Trends from the trenches of Internet traffic. Hackers, spammers and Internet abuse. IP address database. DNS sightings. Views and opinions expressed are my own. ~ Teri Radichel @teriradichel
Tuesday, March 06, 2007
Ebay vs. Romanian Hacker
http://www.eweek.com/article2/0,1895,2100808,00.asp?kc=EWSTEEMNL030607EOAD
Of interest are the various tactics ebay is using to thwart this criminal which go beyond simple tactics to more complete analysis of hacker activity ...a trend in the industry which has long been needed over an above simple firewall rules and was the reason I started writing this hacker / Internet security / Internet service blog.
More analysis of specific hacker activity by humans, not machines, will help determine traffic and activity patterns to block out attacks better than any firewall rules. It is a constant, on-going effort at mutliple layers from network to firewall to OS to application - it is not a simple one time fix.
Sunday, March 04, 2007
Hacker in Japan
203943 BLOCKED a2ge8iqi9mcec Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203942 BLOCKED 1trlwusqdgvg5 Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //Ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /Ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203941 BLOCKED 4tnft3pc3kubt Sun Mar 04 09:24:50 PST 2007 203.143.125.226 //phpads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /phpads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
..repeat about 50 times
A bunch of IPs requesting stuff we don't host
74.118.71.252
124.50.43.214
60.217.227.135
210.191.147.120
203.165.129.2
210.6.97.244
They all hit our site at the same time requesting things our server does not host.
Here's another set shortly before doing something similar, probably also related to the above:
195.49.188.202
71.63.100.55
210.245.147.241
218.233.57.23272.145.6.47
218.48.127.177
71.63.100.55
210.245.147.241
218.233.57.232
Perhaps someone pointed a domain to the wrong IP since they were all hitting the same domain.
These IPs are all requesting php files -- the favorite language of the hacked and hackers as far as I can tell by the percentage of hacks in the logs on various types of web programming and scripting languages.
Wednesday, February 28, 2007
253-719-0012
I figured out what this number is. I got an electronically placed and recorded call from Comcast.
When you put this number in Google however you get a ton of nasty hacker information.
Interesting.
Tuesday, February 20, 2007
Defender Technologies, DefenderHost.com - Hacker Source
OrgName: Defender Technologies Group, LLC
OrgID: DTGL
Address: 44470 Chilum Place, Building 1
Address: Suite 1197
City: Ashburn
StateProv: VA
PostalCode: 20147
Country: US
NetRange: 69.65.96.0 - 69.65.127.255
Inhoster - bad bot source
This is the latest blatant abusing network:
inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
country: UA
Saturday, February 17, 2007
Related Hacker IPs
Time of hack attempt: 2/17/07 21:42:33
65.184.191.13
211.213.118.32
75.34.23.14
212.119.45.138
71.83.46.82
12.206.187.108
59.95.212.177
In addition this IP was in the middle of this looking at another site:
89.150.197.192
Friday, February 16, 2007
Message Guard - Network Solutions
This is the typical message I get from other people when I try to use Network Solutions Message Guard to send them emails:
_______________
I do not have time to go do all of these steps to read the email. It takes over 5 minutes to complete this. I am the only one here in my department and this is very time consuming. Can you please just send me a regular email.
_______________
Until this is fixed, this is not a viable solution for every day use between two parties that are not both using the same service. I thought the idea was that the person only has to go through the steps one time...
I also asked Voltage Security how they guarantee that someone at their location is not able to decrypt and read the email - what policies and auditing do they have in place - and as of yet no response.
Monday, February 12, 2007
Catepillar, Inc. really Interested in Australia?
12.2.142.7
Arrival Communications - Hacker
There appears to be a hacker at arrival communications on this IP 69.84.207.35 targeting one of our real estate web sites.
They hit our contact request form about 70 times in one day.
Shortly thereafter the publishing of the site was altered, but we were able to easily republish.
OrgName: Arrival Communication, Inc
OrgID: ARRV
Address: 5100 California Ave Suite 104
City: Bakersfield
StateProv: CA
PostalCode: 93309
Country: US
NetRange: 69.84.192.0 - 69.84.207.255
Identity Based Encryption - Update
The latest is that I just had to re-authenticate to send a message and I'm not sure why. Is this an on-going thing where you have to re-authenticate on a weekly basis?
The other thing to note is that I bought the service from Network Solutions and it is authenticating on the Voltage Security system.
Wednesday, February 07, 2007
Reverse Load Testing
http://www.networkworld.com/news/2007/020707-hackers-slow-internet-root-servers.html?nlhtsec=0205securityalert3&company=
The engineers are "scratching their heads" wondering why the attack was performed.
I can think of a few reasons.
1. Reverse load testing. Hackers are trying to calculate what it will take to bring down the Internet. Bringing down the Internet could cause a myriad of disruptions that might be beneficial to a myriad of sneaky, slimy people.
2. Bringing down the Internet at a particular time when a certain crime is being committed may prevent certain communications which may then alert the authorities or warning systems to the crime underway.
3. Someone wants attention.
4. Some really flawed programming.
5. Mischief.
Tuesday, February 06, 2007
Identity Based Encryption (IBE) - Trial
As supsected a few people were skeptical of the email and didn't want to open it until I called them since it doesn't look like your typical email.
I also had a few people have problems with it including:
#1 my boss couldn't open it on his cell phone - didn't work at all. Also he didn't want to "sign up for an account" even though I explained that's not what it is.
#2 Someone on AOL couldn't open it at all.
#3 One of my customers using Electric Mail and also I think another provider could not open the message. She tried a few different times today...going to have to call tomorrow and see if we can figure this out.
#4 Couldn't respond to tickets to my data center which is a pretty big hosting company. They have an automated system and the message came as an attachment which was then not included in their automated messaging system.
#5 I was told after asking if I could use it on a web server to send messages that it only works in Outlook - after I told them I was using Outlook already so obviously I know that. So you can't sign up for this and then send secure messages in an automated fashion to potential clients, for instance, or email receipts from an e-commerce web site or links to file downloads, etc.
A few things to resolve here...it's not quite as simple as normal email and obviously doesn't work for all scenarios.
Monday, February 05, 2007
PHP: Most Requested URLs by Hackers
Per our records, PHP is far and away the most attacked language - and we don't even host it.
These are the URLS various hackers have been scanning our boxes for in the past few months:
/phpAdsNew/adxmlrpc.php
/index.php
/profile.php
/cmd.php
/Ads/adxmlrpc.php
/register.php
/thisdoesnotexistahaha.php
/stats/cmd.php
/portal/cmd.php
/adserver/adxmlrpc.php
/adxmlrpc.php
/a1b2c3d4e5f6g7h8i9/nonexistentfile.php
/phpads/adxmlrpc.php
/web/e-commerce/database/index.php/administration/module/module/index.php
/portal/cacti/cmd.php
/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
/blog/xmlrpc.php
/cacti/cmd.php
/drupal/xmlrpc.php
/web/phpMyAdmin/main.php
/web/phpMyAdmin/main.phpmain.php
/w3c/p3p.xml
/_vti_bin/_vti_aut/author.dll
/admin/login/index.php
/admin/pages/index.php
/admin/pages/settings.php
/admin/start/index.php
/public.php
/web/.../work/index.php
/web//work/index.php
And here are the IPs that have been up to this mischeif along with number of hits:
39 213.186.50.160
25 62.39.119.241
24 208.72.168.27
16 64.208.172.181
12 216.218.196.210
7 206.169.110.66
4 203.121.69.154
3 212.145.93.63
3 81.196.150.45
2 89.110.131.89
2 74.6.74.225
2 72.10.45.38
2 212.8.197.79
2 212.138.64.171
2 125.248.244.131
1 195.175.37.6
1 195.175.37.71
1 200.88.125.9
1 200.88.223.98
1 212.138.64.172
1 212.138.64.175
1 212.138.64.179
1 125.244.164.69
1 62.150.130.26
1 216.129.105.149
1 72.3.139.176
1 72.30.252.98
1 74.6.71.59
1 74.6.72.189
1 74.6.72.225
1 80.95.160.188
1 64.28.23.49
1 82.114.68.194
1 85.214.45.212
1 86.145.147.223
Friday, February 02, 2007
Identity Based Encryption - mail forwarding
I have one account set up to forward to the other.
I sent from account A to account B.
Then account B forwarded the IBE message to create a key back to account A.
I was able to create the private key on my computer by creating a login - using a different email address than the one the email was sent to. (I was in account A - the one that sent the message).
When I went back to the email in my webmail based email account B I had the key on my machine and was able to read it even though the email address I entered when I created the key for was not the email address the mail was sent to...
Also about 5 minutes later I was forwarded the test message from account B back to account A and was able to read it without doing anything else.
Seems a bit odd. Not sure the implications of this on secure email. I will have to think this one through a bit more.
Tuesday, January 30, 2007
Identity Based Encryption
I recently asked Voltage Security about their IBE product to explain some of the problems they would have to overcome to create the encrypted email solution they propose on their web site. Most of their answers sound pretty good, except I still have questions about #5 noted below.
They also sent me a sample message so I could see how their product works. I received a secure message with a graphic button that was blocked by our mail scanning/security products and an attached html file. When I click the button to retrieve the message I have to create a user name and password to read the message and get the private key to read the message. I can see this working for internal organizations but when sending information to potential customers - I can imagine some of them not understanding what this is or being apprehensive about filling something like this out or clicking on an html attachment from a vendor they never heard of or have not worked with before - at least until and unless people get used to this concept. This may be a good solution for internal organizations however, if you trust the vendor of this technology of course and have had your own technical gurus look into the actual details. I am not an encryption expert. I am only looking at the process of getting the mail encrypted from A to B. I cannot say whether the encryption is not decryptable by the company selling it to you, for instance. But here's the scoop on the process:
Once the recipient of an IBE email receives a key they no longer have to get the key for future messages. What happens if they use a different computer?
When a person moves to a different machine, the key is then fetched again from the key server for future and past messages. There is no limit on how many keys one user can fetch as long as they properly authenticate each and every time.
What happens if they log on to web mail on a public computer in an Internet cafe? Is their private key downloaded there for future users of that machine to potentially exploit?
In a public web mail instance, they would be using ZDM, that only caches a stateless cookie that can be set to expire to meet your internal security policies. Also, once an end-user “logs out”, the session cookie is terminated, mitigating any security threat by reading secure email on a public machine. By default, there is a configurable 1 hour session timeout in case the user forgets to logout. Our ZDM cookie security has been fully vetted/tested and is currently in use by several large banks, health organizations and retail companies.
What if someone can steal the private key from the recipient’s machine - since authentication only happens on the first email they could basically read any email after that point if they have the key?
One key is only good for less than 1 week. They would only be able to read secure messages for that one user that fall within that one week session (it’ll most likely be less than half a week). We can utilize any authentication method – email answerback, or one email to prove who you are, is a highly usable, widely used industry standard (see Amazon, Yahoo, Microsoft, banks, etc) but not the most robust authentication standard. We support two-factor authentication, Windows Domain authentication, and different groups of users can be forced to authenticate by different means. The encryption method is tied down to one authentication method, giving you the flexibility to meet your security needs for secure communications.
How does IBE work with email addresses and accounts sending mail from a web server to another address, such as an order receipt?
If you are talking about automated emails, the messages must simply flow through our Voltage SecureMail Gateway, and it will encrypt using the designated recipients individual email address. Nothing special has to happen to encrypt this type of mail flow.
IBE encrypts mail from me to the person I am sending the mail to – what happens when they reply? Is that message sent unencrypted back to me? So if I have my mail encrypted so support people at my mail provider cannot read my outgoing mail, then the customer replies back to me – and my mail is unencrypted coming back from them – so it doesn’t really help? Or…is the mail back encrypted as well even if that person isn’t using IBE?
If they reply to a secure message using our integrated desktop client or ZDM, then you can force the reply or forwarded message to be secure (called “Secure Conversation”). If they don’t ever decrypt the message and simply reply to you, then your message is sent back still in its encrypted form.
My follow up questions to the answer above:
If they do decrypt the message and reply – then is it sent back unencrypted if they are not using IBE themselves or one of your products?
Scenario:
A person comes to our web site and requests product info. We send a secure encrypted message. They are not using any of your products or IBE. They open and read the mail, hit reply and send us back a question. They have outlook or their webmail system set to include the original message in the reply.
Is all our initial information now unencrypted in his reply as it travels back to us? Or once they go through the steps to decrypt the mail are they now using ZDM?
Also what if that ZDM cookie expires? Then when they reply to the message is it sent back unencrypted? Or do they have to log back in each time they read the message to get the cookie?
Hurricane Electric
I have been writing about hackers at Hurricane Electric since the beginning of this blog and their potential connection with a group of hackers in Alaska. More proof:
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Friday, January 26, 2007
Identity-Based Encryption
This works by authenticating the email recipient based on their email address the first time they recieve an email. They are given a key and after that they can read all emails based on that key.
My questions in this case are (still resarching):
- What if someone steals their private key? Can they read all the email?
- What if the person moves to another machine that does not have the private key - will they be unable to read their mail?
- What if someone logs in at an Internet cafe to read webmail - is the email they download encrypted and will they get a new private key? In this case will the private key potentially be stored on the Internet cafe computer for abuse by future users of that machine?
It sounds really good...but will have to try it out to see if it actually works in all reality. I'll let you know... probably some encryption and verification is better than none but not sure how foolproof this is.
Another interesting idea would be to verify that the person downloading the mail to read it is contacting a server defined in the SPF records for that domain, otherwise the server storing the mail for download is not legit. Haven't thought through how this could be implemented nor do I know if this is already part of SPF, to be honest.
Identity Based Encryption
Addendum:
I did some additional research and got answers to these and other questions in this Identity Based Encryption Post: http://randominternet.blogspot.com/2007/01/identity-based-encryption_30.html
Thursday, January 25, 2007
Storing Credit Cards
http://www.eweek.com/article2/0,1895,2085390,00.asp
There are services that have been in business for years that specialize in keeping this data safe and allow transactions on stored credit card information through PCI compliant mechanisms.
Monday, January 22, 2007
Cybercrime More Profitable than Drugs
Apparently it is true according to a white paper from MessageLabs.
I warned recently of the need for security in programming frameworks, suggesting that just because you are behind a firewall doesn't make you "safe" from all the world.
This whitepaper also hammers this point home talking about phishing attacks. If someone can weasel one piece of spam through and get one of your 800-20,000 employees to click on the wrong link...they may be able to open the floodgate to all your corporate data.
One recent article I read on top security practices suggests encrypting - everything. Hard drives, databases, etc. Plus you need a good key management system in case someone loses their password or means of encryption and needs to reverse it.
But the point here is - email is the doorway hackers are trying to crack. And just becuase you don't see it - think again. They are pretty sly. Virus programs embedded in malware so the more obvious hacks are wiped clean, monitoring logins so when you login they vamoose, using students at Universities, disguising themselves as harmless but annoying bots...
Here's the white paper regarding the latest email attacks and IT security:
http://reg.itworld.com/servlet/Frs.frs?Context=LOGENTRY&Source=eTEXT0104hm&Source_BC=7&Script=/LP/10011793/reg&code=MSGPSA0122
Sunday, January 21, 2007
Google Imposters
64.202.165.132
OrgName: Go Daddy Software
OrgID: GDS-31
Address: 14455 N Hayden Road
Address: Suite 226
City: Scottsdale
StateProv: AZ
PostalCode: 85260
Country: US
NetRange: 64.202.160.0 - 64.202.191.255
CIDR: 64.202.160.0/19
NetName: GO-DADDY-SOFTWARE-INC
72.232.194.66
NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07
72.14.75.44
ISP Alliance, INC. ZCORUM (NET-72-14-64-0-1)
72.14.64.0 - 72.14.127.255
Millry.net MILLRY (NET-72-14-75-0-1)
72.14.75.0 - 72.14.75.255
___________________________
66.102.66.148
OrgName: Cingular Wireless
OrgID: CINW
Address: Cingular Wireless, LLC
Address: 12555 Cingular Way, Suite 4360
City: Alpharetta
StateProv: GA
PostalCode: 30004
Country: US
NetRange: 66.102.160.0 - 66.102.191.255
________________________________
66.102.186.15
OrgID: INKG
Address: 177 Wellington Street
Address: Suite 302
City: Kingston
StateProv: ON
PostalCode: K7L-3E3
Country: CA
NetRange: 66.102.64.0 - 66.102.95.255
__________________________________
217.160.230...
inetnum: 217.160.224.0 - 217.160.239.255
netname: SCHLUND-CUSTOMERSdescr: Schlund + Partner AGcountry: US
Saturday, January 20, 2007
Windows Defender - Cool Feature
Windows Defender has a feature that is pretty cool. I don't know if they added it recently or I just missed it but it really helps pinpoint the nitty gritty of your network traffic.
If you do a netstat in a command window you can see a bunch of IP addresses and ports and try to figure out which apps are generating which of those lines of traffic - and it is a pain.
Windows Defender has a section that tells you which programs and services are connected to the network, as well as the end point IPs and ports.
For example you can see a program xyz and the local IP is your local ip address connected on port 52345 and the remote IP is IP 72.34.53.232 (randomly picked this out of my head) on port 80 (which you know means you are connected over HTTP probably to a web site but possibly to something else.
Then you can look up those IPs on DNSstuff.com or in the appropriate databases: arin.net, lacnic.net, ripe.net, apnic.net, afric.net to verify that the process claiming to be the Google Toolbar update checker is really going to a Google IP address.
Pretty cool and much needed...if you've been following this blog for the life of it back to the day when I was complaining about this problem with Windows (and reporting it to a guy that I know is in contact with Bill Gates.) Could I have made a difference? Who knows...I am just happy to see it.
What would be even more useful now (maybe it is there) would be to log all this traffic because I have a feeling hackers are monitoring logins and web sites and they know, for instance, when someone is remotely connected to or logged into a machine, when an app has been updated, and then they wait for you to get off and fire up their nasties. So whenever you look on the machine - it's clean. You never see a problem real time.....so that would be the next logical step. I'll have to do some research to see if it's in there already.
Friday, January 19, 2007
Match.com Scam
So anyway her latest move was to try match.com. She met this "terrific" guy. He sent her a picture - he was a gorgeous black man - supposedly a model from California now on assignment in Africa. Nigeria, to be exact. Anyone involved in Internet security already knows where I am going with this...
He has this match.com profile which is PERFECT. I like walks on the beach, holding hands, watching the sunset...cuddling. Ahem. Ha! I'm cringing as my friend tells me the story...
Within one week my friend's friend is hooked. She thinks he is "the one" and he says he can tell she is "the one" and doesn't want her to talk to anyone else.
...and then it comes...the story...he has these money orders or something that he can't access and needs her to transfer some money...pretty much anyone up on Internet scams knows the routines...
But she is in love. She tells my friend about it and how she's wired this money etc. and how it showed up. Of course my friend is totally freaking about it and like what the hell - don't do it. But her friend is convinced this is a good guy and sure that he must be in love with her and the bank account is real so...she ends up asking someone else who confirms it is a scam and she tells the guys she knows what is going on. And last night I guess they called her twice.
Well I told them to report all of this to the FBI immediately on the Internet crime link...or should it be the CIA as it is international...or both...my friend says "well she reported it to Match.com and his account was somehow closed..." I urged them to report it with any phone numbers they have, etc.
And then my friend asks - so what can you do about these people in huts in Africa - she says she's seen TV shows where they have computers all lined up...what can we do? It's a government thing. There needs to be an international effort to crack down on this stuff. Everyone knows there are so many Internet scams coming out of Nigeria and ripped off software and stolen goods, and hackers in China doing espianage for the government and the Russian mafia stealing credit cards and hacker organizations like Gulli.com and spammers in Brazil. Everyone knows....but is anyone doing anything about it?
And if a doctor like my friend's friend can fall for such a scam....
Hopefully Match.com has some sort of automated program that analyzes content to look for scammer type material but I am not sure how this works with privacy laws. The least they can do is make a HUGE alert on their web site to anyone signing up for and using their account. Obliviously they are not doing that since this person did not see any such warning - or it needs to be more blatant.
Thursday, January 18, 2007
Preventing Zero Day Attacks
This looks promising. Symantec is using brains instead of a database to figure out if software is malicious or not. Something like this is definitely needed - over and above a database approach. It is too easy to change a file name - let's say if you know xyz.exe is a known hack - the hacker can simply post that file all over the place for the unwary user to download with countless other names. Zero day attacks need more than a known list of hacks because their goal is to get out and do damage in one day - before they get into that database. Also with an FBI representative claiming that 15% of the world's computers are hacked and/or controlled by command and control servers doing dirty work - and new hacked servers coming online every day, it is impossible to block out hackers based on IP address or other identifying information alone.
Tuesday, January 16, 2007
Open Resolvers - DNS
http://dns.measurement-factory.com/surveys/openresolvers.html
I have a new client who is coming from one of the companies on this list of known open resolvers:
http://dns.measurement-factory.com/surveys/openresolvers/ASN-reports/20060923.html
We shall see if and what problems come out of all of this.
Here is some more technical information about open resolvers:
http://condor.depaul.edu/~jkristof/slides/dns-ctinetseminar.pdf
Wednesday, January 03, 2007
Today's blocked IPs
193.110.140.148
220.181.19.187
38.98.120.70
220.181.19.187
71.13.115.117 (multiple times - reported to network but has not stopped)
220.130.191.239
206.138.130.2
64.229.220.96
88.198.43.39
62.13.25.219
220.181.19.164
216.71.96.94
206.67.139.100
38.98.120.70 (multiple)
38.100.225.5
76.215.57.44
Sunday, December 31, 2006
89.240.207.15 - Unidentified IP?
89.240.207.15
DNS Stuff reports that it resolves to the UK. The information should be found in RIPE (ripe.net) however it is not there, either.
Toshiba Power Saver - Hack or Problem?
Bascially the first error I saw on this computer is when it was connected to a wireless network and I shut down the connection. Then the Toshiba power saver gave me an unexpected error message.
So why is this power saver getting errors when I shut off internet access unless it is somehow dialed out to the Internet, pray tell?
Very curious as this is the same component that continually crashes even after re-building my last Toshiba about three times. Each time I start having problems with the power saver. I thought it had something to do with my third party power cord that also flaked out but on this new computer I have only used the power adaptor that came with the machine.
So either there is a hack in this software that is somehow allowing access it should not - or there is some really bad programming and error checking in the software.
I hope someone out there is reading and will do some additional testing on this besides just hackers.
Friday, December 22, 2006
For those who throw up their hands at hackers...
http://www.eweek.com/article2/0,1895,2073611,00.asp
Hacking is profitable. Just as is selling drugs. More so.
The internet is the new wild, wild west. Lawlessness abounds. Fend for yourself.
By the time the Marshall arrives it will be too late, and what good is one guy against a gang of thugs anyway.
Tuesday, December 12, 2006
Students, University Networks and Criminals
You'll probably never believe this but had it in my head for a while to write about the huge amount of traffic I see coming from universities that is obviously hacker traffic. I was going to suggest that maybe someone was paying students to do dirty work or possibly download "cool new stuff" which is unknowling running worms, viruses or malware. Something has to be going on at Universities because I cannot believe they are all just hacked to such a high extreme.
Lo and behold I found this article today:
Saturday, November 25, 2006
Command and Control Bots
Could be coincidental but just saw a whole bunch of hits in a short time period. I have been working all day and not been seeing this. These hits are from the usual suspects - Germany, Taiwan, etc.
And coincidentally - I just made a significant update to my web server. Seems as though they are monitoring changes.
64.124.85.78
64.34.145.194
64.34.145.195
66.246.252.172
38.100.225.11
193.47.80.39
220.130.191.240
219.142.118.37
212.241.204.251
38.98.120.70
64.34.145.198
88.198.43.39
Tuesday, November 21, 2006
Sites with XSS Flaws
Sites with XSS Flaws
I accidentally found an XSS flaw on my bank's web site recently. They were trying to prevent it by using a JavaScript pop up box. Helllloooo. Who doesn't know you can turn off JavaScript these days? A bank for goodness sakes...my money at stake.
It is a small credit union. Needless to say I am in the process of changing banks.
Saturday, November 18, 2006
Root Kits
http://66.102.7.104/search?q=cache:BIB2gaxTOGUJ:www.rootkit.com/board.php%3Fdid%3Dedge0%26closed%3D1%26lastx%3D15+windows+defender+login&hl=en&gl=us&ct=clnk&cd=9
Sunday, November 12, 2006
Process Monitor: What is that process doing?
Process Monitor
This looks to be the information requested for months in my pleas to help find out what is causing problems on a machine in past articles (of course I am just one of the many...) I haven't tried it yet but if it lives up to the description it could be very useful if and when you suspect hacking on a machine - to verify and validate every process and user and what they have been up to.
Friday, November 10, 2006
Windows Security Utilities
Security Utilities
Microsoft has purchased a the site formerly Sysinternals.com which was a good source of utilities - probably used by both hackers and legitimate security professional alike.
Wednesday, November 08, 2006
Kernel bugs & vulnerabilities
This month that topic is being explored by some developers on this web site with contributions accepted from other developers around the world:
Kernel Bugs
The scariest one to me so far is the GDI bug on windows that allows escalation of privileges to take over a machine. Not good and no fix available yet supposedly.
Also interesting are the tools used to find these bugs. Aren't the developers building this software familiar with and testing their software with these tools for such a critical piece of functionality such as an operating system kernel?
Yeah I might not be using them for my code but I don't have the whole world relying on the securty of my software as these vendors do.
Tuesday, November 07, 2006
Site Rippers
I would guess most people are site ripping for the purpose of reverse engineering a site either to compete with SEO rankings or to try to find a way to hack the site. For instance they can rip the site, run tests against it without hitting your web logs, and then put the program they have developed to do whatever to you web site undected - so it looks like normal traffic in your web logs.
Some site rippers are obvious - like looking in the request headers and finding the user agent. Others are more sly, doing things to cover their tracks and appear as if they were a "normal" user.
What to do about site ripping? Good question. First block the blatant ones. Second, look for traffic anomalies that don't appear to be "normal" users clicking through a site at normal speed. Finally, frequent site changes can help ensure someone has not written a program to walk through your pages and do something malicious. You can "break" their code by finding ways to change your pages frequently.
Tuesday, October 31, 2006
Codecs, Drivers, and Kapersky
Here's something more about fake codecs and driver security hacks: Fake Codecs
I've wondered about the potential security issues with drivers for quite some time.
A note on Kapersky: Since it recognizes this hack and was used in some very sophisticated hacking in commercial software server abuse (see a recent post on a hack that installs it's own virus checker) I am wondering more and more about the virus scanner.
So I read more about it: This company seems to be "headquartered" in a number of countries all over the world, listing Russia first. I read that they have since moved headquarters to England and a visit to their web site reports a US address.
I bet it is the best virus checker out there...that doesn't mean I'll use it.
Let's say someone wanted to infiltrate the most protected and secure machines around the world? What would be the most effective way to do that?
Think Trojan horse.
Write the software that is protecting them of course.
Just a twisted idea for a movie plot.
Instead of making the world hate them - by sneaking things onto their machine or creating PR nightmares such as this supposed FBI Keylogger (Magic Lantern) has done -- the world loves them...and invites them in...yes protect my computer!
Here's a twisted thought: What if Kapersky likes the idea that Microsoft is blocking out anti-virus checkers from other vendors:
Kapersky says Vista doesn't block out anti-virus vendors
I did some research on Kapersky just for fun...I'm sure all security software has bugs but here's what I found...
Kaspersky Anti-Virus cab.ppl CAB Archive Handling Overflow
A remote overflow exists in Kapersky Anti-Virus. The 'cab.ppl' engine fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted CAB archive, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Kapersky Buffer Overrun
"The recent compromise at Kapersky Labs, in which subscribers were potentially duped into accepting fake updates which contained the Bridex Worm, demonstrates the critical importance of this enhanced approach to update security," said John Sharp, president and CEO of Authentium in a statement...Kapersky fake downloads
Something that someone else will need to interpret Congrats, you've detected Kapersky AV
Here's another article worth a look - on security problems with your anti-virus software. One of the problems with Panda could leave your machine open to a complete take-over by a hacker. A seemingly innocent error...
Security problems in Security Software
Who's auditing the virus scanners and security software?
And who's to say all distributions of a particular software are the same?
And who's to say things aren't hiding in plain sight?
Ok yeah it's just a thought. Just kidding. Kind of.
Verify, validate, audit.
Thursday, October 26, 2006
How much of your traffic is HUMAN?
60% of the traffic was from machines. Non-human beings. Non potential sources of income. Of course the search engines are helpful in getting traffic to us and some was our monitoring system, but 60%?? That is a lot of wasted bandwidth because not all those search engines are at all helpful. Some are actually malicious.
Monday, October 23, 2006
Stock Spam
A hack with it's own virus checker
This piece of malware is spewing out all that stock spam you've possibly been seeing lately with some pretty advanced tactics.
The article states that the trojan uses peer-to-peer technology to communicate with command and control servers, however it does not tell you how it got on the box in the first place.
This software is making some use of dlls...a major annoyance if you read my previous posts.
Sunday, October 22, 2006
Stock Picking Service - Internet Influence?
While researching the customer I found that there are a bunch of spam like stock postings with some apparently somewhat useful information but I am not quite sure yet if it is clearly spam or just a feeble attempt at marketing.
Then I notice this other guy's name all over related to the guy who made me the request. So I go check out the other guy's web site and he's got this video of himself and a clearly used-car salesman looking site guaranteeing people they will make money using his stock analysis / picking service.
So I start to ponder whether these guys are legit or not and then it hits me. The first guy wants me to get people to sign up for his free newsletter at 1000 people per day. In one month that would be 30,000 people.
If he says "buy this stock" and 30,000 people buy the stock - what effect will that have on that particular stock? If he says sell....
I am not sure exactly how many people it would take to influence a stock but the thought is somewhat interesting. L. Ron Hubbard, founder of Scientology and author of Dianetics, was quoted as saying "if you want to make a little money, write a book. If you want to make a lot of money - create a religion" (according to my professor of comparative religion in college). I found a reference to the statement here. That always fascinated me - that he said it, did it- and people still follow this religion even though his motivations are blatant.
The same principle kind of applies here. If you can get thousands or even millions of people to believe you have magical stock picking ability and some incredible "magical" software that helps you pick stock - and then you tell all your believers to go buy or sell something - you may be able to influence the market. And guess what. You believe in yourself too in that case...Because you know what will happen when you say "go".
Friday, October 20, 2006
Microsoft Vista Driver Authentication
At least I applaud Microsoft for making attempts to resolve this problem but it looks like they still have a ways to go.
My friend from Microsoft just warned me that Vista's new security model is not good, however he didn't say why. He was in the past working on something to control driver security and completely frustrated with Microsoft and his job. He used to work with really smart people and sounds like they left one by one and no one wants to solve the "really hard problems". Could it be that Microsoft is infiltrated with people who do not want to solve these problems? Or is it that they just don't want to take the risk of doing something extremely complicated and have it exploited and put their heads on the chopping block at Microsoft? Who knows.
Even if Vista's new security model is not good - could it be worse that what existed before? It seems that some level of authentication is better than none, doesn't it?
Thursday, October 19, 2006
SPF Records: Do it Now
Right now I am getting hundreds of bounce back messages because spammers are spewing out messages using my domains.
The problem for the people who are using mail systems that do not check SPF records is that they do not know this spammer IP is not on our allowed list and that this is obviously spam. If their mail system was checking our SPF records they would not be getting the messages in the first place, and if it was a good mail system it would not be spewing out bounce messages for spoofed emails.
The problem for mail administrators and mail servers is that by not checking SPF records a lot of bandwidth and processing power is wasted. If they would first check SPF records before touching the mail then they wouldn't have to even deal with checking to see if the user really exists on the system, and storing the message at all. And possibly spammers would leave their servers alone since they can't get messages to it.
The problem for me is that the end users, our potential customers, who are uninformed about SPF records, spoofers and spamming, is that they may be reporting our email as spam to their service providers and our domain may get blocked - incorrectly - by mail administrators and mail systems that are not smart enough to look at the spf records to verify the mail is from a legitimate source.
If you are not using SPF records it could be harming your business and limiting your business opportunities. Let's say you sumbmit a request for a quote to some business in their web form - they reply to you but you never get it because their domain has been incorrectly flagged as spam. Or let's say you get a bunch of spam and block that domain entirely. Now suddenly you can't get mail from a possibly legitimate new customer who didn't know their domain had been hijacked.
As I write this I must warn however that someone out there, needs to be keeping an eye on all this rejected spam...as mentioned in previous posts it could actually be used as a form of communication by people who do not want you to know what they are writing! So hopefully someone out there is keeping an eye on legitmate AND spoofed and spam email messages.
To find out more about SPF records contact your mail provider, your hosting provider and take a look at http://www.openspf.org
If your mail provider tries to talk you out of SPF records - yes there are some issues with them - but you can define all the allowed servers to send your mail and that should resolve the problem and make your domain harder to steal and spoof. In most cases they try to talk to you this way because they don't know how to set it up correctly - get a new mail provider.
SPF may not be a perfect solution - but it is the only solution I know of right now that even attempts to resolve this problem. Maybe there are others that are better and I would love to hear about them, but my mail provider has received awards for secure email solutions and this is their recommendation.
Sunday, October 15, 2006
DDOS Attacks
DDOS attacks on Al-Jazeera
And let me tell you, I was with a news junky and we were watching every right wing news show known to man. Maybe the newscasters just didn't understand it. This is almost scarier because the next real war is at the computer and network level. I have written about this previously.
But enough of that. The interesting thing about this article is that DDOS attacks can cripple a web site -- and that using a private network such as Akamai can be a solution to this problem. Probably at a hefty price, of course.
Thursday, October 12, 2006
Web Site Hacks
Web Site Hacks & How To Fix
Chargebacks - the Crime No One is Watching
The reason listed on the piece of paper I received in the mail from my bank (Bank of America) is this: 32-Cardholder Does Not Recognize Transaction.
I contacted the cardholder and they told me they never reported any problem with the transaction to their bank. Someone is initiating this response, it is not the cardholder and therefore it is fraudulent based on the response on the document I have.
Worse yet, the document asks me to fax the account number, expiration date and all the information including a signature from the sales draft to their fax number.
Just by reading this it looks as if I have to provide the ENTIRE account number, expiration date and the customer's signature. Hmmm. Is this secure to be faxing this stuff around? When I called in they said I could just give them the last four digits. I do not even store the full card number anywhere for security reasons. (So if you're hacking my server - you're wasting your time).
Finally when I explain this is potentially a fraudulent scam and someone should look into it and try to crack down on this there is nothing they can do. They just blindly send the requested data to any bank that asks for it in any country (this is an international web site) to resolve the issue. Supposedly they would not send the information "to just anybody" but I wonder how tight that security is, based on this whole scenario, on validating where they are sending cardholder data and who has access to it.
Here's the potential: Someone, be it at Bank of America, the third party bank, or a hacker, could be intiating the charge back to me and if I miss it, the money is taken out of my account. But guess what, the cardholder never said they didn't recognize the transaction in the first place...think about it...where did that money go?? Someone's pocket - and not the right one.
Monday, October 09, 2006
PayPal Sent Me a Virus
So I did the good citizen thing and reported it to PayPal so they would know and could look into it.
And they send me back a message stating something like:
"PayPal occasionally sends message to users...if you don't want these messages go into your preferences and change them..."
Sorry but I didn't see the option for "DON'T SEND ME VIRUSES".
Friday, October 06, 2006
Blog Spam
http://payperpost.com/
This company is advertising to bloggers to get paid for writing stuff for their advertisers. Heck I write fast I should probably do it but I won't - because I have some stupid principal in me that doesn't want to spew out fake garbage.
The problem with this thing is that people are spewing out fake, useless, biased content in an attempt to make money. For instance you can write about some product and you're getting paid for it. Are you going to write something negative?? And even if you would, is the advertiser going to post the negative feedback? No.
To me this is a blog spam factory and wasting everyone's time.
Wednesday, October 04, 2006
Serve-U hack?
Coincidentally I started to have a bunch of problems on my machine around that same time. See two posts prior.
I reported the problem with dllhost.exe to my hosting provider.
Then suddenly my ftp software stopped working. It said the executable was missing. I tried reinstalling. No dice. I then uninstalled and reinstalled the thing and now it works again.
There are various things you can do to lock it down like restricting IP access, etc so I tried that.
I don't know if this is all coincidental but I started having all these problems at the same time which I mentioned in previous posts:
- cannot access admin portal for Datapipe in Mozilla
- email bounce backs show spam from my domain names (working on spf records now)
- ftp server is hosed and have to reinstall
- web server using 100% of cpu and supposedly reboots itself while hosting techs are looking at it (hmm)
- web sites and/or local network is dog slow upon occasion - sometimes so slow images don't load at all from my web server
- dllhost.exe running on my box when supposedly dcom is locked down and all IIS services are disabled
- IIS service accounts have been re-enabled
I only report what I see....I am making no conclusions here until I pin down what is going on.
Global and Catastrophic IT Hacker Holes
Dirty Dozen IT Blunders
Tuesday, October 03, 2006
Spam/Hack attack on a Java User Group
it appears that our fun little wiki site has attracted spammers from holland
and russia. their favorite mechanism so far appears to be to create bogus
accounts and upload html files which contain spam.
I am running daily reports and swatting them as I find them. In the meantime,
if anyone finds anything else I might have missed, pls let me know.
Thanks!
Monday, October 02, 2006
Recent Hacker IP Addresses
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 12:24:16 PDT 2006 194.72.238.62 /
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Wed Sep 20 23:29:32 PDT 2006 194.72.238.62 /
Wed Sep 20 16:12:12 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 22:17:30 PDT 2006 194.72.238.62 /
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Mon Sep 25 10:26:23 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 13:45:56 PDT 2006 194.72.238.63 /
Tue Sep 26 12:15:09 PDT 2006 194.72.238.63 /
Wed Sep 27 05:58:18 PDT 2006 194.133.131.201 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 27 10:57:30 PDT 2006 194.72.238.63 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Sat Sep 16 14:41:49 PDT 2006 194.72.238.62 /
Tue Sep 19 04:12:53 PDT 2006 212.43.248.186 /
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Wed Sep 20 15:02:32 PDT 2006 194.72.238.62 /
Wed Sep 20 15:57:28 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Thu Sep 21 16:18:31 PDT 2006 64.246.0.17 /robots.txt
Fri Sep 22 08:59:01 PDT 2006 194.72.238.62 /
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php
Sunday, October 01, 2006
Invalid SSL Certificate Accessing Hosting Company Admin Web Site
The weird thing here though is that one time when I tried to access via HTTPS in Mozilla, I got an error saying the SSL certificate domain name did not match the domain name I was trying to access. When I took a look at the certificate details it was pointing to a choicepoint SSL certificate. I am not sure but I think it was secure.choicepoint.net.
Interestingly choicepoint.net is in Atlanta which was probably the most major source of hacking I saw while on my previous hosting provider network. Could be a coincidence. Coincidences and random Internet connections abound.
I went to read about choicepoint on the net and found this: choicepoint
Related?
Thursday, September 28, 2006
Russian Federation IP Going After My IPs?
81.3.160.38
Seems that they should be going after the actual web site url not the ip directly.
Could be a network admin mistyping an IP - maybe once or twice, but 16 times?
Here are some other IPs doing the same thing multiple times:
81.3.160.38 Russian Federation
66.221.181.243 C I Host
194.72.238.63 Netcraft Limited
194.72.238.62 Netcraft Limited
82.192.89.153 ORG-OB3-RIPE
64.114.199.1 TELUS Communications Inc.
66.221.181.243 C I HOST
81.3.160.38 OOO Riviera holding, St. Petersburg Russia
82.192.89.153 ORG-OB3-RIPE
64.114.199.1 TELUS Communications Inc.
66.221.181.243 C I HOST
82.192.89.153 ORG-OB3-RIPE
82.192.89.153 ORG-OB3-RIPE
Tuesday, September 19, 2006
PDF Security Exploit - Adobe Acrobat Reader
Adobe PDF Reader Hack
This is really scary knowing how many people use Adobe Acrobat Reader and how many PDF files are being downloaded from the web every day. Try viewing PDF files online from unknown sources as HTML when you find them in Google search results.
Tuesday, September 12, 2006
Adware Vulnerabilities
Guess what, you may be supporting the proliferation of malware.
Read this:
http://www.eweek.com/article2/0,1895,2013957,00.asp
http://ct.enews.eweek.com/rd/cts?d=186-4422-5-92-283087-513065-0-0-0-1
Friday, September 01, 2006
PHP Security Bandwagon
Looks like PHP security is becoming a hot topic - as it should be:
PHP Security Issues
PHP hacks
PHP Vulnerability Fixes
Thursday, August 31, 2006
Regarding Jetty Cipher Suites
Here is the response from the Jetty team:
The list of cipher suites available is determined by the security provider that is available in Java and by default it is the SunJSSE provider. Its not included in Jetty but in your Java installation itself. It is possible to use a third party provider but its not simple to install it (here are the details:
http://java.sun.com/j2se/1.5.0/docs/guide/security/jsse/JSSERefGuide.html#JCECust).
Thus, if you know the provider, you can just select the low level ciphers from the list of available ciphers provided by that provider. To see the list of available cipher suites in Java 1.5, just go to appendix A in the link above.
In appendix B, you'll see that Java has a list of allowed cipher suites for other providers. Java 5 will only allow third party providers as long as they support only those cipher suites in the list. You can just select the weak encryptions from this list and enumerate them in the excludeCipherSuites list so no one will be able to sneak in a weak encryption cipher.
Sunday, August 27, 2006
Foiling Key Loggers & More McAfee Software Problems
Needless to say, logging into my computer with these extra characters spewing out of my keyboard was a total waste of time. I was so annoyed I went and bought a new laptop.
Then wandering around the random Internet I happened across a white paper by Microsoft talking about messing up key loggers by inserting additional random characters as someone typed passwords into text boxes. AHA.
I had McAfee software installed and although I tried to uninstall it something was completely hosed on my machine and it didn't work right. There were still random services floating around that I would mostly ignore.
I went to start/run and typed msconfig to pull up start up programs and sure enough there were some McAfee services in there yet. I killed them all and removed them from automatic start up on my machine. Yep. That stopped the random characters from messing up my login.
This is not the first time I have had problems with McAfee and the feeling like it is more a foot in the door for hackers through their update process rather than a piece of security software. This feeling was justified in the case where their "enterprise" software had a serious vulnerability doing just such a thing. See other comments in past entries here.
And if you're having problems with extra characters appearing and getting in your way...msconfig and stop the McAfee services from auto start up.
Wednesday, August 23, 2006
Online Advertising - Click Fraud
Click Fraud
This is a serious issue for businesses because it can drain a lot of revenue. I once put up and ad and wasn't watching it and the amount billed in two days was something like $600.00 for Christmas decorations. I cannot believe all that was legitimate, however Google claimed it was and I didn't have the proper logs to look into it. I never had such an issue so didn't bother in the past.
More recently I have found that in competitive spaces like the online travel industry, online advertising is a significant part of the cost of doing business. The ads are very expensive based on the amount of clicks received.
Even worse is the web development space where you have to spend $2.50 per click just to get on the board. Something is wrong with that picture - and I got no leads for a huge amount of expense which just doesn't seem right.
Of interest is that recently I got a letter in the mail about a class action law suit against Google to get money back for fraudulent clicks. Hmm. Some lawyer will make a lot of money. The more alarming thing to me was that this letter stated I either had to send in a letter to remove myself from the suit, otherwise I would be a part of this suit and could never again sue Google for this reason. Well if I send in a letter is Google going to see that and shut down my advertising so they won't get sued? And what if I join the suit but I don't have any click fraud that I know of. I don't get any money now but I may have a click fraud issue later? I would like to think that Google is angelic and all that but reality is...Enron happens. The nice thing for Google is they basically settle this suit, pay a bunch of money, and can never be sued again for all the people who didn't see the letter or respond to it. And for those that did they might just close those people's accounts. It's always the little guy getting burned no matter which way you look at it. I saw subsequent similar letters for other online advertising services.
Click fraud is a serious issue for businesses. Not only do you have to ensure you aren't paying for fraudulent clicks, however, you have to make sure your site is secure, because if you are pouring a lot of money into advertising and someone else can redirect your visitors to another site - you're paying for their advertising.
Jetty Cipher Suite Handling
Cipher suites allow the web server to use different types of encryption. If you are allowing weak encryption on your web server - you'll want to fix this.
In the case of the latest version of Jetty now you have to think of and exclude every possible cipher suite instead of just specifying those you want to allow. This is very poor security.
The way to handle security is to first disallow everything, then specify the things you want to allow explicitly.
Microsoft has this in their top 10 application security problems list however they also do not follow this principle in regards to DCOM and RPC. Functions which are not required should always be disabled - especially those which can clearly be hacked, and administrators should be given the option to enable these things when needed.
In the case of Jetty I hope this was an oversight because this seems to be a well engineered application for the most part, however their use of certain non-standard third party tools does worry me at times. I hope they have checked every line of code inside and out.
Jetty is not the only organization doing this of course. I have written about many PHP frameworks which are on many more vulnerability lists!
Friday, August 18, 2006
Are You Getting All Your Email?
Tuesday, August 15, 2006
More PHP Hacks: Better Web Systems
PHP Hacks
I wrote previously about how I hate PHP becuase it is this free software with all these neat widgets which script loving programmers and web site owners who many not be programmers at all hack together into something that externally - looks like a web site. Ok it is a web site.
Well, if you're running a web site for the neighborhood street party maybe that is ok. But using someone who is not on top of ALL the issues in building and maintaining secure and solid web sites, and you're basing your whole career off this web site...good luck.
The problem here was that someone threw together a PHP web site (so you can guess it was cheap...) and didn't apply a patch that came out that would have prevented the whole problem. Too often people set up a web site and then think they can never pay attention to it again. Not true.
Whatever software you are running, besides your automatically updated Windows operating system, is potentially hackable and must be managed and monitored if you don't want someone to hack it.
And as mentioned previously I have somewhat of a disdain for PHP for various reasons. There are some good PHP programmers but seems more bad than good and more hacks than most other languages.
You get what you pay for.
Sunday, August 13, 2006
A different View of Netcraft Server Usage Rankings
The way these rankings are gathered is by scouring the web and pinging each web server to determine what type it is to add to the statistics.
Consider that a properly secured configuration will not advertising this information because then as new vulnerabilities are announced, hackers will use this information and scour the Internet (the same way Netcraft does) looking for these types of servers so they can attempt to exploit that vulnerability.
So instead of thinking, hey most people use IIS so I'm going to use that too, you can think, geez IIS has the most insecure installations therefore there are more IIS admins that don't know what they are doing than other types of web servers in terms of security.
By the way I haven't looked to see which type of server is most widely used right now. IIS is just an example. It is probably one of the free web servers like apache - which is a good web server for certain uses. The problem is not with the server itself. The problem is with administrators who are not properly trained on implementing secure configurations of their web servers.
I for one, knew my limitations and hired a managed hosting company, thinking they would have all the answers to make my systems secure so I could focus on development. Not so. Your application developers need to be aware of application issues and your internal staff and/or external auditors need to be checking everything your managed hosting company is doing. People at managed hosting companies can make mistakes, as well as the possibility of internal security breaches.
So secure your web server by hiding the implementation from prying eyes, including Netcraft unfortunately. Additionally, run security audits and don't assume your administrator or your managed hosting company can find every single problem. Security is a tough issue that requires constant monitoring and updating to keep up with the hackers.
Validating Click To Call Advertising Charges
However instead, I must now complain about the advertising company. I emailed them and told them I think I was billed incorrectly because I hadn't gotten any "leads". However just to make sure I asked for the phone records so I could match them up to my phone calls and determine if I had actually received calls from other sales people rather than actual leads and that was the source of this whole thing. Maybe that research company is using their list and generating charges for people - in which case they need to stop!
Instead of simply sending me the phone logs or telling me where I could find them, the advertising company emailed me and told me to call them. I told them I couldn't right now because I'm on a contract during the day where I can't take/make phone calls and additionally, I am super busy. I use my lunch hours and any extra time to get projects done. Could they please just send me the phone records and I would look into it later.
Then they tell me they can't provide the phone records like the number that called me - for "privacy" reasons. What the heck? What kind of phone service doesn't provide you record of the calls you are being charged for? Does anyone see anything wrong with this picture? They could tell me I got 100 phone calls and have no way to prove it and I am supposed to just pay it? Even with pay per click advertising you can track back clicks to their source and validate you are getting the clicks you are paying for. Same should be true for phone.
Additionally this company told me that my phone line would not allow them to leave a message. That's odd. I have messages from this research company, vendors, etc. I also have hang up messages (clicks) from their number so if I can get the hang up why couldn't they speak and leave a message? However I realize something may have been wrong with the phone line and need to call the company providing me with that service in that case, so I asked them exactly how they tried to leave a message so I could resolve it. Were they on the main extension and didn't select a particular extension or what?
Additionally I sent some suggestions for making the service better and why it would make more sense if they could provide the phone logs. For instance if someone placed a call and didn't leave a message you could use the phone number in the logs to call them back. If nothing else you could validate that you actually did receive the calls you are being charged for. I asked if she could pass that message on because I think it would be valuable for marketers to be able to track the source of their leads and make this online advertising service more valuable if it could be associated with dollar value in terms of new sales.
In the meantime I said I would try to login and see if there was some information in the system I could match up to my phone logs to figure out what happened.
So what did they do? Did they answer my question about the voicemail so I can fix it? Did they pass my message along? Did they tell me how they tried to leave a message so I could resolve that problem on my end (if it was on my end)? Did they allow me to log in and find potential answers to my questions -- OK I should have looked there first but I didn't realize they had stats in their online system and actually just forgot about it altogether so I will say shame on me for that. But apparently the info I needed was not there anyway from what she told me.
But no...she deactivated my account and refunded all the money before I had a chance to log in. Hmmm... I did not ask for this. I did not refuse to pay the charges if they are legitimate. I did not even refuse to pay the charges if they were wrong! I was just trying to understand how they track these things because I didn't have record of these calls they were charging me for.... I just wanted to see where they are coming from!
Could it be that they closed my account because there were no record of these calls? Before I could login and prove it??
If you are paying for "pay for call" advertising online - check that the service you are using can actually prove that you are getting the calls for which you are getting billed.
Maybe this company is not even doing it intentionally...but they should think about and change the service so people can verify the charges they are receiving. The other thing is that competitors may be clicking on this link to generate invalid charges and there needs to be a way to trace this back to the source and make it stop if that is happening. This services provides no recourse for doing so. We simply have to pay for the fraud with everything else.
Thursday, August 03, 2006
International Crime Ring - The Web Mob
FBI Discusses International Web Crime
My take that the next war will be an information war is being played out in references to Internet crime "cells" similar to terrorist network cells. My speculation further suggests that these "cells" are related to terrorist cells trying to produce nuclear bombs and weapons.
It's always about power and money isn't it? Sometimes I wish I was blissfully oblivious but I can't help what I see. And it all started by digging into the network of spam drowning my emails last year. The trends...the networks involved...the targets...the messages...I knew it was somehow coordinated.
Piece by piece the random Internet connections are connecting into a puzzle that is starting to form comprehensible and recognizable images that explain what is really going on.
The Internet is the new Wild, Wild West ... the new digital mob ... a new form of drug lords that want to rule the world ... a new brand of espionage and terrorism predicted in war games but very much an understatement in terms of the reach and complexity of the network and crimes involved.
Wednesday, August 02, 2006
JSP Vulernability
Two things come to mind after reading this statement.
#1. That hosting company is partnered with JBoss, and open source Java Application Server that serves up JSP. They must have some expertise in that area - and potentially some people who are aware of known hacks who may have internal access at the organization.
#2. Maybe there is some sort of flaw in JSP...which was something I was starting to wonder prior to reading this. The thing about JSP is that it is compiled after the fact and there are some temporary files that contain the compiled code. What this means is that if someone can get into your cache off compiled JSP pages, they could potentially change those cached pages and alter the functionality of your application. You wonder what is going on so you do a diff on your code and it all looks the same...but in reality what was altered was the cached files. In the past I have found permissions changed on these cached files as well so they could not be deleted. That means that the code you think you are running may not be the code you are actually running.
#2 does not just apply to JSP but any programming language that compiles at run time. There needs to be a way to verify that the cache has not been poisoned.
So don't use JSP? I don't think that is the answer here because so many other application programs work in a similar way. In terms of Java application servers you could opt for using servlets. You can also perform some security auditing on your system to verify this is not happening.
DCOM - Vulnerability #1
And by the way I didn't ask to disable DCOM. I just want it to be secure so someone can't use it to launch rogue applications like they did on my box at the last hosting company. Someone was able to launch apps that were sending spam and who knows what else (see previous topics) using DCOM.
I am not sure how they got those apps on the box in the first place - I know they were launched through DCOM however they could have been installed by other means. Was it through my app or someone internal to the organization who had access to the machine? I also find it interesting that they say they have no knowledge or understanding of my web application and I find this to be a crock of you know what since I recently found an article saying they are partnered with the company who wrote my application server. Since they are partnered up with JBoss they probably have some internal or closely related people over there who are very aware of any known hacks should they want to take this hacker action to steal my money. (Which was clearly happening for three months over there and I am not yet positive it has been resolved).
But back to DCOM.
SO whose responsibility is DCOM anyway? It's kind of an application thing. Something people use to write apps that connect to and talk to each other over the Internet and a way to launch remote applications. However it ships with the OS and so in my opinion, if a hosting company is claiming that it is going to "harden the OS" for you and manage security then security DCOM from launching rogue applications and being left unnecessarily accessible if the client is not using it is an issue that the hosting company should address.
So far not one single company I have talked to has anything about DCOM or RPC in their OS hardening policies. This is clearly a fact that hackers are taking advantage of based on my experience.
Additionally if changing DCOM settings can "cripple the OS" why is there no clear documentation from Microsoft on how to correctly secure DCOM and a more simple way to figure out what apps are using it and if it can be safely disabled on a machine where it is not needed. The documentation on the Microsoft web site is even sketchy - warning that disabling DCOM may cause problems - but not clearly defining those problems so a person can make a technical and accurate decision as to whether disabling it is the correct thing to do or not.
And as argued before, you should not be able to do something on the OS that allows you to "cripple" your machine via the user interface. I understand if you are changing registry settings or something like that. But changing security in the OS settings? What's the point of a user interface. It should have some application logic to prevent this and a way to safely back it out if they aren't going to prevent it.
Managed Hosting Companies - Internal Employee Access Policies
Seems like most companies do not have well documented processes in terms of how and when employees can access managed systems and how this access is audited. To me I find this scary. I am working with some mid range hosting companies that support multi-million dollar businesses. I know because the reason I found out about one of these companies was through one of my $150 million per year clients.
One company was able to have a tech respond to me and outline the process. The company I was at previously could not articulate their processes and apparently did not have them written down anywhere - or want to provide me these documents in writing - because they constantly wanted to call me. The third company I am speaking to tells me that they have very stringent processes but no customer facing documents to explain these processes.
Since system administration is one of the very weakest points in the whole process - typically errors and hacks are caused by humans and most easily someone who has open access to the machine already - this is a huge problem! Yes so someone can't get into the building because you have biometric controls and chainlink fence lockers and separately locked cabinets. So what if your administrator is the one causing the problem!
This was highlighted by an instance at Internap that took down their whole Fisher Plaza facility one fine Friday evening - when I just happened to have a potential customer looking at my web site and freaking out, thinking I am some fly by night operation. Someone who had access to the building already went and flipped off the power switch somehow and for whatever reason in such a way that the generators didn't kick in. Seems they pushed that big red button that says "do not push" all over it way up in the air and Internap reported to me that it was "an accident"?? Hmm.
Internap is a good company but things happen. In "Who Says Elephants Can't Dance" Lou Gerstner says "People do what you INSPECT, not what you EXPECT." I wholeheartdly believe this after being ripped off by some of my own employees. Hosting companies want me to "just trust them" but that is foolish. You need to have good auditing in place in your hosting environment for true security - both internally and externally.
Tuesday, August 01, 2006
Managed Hosting Companies - Comparison
Managed Hosting - Comparison
It is very difficult to find a hosting company that sounds confident in their ability completely secure DCOM based on the applications I am running. I know what the potential settings are but am not sure why setting them a certain way crashes a server. Additionally it is unclear what settings must be left turned on for the applications at the managed hosting companies - most of them don't even know if their applications require DCOM or not.