Monday, October 29, 2007

The next generation of smileys

That last version of smiley faces were full of adware and other undesirable attributes. I wonder if these new smileys are just as two-faced:

http://media.fastclick.net/w/pc.cgi?mid=154031&sid=15400

Hopefully someone is looking into this.

Monday, October 01, 2007

Storm - Largest Botnet

Network World has an article about Storm which they report is potentially the largest botnet in the world:

Storm

In another article they write:

The most important thing about Storm, and the point on which everyone seems to agree, is that it creates botnets. Once a PC visits an infected Web site and Storm is downloaded, the PC is considered compromised, which means it can be controlled by someone else without the user knowing it. Together these compromised PCs create botnets that can be used to covertly send spam, launch distributed denial-of-service attacks, or host Web sites that download more malware.

Storm FAQ

The thing I don't yet understand about Storm is exactly how to figure out your computer is affected with this malware since the file names change constantly and the hacker is constantly changing the way it works. Is there something in the way of network traffic that can pin down an affected machine? Is there some way to define this when someone clicks on a link and goes to your web site? Someone needs to look at it from this level to help nail this down. If someone could track when someone clicks on a web site that is infected and trace that back to the hosted web site and stop the problem there, that would help.

Wednesday, September 19, 2007

More Grub

More computeres infected with the grub-worm (intentionally or not I'm not sure)


9/19/2007 19:01 166.70.146.22 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 14:42 70.21.113.185 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 14:16 82.91.56.67 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 11:14 75.152.151.162 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 10:42 24.97.214.156 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 7:52 88.176.176.60 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 7:27 24.97.214.157 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 4:34 82.56.126.238 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 3:58 66.30.137.58 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 1:11 67.87.117.17 Mozilla/4.0 (compatible; grub-client-2.6.0)
9/19/2007 0:41 75.152.151.162 Mozilla/4.0 (compatible; grub-client-2.6.0)

Tuesday, September 18, 2007

Romanian Hacker Bomb

This Romanian computer bombed our server: 83.218.203.111 at 9/18/2007 9:25:41 AM

In the midst of that this IP sent a completely invalid request from Japan: 219.103.236.49

Skype and Ebay Hacked?

I have been getting repeated calls from odd numbers lately. I do not recognize them or know anyone in those area codes so I figure if they are for real they will leave a message and I will call back.

The latest such odd nuber is 202 580 8200. I looked it up online and found this post on ebay (and I recently posted a couple things up there), so I figure this is some hacker/scammer that has cracked skype and uses it to call people without being identified.

http://72.14.253.104/search?q=cache:DdeHN0U5tW8J:forums.ebay.com/db2/thread.jspa%3FthreadID%3D1000403037%26tstart%3D0%26mod%3D1166256674699+202-580-8200&hl=en&ct=clnk&cd=1&gl=us

This is the post on ebay - I would wonder if it is related to their Romanian hacker fan. Hopefully Skype will get serious about this problem soon - it is too bad because this is a really cool service -- if you could trust that your phone calls were not all hacked:
___________

I recently used Skype to place a call from the UK to a 800 number (love it - it is the easiest, sure-fire way to make a free 800 call trans- internationally) and made several purchases using my credit card

Subsequently the credit card was rejected - when I called the card company, they said a security block had been added, and unless I could identify a given phone number the card would be cancelled. The card had become "associated" with a phone number used in fraudulent transaction. 202 580 8200 - is the number.

It turns out that this number often shows up as the original number for call id. Evidently this is known issue, but Skype either cannot or will not correct this.

So,be aware, and decide how you want to deal with it...Myself, I was able to find this information out while on the phone with the credit card company and said I recognized the number - card was not cancelled. I guess everyone needs to make their own decision about how they will use Skype, and the ramifications

Thursday, September 13, 2007

Peer-2-Peer Hacking

Here is a report on peer to peer hacking. What this leads me to wonder is if people can get hooked up on peer to peer networks without knowing it:

Peer-2-Peer Hacking

Preventing man-in-the-middle attacks on wireless networks

This book has some information on preventing man-in-the middle attacks on wireless networks.

Specifically:

Static ARP Entries
To protect against ARP man-in-the-middle attacks, which are described in
Chapter 2, set static ARP entries using a startup item script similar to the one
described for the firewall.

It goes on to explain how to do this.

Man-In-The-Middle on Wireless Networks

Friday, September 07, 2007

Man-in-the-middle Attack

This site has a pretty good explanation of a Man-In-The-Middle attack and different ways of doing this.

Man-in-the-middle Attack

This page explains how SSL might not always prevent man-in-the-middle attacks:

SSL not preventing man-in-the-middle attacks

Computer Weekly says RSA warns of more man-in-the-middle attacks as of August 15, 2007 due to free phishing kits being circulated:
Man-in-the-middle on the rise

I suggest the federal government puts out a free phishing tool - that sends the phishers details to the FBI.

This page suggests Firefox extensions are subject to Man-In-The-Middle attacks:
Firefox Man-In-The-Middle vulnerability

What we need are some good patterns out there to prevent this type of thing at all levels - network, application, and server configuration.

Also what is the fastest way to spot a man-in-the-middle attack?

Sunday, September 02, 2007

Snail Mail Nigerian Scam

I call this the Nigerian scam becuase it is related to all those types of scams you get out of Nigeria on the Internet but I don't really know where this comes from.

My friend got a letter in the mail with a check. It said she won $50,000 and all she needed to do was pay the UK taxes. She had to cash a check for $2600 and pay the $2400 for the tax and supposedly she'd be getting the rest of the $50,000.

Of course the check probably was coming from a bank account not belonging to the person who sent her the letter.

Of course I recommended that she report this - not just trash it. Send a copy to the CIA, FBI and local police.

Could this be related to the Monster scam? Or just another scam out of Nigeria to transfer money out of bank accounts that do not belong to them?

When is our government going to get serious about these problems and crack down on these people in a big, big, painful way?

Thursday, August 30, 2007

Tuesday, August 28, 2007

Monster hacker server in Ukraine

FROM:

http://www.networkworld.com/news/2007/082407-the-monstercom.html?nlhtsec=0827securityalert2

How was the information stolen? The Infostealer.Monstres Trojan runs batch searches by sending HTTP commands to the Monster Web site to navigate through folders, said Hidalgo. The malware then parses the output that appears in a pop-up window that holds the job seeker profiles that match the search criteria. Essentially, the Trojan worked as an automated search bot that located candidates, captured their contact information and sent it to a remote server controlled by the criminals. Symantec said that the server, though located in Russia, was hosted by a company out of Ukraine.

Essentially the article claims Monster was not hacked. I would claim that Monster needs to do a better job of scouring it's traffic and users and protecting those who posted resumes there in the past - like me.

Wednesday, August 22, 2007

PCI Compliant Managed Hosting

Someone needs to offer PCI compliant managed hosting with appropriate security auditing.

For instance firewall rules should be able to be seen by the end customer at ANY time and the customer should be able to have a third party test and audit all firewall rules and DNS rules that are supposed to be in effect without the knowledge of the managed hosting company and staff.

All touches on a server or network related to an ecommerce system or system with sensitive data including hardware, software and any network devices along the way should be logged and that log should be available to customers at any time upon request or possibly available at any time through a secure system.

Make sure customers are always up to date with latest VPN client software. My hosting company with highest industry uptime server rating was letting me run with out of date VPN software.

Monster Hacked

Monster was hacked and personal information was stolen.

Until our government gets serious about prosecuting intnernational hackers and system admins take seriously good and bad internet traffic and do more to protect apps, networks, VPNs, routers, etc....

This will continue.

And it may be the fall of Rome.

We built the computer. We created the problem. Let's fix it.

Monday, August 20, 2007

Length of SQL strings

If you are using SQL to record actions and log errors, make sure to validate the lenghth of all inputs before inserting into the database. If hackers can pass in a string that is too long they can cause an error that can allow their actions to bypass logging functions going into a database.

Hacking Regular Expressions

If you are using regular expressions you will want to filter out these characters from strings which may be used by hackers to change the meaning of your regular expressions when input is passed into them:

\, *, +, ?, , {, [, (,), ^, $,., #, and white space

Sunday, August 19, 2007

Google Bot Blocking Software

Google bot-blocking software blocked me out of Google adwords on one computer I am using. When I write to customer support I can't get it resolved.

If I didn't have a secondary computer to get in and change my ads - I could possibly be blocked out and continuously charged for something I am trying to shut down.

I have bot blocking software on my site - but if someone calls and provides the appropriate information I can easily resolve any false-posistives. This is an unhelpful response I received - I hope that Google does something about this:


Hello

Thank you for writing back to us. As I mentioned in my previous email, we are unable to provide you the information regarding what is leading to your IP address getting blocked while making certain changes in your AdWords account. I suggest that the next time you get this problem, please delete your system's cache and cookies and log in after a couple of hours.
If the problem persists, you will need to figure out the reason for the IP getting blocked yourself. I apologize for any inconvenience this may cause.

If you have additional questions, please visit our Help Center at https://adwords.google.com/support to find answers to many frequently asked questions. Or, try our Learning Center at http://www.google.com/adwords/learningcenter/ for self-paced lessons that cover the scope of AdWords.

We look forward to providing you with the most effective advertising available.

Sincerely,
Sandhu
The Google AdWords Team

TRANSLATION:


"Sorry we cannot let you back into the administrative site we are charging you for and therefore you may get charged eternally -- but you have to figure out what the problem is with our software, not us."

I know for a fact that there are amazing, smart technical people at Google who can resolve this issue in a matter of minutes. I wonder if they realize this is happening.

ProjectHoneypot.org

While searching for an explanation of the IEMB3 user agent string - which I can find no useful information about - I ran across this site which at first glance has a very interesting thing going on. The way I got here searching for IEMB3 was kind of odd since the page was just telling me they have no informationa bout IEMB3, however the concept of what they are doing, if legit, can help track down bots and spammers across multiple web sites across the Internet:

http://www.projecthoneypot.org/

How it works is you set up a monitor on your IPs and they tell you if they see any malicious behavior from your IP space. Of course you have to trust these guys to not be doing some monitoring for their own malicious purposes but hopefully someone will look into that. The concept is interesting and by so doing some unsuspecting web site owners may be alerted if their servers are being used by command and control servers to perform dirty work.

Saturday, August 18, 2007

Monitor Your Monitoring System

Do you know if your monitoring system is really monitoring what it is supposed to be monitoring? Have you audited it? Do you have a way to be notified if it is doing the wrong thing?

In my case I found out my monitoring system at DataPipe was set up to monitor IP address, not the urls I had requested. The problem with this is while the monitoring system may show you that your server is up, it doesn't tell you if there is a DNS error that is disallowing people from accessing your site - or worse - sending them somewhere else via a man-in-the-middle DNS spoofing attack.

Monitor your monitoring systems. Audit your hosting company.

Forum for Women Entrepreneurs Email List Hacked

Members of that group got this total spam email - with the organization's name in the subject line:

Official letter to Forum for Women Entrepreneurs

My name is Rev. Clysta de Armas,the president of the Fellowship of Baptist Church.
We are writting you this letter because we have recieved your recommendation from the Baptist christian organization in your country. You have been recomended as one who is trustworthy and our institution has decided to chose you for a humanitarian mission, one which will be greatly rewarding in financial terms.
The crisis in Zimbabwe has rendered many kids from european decent orphans and most of them have managed through the help of our missionary work to find themselves in South Africa and under the care of the Baptist Church world wide. In one major case a set of twin orphans were left with a treasure under the care and protection of the Baptist Church because one of our reverends was present at the hospital where the father passed away and the father had to entrust the safey and upkeep of the twins in the custody of Baptist organization.
Their father was a co-founder of the commercial farmers corperative union and in his will he entrusted all his estates to the two twin sons. We were also made executors of the last will and testament hence on the demise of Late Mr. Stevens, the sum of 15.5 Million dollars inherited by his sons Patrick Stevens and Mattew Stevens secured in VEF BANK in Riga Latvia was moved down to South Africa and secured in a special reserve account opened in the name of our church on behalf of young Patrick since is not mature enough to hold an account with any financial institution in South Africa.
God’s call comes clearly when we are listening for His voice. It is not just a one time call to salvation. That is the first call on our lives. But it is also a daily call to follow Christ in every situation.As I have tried to answer the call on my life, it has not always been easy or convenient, but it has always been the best for me. I challenge us all to take to heart our new emphasis and "Live the Call" each day. When we hear Jesus calling, let’s jump up and run to Him just as Mary did.
We would like you to help Patrick and his Twin brother Mattew. You may wonder, what do we want you to do for them.
1. Our church organization has no business ideas in mind to plunge this funds.
2. We are not involved in financial matters hence we lack fund management skills
3. We are prepared to raise Patrick and his twin brother Mattew until they are upto the age of 21 when they can manage their own affairs and be free from the orphanage but we need someone who will manage this funds for a period of 15 years because they are only 6 years old now.
4. We also need someone who will receive this fund oversea for this investment purpose.
5. We need a trustworthy and God fearing someone who will give proper accountability and also report events concerning the funds from time to time as shall be required by our organization.
6. For helping in the relocation of the funds to an overseas account, we are prepared to compensation you with 10% of the total funds and also in securing the funds in a solid investment we are prepared to offer you 30% of every yearly profit that shall accrue in the said investment.
7. The terms and conditions of this matter shall be put in a formal business and fund manager contract.
8. In your response, I shall send you some vital information that will enhance your decision making.
I am too busy with official matters regarding the church so please contact Rev. James Willis at the email below:
jameswillismail@sify.com
You can call him on the phone number: +27 79 753 3836
He has been given full authority by our church organization to facilitate this process and shall work in collaboration with you to actualize same so feel free to contact him.
Please respond to this call in the name of humanity.
On getting your response you shall be properly informed on what to do.
Thanks and may the blessings of God be with you.
He awaits your response,

Rev. Clysta de Armas

Take note , send your response to this email only to Mr. James Willis at jameswillismail@sify.com and additionally kindly call him at his phone number
+27 79 753 3836


Received: from gwsin04.mbox.net [165.212.64.16] by cmsmail03.cms.usa.net via mtad (C8.MAIN.3.27X) with ESMTP id 629LHRgwE0189M03; Sat, 18 Aug 2007 06:22:31 GMTReturn-Path: <clystamail_2006@sify.com>Received: from gwsin04.mbox.net [127.0.0.1] by gwsin04.mbox.net via mtad (C8.MAIN.3.31J) with ESMTP id 917LHRgwd0383Ms4; Sat, 18 Aug 2007 06:22:29 GMTReceived: from esmail01.eservices.usa.net [165.212.64.8] by gwsin04.mbox.net via mtad (C8.MAIN.3.31J) with ESMTP id 905LHRgwb0309Ms4; Sat, 18 Aug 2007 06:22:27 GMTX--Routed: 1 gwsin-bmrelay Q:bmrelayX--Routed: 2 gwsin-vs R:localhost:1825X--Routed: 100 IN-RELAY R::525Received: from fdvhgdf [63.147.22.100] by esmail01.eservices.usa.net via smtad (C8.MAIN.3.34P) with ESMTP id XID944LHRgwb8606Xma; Sat, 18 Aug 2007 06:22:27 -0000X--Source: 63.147.22.100 IN clystamail_2006@sify.com fdvhgdfX--MsgId: XID944LHRgwb8606XmaFrom: "Clista De Amas" <clystamail_2006@sify.com>To: [x@x.com]Subject: Official letter to Forum for Women Entrepreneurs - Seattle Date: Fri, 17 Aug 2007 23:21:50 -0700MIME-Version: 1.0Message-ID: <>Reply-To: clystamail_2006@sify.comContent-Type: multipart/alternative; boundary="--=_NextPart_0CEAF315_76FDB910_01C9F258.D84EF1C0"

Friday, August 17, 2007

Cisco Open Source Safe Mapping Software

Cisco released some open source software here aparently. Did someone verify this is really from Cisco? Just wondering.

http://www.networkworld.com/community/?q=node/18481&nlhtsec=0813securityalert5&

URIs can create security holes

URIs in your registry can launch applications according to this article. Some vendors make registry entries with these URIs to make it easier for people to launch applications, however this can lead to serious security flaws:

http://www.networkworld.com/news/2007/081507-new-uri-browser-flaws-worse.html?t51hb&nladname=securityal

Check your registry. Maybe we need Microsoft to wire a tool that reports all these URIs so you can remove them if you don't need or want them on your system.

Wednesday, August 15, 2007

Is your web reporting accurate?

You may not be getting all the referer information you think you are getting. Some data may be completely lost depending on what browsers and search engines are used.

I got to this article because something called GLinkPing.aspx was doing something funky on our server.

Check this out:

http://www.webmasterworld.com/website_technology/3076218.htm

and this:

http://www.javascript-examples.com/track-outgoing/
This article has some good points...

but what I liked best was the grand finale about the author blurb:

Jon Espenschied has been at play in the security industry for enough years to become enthusiastic, blasé, cynical, jaded, content and enthusiastic again. He manages information governance reform for a refugee aid organization, and continues to have his advice ignored by CEOs, auditors and sysadmins alike.
I feel your pain. Auditing and information security is way too lax in this country. It is an esoteric topic that the end user doesn't get so it can be swept under the rug by politicians (or maybe they don't understand it either). People in organizations don't know enough about it and trust people who don't want any more work or look ignorant to do to tell them everything is just fine.

Thursday, August 09, 2007

Fight Spammers - Block their Sites - Google - Help!

This article suggests fighting spam by blocking out the sites that host spam related products:
http://www.networkworld.com/news/2007/080707-uc-researchers-take-antispam-fight.html?nlhtsec=0806securityalert4&

This is an intersting approach to making spam less profitable and protect people on networks where these web sites are blocked, though it may not initially affect the amoung of mail in people's in boxes. The spam will still come - you just won't be able to get to the web site (which is good).

I think penalizing the web hosts that knowingly host these web sites for spammers when it is clear what they are doing is a better approach. Drive up the cost of running these businesses and send the people who support them to jail as accomplices.

Being a hosting company I know this is tricky. I don't want to go to jail because one of my customers sent spam - so this would have to be done knowingly. There would have to be proof of the actions and that may prove difficult when the hosting company says "we didn't know".

However requiring hosting companys that have had 2-3 spam incidents to perform certain types of audits like monitoring outbound mail traffic levels and such might help. If they see an exhorbitant amount of mail coming from a particular customer the should be able to determine if the actions are suspect. Typically you can tell a crappy, spammy web site or email when you see it. You can also find out if that company has a double opt in policy and a clear way to get off the list.

Another concept would be to require spammers to include footers that send complaints back to the top level hosting providers or networks. Each spam message would need to have a clear and easy to read abuse email address that goes to the hosting provider that way they cannot say "we didn't know"...

Obviously there are a lot of web hosting companies and server owners whose systems and networks abused without their knowledge, but some of these people are catering to the bad guys. Those people should be penalized along with the people they support.

Tuesday, August 07, 2007

Blocking Both Ways - China

Here's an interesting post on what China is blocking out due to censorship. Hey maybe they will block out my blog now. Cool.

http://www.schneier.com/blog/archives/2006/06/ignoring_the_gr.html

Anyway it's quite ironic that I want to block my sensitive information from an abundance of hackers coming out of China (and elsewhere) and China wants to block their end users from valid, useful, true and honest information that, once discovered, my help make the world a better place.

We can all learn from our mistakes.

China Building Cyberwarfare Units

Not sure how I missed this one. China is promoting cyberwarfare. Our country created the computer and it is the monster that may be the thing that knocks us off our pedastal if we don't get with the game and get our systems up to speed.

Just recently I went to a governmental web site and the security mechanisms and web site were absolutely pathetic. It is scary that we trust our data and put it all online for anyone to rip off behind these pathetic security models.

I hope that our government will make this one of our top priorities. Are you listening presidential candidates? Our country needs to focus on Internet security, intelligence, protecting our money and our identities.

Monday, August 06, 2007

Core Security Patterns - Wish List

I have pretty much read the Core Security Patterns book from Sun. Ok I skimmed a couple issues we aren't reading but I read some parts 3 or 4 times looking for the information I wanted.

The book is very good, but as I read it I realized I was doing a lot of things in it without having anyone tell me it is a "pattern" because they are just common sense.

The part I found missing was a basic comprehensive example of managing user logins and lost passwords and clearly identify when you send out someone's password that you are sending it to the right user (sending being as an encrypted email, or via allowing them to reset their password online). I understand to some degree this is in the book but from a comprehensive standpoint:

Ok so I store my user passwords as a one-way hash and that's fine and dandy.

But when a user wants to reset their password - what is the best and most secure way to do that? How do you ensure someone who has ripped off the hash cannot reset the password to whatever they want?

Also why do some places have additional questions you have to answer before you login or photos that have to match what you expect - otherwise you know you're at the wrong site. There could be security patterns for this as well for these type of double logins. Do they have login information coming from two different sources in that case?

And how do you know when someone is on dynamic IP addresses and moving from location to location that it is really the same person - you have to assume the user name and password are good enough?

And it talks about man-in-the middle attacks but as I read this it seems like all the discussion is one way - from the client to the server. The client ends up on a different web site.

What about from the server to the client? How can you really know that that the person you think is sending you the request is really that person? This is related to the above issue. What if someone submits a request and your server gets hacked and the person is redirected elsewhere from that point and all future requests are from another source that is then controlling that user? I would like some discussion on how and why that would or would not be possible.

Also your firewall should prevent IP spoofing, but does it in all cases? This is something I wonder because I have actually seen IPs missing in request logs, but perhaps this is some xss in interjection technique and my backup logs are getting all the data. I haven't had time to drill into this in more detail.

There is information about filtering requests but the book does not go into detail about how to filter out invalid characters for XSS and sql injection attacks. Why not put a chunk of sample code and say - use this for JavaScript, this for SQL, this for Java, this for Perl, etc. etc. etc. so people can drop this code into their apps for better security.

What about random request keys so requests cannot be duplicated as in the case of a hiddne form submitting from another tab open in the browser to your site? How can this be determined if the hidden frame does not pass the referrer with the request?

These are just some things I wondered about as I read this book.

Social Security Administration - Technology

It is amazing how poor the Social Security Administration web site and support are. It is no wonder we have a problem with identity theft in this country. I was trying to register for their online system to submit information for my company - W2 forms, etc. - and it doesn't recognize the information I am inputting - which is correct - and which matches the document they sent to me. The only thing I can figure out is that they don't have my correct birth date perhaps. Everything else is matching up.

The person on the phone was very non-technical and told me to call some technical support number if I get stuck again. I think someone needs to definitely review this web site and the security around it. It would probably be a good idea for someone to read the security patterns book mentioned in previous posts here.

Additionally they could at least install and SSL certificate on the main site so you can verify that you are at the official social security web site.

Saturday, August 04, 2007

WinHTTP Web Proxy - Hack or Bug or?

Hmm. I logged in to review my logs today and saw a lot of errors surrounding this particular service, which to my knowledge is not be started or run by anything I expect or want to be running on my server:

The WinHTTP Web Proxy Auto-Discovery Service service depends on the DHCP Client service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

A proxy can be used to forward requests to one server to another server - so has this service been exploited somehow to forward requests to our web site to some other server?

I hope someone at Microsoft can look into and resolve why this is happening and write a patch so that this service is only run when explicitly requested. I don't quite see why it should be required.

JVM Security Wish List

I wish when you installed the Java JVM on a server you could have fine grained control to include only the components you are actually going to use and a security wizard to set up the default security policies, for instance. This would allow not installing additional unneccessary code and potential exploits. I try to remove each jar or directory I know I do not need but I do not know what every single file in the jdk is and whether I can safely remove it or not.

Friday, August 03, 2007

Java Exploits On the Rise? Read this.

I am really curious how much Microsoft stock Larry Seltzer owns.

In his latest article: Java Exploits on the Rise he is reporting Java exploits in a rather curious way.

http://www.eweek.com/article2/0,1895,2161797,00.asp

First all he is talking about the Apple Quicktime implementation in Java. I am not sure the details of this but if there is an application written in a particular language and it has a flaw, typically that is an issue that should be blamed on the application developer, not the language which they chose to implement the application in, right? Perhaps the underlying flaw was a Java bug, but the orginal article he references states:

As in one of the two QuickTime flaws that Apple fixed on May 29, the pwn-2-own hole fixed earlier in the month involved a problem with implementation of QuickTime for Java that allowed reading or writing out of the bounds of the allocated heap, and it also worked by enticing a user to visit a site containing a maliciously crafted Java applet.

"An implementation of " meaning the bug was in the implementation of the application - not in the software language used to implement the application. Right? Let's be clear about what is actually happening in this case. From the words above it is not clear if the error was caused by poorly written application code or Java itself.

On the other points:

#1 I agree with this article stating that Sun's handling of the release of a security patch was somewhat problematic:
http://www.theregister.co.uk/2007/07/10/sun_java_security_update/

#2 The flaw of a buffer overrun in the JavaWeb start app: was this flaw a result of programming done in Java (Java itself does not allow buffer overruns so I doubt this very much). After testing out a download on the sun web site which utilizes at least some component of the Java Web Start app I get this message:

This web site wants to run the following add-on: Java (TM) Web Start active x control from Sun Microsystems, Inc.

Note: this is an Active X control. It is not required to run Java applications. It is a tool to help keep Java applications up to date. In this case it is platform specific technology, so if this flaw is related to this component of running Java it is due to an improperly written Active X control (microsoft technology) or something in the Java Web Start active X control utilizing an underlying OS component to display images, not Java as a programming langage - at least for this Windows component. I would guess in this case it was written in C/C++ and compiled in native languages for each OS, and that is how the same bug got propagated to Linux and Solaris as well but cannot know for sure. Because it was not written in Java most likey that is the source of the buffer overrun, not Java itself.

#3 As for the image parsing flaw:

Consider the recent vulnerability in Java's image parsing code.

followed up by:

The parsing of data coming out of files seems to be a never-ending source of security issues in all platforms.

Yes image parsing is a source of security flaws on all platforms - and more than one report has come out on image parsing by various Microsoft technologies including Office. Java does not claim to prevent all image parsing flaws in and of itself. Some of this would be up to the application developer to validate input and output. Additionally since images are actually displayed by the OS (Microsoft - GDI) I would question - is it not up to the OS to validate the image? I am not sure but since all applications use the OS to display images and the OS sends the data to an output device for human visability - then I would recommend that this error checking be done on an OS level. BUT. I am not an OS developer. This occurs on all platforms - so I am guessing this needs to be handled by the app given that info.

The fact that Java is used to write malware is more like a compliment to the language than a detriment. Hacks can be written in any language. Perhaps Java is used because it offers more fine grained control over the environment and is more reliable and takes advantage of the fact it runs on any OS. HMM???

Also for the malware he referenced - that is not a Java flaw but an application written in Java that someone would have to download and run - just as they would have to run malware on any windows machine. You can write a piece of malware in windows technology and email it to someone and if they run it and it deletes their entire hard drive - is that a flaw in the technologies used to write the exploit? Please do not mince words and twist reality into an article designed to create a big headline where people get an idea in their head and don't read the details.

And finally, the most outrageous part of this article, is that he is referencing an exploit on the Symantec web site which references an OCX -- a Microsoft technology. An active X control. Also, the article references JavaScript. Have you ever heard the statement "JavaScript is not Java?" JavaScript runs client side, not server side. JavaScript was used in the exploit - it was not exploited. The Javascript mentioned at the beginning of the article is used to exploit Microsoft IE bugs and is an old, known exploit. The bottom of the article summarizing the new exploit and further clarifies that this is a Microsoft browser flaw - not a Java exploit:

The good news is that the vulnerability exploited in this attack was already patched by MS06-067; the bad news is that malware authors now know and will use this new technique. Heap Feng Shui really takes heap exploitation for browsers to the next level and it’s a powerful method that allows the creation of more efficient and reliable exploits in the future.

Yes there are flaws in Java as with any programming language including this very serious flaw in Java Web Start:

http://www.securiteam.com/windowsntfocus/5UP010UM0G.html

Every language has holes and will continue to be exploited just as banks are still robbed. However I still think Java provides a lot more control over your environment to manage security - unless you are running on Windows in which case you have to rely on the Windows OS for some aspects of security - which can be good and bad. If you are not an OS developer, Microsoft pours more money into OS development than you could do alone and you may be better off, though Linux is cheaper and for OS developers they will have more total control of the environment and Linux has proven to be more secure in some apsects than Windows.

However everything is ultimately exploitable and constant analysis is needed - no matter which language or OS you choose.

Audit the auditors

I keep repeating in this blog...audit everything. Audit your auditing software. Audit your security auditors. Audit audit audit.

And software cannot do EVERYTHING for you. Some brains and analytics need to be involved in any good security policy:

Audit your security software

Wednesday, July 25, 2007

DNS Bind Vulnerability

I saw headline reporting a DNS Bind vulnerability. Make sure you have the latest updates for your DNS Bind servers.

Sunday, July 15, 2007

Core Security Patterns

I was reading a book called core Security Patterns from Sun today and in the introduction chapter in this book they state:

"A Gartner Group report [CSO online] estimates that employees of companies are responsible for more than 70% of the unauthorized access to information systems in those companies. It is also employees of companies who perpetrate more than 95% of information systems intrusions that cause significant financial losses."

So when I ask - do you just "trust" your managed data center employees like the managed hosting companies would like you to do? No. Audit everything. If they cannot provide an audit trail to explicitly define who accessed your server on what time and day and what they did - you'll need to keep your password to yourself and manage access to your server and do your own auditing -- don't use that company.

And for all those companies that swear up and down that they are invincible and secure, I say no one is ever 100% secure and constant auditing and monitoring is needed. Case in point, this book says:

"According to an FBI survey [eWeek] of 500 companies, 90 percent say they'd had a computer security breach, and 80 percent of those said they'd suffered a financial loss as a result."

There are more reports an examples in the book as well as a good list of security patterns for those who use a programming language that allows you to, in my opinion, have more control over your environment such as with a Java web server. I say that because you cannot get the IIS source code...

Anyway the book for anyone who wants to read it again is:

Core Security Patterns from Sun by Christopher Steel, Ramesh, Nagappan and Ray Lai

Even if you don't program in Java it seems that some of the information could apply to any web application.

I haven't read the whole book so I cannot say how useful it is yet.

Friday, July 13, 2007

Network Solutions SSL Certificate Instructions - Java Web Server

It is really annoying that the Java web server ssl instructions on the Network Solutions web site have been wrong for over 4 months.
I also wonder what the security implications are that they send people SSL certificates in email.
Here are the correct instructions:

Installing Your Network Solutions SSL Certificate on Java Based Web Servers
There are 4 certificates that you will receive from Network Solutions:

1. AddTrustExternalCARoot.crt
2. UTNAddTrustServer_CA.crt
3. NetworkSolutions_CA.crt
4. yourdomainname.crt

These must be imported in the correct order:

1. AddTrustExternalCARoot.crt
2. UTNAddTrustServer_CA.crt
3. NetworkSolutions_CA.crt
4. yourdomainname.crt

Use the keytool command to import the certificates as follows:
keytool -import -trustcacerts -alias root -file AddTrustExternalCARoot.crt -keystore domain.key

Use the same process for the UTNAddTrustServer_CA.crt certificate using the keytool command:
keytool -import -trustcacerts -alias utnaddtrustserverca -file UTNAddTrustServer_CA.crt -keystore domain.key

Use the same process for the NetworkSolutions_CA.crt certificate using the keytool command:
keytool -import -trustcacerts -alias networksolutionsca -file NetworkSolutions_CA.crt -keystore domain.key

Use the same process for the site certificate using the keytool command, if you are using an alias then please include the alias command in the string.
Example:
keytool -import -trustcacerts -alias yyy (where yyy is the alias specified during CSR creation) -file yourdomainname.crt -keystore domain.key
The password is then requested.
Enter keystore password: (This is the one used during CSR creation) After the password is entered information will be displayed about the certificate and you will be asked if you want to trust it.
Trust this certificate? [no]:
(The default is no so type 'y' or 'yes')
Then an information message will display as follows:
Certificate was added to keystore
All of the certificates are now loaded.

Anti-virus software: Chinese vs. Russian

Looks like two anti-virus vendors are attacking each other:

http://www.networkworld.com/news/2007/071207-update-gloves-come-off-in.html?nlhtsec=0709securityalert5&

There are other options developed in the US.

Kapersky itself was embedded into a piece of malware that removed other malware from computers so who knows what is the underlying cause of all this.

This article makes it sound like you have a choice between one or the other - you don't. There are other vendors that have been doing this longer in the US.

Thursday, July 12, 2007

A list of known bots

Not sure how old this is but here is a list of known bots from a random ranting user:


Bot not obeying the Rules

This bot does not appear to be obeying robots.txt

Unversity of Illinois192.17.0.0 - 192.17.255.255MQBOT/Nutch-0.9-dev (MQBOT Nutch Crawler; http://falcon.cs.uiuc.edu; mqbot@cs.uiuc.edu)

/instmsg/aliases/orders

We are still getting hits for this URL on our server from various IPs:

/instmsg/aliases/orders

I wrote about this in another post.

RedBot

Here's a new bot:

RedBot/redbot-1.0 (Rediff.com Crawler; redbot at rediff dot com)

Seems to be some India related web site.

Doesn't say how to block it in robots.txt at first glance.

Wednesday, July 11, 2007

IEMB3 may be hacked

Whatever this is: IEMB3 may be hacked, or it may be a coincidence that this is running on a machine that appears to be scanning our sites in un-normal-web-visitor-like or hacker-like ways.

Cazoodle

Looks like the Cazoodle bot has moved to the University of Illinois. I thought this one was running out of China before:

CazoodleBot/Nutch-0.9-dev (CazoodleBot Crawler; http://www.cazoodle.com/cazoodlebot; cazoodlebot@cazoodle.com)

OrgName: University of Illinois OrgID: UIUCAddress: 1120 DCL, MC-256Address: 1304 West Springfield AvenueCity: UrbanaStateProv: ILPostalCode: 61801Country: USNetRange: 72.36.64.0 - 72.36.127.255

Bell Canada

This IP at Bell Canada is trying to be sneaky about surfing the net. Something to hide?

67.68.135.71

Bell Canada BELLNEXXIA-11 (NET-67-68-0-0-1) 67.68.0.0 - 67.71.255.255HSE HSE020924-CA (NET-67-68-0-0-2) 67.68.0.0 - 67.68.255.255

1-800-HOSTING

An IP at 1-800-HOSTING continues to attempt to surf our web sites. Why would a web server be surfing our web sites?

69.41.185.18

OrgName: 1-800-HOSTING, Inc.OrgID: 1800HAddress: 3509 Oak Lawn AveCity: DALLASStateProv: TXPostalCode: 75219Country: US
NetRange: 69.41.160.0 - 69.41.191.255

Ask Jeeves not identifying itself

An Ask Jeeves machine is not correctly identifying itself as the ask search engine in the User-Agent string when requesting robots.txt

MCI Communications Services, Inc. d/b/a Verizon Business UUNET65 (NET-65-192-0-0-1) 65.192.0.0 - 65.223.255.255AskJeeves, Inc. UU-65-214-36 (NET-65-214-36-0-1) 65.214.36.0 - 65.214.39.255

Interland, Inc.

Someone on Interland, Inc.'s network (Atlanta, GA) is hitting our site with a bot.

64.239.7.216

OrgName: Interland, Inc.OrgID: INTDAddress: 101 Marietta StreetCity: AtlantaStateProv: GAPostalCode: 30039Country: US
NetRange: 64.239.0.0 - 64.239.127.255

Bay Area Internet Solutions

Bay Area Internet Solutions is hitting our site with some sort of bot.

OrgName: Bay Area Internet Solutions OrgID: BAYAAddress: 2650 San Thomas ExpresswayCity: Santa ClaraStateProv: CAPostalCode: 95051Country: USNetRange: 72.20.96.0 - 72.20.127.255

Server4You - Germany

We are still getting unwanted hits from this hosting facility.

inetnum: 85.25.129.0 - 85.25.148.255descr: SERVER4YOU Dedicated Server Hostingdescr: http://www.server4you.denetname: SERVER4YOU-1country: DE

Tuesday, July 10, 2007

Internet Crime - Summary Of Issues - 2007

This is a bit in the past but I missed it and it is very interesting in summing up the issues with Internet Crime: http://searchsecuritychannel.techtarget.com/originalContent/0,289142,sid97_gci1248099,00.html

Monday, July 09, 2007

Hits from Czech Data Center

This doesn't look right - hits from a data center...

inetnum: 81.31.32.0 - 81.31.35.255netname: MASTER1descr: Master Internet s.r.o.descr: server housing Brno, Cejlcountry: CZ

Bot coming from this IP: 80.194.189.66

Here's another bot snooping around - 80.194.189.66

7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:09
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:07
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:09
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:09
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:08
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)
7/8/2007 23:09
80.194.189.66
MJ12bot/v1.2.0 (http://majestic12.co.uk/bot.php?+)

Sunday, July 08, 2007

PHP hacker - everyone's internet - 66.98.228.8

7/7/2007 15:28
66.98.228.8
/phpgroupware/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/wordpress/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2evo/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpgroupware/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/wordpress/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpgroupware/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogtest/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2evo/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/wordpress/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpgroupware/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/wordpress/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2evo/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogtest/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2evo/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogtest/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/b2/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/community/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogtest/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/drupal/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/community/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/community/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/drupal/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blogs/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/drupal/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/community/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/drupal/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/blog/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlsrv/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/Ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/xmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/Ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew2/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/Ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adserver/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/Ads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpads/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpadsnew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adserver/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/phpAdsNew/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adserver/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adserver/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adxmlrpc.php
7/7/2007 15:28
66.98.228.8
/adxmlrpc.php
7/7/2007 15:01
66.98.228.8
/community/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chat3/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chat2/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/forums/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chat1/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpMyChat-0.14.4/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpMyChat-0.14.3/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpMyChat/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpMyChat-0.14.5/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpMyChat-0.14.2/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/php/phpmychat/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/forum/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chats/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chatroom/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/PhpMyChat/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/phpchat/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chat/chat/messagesL.php3
7/7/2007 15:01
66.98.228.8
/chat/messagesL.php3

Thursday, July 05, 2007

Blatant hacker: SERVER4YOU network

Here's a blatantly hacking IP from the Server4You network in Germany:

85.25.138.126

This IP hit our sites over 200 separate times in one day

inetnum: 85.25.129.0 - 85.25.148.255descr: SERVER4YOU Dedicated Server Hostingdescr: http://www.server4you.denetname: SERVER4YOU-1country: DE

Network Admins Not Paying Attention To Traffic

Hmm. Interesting.

http://blogs.zdnet.com/security/?p=349

Not sure I agree however. I don't know if this person understands exactly what was done in this case and yes, it should have been done sooner, but the fact is prior to this network admins didn't pay attention to traffic much at all unless it took down a machine. The fact that the government is involved and looking at the problem is a major step forward as we all know how long it takes to get the government moving...business has financial motivation. The government is pushed by voters and many voters don't even understand what is going on. So I say go Microsoft, go FBI and keep going - do more. Catch them and start whacking people with fines and putting them in jail the same way the Enron guys were put in jail - as an example to all and yes you will pay. But make the price high.

The note about cutting off criminal resources is interesting. Yes we can and should do more about this problem, but at least someone "gets it" and it is a step in the right direction. That's my take.

And as for the last line, yeah right. I'm going to let some ex (supposedly) hacker "fix" my machine. Time for a reality check.

Monday, July 02, 2007

Definitely a Hacker from Romania

This is definitely a hacker in Romania:

inetnum: 89.42.140.0 - 89.42.141.255netname: SC-ALIENSTATION-SRLdescr: SC AlienStation SRLdescr: B-dul Ferdinand, Nr. 56descr: Constanta Constanta 900693country: ro

Looks like they are scanning our sites and possibly stealing the content and posting it elsewhere - potentially they have found a way to hack DNS.

Null IP addresses in logs

I would like to know how someone is able to get a null IP address into our logs. I would like to make this not possible and to stop. All web server vendors need to look into this. Of course we have backup logging that handles this issue.

And see my last post for the matching IP address. Not sure which one but one of those generated this:

[30/06/2007:01:48:36 -0800] "GET / HTTP/1.0" 302 0 "Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.7.6) Gecko/20050317 Firefox/1.0.2" -

Noc4Host servers visiting again

Noc4Hosts is an IP range you might want to block out at the firewall level for web servers. Servers in their IP ranges are visiting again.

Products from China

Was just reading a report in the paper that said 100% of the 24 defective toys recalled in the US this year came from China. Also there was some toothpaste infected with poison coming from China which was distributed to US prisons.

Friday, June 29, 2007

PHP bomber: 81.149.56.227

This IP 81.149.56.227 was bombing our server today looking for PHP hacks.

Servervault

There are web sites hosted by this hosting company that have bogus information on them...someone may want to explore this:

OrgName: Servervault OrgID: SVLT Address: 1506 Moran Road City: Dulles StateProv: VA PostalCode: 20166 Country: US ReferralServer: rwhois://rwhois.servervault.com:4321 NetRange: 216.12.128.0 - 216.12.159.255

Network Solutions Validation Flaws

It looks like there is an imposter company in Princeton Junction, New Jersey trying to impersonate a valid company in Seattle, Washington - Radical Software, Inc. Radical Software, Inc. has been in business since 1998 and partners with major solid companies that have been in business for a long time and are major players in the web industry.

The imposter company is listed on a bunch of spammy web sites that are detracting from the business of the valid company. The imposter company was even listed in Hoovers and D & B databases -- which are used to by Network Solutions to validate SSL certificates.

Do you see a HUGE problem here? This is it: some company gets bogus records into the much flawed D & B records - D & B had company addresses that were six years old in this database. Also anyone can call in and change company records pretty easily. So Network Solutions uses these very inaccurate databases to validate SSL certificates and back them with a $1 Million Guarantee - and because the records are flawed it is a real pain in the you know what for the legitimate companies to actually get SSL certificates because D & B is showing records for some imposter company.

Using a marketing database that anyone can call in and update is a pretty flawed way of validating a company is legitmate. Additionally they use the state records to validate and companies typically have a separate address for power of attorney which may not match their billing and mailing addresses for the actual company. Using these things to validate the company is also flawed.

Also recently someone was able to change my banking records to send my mail to an old PO box. If someone could get my banking records to go to an old mailbox and pick up my mail they can send in the bank statements to validate the company with Network Solutions. The whole way Network Solutiongs is doing their validation is completely flawed.

Why can't they use verified by Visa or the billing address on the credit card that and the information on the actual web site that the person owns? Also since I have other SSL certificates which I registered with them recently and already sent in validation for that- why can't they look at the history - both to validate and to invalidate rip off requests?

There has to be some better form of validation, though I am not exactly sure what it is. I just know the current forms of validation are not the best.

Thursday, June 28, 2007

131.107.0.73

This IP is searching on odd things nad not quite sure how they were directed to our site from these links...


http://sailingseattle.com/catering.htm
131.107.0.73
http://search.live.com/result.aspx?q=buspar&mrt=en-us&FORM=LVSP
131.107.0.95
http://search.live.com/result.aspx?q=keno&mrt=en-us&FORM=LVSP
131.107.0.95
http://search.live.com/result.aspx?q=nissan&mrt=en-us&FORM=LVSP
131.107.0.95
http://search.live.com/result.aspx?q=porche&mrt=en-us&FORM=LVSP
131.107.0.95
http://search.live.com/result.aspx?q=tenuate&mrt=en-us&FORM=LVSP
131.107.0.95
http://search.live.com/result.aspx?q=amitriptyline&mrt=en-us&FORM=LVSP
131.107.0.96
http://search.live.com/result.aspx?q=blowjob&mrt=en-us&FORM=LVSP
131.107.0.96
http://search.live.com/result.aspx?q=hydrocodone&mrt=en-us&FORM=LVSP
131.107.0.96
http://search.live.com/result.aspx?q=milf&mrt=en-us&FORM=LVSP
131.107.0.96
http://search.live.com/result.aspx?q=tramadol&mrt=en-us&FORM=LVSP
131.107.0.96
http://www.google.com.au/search?sourceid=navclient&ie=UTF-8&rls=GGLD,GGLD:2004-09,GGLD:en&q=low+carb+lunches
131.170.90.4

Wednesday, June 27, 2007

Cross Site Request Forgeries

Another cross site attack...the kind I was assured by my hosting providers could not possibly exist:

http://www.eweek.com/article2/0,1895,2151154,00.asp

http://shiflett.org/articles/cross-site-request-forgeries

http://4diggers.blogspot.com/

67.40.220.161

This IP is at it again. It just requested this URL from our shopping cart system:

/instmsg/aliases/orders

Tuesday, June 26, 2007

instmsg/aliases/orders 67.40.220.161

Hmm, here's a new one.

This IP: 67.40.220.161 from Qwest

is trying to access this URI

instmsg/aliases/orders

on our shopping cart system.

I found this on the Microsoft web site:
http://support.microsoft.com/kb/278974

Noc4Hosts bombing our server

Someone at this IP address was just attempting to access our server. Since this is a data center related company in Florida I am not sure why they would be trying to access a local service business in California. Seems a bit fishy doesn't it?

66.232.97.32

OrgName: NOC4Hosts Inc. OrgID: NOC4HAddress: 400 N Tampa StAddress: #1025City: TampaStateProv: FLPostalCode: 33602Country: USReferralServer: rwhois://rwhois.noc4hosts.com:4321/NetRange: 66.232.96.0 - 66.232.127.255

Monday, June 25, 2007

XSL Transformations and Client Side Calculations

In a recent edition of Dr. Dobb's Journal (May 2007) a couple of programmers from Turkey explain how to do client side mathematical calculations using XIM and XSLT transformations. This, they explain, is a way to offload some processing to the client side computer.

Yes, this all sounds lovely but I'm sure that most smart e-commerce programmers would instantly recognize that you should not leave any important calculations to the client side of the e-commerce process where it can be manipulated, either by the end user, or by a hacker that has infected his or her machine.

I was going to note that I've always had a somewhat significant amount of traffic from Turkey, by the way, which I find odd given what I am hosting.

Programmer beware - don't jump on everything you read as the next best thing. Consider the pros, cons and appropriate usages of each new technology option. And if you are not entirely sure how it works within your application framework, best check that out before rushing to implementation.

RackSpace potential hacker

This IP is snooping around on our servers - it is coming from a RackSpace data center:

It is either a bot or a hacker since this is not an end user computer:

207.97.207.39 resolves to"navigatormultimedia.com"
Top Level Domain: "navigatormultimedia.com"

OrgName: Rackspace.com, Ltd. OrgID: RSPCAddress: 9725 Datapoint DriveAddress: Suite 100City: San AntonioStateProv: TXPostalCode: 78229Country: USNetRange: 207.97.192.0 - 207.97.255.255

Friday, June 22, 2007

Are you worried yet?

I have been writing in this blog about the need for increased security and government involvement to resolve these problems. I have been writing that these problems are bigger than people realize and affect each and every one of us - our security, our salary, our bank accounts, credit cards, identities and our online purchases.

Today the pentagon was hacked:

http://www.networkworld.com/news/2007/062107-pentagon-shuts-down-systems-after.html?nlhtsec=0618securityalert5

Ok it happens. But how long has this been going on I wonder?

And even worse...our secretary of state says "I'm a very low-tech person."

If the government doesn't get it that they need someone who understands Internet security at the top of the chain - then we are all in big trouble. He better get high-tech or at least tech savvy pretty soon or we are all in big trouble.

Kapersky Wants to Give Awards to Hackers

Kapersky wants to give awards to hackers:

http://blogs.pcmag.com/securitywatch/2007/06/the_kaspersky_malware_awards_1.php

Not a fan. These people do not deserve awards and they probably thrive on the attention. Shame on any news organization that publishes these things. These people do not need to be given attention as if they have performed some great feat. They need to be put in jail and shown to all the world that they are hated, despised criminals that will be punished.

Kapersky says who knows malware better than the people who fight it. I say who knows malware better than the people who WRITE it.

Hmm so the logic goes if A=B and B=C then A = B. Oh never mind.

Just audit everything. Everything.

Thursday, June 21, 2007

AOL Bot

Someone on this AOL IP: 172.203.88.173 is pounding our site with the MJ12 bot - 6/21/07 10:28 a.m.

Following right on it's heels - this known hacker IP was attempting to reach the web server: 8.7.22.195

Shortly before we were hit multiple times by a known hacker IP range: 207.36.201.40

Firefox spyware

Hmm, related to my last post about IE acting all weird, I moved to Firefox and while using the Google web site got a message that it appears I have spyware on my machine. Perhaps messing up IE will get me to switch to Firefox and then... Downloading spybot now...

IPhone not secure

Hmm...this article claims the hot new iPhone is not really secure:
http://www.networkworld.com/news/2007/061907-apple-iphone-gartner.html?nlhtsec=0618securityalert4&

Tuesday, June 19, 2007

Google Security API

This is interesting - Google has a security API that can be incorporated into software programs to blacklist malicious URLS:

http://www.pcworld.com/article/id,133069-page,1/article.html

Spammers and Hackers - Going to Jail

It's about time:
http://blogs.pcmag.com/securitywatch/2007/06/more_phishers_and_spammers_in_1.php

Microsoft - Security Opinion

I am not 100% in agreement with this person. He claims he would "never blame Microsoft" because many apps are not written by Microsoft.

http://www.networkworld.com/community/?q=node/16266&nlhtsec=0618securityalert1&

I disagree. There is a certain level of security that needs to be provided at the operating system level that is beyond the application itself, and in some cases the people who own the system did not even intend to install the software, or the software is doing something other than it's intended purpose. My point here is the operating system has certain "responsibilities" shall we say to manage all these applications and it should prevent some rogue activity and provide appropriate monitoring of things it will not necessarily block so users can easily see what is happening on their system.

Additionally Microsoft does write some of these programs and has responsibility to ensure they are secure and fix any new security breaches. This is not necessarily blaming - it is a fact, however.

Additionally Microsoft needs to delve deeply into the security of things that allow communication across servers such as RPC and DCOM. I have had someone hacking on my server using these technologies - I don't even use them. Microsoft needs to ensure these cannot be used unless the server owner specifically requests to open up these channels in and out of their servers or provide some huge warning if they are open and available.

These are the areas where I would blame Microsoft if there is a security breach, or at least where they can improve and help ensure security.

Microsoft actually can have a competitive advantage over other operating systems that are open source because they have the resources, if they so choose, to pour into security on systems and provide a more cohesive solution than an open source software platform. However some people will always choose open source due the cost issue and the ability to reprogram parts of the OS if needed.

Where to report Internet Crime...

So you've been hacked, spammed, ripped off and defrauded...now what?

Here are some tips....

Here are some useful links for reporting fraud: Internet Fraud

You can report crimes at the Internet Crime Complaint center:
Internet Crime Complaint Center

If it is a crime by someone within the US, there is a link on the FBI web site.

If it is a crime committed by someone outside of the US you may want to report it to the CIA and related web sites.

You can report your hacker traffic trends at SANS Institute. The more people submit firewall logs the more information they have to analyze and compile research to help thwart hackers.

For spam you can report it in some cases to your local government officials. Some states have laws against spam and will prosecute so try your state prosecuting attorney's office. You can also report to anti-spam organizations that go after and try to prosecute spammers such as Spam Cop. Here are some good links: How to Report Spam In the case of spam if you know how to look at email headers, report the spam to the offending network - and not just the local network if it is a company - but the larger network such as AT&T, Comcast or SBC.

In the case of bots and extraneous network traffic report the excessive traffic to the offending network, same as above and the server owner if possible. In some cases you can find out the owner of a computer by doing a reverse look up on the IP address to get the domain name. You can also use tools like DNSStuff.com to look up an IP address and find out the abuse email of the offending network. Send them your logs so they have accurate information with time and date to track down the offending person or malware infected machine.

Make sure you report known bugs and affected software to the vendors that make the hardware and software that may be the source of the problem. The more people that report the problem the better the chance it will be solved.

Write to your local, state, and federal representives for issues such as fraud, identity theft, hacking and spam so they understand and address your concerns. Some of these issues on the international level require government knowledge, diplomacy, more approriate laws and better law enforcement to be resolved.

More useful links on reporting Internet crime:

Report fraud here: http://www.sec.gov/investor/pubs/cyberfraud/tellus.htm and read more about it here: http://www.usa.gov/Citizen/Topics/Internet_Fraud.shtml or here: http://www.fbi.gov/majcases/fraud/internetschemes.htm

CyberCrime: http://www.usdoj.gov/criminal/cybercrime/
http://wiki.castlecops.com/Reporting_Internet_Crime:_The_United_States_of_America

Internet Scams: http://www.scambusters.org/

Reporting Internet Crime in the UK: http://www.homeoffice.gov.uk/crime-victims/reducing-crime/internet-crime/

IFrame Hack Job

Over 10,000 legitimate web sites using IFrames were exploited and used to download malicious software to end user computers.

http://www.networkworld.com/news/2007/061907-italian-job-web-attack.html

Monday, June 18, 2007

PHP Hackers - 2007 to date

Count IP Requested Page Month
36 205.247.203.14 /PHPMYadmin/main.php 6
20 205.247.203.14 /myADMIN/main.php 6
8 205.247.203.14 /mysql-admin/main.phpmain.php 6
8 205.247.203.14 /pma/main.php 6
4 205.247.203.14 /PMA/main.phpmain.php 6
4 205.247.203.14 /pmamy/main.php 6
4 205.247.203.14 /admin/mysql/main.phpmain.php 6
4 205.247.203.14 /admin/phpmyadmin/main.phpmain.php 6
4 205.247.203.14 /admin/pma/main.phpmain.php 6
4 217.71.214.163 /cacti//graph_image.php 6
4 205.247.203.14 /db/main.phpmain.php 6
4 205.247.203.14 /mysql/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.3/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.7-pl1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.7/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.7.0/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.1/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin2/main.phpmain.php 6
4 217.71.214.163 //graph_image.php 6
4 205.247.203.14 /web/phpMyAdmin/main.phpmain.php 6
4 205.247.203.14 /mysqladmin/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.0/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.6/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.6/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.6.4-pl4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.6.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.7.0-pl2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0.2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin/test.phpmain.php 6
4 205.247.203.14 /admin/main.phpmain.php 6
4 205.247.203.14 /dbadmin/main.phpmain.php 6
4 205.247.203.14 /myadmin/main.phpmain.php 6
4 205.247.203.14 /main.phpmain.php 6
2 87.106.103.182 /include/include_top.php 6
1 130.39.11.106 /index.php 6
1 218.127.216.28 /index.php 6
1 219.254.1.163 /index.php 6
1 67.82.106.110 /index.php 6
1 87.228.58.238 /index.php 6
1 122.16.74.92 /profile.php 6
1 220.102.115.237 /profile.php 6
1 67.84.237.55 /profile.php 6
1 68.102.105.73 /profile.php 6
1 68.197.29.166 /profile.php 6
1 68.226.166.235 /register.php 6
1 61.47.47.58 //index.php 6
1 195.222.29.132 //forum/admin/index.php 6
1 172.177.4.5 /index.php 6
1 24.210.154.219 /index.php 6
1 24.250.199.114 /index.php 6
1 64.178.157.212 /index.php 6
1 68.42.187.199 /index.php 6
1 70.161.19.176 /index.php 6
1 222.66.48.253 /profile.php 6
1 68.40.241.80 /profile.php 6
1 72.137.246.167 /profile.php 6
1 72.187.132.166 /profile.php 6
1 213.113.230.166 /register.php 6
1 61.102.25.233 /register.php 6
1 61.157.96.36 /register.php 6
1 65.75.109.219 /register.php 6
1 68.102.172.102 /register.php 6
1 68.94.231.55 /register.php 6
1 72.188.93.47 /register.php 6
1 86.107.156.115 /register.php 6

71.13.115.117 - Charter - Bot

71.13.115.117 is running a bot that continues to hit our sites after asking Charter for months to make it stop.

Charter Communications MDS-WI-71-13-112 (NET-71-13-112-0-1) 71.13.112.0 - 71.13.119.255Charter Communications CC04 (NET-71-8-0-0-1) 71.8.0.0 - 71.15.255.255

CONTINENTAL BROADBAND PENNSYLVANIA, INC. - HACKER

There's a hacker at this location attempting to access our sites with ColdFusion:

OrgName: CONTINENTAL BROADBAND PENNSYLVANIA, INC. OrgID: CBP-17Address: 810 Parish StCity: PittsburghStateProv: PAPostalCode: 15220Country: USNetRange: 208.40.128.0 - 208.40.207.255

IP Address: 208.40.131.148

New Horizons - Major Hacking

We are getting major hacking from this network on this IP: 205.247.203.14

OrgName: New Horizons OrgID: NEWHOR-1Address: 1231 E Dyer Rd, Ste 140City: Santa AnaStateProv: CAPostalCode: 92705Country: USNetRange: 205.247.203.0 - 205.247.203.255

They have requestsed PHP admin pages in over 200 sessions this month so far alone.

Saturday, June 16, 2007

Another Hacker - CenturyTel

This appears also to be someone hacking: 69.179.76.130 at CentryTel in Louisiana at 6/13/2007 12:55:48 PM.

Hacker - Comcast in Miami

Someone on Comcast in Miami at this IP address: 76.109.211.88 was attempting to hack our e-commerce sites by passing invalid data to our application and causing a null pointer exception. The issue has been fixed. I hope someone will monitor the activities of the user of this IP address at 6/15/2007 3:14:59 PM

Thursday, June 14, 2007

Botnets - Scourge of the Internet

SWEET. Finally big companies and the governement are honing in on this issue. It is about time and I am so happy to hear it:

http://www.networkworld.com/news/2007/061307-fbi-operation-bot-roast.html?nlhtsec=0611securityalert4

Since starting to uncover the network patterns of spam about 3 years ago when I got sick of 950 spam emails per day I have been sending out messages about how these attacks are coordinated and coming from the servers of large companies...and since then the problem has only gotten worse.

One of my biggest reasons for writing this blog was to get someone - anyone - to take notice of the underlying Internet traffic - good and bad - and do something about it. I got sick of network admins throwing up their hands and telling me I was full of it when my server was hacked or that there was nothing that can be done about it...

This is exactly what we need. We need big businesses involved and the government and even better yet, we need large hosting facilities to analyze their traffic on an anonymous but global basis to determine traffic patterns that are obviously bots and illegal activities.

This is a long awaited happy day...

Thursday, June 07, 2007

National Vulnerability Database

Here's a database of products and their vulnerabilities:

http://nvd.nist.gov/viewvpv.cfm?complete=no&vendor=yes&product=yes&version=no&vendorchar=Omniture

This can be useful when researching whether or not you want to use a particular product - how many times has it been hacked?

Omniture Vulnerabilities

Related to my last two Omniture posts I did a little research on Omniture related vulnerabilities and hacks - this is what I found:

http://securitytracker.com/alerts/2006/Dec/1017392.html

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6640

http://securitytracker.com/alerts/2006/Dec/1017392.html

Vulnerability using .gif files

I was talking to my boss about the possibility of an Omniture hack:

http://randominternet.blogspot.com/2007/06/omniture-hacking-again.html

He stated that he's reviewed the code and all they are doing is downloading gif files, and that Omniture is used by large sites like CNN, Amazon and Sun. (Implication: if they use it it must be secure).

My response was: that makes them a great target. Look at the pot of gold at the other end of the rainbow. There are huge user bases for these sites plus people testing and reviewing the code at these companies behind firewalls...

So anyway I said what if the execution of malicious code is in the gif files, not in the JavaScript itself? And my boss says no, they are just simple gif files.

So I thought well, I've seen hacks in image files before let's see what's out there. And I found this:
___________

http://vil.nai.com/vil/Content/v_vul26549.htm

http://www.microsoft.com/technet/security/advisory/912840.mspx

Microsoft Office Remote Code Execution Using a Malformed GIF Vulnerability - CVE-2006-1540A remote code execution vulnerability exists in Office using a GIF file. An attacker could exploit the vulnerability by constructing a specially crafted Office file that could allow remote code execution. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
________

And guess what. If someone could get this onto the Sun web site, that is where everyone goes to download Java - on servers that run e-commerce web sites, application servers, etc. You get the picture.

I have no idea how to test this theory. Maybe someone out there can just verify nothing funky is going on...

Tuesday, June 05, 2007

The problem with your VPN

So you set up a user and you say OK, you can do stuff on the VPN that you cannot do when you're not on the VPN and that makes my server that you are remoting into secure.

Right.

Talking to a firewall administrator today at Datapipe here's how your Cisco Pix really works:

Someone logs into the VPN and gets onto the server. From there they have free reign to do anything your outbound port access allows them to do. If they can get onto the server, they can send all your data to whatever server they want outside that server if your outbound access includes FTP. Apparently if you want to restrict downloading FTP to anyone but, say, and administrative VPN user - you can't do that at the firewall level.

And it also means if you want to allow customers to upload photos, for instance, but not download data, and make their access more secure so only VPN users can upload files, that's not completely solved by a VPN.

Which means you have to count on software - your OS, your applications... and you have to manage via a Windows domain or manage each individual server and cannot globally handle these things at the network level.

And that's scary.

Monday, June 04, 2007

First Data Better Check How Internet Requests are Handled

I sent an email to First Data via their web site with some specific technical questions about processing cards over their platform(s) and integration with certain types of transactions and hardware.

Some fast talking woman just called me who either had no comprehension of my request or she sniped the information somehow from the FirstData database. She was speaking very quickly and told me she was with Express Merchant blah blah blah or something like that. She told me this is some part of First Data. Maybe it is but it is but the way this request was handled was completely innapropriate.

First she asked me if I already have a processor. In my request I stated specific information that would have answered that question. It was pretty clear that she was about to try to sell me something and that is not why I requested information from First Data. Secondly when I said that is not what I requested she said "what was your request?" Excuse me but shouldn't you have the customer's request in front of you when you are calling them to answer the questions in their request?

Basically I already got the information through other means. I had to call First Data and sit on hold forever and talk to five different departments. I had to call my software gateway and go through 3 different people over there to get partial answers. I had in depth conversations with my bank who clearly knows very little how any of this works. Then I called an equipment manufacturer of terminals for their side of the story. They clearly didn't have the big picture either. I was able to piece together the information step by step and probably have a 95% grasp of what I need to know to implement a secure solution for my client - however no thanks to First Data's convoluted phone system or uninformed phone operators, sales people, and technical staff. This is nothing against the people themselves as they are all just doing their job the way they were trained to do it. There is a lack of global understanding in the credit card industry which makes it easier for hackers and harder and more expensive for customers to get things done.

Saturday, June 02, 2007

Wrong Country? DODO

This Ip range lists a country of AP but the contact information is for AU

inetnum: 122.148.0.0 - 122.149.255.255netname: DODO-AUdescr: Layer 2 Broadband Customer Networkcountry: APadmin-c: PR93-APtech-c: PR93-APstatus: ALLOCATED PORTABLEmnt-by: APNIC-HMremarks: Send abuse reports toremarks: abuse@dodo.com.auperson: Paul Rivoliaddress: Dodo Australia Pty Ltdaddress: Level 14 / 600 St Kilda Rdaddress: Melbourneaddress: VIC 3004country: AU

Thursday, May 31, 2007

Omniture Snooping?

Someone was snooping around my local network again. When I took a look there were 3 connections to Google which seemed ok, a connection to a Belgium electronic publishing company which might be ok since I was connected to a technical article, and a connection out on port 80 to Omniture in this IP range:

Omniture TRFR-ORM-UT-OMNITURE-4 (NET-216-194-125-0-1) 216.194.125.0 - 216.194.125.255

The thing is - I never connected to Omniture. The other weird thing is, the company I am working for at the moment is using Ominture. A random internet connection?

regencypacificinc.com surfing the web?

It seems that this web server is surfing the web...
63.236.119.29 resolves to"regencypacificinc.com"
Top Level Domain: "regencypacificinc.com"

Amazon + Nutch again...

Amazon was visiting our sites with Nutch again today.

Amazon scanning my machine again

Why is someone at Amazon scanning my machine with Nutch?

72.44.62.122

ilial/Nutch-0.9 (Ilial, Inc. is a Los Angeles based Internet startup company. For more information please visit http://www.ilial.com/crawler; http://w

OrgName: Amazon.com, Inc.
OrgID: AMAZO-4
Address: Amazon Development Centre South AFrica
Address: 1200 12th Avenue South
City: Seattle
StateProv: WA
PostalCode: 98144
Country: US
NetRange: 72.44.32.0 - 72.44.63.255

Korea Hackers - again

Korea is always a major source of spam and hacking for us.

Today we were bombed by this IP: 222.122.151.181

Looking for PHP hacks.

Wednesday, May 30, 2007

Hmm. ftp.grede.com hacked?

This IP was surfing our web site...

12.34.44.226 resolves to"ftp.grede.com"
Top Level Domain: "grede.com"

Tuesday, May 29, 2007

Google Copied Me

Google copied me. Well they have a bit more resources and some interesting stuff.

http://www.eweek.com/article2/0,1895,2135462,00.asp

http://googleonlinesecurity.blogspot.com/

Monday, May 28, 2007

Hacker activity from 81.223.153.134

inetnum: 81.223.153.128 - 81.223.153.143netname: Technix-Internetdescr:descr: Technix InternetServices GmbHdescr: Wilhelm Pfeiferdescr: Wiencountry: AT

What is YPC 3.2.0

I am finding this in my logs but cannot figure out what it is in a brief web search. Hopefully someone will post some information about it.