Pages

Showing posts with label fail. Show all posts
Showing posts with label fail. Show all posts

Wednesday, March 23

Suspicious Domains related to Japan Disaster

With every disaster that takes place, one of things that I do is start to watch the domain names being registered on the internet in relation to the event.

For instance, "earthquake", "Tsunami", Haiti, Chile, and now, Japan.

We mourn for all of those that lost loves ones in each of the disasters, and I feel very sorry for those that have lost everything.  Homes, cars, valuable pictures of your loved ones, family history, and the families themselves.  I am quite sure there are examples where entire families may have been lost to this most recent tragedy.

It's despicable that a malicious person would register a domain, and set up a webpage to receive donations, only to keep the money themselves, or fund $bad_thing.  Absolutely disgusting.

I was taking a look through my list for this morning (I get a list every day), and looking at some of the examples.  A lot of the names you wouldn't even think, just by looking it, that it would be bad.  Examples like "redcrossjapan.com" and .org.  One might think that was a legitimate site.  A few more interesting ones, I'll leave the extension off of these:

  • "earthquakeandtsunamis"

  • "tsunamidanger"

  • "tsunamireliefforjapan"

  • "savejapanesepeople"

  • "rebuildjapan"

  • "japanemergency"

  • "japanliferescue"

  • "earthquakeeastjapan"


Now, I'm not implying that any of the above are bad or linked to the evil-doers. I'm saying that you need to use caution when donating and visiting these sites.  Not all humans are decent, wholesome, and good.  In fact, there are a large amount of people that aren't.  I know, surprise, surprise.

How many domains have I see like this?  Hundreds.  Several.  Hundred.

Donate


I don't want to dissuade you from donating funds to the people of Japan.  They need your help.  They need it bad.  I've donated, and will donate more.  But ensure, when you are donating, you are donating to a reputible organization.  People flocked to help Haiti, I'm asking that we flock to help Japan too.  Just because they are not a 3rd world country, doesn't make them any less important.  Japan came to our rescue when Hurricane Katrina hit, donating millions and millions of man hours and dollars towards the tragedy.  Let's do the same for them.

http://www.redcross.org/

Tuesday, July 13

Mailing lists do not get Anti-Spam

Note: If you are subscribed to a Mailing List, and you have one of those "Auto-answer-back-auto-emailing-verify-that-you-are-a-human-by-clicking-on-this-link-really annoying-things". You are doing it wrong.

Get a frickin Gmail account people.

Saturday, May 22

Facebook privacy, why you should be careful, and what I'm doing personally.

It seems everyone has been jumping on the "Facebook is evil" bandwagon lately, some of it being fair, some of it not.  I thought I'd try and jump on the bandwagon too, but this time, let's lay out the facts and reflect on them and see how they are changing my outlook on Facebook and why it might be good to change yours too.

<bear with me, it's a long one, but it's a real one, and it's meant for you to read>

Facebook is a social networking site.  Two words.

Social -- relating to or designed for activities in which people meet each other for

Networking -- a group or system of interconnected people or things

A place where people come together to be interconnected and share things and activities.  Facebook.  Exactly what it does, so why is everyone so up in the air about it, why are people complaining about it?

Privacy.  Those of you that signed up for Facebook in the beginning, and are like me, take the world on the Internet with the assumption that everything that you do online can be read by anyone, you are careful what you put on Facebook.  I personally live with the realization that I have an Internet stalker.  A guy out there on the Internet -- for whatever reason -- follows me.  Goes to every email listserver I am on, listens to every podcast I do, watches everything that I do.  Now, some of you will look at that and say "Whoa, that dude is nuts!"  Well, I agree.

However, having someone like that is like a check and balance in Government.  It makes you realize that what you put out there on the Internet, no matter how mundane and stupid it may be, someone will jump on it like a horse and ride that sucker for all it's worth.  So you really pay attention to what you put up on the Internet in the first place.

Facebook, when it started out was this concept, very different from "MySpace", where MySpace was "Everything is public".  When Facebook started many people jumped on it, thinking, "Wow, some privacy!"  Everything you put on Facebook could only be seen by your friends.  Those you invited to be your friends, or you authorized to be your friends.  Then, along the way, as Facebook started stealing ideas from Twitter, started making things more public, if you didn't change you privacy settings at each step along the way, your privacy was gone, and everything that was yours and your friends was now available to "Everyone".

Facebook's privacy policy got longer and longer, more and more confusing, until recently this article came out that compared Facebook's privacy policy length to that of the United States Constitution, the document that established and Governs our ENTIRE country, and found that the Facebook privacy policy was longer.

I started thinking about ditching my Facebook page back in November or December of last year when all of this was coming down, and it's just gotten worse and worse.  Take a look at this article written by Jason Calacanis (say what you will about Calacanis, but he brings up some good points to think about, and things that you might want to read yourself).

Jason recently wrote another article about Facebook has overstepped the lines and violated the privacy and trust of it's users.  Both are worth a read.  He talks about how Facebook screwed Foursquare, how they screwed Twitter, how they have screwed their users by changing their privacy model three times.

All of this stems from one guy.  Mark Zuckerberg.  Facebook's CEO and Founder.

"Zuck" as he's known in the "Valley" (I've never met the dude.) started Facebook, or at least came up with the concept for it while he was at Harvard.  Now, there is a lot of controversy about how the idea for Facebook came up, and that he stole it from other people, and this that and the other thing.  I'm not here to decide that, there are lawsuits in progress, and the courts will decide that one.

Zuckerberg has apparently (allegedly) screwed over many companies, partners, etc in the setting up of Facebook.  Claims are (from "they") that he wants to be the next Bill Gates, and is doing so by doing the same thing that Bill Gates allegedly did back in the 80's/90's, by "stealing" the idea for "x" from "y".  (Not mentioning names, because, like I said, allegedly.)

"Good artists copy, Great artists steal" -- Pablo Picasso (Allegedly)

Personally, I don't trust the dude, and neither should you.  <-- Read that.

So what does that mean for you?

If you have the realization that everything you put on the Internet, everyone can see, you are fine.  However, I don't like the fact that Facebook started off with one idea about privacy, and now it's a different story.

So what am I doing personally?

My "content" that I "produce" will no longer go on Facebook.  I'll point to my content on other places, (my pictures, my posts, my comments), however, I won't put things on Facebook anymore.  This will give me a metric.  A metric that says "How much do you really use Facebook".

I use Facebook for a couple things.  I like to put pictures up there and have people comment on them.  I like to put funny sayings and what not up there, but I also like to read what people have to say and look at their pictures as well.  I really use mine as a Social Network.

The people that I add on Facebook are my real-life friends.  Not "Facebook friends".  Not "Internet Friends".  I probably receive about 10 requests to be my "Facebook friend" from people everyday.  People who read my articles on the blog, people who read my articles on the Internet Storm Center..  People who just read my emails on the Snort user groups (or God knows where else) and want to be my friend.  However, no, I don't add them.  Unless I've met you in real life, I don't add you.  In fact, I've deleted a bunch of people recently.

Facebook isn't for those people.  Those people can read this blog, and they are welcome to participate with me through the comments fields.  They are also welcome to follow me on Twitter.  But on Facebook, I have stuff like, pictures of my daughter and other things on there that I just don't want everyone to have complete access to.

I've locked down my Facebook profile along the way as well, making my profile viewable "Only to Friends".  But the trust that I've put in Facebook is lost.  Have you read their privacy policy?

Here are some choice quotes:

"Access Device and Browser Information. When you access Facebook from a computer, mobile phone, or other device, we may collect information from that device about your browser type, location, and IP address, as well as the pages you visit."

I'm not tracking you when you come to my blog.  I don't know who you are.  I don't much care.

"If in any of these cases we receive data that we do not already have, we will “anonymize” it within 180 days, meaning we will stop associating the information with any particular user."

But they don't delete it.

"Deactivating or deleting your account. If you want to stop using your account you may deactivate it or delete it. When you deactivate an account, no user will be able to see it, but it will not be deleted. We save your profile information (connections, photos, etc.) in case you later decide to reactivate your account."

But they don't delete it.

So make sure you read the privacy page.  Oh but wait there's more!  There's the Statement of Rights and Responsibilities page.

My favorite is here:

"For content that is covered by intellectual property rights, like photos and videos ("IP content"), you specifically give us the following permission, subject to your privacy and application settings: you grant us a non-exclusive, transferable, sub-licensable, royalty-free, worldwide license to use any IP content that you post on or in connection with Facebook ("IP License"). This IP License ends when you delete your IP content or your account unless your content has been shared with others, and they have not deleted it."

So..  Anything I upload to Facebook belongs to Facebook.  They can use it however they want.  Including photos, and videos, and what else.

What about individual Apps?  Oh, there's a page for that too.  Check this out.  Good luck locking that down!


So, where am I putting my pictures?

I'm going to put them on my MobileMe gallery.  That allows me to have public photo albums, photo albums I can mark as private, and even more, I can secure certain photo albums with a password.

My Mobile Photo gallery is here. (Pictures that I take while I am on the go.)

But otherwise all my public galleries are here.

Can you subscribe to those photo galleries?  Yes, you sure can.  Via the RSS button at the top.  You can even subscribe to them in iPhoto if you are an iPhoto/Mac user.

If I have a special gallery that I want you to be able to see, I'll post it.  But I don't want my Intellectual Property rights being turned over to Facebook just because I uploaded a photo.  My pictures are mine.  Free for me to do what *I* want to with them.  Not Facebook.

I'm not going to put anymore photos on Facebook.  Done with that.  When I put new photos up in one of my galleries, I'll post a link on Facebook pointing to the gallery.

I'm not going to put any more "content" on Facebook.  I'll put it here, on the blog, or I'll put it on Twitter, then I'll point to it on Facebook.  Annoying as that may be for those of you that are my Facebook Friends, I ask that you respect that I do that, and play along.  I feel that my real friends will still participate, and my "Facebook friends" will fall off.  That's life.

Lock your stuff down people, you have no idea what you are sharing with the world.  For proof, go here.  Take a look at what people are saying!

Does this mean I'm getting off Facebook?  No.  I am just controlling what goes up there.  I'm still going to participate with my friends, I'm still going to comment, and I'm still going to have fun.

Plus this alleviates my annoyance about having to "hide" and "ignore" all those stupid Applications that you people keep putting on there, wanting to share your Pirate Gold and wondering if I'll help you water your crops in Farmville.

I ask that you read what I've written above, click on those links I've put in the post, and decide for yourself.

Oh, and for God's sake.  Lock your PROFILE DOWN.

Wednesday, May 19

LifeLock CEOs Identity Has Been Stolen 13 Times

Can't say I'm surprised at this one.  Any guy that trapes around putting his name and SSN on the side of a billboard is waiting to be had.  I remember remarking to my wife the first time I saw a LifeLock commercial "I call BS."

Of course, now, LifeLock has been fined 12 Million dollars and called liars.

LifeLock CEOs Identity Has Been Stolen 13 Times - IdentityTheft - Gizmodo.

Saturday, March 27

Day Two: No One Even Attempts Hacking Chrome at Pwn2Own Competition

Day Two: No One Even Attempts Hacking Chrome at Pwn2Own Competition - Google Chrome - Lifehacker.

Found this interesting.  I didn't make it to CanSecWest this year, but several of my friends did go to this event/competition.  While I did see that every other major browser was cracked on day one, (IE8, Firefox, and Safari) Chrome didn't even get  tried, apparently.

While Chrome does use the Webkit (safari) engine, Chrome starts each browser tab in a separate process which is in a 'sandbox'.

On the usability side, I've been using Chrome on the Mac since they opened up the dev channel for it, and I really like it.

Tuesday, February 16

Will Hack For SUSHI » MiFi Config Hack

Will Hack For SUSHI » MiFi Config Hack.

A post by friend and collegue at SANS Joshua Wright.  Joshua is one of the guys I know that is really proficient at hacking wireless.  Bluetooth, wifi, etc.  He does some really wonderful work at that, and he's fantastic at it.

This post is about him hacking his Mifi (Verizon).  He has two posts on the subject you should check out if you have a Mifi.

The other post is here.

Friday, February 5

If you never knew it occurred, did it occur in the first place?

In my To-Do list, I have a section for Blog topics that I think of in $random_place and I want to jot down for brainstorming later. This topic has been on my to-do list for about a year.

I was standing on a stage giving a speech at a military base, in about 2004.  The people I was giving a speech to were about 200-250 different "network" and "Systems" administrators from all over this military base in tons of different units.  In this audience I had military, civilian, and contractor.  I was asked to give a speech to the system administrators because some of them didn't see the value in security in their systems.  It was an afterthought and people weren't terribly excited about having to follow $regulation that ensured proper lock down of various controls in the operating system and network.

I asked this question:  "If you never knew it occurred, did it occur in the first place?"  I paused for effect, waiting for an answer.  One didn't come.  Obviously they had no idea was I was talking about.

I proceeded to explain the importance of reviewing logs, system and network information, explaining to them the importance of what I had found that week upon a security audit I was doing of their Army post.

Hundreds of compromised machines, botnets, poor security controls, inadequate permissions, etc.  This was all from about 3 days of work.  I didn't even get into the trenches trying to find things, this was just surface level scanning and network monitoring.  Not even penetration testing, just scanning.

They didn't know.  They thought their network was perfect.  They thought it was clean.  They didn't need to review logs.  They thought wrong.

If you aren't going to review logs, if you aren't going to look at the system logs, the firewall logs, the IDS/IPS logs, then why collect them?  The problem is, we have things like SOX compliance now that mandates that we have some kind of logging system.  Which is fine, it's a great idea, but people are missing the point.  The point of the SOX compliance and log review is for people to REVIEW the logs.  Otherwise what is the point?  So you can go back and see when you were compromised?

Some people will agree with me here and say "Yes, I'd like to have historical information so I can go back and see when the intrusion occurred."

That's fine, I don't disagree, but stop for a second while reading this and meditate on this question "Why?"  What are you going to do about it?

If you are going to look at your logs and dismiss them, instead of looking at your logs and doing something about the mistakes that you find, then what's the point in looking at the logs.  Don't waste your time.

It's your JOB to be looking at these things, if you aren't going to DO your job, then quit.  We don't need you in our industry because it's people like YOU that are messing things up for the rest of us.

I'm going to do it...  I am going to use APT (Advanced Persistant Threat).  APT was found by looking at logs.  APT has been around for a long time.  Before I worked at Sourcefire, I worked for the Department of the Army in computer security, and we were dealing with APT (only it wasn't called that back then) then.  We didn't have an advanced term for the threat, we used terms like 'rootkit' and 'trojan'.  We were looking at hacks that we had never thought possible offloading information to countries that weren't ours.  Some of the techniques were so interesting and secret, they haven't been made public to this day, so I can't talk about them here.

But we found the compromises by looking through logs.  I've said this before, and I'll say it again, what's the point in having a security device that keeps logs if you aren't going to LOOK at it?

Sunday, January 31

Flash, time for you to die

I've been reading a lot of hubbub about the new Apple iPad not having the capability of displaying Flash.  Of course!  It stands to reason that it can't, it has the same OS as the iPhone, which, also can't display Flash.  Which leads me to think, why do we need flash?

Answer is, we don't.  Not anymore.  90% of Flash usage is for audio or video on the Internet and HTML5 can handle <audio> and <video> tags.  It can do Canvas. (Oh and a TON more, I'm just illustrating a point.)  Some of the major browsers have adapted most of these technologies.  Webkit (Invented by Apple, powers Safari, Webkit, and Google Chrome [amongst others], and Presto (The rendering engine that powers Opera) have supported more than the other two majors (Gecko -- The engine that powers Firefox and all of it's kin), and Trident (The engine that powers Internet Explorer).  The last being the worst adopter.  Surprisingly.

I read somewhere (I can't find it now), about most browser crashes come from plugins.  Flash, Java, etc.  Why can't we eliminate these plugins and go with the native protocols?  That's what HTML5 is attempting to do for the most part, and I, for one, am glad for it.

Apple has always been about killing off technologies and moving onto what is on the horizon (killing off serial, going for USB, killing of Diskettes, going to CD, Killing off CD's (Macbook Air), moving more wireless (Airport), Killing off displayport, hdmi, dvi, vga, going with Mini Displayport).  They have never been afraid to just "move on" to the new thing.

I believe they said to Flash, die, HTML5 is here.  Then they turned to web developers and said "fix your stuff".  How did they do that?  Rolled out the iPhone, which has become the largest mobile browsing platform on the planet now.  Slowly and surely, what's happening?  Websites are changing away from Flash.

Unless, you know, of course, you are a band or a restaurant.  (Seriously?  What is with bands and restaurants and your use of Flash?)

I don't even need to get into the security issues of Adobe's Flash.  Look, there is one small part of Adobe working on Flash.  The entire internet is working on HTML5.

Flash (and Silverlight) is dead.  Get over it.

--

100% of the statistics in this post are made up.  ;)

Friday, January 8

Verizon Wireless's Fail

Several months ago I ditched my AT&T 3G Card that I was using for mobile Internet and bought a Mifi from Verizon.

A) Verizon has better connectivity in New York (I was spending a lot of time in New York)

B) Verizon has better connectivity on trains than AT&T.  (Not faster, just a more persistant connection.)

Well, in order to manage your account, you have to sign-up for a website called myverizon.com, which, in order to complete the sign-up, asks to text message you your pin/password to verify your identity.  So, I laugh to myself, as the Mifi doesn't have a screen or any way to receive a text.  So, I get a hold of Verizon, and they tell me that their VZwireless software allows you to see the txt's send to the Mifi, okay, fine..

I fire up the software, no "txt".  It's not in the Mac Software, it's only on the Windows VZWireless software.  Hilariously irritating, so the alternative is, they mail you a pin number.  Physically mail you, using snail mail, a pin number.  What a waste of trees.  Anyway..  I arrive today at getting my pin number via the mailbox, I sit down, type in the temporary password (pin number) on my login page, and finally, I get to reset the password.

So, there's 3 blanks on this page, and a drop down.  First -- New password, second -- as you guessed it -- verify new password.

Now, here's where it gets good.  Drop down "Select the phrase to remind you of your password".   Your typical "Challenge/Response" thing right?

Here's the drop down:



Yup, seriously.  No questions for the "Secret Question" -- I mean, if the questions are secret...

Last drop down was the answer to the "Secret Question".

Okay, so, what have we learned here?  Verizon.  You are making life extremely painful to me.  FIX YOUR SIGNUP METHOD.

Oh, and your webpage.  You are DOING IT WRONG.