Showing posts with label Computer Security. Show all posts
Showing posts with label Computer Security. Show all posts

Monday, December 22, 2014

Tuesday, August 12, 2014

Nerd News: LastPass Back Up

LastPass has been down for a while, but according to LastPass and other reports it should be back up, though there may still be some issues.

Sounds like they only use 2 datacenters, or maybe even only single primary one with a "backup".
"Update: 1:28 pm EST

Though one of our data centers remains completely down, the service is generally stable and should be available to the majority of users (with the exception of login favicons). Some users may see connection errors but should still be able to access their data. We continue to work as quickly as possible to get the service back to 100%. "
       Source http://blog.lastpass.com/


"Aug 12, 2014 - One of LastPass' datacenters has been down since 3:57am EDT. The service is now running fully off one Herndon VA datacenter and we have been engaged with our provider all morning. Currently favicons/sprites are impacted. We are doing what we can to minimize the impact and apologize for the inconvenience. "

       Source https://lastpass.com/status.php


Also http://www.isitdownrightnow.com/lastpass.com.html 

For LastPass users that want an offline solution to prevent this type of problem in future consider LastPass Pocket

This is LastPass link specifically about offline access https://helpdesk.lastpass.com/password-manager-basics/your-lastpass-vault/offline-access-to-your-lastpass-vault/ 


Thursday, May 8, 2014

Security & Hacking: DEFCON 20 "Can You Track Me Now?"



DEFCON 20: Can You Track Me Now? Government And Corporate Surveillance Of Mobile Geo-Location Data

This was posted on Youtube November 22, 2012, so was well before Snowden release of information in May of 2013.

Main emphasis of this talk was tracking of cell phones.

But Christopher Soghoian briefly covers, at 31:05, that both Android (Google) & iOS (Apple) device encryption can be defeated by Google & Apple respectively.

This is a service they provide for Law Enforcement & other Government agencies.

Google can force a password reset for Android device, they don't require physical access.

Apple appears to use what Soghoian calls a "Master Skeleton key," they require departments to provide actual device (ie physical access).  They then provide unencrypted data on a CD, while device remains encrypted.

I wonder if they might actually need device to decrypt data with way devices since iPhone 4S & iPad 2 have been designed (they have hardware based encryption).

Entire video is worth watching, though it is rather long, they joke about having 3 different audience during the course of the talk.
 



Monday, May 5, 2014

Pen Testing: Pwnie Express new Nexus 5 based phone

1/13/15 Updated link to software download page due to changes on Pwnie Express site: new link to download page, confusingly labelled IMHO "Community" is  https://www.pwnieexpress.com/community/

XXXXXXX


Pwnie Express is a pretty awesome company, https://www.pwnieexpress.com/, you have probably heard of their Pwn Plug even if you don't recognize the company's name.

They have a new Pen Testing phone out called:  Pwn Phone 2014

Product link https://www.pwnieexpress.com/penetration-testing-vulnerability-assessment-products/sensors/pwn-phone-2014-penetration-testing-phone/

They aren't cheap, but Pwnie Express also provides free downloads for the entire software suite they use in their products.

It usually take a little time for new product's software to be added, but they already have software for 2014 Pwn Pad, Nexus 7 based, available.

Download [Updated link 1/13/15] https://www.pwnieexpress.com/community/ if you want to use your existing Nexus 7, they should have the Nexus 5 download available in near future as well.

The downloads for DIY are listed under "Community Editions & Legacy Product Downloads"

If I can find the time this week, I will also track down current hardware accessories they offer, & update this post or make post dealing with accessories.

Meanwhile you can view hardware accessories I listed for the 2013 Pwn Pad http://cliffsesportcorner.blogspot.com/2013/02/pen-testing-pwn-pad-by-pwnie-express.html.

Probably newer options available for some of those products, but those should work.

Just click following labels for more blog posts on Pwnie Express or Pen Testing, labels can be found at bottom left of every blog post, easy way to find similar or related content.

Select labels can also be found in label cloud at left side of Blog.

Wednesday, October 9, 2013

PSA TrueCrypt Audit project

What an interesting day!

Started with comments about Bruce Schneier's article at Wired http://www.wired.com/opinion/2013/10/149481/ where he mentions some concerns about TrueCrypt:
No, I don’t have any inside knowledge about TrueCrypt, and there’s a lot about it that makes me suspicious. But for Windows full-disk encryption it’s that, Microsoft’s BitLocker, or Symantec’s PGPDisk — and I am more worried about large U.S. corporations being pressured by the NSA than I am about TrueCrypt.

Eventually Matthew Green made the following tweet:
. and I are working on a 'Kickstarter' for a proper review of Truecrypt. The terms are a work in progress.

Fundfill link from Tweet above http://www.fundfill.com/fund/4-spzFJdDQk211KJDAUfcOw==#

Draft at http://istruecryptauditedyet.com/

You can follow Kenn White & Matthew Green on Twitter:

I am still very much a noob when it comes to Crypto, but Matthew Green is one of the people I follow to learn.

If your not into Crypto you probably haven't heard of him, this Ars article would be one place to start http://arstechnica.com/security/2013/09/crypto-prof-asked-to-remove-nsa-related-blog-post/

I am sorry to say I don't know much about Kenn White currently, I'd welcome comments or links that correct my ignorance.

Monday, August 26, 2013

Updated oclHashcat-plus v0.15

Main link:  http://hashcat.net/oclhashcat-plus/

oclHashcat-plus v0.15 "Added support for cracking passwords longer than 15 characters," lot of other improvements see https://hashcat.net/forum/thread-2543.html for full details.

I am still digging through the changes, and I have been sick, so it will probably take me a while, but it looks like some big improvements have been made.

They have also added support for several algorithms, including TrueCrypt 5.0+, Lastpass, & MacOSX v10.8 that are of particular interest to me.



Tuesday, August 13, 2013

Very interesting NYT article about Snowden, Laura Poitras, & Glenn Greenwald

Longer, more in depth article http://www.nytimes.com/2013/08/18/magazine/laura-poitras-snowden.html?pagewanted=all and a shorter one that is also used in longer article http://www.nytimes.com/2013/08/18/magazine/snowden-maass-transcript.html

Lot of people know who Snowden and Greenwald are now, I think fewer know who Laura Poitras is, sad to say I didn't before seeing this article.

For quick reference about these people see their Wikipedia links:
Lot of things of interest in above links.

Close reading of the NYT's article can provide some useful insights and tidbits to serious security.

I also want to note one comment by Snowden: 
"I was surprised to realize that there were people in news organizations who didn’t recognize any unencrypted message sent over the Internet is being delivered to every intelligence service in the world. In the wake of this year’s disclosures, it should be clear that unencrypted journalist-source communication is unforgivably reckless. "

Thursday, August 8, 2013

VPN Guide by Steve Gibson

https://www.grc.com/vpn/overview.htm is link to Steve Gibson's guide to VPN, if your learning how to set up your own VPN like me, or if your just curious about VPN and want to learn, it is a great resource.

It also ties in with setting up your own server, I am looking at this neat ARM based machine, called Utilite, for low power server http://utilite-computer.com/web/home

Blurb about it on Ars http://arstechnica.com/information-technology/2013/07/99-arm-based-pc-runs-either-ubuntu-or-android/

Tuesday, October 16, 2012

Security & Hacking: " Scrap Value of a Hacked PC"

http://krebsonsecurity.com/2012/10/the-scrap-value-of-a-hacked-pc-revisited/

EXCELLENT Article with clear picture showing what Hackers gain from hacking a computer, even a simple one just used for web surfing and email!

Brian Kreb's security blog is one of my favorite!

Think this article illustrates why, lot of computer people understand computer security, but I know as a writer just how hard it can be to communicate concepts at times.

This illustration is brilliant!

It really is an outline in visual form:
  1. Web Server
  2. E Mail Attacks
  3. Virtual Goods
  4. Reputation Hijacking
  5. Bot Activity
  6. Account Credentials
  7. Financial Credentials
  8. Hostage Attacks
Followed by simple details so non computer security geeks will understand that "Reputation Hijacking" means they take control of your Facebook/Twitter/etc.

Learned about a new Bot myself today from this artical, the CAPTCHA Solving Zombie, Krebs' answered question about that in the comments with this link http://www.inwyrd.com/blog/2010/03/hijacking-koobfaces-captcha-solver/

Wednesday, September 12, 2012

Security & Hacking: Blackhole Exploit Kit update Version 2.0

Article at Ars http://arstechnica.com/security/2012/09/blackhole-2-0-gives-hackers-stealthier-ways-to-pwn/

Related links http://malware.dontneedcoffee.com/2012/09/blackhole2.0.html & http://threatpost.com/en_us/blogs/black-hole-exploit-kit-20-released-091212

I would like to think average people will pay more attention to patching and other basic security issues if they had any idea about the powerful attacking tools available today, many of which really don't require a lot of skill or knowledge to utilize.

Unfortunately I know better, on the other hand I often think about how reality is starting to mimic games like Shadowrun http://en.wikipedia.org/wiki/Shadowrun minus the magic.

Okay I exaggerate a little, but I am a  gamer ^_^


For more on Shadowrun http://www.shadowrun4.com/

Wednesday, August 15, 2012

Nerd Jobs: Google raises Bug Bonus program

Full information at http://blog.chromium.org/2012/08/chromium-vulnerability-rewards-program.html

Security & Hacking: "Security Flaw in Dirt Jumper Family of DDoS Toolkits Exposes Attacker’s Own Database"

Report from distributed denial of service (DDoS) mitigation service providerSecurity Flaw in Dirt Jumper Family of DDoS Toolkits Exposes Attacker’s Own Database, is linked from Ars "White hats publish DDoS hijacking manual, turn tables on attackers" they (Ars) cover the story in more depth than normal.




Links of Interest:

Thursday, August 9, 2012

Security & Hacking: Gauss Malware, linked to Flame

Saw this first on Ars http://arstechnica.com/security/2012/08/nation-sponsored-malware-has-mystery-warhead/

Original discovery & announcement from Kaspersky

I suggest reading whole story at above links, more detail from Kaspersky link:
At the present time, the Gauss Trojan is successfully detected, blocked and remediated by Kaspersky Lab’s products, classified as Trojan-Spy.Win32.Gauss.
The company’s experts have published in-depth analysis of the malware at Securelist.com: http://www.securelist.com/en/analysis/204792238/Gauss_Abnormal_Distribution
A Gauss FAQ containing the essential information about the threat is also available: http://www.securelist.com/en/blog?weblogid=208193767
Stay tuned for updates by following our Facebook page: https://www.facebook.com/Kaspersky?ref=ts

Tuesday, August 7, 2012

Security & Hacking Updated: Mat Honan Targeted

I posted about this story the other day, VOD interview/discussion at http://twit.tv/show/this-week-in-tech/365

Mat Honan also talks about it on his Blog at http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard

Since I wrote about this, Honan's has written an article How Apple and Amazon Security Flaws Led to My Epic Hacking, were he explains how the hack was done, and how this vulnerability still exists.

Strongly suggest reading the whole story, but the key aspects of the hack are as follows:

  1. "My [Honan's] Twitter account linked to my personal website, where they found my Gmail address."
  2. "Because I didn’t have Google’s two-factor authentication turned on, when Phobia entered my Gmail address, he could view the alternate e-mail I had set up for account recovery. Google partially obscures that information, starring out many characters, but there were enough characters available, m••••n@me.com. Jackpot. "
  3. "Since he already had the e-mail, all he needed was my billing address and the last four digits of my credit card number to have Apple’s tech support issue him the keys to my account. "
  4.  "He got the billing address by doing a whois search on my personal web domain."
  5. Then Hacker calls Amazon & adds bogus Credit Card number to account, since they can do this with just Name, billing address, and email associated with the Amazon account.
  6. Call Amazon back & say can't get into account, Amazon will let you in with:  Name, Billing Address, Email, and Bogus Credit Card numbers Hacker just added.  Then you can add new email to account and see last four Credit Card numbers of every Card on that Account.  So you now have the keys to the Apple account.
This sounds a lot like certain types of games were you have to find small pieces of information and use those bits to build more.

Couple of things stand out to me, besides Apple's horrible policy, if at all possible, don't associate emails or Credit Cards between Apple and any other company that you do online or phone ordering with, because Apple considers the last four numbers of your credit card to be  more than a password, since you can reset valid passwords with that information!

Maybe only use a prepay Card with Apple?  Not sure how else to protect your Apple accounts from being hacked this way.

Monday, August 6, 2012

Security & Hacking: Mat Honan Targeted

VOD interview/discussion at http://twit.tv/show/this-week-in-tech/365

Mat Honan also talks about it on his Blog at http://www.emptyage.com/post/28679875595/yes-i-was-hacked-hard

Take the time to look at this, and think about structuring your accounts & etc to protect yourself from this, Hackers will certainly take note of this.

Couple of Basic Points:

Backup critical data, you need at least 3 copies of important data, the "working" copy, plus two separate backups in different locations/companies.

Don't interlink all your accounts.  That leads to domino effect of a single vulnerability being exploited, perhaps something out of your control like happened to Honan, that gives Hacker access to one of your accounts, and that one account will let them in to all the others.


Tuesday, July 31, 2012

PSA: Dropbox Reports on Customer Spam/Hacking Complaints

See Dropbox's Blog Post http://blog.dropbox.com/index.php/security-update-new-features/ for the full story.

Short version, they say one Dropbox employee account was compromised, and that user emails were available because of that.

Also that some people are using password on multiple sites, and some of those passwords were Hacked from other sites. 

They say they will be improving security, and list a few of the improvements, Two Factor Authentication being the most useful IMO.

For those looking for deeper understanding on (good strong)passwords, see Steve Gibson's Haystacks & Needles (Understanding Passwords).

For more about Hacking or Cracking Passwords, see "Lessons Learned from Cracking 2 Million LinkedIn Passwords".

You can also see all my posts about Passwords or Hacking, by clicking on the Labels Passwords or Hacking respectively, Labels can be found at bottom left of every Blog post, and selected Labels can be found in the cloud at left side of Blog.

Sunday, July 29, 2012

Security & Hacking: "Stop using PPTP and switch to other technologies like IPsec or OpenVPN"

Article on Computerworld, about tools released at "Defcon security conference that can be used to crack the encryption of any PPTP (Point-to-Point Tunneling Protocol) and WPA2-Enterprise (Wireless Protected Access) sessions that use MS-CHAPv2 for authentication."

Bruce Schneir has written about problems with MS_CHAPv2 see http://www.schneier.com/pptp.html or full paper at http://www.schneier.com/paper-pptpv2.html