Tuesday, March 06, 2007

Ebay vs. Romanian Hacker

Ebay has been plagued by a Romanian hacker lately per this article:
http://www.eweek.com/article2/0,1895,2100808,00.asp?kc=EWSTEEMNL030607EOAD

Of interest are the various tactics ebay is using to thwart this criminal which go beyond simple tactics to more complete analysis of hacker activity ...a trend in the industry which has long been needed over an above simple firewall rules and was the reason I started writing this hacker / Internet security / Internet service blog.

More analysis of specific hacker activity by humans, not machines, will help determine traffic and activity patterns to block out attacks better than any firewall rules. It is a constant, on-going effort at mutliple layers from network to firewall to OS to application - it is not a simple one time fix.

Sunday, March 04, 2007

Hacker in Japan

Japan scanning IP addresses for security flaws:

203943 BLOCKED a2ge8iqi9mcec Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203942 BLOCKED 1trlwusqdgvg5 Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //Ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /Ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203941 BLOCKED 4tnft3pc3kubt Sun Mar 04 09:24:50 PST 2007 203.143.125.226 //phpads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /phpads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM

..repeat about 50 times

A bunch of IPs requesting stuff we don't host

The following are related hacker IPs probably controlled by a command and control bot:

74.118.71.252
124.50.43.214
60.217.227.135
210.191.147.120
203.165.129.2
210.6.97.244

They all hit our site at the same time requesting things our server does not host.

Here's another set shortly before doing something similar, probably also related to the above:

195.49.188.202
71.63.100.55
210.245.147.241
218.233.57.23272.145.6.47
218.48.127.177

71.63.100.55
210.245.147.241
218.233.57.232

Perhaps someone pointed a domain to the wrong IP since they were all hitting the same domain.

These IPs are all requesting php files -- the favorite language of the hacked and hackers as far as I can tell by the percentage of hacks in the logs on various types of web programming and scripting languages.

Wednesday, February 28, 2007

253-719-0012

AHA...

I figured out what this number is. I got an electronically placed and recorded call from Comcast.

When you put this number in Google however you get a ton of nasty hacker information.

Interesting.

Tuesday, February 20, 2007

Defender Technologies, DefenderHost.com - Hacker Source

Hackers have also been pinging our sites from this IP range:

OrgName: Defender Technologies Group, LLC
OrgID: DTGL
Address: 44470 Chilum Place, Building 1
Address: Suite 1197
City: Ashburn
StateProv: VA
PostalCode: 20147
Country: US
NetRange: 69.65.96.0 - 69.65.127.255

Inhoster - bad bot source

This is the latest blatant abusing network:

inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
country: UA

Saturday, February 17, 2007

Related Hacker IPs

Here's a group of related hacker IPs that hit our web sites all at once. All the IPs hit the same web site and it is an odd site for site for these IPs to be hitting:

Time of hack attempt: 2/17/07 21:42:33
65.184.191.13
211.213.118.32
75.34.23.14
212.119.45.138
71.83.46.82
12.206.187.108
59.95.212.177

In addition this IP was in the middle of this looking at another site:
89.150.197.192

Friday, February 16, 2007

Message Guard - Network Solutions

Been writing about trying out Identity Based Encryption - specificall the Message Guard service from Network Solutions provided by Voltage Security.

This is the typical message I get from other people when I try to use Network Solutions Message Guard to send them emails:
_______________

I do not have time to go do all of these steps to read the email. It takes over 5 minutes to complete this. I am the only one here in my department and this is very time consuming. Can you please just send me a regular email.
_______________

Until this is fixed, this is not a viable solution for every day use between two parties that are not both using the same service. I thought the idea was that the person only has to go through the steps one time...

I also asked Voltage Security how they guarantee that someone at their location is not able to decrypt and read the email - what policies and auditing do they have in place - and as of yet no response.

Monday, February 12, 2007

Catepillar, Inc. really Interested in Australia?

It could be legit but this past month alone we've had a huge number of hits from Catepillar, Inc. to a site for an Australian hotel booking system...maybe someone wants to take a trip, or perhaps their server is being used for monitoring unbenknownst to them?

12.2.142.7

Arrival Communications - Hacker

There appears to be a hacker at arrival communications on this IP 69.84.207.35 targeting one of our real estate web sites.
They hit our contact request form about 70 times in one day.
Shortly thereafter the publishing of the site was altered, but we were able to easily republish.

OrgName: Arrival Communication, Inc
OrgID: ARRV
Address: 5100 California Ave Suite 104
City: Bakersfield
StateProv: CA
PostalCode: 93309
Country: US

NetRange: 69.84.192.0 - 69.84.207.255

Identity Based Encryption - Update

As noted in previous posts I'm trying out Identity Based Encryption and having lots of problems with it. A lawyer on comcast can't use it, a customer couldn't access it, people I work with in Australia aren't replying so I am not sure what that meants, someone on AOL couldn't read it. It's a toss up who will be able to read it and who won't. Someone on Yahoo gets it just fine as does someone on SpeakEasy. One mail provider - ElectricMail.com - refuses to let their support staff use it.

The latest is that I just had to re-authenticate to send a message and I'm not sure why. Is this an on-going thing where you have to re-authenticate on a weekly basis?

The other thing to note is that I bought the service from Network Solutions and it is authenticating on the Voltage Security system.

Wednesday, February 07, 2007

Reverse Load Testing

In this article which talks about an attack on the root servers that support the Internet:
http://www.networkworld.com/news/2007/020707-hackers-slow-internet-root-servers.html?nlhtsec=0205securityalert3&company=

The engineers are "scratching their heads" wondering why the attack was performed.

I can think of a few reasons.

1. Reverse load testing. Hackers are trying to calculate what it will take to bring down the Internet. Bringing down the Internet could cause a myriad of disruptions that might be beneficial to a myriad of sneaky, slimy people.

2. Bringing down the Internet at a particular time when a certain crime is being committed may prevent certain communications which may then alert the authorities or warning systems to the crime underway.

3. Someone wants attention.

4. Some really flawed programming.

5. Mischief.

Tuesday, February 06, 2007

Identity Based Encryption (IBE) - Trial

So far IBE has been mildly usable. Most people were able to get it and login and read the message without any problem.

As supsected a few people were skeptical of the email and didn't want to open it until I called them since it doesn't look like your typical email.

I also had a few people have problems with it including:

#1 my boss couldn't open it on his cell phone - didn't work at all. Also he didn't want to "sign up for an account" even though I explained that's not what it is.

#2 Someone on AOL couldn't open it at all.

#3 One of my customers using Electric Mail and also I think another provider could not open the message. She tried a few different times today...going to have to call tomorrow and see if we can figure this out.

#4 Couldn't respond to tickets to my data center which is a pretty big hosting company. They have an automated system and the message came as an attachment which was then not included in their automated messaging system.

#5 I was told after asking if I could use it on a web server to send messages that it only works in Outlook - after I told them I was using Outlook already so obviously I know that. So you can't sign up for this and then send secure messages in an automated fashion to potential clients, for instance, or email receipts from an e-commerce web site or links to file downloads, etc.

A few things to resolve here...it's not quite as simple as normal email and obviously doesn't work for all scenarios.

Monday, February 05, 2007

PHP: Most Requested URLs by Hackers

Per our records, PHP is far and away the most attacked language - and we don't even host it.

These are the URLS various hackers have been scanning our boxes for in the past few months:

/phpAdsNew/adxmlrpc.php
/index.php
/profile.php
/cmd.php
/Ads/adxmlrpc.php
/register.php
/thisdoesnotexistahaha.php
/stats/cmd.php
/portal/cmd.php
/adserver/adxmlrpc.php
/adxmlrpc.php
/a1b2c3d4e5f6g7h8i9/nonexistentfile.php
/phpads/adxmlrpc.php
/web/e-commerce/database/index.php/administration/module/module/index.php
/portal/cacti/cmd.php
/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
/blog/xmlrpc.php
/cacti/cmd.php
/drupal/xmlrpc.php
/web/phpMyAdmin/main.php
/web/phpMyAdmin/main.phpmain.php
/w3c/p3p.xml
/_vti_bin/_vti_aut/author.dll
/admin/login/index.php
/admin/pages/index.php
/admin/pages/settings.php
/admin/start/index.php
/public.php
/web/.../work/index.php
/web//work/index.php

And here are the IPs that have been up to this mischeif along with number of hits:


39 213.186.50.160
25 62.39.119.241
24 208.72.168.27
16 64.208.172.181
12 216.218.196.210
7 206.169.110.66
4 203.121.69.154
3 212.145.93.63
3 81.196.150.45
2 89.110.131.89
2 74.6.74.225
2 72.10.45.38
2 212.8.197.79
2 212.138.64.171
2 125.248.244.131
1 195.175.37.6
1 195.175.37.71
1 200.88.125.9
1 200.88.223.98
1 212.138.64.172
1 212.138.64.175
1 212.138.64.179
1 125.244.164.69
1 62.150.130.26
1 216.129.105.149
1 72.3.139.176
1 72.30.252.98
1 74.6.71.59
1 74.6.72.189
1 74.6.72.225
1 80.95.160.188
1 64.28.23.49
1 82.114.68.194
1 85.214.45.212
1 86.145.147.223

Friday, February 02, 2007

Identity Based Encryption - mail forwarding

This is interesting - I set up an IBE on an email account to test out Identity Based Encryption.

I have one account set up to forward to the other.

I sent from account A to account B.

Then account B forwarded the IBE message to create a key back to account A.

I was able to create the private key on my computer by creating a login - using a different email address than the one the email was sent to. (I was in account A - the one that sent the message).

When I went back to the email in my webmail based email account B I had the key on my machine and was able to read it even though the email address I entered when I created the key for was not the email address the mail was sent to...

Also about 5 minutes later I was forwarded the test message from account B back to account A and was able to read it without doing anything else.

Seems a bit odd. Not sure the implications of this on secure email. I will have to think this one through a bit more.

Tuesday, January 30, 2007

Identity Based Encryption

In a recent post I posted some questions about IBE or Identity Based Encryption for email which some vendors are selling at the moment and suggesting that now their email is encrypted and secure from end to end. On Network Solutions web site they even talk about sending credit cards in email not being secure, thereby implying with IBE that would be secure.

I recently asked Voltage Security about their IBE product to explain some of the problems they would have to overcome to create the encrypted email solution they propose on their web site. Most of their answers sound pretty good, except I still have questions about #5 noted below.

They also sent me a sample message so I could see how their product works. I received a secure message with a graphic button that was blocked by our mail scanning/security products and an attached html file. When I click the button to retrieve the message I have to create a user name and password to read the message and get the private key to read the message. I can see this working for internal organizations but when sending information to potential customers - I can imagine some of them not understanding what this is or being apprehensive about filling something like this out or clicking on an html attachment from a vendor they never heard of or have not worked with before - at least until and unless people get used to this concept. This may be a good solution for internal organizations however, if you trust the vendor of this technology of course and have had your own technical gurus look into the actual details. I am not an encryption expert. I am only looking at the process of getting the mail encrypted from A to B. I cannot say whether the encryption is not decryptable by the company selling it to you, for instance. But here's the scoop on the process:

Once the recipient of an IBE email receives a key they no longer have to get the key for future messages. What happens if they use a different computer?

When a person moves to a different machine, the key is then fetched again from the key server for future and past messages. There is no limit on how many keys one user can fetch as long as they properly authenticate each and every time.

What happens if they log on to web mail on a public computer in an Internet cafe? Is their private key downloaded there for future users of that machine to potentially exploit?

In a public web mail instance, they would be using ZDM, that only caches a stateless cookie that can be set to expire to meet your internal security policies. Also, once an end-user “logs out”, the session cookie is terminated, mitigating any security threat by reading secure email on a public machine. By default, there is a configurable 1 hour session timeout in case the user forgets to logout. Our ZDM cookie security has been fully vetted/tested and is currently in use by several large banks, health organizations and retail companies.

What if someone can steal the private key from the recipient’s machine - since authentication only happens on the first email they could basically read any email after that point if they have the key?

One key is only good for less than 1 week. They would only be able to read secure messages for that one user that fall within that one week session (it’ll most likely be less than half a week). We can utilize any authentication method – email answerback, or one email to prove who you are, is a highly usable, widely used industry standard (see Amazon, Yahoo, Microsoft, banks, etc) but not the most robust authentication standard. We support two-factor authentication, Windows Domain authentication, and different groups of users can be forced to authenticate by different means. The encryption method is tied down to one authentication method, giving you the flexibility to meet your security needs for secure communications.

How does IBE work with email addresses and accounts sending mail from a web server to another address, such as an order receipt?

If you are talking about automated emails, the messages must simply flow through our Voltage SecureMail Gateway, and it will encrypt using the designated recipients individual email address. Nothing special has to happen to encrypt this type of mail flow.

IBE encrypts mail from me to the person I am sending the mail to – what happens when they reply? Is that message sent unencrypted back to me? So if I have my mail encrypted so support people at my mail provider cannot read my outgoing mail, then the customer replies back to me – and my mail is unencrypted coming back from them – so it doesn’t really help? Or…is the mail back encrypted as well even if that person isn’t using IBE?

If they reply to a secure message using our integrated desktop client or ZDM, then you can force the reply or forwarded message to be secure (called “Secure Conversation”). If they don’t ever decrypt the message and simply reply to you, then your message is sent back still in its encrypted form.

My follow up questions to the answer above:

If they do decrypt the message and reply – then is it sent back unencrypted if they are not using IBE themselves or one of your products?

Scenario:
A person comes to our web site and requests product info. We send a secure encrypted message. They are not using any of your products or IBE. They open and read the mail, hit reply and send us back a question. They have outlook or their webmail system set to include the original message in the reply.

Is all our initial information now unencrypted in his reply as it travels back to us? Or once they go through the steps to decrypt the mail are they now using ZDM?

Also what if that ZDM cookie expires? Then when they reply to the message is it sent back unencrypted? Or do they have to log back in each time they read the message to get the cookie?

Hurricane Electric

Hackers live at Hurricane Electric.

I have been writing about hackers at Hurricane Electric since the beginning of this blog and their potential connection with a group of hackers in Alaska. More proof:

Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)

Friday, January 26, 2007

Identity-Based Encryption

An interesting new approach to encrypting emails and make sure only the intended recipient can decrypt the email: Identity-Based Encryption.

This works by authenticating the email recipient based on their email address the first time they recieve an email. They are given a key and after that they can read all emails based on that key.

My questions in this case are (still resarching):

- What if someone steals their private key? Can they read all the email?

- What if the person moves to another machine that does not have the private key - will they be unable to read their mail?

- What if someone logs in at an Internet cafe to read webmail - is the email they download encrypted and will they get a new private key? In this case will the private key potentially be stored on the Internet cafe computer for abuse by future users of that machine?

It sounds really good...but will have to try it out to see if it actually works in all reality. I'll let you know... probably some encryption and verification is better than none but not sure how foolproof this is.

Another interesting idea would be to verify that the person downloading the mail to read it is contacting a server defined in the SPF records for that domain, otherwise the server storing the mail for download is not legit. Haven't thought through how this could be implemented nor do I know if this is already part of SPF, to be honest.

Identity Based Encryption

Addendum:
I did some additional research and got answers to these and other questions in this Identity Based Encryption Post: http://randominternet.blogspot.com/2007/01/identity-based-encryption_30.html

Thursday, January 25, 2007

Storing Credit Cards

Tell me one more time why anyone would opt to store credit cards and take on the associated liability?

http://www.eweek.com/article2/0,1895,2085390,00.asp

There are services that have been in business for years that specialize in keeping this data safe and allow transactions on stored credit card information through PCI compliant mechanisms.

Monday, January 22, 2007

Cybercrime More Profitable than Drugs

I suggested in a recent post that hacking is probably more profitable than selling drugs.

Apparently it is true according to a white paper from MessageLabs.

I warned recently of the need for security in programming frameworks, suggesting that just because you are behind a firewall doesn't make you "safe" from all the world.

This whitepaper also hammers this point home talking about phishing attacks. If someone can weasel one piece of spam through and get one of your 800-20,000 employees to click on the wrong link...they may be able to open the floodgate to all your corporate data.

One recent article I read on top security practices suggests encrypting - everything. Hard drives, databases, etc. Plus you need a good key management system in case someone loses their password or means of encryption and needs to reverse it.

But the point here is - email is the doorway hackers are trying to crack. And just becuase you don't see it - think again. They are pretty sly. Virus programs embedded in malware so the more obvious hacks are wiped clean, monitoring logins so when you login they vamoose, using students at Universities, disguising themselves as harmless but annoying bots...

Here's the white paper regarding the latest email attacks and IT security:

http://reg.itworld.com/servlet/Frs.frs?Context=LOGENTRY&Source=eTEXT0104hm&Source_BC=7&Script=/LP/10011793/reg&code=MSGPSA0122

Sunday, January 21, 2007

Google Imposters

Here are some IPs that recently reported themselves to be Google IP addresses to our server, however looking up those IPs seems like perhaps these are imposters.

64.202.165.132
OrgName: Go Daddy Software
OrgID: GDS-31
Address: 14455 N Hayden Road
Address: Suite 226
City: Scottsdale
StateProv: AZ
PostalCode: 85260
Country: US
NetRange: 64.202.160.0 - 64.202.191.255
CIDR: 64.202.160.0/19
NetName: GO-DADDY-SOFTWARE-INC

72.232.194.66

NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07

72.14.75.44
ISP Alliance, INC. ZCORUM (NET-72-14-64-0-1)
72.14.64.0 - 72.14.127.255
Millry.net MILLRY (NET-72-14-75-0-1)
72.14.75.0 - 72.14.75.255

___________________________

66.102.66.148

OrgName: Cingular Wireless
OrgID: CINW
Address: Cingular Wireless, LLC
Address: 12555 Cingular Way, Suite 4360
City: Alpharetta
StateProv: GA
PostalCode: 30004
Country: US
NetRange: 66.102.160.0 - 66.102.191.255

________________________________

66.102.186.15

OrgID: INKG
Address: 177 Wellington Street
Address: Suite 302
City: Kingston
StateProv: ON
PostalCode: K7L-3E3
Country: CA
NetRange: 66.102.64.0 - 66.102.95.255

__________________________________

217.160.230...

inetnum: 217.160.224.0 - 217.160.239.255

netname: SCHLUND-CUSTOMERSdescr: Schlund + Partner AGcountry: US

Saturday, January 20, 2007

Windows Defender - Cool Feature

[UPDATE: Windows Defender had all the useful functionality removed in Windows 7. So someone will have to write another application to do this all over again so Microsoft can by it for billions of dollars all over again.]

Windows Defender has a feature that is pretty cool. I don't know if they added it recently or I just missed it but it really helps pinpoint the nitty gritty of your network traffic.

If you do a netstat in a command window you can see a bunch of IP addresses and ports and try to figure out which apps are generating which of those lines of traffic - and it is a pain.

Windows Defender has a section that tells you which programs and services are connected to the network, as well as the end point IPs and ports.

For example you can see a program xyz and the local IP is your local ip address connected on port 52345 and the remote IP is IP 72.34.53.232 (randomly picked this out of my head) on port 80 (which you know means you are connected over HTTP probably to a web site but possibly to something else.

Then you can look up those IPs on DNSstuff.com or in the appropriate databases: arin.net, lacnic.net, ripe.net, apnic.net, afric.net to verify that the process claiming to be the Google Toolbar update checker is really going to a Google IP address.

Pretty cool and much needed...if you've been following this blog for the life of it back to the day when I was complaining about this problem with Windows (and reporting it to a guy that I know is in contact with Bill Gates.) Could I have made a difference? Who knows...I am just happy to see it.

What would be even more useful now (maybe it is there) would be to log all this traffic because I have a feeling hackers are monitoring logins and web sites and they know, for instance, when someone is remotely connected to or logged into a machine, when an app has been updated, and then they wait for you to get off and fire up their nasties. So whenever you look on the machine - it's clean. You never see a problem real time.....so that would be the next logical step. I'll have to do some research to see if it's in there already.

Friday, January 19, 2007

Match.com Scam

I have a friend who is always telling me stories about her friend who is on a quest to get married. She's a an attractive doctor. She must be smart as she made it through medical school.
So anyway her latest move was to try match.com. She met this "terrific" guy. He sent her a picture - he was a gorgeous black man - supposedly a model from California now on assignment in Africa. Nigeria, to be exact. Anyone involved in Internet security already knows where I am going with this...

He has this match.com profile which is PERFECT. I like walks on the beach, holding hands, watching the sunset...cuddling. Ahem. Ha! I'm cringing as my friend tells me the story...

Within one week my friend's friend is hooked. She thinks he is "the one" and he says he can tell she is "the one" and doesn't want her to talk to anyone else.

...and then it comes...the story...he has these money orders or something that he can't access and needs her to transfer some money...pretty much anyone up on Internet scams knows the routines...

But she is in love. She tells my friend about it and how she's wired this money etc. and how it showed up. Of course my friend is totally freaking about it and like what the hell - don't do it. But her friend is convinced this is a good guy and sure that he must be in love with her and the bank account is real so...she ends up asking someone else who confirms it is a scam and she tells the guys she knows what is going on. And last night I guess they called her twice.

Well I told them to report all of this to the FBI immediately on the Internet crime link...or should it be the CIA as it is international...or both...my friend says "well she reported it to Match.com and his account was somehow closed..." I urged them to report it with any phone numbers they have, etc.

And then my friend asks - so what can you do about these people in huts in Africa - she says she's seen TV shows where they have computers all lined up...what can we do? It's a government thing. There needs to be an international effort to crack down on this stuff. Everyone knows there are so many Internet scams coming out of Nigeria and ripped off software and stolen goods, and hackers in China doing espianage for the government and the Russian mafia stealing credit cards and hacker organizations like Gulli.com and spammers in Brazil. Everyone knows....but is anyone doing anything about it?

And if a doctor like my friend's friend can fall for such a scam....

Hopefully Match.com has some sort of automated program that analyzes content to look for scammer type material but I am not sure how this works with privacy laws. The least they can do is make a HUGE alert on their web site to anyone signing up for and using their account. Obliviously they are not doing that since this person did not see any such warning - or it needs to be more blatant.

Thursday, January 18, 2007

Preventing Zero Day Attacks

This looks promising. Symantec is using brains instead of a database to figure out if software is malicious or not. Something like this is definitely needed - over and above a database approach. It is too easy to change a file name - let's say if you know xyz.exe is a known hack - the hacker can simply post that file all over the place for the unwary user to download with countless other names. Zero day attacks need more than a known list of hacks because their goal is to get out and do damage in one day - before they get into that database. Also with an FBI representative claiming that 15% of the world's computers are hacked and/or controlled by command and control servers doing dirty work - and new hacked servers coming online every day, it is impossible to block out hackers based on IP address or other identifying information alone.

http://www.networkworld.com/news/2007/011707-symantec-to-use-sonar-to.html?nlhtsec=0115securityalert3&company=BMC

Tuesday, January 16, 2007

Open Resolvers - DNS

Open resolvers seem to be a problem as defined here:

http://dns.measurement-factory.com/surveys/openresolvers.html

I have a new client who is coming from one of the companies on this list of known open resolvers:

http://dns.measurement-factory.com/surveys/openresolvers/ASN-reports/20060923.html

We shall see if and what problems come out of all of this.

Here is some more technical information about open resolvers:
http://condor.depaul.edu/~jkristof/slides/dns-ctinetseminar.pdf

Wednesday, January 03, 2007

Today's blocked IPs

Here are the Ips blocked by our hacker filter:

193.110.140.148
220.181.19.187
38.98.120.70
220.181.19.187
71.13.115.117 (multiple times - reported to network but has not stopped)
220.130.191.239
206.138.130.2
64.229.220.96
88.198.43.39
62.13.25.219
220.181.19.164
216.71.96.94
206.67.139.100
38.98.120.70 (multiple)
38.100.225.5
76.215.57.44

Sunday, December 31, 2006

89.240.207.15 - Unidentified IP?

Interesting, the information for this IP address is mysteriously not found in the IP databases.

89.240.207.15

DNS Stuff reports that it resolves to the UK. The information should be found in RIPE (ripe.net) however it is not there, either.

Toshiba Power Saver - Hack or Problem?

Is there any reason why the Toshiba Satellite laptop power saver needs to dial out to the Internet? This particular piece of code has been the source of major problems on my last two computers and just had an error with a new one I bought only a couple of months ago.

Bascially the first error I saw on this computer is when it was connected to a wireless network and I shut down the connection. Then the Toshiba power saver gave me an unexpected error message.

So why is this power saver getting errors when I shut off internet access unless it is somehow dialed out to the Internet, pray tell?

Very curious as this is the same component that continually crashes even after re-building my last Toshiba about three times. Each time I start having problems with the power saver. I thought it had something to do with my third party power cord that also flaked out but on this new computer I have only used the power adaptor that came with the machine.

So either there is a hack in this software that is somehow allowing access it should not - or there is some really bad programming and error checking in the software.

I hope someone out there is reading and will do some additional testing on this besides just hackers.

Friday, December 22, 2006

For those who throw up their hands at hackers...

Hackers sell zero day exploits to Microsoft products at $50,000 a crack.

http://www.eweek.com/article2/0,1895,2073611,00.asp

Hacking is profitable. Just as is selling drugs. More so.

The internet is the new wild, wild west. Lawlessness abounds. Fend for yourself.

By the time the Marshall arrives it will be too late, and what good is one guy against a gang of thugs anyway.

Tuesday, December 12, 2006

Students, University Networks and Criminals

You'll probably never believe this but had it in my head for a while to write about the huge amount of traffic I see coming from universities that is obviously hacker traffic. I was going to suggest that maybe someone was paying students to do dirty work or possibly download "cool new stuff" which is unknowling running worms, viruses or malware. Something has to be going on at Universities because I cannot believe they are all just hacked to such a high extreme.

Lo and behold I found this article today:

http://www.pcmag.com/article2/0,1895,2070706,00.asp

Saturday, November 25, 2006

Command and Control Bots

Working away and suddenly a whole bunch of hits on my server from bots around the world lead me to suspect that these IPs are somehow working together in a coordinated attack of some kind.

Could be coincidental but just saw a whole bunch of hits in a short time period. I have been working all day and not been seeing this. These hits are from the usual suspects - Germany, Taiwan, etc.

And coincidentally - I just made a significant update to my web server. Seems as though they are monitoring changes.

64.124.85.78
64.34.145.194
64.34.145.195
66.246.252.172
38.100.225.11
193.47.80.39
220.130.191.240
219.142.118.37
212.241.204.251
38.98.120.70
64.34.145.198
88.198.43.39

Tuesday, November 21, 2006

Sites with XSS Flaws

Here's a forum of sites with XSS flaws. Verify for yourself. If you can stand the terrible language and tangents.

Sites with XSS Flaws

I accidentally found an XSS flaw on my bank's web site recently. They were trying to prevent it by using a JavaScript pop up box. Helllloooo. Who doesn't know you can turn off JavaScript these days? A bank for goodness sakes...my money at stake.

It is a small credit union. Needless to say I am in the process of changing banks.

Saturday, November 18, 2006

Sunday, November 12, 2006

Process Monitor: What is that process doing?

Microsoft took over sysinternals.com as mentioned and in so doing is replacing regmon and filmon with the Sysinternals Process Monitor.

Process Monitor

This looks to be the information requested for months in my pleas to help find out what is causing problems on a machine in past articles (of course I am just one of the many...) I haven't tried it yet but if it lives up to the description it could be very useful if and when you suspect hacking on a machine - to verify and validate every process and user and what they have been up to.

Friday, November 10, 2006

Windows Security Utilities

Here are some utilities that can be used to explore what is running on your machine:

Security Utilities

Microsoft has purchased a the site formerly Sysinternals.com which was a good source of utilities - probably used by both hackers and legitimate security professional alike.

Wednesday, November 08, 2006

Kernel bugs & vulnerabilities

Which OS has the most hacks -- and the most alarming hacks or bugs?

This month that topic is being explored by some developers on this web site with contributions accepted from other developers around the world:

Kernel Bugs

The scariest one to me so far is the GDI bug on windows that allows escalation of privileges to take over a machine. Not good and no fix available yet supposedly.

Also interesting are the tools used to find these bugs. Aren't the developers building this software familiar with and testing their software with these tools for such a critical piece of functionality such as an operating system kernel?

Yeah I might not be using them for my code but I don't have the whole world relying on the securty of my software as these vendors do.

Tuesday, November 07, 2006

Site Rippers

There are many reasons why someone may want to "rip" a site but in my opinion, it should be illegal. Things are copyrighted and available online. If you need them offline you should have to request permission from the site owner.

I would guess most people are site ripping for the purpose of reverse engineering a site either to compete with SEO rankings or to try to find a way to hack the site. For instance they can rip the site, run tests against it without hitting your web logs, and then put the program they have developed to do whatever to you web site undected - so it looks like normal traffic in your web logs.

Some site rippers are obvious - like looking in the request headers and finding the user agent. Others are more sly, doing things to cover their tracks and appear as if they were a "normal" user.

What to do about site ripping? Good question. First block the blatant ones. Second, look for traffic anomalies that don't appear to be "normal" users clicking through a site at normal speed. Finally, frequent site changes can help ensure someone has not written a program to walk through your pages and do something malicious. You can "break" their code by finding ways to change your pages frequently.

Tuesday, October 31, 2006

Codecs, Drivers, and Kapersky

Fake Codecs and Kapersky - written by hackers?

Here's something more about fake codecs and driver security hacks: Fake Codecs

I've wondered about the potential security issues with drivers for quite some time.

A note on Kapersky: Since it recognizes this hack and was used in some very sophisticated hacking in commercial software server abuse (see a recent post on a hack that installs it's own virus checker) I am wondering more and more about the virus scanner.

So I read more about it: This company seems to be "headquartered" in a number of countries all over the world, listing Russia first. I read that they have since moved headquarters to England and a visit to their web site reports a US address.

I bet it is the best virus checker out there...that doesn't mean I'll use it.

Let's say someone wanted to infiltrate the most protected and secure machines around the world? What would be the most effective way to do that?

Think Trojan horse.

Write the software that is protecting them of course.

Just a twisted idea for a movie plot.

Instead of making the world hate them - by sneaking things onto their machine or creating PR nightmares such as this supposed FBI Keylogger (Magic Lantern) has done -- the world loves them...and invites them in...yes protect my computer!

Here's a twisted thought: What if Kapersky likes the idea that Microsoft is blocking out anti-virus checkers from other vendors:

Kapersky says Vista doesn't block out anti-virus vendors

I did some research on Kapersky just for fun...I'm sure all security software has bugs but here's what I found...

Kaspersky Anti-Virus cab.ppl CAB Archive Handling Overflow
A remote overflow exists in Kapersky Anti-Virus. The 'cab.ppl' engine fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted CAB archive, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Kapersky Buffer Overrun

"The recent compromise at Kapersky Labs, in which subscribers were potentially duped into accepting fake updates which contained the Bridex Worm, demonstrates the critical importance of this enhanced approach to update security," said John Sharp, president and CEO of Authentium in a statement...Kapersky fake downloads

Something that someone else will need to interpret Congrats, you've detected Kapersky AV

Here's another article worth a look - on security problems with your anti-virus software. One of the problems with Panda could leave your machine open to a complete take-over by a hacker. A seemingly innocent error...

Security problems in Security Software

Who's auditing the virus scanners and security software?

And who's to say all distributions of a particular software are the same?

And who's to say things aren't hiding in plain sight?

Ok yeah it's just a thought. Just kidding. Kind of.

Verify, validate, audit.

Thursday, October 26, 2006

How much of your traffic is HUMAN?

I just did an analysis of my web traffic to see how much of it came from valid potential purchasers of our products and services collectively and how much of the traffic came from some sort of automated mechanism - bots, robots, spiders, programming libraries, widgets and unidentified surfing objects.

60% of the traffic was from machines. Non-human beings. Non potential sources of income. Of course the search engines are helpful in getting traffic to us and some was our monitoring system, but 60%?? That is a lot of wasted bandwidth because not all those search engines are at all helpful. Some are actually malicious.

Monday, October 23, 2006

Stock Spam

I've written about a lot of problems related to dlls and spam spewing out of my servers. Maybe this was the source:

A hack with it's own virus checker

This piece of malware is spewing out all that stock spam you've possibly been seeing lately with some pretty advanced tactics.

The article states that the trojan uses peer-to-peer technology to communicate with command and control servers, however it does not tell you how it got on the box in the first place.

This software is making some use of dlls...a major annoyance if you read my previous posts.

Sunday, October 22, 2006

Stock Picking Service - Internet Influence?

I got a request from someone to help them market a stock picking web site. I am not yet completely sure what it is and how he makes his money. He sells a newsletter on one site and gives it away free on another site.

While researching the customer I found that there are a bunch of spam like stock postings with some apparently somewhat useful information but I am not quite sure yet if it is clearly spam or just a feeble attempt at marketing.

Then I notice this other guy's name all over related to the guy who made me the request. So I go check out the other guy's web site and he's got this video of himself and a clearly used-car salesman looking site guaranteeing people they will make money using his stock analysis / picking service.

So I start to ponder whether these guys are legit or not and then it hits me. The first guy wants me to get people to sign up for his free newsletter at 1000 people per day. In one month that would be 30,000 people.

If he says "buy this stock" and 30,000 people buy the stock - what effect will that have on that particular stock? If he says sell....

I am not sure exactly how many people it would take to influence a stock but the thought is somewhat interesting. L. Ron Hubbard, founder of Scientology and author of Dianetics, was quoted as saying "if you want to make a little money, write a book. If you want to make a lot of money - create a religion" (according to my professor of comparative religion in college). I found a reference to the statement here. That always fascinated me - that he said it, did it- and people still follow this religion even though his motivations are blatant.

The same principle kind of applies here. If you can get thousands or even millions of people to believe you have magical stock picking ability and some incredible "magical" software that helps you pick stock - and then you tell all your believers to go buy or sell something - you may be able to influence the market. And guess what. You believe in yourself too in that case...Because you know what will happen when you say "go".

Friday, October 20, 2006

Microsoft Vista Driver Authentication

In this article a Singapore security expert shows how Microsoft Vista correctly blocks a malicious driver attack, and yet how other vulnerabilities exist in the driver security process added to the operating system. Microsoft Vista driver authentication

At least I applaud Microsoft for making attempts to resolve this problem but it looks like they still have a ways to go.

My friend from Microsoft just warned me that Vista's new security model is not good, however he didn't say why. He was in the past working on something to control driver security and completely frustrated with Microsoft and his job. He used to work with really smart people and sounds like they left one by one and no one wants to solve the "really hard problems". Could it be that Microsoft is infiltrated with people who do not want to solve these problems? Or is it that they just don't want to take the risk of doing something extremely complicated and have it exploited and put their heads on the chopping block at Microsoft? Who knows.

Even if Vista's new security model is not good - could it be worse that what existed before? It seems that some level of authentication is better than none, doesn't it?

Thursday, October 19, 2006

SPF Records: Do it Now

Yes a lot of people complain about the problems with SPF records. However the problems with not using them are greater.

Right now I am getting hundreds of bounce back messages because spammers are spewing out messages using my domains.

The problem for the people who are using mail systems that do not check SPF records is that they do not know this spammer IP is not on our allowed list and that this is obviously spam. If their mail system was checking our SPF records they would not be getting the messages in the first place, and if it was a good mail system it would not be spewing out bounce messages for spoofed emails.

The problem for mail administrators and mail servers is that by not checking SPF records a lot of bandwidth and processing power is wasted. If they would first check SPF records before touching the mail then they wouldn't have to even deal with checking to see if the user really exists on the system, and storing the message at all. And possibly spammers would leave their servers alone since they can't get messages to it.

The problem for me is that the end users, our potential customers, who are uninformed about SPF records, spoofers and spamming, is that they may be reporting our email as spam to their service providers and our domain may get blocked - incorrectly - by mail administrators and mail systems that are not smart enough to look at the spf records to verify the mail is from a legitimate source.

If you are not using SPF records it could be harming your business and limiting your business opportunities. Let's say you sumbmit a request for a quote to some business in their web form - they reply to you but you never get it because their domain has been incorrectly flagged as spam. Or let's say you get a bunch of spam and block that domain entirely. Now suddenly you can't get mail from a possibly legitimate new customer who didn't know their domain had been hijacked.

As I write this I must warn however that someone out there, needs to be keeping an eye on all this rejected spam...as mentioned in previous posts it could actually be used as a form of communication by people who do not want you to know what they are writing! So hopefully someone out there is keeping an eye on legitmate AND spoofed and spam email messages.

To find out more about SPF records contact your mail provider, your hosting provider and take a look at http://www.openspf.org

If your mail provider tries to talk you out of SPF records - yes there are some issues with them - but you can define all the allowed servers to send your mail and that should resolve the problem and make your domain harder to steal and spoof. In most cases they try to talk to you this way because they don't know how to set it up correctly - get a new mail provider.

SPF may not be a perfect solution - but it is the only solution I know of right now that even attempts to resolve this problem. Maybe there are others that are better and I would love to hear about them, but my mail provider has received awards for secure email solutions and this is their recommendation.

Sunday, October 15, 2006

DDOS Attacks

This past year I was subjected to a huge amount of Fox News. I prefer the BBC and NPR any day, but I find it interesting that in all the news stories about the information posted on Al-Jazeera about the soldier/prisoner scandal I never heard anything about this:

DDOS attacks on Al-Jazeera

And let me tell you, I was with a news junky and we were watching every right wing news show known to man. Maybe the newscasters just didn't understand it. This is almost scarier because the next real war is at the computer and network level. I have written about this previously.

But enough of that. The interesting thing about this article is that DDOS attacks can cripple a web site -- and that using a private network such as Akamai can be a solution to this problem. Probably at a hefty price, of course.

Thursday, October 12, 2006

Web Site Hacks

I have mentioned most of these previously but here's another resource outlining potential web site hacks:

Web Site Hacks & How To Fix

Chargebacks - the Crime No One is Watching

I received some chargebacks on my merchant account. Supposedly they are not really chargebacks, however if I do not provide the information requested on the form back the bank within 25 days, they can take the money out of my account.

The reason listed on the piece of paper I received in the mail from my bank (Bank of America) is this: 32-Cardholder Does Not Recognize Transaction.

I contacted the cardholder and they told me they never reported any problem with the transaction to their bank. Someone is initiating this response, it is not the cardholder and therefore it is fraudulent based on the response on the document I have.

Worse yet, the document asks me to fax the account number, expiration date and all the information including a signature from the sales draft to their fax number.

Just by reading this it looks as if I have to provide the ENTIRE account number, expiration date and the customer's signature. Hmmm. Is this secure to be faxing this stuff around? When I called in they said I could just give them the last four digits. I do not even store the full card number anywhere for security reasons. (So if you're hacking my server - you're wasting your time).

Finally when I explain this is potentially a fraudulent scam and someone should look into it and try to crack down on this there is nothing they can do. They just blindly send the requested data to any bank that asks for it in any country (this is an international web site) to resolve the issue. Supposedly they would not send the information "to just anybody" but I wonder how tight that security is, based on this whole scenario, on validating where they are sending cardholder data and who has access to it.

Here's the potential: Someone, be it at Bank of America, the third party bank, or a hacker, could be intiating the charge back to me and if I miss it, the money is taken out of my account. But guess what, the cardholder never said they didn't recognize the transaction in the first place...think about it...where did that money go?? Someone's pocket - and not the right one.

Monday, October 09, 2006

PayPal Sent Me a Virus

The other day an address listed as coming from PayPal sent me a virus and it appeared to be actually coming from a PayPal email server. It was caught by the virus checker on my email system.

So I did the good citizen thing and reported it to PayPal so they would know and could look into it.

And they send me back a message stating something like:

"PayPal occasionally sends message to users...if you don't want these messages go into your preferences and change them..."

Sorry but I didn't see the option for "DON'T SEND ME VIRUSES".

Friday, October 06, 2006

Blog Spam

Here's a company using blog spamming to advertise products and presumably to try to increase search engine rankings with crap writing:

http://payperpost.com/

This company is advertising to bloggers to get paid for writing stuff for their advertisers. Heck I write fast I should probably do it but I won't - because I have some stupid principal in me that doesn't want to spew out fake garbage.

The problem with this thing is that people are spewing out fake, useless, biased content in an attempt to make money. For instance you can write about some product and you're getting paid for it. Are you going to write something negative?? And even if you would, is the advertiser going to post the negative feedback? No.

To me this is a blog spam factory and wasting everyone's time.

Wednesday, October 04, 2006

Serve-U hack?

I was running a trial of Serve-U Corporate edition. At the end of thirty days it turns to the personal edition.

Coincidentally I started to have a bunch of problems on my machine around that same time. See two posts prior.

I reported the problem with dllhost.exe to my hosting provider.

Then suddenly my ftp software stopped working. It said the executable was missing. I tried reinstalling. No dice. I then uninstalled and reinstalled the thing and now it works again.

There are various things you can do to lock it down like restricting IP access, etc so I tried that.

I don't know if this is all coincidental but I started having all these problems at the same time which I mentioned in previous posts:

- cannot access admin portal for Datapipe in Mozilla
- email bounce backs show spam from my domain names (working on spf records now)
- ftp server is hosed and have to reinstall
- web server using 100% of cpu and supposedly reboots itself while hosting techs are looking at it (hmm)
- web sites and/or local network is dog slow upon occasion - sometimes so slow images don't load at all from my web server
- dllhost.exe running on my box when supposedly dcom is locked down and all IIS services are disabled
- IIS service accounts have been re-enabled

I only report what I see....I am making no conclusions here until I pin down what is going on.

Global and Catastrophic IT Hacker Holes

This is a great read. Peter Coffee outlines some really big IT blunders that caused huge problems losing millions of dollars, blowing up huge infrastructures and causing world wide waves of hacking.

Dirty Dozen IT Blunders

Tuesday, October 03, 2006

Spam/Hack attack on a Java User Group

Just another report from the trenches. A recent message from a Java user group mailing list:

it appears that our fun little wiki site has attracted spammers from holland
and russia. their favorite mechanism so far appears to be to create bogus
accounts and upload html files which contain spam.

I am running daily reports and swatting them as I find them. In the meantime,
if anyone finds anything else I might have missed, pls let me know.

Thanks!

Monday, October 02, 2006

Recent Hacker IP Addresses

Here are some recent hacker IP addresses. How do I know? Because they are hitting my server on the IP and not on the domain names, and requesting technologies that do not exist on my server. They are most likely scanning for things with known holes in them that have not been patched. Notice that the most highly sought after holes are in PHP. See my other posts about PHP hacks.

Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 12:24:16 PDT 2006 194.72.238.62 /
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Wed Sep 20 23:29:32 PDT 2006 194.72.238.62 /
Wed Sep 20 16:12:12 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 22:17:30 PDT 2006 194.72.238.62 /
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php

Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Mon Sep 25 10:26:23 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 13:45:56 PDT 2006 194.72.238.63 /
Tue Sep 26 12:15:09 PDT 2006 194.72.238.63 /
Wed Sep 27 05:58:18 PDT 2006 194.133.131.201 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 27 10:57:30 PDT 2006 194.72.238.63 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Sat Sep 16 14:41:49 PDT 2006 194.72.238.62 /
Tue Sep 19 04:12:53 PDT 2006 212.43.248.186 /
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Wed Sep 20 15:02:32 PDT 2006 194.72.238.62 /
Wed Sep 20 15:57:28 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Thu Sep 21 16:18:31 PDT 2006 64.246.0.17 /robots.txt
Fri Sep 22 08:59:01 PDT 2006 194.72.238.62 /
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php

Sunday, October 01, 2006

Invalid SSL Certificate Accessing Hosting Company Admin Web Site

Today was trying to access the Admin console for DataPipe (a managed server I work on ) and could not access the site via https in Mozilla using HTTPS. It keeps timing out. Interestingly enough when accessing it via HTTP in Mozilla or on IE with HTTPS it would work correctly.

The weird thing here though is that one time when I tried to access via HTTPS in Mozilla, I got an error saying the SSL certificate domain name did not match the domain name I was trying to access. When I took a look at the certificate details it was pointing to a choicepoint SSL certificate. I am not sure but I think it was secure.choicepoint.net.

Interestingly choicepoint.net is in Atlanta which was probably the most major source of hacking I saw while on my previous hosting provider network. Could be a coincidence. Coincidences and random Internet connections abound.

I went to read about choicepoint on the net and found this: choicepoint

Related?

Thursday, September 28, 2006

Russian Federation IP Going After My IPs?

Why is a Russian Federation IP address directly targeting one of my IP addresses?

81.3.160.38

Seems that they should be going after the actual web site url not the ip directly.

Could be a network admin mistyping an IP - maybe once or twice, but 16 times?

Here are some other IPs doing the same thing multiple times:

81.3.160.38 Russian Federation

66.221.181.243 C I Host

194.72.238.63 Netcraft Limited

194.72.238.62 Netcraft Limited

82.192.89.153 ORG-OB3-RIPE

64.114.199.1 TELUS Communications Inc.

66.221.181.243 C I HOST

81.3.160.38 OOO Riviera holding, St. Petersburg Russia

82.192.89.153 ORG-OB3-RIPE

64.114.199.1 TELUS Communications Inc.

66.221.181.243 C I HOST

82.192.89.153 ORG-OB3-RIPE

82.192.89.153 ORG-OB3-RIPE

Tuesday, September 19, 2006

PDF Security Exploit - Adobe Acrobat Reader

A hack in Adobe Acrobat Reader has been found to allow running malicious code:

Adobe PDF Reader Hack

This is really scary knowing how many people use Adobe Acrobat Reader and how many PDF files are being downloaded from the web every day. Try viewing PDF files online from unknown sources as HTML when you find them in Google search results.

Tuesday, September 12, 2006

Adware Vulnerabilities

So you want to sell advertising on your web site. You go out and sign up with some affiliate network and put the ads on your site and ouilla - your making money every time someone clicks or downloads some software.

Guess what, you may be supporting the proliferation of malware.

Read this:

http://www.eweek.com/article2/0,1895,2013957,00.asp

http://ct.enews.eweek.com/rd/cts?d=186-4422-5-92-283087-513065-0-0-0-1

Friday, September 01, 2006

PHP Security Bandwagon

Been complaining a lot about PHP here -- BEFORE the whole infamous Senator Lieberman web site hack.

Looks like PHP security is becoming a hot topic - as it should be:

PHP Security Issues
PHP hacks
PHP Vulnerability Fixes

Thursday, August 31, 2006

Regarding Jetty Cipher Suites

Well it looks like the default in Jetty is going to remain that you must explicitly DENY the ciphers you don't want rather than enable those that you do want. This is against the principle of locking down everything first and then granting access only as needed. I would be worried that someone misspelled something or forgot to add something or new ciphers come along when you're not looking ...

Here is the response from the Jetty team:

The list of cipher suites available is determined by the security provider that is available in Java and by default it is the SunJSSE provider. Its not included in Jetty but in your Java installation itself. It is possible to use a third party provider but its not simple to install it (here are the details:

http://java.sun.com/j2se/1.5.0/docs/guide/security/jsse/JSSERefGuide.html#JCECust).

Thus, if you know the provider, you can just select the low level ciphers from the list of available ciphers provided by that provider. To see the list of available cipher suites in Java 1.5, just go to appendix A in the link above.

In appendix B, you'll see that Java has a list of allowed cipher suites for other providers. Java 5 will only allow third party providers as long as they support only those cipher suites in the list. You can just select the weak encryptions from this list and enumerate them in the excludeCipherSuites list so no one will be able to sneak in a weak encryption cipher.

Sunday, August 27, 2006

Foiling Key Loggers & More McAfee Software Problems

I had this laptop that kept inserting letters when I tried to login. It would stick a bunch of extra letters in after every key I typed. Seemed like if I waited long enough then it would stop and I could login. Or if I rebooted six times. Sometimes it seemed like a certain combination of characters hit into the keyboard out of frustration would work but the combination was inconsistent so that was most likely a coincidence.

Needless to say, logging into my computer with these extra characters spewing out of my keyboard was a total waste of time. I was so annoyed I went and bought a new laptop.

Then wandering around the random Internet I happened across a white paper by Microsoft talking about messing up key loggers by inserting additional random characters as someone typed passwords into text boxes. AHA.

I had McAfee software installed and although I tried to uninstall it something was completely hosed on my machine and it didn't work right. There were still random services floating around that I would mostly ignore.

I went to start/run and typed msconfig to pull up start up programs and sure enough there were some McAfee services in there yet. I killed them all and removed them from automatic start up on my machine. Yep. That stopped the random characters from messing up my login.

This is not the first time I have had problems with McAfee and the feeling like it is more a foot in the door for hackers through their update process rather than a piece of security software. This feeling was justified in the case where their "enterprise" software had a serious vulnerability doing just such a thing. See other comments in past entries here.

And if you're having problems with extra characters appearing and getting in your way...msconfig and stop the McAfee services from auto start up.

Wednesday, August 23, 2006

Online Advertising - Click Fraud

Here's a good article on the issues surrounding click fraud - the clicks you pay for at sites like Google, MSN and Yahoo and pages like this with the ads on the side of the page (or wherever).

Click Fraud

This is a serious issue for businesses because it can drain a lot of revenue. I once put up and ad and wasn't watching it and the amount billed in two days was something like $600.00 for Christmas decorations. I cannot believe all that was legitimate, however Google claimed it was and I didn't have the proper logs to look into it. I never had such an issue so didn't bother in the past.

More recently I have found that in competitive spaces like the online travel industry, online advertising is a significant part of the cost of doing business. The ads are very expensive based on the amount of clicks received.

Even worse is the web development space where you have to spend $2.50 per click just to get on the board. Something is wrong with that picture - and I got no leads for a huge amount of expense which just doesn't seem right.

Of interest is that recently I got a letter in the mail about a class action law suit against Google to get money back for fraudulent clicks. Hmm. Some lawyer will make a lot of money. The more alarming thing to me was that this letter stated I either had to send in a letter to remove myself from the suit, otherwise I would be a part of this suit and could never again sue Google for this reason. Well if I send in a letter is Google going to see that and shut down my advertising so they won't get sued? And what if I join the suit but I don't have any click fraud that I know of. I don't get any money now but I may have a click fraud issue later? I would like to think that Google is angelic and all that but reality is...Enron happens. The nice thing for Google is they basically settle this suit, pay a bunch of money, and can never be sued again for all the people who didn't see the letter or respond to it. And for those that did they might just close those people's accounts. It's always the little guy getting burned no matter which way you look at it. I saw subsequent similar letters for other online advertising services.

Click fraud is a serious issue for businesses. Not only do you have to ensure you aren't paying for fraudulent clicks, however, you have to make sure your site is secure, because if you are pouring a lot of money into advertising and someone else can redirect your visitors to another site - you're paying for their advertising.

Jetty Cipher Suite Handling

In the latest version of Jetty rc1 it appears that the method setCipherSuites was removed and replaced with excludeCipherSuites.

Cipher suites allow the web server to use different types of encryption. If you are allowing weak encryption on your web server - you'll want to fix this.

In the case of the latest version of Jetty now you have to think of and exclude every possible cipher suite instead of just specifying those you want to allow. This is very poor security.

The way to handle security is to first disallow everything, then specify the things you want to allow explicitly.

Microsoft has this in their top 10 application security problems list however they also do not follow this principle in regards to DCOM and RPC. Functions which are not required should always be disabled - especially those which can clearly be hacked, and administrators should be given the option to enable these things when needed.

In the case of Jetty I hope this was an oversight because this seems to be a well engineered application for the most part, however their use of certain non-standard third party tools does worry me at times. I hope they have checked every line of code inside and out.

Jetty is not the only organization doing this of course. I have written about many PHP frameworks which are on many more vulnerability lists!

Friday, August 18, 2006

Are You Getting All Your Email?

I have this vision for a new company - maybe someone can take my idea for free and run with it. I am having problems getting some email right now from a vendor. In the past I have had problems getting emails from other companies. There are various companies set up to check your web site content from different locations. It would be cool if there was a company that was not too expensive that would send you emails from different places and you could see online from where and when they sent them to validate you are getting all the email you think you should be. It would need to be something random so that the company stealing your email doesn't realize it's a verification email. Sounds like spam doesn't it?? Actually I think it's more like a secret shopper.

Tuesday, August 15, 2006

More PHP Hacks: Better Web Systems

Lieberman's site was hacked on the eve of his defeat in the race for US Senator. You can read more about it here:

PHP Hacks

I wrote previously about how I hate PHP becuase it is this free software with all these neat widgets which script loving programmers and web site owners who many not be programmers at all hack together into something that externally - looks like a web site. Ok it is a web site.

Well, if you're running a web site for the neighborhood street party maybe that is ok. But using someone who is not on top of ALL the issues in building and maintaining secure and solid web sites, and you're basing your whole career off this web site...good luck.

The problem here was that someone threw together a PHP web site (so you can guess it was cheap...) and didn't apply a patch that came out that would have prevented the whole problem. Too often people set up a web site and then think they can never pay attention to it again. Not true.

Whatever software you are running, besides your automatically updated Windows operating system, is potentially hackable and must be managed and monitored if you don't want someone to hack it.

And as mentioned previously I have somewhat of a disdain for PHP for various reasons. There are some good PHP programmers but seems more bad than good and more hacks than most other languages.

You get what you pay for.

Sunday, August 13, 2006

A different View of Netcraft Server Usage Rankings

Here's a twist on how to view the Netcraft rankings that tell you how many of each type of server (IIS, Jboss, Jetty, Apache, Tomcat, etc) are being used on the Internet.

The way these rankings are gathered is by scouring the web and pinging each web server to determine what type it is to add to the statistics.

Consider that a properly secured configuration will not advertising this information because then as new vulnerabilities are announced, hackers will use this information and scour the Internet (the same way Netcraft does) looking for these types of servers so they can attempt to exploit that vulnerability.

So instead of thinking, hey most people use IIS so I'm going to use that too, you can think, geez IIS has the most insecure installations therefore there are more IIS admins that don't know what they are doing than other types of web servers in terms of security.

By the way I haven't looked to see which type of server is most widely used right now. IIS is just an example. It is probably one of the free web servers like apache - which is a good web server for certain uses. The problem is not with the server itself. The problem is with administrators who are not properly trained on implementing secure configurations of their web servers.

I for one, knew my limitations and hired a managed hosting company, thinking they would have all the answers to make my systems secure so I could focus on development. Not so. Your application developers need to be aware of application issues and your internal staff and/or external auditors need to be checking everything your managed hosting company is doing. People at managed hosting companies can make mistakes, as well as the possibility of internal security breaches.

So secure your web server by hiding the implementation from prying eyes, including Netcraft unfortunately. Additionally, run security audits and don't assume your administrator or your managed hosting company can find every single problem. Security is a tough issue that requires constant monitoring and updating to keep up with the hackers.

Validating Click To Call Advertising Charges

I set up a pay per call account with this online advertiser and after a couple of months I was billed for a couple of calls. No big deal right? Couldn't cost that much? Well the problem is - I didn't get these supposed leads. I had no additional business, no messages, and no record of the phone calls in my logs. I only had some calls from some marketing research company in Canada. I wondered if they were calling and creating the charges and wanted to complain about that.

However instead, I must now complain about the advertising company. I emailed them and told them I think I was billed incorrectly because I hadn't gotten any "leads". However just to make sure I asked for the phone records so I could match them up to my phone calls and determine if I had actually received calls from other sales people rather than actual leads and that was the source of this whole thing. Maybe that research company is using their list and generating charges for people - in which case they need to stop!

Instead of simply sending me the phone logs or telling me where I could find them, the advertising company emailed me and told me to call them. I told them I couldn't right now because I'm on a contract during the day where I can't take/make phone calls and additionally, I am super busy. I use my lunch hours and any extra time to get projects done. Could they please just send me the phone records and I would look into it later.

Then they tell me they can't provide the phone records like the number that called me - for "privacy" reasons. What the heck? What kind of phone service doesn't provide you record of the calls you are being charged for? Does anyone see anything wrong with this picture? They could tell me I got 100 phone calls and have no way to prove it and I am supposed to just pay it? Even with pay per click advertising you can track back clicks to their source and validate you are getting the clicks you are paying for. Same should be true for phone.

Additionally this company told me that my phone line would not allow them to leave a message. That's odd. I have messages from this research company, vendors, etc. I also have hang up messages (clicks) from their number so if I can get the hang up why couldn't they speak and leave a message? However I realize something may have been wrong with the phone line and need to call the company providing me with that service in that case, so I asked them exactly how they tried to leave a message so I could resolve it. Were they on the main extension and didn't select a particular extension or what?

Additionally I sent some suggestions for making the service better and why it would make more sense if they could provide the phone logs. For instance if someone placed a call and didn't leave a message you could use the phone number in the logs to call them back. If nothing else you could validate that you actually did receive the calls you are being charged for. I asked if she could pass that message on because I think it would be valuable for marketers to be able to track the source of their leads and make this online advertising service more valuable if it could be associated with dollar value in terms of new sales.

In the meantime I said I would try to login and see if there was some information in the system I could match up to my phone logs to figure out what happened.

So what did they do? Did they answer my question about the voicemail so I can fix it? Did they pass my message along? Did they tell me how they tried to leave a message so I could resolve that problem on my end (if it was on my end)? Did they allow me to log in and find potential answers to my questions -- OK I should have looked there first but I didn't realize they had stats in their online system and actually just forgot about it altogether so I will say shame on me for that. But apparently the info I needed was not there anyway from what she told me.

But no...she deactivated my account and refunded all the money before I had a chance to log in. Hmmm... I did not ask for this. I did not refuse to pay the charges if they are legitimate. I did not even refuse to pay the charges if they were wrong! I was just trying to understand how they track these things because I didn't have record of these calls they were charging me for.... I just wanted to see where they are coming from!

Could it be that they closed my account because there were no record of these calls? Before I could login and prove it??

If you are paying for "pay for call" advertising online - check that the service you are using can actually prove that you are getting the calls for which you are getting billed.

Maybe this company is not even doing it intentionally...but they should think about and change the service so people can verify the charges they are receiving. The other thing is that competitors may be clicking on this link to generate invalid charges and there needs to be a way to trace this back to the source and make it stop if that is happening. This services provides no recourse for doing so. We simply have to pay for the fraud with everything else.

Thursday, August 03, 2006

International Crime Ring - The Web Mob

More correlations between all the data I have been presenting or almost a year now (go back to my very first story and the speculations about coordinated crime efforts spawning from Russia, China and elsewhere) can be found in this report:

FBI Discusses International Web Crime

My take that the next war will be an information war is being played out in references to Internet crime "cells" similar to terrorist network cells. My speculation further suggests that these "cells" are related to terrorist cells trying to produce nuclear bombs and weapons.

It's always about power and money isn't it? Sometimes I wish I was blissfully oblivious but I can't help what I see. And it all started by digging into the network of spam drowning my emails last year. The trends...the networks involved...the targets...the messages...I knew it was somehow coordinated.

Piece by piece the random Internet connections are connecting into a puzzle that is starting to form comprehensible and recognizable images that explain what is really going on.

The Internet is the new Wild, Wild West ... the new digital mob ... a new form of drug lords that want to rule the world ... a new brand of espionage and terrorism predicted in war games but very much an understatement in terms of the reach and complexity of the network and crimes involved.

Wednesday, August 02, 2006

JSP Vulernability

Besides DCOM I am wondering if there is some type of security problem with JSP. In one of my last entries you'll see some comments from people about various hosting companies. One of them mentions problems at a company I also have had problems with. They also mention that they wonder whether the problem stems from a JSP application.

Two things come to mind after reading this statement.

#1. That hosting company is partnered with JBoss, and open source Java Application Server that serves up JSP. They must have some expertise in that area - and potentially some people who are aware of known hacks who may have internal access at the organization.

#2. Maybe there is some sort of flaw in JSP...which was something I was starting to wonder prior to reading this. The thing about JSP is that it is compiled after the fact and there are some temporary files that contain the compiled code. What this means is that if someone can get into your cache off compiled JSP pages, they could potentially change those cached pages and alter the functionality of your application. You wonder what is going on so you do a diff on your code and it all looks the same...but in reality what was altered was the cached files. In the past I have found permissions changed on these cached files as well so they could not be deleted. That means that the code you think you are running may not be the code you are actually running.

#2 does not just apply to JSP but any programming language that compiles at run time. There needs to be a way to verify that the cache has not been poisoned.

So don't use JSP? I don't think that is the answer here because so many other application programs work in a similar way. In terms of Java application servers you could opt for using servlets. You can also perform some security auditing on your system to verify this is not happening.

DCOM - Vulnerability #1

I am starting to think DCOM is a real security hazard. Every hosting company I talk to seems afraid to touch it. The one I talked to last said disabling it can "cripple the OS". The one I talked to before that said it could be "disabled no problem". So which is it?

And by the way I didn't ask to disable DCOM. I just want it to be secure so someone can't use it to launch rogue applications like they did on my box at the last hosting company. Someone was able to launch apps that were sending spam and who knows what else (see previous topics) using DCOM.

I am not sure how they got those apps on the box in the first place - I know they were launched through DCOM however they could have been installed by other means. Was it through my app or someone internal to the organization who had access to the machine? I also find it interesting that they say they have no knowledge or understanding of my web application and I find this to be a crock of you know what since I recently found an article saying they are partnered with the company who wrote my application server. Since they are partnered up with JBoss they probably have some internal or closely related people over there who are very aware of any known hacks should they want to take this hacker action to steal my money. (Which was clearly happening for three months over there and I am not yet positive it has been resolved).

But back to DCOM.

SO whose responsibility is DCOM anyway? It's kind of an application thing. Something people use to write apps that connect to and talk to each other over the Internet and a way to launch remote applications. However it ships with the OS and so in my opinion, if a hosting company is claiming that it is going to "harden the OS" for you and manage security then security DCOM from launching rogue applications and being left unnecessarily accessible if the client is not using it is an issue that the hosting company should address.

So far not one single company I have talked to has anything about DCOM or RPC in their OS hardening policies. This is clearly a fact that hackers are taking advantage of based on my experience.

Additionally if changing DCOM settings can "cripple the OS" why is there no clear documentation from Microsoft on how to correctly secure DCOM and a more simple way to figure out what apps are using it and if it can be safely disabled on a machine where it is not needed. The documentation on the Microsoft web site is even sketchy - warning that disabling DCOM may cause problems - but not clearly defining those problems so a person can make a technical and accurate decision as to whether disabling it is the correct thing to do or not.

And as argued before, you should not be able to do something on the OS that allows you to "cripple" your machine via the user interface. I understand if you are changing registry settings or something like that. But changing security in the OS settings? What's the point of a user interface. It should have some application logic to prevent this and a way to safely back it out if they aren't going to prevent it.

Managed Hosting Companies - Internal Employee Access Policies

The saga continues...In search of a new managed hosting company.

Seems like most companies do not have well documented processes in terms of how and when employees can access managed systems and how this access is audited. To me I find this scary. I am working with some mid range hosting companies that support multi-million dollar businesses. I know because the reason I found out about one of these companies was through one of my $150 million per year clients.

One company was able to have a tech respond to me and outline the process. The company I was at previously could not articulate their processes and apparently did not have them written down anywhere - or want to provide me these documents in writing - because they constantly wanted to call me. The third company I am speaking to tells me that they have very stringent processes but no customer facing documents to explain these processes.

Since system administration is one of the very weakest points in the whole process - typically errors and hacks are caused by humans and most easily someone who has open access to the machine already - this is a huge problem! Yes so someone can't get into the building because you have biometric controls and chainlink fence lockers and separately locked cabinets. So what if your administrator is the one causing the problem!

This was highlighted by an instance at Internap that took down their whole Fisher Plaza facility one fine Friday evening - when I just happened to have a potential customer looking at my web site and freaking out, thinking I am some fly by night operation. Someone who had access to the building already went and flipped off the power switch somehow and for whatever reason in such a way that the generators didn't kick in. Seems they pushed that big red button that says "do not push" all over it way up in the air and Internap reported to me that it was "an accident"?? Hmm.

Internap is a good company but things happen. In "Who Says Elephants Can't Dance" Lou Gerstner says "People do what you INSPECT, not what you EXPECT." I wholeheartdly believe this after being ripped off by some of my own employees. Hosting companies want me to "just trust them" but that is foolish. You need to have good auditing in place in your hosting environment for true security - both internally and externally.

Tuesday, August 01, 2006

Managed Hosting Companies - Comparison

Here are some postings about potential managed hosting companies. Please note that I did not participate in this discussion. I am currently in the process of researching and evaluating new potential hosting companies in order to find one that can provide better security configuration and resolve some of the problems mentioned in past articles.

Managed Hosting - Comparison

It is very difficult to find a hosting company that sounds confident in their ability completely secure DCOM based on the applications I am running. I know what the potential settings are but am not sure why setting them a certain way crashes a server. Additionally it is unclear what settings must be left turned on for the applications at the managed hosting companies - most of them don't even know if their applications require DCOM or not.