Search This Blog

Monday, December 5, 2011

(W) Yahoo Mail users - DON'T CLICK ON THAT !!!


Here we go again with Phishing attempts to gain your username and password...

NEVER, EVER, EVER provide your username and password or any other personal information to validate an account or login.  The website or company will NEVER do this, so don't fall for something so obvious...

And yahoo can't block this ???  Can you say "FAIL!!!"

#InfoSec  #Yahoo  #Phishing




Friday, December 2, 2011

(I) VanishCrypt..Fails practical use

If you are looking for a solution to encrypt USB Devices, this new solution fails practical use.  Practical use is where a newb or greenhorn can install a tool and use it.  There is no installer, you have to run a tool to add some needed Windozs components and register an .OCX file, so only for the geeks at heart.

TruCrypt still reigns king in the encrypted USB drive space.

http://code.google.com/p/vanishcrypt/


Thursday, December 1, 2011

(R) Research on HP Printers

We have all recently read the articles on the HP printer vulnerability, but after a friend said "this seems to be a pretty targeted attack scenario..." I replied back saying.. "Not really, I discovered years ago with JetDirect printers that you can harvest data" and as another friend pointed out today even Nessus can lock up the JetDirect Print Server and interrupt print jobs..

Using the oldest trick in the book... Cough...cough.. Telnet port 80....

You can obtain data from HP printers easier than easy..

HTTP/1.1 400 Bad Request

Connection: close

Server: HP HTTP Server; HP Officejet Pro 8600 - CM750A; Serial Number: CN19T1K0W

V05KD; Coulomb_pp Built:Wed Sep 07, 2011 11:21:09PM {CLP1CN1136AR, ASIC id 0x00320104}


Yup... Now if you read this from a simple telnet query, you can grep what you're looking for and know exactly what firmware sploit to throw at an HP printer..


Not targeted, just plain stooped to serve up so much info...


HP... Epic FAIL !!!!



Taking a Blogging break.. Not by choice.. By IOS 5 upgrade

IOS 5 has broken all my iPad Blogging Apps, so until they work again I am on a 'Blogging Break'.. Or is is 'Break Blog'?

I could use a browser... but seriously, why should I have to?

#BlogPress #Blogsy #Blogger+

Tuesday, November 22, 2011

(I) LastPass users MUST take this challenge, how strong are your passwords?




If you are a LastPass user, then the LastPass Security Challenge is a must do. You can email your results to your colleagues and have a contest of who can get the highest score. It shows you how many duplicate passwords you have in your vault along with The strength of each and links to change them.

LastPass Security Challenge

#InfoSec #LastPass

Monday, November 21, 2011

(I) LastPass adds Google Authenticator option for your phone

LastPass has added the option to use your Smartphone as your second factor authentication token. Very nice option for those of us that have iDevices, Android or BlackBerry... For those that use some other cell phone... You can use YubiKey or a USB thumb drive and the Sesame option.

Wednesday, November 9, 2011

(I) LastPass adds Google Authenticator so your phone adds 2 factor Auth

If you are a LastPass user or thinking of sing LastPass as your password manager, which I highly recommend... They have added the option of using your smartphone with the Google Authenticator app as your 2nd Factor 'something I have' authentication. Now your password vault can only be opened if you have your phone and enter the Google Auth code from the App... Very kewl LastPass!!

Friday, October 7, 2011

Two Greats in InfoSec and technology passed this week




Dr. Eugene Schultz, a famed Information Security expert passed away suddenly this week. For those that met Gene or had a chance to hear him speak, you are one of the lucky ones. I had the opportunity to talk with him on many occasions. Dr. Schultz will be missed and there is no doubt many people got into Information Security because of what he shared over the years.

Rest securely Gene!!!



Steve Jobs, a genius and technology revolutionary also passed away this week. Steve helped create the Apple or Windows debates and that has led to an improvement to security as well. I used to say, "Just look at all the applications you see in Computer City, Incredible Universe and CompUSA". Windows was clearly the winner... Not so fast... The App store through Steve's genius clearly now shows Apple has won the most available apps game, and yes Apple systems are far less exploited than Windows systems and thus more secure.. Yup I said it.. Apple shtuff is more secure.

Rest well Steve, you changed the world!!!

#InfoSec

Tuesday, September 27, 2011

(W) So you think you are clever and anonymous when using anon proxies and VPN?




Are you one those people that hide your Internet activity by using anonymous proxies or an anonymous hidden secret VPN solution?

Think you are truly secure and obscure? Think again..

A web proxy service has come under fire after a federal indictment revealed that the company cooperated with U.S. authorities in their investigation into the hacking of SonyPictures.com.

HideMyAss.com, a VPN service that encrypts one's traffic to enable users to surf the web anonymously, was ordered by a U.K. judge, at the request of FBI agents, to release log information about an Arizona man who was arrested Thursday for his role in the Sony intrusion.

SC Magazine article

#InfoSec

Monday, September 26, 2011

(I) Card Key system updated by the vendor - research to continue




We received updated hardware and software from the vendor we are working with from the original vulnerability/exploit and setup this Testing configuration in order to test and verify any improvements the vendor integrated into the new hardware and software.

It is a simple emulation of a Card Key reader that triggers a buzzer when the user is authorized to enter. The buzzer is clearly smaller than an actual door lock..

It works like a charm, the Cards were added, given permission and tested to open the door, aka sound the buzzer for 5 seconds to emulate the door unlock period.

Stay tuned as we continue our testing on the update or attend one of the two InfoSec conferences where we will be presenting.

HouSecCon 2011 - Houston Nov 3rd

Security BSides DFW 2011 - Dallas Nov 5th

#InfoSec #keycard #cardkey

Wednesday, September 21, 2011

(W)(I) Do you store email on your Cloud email provider servers?




If you are like most of us today, we all use and rely on Internet email and especially those that are browser based like Gmail, HotMail, Yahoo mail and others.

Do you also store information you would consider 'confidential' like Health, Financial and photos of yourself?

Recently Kunis Scarlett Johansson, Christina Aguilera, Lady Gaga, Miley Cyrus and High School Musical's Vanessa Hudgens have all had pictures stolen from their emails and smart phones because they stored these pics in the cloud and probably had easy, discoverable or guessable passwords.

If you do store confidential data in the cloud, you should seriously consider long and complex passwords and a password manager like LastPass to remember the passwords and URL's and make it easy to keep track of all those websites we have to login to these days.



#InfoSec #LastPass

(W)(I) Your GM OnStar enabled car will rat you out starting Dec 2011




Yup.. GM cars with OnStar will start in Dec 2011 sending critical data to GM whether you want to or not... So if you are going too fast, get in a fender bender, don't use your seatbelt or various other items, GM will provide this info to Insurance companies, law enforcement when asked and send you service notices, without you 'Opting in' to the program...

So now your GM car is a 'Dirty Rat'..

PacketStorm article on GM.. You Dirty Rat..

#InfoSec #OnStar

Thursday, September 15, 2011

(I) BackTrack 5 Wireless book now available




Vivek Ramachandran has written a beginners book for BackTrack 5 WiFi Tools that is a must read for new or seasoned InfoSec Pros that want to learn about this Live CD Tool that should be in every InfoSec and Forensic Toolkit.

Hacker News article



#InfoSec #BackTrack

Friday, August 26, 2011

(W)(I) Care to know how many malware samples go to an AV vendor per day??




Anti-Virus vendor Sophos just released their "Mid-year 2011 Security Threat Report" and stated the following...

"Since the start of 2011, we've seen 150,000 malware samples ever day. That's a unique file almost every 1/2 second, and a 60% increase as compared to malware analyzed in 2010. We've also seen 19,000 new malicious URL's each day in the first half of this year. And, 80% of those URL's are legitimate websites that were hacked or compromised".

If this doesn't surprise and spook you into improving YOUR Internet surfing and use behavior, like I promote with 'Don,t Click on That', then you WILL be one the statistics above.

Safe Surfing... Errrrr Good Luck on the InterWebbings !!!!



Sophos Mid-year 2011 Report

#InfoSec

Monday, August 22, 2011

(I) Facebook publishes a Security Guide - a MUST read




This is a MUST read for all Facebook users young and old! This 14 page guide will explain many of the ills of being a Facebook user and some things you can do to protect yourself.

And be sure to add "Web of Trust" (WOT) to your browser to show you safe and bad links within FB messages... Don,t Click on anything that is NOT green!!!!

A Guide to Facebook Security (PDF)

#InfoSec #Facebook

Thursday, August 11, 2011

(I) FireCAT - Security Audit extensions for your browsers




Here Kitty Kitty...This is swEEEt! Ever want a list of all the security related extensions for FireFox and Chrome?

Well FireCAT is it! Download the local HTML files and have a nice browsable index of security audits browser plug-ins and add-ons.

FireCAT website

#InfoSec #FireCAT

Tuesday, July 26, 2011

(T) Ethical Hacker Video Training - FREE




Want to learn some Ethical Hacker skills? Thanks to the folks over at Logical Security you can. View over 25 hours of videos on CEH training - FREE!!!!!

LogicalSecurity CEH Training videos

#InfoSec #LogicalSecurity #CEH

Monday, July 25, 2011

(I) check out a collection of info on recent Hacks.. CNET Hacker Chart







Very kewl... CNET has compiled info on recent hacks... It shows when the hack occurred, the type of hack, who got hacked and by whom, lost IP and other info and links... Very handy.

CNET Hacker chart - Google Doc

#InfoSec #CNet #Hacks

(I) Want to see how websites track you graphically?




Ever wonder what websites track about you and how they are related? Now you can with these two Firefox add-ons.


Ghostery website


Collusion Toolness website

Thanks Steve Gibson for these!

#InfoSec #Ghostery #Collusion #SGgrc

Thursday, July 21, 2011

(I) Microsoft Forefront Event Log ID's







If you are a Microsoft ForeFront user and want to know an undocumented Event Log item, here you go...

You can setup email alerts and get flooded with un-actionable information, or tweak the settings to reduce the noise, which you should by the way.

But what about those of us that use SEIM or logging solutions? You can find some event ID's in TechNet, but here are two that you really need that are events you should take action on...

3007 - Forefront Endpoint Protection Alert: Malware Outbreak
3009 - Forefront Endpoint Protection Alert: Repeated Malware Detection
3010 - Forefront Endpoint Protection Alert: Multiple Malware Detection

Ignore EventID '3006 - Malware Detected' as it is just noise and not actionable as the AV client acted upon it, the three above are what's actionable.

Look for these two events from the source Fepsrv or use Wevtutil.exe to query your servers event logs for these two events.

Wevtutil qe "Forefront Endpoint Protection" /q:"*[System[(EventID=3009 or EventID=3010)]]" /r:system_name /f:text

Or look for events in the last 24 hours:

Wevtutil qe "Forefront Endpoint Protection" /q:"*[System[TimeCreated[timediff(@SystemTime) <= 86400000]]]" /r:system_name /f:text

43200000 - 12 hours
86400000 - 24 hours
129600000 - 36 hours
172800000 - 48 hours
604800000 - 7 days
2592000000 - 30 days

You can pipe it to a file ">file_name_AV.log" if you want to as well.

If you see them, take action, these are bad offenders getting repeated malware of the same kind or received multiple malware at once, either way these systems need some attention. Are they Administrators? I recommend a re-image, if not then maybe a deep scan. Create a process flow that your admins can follow when alerts occur and consider having the Forefront alerts send an email to your Help Desk solution to automatically open tickets for these items, ignore the 'a user has Malware' alerts and set 'Malware Detection Alerts' to 'Medium' to reduce some noise.

Logs have good data you can act upon if you look, find what you want and parse it out so what you see is actionable... Not hard if you do a little prep.

#InfoSec #ForeFront #eventlogs #Wevtutil



Wednesday, July 20, 2011

(I) Want to force all Internet sites to use HTTPS?







If you want to make sure your web surfing always uses and forces websites to use HTTPS (encrypted connections) to prevent ne'er-do-wellers from sniffing your surfing, logins and other info you might enter while using the InterWebbings.. Then use FireFox and add EFF's add-on 'HTTPS Everywhere' and poof! If a site has HTTPS, this little add-on will force it to use HTTPS... Handy, oh yeah.. Donate them some $$$$, they fight for our Internet rights!!!

EFF website download

#InfoSec #EFF

(W) If you see this message while Googling.. Your screwed !!!




If you see this message while searching for something on The Google.. You're screwed and your computer needs to have Windows re-installed.

Google now looks for certain types of behavior from clients that indicate a system is infected with Malware, if you are,The Google will popup the above message and tell you. Only in your browser, so if you see an email with this message.. WARNING WILL ROBINSON.. It's malware via email trying to get you to click on that.. And we all hopefully know.. 'Dont Click on That!'

If you do see this message, then your system needs a rebuild! Plain and simple, don't pass go and try to 'clean' your computer, the fact you are infected and see this message means your system is not security worthy and other problems most likely exist.

So what do you do? Read my article "Top 10 Tips - If your Windows PC or an account has been hacked" and rebuild your system with these tips to avoid future issues.

Thanks Google!

Brian Krebs article on the Google warning

#InfoSec #Krebs #Malware #Google

Thursday, July 14, 2011

(I) Microsoft to block common passwords for HotMail users







Hard to believe that Micro$oft of all people is taking the lead in such an obvious area as passwords. With all the password breaches Micro$oft feels it is time to block many of the more stoopid passwords that people use.

List of Top 500 worst passwords

For years we have been Whitelisting (allow) and Blacklisting (block) websites with web proxies in the corporate world, it is obvious to implement a blacklist for known bad passwords as well. Frankly, EVERY Internet facing website should implement this feature to not just protect your users, but improve customer service. How is at you say? Well, if you are suffering from a brute force attack that either creates a DoS situation locking out thousands of your users, because you know they use crappy passwords and locking out their account to keep it from being breached is the best option.. Sucks, but the best option. Unless you want to force two-factor authentication on your users, forcing them to use stronger passwords so you can ignore typical brute force web based attacks is the best low cost solution you can do.

Many web and email proxies and web filtering solutions like OpenDNS and Norton Online Family use blacklist providers to block users from going to well known bad sites and email senders.

This is an easy solution to implement and I would hope Micro$oft would use their reason (too many p0wned accounts.. Aka too many customer support calls and emails) to implement common password blocking into a service that we all can use and access, just like URL Blacklists..

Your ability to create ridiculous and easy passwords is coming to an end... Start considering using solutions like SuperGenPass, LastPass, PasswordSafe, RoboForm and other password managers to avoid this issue in the future.

Come on FaceBook, Twitter, Gawker, Sony... The list is endless.. Get a clue from... I can't believe I am going to say this... Microsoft and implement common stoopid password blocking!!!

Article on MS HotMail common password blocking

#InfoSec #HackerHurricane

(I) New MetaSploit Book and PDF deal - a MUST have !!!




Pentesters and InfoSeek Geeks take note.. This is a serious deal on the hottest InfoSec topic. You get the new MetaSploit book AND PDF (iPad yeah) Use the code 'REDTEAM' and get a $19.98 discount !!!

NoStarch website to order the MetaSploit book deal

#InfoSec #MetaSploit

(I)(W) Pwnie device can split your network in the palm of your hand




Just add a touch of Social Engineering and add this to any location, plug it into a wall jack near an ethernet jack, or use the WiFi version if you know or cracked the key. Install by a printer or under a desk would work best and you can start assessing and exploiting a network.

I can tell you from years of experience it would be trivial to get this device installed and talking out a corporate or government network.

This little PC in a brick the size of a power supply packs a punch of tools. The 'Standard' device comes with the following loaded:

:: Includes "Plug UI" for simple web-based setup
:: Tunnels through application-aware firewalls & IPS
:: Sends an SMS message when SSH tunnel is activated
:: Preloaded with Ubuntu, Metasploit, SET, Fasttrack, SSLstrip, nmap, dsniff, netcat, nikto, nbtscan, scapy, ettercap, JTR, medusa, & more!
:: Unpingable and no listening ports in stealth mode


For $320 USD it is cheap for the capability. They also make a Wireless version and 3G version as well and have accessories, which include stickers to make it look like an air freshened or printer power brick.

This is one KEWL Pen Test Do-Dad

Send me one Pwnie.. Pleeeeeaaaassseeeeeee

#InfoSec #HackerHurricane #Pwnie