Your security, networking, programming, and application news source.
Google
Showing posts with label web. Show all posts
Showing posts with label web. Show all posts

Sunday, April 22, 2012

CISPA - US Internet Survalience Bill

Customers voice their opinion to supporters of the newest dangerous Internet bill, CISPA (H.R. 3523).



Cyber Intelligence Sharing and Protection Act (CISPA), also known as H.R. 3523, is not just another horribly irresponsible SOPA / PIPA. This bill focuses on a real issue, but does it the most horrible and irresponsible way possible.

CISPA is meant to lay the foundation for private companies and Internet service providers to share information with the US Government about cyber security threats. The main problems are the lack of any real definition to what a threat is, the bypassing of all existing laws to protect collection and sharing of your personal data by private companies, the lack of restriction of what information can be shared and with who, the warrant-less unrestricted sharing of data with the NSA, DHS, and other government agencies, and encouragement of heavy broad surveillance of citizens.

This bill will directly encourage private companies such as your cellular carrier (Verizon / AT&T), your operating system (Microsoft), your anti virus scanner (Symantec), and your Internet service provider (ISP) to collect huge amounts of your personal data to a level that would previously be illegal. This CISPA authority would override privacy protection laws (such as protecting of your medical records), local eavesdropping and wiretapping laws, and allow collection of almost any data based on recklessly vague "cybersecurity" purposes. This private companies would be able to collect this data anonymously without ever having to tell you they collected it or what they collected. They would be free to share the data with any company they want, possibly even selling the data, with complete immunity to legal actions such as lawsuits of criminal charges for privacy violations. They would be allowed to dump all this data on any US Government agency without requiring a warrant.

This is at the wake of the NSA beginning building the country's biggest spy center in Utah. As well as a recent NSA whistle-blower's claim that the US Government has illegally been engaged in wide spread Internet surveillance for quite some time having intercepted 20 Trillion communications and has copies of "most of your Emails". Again, illegally and therefor with no oversight, I might add.

CISPA (H.R. 3523) is another horrible dangerous and irresponsible bill that will erode all existing personal data and privacy protection laws, and give ALL your data to private companies to use and abuse under the table with complete immunity from legal repercussions.

Verizon disgustingly supports this bill. We call on you, Verizon, to change your stance away from this strong-arm theft and abuse of citizens personal data!

Verizon's letter of support for CISPA:
http://intelligence.house.gov/sites/intelligence.house.gov/files/documents/Verizon113011.pdf


More Information:

Electronic Freedom Foundation:
http://cyberspying.eff.org/

TIME Magazine:
http://techland.time.com/2012/04/19/5-reasons-the-cispa-cybersecurity-bill-should-be-tossed/



Source: Verizon Wireless Community Forum
April 22, 2012 12:00PM
(The original text has been modified for formatting, linking, and alignment.)

Some other supporters:
  • AT&T
  • Boeing
  • BSA
  • Business Roundtable
  • CSC
  • COMPTEL
  • CTIA - The Wireless Association
  • Cyber, Space & Intelligence Association
  • Edison Electric
  • EMC
  • Exelon
  • Facebook
  • The Financial Services Roundtable
  • IBM
  • Independent Telephone & Telecommunications Alliance
  • Information Technology Industry Council
  • Intel
  • Internet Security Alliance
  • Lockheed Martin
  • Microsoft
  • National Cable & Telecommunications Association
  • NDIA
  • Oracle
  • Symantec
  • TechAmerica
  • US Chamber of Commerce
  • US Telecom - The Broadband Association
  • Verizon

Tuesday, January 17, 2012

Fight SOPA and PROTECT IP

This blog would be forced offline if the currently proposed U.S. legislature is passed.

SOPA and PROTECT IP are poorly defined, easily abused, unclear bills proposed to the U.S. House and Senate with unrealistic expectations of Internet technology, which will stifle free speech and innovation while giving the U.S. Government the ability to censor the U.S. Internet and seize U.S. domain names with little reason or limitation. Enforcement of these bills would require the restructuring of many web services which would affect Internet users globally.

These bills threaten a blog like this through vague terminology lacking definitions, such as "committing or facilitating the commission of criminal violations" [of copyright infringement or counterfeit products]. "Facilitation" can often be argued as simply teaching or demonstrating how to do something. As I interpret this, any website with Hacking/Hacker/Hack in the name or topic would technically be automatically out of compliance and be at the mercy of enforcement of these laws to not permanently seize associated domain names and possibly further prosecute owners.

These bills create a largely undefined take down process that will clearly leave many types of web services, such as the free blog host here at blogger.com, unable to meet requirements. No provisions for abuse make these vague bills a prime target for more abuse than the DMCA takedown request system has historically endured.

Some other concerning areas of these bills include provisions against circumvention of such measures, which the U.S. State department funds creating hypocritical tools for doing just that, to offer citizens under [foreign]"repressive regimes" uncensored access to the internet.

Please do all you can to educate the public and urge U.S. citizens to contact their government representatives urging them to vote against these reckless bills.


Bill text PROTECT IP (Senate):
http://hdl.loc.gov/loc.uscongress/legislation.112s968

Bill text SOPA - Stop Online Piracy Act (House):
http://hdl.loc.gov/loc.uscongress/legislation.112hr3261

A Layman's examination:
http://blog.reddit.com/2012/01/technical-examination-of-sopa-and.html

History of DCMA takedown abuse:
https://www.eff.org/takedowns

How these bills violate free speech and innovation:
https://www.eff.org/deeplinks/2012/01/how-pipa-and-sopa-violate-white-house-principles-supporting-free-speech

U.S. State department funds tools to circumvent censoring:
http://www.bloomberg.com/news/2011-04-20/u-s-funds-help-democracy-activists-evade-internet-crackdowns.html

I apologize for any inconvenience. We will be returning soon.

SoCo

Thursday, December 8, 2011

Another CA Compromised

itworld.com
Lucian Constantin, IDG News Service (December 08, 2011)

<Dutch SSL certificate provider Gemnet investigates website compromise>

Saturday, November 19, 2011

[Video Link] Facebook Social XSS by Copy-Paste

Matt Jones (November 19, 2011)
(Video hosted on Facebook as public in Matt's gallery)

<Facebook Social XSS by Copy-Paste>

Friday, October 28, 2011

[Link] SQL Injection Start to Finish Example

(Moderate SQL understanding expected)

Mathy Vanhoef (October 26, 2011)

<Exploiting 'INSERT INTO' SQL Injections Ninja Style >

Tuesday, October 25, 2011

Sunday, October 2, 2011

Payload Anatomy of InMotion Hosting Defacements

The Attack


<InMotion Hosting> was hacked leaving more than 70,000 websites compromised on the weekend of September 23, 2011. One of many news articles that covered the attack:

(Article by Jack Phillips Sep 29, 2011)
<The Epoch Times: Hosting Firm InMotion Hacked, Thousands of Websites Defaced>

The Defacement


This attack appears to be a host-wide defacement. The defaced websites had hacked-by pages added to their site which credited "TiGER-M@TE":

(This is a screen shot of the defacement page, index.php )

From the perspective of the customer, there were no access, web, or ftp log entries. A file named hacked_page was dropped in to the root www directory and was propagated to all the immediate sub-directories as index.php.

<index.php contents>(pastebin.org)

Encoding


This PHP page contains only HTML and JavaScript. A close look at its contents shows that it uses some cleaver encoding in an attempt to avoid security fingerprinting, which could later allow for easy automated detection.

A common technique is to represent malicious JavaScript code in escaped hexadecimal character format, then pass that through JavaScript's unescape function at run time. First, this obscures the malicious code. With some small adjustments, the same encoded contents can be generated in many copies all uniquely different. But, with a little time one can decode the page's contents.

The unescape function decodes the URL escape character syntax as well as the JavaScript escape character syntax. The defacement page used both, one over top of the other:

found in index.php
(JavaScript escaped hexadecimal characters)

\x25\x33\x43\x25\x37\x33\x25\x36\x33\x25\x37\x32\x25\x36\x39\x25\x37\x30\x25\x37\x34

unescape's to...
(URL escaped hexadecimal characters)

%3C%73%63%72%69%70%74

unescape's to...
(The start of an HTML tag that will contain the malicious JavaScript)

<script

This is not a new technique and is easily decoded after the fact. After coding up a quick tool I was able to decode the page:

<index.php decoded>(pastebin.org)
(The decoded contents are noted in JavaScript comments.)

I've created an open source tool for decoding escaped hex, <Unescape>, so you can follow along.

Analyzing this shows that this page has five parts of interest:
  • Connection to statistics tracking service
  • Window animation and color cycling
  • A base64 embedded GIF image (not hex-coded)
  • "Hacked" image
  • Playing of an embedded Flash file (apparently for auto playing audio)

Statistics tracking


Line #33 of the <decoded page> (line #11 originally) defines the function details. This function is set as an onclick event for the "TiGER-M@TE" text. The function open three web pages when triggered, two different statistics tracking service links at <zone-h> and one Google search of "Hacked by TiGER-M@TE" through <LMGTFY (Let Me Google That For You)> The statistics at zone-h can be viewed here:

<zone-h notifier: TIGER-M@TE>

<zone-h notifier: TIGER-M@TE special=1>

Window animation


Line #40 through #133 of the <decoded page> (also line #11 originally) defines a timed script of moving and resizing the browser window in some sort of animated show while cycling colors.

Embedded base64 GIF image


Line #148 of the <decoded page> (the end of line #11 originally) contains a GIF image embedded in the page using <base64(wiki)> encoding. This appears to merely be a faded line. As we'll seen next, maintaining image hosting seems like a challenge for the defacers.


"Hacked" image


Line #183 of the <decoded page> (then end of line #15 originally) is some encoded JavaScript to add an image tag to a small image of the word "Hacked". This <image is hosted on Fotonons.ru> but the tag is crafted to fall back on <the same image hosted at BayImg.com>. This seems to highlight the perceived difficulty of maintaining image hosting during the peak of the defacement activity.

Embedded flash audio


The code inside the "mp3 code starts from here" HTML comments turned out to be the most complicated. This part was encoded in multiple layers and revealed a custom character transformation function. First the contents had some key characters escaped with JavaScript hex characters, the entire resulting contents was escaped with URL escaped hexadecimal characters, then the resulting contents was additionally escaped with JavaScript hex characters. Pealing this away reveals a dF function which provided a custom transformation decoder for decoding the accompanying section of escaped data:

<index.php decoded dF function>(pastebin.org)

This decoder merely did some basic arithmetic to each character's value. The final results start at line 200 of the <decoded page>. This resulting code adds the following flash file to the page for auto-play:

http://77.247.69.68/.../By_TiGER-M@TE.swf

The host 77.247.69.68 <resolves> to <Rackhosting.com> in Denmark. The link, with its peculiar "..." directory, seemed dead as as soon as tested.

Variable Names


The "_0x9355" style of JavaScript variable names imply that many documents where intended to be generated with unique variable names. This technique would act as an obfustication while attempting to evade fingerprinting by security applications such as anti-virus and intrusion detection services.

Summary


The index.php defacement page propagated nearly one hundred thousand times in recently compromised <InMotion Hosting> web sites display a decorative brand promotion while loading a flash file that appeared to be for audio, but was unrecovered. A statistics tracking service was used and a couple of mostly common techniques where used to obfusticate the JavaScript code in an apparent attempt to evade filtering and detection by security services.

UPDATES:

10/2/2011 - Added decoded dF function pastebin
10/8/2011 - Added open source Unescape tool.

Tuesday, August 30, 2011

DigiNotar Issued Fraudulent Google Certificate

<DigiNotar> is a Dutch Certificate Authority who issued a rogue SSL certificate to somebody in Iran on July 10th, 2011 for the domain name .google.com. This allows the certificate holders the ability to possibly carry out a man in the middle attack on most of Google's services, including GMail, Google+, and Google Docs.

DigiNotar is a wholly owned subsidiary of VASCO Data Security International. On August 30, 2011 <VASCO released a public statement> acknowledging that their DigiNotar Certificate Authority infrastructure was hacked on July 19, 2011, and was used to issue fraudulent CA's for a number of domains, including Google.com. <Some digging by F-Secure> found defacements left over from at least two separate intrusions that could be years old.

The Google Chrome browser <has an extra fine grained set of CA's with the authority to sign for Google> which is rumored to have protected Google Chrome users.

Firefox suggested revoking DigiNotar and <provides instructions for revoking the CA> in your local browser.


Fraudulent Digital Certificates Could Allow Spoofing (Aug 29, 2011)
<Microsoft Security Advisory (2607712)>

UPDATE (Aug 31, 2011):
<Mozilla pushes Firefox 6.0.1 update explicitly to revoke the DigiNotar CA>

Wednesday, August 17, 2011

Wednesday, January 7, 2009

Happiness P0wns Twitter

  About a week after the new year, <Twitter> had several high profile accounts (Tech Crunch)<taken and defaced>. Obama, FoxNews, Miley Cyrus, and Britney Spears, just to name a few, had lewd comments or questionable links posted. Miley Cyrus (Hannah Montana) had a (YouTube)<video memorial> hoaxing her death made widely public by <MTV> (who didn't fall for it).
  This event was quickly tracked back to a hacker forum called <Digital Gangster>. An 18 year old hacker calling himself GMZ took credit for the hack. He gave an interview of his account to Threat Level, who verified his story with video of his administration access.
  GMZ claimed that he merely made a dictionary attack program/script and pointed it at a popular Twitter user named "Crystal". After only one night the administrative account was cracked with the epically stupid password "Happiness". That's pretty ridiculous that the system allows such weak passwords, especially for administrative accounts, but its worse. GMZ claims that Twitter has no limitation on log-in attempts. When he realized the account he cracked was an administrative account and that he hadn't bothered using a proxy, he decided not to take any accounts himself. He merely took requests to reset account passwords and tossed them on Digital Gangster. Digital Gangster quickly deleted the related posts, but not before some quite entertaining mayhem took place.

<Wired Blog - Weak Password Brings 'Happiness' to Twitter Hacker>

Thursday, November 20, 2008

Tired of Stupid Questions People Should Have Googled?

Let Me Google That For You [dot] Com


<LetMeGoogleThatForYou.Com>

Tired of people asking stupid questions they could have easily Google'd themselves? This website generates a link for you like so:

http://letmegooglethatforyou.com/?q=turn+power+on

This link you can share with your local lazy fool. The link will show an informative animation showing how to enter their particular query into Google, click search, declare "Was that so hard?", and then show the results. Try it above!

(Requires JavaScript access to letmegooglethatforyou.com and googleapis.com)

Thursday, October 30, 2008

Almost Every Music Video Now Availible Free

  Video giant <YouTube> has been making lots of music videos available among their other user submitted videos. Using <Fire Fox> browser <add-ons> like <Fast Video Download> and automated web sites like <VideoDownloadX.com> (formerly YouTubeX.com), you can download a nice video/music collection from YouTube.

  The once popular music video cable TV station <MTV> has replied to YouTube by opening it's own video site which is likely to host most every music video produced, <MTV Music>. YouTube does host remixed and modified videos, user posted music videos, and home made videos that you wouldn't expect to find on MTV Music, but MTV is likely to have a consistent quality collection. MTV doesn't appear to openly allow downloading, but like with YouTube; if there is a will, there is a way.

Tuesday, October 7, 2008

Google Project: Obfuscated TCP

From the <Obfuscated TCP Project's Home>,

"Obfuscated TCP is a transport layer protocol that adds opportunistic encryption. It's designed to hamper and detect large-scale wiretapping and corruption of TCP traffic on the Internet."

View the <quick YouTube explanation>:

Tuesday, September 23, 2008

FLOSS Weekly

FLOSS Weekly


  <FLOSS Weekly> is an audio netcast (also known as a podcast) about 'Free Libre Open Source Software'. Hosted by Leo Laporte and Randal Schwartz, supported by Cachefly, and hosted on <TWiT.TV> (This Week in Tech). This is all reminiscent of Steve Gibson and Leo Laporte's once very popular netcast, <Security Now>.
  For many of us Security Now paved our interest in podcasts, then renamed them to netcasts. Steve Gibson coined the term netcast when podcast's copyright status came in question. Security Now caught our attention with it's early networking, encryption, and security episodes. It pioneered as one of the first semi-professional tech shows with real topics. They brought tech media away from the trend of underground bumbled garage shows battling it out against commercial fluff-tech. Fusing a respectable quality show with respectable topics.
  Security Now has slowed down in it's innovation at over 160 episodes. Pushing of products as a shows topic seemed cool when it was great new software like <Tor> and <True Crypt>, but recent plug episodes have left a bad taste in listeners' mouths.
  <FLOSS Weekly> continues this start with a different focus, open source software. FLOSS Weekly started off slow, sometimes going 2 months without a new episode, but recently has began full steam carving a schedule that is fitting of the show's title. Let the show's topics do the talking:



<FLOSS Weekly 41: DotNetNuke> - The open source content management and Web application system that runs under the .NET framework. (September 19th, 2008)

<FLOSS Weekly 40: Jeff Robbins on Drupal> - Jeff Robbins talks about Drupal the popular open source PHP/LAMP web content management system. (September 12th, 2008)

<FLOSS Weekly 39: Simon Phipps> - Simon Phipps, chief open source officer of Sun Microsystems. (September 5th, 2008)

<FLOSS Weekly 38: Asterisk> - Asterisk, an open source PBXi, telephony engine, and telephony applications toolkit. (August 30th, 2008)




See the full list of 40+ episodes and growing at <TWiT.TV / FLOSS>.

Other episodes talked about open source software you shouldn't miss. Just to name a few:

Drizzle
SQLite
CouchDB
Smalltalk / Squeak
Django
WebDAV
OpenJDK
Blender

Monday, August 4, 2008

New PHP Features Coming v5.3

<Skip to the run down>

  PHP(Wiki) is becoming a popular web development language with the recent boom of LAMP(Wiki) servers.

  In general, PHP is a script language with very similar syntax to C/C++. It uses type safe(Wiki) variables that support arrays and tuples(Wiki)(associative arrays), much like Perl and Python.

  PHP is typically embedded into HTML pages (with the .php extension) on a web server. When a PHP page is requested, the PHP content is parsed server-side and only the resulting HTML is replied to the requesting browser.

  PHP 5.3 alpha <was released>(Aug 1, 2008). Version 5.2.6 was recently released in May and was the first release in a couple years. Version 5.2.6 was mostly security and bug fixes. Version 5.3 sports the most new features and improvements seen in a long time. The expected date for a stable PHP 5.3 is mid October 2008.



A quick rundown of some new features in PHP 5.3 Alpha:

 Namespaces(Wiki) - This should allow much shorter class names and grouping flexibility.

 Late Static Binding(Example) - For some more robust class inheritance.

 __callStatic(PHP.net) -  __call is a built in class member function that allows you to define behavior for calls to non-existent member functions. __callStatic extends this functionality to static member calls.

 Lambda Functions(PHP.net) - Quick, throw away, inline functions.

 Closures(PHP.net) - Associate a list of the parent scope's variables to be imported into a function. This also make Lambda functions much more useful.

 __DIR__ - This constant will replace the commonly used dirname(__FILE__) statement to retrieve the current script's directory.

 Phar - A PHAR file is a compressed archive and can contain a complete PHP application. Similar to a Java's JAR files, a Phar file could allow large multi-file PHP scripts to be distributed and used as one, compressed, file.

 PHP goes Windows 2000 and up only

<PHP.NET 5.3 Alpha1 Release announcement>(Aug 1, 2008)

Wednesday, July 23, 2008

Wednesday, July 9, 2008

DNS Design Flaw Allows Spoofing

DNS

(July 8, 2008) United States Computer Emergency Readiness Team (US-CERT) Vulnerability notice <#800113> regarding a DNS Cache Poisoning Issue.

"It is a fundamental issue affecting the design. Because the system is behaving exactly like it is supposed to behave, the same bug will show up in vendor after vendor after vendor.", says Dan Kaminsky, director of penetration testing, at the <IOActive> security firm. Kaminsky found this flaw more than six months ago while doing non-security related research of the DNS system.

A number of software vendors released patches Tuesday, July 8th. A patch <was released>(July 8, 2008) by Microsoft, being it's scheduled update day, and a patch <was also released> (July 8, 2008) for the Berkeley Internet Name Domain (BIND) server. The <Security Focus article> (July 8, 2008) claims both Cisco and Juniper also acknowledged flawed systems (but haven't released patches).

Monday, April 28, 2008

Automated SQL Injection Mass Attack Hits IIS Websites

“Exploits of a Mom” by <xkcd>

  An automated attack against Microsoft’s IIS servers has hit some 500,000 websites. Websites affected include the United Nations, UK Government sites and the U.S. Department of Homeland Security.

  These attacks targeted Microsoft IIS servers which allow generic SQL commands that don’t require specific table-level arguments. The attack targets IIS servers which run ASP allowing them to pollute database servers in a generic way that doesn't require prior knowledge of the database's table and field structure.

  The attacking script injects malicious JavaScript code into every text field of the database. The JavaScript then loads an external script that can compromise a user’s PC. So far there have been no details about who is behind the attacks.

<Wired Blog - Massive Attack: Half A Million Microsoft-Powered Sites Hit With SQL Injection> (4/28/2008)
<Hackademix - Mass Attack FAQ> (4/26/2008)