Showing posts with label PSA. Show all posts
Showing posts with label PSA. Show all posts

Thursday, August 1, 2013

PSA: Blizzard says "WoW, SC2, & D3 on NA servers will be down for maintenance"

Sounds like Bnet is going down in NA today Thursday August 1, 2013 at 7:00 pm EST, see Tweets below:

"Maintenance is scheduled for tonight so & will be unavailable during this time. Start time for the maintenance is 7pm AEST."
~https://twitter.com/Blizzard_ANZ/status/362800725161545728

"Yes KR or any other server outside of NA will be fine."
~ https://twitter.com/Blizzard_ANZ/status/362809784774299648

Edited to add:  "NA servers, and it looks like a 6 hour maintenance window"
~https://twitter.com/Blizzard_ANZ/status/362803226396999682

Updates are welcome in comments section, I will probably not be able to update Blog if anything changes till late Thursday night (US time).

GL HF

Saturday, June 22, 2013

Home Story Cup VII (HSC) stream is up

Update:  Stream A is up on Twitch now http://www.twitch.tv/taketv

Update:  Stream B for HSC http://www.twitch.tv/TaKeTVBStream
also other streams on Twitch for HSC seem to be working and are listed on TL http://www.teamliquid.net/

Update:  stream crashed and is still down for me, but up for some of my friends

HSC Stream is up at http://taketv.net/

Via TLO's Tweet:  "you'll find the stream for on now! Sorry for the delay ;;" ~https://twitter.com/LiquidTLO/status/348429765365088257

TwitchTV Outage & HSC VII delay

Twitch was down for a while, now I believe it is up in limited ways/areas, many people getting 403 Forbidden error, official post about it from Twitch.TV here http://blog.twitch.tv/2013/06/site-outage-passwords-and-stream-keys-reset/

So far they are saying they were not hacked, rather their "web CDN made a requested change without obeying our caching ruleset," but they are forcing password reset because of issue.

If you read the comments, it sounds like they discovered more problems after they made that blog blog posts or initial tweets.

In addition to their blog site, you can follow Twitch's main Twitter at https://twitter.com/TwitchTV, or their support Twitter at https://twitter.com/TwitchTVSupport

They are working on getting things backup and running ASAP.

HSC (Home Story Cup) was delayed an hour from what I have seen on Twitter from Rotti:
"We were supposed to start at 13:00 CET but it might be 14:00, depends if Twitch tv is working fine or not, I'll keep you guys posted!"
~ https://twitter.com/RotterdaM08/status/348393076617797632

Note I have world clock at top of Blog, starting with Korean time, to make figuring out time zones at a glance easier.

I will post updates if possible when they become available.

Tags:  TwitchTV, HSC VII, streaming, PSA

Thursday, January 31, 2013

PSA Security & Hacking: UPnP (Universal Plug and Play ) Vulnerability



Security Now 389 "Unplug UPnP" links for audio downloads & etc http://twit.tv/show/security-now/389

[Edited to Add:  Steve Gibson has UPnP exposure test in Shields up now!  Thanks Steve!! https://twitter.com/SGgrc/status/297165652257554432]

CERT Note http://www.kb.cert.org/vuls/id/922681

US CERT "Multiple vulnerabilities have been announced in libupnp, the open source portable SDK for UPnP devices. Libupnp is employed by hundreds of vendors for UPnP-enabled devices. Information is also available in CERT Vulnerability Note VU#922681.

US-CERT recommends that affected UPnP device vendors and developers obtain and employ libupnp version 1.6.18, which addresses these vulnerabilities.

US-CERT recommends that users and administrators review CERT Vulnerability Note VU#922681, disable UPnP (if possible), and restrict access to SSDP (1900/udp) and Simple Object Access Protocol (SOAP) services from untrusted networks such as the Internet." ~http://www.us-cert.gov/current/

Steve Gibson provides details on this issue, he also notes in the VOD above that he is going to add the capability to test for this Vulnerability to his ShieldsUP service/software.

ShieldsUP http://www.grc.com/x/ne.dll?rh1dkyd2

Problem with this, is even if you disable UPnP on your Router, it may still be enabled on the WAN (Internet) side.

Till Gibson gets this functionality added to ShieldsUP, not sure how most people could scan for it to be sure it was disabled on their routers.

Hard Core Nerds with correct tools could Pen Test individual Routers, but not aware of any practical way to test for people that don't have the skillset and tools for Pen Testing.

AFAIK the Rapid7 tool isn't stable/reliable, least it wasn't yeasterday for many people, it may have been patched since then, but not comfortable recommending it at this time.

I wouldn't trust vulnerability list from any Manufacturer on this, because it is a very bad case of stupid to have in the first place.

I haven't had enough time to find out if Tomato http://en.wikibooks.org/wiki/Tomato_Firmware#Supported_devices or DD WRT http://www.dd-wrt.com/site/index provide a guaranteed fix for this yet.



Monday, January 21, 2013

PSA Wikipedia downtime & disruptions with Server Migration likely

Wikimedia sites to move to primary data center in Ashburn, Virginia

Tuesday Jan 22 through Thursday 24, 2013 is the current planned time frame.

Source http://blog.wikimedia.org/2013/01/19/wikimedia-sites-move-to-primary-data-center-in-ashburn-virginia/:

"Engineering teams have been preparing for the migration to minimize inconvenience to our users, but major service disruption is still expected during the transition. Our sites will be in read-only mode for some time, and may be intermittently inaccessible. Users are advised to be patient during those interruptions, and share information in case of continued outage or loss of functionality.
The current target windows for the migration are January 22nd, 23rd and 24th, 2013, from 17:00 to 01:00 UTC (see other timezones on timeanddate.com)."

Makes me wish I had Wikipedia already downloaded for offline access, it is on my to do list, have blogged about it before http://cliffsesportcorner.blogspot.com/2012/09/random-wikipedia-of-day.html.

Link to Download page http://en.wikipedia.org/wiki/Wikipedia:Database_download

Friday, January 18, 2013

PSA Security & Hacking: Shylock Banking Trojan now spreading via Skype

Primary source https://www.csis.dk/en/csis/blog/3811

As someone that is computer security conscious, I avoid online banking completely.

For friends, family, & others that insist on online banking I suggest either of the following:

  • Use a Live CD, Brian Kreb has excellent articales on how to do this http://krebsonsecurity.com/2012/07/banking-on-a-live-cd/ or http://krebsonsecurity.com/banking-on-a-live-cd/
  • Use a recent iOS device, iPhone 4S or newer, iPad 2 or newer, iPod Touch 5th generation or newer.  There are significant hardware security improvements that started with those respective devices. 
I also strongly suggest if using the iOS devices, to turn off Simple Passcode, and use a Pass Phrase, even if you don't lock your iOS device all the time, this will enable whole device encryption.

Clear instructions & screenshot for turning off Simple Passcode http://www.computerworld.com/s/article/9231627/Kenneth_van_Wyk_Shutting_down_security_gotchas_in_iOS_6?taxonomyId=17&pageNumber=1

The reason for this, is that a hacker with right software, can use a computer to try passwords, they can also bypass the 10 try feature.

So if your using the Simple Passcode, which is just a 4 digit number, they will probably be able to hack it in less than an hour.

However, if you use a Pass Phrase, like I <3 my iPad.  I hate green beans! the hacker will have a much more difficult time.  [Note, don't use that pass phrase, it is just to illustrate the concept.]

Since instead of only 4 numbers, there are 34 characters, counting the blank spaces, plus your using uppercase letters , lowercase letters, numbers, special characters, and blank spaces.

The hacker won't have any idea how long your password is, and by using at least one of all possible upper/lower case, numbers, symbols, and blank spaces you make hackers job a lot harder.

For more on passwords see http://cliffsesportcorner.blogspot.com/2012/05/steve-gibsons-haystacks-needles.html

Additional links:


Thursday, November 29, 2012

PSA Security & Hacking: Western Connecticut State University possible data breach

"Personal information Western Connecticut State University kept over a 13-year span on students and their families, as well as high school students, might have been exposed to unauthorized access between April 2009 to September 2012, school officials are warning."
~ Source and full story at http://www.nbcconnecticut.com/news/local/WCSU-Data-Vulnerability-Could-Affect-235000-181374021.html


Wednesday, November 14, 2012

PSA Security & Hacking: Skype Password Reset Exploit

Edited to add:  Skype is Patched now

http://heartbeat.skype.com/2012/11/security_issue.html
[UPDATE:14/11/2012@15:28GMT]
Early this morning we were notified of user concerns surrounding the security of the password reset feature on our website. This issue affected some users where multiple Skype accounts were registered to the same email address. We suspended the password reset feature temporarily this morning as a precaution and have made updates to the password reset process today so that it is now working properly. We are reaching out to a small number of users who may have been impacted to assist as necessary. Skype is committed to providing a safe and secure communications experience to our users and we apologize for the inconvenience.

*****************

This story is breaking all over net now, I like Sophos Naked Security's article the best http://nakedsecurity.sophos.com/2012/11/14/skype-security-hijack/

They refer to this article http://thenextweb.com/microsoft/2012/11/14/security-hole-allows-anyone-to-hijack-your-skype-account-using-only-your-email-address/

Supposedly this has been used in the wild for months, evidently posted about on Russian forums that long ago.

Official Skype statement from http://heartbeat.skype.com/2012/11/security_issue.html:
We have had reports of a new security vulnerability issue. As a precautionary step we have temporarily disabled password reset as we continue to investigate the issue further. We apologize for the inconvenience but user experience and safety is our first priority 

Don't have any other details to provide at the moment.

Tuesday, October 30, 2012

PSA: NYC Hurricane Sandy & Delieveries of Food, Medicine, or Water

 Via Twitter:
Anyone who needs food, water or medical supplies delivered via bike please message us 
~https://twitter.com/OWSBC/status/263395580238249984

 Their webpage is http://owsbc.org/

Their Twitter homepage is https://twitter.com/OWSBC

Email: OWSBC@OWSBC.ORG
Twitter: @OWSBC
Facebook: OWSBC

Monday, October 29, 2012

PSA: Live Radio (EMS) feed from NYC

http://www.radioreference.com/apps/audio/?action=cwp&ctid=1855

Hurricane Sandy: Map with Gauge Flooding in Real Time

http://www.wnyc.org/articles/wnyc-news/2012/oct/29/map-real-time-flood-gauge/

A real time map showing flooding, based on remote sensors if I understand correctly.

PSA: Hurricane Sandy Reference Page

Edited to add:  online broadcast of EMS radio from NYC area http://www.radioreference.com/apps/audio/?action=cwp&ctid=1855 

Flood Map based on sensors if I understand correctly http://www.wnyc.org/articles/wnyc-news/2012/oct/29/map-real-time-flood-gauge/

*****

http://researchbuzz.me/sandynyc/

Research Buzz is a blog by a very good researcher, that I have been following for some time, today they have resource page up for Hurricane Sandy, focusing on New York City (NYC), but is relevant to surrounding areas and for general info on Hurricane Sandy.

One handy tip quoted from link above:
"Remember, if you want to follow a single Twitter account via SMS, you can send a text message to 40404 reading follow username (substituting the Twitter account name for the user name you want) — depending on your phone it might be easier for you to get updates from emergency service Twitter accounts via SMS than via a Twitter application."
Just a handful of the more general resources, from Research Buzz:



Thursday, October 4, 2012

PSA Skype Malware Alert

Update:  GFI Labs has report about it http://www.gfi.com/blog/infection-spreads-profile-pic-messages-to-skype-users/


****
There is some type of Skype Malware that was making rounds last night.

Several of my friends, including one Pro SC2 player, got hit by it, and it spammed malware link to everyone in their contact list.

So if you get a Skype link from anyone, I would check with them first before opening it, versions I was sent said something about "Is this your new profile pic lol" but I am sure there are more than one version out there.

There always are.

Tuesday, September 18, 2012

PSA Security & Hacking: Virgin Mobile forces users to 6 digit numerical password

http://arstechnica.com/security/2012/09/virgin-mobile-password-crack-risk/

This story is all over the web today, short version, it is ridiculously easy to crack.

Other thing, though I haven't seen this posted, is since they require 6 digit number only, very good chance the "passwords" are not stored securely either.

If you using best practices, no real reason to limit password length, and 6 digit passwords, numbers only(!) no letters or characters, are about as secure as lock on bathroom stall.

I am basing the storage is not done well on the fact that a 6 digit password is clear sign of bad security planning, so I figure rest of the security connected to this would be poorly designed and/or executed.


Security & Hacking: "ID Theft Service Tied to Payday Loan Sites"

Article at http://krebsonsecurity.com/2012/09/id-theft-service-tied-to-payday-loan-sites/

Everyone who isn't fully aware of the sad, frightening realities of Hacking, should really read Brian Krebs' article linked above, for those that don't know Brian was a reporter for The Washington Post for several years, he knows his topic very well.

This reminds me of the Mat Honan hack or Social Engineering attack that happen not that long ago, I hope a lot of people read Brian Krebs' article, and start making noise to their Banks, Schools, Legislators, etc.

If your not familiar with Mat Honan case see Mat Honan Targeted, and click this link for response by Apple & Amazon.

There really isn't any information about you a motivated criminal Hacker can't find out, so those elements should not be used to give control of accounts to someone over the phone or net.

There is no perfect solution yet that I am aware of, best thing for institutions like banks, that I know, is to make people come in to a Brick & Mortar location, and provide current picture ID from Government/Military, not just asking them over phone or Net for SSN or Mother's Maiden name.

For more blog posts on similar topics, click either label Security or Hacking, those labels can be found in Label cloud at left side of blog.

Labels can also be found at bottom left of every post.

Stay Safe,

Cliff


Friday, August 31, 2012

PSA | Security & Hacking: Java Patch has critcal bug(s?)

See Ars link for full details http://arstechnica.com/security/2012/08/critical-bug-discovered-in-newest-java/

In case you missed it, this patch was out of cycle on released yesterday to deal with this Zero Day Java Exploit 

At this point I am joining lot of other people in recommending disabling Java from all the browsers you use.

AFAIK using Java on your computer, but not with Browser, like to play Minecraft should be okay, I have heard had more than one computer professional say that.

If there are online services that you need to use for work, or whatever, that require Java in Browser you can do several things:
  1. Ask that company if they have any Java alternatives, or if they are working on alternatives because of the Security risks of Java.
  2. Use a second browser only for the sites that you have to use Java for, make sure you keep it patched (most of the mainstream browsers now disable Java if you don't have current version installed)!
  3. Disable Java on your browser and only turn it on when needed, then turn it off again.

See Also:

Monday, August 13, 2012

Security & Hacking: "Math Model Identifies Network Source of Rumors, Epidemics"


See http://sciencebusiness.technewslit.com/?p=10795 for full story.

Short version, they use some type of statistical sampling (I believe) to locate probable source of events, this can be used for tracking source of Malware, Spam, Rumors, Epidemics, etc.

While a very useful tool, this also has clear implications for freedoms, it could make SOPA look like nothing, and it is frightening to consider what a truly repressive government could do with such a tool.
 
Excerpt (?) of Paper, authored by  Pedro C. Pinto, Patrick Thiran, and Martin Vetterli, can be seen at (PDF) http://www.pedropinto.org.s3.amazonaws.com/publications/locating_source_diffusion_networks.pdf

Full paper, behind paywall, at Phys. Rev. Lett. 109, 068702 (2012) [5 pages]Locating the Source of Diffusion in Large-Scale Networks

DOI:
10.1103/PhysRevLett.109.068702
PACS:
89.75.Hc, 89.20.Hh, 89.75.Da


According to PDF link:
  • "This work was supported by the ERC Advanced Grant – Support for Frontier Research – SPARSAM Nr: 247006."
  • "[16] See Supplemental Material at [URL will be inserted by pub- lisher] for additional details on proofs, accuracy of approxi- mations, complexity, and parameters of the case study."

Tuesday, July 31, 2012

PSA: Dropbox Reports on Customer Spam/Hacking Complaints

See Dropbox's Blog Post http://blog.dropbox.com/index.php/security-update-new-features/ for the full story.

Short version, they say one Dropbox employee account was compromised, and that user emails were available because of that.

Also that some people are using password on multiple sites, and some of those passwords were Hacked from other sites. 

They say they will be improving security, and list a few of the improvements, Two Factor Authentication being the most useful IMO.

For those looking for deeper understanding on (good strong)passwords, see Steve Gibson's Haystacks & Needles (Understanding Passwords).

For more about Hacking or Cracking Passwords, see "Lessons Learned from Cracking 2 Million LinkedIn Passwords".

You can also see all my posts about Passwords or Hacking, by clicking on the Labels Passwords or Hacking respectively, Labels can be found at bottom left of every Blog post, and selected Labels can be found in the cloud at left side of Blog.