris Server Management Suite 7.0. Read what else transpired and learn about cool new technologies in development.

          Twitter Flies into the Enterprise

          Analysis: Companies are already leveraging Twitter to gain an edge, and some are doing it rather well.

          Conficker to Phone Home on April Fools' Day

          While it's unclear what will happen next week when the newest variant of Conficker begins trying to contact its controllers, it likely won't be good news.

          Keep Computer Spies at Bay

          Analysis: Computer espionage headlines abound, but you can fight back by following a few simple steps.

          Site Hacks, Fake Security Rakes in Serious Cash

          Digging into the underhanded tricks online crooks use reveals site hacks that can harm business - and plenty of illicit profit.

          New Unisys Service Offers Single View of IT Infrastructure

          C-RIM service can provide visibility across service providers to enterprises

          VMware to Manage Virtual Machines From Mobile Phones

          New tool set for preview release in April

          Skype Will Let Its VOIP Service Talk to SIP Phone Switches

          Skype is beta-testing a link between its proprietary VOIP system and switches using the open Session Intiation Protocol

          Symantec Says Credit Card Data May Have Leaked From India

          Stops routing calls to Indian call center after BBC report of data theft

          Internet Archive Upgrades Wayback Machine

          The Internet Archive is unveiling a massive Wayback Machine data center to preserve Web history.

          Saturday, March 21, 2009

          Around The Horn vol.1,67

          EPIC Asks FTC to Investigate Google's Cloud Computing Services Security (March 18, 2009)

          The Electronic Privacy Information Center (EPIC) has filed a complaint with the Federal Trade Commission (FTC) asking the agency to investigate whether Google's cloud computing services, including Gmail, are taking adequate steps to protect users' privacy...

          Visa Sets Deadline for Bank Fraud Claims in Heartland Breach (March 16, 2009)

          Visa has established May 19, 2009 as the deadline for banks to file fraud claims resulting from the Heartland Payment Systems data security breach...

          Jurors Admit to Accessing Internet to Research Cases (March 18, 2009)

          The pervasiveness of connectivity through Blackberrys, iPhones and other devices is causing problems in court cases around the country...

          FBI Agent Allegedly Accessed Confidential Database Without Authorization (March 18, 2009)

          An FBI agent in New York has been suspended without pay following charges that he accessed a confidential law enforcement database without authorization...

          IT Contract Worker Indicted for Sabotage (March 17 & 18, 2009)

          Mario Azar, who was formerly employed as an IT consultant at an oil and gas production company, has been charged with illegally accessing and compromising a computer system that was used to monitor offshore oil platforms...

          Senate Committee Holds Hearing on Cyber Security Vulnerabilities and Defense (March 19, 2009)

          On Thursday, March 19, 2009, the US Senate Committee on Commerce, Science, and Transportation held a hearing titled Cybersecurity: Assessing Our Vulnerabilities and Developing an Effective Defense...

          Kundra Reinstated (March 17, 18 & 19, 2009)

          Vivek Kundra is back at work as federal chief information officer (CIO)...

          UK May Start Retaining Social Networking Site Data (March 18 & 19, 2009)

          UK Home Office Security Minister Vernon Coaker says that the EU Data Retention Directive does not go far enough because it does not include communications on social networking sites like Facebook and Bebo...

          Critical Buffer Overflow Flaw in WordPerfect Library (March 18, 2009)

          The SDK Autonomy KeyView library used by the WordPerfect office suite is susceptible to a critical buffer overflow flaw...

          Cyber Squatting and Brand Abuse a Growing Problem (March 17, 2009)

          A study from MarkMonitor found that the practice of cybersquatting increased 18 percent during 2008...

          Microsoft Releases IE 8 (March 19, 2009)

          Microsoft has released Internet Explorer 8 (IE 8), the first major update for the browser since 2006...

          Australian Internet Blacklist (March 17, 2009)

          People who hyperlink to websites on the Australian Communications and Media Authority's blacklist could find themselves fined AU $11,000 (US $7,600) a day...

          Latest on Conficker, (Fri, Mar 20th)

          The researchers at SRI International updated their Conficker paper today. This is by far one ...

          Stealthier then a MBR rootkit, more powerful then ring 0 control, it's the soon to be developed SMM root kit. , (Fri, Mar 20th)

          Joanna Rutkowska founder and CEO of Invisible Things Lab along with Rafal Wojtczuk has released a ...

          Browsers Tumble at CanSecWest, (Thu, Mar 19th)

          The three major browsers fell in quick succession at CanSecWest. The Pwn2Own competition prod ...

          Updates to ISC BIND, (Sat, Mar 21st) (InternetStormCenter)

            ANSI Panel to Standardize Identity Theft Tracking (NetworkWorld Security)

              Crooks Flock to Rogue Antivirus Apps (NetworkWorld Virus/Worms)

                CVE-2008-6496 (expertpdfeditorx) (Natl. Vulnerability Database)

                  CVE-2009-1023 (phpcomasy) (Natl. Vulnerability Database)

                    Bugtraq: SECURITY DSA 1748-1 New libsoup packages fix arbitrary code execution (SecurityFocus Vulnerabilities)

                      Rogue Antivirus Distribution Network Dismantled (SecurityFix Blog)

                        Researchers make wormy Twitter attack (NetworkWorld Security)
                          Intel Chip Vulnerability Could Lead to Stealthy Rootkits (E-Week Security)

                            Romanian police arrest Pentagon hack suspect (The Register)

                              (3) MODERATE: GNOME glib Base64 Functions Mutiple Integer Overflow Vulnerabilities (SANS @Risk)

                                Why People Steal Rare Books (Schneier blog)

                                  A Search Is Launched for Conficker's First Victim (PC World) (Yahoo Security)

                                    Antivirus2009 Holds Victim's Documents for Ransom (SecurityFix Blog)

                                      Vuln: Pixie CMS SQL Injection and Cross Site Scripting Vulnerabilities (SecurityFocus Vulnerabilities)

                                        Visa: Post-breach criticism of PCI standard misplaced (NetworkWorld Security)

                                          CVE-2008-6498 (Natl. Vulnerability Database)

                                            Visa pilots new payment card security initiatives (NetworkWorld Security)

                                              Brief: Researchers aim low to root hardware (SecurityFocus News)

                                                CVE-2009-1027 (Natl. Vulnerability Database)

                                                  Latest on Conficker, (Fri, Mar 20th) (InternetStormCenter)

                                                    Flaw makes Twitter vulnerable to serious viral attack (The Register)

                                                      CVE-2008-6485 (phpimagegallery) (Natl. Vulnerability Database)

                                                        Bloginator v1a (Cookie Bypass/SQL) Multiple Remote Vulnerabilities (milw0rm)

                                                          Bugtraq: GLSA 200903-32 phpMyAdmin: Multiple vulnerabilities (SecurityFocus Vulnerabilities)

                                                            Intel chip flaw gets double exposure (The Register)

                                                              The CCTV Project Planner (NetworkWorld Security)

                                                              Tech Insight: A DIY Security Testing Lab

                                                              How to set up an in-house, do-it-yourself security testing lab

                                                              Small Business: The New Black In Cybercrime Targets

                                                              Security experts say hackers are turning away from stiff defenses of banks and large enterprises and turning toward small businesses

                                                              Indian Credit Card Fraud Exposed - Linked to Symantec

                                                              By Darknet on symantec credit card scam

                                                              In a recent undercover sting the BBC has uncovered some unscrupulous Indian chaps selling valid UK credit card details, the kicker to the story is the fraud is linked to Symantec as the people being defrauded had all recently bought Norton subscriptions. I guess it’s hard to control a 3rd party call center though and who

                                                              Webshag 1.10 Released - Free Web Server Audit Tool

                                                              By Darknet on webshag

                                                              Webshag is a multi-threaded, multi-platform web server audit tool. Written in Python, it gathers commonly useful functionalities for web server auditing like website crawling, URL scanning or file fuzzing. You may remember back in March 2008 we published about Webshag 1.00 being released. Now Webshag 1.10 has been released! This new version...

                                                              Stimulus Package Includes New HIPAA Security Rules

                                                              Posted by InfoSec News on Mar 20

                                                              http://www.aafp.org/online/en/home/publications/news/news-now/government-medicine/20090318hipaa-security-rules.html

                                                              By Sheri Porter
                                                              AAFA News Now
                                                              3/18/2009

                                                              The recently passed federal stimulus package includes changes to federal
                                                              health information privacy and security provisions under the...

                                                              Yahoo! paid for Peerbhoys training to hack networks

                                                              Posted by InfoSec News on Mar 20

                                                              http://www.hindustantimes.com/StoryPage/StoryPage.aspx?sectionName=HomePage&id=99ed5976-6d8d-4402-abe0-e43a70e1c603&Headline=%E2%80%98Yahoo!+paid+for+Peerbhoy%E2%80%99s+training+to+hack+networks%E2%80%99

                                                              [Playing connect-the-dots with this story below, e2 Labs, was started in
                                                              2003 in...

                                                              Sniffing keystrokes via laser and keyboard power

                                                              Posted by InfoSec News on Mar 20

                                                              http://news.cnet.com/8301-1009_3-10200631-83.html

                                                              By Elinor Mills
                                                              Security
                                                              CNet News
                                                              March 19, 2008

                                                              VANCOUVER, B.C. -- Presenters at the CanSecWest security conference
                                                              detailed on Thursday how they can sniff data by analyzing keystroke
                                                              vibrations using a laser trained on a shiny laptop...

                                                              Small Business: The New Black In Cybercrime Targets

                                                              Posted by InfoSec News on Mar 20

                                                              http://www.darkreading.com/security/perimeter/showArticle.jhtml?articleID=215901301

                                                              By Tim Wilson
                                                              DarkReading
                                                              March 19, 2009

                                                              WASHINGTON, D.C. -- Visa Security Summit 2009 -- Hacking banks and large
                                                              businesses? That's sooo 2008.

                                                              Hackers and computer criminals this year are taking a new aim...

                                                              A hacking tool gets updated for the Mac

                                                              Posted by InfoSec News on Mar 20

                                                              http://www.networkworld.com/news/2009/031909-a-hacking-tool-gets-updated.html

                                                              By Robert McMillan
                                                              IDG News Service
                                                              03/19/2009

                                                              Two well-known Mac hackers are updating a widely used hacking toolkit,
                                                              making it easier to take control of a Macintosh computer.

                                                              Over the past few days, the...

                                                              Chinese spy who defected tells all

                                                              Posted by InfoSec News on Mar 20

                                                              http://washingtontimes.com/news/2009/mar/19/exclusive-chinese-spy-who-defected-tells-all/

                                                              By Bill Gertz
                                                              The Washington Times
                                                              March 19, 2009

                                                              EXCLUSIVE:

                                                              A veteran Chinese intelligence officer who defected to the United States
                                                              says that his country's civilian spy service spends most of its...

                                                              Secunia Weekly Summary - Issue: 2009-12

                                                              Posted by InfoSec News on Mar 20

                                                              ========================================================================

                                                                                The Secunia Weekly Advisory Summary

                                                              RampD work vulnerable to cyber threats

                                                              Posted by InfoSec News on Mar 20

                                                              http://fcw.com/articles/2009/03/19/cybersecurity-economy.aspx

                                                              By Ben Bain
                                                              FCW.com
                                                              March 19, 2009

                                                              Cyber vulnerabilities could threaten research and development efforts,
                                                              and action is needed to stop the commercial losses caused by cyber
                                                              attacks, cybersecurity experts told a Senate committee...

                                                              Kaminsky: MS security assessment tool is a 'game changer'

                                                              Crash, bang, analyze

                                                              CanSecWest Microsoft on Friday released an open-source program designed to streamline the labor-intensive process of identifying security vulnerabilities in software while it's still under development.

                                                              Websense mistakes Cisco.com for hack site

                                                              IPs of ill repute

                                                              Websense briefly classified the home page of networking giant Cisco as a hacking site earlier this week.

                                                              Romanian police arrest Pentagon hack suspect

                                                              'Wolfenstein' cuffed

                                                              Romanian police have arrested a hacker suspected of breaking into Pentagon systems and planting malware.

                                                              Indian call centre credit card 'scam' exposed

                                                              Symantec renewal details end up on black market

                                                              An undercover investigation by the BBC has exposed evidence of the theft of credit card details by workers at an Indian call centre used by security giant Symantec.

                                                              Flaw makes Twitter vulnerable to serious viral attack

                                                              Son of Samy?

                                                              Updated Micro-blogging site Twitter suffers from a potentially devastating vulnerability that forces logged-in users to post messages of an attacker's choice simply by clicking on a link. It could be used to spawn a self-replicating worm.

                                                              Boffins sniff keystrokes with lasers, oscilloscopes

                                                              I know what you typed last summer

                                                              CanSecWest Researchers have devised two novel ways to eavesdrop on people as they enter passwords, emails, and other sensitive information into computers, even when they're not connected to the internet or other networks.

                                                              Richardson death used to bait scareware traps

                                                              Off-piste

                                                              Criminal hackers are exploiting interest in news of the tragic death of actress Natasha Richardson on Wednesday to bait scareware traps.

                                                              Intel chip flaw gets double exposure

                                                              Security researchers converge on cache vuln.

                                                              Security researchers are due to publish research on how an Intel chip flaw might be used for potentially malign purposes on Thursday.

                                                              IT contractor charged over US oil rig hack

                                                              Roughneck cracker charges

                                                              An IT contractor has been charged with sabotaging offshore oil rig computer systems.

                                                              Air France trials biometric boarding cards

                                                              Fingerprints and smart cards

                                                              Air France has started trialling RFID-equipped smartcards which store passenger fingerprints to allow automated boarding.

                                                              March Madness-related SEO Poisoning Leads To Rogue AV

                                                              By Robert A. on Worms

                                                              "With only a few days left before the tournament starts, if a user searches for popular March Madness-related terms in Google, malicious URLs as high as the first result are returned. Search terms that currently exist within the Top 10 of Google's Hot Trends (the most popular search results) return these...

                                                              Web Application Security Spending Relatively Unscathed By Poor Economy

                                                              By Robert A. on Metrics

                                                              "First the good news: Despite the global recession, two-thirds of organizations either have no plans to cut Web application security spending, or they expect their spending to increase this year. Now the bad news: Spending for security applications is less than 10 percent of the overall security budget in 36 percent...

                                                              Malware installing rogue DHCP server

                                                              By Robert A. on Worms

                                                              Sans published an entry about a new piece of malware that installs a rogue DHCP server that specifies a rogue DNS server, presumably for phishing and malware deployment. I wouldn't be surprised if this concept is fairly old but it appears to be the first time a common piece of malware...

                                                              Oliver Day: Time to Shield Researchers

                                                              Time to Shield Researchers

                                                              Brief: China more friend than foe, says white hat

                                                              China more friend than foe, says white hat

                                                              Brief: Researchers aim low to root hardware

                                                              Researchers aim low to root hardware

                                                              Mobile phones win during Pwn2Own contest

                                                              By Robert Westervelt

                                                              Hackers failed to crack mobile devices during the Pwn2Own contest at the CanSecWest conference, but a security team later demonstrated a way in with a simulated flaw.

                                                              Internet Explorer 8 includes a bevy of security features

                                                              By Robert Westervelt

                                                              Experts praise the IE 8 security features, but say browser makers have a long way to go in preventing the browser from being a hacker's favorite mode of attack.

                                                              Latest Apple iPhone features prompt security concerns

                                                              By Eric Ogren

                                                              Push notification, copy/paste and Bluetooth peer-to-peer communication features give hackers new areas to target.

                                                              Security incident response 101

                                                              By Robert Westervelt

                                                              Even the best procedures fail to overcome the stresses in the initial throes of an incident. Security consultant Lenny Zeltser explains how to run a well coordinated response.

                                                              ANSI Panel to Standardize Identity Theft Tracking

                                                              Know the difference between 'identity theft' and 'identity fraud'? Don't feel bad if you don't. Even within the security industry, within the government, and within law enforcement, the terms are used interchangeably although they are in fact different.

                                                              Crooks Flock to Rogue Antivirus Apps

                                                              Chasing massive profits, crooks have unleased a flood of rogue antivirus programs that attempt to fool or scare unsuspecting PC users into forking over cash for an app that does nothing worthwhile.

                                                              Pin Down Your Passwords

                                                              You know better. You know you should have complicated, hard-to-guess passwords with numbers and both uppercase and lowercase letters. The problem is, they're so hard to remember. As your business uses more web applications and your password collection grows unruly, look to password tools as a way to manage security for you and your employees.

                                                              Report links Russian intelligence to cyber attacks

                                                              A follow-up report authored by a group of cyber-security experts claims that Russian intelligence agencies were probably involved in the 2008 cyber attacks on Georgia.

                                                              BBC says U.K. credit card information for sale in India

                                                              Reporters from the BBC posing as fraudsters claim they bought names, addresses and valid credit card details of U.K. residents from a man the BBC identified as Saurabh Sachar in Delhi.

                                                              iWonder Surf offers managed browsing on iPhone, iPod touch

                                                              Parents concerned that their iPhone and iPod touch-touting kids might be visiting unsavory Web sites now can install an application that will help them. It's called iWonder Surf, and it's available for US$15 from the App Store.

                                                              Researchers make wormy Twitter attack

                                                              Computer security researchers have devised a new Twitter attack that they say could spread virally, much like a worm on the microblogging service.

                                                              Visa pilots new payment card security initiatives

                                                              Acknowledging the need for controls that go beyond those offered by the Payment Card Industry (PCI) Data Security Standard, a senior Visa Inc. executive Thursday described two new initiatives to reduce payment card fraud being tested by the company.

                                                              A search is launched for Conficker's first victim

                                                              Where did the Conficker worm come from? Researchers at the University of Michigan are trying to find out, using a vast network of Internet sensors to track down the so-called "patient zero" of an outbreak that has infected more than 10 million computers to date.

                                                              Security researchers hack Safari in contest

                                                              For the second year running, security researcher Charlie Miller has taken home the top prize at security conference CanSecWest in Vancouver, after successfully hacking a MacBook via Safari. Miller exploited a vulnerability in Safari that allowed him to take control of the computer by having the user click on a malicious link.

                                                              A hacking tool gets updated for the Mac

                                                              Two well-known Mac hackers are updating a widely used hacking toolkit, making it easier to take control of a Macintosh computer.

                                                              Protect Your Data With Whole-Disk Encryption

                                                              In my last post, I talked about some of the tools that claim to recover your stolen laptop. This time I want to review another series of tools that can be useful protection as well: doing whole-disk encryption of your hard drives across your enterprise. The idea that even if your laptop falls into the wrong hands, no one besides yourself will be able to read any of the files stored on it. When you boot your PC, you need to enter a password, otherwise the data in each file is scrambled, and no one else can gain access to your files.

                                                              Expert: Hackers penetrating control systems

                                                              The networks powering industrial control systems have been breached more than 125 times in the past decade, with one resulting in U.S. deaths, a control systems expert said Thursday.

                                                              Researcher hacks just-launched IE8

                                                              Just hours before Microsoft Corp. officially launched the final code for Internet Explorer 8 (IE8), a German researcher yesterday hacked the browser during the PWN2OWN contest to win $5,000 and a Sony Viao laptop.

                                                              Visa: Post-breach criticism of PCI standard misplaced

                                                              Visa Inc.'s top risk management executive Thursday dismissed what she described as "recent rumblings" about the possible demise of the PCI data security rules as "premature" and "dangerous" to long-term efforts to ensure that credit and debit card data is secure.

                                                              Is IE8 Actually Safer?

                                                              Internet Explorer 8 hits the wires Thursday with a bevy of new security features, including more protection against hacked sites, ActiveX lockdowns, and a private browsing mode. And if you're wondering whether you should get it, then here's your short answer: Yes.

                                                              Chinese high-tech spy case inches closer to trial

                                                              Did software engineer Hanjuan Jin steal thousands of confidential documents from Motorola to share with the People’s Republic of China? The strange and complex case is expected to go to trial in Chicago.

                                                              Microsoft releases IE8, stresses security

                                                              Microsoft plans to make its Internet Explorer 8 browser available on Thursday, along with a company-commissioned report claiming IE8 is more secure against malware than rival browsers from Mozilla and Google.

                                                              IE 8 released, made available on Web

                                                              Microsoft Thursday released Internet Explorer 8, the next version of its Web browser that includes a number of corporate features, including tools to customize and control the software via centralized policies.

                                                              NAC remediation options

                                                              When NAC was conceived, it had everything to do with finding out if endpoints met security checks, but not so much about what to do about it.

                                                              Researcher cracks Mac in 10 seconds at PWN2OWN, wins $5K

                                                              Charlie Miller, the security researcher who hacked a Mac in two minutes last year at CanSecWest's PWN2OWN contest, improved his time Wednesday by breaking into another Mac in under 10 seconds.

                                                              Brits stuff mobiles with risky ID data

                                                              The data stored by Brits on their personal mobile phones can be easily used for ID theft purposes, especially because of the minimal security measures they take to guard the data, warned Credant Technologies.

                                                              The CCTV Project Planner

                                                              This article provides an overview of the video surveillance system planning and implementation process, and focuses on end-user perspectives. Successful CCTV projects are difficult to accomplish. Success factors are endogenous and exogenous to individual systems. Both are equally important to understand when planning for system implementations. The best way for an end-user to find success is first to gain insight into a few key issues in the CCTV industry.

                                                              Top Internet Threats: Censorship to Warrantless Surveillance

                                                              By David Kravets

                                                              In celebration of Sunshine Week, Wired has compiled a list of top threats to the internet — ranging from censorship to warrantless eavesdropping.

                                                              Wizzywig Cartoonist Inks a Phreakin' Comic Book

                                                              By Steven Levy

                                                              Ever since Kevin Mitnick's notorious exploits of the early 1990s, commentary inspired by the dark-side hacker has proliferated like a well-crafted computer virus. There have been six books, one feature film, a documentary, and endless hagiography in the quarterly phreaker bible 2600. The latest entry in the canon: Wizzywig, a four-part graphic novel by Ed Piskor.

                                                              Why did Piskor—a 26-year-old Pittsburgh cartoonist best known for his work with cranky comic god Harvey Pekar—choose the greasy-fingered milieu of the computer underground for his solo debut? Certainly not out of technolust: He's a self-described semi-Luddite. Instead, he was seduced by the funky phreak culture. Over the course of 14 months, Piskor devoured the archives of 2600, Phrack, TAP/YIPL, and other tech prankster zines; read a shelf's worth of computer-crime tomes; and listened to the entire run (via podcast) of Off the Hook, a radio show hosted by 2600 editor Emmanuel Goldstein. In the process, he found not only a fascinating subculture but also himself. "Cartoonists have a lot in common with hackers," he says. "Both lead very solitary existences."

                                                              Wizzywig is a delight, wryly rendered and packed with dead-on details of the hacker life. Though the narrative of protagonist Kevin Phenicle tracks Mitnick's life and crimes, Phenicle (aka Boingthump) is a composite drawn not just from Mitnick but other geek malfeasants like Mark Abene (Phiber Optik) and Wired's own Kevin Poulsen (Dark Dante). Famous incidents and hacker luminaries also make Ragtime-style cameos: the 1971 Esquire article about phone phreaking, Captain Crunch's "war dialer" gizmo, and Robert Morris' 1988 Internet worm. Piskor even brings in Apple's cofounders (below), in a hilariously drawn depiction of the time the two Steves almost got busted selling blue boxes—devices that let phreakers make free long-distance calls. With the publication of volume 2, Hacker, late last year, Wizzywig is now half complete. Volume 3 (Fugitive) is pegged for late 2009.

                                                              Piskor is self-publishing Wizzywig and sells it at Edpiskor.com. He prints 100 copies at a time and spends his mornings processing orders and shipping. (It's also a kind of fitness routine: "A lot of cartoonists get really fat, so I walk to the post office every day.") By examining the PayPal paper trail, he has discovered that one of his customers is Mitnick's mother. So far, nothing from Mitnick himself. Better yet, no denial-of-service attacks on his site. The dark-siders must like him.

                                                              Gmail's New 'Undo Send' Feature Saves You From Outbox Regret

                                                              By Michael Calore

                                                              Ever say something in an e-mail that got you into serious hot water? Google now gives users a five second window to "undo" any Gmail message before it's sent out over the tubes.

                                                              First Look: IE8 Is Microsoft's First Truly Modern Browser

                                                              By Michael Calore

                                                              Microsoft has released the latest version of Internet Explorer, the most-used web browser in the world. IE8 shows significant improvements in most areas, and while it still lags behind more forward-looking browsers like Firefox, its sure to please users upgrading from older versions of IE.

                                                              I Stole My Friend's Identity

                                                              If you've not yet leapt into the great abyss of social networking, then you haven't created any accounts that can be compromised, and you're safe, right? Not!

                                                              Researchers hunting for Conficker's Patient Zero

                                                              By jhruska@arstechnica.com (Joel Hruska) on patient zero

                                                              The Conficker worm has been making headlines for several months, thanks to periodic refresh cycles that have shifted both its attack vectors and its behavior once inside a system. Part of what makes the worm unique is that it takes advantage of a security flaw Microsoft had actually patched several months prior; any system with the MS08-67 security update was immune to Conficker.A's initial attack. It's been theorized that the worm initially latched on to a relatively small group of enterprise computers with long patch update cycles; researchers are now combing through data from the earliest stages of the worm's existence, attempting to find the system or group of simultaneously infected systems that represent a digital Patient Zero.

                                                              New FOIA rules official—let the data flood begin

                                                              By julian.sanchez@arstechnica.com (Julian Sanchez) on transparency

                                                              Since 2001, the rule of thumb for government agencies responding to Freedom of Information Act requests has been "when in doubt, leave it out." A month after the 9/11 attacks, a directive from then-Attorney General John Ashcroft urged agencies to carefully consider all possible grounds for withholding information before making disclosures, and promised the Justice Department's backing for any decision to withhold with a plausible legal basis. On Thursday, new Attorney General Eric Holder reversed that order, instructing executive branch officials that "an agency should not withhold information simply because it may do so legally." The new guidelines could potentially affect a slew of pending cases concerning secretive copyright treaties, warrantless wiretapping, and military interrogation practices.

                                                              This is the way the Internet ends: not with a bang, but DPI

                                                              By nate@arstechnica.com (Nate Anderson) on network neutrality

                                                              Does deep packet inspection mean the end of the Internet?

                                                              Deep packet inspection (DPI) gear has always been marketed to ISPs as a way to earn more money by scanning Internet traffic and charging more for various services. Want to game online? Better upgrade to the "Gaming Xtreme!" plan. Want to use VoIP? Prepare to open your wallet. Watch much streaming video? Well, it would be a whole lot smoother if you just paid another $2.99 a month.

                                                              DPI vendors haven't tried to hide this; one company's marketing literature suggests that it can help "reduce the performance of applications with negative influence on revenues" (e.g. competitive VoIP services).

                                                              Chrome only browser left standing after day one of Pwn2Own

                                                              By segphault@arstechnica.com (Ryan Paul) on safari

                                                              Browser vendors often make strong claims about their responsiveness to vulnerability reports and their ability to preemptively prevent exploits. Security is becoming one of the most significant fronts in the new round of browser wars, but it's also arguably one of the hardest aspects of software to measure or quantify.

                                                              A recent contest at CanSecWest, an event that brings together some of the most skilled experts in the security community, has demonstrated that the three most popular browser are susceptible to security bugs despite the vigilance and engineering prowess of their creators. Firefox, Safari, and Internet Explorer were all exploited during the Pwn2Own competition that took place at the conference. Google's Chrome browser, however, was the only one left standing—a victory that security researchers attribute to its innovative sandbox feature.

                                                              Intel CPU-level exploit could be tempest in a teapot

                                                              By jhruska@arstechnica.com (Joel Hruska) on Trusted Computing

                                                              Johanna Rutkowska of Invisible Things Lab has been making headlines ever since she announced her development of a seemingly undetectable rootkit she dubbed "Blue Pill." While that project is now defunct, Rutkowska has continued her research into hardware virtualization technology. Her more recent efforts have focused on Intel platforms and the company's Trusted Execution Technology; Intel released a BIOS update to fix several security vulnerabilities Invisible Things Lab discovered back in August of 2008. On Thursday, March 19, Rutkowska and fellow team member Rafal Wojtczuk released details of yet another Intel-focused exploit—is the CPU manufacturer's security sandbox not up to snuff?

                                                              Save the children? ICANN opens debate on CyberSafety charter

                                                              By jhruska@arstechnica.com (Joel Hruska) on internet filtering

                                                              companion photo for Save the children? ICANN opens debate on CyberSafety charter

                                                              ICANN has been soliciting a lot of comments on its governance and future of late, including one petition to form a CyberSafety Constituency (CSC) within the Non-Commercial Stakeholders Group. (NCSG). The petition (PDF) as filed with ICANN is fairly innocuous and harmless-sounding, but the woman doing the filing—Professor Cheryl B. Preston, of Brigham Young University—has ties to other nonprofit organizations that should have been disclosed at some point within the application procedure.

                                                              Sentencing commission ponders extra jail time for proxy users

                                                              By julian.sanchez@arstechnica.com (Julian Sanchez) on privacy

                                                              I'm betting Michael DuBose, chief of the Justice Department's Computer Crime & Intellectual Propety Section, is a Steven Seagal fan. At a hearing held Tuesday by the US Sentencing Commission, Dubose warned that "cyber-criminals are increasingly using sophisticated technological tools like 'proxies' to evade detection and prosecution." Naturally, I immediately thought of Under Siege 2: Dark Territory, in which the flabbifying action hero must track down nefarious hacker Travis Dane (playwright Eric Bogosian slumming for a paycheck), who has seized control of a government satellite weapon. Just when the grim-faced folks in the government command center think they've got a lock on the hijacked bird—bang!—the screens are filled with 50 "ghost" satellites Dane has created to throw them off the trail. Proxies!

                                                              In reality, of course, proxy servers and anonymous routing are not l33t haxx0r tools, but rather a feature of modern Internet use so commonplace and banal that Web surfers in corporate or university environments routinely make use of proxied connections without even knowing it. But the Justice Department is urging the Sentencing Commission to recognize proxies as "sophisticated means" automatically meriting stiffer penalties when used in the course of a computer crime.

                                                              Internet Explorer 8 released, progress unmistakable

                                                              By emil.protalinski@arstechnica.com (Emil Protalinski) on Internet Explorer

                                                              The final build of Internet Explorer 8 has been released in 25 languages. You can also grab the download directly from these links: Windows XP 32-bit (16.1 MB), Windows XP 64-bit (32.3 MB), Windows Server 2003 32-bit (16.0 MB), Windows Server 2003 64-bit (32.3 MB), Windows Vista 32-bit (13.2 MB), Windows Vista 64-bit (24.3 MB), Windows Server 2008 32-bit (13.2 MB), and Windows Server 2008 64-bit (24.3 MB). The final build number is 8.0.6001.18702.

                                                              The public Windows 7 beta is not being updated, and although Microsoft released an update for IE8 for Windows 7 in February, the next update is not likely to arrive until the Windows 7 Release Candidate next month. For everyone else, in the coming weeks Microsoft will put IE8 out as an optional download on Windows Update and then later roll it out to users via Automatic Updates. A quick note to all the IT administrators out there reading this post: the IE8 blocker toolkit is already available, so make sure you get acquainted with it if you're planning on avoiding IE8 when it's released via Microsoft's update channels.

                                                              Connecticut Man Sentenced for E-card Scam

                                                              His phishing scheme targeted AOL subscribers

                                                              BBC Says UK Credit Card Information for Sale in India

                                                              Three of the victims had used their cards to buy Symantec software

                                                              Report Links Russian Intelligence to Cyber Attacks

                                                              Also in the report, an employee at a major North American wireless carrier is said to be part of a hacker group

                                                              E-health Records Not Enough, Experts Say

                                                              Doctors say better EHRs and better interoperability are also needed

                                                              IPod Scammer Brought up on Federal Charges

                                                              Prosecutors have just brought federal charges of fraud and money laundering against Nicholas Arthur Woodhams of Kalamazoo...

                                                              Oracle Offering Scaled-down Version of Database Machine

                                                              Oracle claims strong demand for its Exadata product line but declines to offer numbers

                                                              Crooks Flock to Rogue Antivirus Apps

                                                              The number of fake security programs pushed by the bad buys to trick victims out of their cash has leapt dramatically.

                                                              ANSI Panel to Standardize Identity Theft Tracking

                                                              In an attempt to simplify the tracking of identity theft and identity fraud for law enforcement, ANSI is working to clearly define these terms.

                                                              Firefox May Already Be Dead

                                                              With Google Chrome poised to become the new, hot open-source browser, the increasingly bloated Firefox could be in trouble.

                                                              Researchers Make Wormy Twitter Attack

                                                              A cross site scripting attack on Twitter could leave it vulnerable to a fast-spreading viral attack.

                                                              A Search Is Launched for Conficker's First Victim

                                                              The outbreak has infected more than 10 million computers to date

                                                              A Hacking Tool Gets Updated for the Mac

                                                              Hackers are making the Mac a 'first-class target' for the popular Metasploit toolkit.

                                                              Is IE8 Actually Safer?

                                                              Microsoft is touting new security features in today's IE8 release. Should you get it?

                                                              Expert: Hackers Penetrating Control Systems

                                                              One attack caused US deaths, a security consultant testified to the Senate

                                                              Security Researchers Hack Safari in Contest

                                                              For the second year running, security researcher Charlie Miller has taken home the top prize at security conference CanSecWest...

                                                              LaCie Acquires Online Storage Provider Wuala

                                                              Caleido AG, parent company of online storage service Wuala, announced Thursday it has merged with computer peripheral maker...

                                                              Cloud Provider 3Tera Announces 'five Nines' SLA

                                                              Customer accounts will be credited automatically if availability drops.

                                                              My Blog List