Pages

Monday, September 27

Let me tell you about my past two weeks

The past couple weeks I've had the opportunity to do some really amazing work, something that most people, if they could do, would understand a lot more of what goes on behind the veiled curtain.

The last two weeks I worked for Sourcefire's Vulnerability Research Team (VRT).

First I'd like to say that I've never worked with a more professional organization.  Period.  I came in to do some technical work with them, which consisted of analyzing hundreds of pcaps, tons of analysis, and as a result writing rules for those threats.  We did, kind of a tech exchange type of thing.

Now, we weren't shooting in the dark.  (even though there is no overhead lighting in the VRT offices, and you have to watch for getting hit in the head with a Nerf dart)  The VRT doesn't take the random vulnerability or exploit found on exploit-db.com or milw0rm or whatever, and just bang out a rule for it.  They do labor intensive work.

For instance, I had to write a rule for a vulnerability in a piece of software that had to do with email.  In order to test of this vulnerability, could I have taken a piece of a malicious attachment, or looked for a malicious attachment and written a "signature" to check for the exploit here.  Sourcefire's standard is higher than that.  We try to not do that kind of thing.  We try and write a rule to look for the vulnerability itself.  For example: If the vulnerability is actually the fact that a certain field, if it's over 512 bytes, can be used to overflow a buffer in the software, looking for a series of "A"s isn't going to work.  Looking to see if the field is bigger than 512 bytes is the correct way to do it.

But I digress….

The easiest way to emulate this problem is to send an email with an attachment on it, and capture the pcap, then pick it apart from there.  The problem with that is, most  email (well at least Sourcefire's) is encrypted.  So, I got with one of the other VRT guys and we came up with a solution.

Write an email delivery system.

So he did.  It's in ruby, and it allows you to send an email, just like any other email client would, unencrypted, and much faster and more reliable than a regular email client would, if we were trying to trick the client into doing something.

We took the ruby script that he wrote, made it attach a file in base64, and captured the pcap.  Now, you may ask me a question, "Heck, why didn't you just make a new email with Outlook Express and make an attachment and send it?"  Because Outlook Express uses a different attachment system, it's crackheaded, and it's non-standard.  Don't believe me?  Send an email with Outlook and then send an email with Outlook Express and compare the two pcaps.

So I captured the pcap -- that's all well and good, except that I noticed that the checksums in the pcap was wrong.  Sometimes when you capture traffic on an interface, on certain OSes, it will capture the traffic before the checksum is computed, so it will write to disk incorrectly.  So that has to be corrected before you can write a rule to look for the vulnerability.

So, I used tcprewrite to correct the checksums on the packet, and off I went from there.

Now, you come up with the realization that this happens, sometimes 10-20x a day for the VRT, and you come to realize that the rules that are written by these guys are very professional and come with a higher degree of accuracy and purpose.

I'd like to thank the VRT to allowing me to come in and learn and share with them.  I hope I helped them out as much as they helped me.

Final thought -- Take your time when writing your rules.  The time spent writing them makes for a much more reliable rule than just banging out a rule…. and I have seen a lot of "just banging out a quick rule" lately.  A quick rule usually isn't a rule.  It's a signature.  There is a difference.

Oh, and whomever wrote the Microsoft Word and Excel standard is a crazy crack smoker.

Long live Razorback.

Friday, September 10

Verizon Rumored To Replace Google With Bing On All Android Devices

Yesterday, Spetember 9th, Verizon gave a preview to their newest "Android" phone coming out for their network, Samsung's Galaxy S.

It has a 4-in AMOLED screen, 1GHZ Hummingbird Processor, and it has the ability to become a hotspot.  However, Verizon has ruined the phone, and may ruin every phone on their network from now on.  Why?

The thing that makes Android great is it's integration.  Google built the OS, it's integrated into Google's infrastructure, and that's the way it works best.  Just like the iPhone, which works best with Apple's infrastructure (MobileMe, iTunes, etc).

Verizon has decided to cripple this phone by instead of tying it to Google, they have tied it to Bing.  Bing Search, Bing Maps, and instead of Google's awesome navigation app, they have replaced it with Verizon's own Navigation app, which, btw, they cleverly charge you 10 bucks a month to use.

Bloatware..  Blockbuster apps, Tetris apps that charge you money, etc.

To make it worse, Verizon has stated that they will be moving all of their "Droid" line to Bing.  It won't be exclusive, (meaning you can switch everything back to Google), but this is basically how to ruin a franchise.  (Verizon having Android on everything.)

This is where Verizon did it wrong with the iPhone as well.  When Apple came to Verizon and said "We are going to make a phone, you can be the carrier, but you can't put any apps or logos or anything on it"  Verizon said No.  So Apple went to Cingular (which later was bought by AT&T).  Cingular agreed, therefore the iPhone is on AT&T right now.

Apple's iPhone doesn't have bloatware (unless you count the apps that Apple puts on there themselves, which, I can understand your argument), it starts off with Google as the search engine by default, but you have the option to change it.

The iPhone doesn't force you to use a service, they force you to use the apps that are built in (unless you download new ones), like the "Maps" application, it's Google Maps and Google Search, but you'd almost never know it.  So far Apple hasn't ruined it, but we'll see.

Verizon may be ruining a good thing here.  Hopefully they don't.

Here's Gizmodo's review as well: here.

Verizon Rumored To Replace Google With Bing On All Android Devices | Markets | Minyanville.com.

Friday, August 27

Why I haven't written

I haven't been writing recently.  Been kinda busy.

For those of you that haven't heard, my wife gave birth to our baby boy last Wednesday.

His name is Paul Esler.

Thursday, August 12

Start with a cage containing five monkeys.

Start with a cage containing five monkeys.


Inside the cage, hang a banana on a string and place a set of stairs under it. Before long, a monkey will go to the stairs and start to climb towards the banana. As soon as he touches the stairs, spray all of the other monkeys with cold water. After a while, another monkey makes an attempt with the same result - all the other monkeys are sprayed with cold water. Pretty soon, when another monkey tries to climb the stairs, the other monkeys will try to prevent it.

Now, put away the cold water.


Remove one monkey from the cage and replace it with a new one. The new monkey sees the banana and wants to climb the stairs. To his surprise and horror, all of the other monkeys attack him. After another attempt and attack, he knows that if he tries to climb the stairs, he will be assaulted.
Next, remove another of the original five monkeys and replace it with a new one. The newcomer goes to the stairs and is attacked. The previous newcomer takes part in the punishment with enthusiasm! Likewise, replace a third original monkey with a new one, then a fourth, then the fifth. Every time the newest monkey takes to the stairs, he is attacked. Most of the monkeys that are beating him have no idea why they were not permitted to climb the stairs or why they are participating in the beating of the newest monkey.
After replacing all the original monkeys, none of the remaining monkeys have ever been sprayed with cold water. Nevertheless, no monkey ever again approaches the stairs to try for the banana.

Why not?


Because as far as they know that's the way it's always been done around here.
And that, my friends, is how policy begins.
-- Don't know the original author or where this came from, but it was posted on a Listserv I belong to, and I thought it was great. If anyone knows where this originally came from, please post in the comments so I can attribute it.
However, I think this really exemplifies some points that I've said for years. Just because "That's the way it's always been" doesn't mean that's the way it always needs to be done. Examine the status quo, and if you can try and make it better, do so.

Thursday, August 5

Security for the SMB makes sense, by Jason Brvenik

Security for the SMB makes sense.



I was off reading some older articles written on a couple of blogs that I follow looking for something in particular. Well, I never did find what i was looking for (in regards to the article itself), but I did reread this post by Jason Brvenik over at Snort.org.

This is a great article in response to another article about why small business shouldn't invest in IPS (which is a crazy view). Jason really does a nice job of laying out the reasons why its important. Definitely worth the read, or reread if you've seen it before.

Google Wave, it's dead. So sad.

In case you haven't heard.


So, on Google's "Official" Blog (which one guys?  You have so many!) they announced yesterday that they are pulling the plug on Google Wave.

So sad.


I think Wave had some really good potential, but I'll say it here, as I have said it since the beginning, Wave would have never caught on unless it replaced something else.  Wave was pretty neat, it was like a Wiki, Google Docs, Gmail, Gtalk, and god-knows-what-else all rolled into one.  It worked, it worked pretty well.  But it didn't replace anything for anyone.  It was a "and also" technology.

Let's Hope


Google rolls some of the technology they developed for Wave into the rest of their products.  For instance, simultaneous typing. That could be useful in Gmail and Gtalk.

I think the collaboration-on-documents idea was great.  That would be most useful in a corporate setting.  I would have loved to use it at Sourcefire.

Design


Some of their design ideas were great. Look at the navigation window over here on the right.  Look at the shading around the box, Look at the title bar (how it can be collapsed).  Look at the "+" button.  It all looks very nice.  It has icons, it has lots of html5 being used to shade and render it.  The drop shadow, the links.  Every box on Google Wave seemed to be more carefully thought out and precise.  The GUI was a wonderful idea and one couldn't very well argue with that.  The scroll bar (not pictured here) was nice to use.  Every pane was separated into it's own individual boxes.  You could tell there was a difference in between all of them.  Take a look at this post over at lifehacker.org: http://lifehacker.com/5400644/google-wave-look-and-feel-coming-to-gmail-other-google-apps.  I don't where they got that screenshot, but that's the way that Gmail should look!  Look at the boxes, the drop shadows, the shading.  The whole look and feel reeks less of a "Web App" and more of a Desktop app.  It has polish.  It has great design.  If you take a look at a screenshot of Gmail, from my own inbox, you will see what I am talking about.  Look at the panes here.  Look at the navigation windows.  This is not good GUI design in a web app, functional?  Yes.  Good looking and easier to navigate? No.

If Gmail wants to act like they are a desktop email replacement tool, they need to stop looking like "Mutt" and start looking like Wave.

In a way, I'm kind of sad to see Wave go.  There was a lot of really great ideas there.  I enjoyed using it.

However, I can totally see how it didn't work for some people.  It was confusing.  People didn't understand how it was different from anything else they used.  As I said, it didn't replace anything they already had, it didn't have a "need".  When the iPhone was invented people immediately saw the "need" for it.  A phone that is brilliantly easy to use.  It also replaced things.  It replaced their phone, it replaced their blackberry.  It was simple.

Wave wasn't simple.  It didn't replace anything, and that is why it failed.  People don't need another email system.  In fact, they need less.

Tuesday, August 3

Now that I have these IDS events, now what?

In my full-time job I work for Sourcefire, as a Sourcefire and Snort Professional Services Consultant.  I deal with a different customer every week (sometimes every day), and with each customer comes a separate set of IDS events.  Customers will often tell me "this network is unlike any you've ever seen before", and for the most part, they are right.  While all networks consist of servers, desktops, switches, routers, firewalls, antivirus, and even IDSes, all networks are essentially the same in that respect.  However, each of them pose their own unique set up and vulnerability attack-landscape.  Each network is unique in this way, it doesn't matter if you have 300,000 users on your network or 10.  All that does is make your life as a security person more difficult, this is essentially a number.  That number may increase lots of things, people hired to handle them, number of sensors needed, the amount of bandwidth needed, etc.

So, in dealing with the hundreds, perhaps hundreds of thousands, perhaps millions of IDS events that I see during the day on different networks, how do I deal with them?  How can I get into a customer engagement and turn 400,000 events a day into 100?   How do I help my customers deal with this?

My answer is: One at a time.

How do I do it?  Well, I take the same fundamentals as I have applied to Getting Things Done and Inbox Zero (mostly the latter) to IDS events.  In other words, for each IDS or IPS event, there is at least one (maybe multiple) outcome(s) to that event.  While yes, that may seem redundant, (and it is) my point in saying that is that there should always be an outcome to any IDS event.  It shouldn't just sit.  You shouldn't just be "moving events to archive".

You can kind of think this as a flow chart.

First -> Look at the event, let's use this event as an example:

POLICY Adobe FLV file transfer

Analyze it in context, what does this event mean?  It means someone is watching a flash video on the internet.  Okay, big deal right?  Is that allowed by policy?  Look at the packet data, is it from youtube?  Is watching YouTube from the corporate network allowed?  Perhaps if you are on a Government network, this isn't allowed, okay, so what next?  Do I need to look at the flows around it recorded by Netflow or RNA?  Do I need to look at my SIEM tool?

Second, Now comes where you ask "what relevancy does this have to my network?"  If it's a Sourcefire protected network (read: not Snort) then you might have RNA to help you perform this function.  How is the impact rating on the alert?  Is it high?  Is the end host vulnerable to this "exploit"?  The impact rating for the above event is probably pretty high, since every browser on every OS (for the most part) can watch a flash video.  How old is the rule or alert?  Does it cover a CVE that was patched in 2002?

Now that we know what the event is, and what relevancy it has to our network, what are we going to do about it?  Well, I view this has having about four possible outcomes.  Of course, this is related to Snort, so your IPS may vary.  But all IPSes get better with tuning, so...

  1. If you are in IPS mode, do you want to block it or not?

  2. Threshold or Surpress?

  3. Edit the rule manually?

  4. Shut the rule off?

  5. Does it provide relevance to other rules?

  6. DO something about the alert.


1.  Set the rule to drop.


This only works if you are in IPS mode, should you change the rule to drop?  Do you want the traffic to go into the big bit bucket in the sky?  Prevent that FLV file from being downloaded?  Prevent that PDF from being downloaded, prevent that newest browser exploit?  If you are in IPS mode, this is your second question after you analyze the event.

2. Threshold or Suppress?


Thresholding in Snort essentially means you still want the rule to alert, but not as much.  Or not until a certain threshold is reached (or both).  Suppressing means you want to turn off alerting to a certain IP or CIDR block.  Say for instance an SNMP alert going to your HP OpenView server.  Legit traffic, so tune it out.

3. Edit the rule.


Probably something you want to stay away from as much as possible, unless you editing your own rules.  But it's always an option to edit the rule manually to reduce false positives.

4. Turn the rule off.


Is the rule out of date?  Do none of the above apply?  Has it no relevance to your network?  For instance, using our above example, if watching flash videos is allowed on the network, and you don't want to track to see if people are doing that kind of thing, then shut the rule off.  If you aren't going to use the final step in this process (DO SOMETHING) then do you need the rule?

5.  Is the rule providing you contextually aware information?


Some rules will make no sense on their own, but they may provide a contextual awareness to other rules.  For instance, if there was a rule to watch for vulnerabilities within a certain flash video file format to exploit older versions of the flash player, that rule coupled with the above example, may provide better contextually aware alerts.  You know the video was bad, but now you can refer back to the above example and perhaps see where the alert came from.  Kind of a bad example, because you could do it either way, but hopefully you grasp my point.

6. DO SOMETHING.


This requires you to go mitigate the problem.  Whether that be to "file a ticket" for your helpdesk to clean off spyware, clean up a botnet, perhaps you'll need to pull forensics on the host machine, perhaps you'll need to pull web proxy logs to get better awareness.  But this is the step where you actually have to use the alerts generated by your IDS to do your job.  Find the bad guy, eradicate the badness from the network, and move onto the next alert.  After all, that's the point of having an IDS or IPS right?

Following these simple steps should allow you to have a greater awareness of the alerts on the network, and perhaps actually do something about them.  Getting an IDS alert and then "moving it to archive" or "marking it as reviewed" is doing nothing.  Following the above ACTION steps should give you a more streamlined IDS or IPS, and then only cause your system to alerts when you need to conduct step 6, above.  DO SOMETHING.

Monday, August 2

New Digg Interface Invites

I have a couple posts brewing in my head that I need to get down on paper, but in the meantime, I have 5 invites for the new Digg.com interface if anyone wants them.

First five people to send me their email address get them.

Wednesday, July 28

Contrary to Recent Assertions - Snort 2.9 beta has been released, and it's awesome..

Snort 2.9 has been in the works now internally for awhile and the first beta release is out and ready for community feedback.


It's a big release with lots of enhancements, so here are the current list of things that need to be beta tested in Snort 2.9, and I'll expand upon them a bit:
* Feature rich IPS mode including improvements to Stream for inline deployments. A common active response API is used for all packet responses, including those from Stream, Respond, or React. A new response module, respond3, supports the syntax of both resp & resp2, including strafing for passive deployments. When Snort is deployed inline, a new preprocessor has been added to handle packet normalization to allow Snort to interpret a packet the same way as the receiving host.

This feature really does away with a lot of the old react/resp/reset code and unifies all that broken code under respond3.  It also allows for RST and ICMP injection into a stream in IPS mode (more reliable than IDS), so, for example, you want to cut a session off in midstream.  In regular IPS mode, we can drop the connection quietly.  With the new response module we can properly inject a RST (or other close) packet into a dropped stream, resetting the connection so that the end hosts don't have open TCP sockets.  There is also a normalization preprocessor,  (See README.normalize), which, essentially, cleans packets up.  For example here a just a few things that the normalization preprocessor can do to TCP:


  • Remove data on SYN.

  • Clear the reserved bits in the TCP header.

  • Clear the urgent pointer if the urgent flag is not set.

  • Clear the urgent pointer and the urgent flag if there is no payload.

  • Set the urgent pointer to the payload length if it is greater than the payload length.

  • Clear the urgent flag if the urgent pointer is not set.

  • [..]

Flexresp (Flex Response) 1 and 2 are now deprecated and a new Flexresp3 has been introduced.  Flexresp3 supports ALL of the flexresp1 and flexresp2 keywords and syntax.  Easy to move right over.


* Use of a Data Acquisition API (DAQ) that supports many different
packet access methods including libpcap, netfilterq, IPFW, and
afpacket. For libpcap, version 1.0 or higher is now required.
The DAQ library can be updated independently from Snort and is
a separate module that Snort links. See README.daq for details
on using Snort and the new DAQ.

Hooray!  Libpcap 1.0 is now required.  Hooray Libdnet!  As you can read above, Snort 2.9 adds support for nfq and afpacket.  In addition to ipfw, ipq, and dump that they've read already.  IPQ wasn't working as well in past releases, so we replaced it with netfilterq.
* Updates to HTTP Inspect to extract and log IP addresses from
X-Forward-For and True-Client-IP header fields when Snort generates
events on HTTP traffic.

This was a feature requested by one of our community people.  They didn't want to see the IPs of their proxies as Source or Destination IPs in HTTP alerts.  They wanted the ability to see the "real" IPs for those proxies that support "X-Forward-For" and "True-Client-IP" header fields in their packets.  This output is only available if you are using the Unified2 output method.

Those of you that are NOT using Unified2 really, really need to move to it.  Older, slower, output methods are eventually going to be deprecated, so please, start your upgrades.
* A new rule option 'byte_extract' that allows extracted values to
be used in subsequent rule options for isdataat, byte_test,
byte_jump, and content distance/within/depth/offset.

This was a feature requested by the community as well, it came from an email I received as a request that we add something like this in Snort.  The ability to yank a value out of a packet and store it for later use with other keywords.  (Unlike byte_test or byte_jump that calculates the value on the fly.)
* Updates to SMTP preprocessor to support MIME attachment decoding
across multiple packets.

I think that one speaks for itself, but make sure you read README.SMTP in the doc/ directory of the tarball to make sure you fully understand what this does.
* Ability to "test" drop rules using Inline Test Mode. Snort will
indicate a packet would have been dropped in the unified2 and console event log if policy mode was set to inline.

This was a feature, also requested by our community.  They wanted to know, for a fact, what traffic would have been dropped had the rule in question be set to drop.  Again, this output is only available in Unifed2 and console, so please start moving over!
* Two new rule options to support base64 decoding of certain pieces
of data and inspection of the base64 data via subsequent rule
options.

Nice feature here.  Base64 decoding in a rule.
* Updates to the Snort packet decoders for IPv6 for improvements to
anomaly detection.

Also added into README.normalize.  This is to continue to support the United States Government's push to IPv6.  In many environments, this is now mandatory.
* Added a new pattern matcher that supports Intel's Quick Assist
Technology for improved performance on supported hardware
platforms. Visit http://www.intel.com to find out more about
Intel Quick Assist. The following document describes Snort's
integration with the Quick Assist Technology
http://download.intel.com/embedded/applications/networksecurity/324029.pdf

This optimization is very hardware specific.  Make sure you read the PDF linked above which is a joint research project underway by Sourcefire and Intel.

I'm sure more tweaks and things will be added to 2.9 before it's actual release, so I look forward to these enhancements.

Be sure and check out Snort 2.9's beta code here, at http://www.snort.org/

Project Razorback has been unleashed on the World

For several months, the Vulnerability Research Team (VRT) here at Sourcefire has been heads down in coming up with a new framework for detection called Razorback, and now, it's been unveiled to the world this this morning.

Being announced at Defcon this weekend by the VRT, so if you are in Defcon this week, reading my posts, First: Have a beer for me, as I am not there this year due to the impending birth of my child, and Second: Attend this talk.  If no other talks are attended during your drunken hacking binge in Vegas, go to this talk.

OH AND BUY THE VRT BEER IF YOU MEET THEM.  Mkay?

What is Razorback?


In Marketing speak: "Razorback is an Open-Source Framework for an intelligence driven security solution."  Okay, okay, what does that mean?

Razorback is a system that detects and decodes, well, just about anything you need it to.  Following that, it has the ability to then block and alert on that activity.  So, for example:

  • Obfuscated Javascript?  Decoded, Blocked?

  • Bad PDFs? Decoded, Blocked?

  • Bad Word Documents? Powerpoint Documents? Decoded, Blocked?


This framework is aimed primarily at these Client based attacks, and, dare I use it?  Advanced Persistent Threat (APT).  It was born out of necessity and a discussion with the VRT during a panel they participated in last year about detection.  The community asked for something to be able to perform a function like this, and well, here it is.  Better.  There is nothing to combat these threats, so Sourcefire created one.

So, say for example, a PDF comes in via email.  The PDF is sent to Razorback by the SMTP engine, Razorback runs it through the detection, -- which I'm not even going to begin to explain here, because it's extremely awesome and complicated, and you should go to the talk to fully understand --, and if the detection decides the PDF is bad, it will record that fact in it's database so that all further attempts with a PDF like that one will be blocked from there on out.   Now, that's just one example.

Since Razorback is an Open-Source project and framework, anyone can write a detection "nugget" for it.  These nuggets, written in C, can detect pretty much anything and provide actionable intelligence on it afterwards, and of course, since it's Open-Source, many different "feeds" can be provided to Razorback.

SMTP, ClamAV, Snort, Web proxies, Web filtering devices, et all.  They can all be written to feed data to Razorback which then can have the ability to take further action after it's analyzation.

This is a different approach to detection than what's been tried before.  While IPS is great, it can't really grab a PDF off the wire, reassemble it, decode it, and block it in real-time.  With Razorback, Snort can grab the PDF off the wire, pass it to Razorback where it will be analyzed, and so on.

After the talk if the VRT puts their slides and more info up on their website, I'll make sure that I post further information about it.  But for now, here it is:

Razorback.

Here's another article about Razorback over at DarkReading.

Safari 5.0.1 Posted this morning

Back in June I wrote a post on a problem with Safari 5 creating a black background around certain objects when moved from one application to another.  For instance, when you attempt to use the "Mail this PDF" function from Preview.  Well, this morning Apple released version 5.0.1 of Safari.  This fixes the issue I described here, along with many others.  As posted on Apple's website here, the following are fixes:

  • More accurate Top Hit results in the Address Field

  • More accurate timing for CSS animations

  • Better stability when using the Safari Reader keyboard shortcut

  • Better stability when scrolling through MobileMe Mail

  • Fixes display of multipage articles from www.rollingstone.com in Safari Reader

  • Fixes an issue that prevented Google Wave and other websites using JavaScript encryption libraries from working correctly on 32-bit systems

  • Fixes an issue that prevented Safari from launching on Leopard systems with network home directories

  • Fixes an issue that could cause borders on YouTube thumbnails to disappear when hovering over the thumbnail image

  • Fixes an issue that could cause Flash content to overlap with other content on www.facebook.com, www.crateandbarrel.com, and other sites when using Flash 10.1

  • Fixes an issue that prevented boarding passes from www.aa.com from printing correctly

  • Fixes an issue that could cause DNS prefetching requests to overburden certain routers

  • Fixes an issue that could cause VoiceOver to misidentify elements of webpages


Safari 5.0.1 also packs in a bunch of security updates.  Of course Blackhat and Defcon are this week, so that may have something to do with this update being released.

Safari
Impact: Accessing a maliciously crafted RSS feed may cause files from the user's system to be sent to a remote server
Description: A cross-site scripting issue exists in Safari's handling of RSS feeds. Accessing a maliciously crafted RSS feed may cause files from the user's system to be sent to a remote server. This issue is addressed through improved handling of RSS feeds.
Credit to Billy Rios of the Google Security Team for reporting this
issue.


Safari
Impact: Safari's AutoFill feature may disclose information to websites without user interaction
Description: Safari's AutoFill feature can automatically fill out web forms using designated information in your Mac OS X Address Book, Outlook, or Windows Address Book. By design, user action is required for AutoFill to operate within a web form. An implementation issue exists that allows a maliciously crafted website to trigger AutoFill without user interaction. This can result in the disclosure of information contained within the user's Address Book Card. To trigger the issue, the following two situations are required. First, in Safari : Preferences : AutoFill, the "Autofill web forms using info from my Address Book card" checkbox must be checked. Second, the user's Address Book must have a Card designated as "My Card". Only the information in that specific card is accessed via AutoFill. This issue is addressed by prohibiting AutoFill from using information without user action. Devices running iOS are not affected.
Credit to Jeremiah Grossman of WhiteHat Security for reporting this issue.
(Nice work Jeremiah!)

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue exists in WebKit's handling of element focus. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of element focus.
Credit to Tony Chang of Google, Inc. for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's rendering of inline elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved bounds checking.
Credit to wushi of team509 for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's handling of dynamic modifications to text nodes. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved memory management.
Credit? Apple Internal?

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's handling of CSS counters. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
This issue is addressed through improved memory management.
Credit to wushi of team509, working with TippingPoint's Zero Day Initiative for
reporting this issue.


WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: An uninitialized memory access issue exists in WebKit's handling of the :first-letter and :first-line pseudo-elements in SVG text elements. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed by not rendering :first-letter or :first-line pseudo-elements in SVG text elements.
Credit to wushi of team509, working with TippingPoint's Zero Day Initiative for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue exists in WebKit's handling of foreignObject elements in SVG documents. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through additional validation of SVG documents.
Credit to wushi of team509, working with TippingPoint's Zero Day Initiative for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's handling of floating elements in SVG documents. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved memory management.
Credit? Apple Internal?

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's handling of 'use' elements in SVG documents. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of 'use' elements in SVG documents. Credit to Justin Schuh of Google, Inc. for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A heap buffer overflow exists in WebKit's handling of JavaScript string objects. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved bounds checking.
Credit: Apple.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A reentrancy issue exists in WebKit's handling of just- in-time compiled JavaScript stubs. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved synchronization.
Credit? Apple Internal?

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A signedness issue exists in WebKit's handling of JavaScript arrays. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of JavaScript array indices.
Credit to Natalie Silvanovich for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A memory corruption issue exists in WebKit's handling of regular expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of regular expressions.
Credit to Peter Varga of University of Szeged for reporting this issue.

WebKit
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: A use after free issue exists in WebKit's handling of "font-face" and "use" elements in SVG documents. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue is addressed through improved handling of "font-face" and "use" elements in SVG documents.
Credit to Aki Helin of OUSPG for reporting this issue.

Safari 5.0.1 and Safari 4.1.1 address the same set of security issues. Safari 5.0.1 is provided for Mac OS X v10.5, Mac OS X v10.6, and Windows systems. Safari 4.1.1 is provided for Mac OS X v10.4 systems

The thing to remember with the above vulnerabilities is that things that are labeled "Webkit", affect more than just Safari. They could possibly affect anything using the Webkit framework. Chrome included.

Tuesday, July 27

Apple's New Products

Apple announced a few new products this morning on their online Store.  New iMac, new Mac Pro, and a totally new product that I saw rumored a couple weeks ago, called the Magic Trackpad.

For years I've had a Fingerworks iGesture pad, I've been using it off and on since about the 2001 timeframe.  I found it to be the neatest and easiest way to navigate my computer's interface differently from the mouse ever.  I'm a big proponent of the keyboard, and hate taking my hand off of the keyboard to mouse, but for some reason I found the iGesture Pad fun to use (especially doing things like cut, copy, and paste.   Fingerworks was founded 1998 at the University of Delaware (a couple miles from where I live) and produced keyboards, pads, keypads, all to help with RSI and to introduce gesture based navigation into the world.  They weren't exclusively Mac based, in fact, they worked on Linux pretty well as well, of course, on Windows.  Which, back then, is what I used.

Apple bought Fingerworks back in 2005, coincidentally, when they started working on the iPad (before they started working on the iPhone.  They started working on the touch tablet first).  Presumably for their patents, and innovations in the technology.  If you've used an Apple product since about 2006 or 2007, you've used Fingerworks-based technology.

Two finger scrolling, three finger swipe, pinch to zoom and pinch to un-zoom, the whole Magic Mouse, the finger manipulation on the iPhone and iPad.

In this line, comes the Magic Trackpad.  Which is kinda like my old iGesture Pad (which is sitting right here -- not in use currently).  It's a trackpad that mimics the trackpad on the laptops.

There are, however, a couple things still missing.  Like these features:

However, since that's basically all software based, I am hoping that Apple builds that stuff into the interface now that we have the hardware.  Here's hoping.

Monday, July 26

Apple Stores are good to me

Yesterday my wife and I took a visit to the local Apple Store, my Time Capsule had died, and since it was one of the original models, it was under a replacement program. I took the Time Capsule back, they traded my broken one for a brand new one, and I was done.

My wife, however, was a different story. You may remember from a previous post of mine that my wife dropped her iPhone4 while getting my daughter out of the car. Whoops.  Cracked the back glass to shreds.

She was fairly upset, since she had it about a week. Anyway, she went in, explained what she did to the Apple Genius dudes, and guess what?

They gave her a brand new phone.

/That's/ why I like Apple Stores.

Thanks to the Christiana Mall Apple Store Geniuses. You rule.

Thursday, July 22

Reading Spam with Common Sense

Usually when I receive an email that looks like spam, I can just mash my "Send to Junk" keyboard shortcut and it goes away.  But every once in awhile there is a decent looking spam that *might* be real.  At first glance it won't have an images or selling viagra, or anything like that in it, and might just look real.

This is where the common sense approach to reading email kicks in.  Obviously this post it not for the expert, this is probably more of the occasional user, but maybe someone in between will find it useful.

Here's a spam I received this morning that prompted me to write this diary:

From: Comcast

"This is a courtesy reminder that your Comcast Billing Information needs to be verified.

In order to continue using comcast services,  click the link below, sign in and and follow the provided steps:


<Malicious Link was right here>

Regards,
Comcast Billing Department"


So, let's look at this and see how easy this is to detect:

  1. I'm not a Comcast customer.  So right there, it was easy to detect.

  2. "comcast" in the second line is not capitalized.  A real Comcast email would have capitalized their own companies name.

  3. Usually an email like this (from Comcast corporate) would tend to have all kinds of disclaimers and other nonsense at the bottom of the email.

  4. The link that I removed was not to "comcast.com"


Now, if we get into the weeds a bit more, we can look at the headers and see where it came from.

It came from a server at a .edu.  I don't want to talk about which .edu (but it was in the United States), as I am going to try and get in touch with their security department after I get done writing this Diary.

Even more bad though -- it came from the "root" account on this server, the headers even indicate what version of Linux this server was running (Ubuntu).  Most likely culprit?  Probably an SSH scan that compromised the root account.

Make sure you have tight controls over those SSH accounts!  And use common sense when reading your email.  If it looks like bull, and it smells like bull.  Chances are, it's bull.

Hopefully this helped someone.

Oh, the malicious link?  Pointed you to a site that collected your usernames and passwords.

Monday, July 19

iPhone 4. A review after practical use, part 2

Part 1 Linked here.


Buttons and other Cosmetics


The volume button, the lock button, and the silent/ringer switch all got the same industrial treatment the rest of the phone did. They work much better, have better tactile feedback and are much more defined, making it much easier to find one of these buttons in the depths of your pocket.  (Like to turn the volume down on your ringer or something)

There is the single button on the front of the phone, the Home button, which they made a bit more "clicky" I would say. But the one thing about the design of the phone is, when you reach in your pocket to grab the phone and bring it out of your pocket in one swift motion while mashing the Home button, you can't do it.

Since the 3GS had that rounded back, it was easy to feel where the backside was and hit the button. With the square design, it's hard to tell which side is the front and back when it's your pocket unless you try and find the buttons on the side.

This isn't a big deal at all. It's just a quirk that I found that I had that I've had to get used to.

FaceTime


FaceTime is Apple's new "video chat" feature. You use two iPhone 4s, call each other on the phone, and as long as both of you are on Wifi, you can then mash the FaceTime button.  If everything is okay, (NAT transversal, etc) you'll shortly be talking to each other via video chat. Is it cool? Yes.

Does it work? Yes.
Have I used it? A lot.

Is it revolutionary? No, video chat has been done before. But this time it's implemented correctly and easily. It works. You don't have to go to Fring and sign up with an account, and then use Video (btw, Fring's video quality sucks, and their audio is a close second).  You don't have to do anything extra.  Ensure you are on Wifi, and hit the "Facetime" button. The quality is good, audio quality is good.  It allows me to sit in my hotel and video chat with my wife and daughter while they are at home.  My daughter can show me her picture that she drew that day, she can show me what she's eating for dinner, she can show me her "beautiful dress" that she's wearing.  (All dresses, according to my daughter, are "beautiful dresses".)

Could we have done this before?  Yes, and still do, with iChat.  But there's two things about that.  First, iChat requires more bandwidth, therefore hotel internet most of the time, can't handle it, and secondly, my wife doesn't always have her laptop.  She most always has her phone.  And since my wife is 8 months pregnant, I'm not about to make her get up to get her laptop.   I have better sense than that.

I think this is a great feature, it'll be neat if my parents get an iPhone 4 so they can enjoy it as well.  Especially when it comes to seeing my new baby.

Speed


This thing is quick.  If you bought the 3GS, upgraded from the 3G, or you have the 3G, or if you have the iPhone original.  The new iPhone 4 is dramatically faster than the 3G or the iPhone original, the 3GS, yes, it's faster than that, but you'd have do some some really processor intensive stuff to notice a huge difference (like compressing video).  So, if you have a 3GS and want to upgrade to the iPhone 4, you need to use one of the other of the 100 new features of the iPhone 4 as your excuse to upgrade.  However, if you have a 3G or the original iPhone, you will be blown away by the speed.

Think about this in perspective for a second, the A4's rumored speed is 1 Ghz (after a cursory search of the internet, it's the best metric I could find).  Now the A4 is the same chip that is in the iPad and the iPhone.  The iPhone A4 is rumored to be clocked down, to preserve battery life.

The amount of RAM on the iPhone 4 is 512 MB (as evidenced by a particular slide  at  WWDC, Apple doesn't announce the RAM amounts or the clock speed in their mobile devices).  I remember, in 2003, my last computer before I bought an Apple computer, was a 1.7 Ghz chip with 512 bytes of RAM.  Seven years later, I have a phone in my pocket that is almost as fast, has the same amount of RAM, and as 32 Gb of storage on it.  Really puts things in perspective, how things are advancing.  I feel it's impressive.  (Of course, back then, I had a 1.5 Mb/s Cable connection to the Internet and I thought that was fast.  Now I have a 25 Mb/s Fiber connection.)

Camera


On the back is a 5 Megapixel camera, on the front is a significantly lower megapixel camera.  The front camera is primarily for taking pictures of yourself, if you are that vain, and also for Facetime. Which serves it's purpose quite well.  The back camera, with the LED flash, is for taking good pictures.  The iPhone does take good pictures.  Not GREAT pictures, not like Cannon 5D Mark II pictures, but it will easily replace that point and shoot my wife carries in her purse.  Anything where I can carry  less devices is a win for me.

Problems with the camera.  The Flash is okay.  If you try to take a picture, in the dark, and if the subject is close, it'll work great.  As long as the person you are taking a picture of doesn't actually look at the flash.  I don't know why, but every picture I have taken of people with the flash at night has a weird "red-eye" effect, except it's not red.  It's white.  Making my photo subjects a bit creepy.

In low light, and if there is any kind of motion, the iPhone will blur the motion in the picture.  Most cameras do this, so I can't fault the actual iPhone.

However, if you are taking pictures during the day, morning, or evening.  Indoors or outdoors, sunny or overcast, the pictures are great.  It replaces point and shoots.

The other feature of the iPhone is the ability to record 720p HD video.  I've done this several times already, recording video of my daughter jumping off the diving board for the first time and things like that.  The iPhone 4 handles it just fine.  The video looks great on playback on the Retina Display or even after you offload it to your iPhoto and play it on the Desktop.

Overall


I have some opinions, and this is the place to share them I guess, since it's my blog.  Overall, I like the iPhone, but I always have.  The iPhone 4 is much better than it's predecessor.  I'm still not too crazy about the Antenna reception "Don't touch this 2mm of the outside of the phone" thing, but I can overlook it by not touching it there, and getting a case.  Do I think it's a bad design?  No.  I understand why they did it, and it can be overcome easily, but it kinda sucks.

I'm not crazy about the glass on both sides, but according to the things I've read, I understand why it was done.  Apparently, they did away with the plastic back because plastic retains more heat than glass, and the iPhone 4 can heat up when doing really processor intensive things like compressing video.  It's slippery and obviously, as tested by my wife, it breaks.  Apple charges waaay to much to fix this issue, and I think that's BS.

  • Do I think it's a good phone?  Yes.

  • Do I think it's a good computer? Yes.

  • Do I recommend it to friends?  Yes, if you buy a case with it, or at least have the cognitive ability to not touch that portion of the phone.


Overall?  Good.  Buy it.  It rocks.

Saturday, July 17

iPhone 4. A review after actual use.

Physical Design


Okay, much has been said about the physical design of this phone, it's industrial features, it's glass front and back, stainless steel metal band around the side that doubles as an antenna, dual camera, and an led flash. The buttons, the glass, the band, everything. It makes for a great design, feels smaller and better in your hand than the 3GS. In fact, the 3GS feels fat, plastic, and bloated. I only see two problems with the design.

One, front and back are both glass, meaning, if you drop it it might break. Even though Apple claims that the glass is harder than sapphire, if you drop the thing at the right angle, it will break. Ask my wife, who has already shattered the back of her phone after dropping it on the driveway. (Which Apple wants 199 dollars to replace the back, which is the cost of a new phone! Apple, have you lost your mind?).

Problem Two: it's slippery. If you place your phone on something smooth, say, like in my car, I have a center console. If I place the phone on there, it slips right off. Or on the arm rest of an easy chair. This is as a result of it being glass. Neither is that big of a deal, if you just are careful about how you take care of the phone. If you buy a bumper (which Apple is now giving away for free until September 30th) it has a bit of rubber on the back edge, making it non-slip, and a bit more protected.

The Display


Just after the iPad comes out, and those of us who bought one were running around saying "Wow, look at this really big touch screen display", then following that the Evo comes out with that big screen and people say "Wow, look at this really big touch screen display". For instance, I have a friend of mine that went from an iPhone (o.g.) to an Evo, and he was like "This screen is huge, it's so big!", but I digress.

Apple comes out with this display on the iPhone 4, it's has 4x the pixel display density of the iPhone 3GS. This results in much sharper rendering of, well, damn near, anything. Photos look great, video looks great, games look great, apps look great, but what's the one thing you do, or view on an iPhone the most?

Text.

Oh, it rocks. If you have an iPhone (not)4, do this, and you'll understand:

Go to http://nytimes.com. Don't zoom in after it loads. Big newspaper website right? Look at the text, see how it's barely readable and all pixelated? On the iPhone 4, you can read it. READ it. Right from this screen. You can zoom in on the (not)4, and you'll be able to read it just fine, which you'd probably want to do on the iPhone 4 as well, but that's just an illustration of how much better this display is.

After you see and use the "Retina" Display, and go back to another phone (even the iPad, or a regular computer) you'll wonder how you ever complimented that old screen and how bothersome it is to have all that fuzzy text.

There has been some dispute about the fact that Apple calls this the "Retina Display". As to whether or not the pixel density is actually higher than what the Retina can perceive. First off, two things.

  1. I am not an optical engineer, and don't play one on TV, so I'm not going to get into the argument by adding my own thoughts here. All I know is that it looks great.

  2. It's a marketing term people, there is a line to how pedantic you must be people.


In short, the display is quite awesome.

The Antenna


Now, the antenna has been in constant controversy since the iPhone 4 came out. Let me cover a few parts of it.

  1. The Antenna is broken into two parts, if you are looking at the left hand side of the phone, you will see a black band. The piece of metal that is around the outside of the phone on the left hand side is for Wifi, Bluetooth, and GPS. The rest of the metal is for Edge and 3G.

  2. It's on the outside of the phone, for better reception.

  3. If you touch it, right at that black band on the left hand side, the "bars" or signal on the phone degrade into almost nothing, and if you are in a weak signal area, your call will just drop.


Not really an optimum design for an antenna you might think. One that you can touch in 2mm of the phone and the call drops? Yup. I can replicate it, I can do it, at will. You know what else I can do?

Not put my pinky over that part of the phone.

Or if worst comes to worst, get a case.  I got a bumper for my phone which covers the antenna and the phone works perfectly.

Now, some people have said that Apple should have never released a phone like this. Well that may be a good point, but I don't know if that would have helped. The antenna is on the outside of the phone, okay? Any phone you grip around the antenna is going to attenuate the signal. It's just the way it is. Apple says this, and you can replicate it on any of the prior iPhones as well as a bunch of the iPhone's competitors.

Remember when we were kids and you grabbed the rabbit antennas on your TV? Remember how the signal would get worse when you did that, even some times when you just got close to the TV? Same principle.

The phone is a radio. Sorry. It has to retrieve and transmit, and they have to put the antenna somewhere. Apple put the antenna on the outside of the phone to try and reduce the dropped calls everyone on AT&T was complaining about.

I personally have much less dropped calls than I used to (despite what Apple said about the iPhone 4 dropping more calls), and I'm not complaining about it one bit. Yes, I can hold the phone in a certain way to attenuate the signal and make the bars go down, so I just don't hold it like that.  It de-tunes the antenna, and therefore make signal reception go down.

Since this post is running right around 1000 words right now, I'll cut it into two posts...  stay tuned for part two.

Friday, July 16

MobileMe's New Look

I use MobileMe, no big surprise there, I have multiple Macs, iPhone, and the iPad.  MobileMe keeps them all in sync, and I have no problems with it.  However recently, Apple's been working on their web application portion of MobileMe with a new look and feel to the frontpage, the login, the "Find my iPhone", Mail revamp, and most recently the beta for the Calendar.

Mail


Let me talk about the Mail at MobileMe first.  This just came out of beta, (on the web) and the features they added are very nice.  First off, I think the attempt is to make it look like the iPad app for Mail.  It has three columns, the Mailboxes, the Inbox, and the message pane on the right.  Kinda like the newer versions of Outlook, or maybe even Mail.app (if you have the three column view turned on).


At the top there there are buttons, from left to right, they have the "Cloud" Icon (which is basically the Application switcher, allowing you to go back and forth between Calendar and Contacts, etc), the Search pane, Trash, Archive, "Move to Folder" Reply (and reply to all, and forward) and "New".  Over on the right you have the "gear" icon which is your "Preferences", and then your account manager (under your name over there).


Mostly everything works the same as the older MobileMe web app, or the same as you'd expect from any web-based Email GUI.  One thing that they did add was "Server-side" email filtering.  Now, it's still pretty limited as to the functionality, and I don't know if there are plans to expand this functionality, however, for me, it gets the job done.



I still like the ability in procmail to use Regular Expressions to filter my email, but this works as well and it works great.


MobileMe features "Push Email" to all your Apple devices, and what's nice about the server-side rule filtering is that emails that are filtered on the server are not pushed to your mobile device.  Why do I like this?  Because after I found this out, I switched all my listservers over to MobileMe and off of Gmail.  I actually don't even use my Gmail account anymore.  MobileMe, is a traditional IMAP server (no "labels are actually folders" or whateverness of Gmail.  (Oh and that stupid "All Mail" folder.  I hate that thing)  It works.  It works well, and it's fast.  Gmail bandwidth throttles their connections via IMAP and POP, leading to much irritation.  I use MobileMe because, once you get past my server side filters, (which are quite extensive), you get pushed to my Mobile device.


Could I do this with Gmail?  Yes. Gmail does feature server-side filtering.  Gmail does push email to the iPhone with the "Exchange" connector.  However, not only for the above reasons, but for one stupidly simple reason in addition:  When you reply to an email on Gmail, you don't get the reply icon in your Mail client.  So, basically, you don't know which emails you've replied to, or not replied to until you log into Gmail on the web.  Maybe this is the way they get you to log in and see their ads, but either way, it's stupid.  So yes, I use MobileMe for all my email, aside from work.


So, what's new recently?



Calendar


The Calendar just entered a new phase of beta.  When MobileMe has something in beta, when you log into the web interface it will ask you "Do you want to try out the beta?"  You click "Okay", and a couple of weeks later they make you eligible for the beta.  I requested my invitation last week, and got it yesterday.


After I logged in, it asked me "Do you want to upgrade your calendars?"  I clicked "Ok".  This whole process took about 10 minutes.  Upgrading my calendars and everything.


It not only changed the calendars on MobileMe (which, now look just like the iPad), with the ripped edges and what not.



But they also change your iCal calendars and your calendars on your iPhone into "Caldav".  What does this mean for you?


Finally, (why did this take so long Apple?  Nice job, but seriously?) you can send invites to other people on your Calendar on your iPhone.  You can accept invites as well, just like the iPhone does with Exchange, if you receive a calendar invitation, you can accept or Deny it right on the iPhone or iPad with MobileMe.  (This feature requires iOS 4, unless you manually add Caldav into your iPhone as a calendar)


You can share your calendar (see in the above screenshot where the "Home" Calendar has a Green button next to it?  Indicating that it's shared?  You can share it with individuals or the world.  (It used to be "The World".)  You can see the "Free-Busy" schedule for anyone on MobileMe (that's in the beta, but after it comes out of beta, it'll be normal.)


All in all, it looks great, and it works great.  I've only found one bug (I'm in the beta, I'm supposed to report this stuff right?) it's an html5 rendering problem with Chrome (works fine in Safari -- surprise!).  You even have a nice "To-Do" bar on the right.  Now, only if we could get a "To-Do" feature on the iPhone, I could do away with these wonky third party apps to manage that stuff.

Thursday, July 15

Microsoft opens source code to Russian secret service

Microsoft opens source code to Russian secret service | Security | ZDNet UK.

The above is a link to ZDNet on the fact that Microsoft has signed a deal with the Russian Federal Security Service (FSB) access to Windows Server 2008 R2, Office 2010, SQL Server, and Windows 7.

The thing to remember about this deal is, this is nothing new...  from the article:

"The agreement is an extension to a deal Microsoft struck with the Russian government in 2002 to share source code for Windows XP, Windows 2000 and Windows Server 2000, said Vedomosti."

I'm not even sure that the United States Government has access to Microsoft's Source Code, although it stands to reason... If the Russians have it, the US has it too.

Tuesday, July 13

Plug-Ins I use for Mail.app

Attention Mac Users that use Mail.app, this one is for you.

Mail.app has a bunch of plugins that are available to it, not like Thunderbird, where Mozilla holds a repository of Plugins, Apple doesn't do that. But there are a ton of them available on the Internet and it would be great if Apple would do something like that (like they are about to do with html5 extensions for Safari). Mail calls these plugins "Bundles" and are found in the ~/Library/Mail/Bundles directory. I just wanted to write a post about a few of the Bundles that I use with Mail.app to make my email a lot easier to use.

1. Mail Act-On


Mail Act-On, written by indev software, the same people who provide MiniMail and Mail Tags (two other great bundles that I don't use), is an Email organization tool. Basically it allows you to tie Mail.app rules to keystrokes. So for example, one of the Keystrokes that I use is "`1" (Backtick, 1). The rule I have tied to that command is to move whatever the current email I have highlighted to a certain folder. What I do is have most of the email that I deal with from listservers go directly to folders (on the server), and then the Mails from certain webservers and other "To Me" email goes to my Inbox. Since I use the Inbox Zero method of filtering email, I can read an email, and if I want to file it away, I use the keystroke to move it to my Archive folder. Simple, done. I can color emails certain colors, I can move emails around, etc. It's nice, and I suggest it's use.

2. Widemail


Widemail is a bundle that displays your email in the three column format. Similar to how the newer versions of Outlook and Entourage display your email, I find this method of email is easier to read (from left to right) as opposed to the old Outlook method of from the "Top Down". It also allows you to color code rows two different colors so it's easy to spot where your cursor is at.

3. QuoteFix


Quotefixformac is like Outlook Quotefix. It reformats emails for bottom posting, cleans up the cruft, removes the signature from the original message, cleans up unnecessary lines, and even prune replies above a certain indentation. It's a nice tool and I use it to format emails the way I like them as well.

So, just three plugins I use for Mail.app, check them out, give them a shot, support the developers that made them.

Mailing lists do not get Anti-Spam

Note: If you are subscribed to a Mailing List, and you have one of those "Auto-answer-back-auto-emailing-verify-that-you-are-a-human-by-clicking-on-this-link-really annoying-things". You are doing it wrong.

Get a frickin Gmail account people.

Saturday, July 10

Plugins I use for mail.app

Attention Mac Users that use Mail.app, this one is for you.

Mail.app has a bunch of plugins that are available to it, not like Thunderbird, where Mozilla holds a repository of Plugins, Apple doesn't do that. But there are a ton of them available on the Internet and it would be great if Apple would do something like that (like they are about to do with html5 extensions for Safari). Mail calls these plugins "Bundles" and are found in the ~/Library/Mail/Bundles directory. I just wanted to write a post about a few of the Bundles that I use with Mail.app to make my email a lot easier to use.

1. Mail Act-On

Mail Act-On, written by indev software, the same people who provide MiniMail and Mail Tags (two other great bundles that I don't use), is an Email organization tool. Basically it allows you to tie Mail.app rules to keystrokes. So for example, one of the Keystrokes that I use is "`1" (Backtick, 1). The rule I have tied to that command is to move whatever the current email I have highlighted to a certain folder. What I do is have most of the email that I deal with from listservers go directly to folders (on the server), and then the Mails from certain webservers and other "To Me" email goes to my Inbox. Since I use the Inbox Zero method of filtering email, I can read an email, and if I want to file it away, I use the keystroke to move it to my Archive folder. Simple, done. I can color emails certain colors, I can move emails around, etc. It's nice, and I suggest it's use.

2. Widemail

Widemail is a bundle that displays your email in the three column format. Similar to how the newer versions of Outlook and Entourage display your email, I find this method of email is easier to read (from left to right) as opposed to the old Outlook method of from the "Top Down". It also allows you to color code rows two different colors so it's easy to spot where your cursor is at.

3. QuoteFix

Quotefixformac is like Outlook Quotefix. It reformats emails for bottom posting, cleans up the cruft, removes the signature from the original message, cleans up unnecessary lines, and even prune replies above a certain indentation. It's a nice tool and I use it to format emails the way I like them as well.

So, just three plugins I use for Mail.app, check them out, give them a shot, support the developers that made them.



Please leave comments below.

Friday, July 2

Some new pictures of the Mustang

Went up to the shop that is restoring my car today and took a few photos.  For all the photos, go here, but here are some I took today.

[gallery]

Thursday, July 1

PulledPork 0.4.2 501 error when downloading rules

Security - The Global Perspective: PulledPork 0.4.2 501 error when downloading rules.

JJ, buddy, and fellow Sourcefire pimp wrote this blog post about errors that people are getting when trying to run PulledPork and it's not working when downloading rules under the new format when using Ubuntu.

Go read his post.

Friday, June 25

Live CD for Remote Incident Handling

This paper was written by Bert Hayes. Bert Hayes is a security professional at the University of Texas. When Bert originally wrote this paper, he submitted it to me for the SANS Gold process, and I helped push the paper in the right direction, however, while it was an excellent paper and well written, it didn't really meet the criteria we were looking for.

However, I thought "Wow, what a great idea, what a great paper. I am sure a lot of organizations will benefit from this."

Of course Bert nor I can be held liable for any damage you to do a computer while using this, (just to get that disclaimer out of the way), and it's recommended that if you are going to use the contents of the computer you are doing the investigation on for a prosecution, don't use this. (Changing the state of the data on the drive during a forensic investigation is generally frowned upon.)

But, as I said, this is a great paper and you should definitely download it and give it a read.

  • http://security.utexas.edu/consensus/How_To_UTIRD2.pdf


Enjoy

Friday, June 18

The Google Command Line Tool

Enough of the readers of this blog can be classified as "Command Line Nerds", myself included, and this post is aimed at you.

Apparently they don't have enough to do at Google, so they sit around and make tools to collect your wifi data, read your email and give you ads for them, and various other nifty Google ideas.  (Yes, I still love Google.)

But apparently they had enough time to make a tool to interact with Google via the command line.  Using Python you can do a whole mess of things..

  • You can Post to Blogger!


google blogger post --title "Just like this" "This is my blog entry, there are many like it but this one is mine"


  • You can Post to your Google Calendar!


google calendar add "Take out garbage at 7 pm on Tuesday"


  • You can perform various tasks with your Contacts!


google contacts list name,email --name *joel* > joel.csv


  • You can edit some Google docs!


google docs edit --title "Document title here"


  • You can upload photos to Picasa easily!


google picasa create --album "Photos of my car" ~/Pictures/Mustang/*.jpg


  • You can even upload videos to Youtube!


google youtube post --category Entertainment video.mov

They have a package available for debian (ubuntu) and they have a tar.gz bundle as well.  So happy computing, check it out here.

But You Know, this might be nifty for uploading pictures to picasa, or scripting it to upload many things to docs, or youtube.  But you know the one thing you can't do with your google command line?

Search Google.

Apple updates Anti-Malware file

Last year in August I wrote a post called "Snow Leopard is coming..." where I mentioned the XProtect.plist file.  This file protects and defends the OSX system against "downloader" trojans.  Ones that you receive via iChat, or download via Safari, Mail.. basically if you download the trojan to your system.

In the most recent update of Snow Leopard that came out last week (10.6.4), that I didn't cover, it seems Apple has updated the XProtect.plist file to include a new trojan named "HellRTS".

I guess this answers my original question, if they are going to keep it updated, am I am glad they are, however, I'd like to see them update it even more often than that, and of course include more things.  It's better than nothing, I suppose..  but I'd like to see more.

As of right now, there are a whole three trojans protected against in the XProtect file.
  • OSX.RSPlug.A
  • OSX.Iservice
  • OSX.HellRTS

You can find this file in the:

/System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/

directory.

This article by Sophos turned me onto the update, but I reposted without the conspiracy theories:

http://www.sophos.com/blogs/gc/g/2010/06/18/apple-secretly-updates

Find My iPhone App Now Available

Along with rolling out some nice GUI improvements to MobileMe (yes, I use it.  It's simple, it works, and I don't have to mess with it.) last night for Mail, Contacts, Calendars, etc.  Apple also released a "Find my iPhone app" available from the App Store.

In the past, if you lost your iPhone, you couldn't log into MobileMe from your buddy's phone (or iPad) and find your phone.  Now, with this app, you can do that.

Grab the app: here.

Apple - MobileMe - News - Find My iPhone App Now Available.

Thursday, June 17

Black Background in Mail.app

I've noticed that for some reason, after you install Safari 5 on OSX, if you are to do a command where it creates an email out of a file.  For instance:

Open a PDF in Preview and you want to email that to someone else, you go to File, and click "Email this PDF" (or similar)  It'll create a new email message, but the background of the mail message will be black.

I've noticed this in Omnifocus as well, if I use a shortcut key to create a "To-Do" from another application by using the "Clipping" function, the background of the "To-Do" will be black.

Well, at least in Mail there is a fix.

If you want to keep the email HTML, Command -A will select the contents of the email, Cut it (not copy it), (command x), then repaste it with Option-Shift-Command-V  (Paste and Match Style -- this is in the Edit menu).  Or...  You can change the email to Plain Text (which will get rid of the black box), Plain Text is in the Format menu.  Or Command Shift T.

Plain Text is usually better anyway.

Tuesday, June 8

Safari 5.0 and Safari 4.1 patches

About the security content of Safari 5.0 and Safari 4.1.

Apple posted Safari 5.0 for 10.5.8 and 10.6, and Safari 4.1 for 10.4.11 yesterday and above is a link to the full patch list (and it's quite extensive)

The things patched in this update are below:

  • ColorSync (Windows versions only)

  • Phishing

  • Handling of PDF files

  • Arbitrary code execution (Windows only)

  • Webkit (tons of updates here including the infamous wushi exploits from team509, also lots of mentions of Chris Evans and Mark Dowd.  Nice work guys.)


Check the full list at the above URL for complete details.

Safari 5. A smackdown to Google?

Safari 5, released yesterday from Apple, introduced many new things (also patched a bunch of Security vulnerabilities as well, I'll touch on those in a second).  One of the things introduced could be interpreted as a smackdown to Google.

I'll make another list:

1)  Faster Javascript Engine


Safari uses a Javascript Engine named "Nitro".  Apple claims that it runs 30% faster than Safari 4, 3% faster than Chrome, and over 2x as fast as Firefox.  I don't know what the degree for error is in those percentage numbers, but that 3% sounds mighty close to me.

2) DNS Prefetching and improved caching


DNS Prefetching works like this.. when you go to a webpage, or you search for something, Safari uses DNS prefetching to look up all the URL's that are found through hyperlinks on a given webpage. I think Chrome has been doing this for awhile, and I know Firefox has been doing it for years, so it's good to Safari doing this as well.  Every little bit helps when it comes to the web I guess.

3) Bing


Apple added the Bing search engine in addition to Google and Yahoo! that were already in the browser.  I've only used Bing a couple times when it first came out, thought it was inferior and stuck with Google.  However, since it's a choice now in the search bar of the Safari Browser (I switch back and forth between Safari and Google Chrome) I'll give Bing a shot.  We'll see.

4) Safari Extensions


Apple has had extensibility in Safari for a couple versions now, so it seems the only thing that is new about it is that they are pushing it hard now.  Already there are a bunch of extensions coming out, so we'll see how far this goes.

5) Smarter Address Field


Sure.  Not really a big deal, but it does better suggestions using your history than it used to.

6) Location Services


It's been in Chrome for awhile now, so glad to see it's in Safari finally, but the browser can now be aware of your location.  For a good example of how this works, go to http://maps.google.com with either Safari or Chrome, and hit this button (the blue one):



That's the location button, the browser should use CoreLocation and be able to find you.

7) Better Html5 support


Hooray.  But every browser should be doing this.

8) Full-screen view and Closed Captions for html5 video


Good. Also glad when computers can help out in Assistive ways (like Closed Captioning)

9) and Finally, Safari Reader


This is the thing I think is the smackdown to Google.  Reader is kinda like a "cleanup" for webpages.  Kinda like Readability is, I blogged about that awhile back as well.  So, let me give you an example, I'll just browse to TUAW.com right quick:



Ad, Ad, Ad, header, links, annoying, annoying...

Now, in the url bar you'll see a button that says "Reader":



When you hit that button, everything is stripped away from the page, and you only get the article:



Nice.  Very nice.  Then, if you mouse over it, you get these options:



Zoom, (and it remembers how big you want your text too!), Email (just the "Reader"-ized version of the webpage), Print, and close.

Why do I say this screws Google?  How does Google make money?  Ads.

This removes Ads.

iPhone 4

Yesterday Steve Jobs got up on stage and announced the new iPhone, iPhone 4.  It has a list of slick features, I'll write a couple, then an opinion or two about each.

1. FaceTime


Facetime is a new feature to the iPhone family.  It's basically, Video Calling.  Using the front or the back camera of the iPhone you can make a Video call with one another.  Right now FaceTime is limited to Wifi only, and Apple is going to work with the cell carriers to get their networks up to speed to allow FaceTime on 3G calling.

Opinion:  I think is a really neat innovation.  I can see a lot of use for this, however...  I have a feeling that no one will use it, it will be a pain in the ass for it to work, and it'll get bad press.  I am sure there will be ports to open on the firewall for it to work, and it won't work for $REASON.  I guess we'll find out, but overall I think this is really neat and I'd love to use it with my family, especially after my new baby is born.  It's also going to be an "Open Standard", so hopefully lots of people build this into their phones/apps.  iChat probably won't get it until 1o.7, and the iPad won't get a camera until Round 2.

2. Retina Display


The Retina Display is a higher resolution screen 960x640 at 326 dpi.  It seals the front glass to the LCD by lamination (I believe that's how it works) so it eliminates the "Depth" in between the front glass and the icons.

Opinion:  Cool.  Love me some higher resolution.  Not much bad you can say about that.

3. Multitasking


The iPhone 4 has Multitasking through the use of services (instead of full apps running in the background).

Opinion:  Cool.  About time.  I've been really, really content with using one app at a time, EXCEPT when I am using something like Instant Messenger, or where I need to go back and forth really quickly between apps, and the app I need to switch back and forth to doesn't remember where I was at the last time I used the app.  Really annoying.  So glad this is getting fixed.  I've occasionally wanted multitasking on the iPhone, but I've wanted it more on my iPad.

4. HD Video Recording


You can now record HD (720p) video on the iPhone with it's new 5 Megapixel camera, put it into iMovie (a new app for the iPhone) make your own home movies and send them out on the internet.

Opinion:  Good.  I've been very content with the camera that is in my iPhone 3GS, so a better camera is always welcome, however, I know once you record video on the 3GS and try and MMS it to someone, it can be annoying as shit waiting for the upload to take place.  I know uploading a video from the iPhone 4 to Youtube, unless some magic happens, especially on the processor side..  sending a 720p video somewhere is going to be awful and take forever.

5. Mail


Unified inbox, email threading, and multiple Exchange accounts

Opinion:  About time.  I've been just fine the way it has been, however, I'm glad they are making it better.  The unified inbox especially.

6. Folders


The ability to group your apps together in a single button.

Opinion:  Useful.  I'll definitely use it to group things like games and Productivity apps together.  I've tried not to put too many apps on my phone.  But I've met some people that have pages upon pages of apps and this will be good for them.

7. iBooks


The ability to read your iBooks that you've purchased for your iPad up until now, on your iPhone.  Also includes a PDF reader (also coming to the iPad).

Opinion:  Okay.  I think reading a book on that small of a screen will be difficult, but we'll see.  I really like reading on my iPad, but it's big.  I also like the fact that PDFs can now be in a native app.

8. Stainless Steel case design


It doubles as the antenna for the phone and it gives it rigid stability.

Opinion:  Great.  Especially if it reduces the amount of calls I drop.  Looking at you AT&T.

9. Glass front and back


It has black (or white) Glass on the front and back of the phone as faces.

Opinion:  Am I going to scratch the shit out of this thing?  My iPhone glass hasn't scratched yet, so I feel okay I guess.  Whereas the plastic black of my iPhone 3GS is scratch city.

10. Extra Microphone for Noise Cancellation


There is now a Microphone on the top of the phone to listen to ambient noise and cancel it out.

Opinion:  If it's as good as the Jawbone, AWESOME.

Things that are missing still:

  • The ability to open a .ics file (Calendar invite) in Mail and add it to your calendar.  I mean, seriously?  It's not clear if iOS 4 will allow this, but we'll see.

  • Note syncing OTA.  Really?  I still have to plug in my iPhone to my laptop to sync notes?  No thanks, I'll use Evernote.

  • The ability for the "place" in a movie or song to auto-sync back to your actual library, through MobileMe, and down to other devices.  That way when I put down my laptop and pick up my iPad to watch the same movie, it's at the same place.

Screen shot 2010-06-08 at 9.24.56 PM

Screen shot 2010-06-08 at 9.24.37 PM

Screen shot 2010-06-08 at 9.23.44 PM

Screen shot 2010-06-08 at 9.09.26 PM

Screen shot 2010-06-08 at 9.02.57 PM

Monday, June 7

Burnout videos of 2010 All-Ford Nationals at Carlisle, PA

Here are some videos that I shot this past weekend of the Burnout contest in Carlisle, PA.  These are kinda loud, so mind your speakers.

Enjoy:

This lady was 63 years old, she went the whole 3 minutes and smoked the tires!

httpv://www.youtube.com/watch?v=h7udeweXLVg

This was a Starsky and Hutch replica 1975 Gran Torino, complete with sirens, flashing lights, and flashing headlights.  This was a great car:

httpv://www.youtube.com/watch?v=PagdZKlMkW8

This one was great, a piece of the rubber flew up and hit me in the arm (that's why the camera moves suddenly when the tire shreds).  Yes, it was hot.

httpv://www.youtube.com/watch?v=i3UHAfT3_LA

This car was named "Uncle Buck", both of his tires shredded at the same time:

httpv://www.youtube.com/watch?v=PL00p79lN-Q

Single Threaded Data Processing Pipelines and the Intel Architecture

VRT: Single Threaded Data Processing Pipelines and the Intel Architecture.

I wanted to bring this post to the attention of my blog readers as well, just in case my readers are also not subscribers to the VRT blog.

Marty Roesch (Sourcefire's benevolent dictator/CTO) guest-blogged on the VRT blog about Snort, multi-threading, Intel architectures, hyperthreading, and cores.  It's a really great post about why

Multithreading isn't all it's cracked up to be, and is only useful when used correctly.  Just because you "Multithread" everything, doesn't mean it'll run faster.  That's a common misconception that Marty is trying to debunk here, and I encourage a read of his article.  Snort is an extremely well performing piece of software and we get a lot of questions about why we aren't pushing "Snort 3.0" harder (as it has multithreading)

Hopefully this post answers some of that.

Pictures from the 2010 Carlisle All-Ford Nationals

Here are some pictures I took at the 2010 Carlisle All-Ford Nationals this weekend up in Carlisle, PA.

I didn't take as many pictures as I should have/wanted, but there were so many cars there it just became overwhelming to try and remember them all.  I annotated each of the photos in the gallery, so for the full caption, just click on the individual photo to make it bigger.

http://gallery.me.com/joel.esler/100207

Sunday, June 6

Pictures by a 3 year old

We occasionally let my daughter have one of our cameras so she can take pictures (which she apparently loves to do).  Here are a few of her shots.

http://gallery.me.com/joel.esler/100199

Yes, I know this is just a link to MobileMe, but that's where I am putting my pictures.

Thursday, June 3

ATM Skimmers: Separating Cruft from Craft

Below is a link to a good article by Brian Krebs (Former reporter for the Washington Post on security) about ATM Skimmers.  I know when I go to an ATM I give the card reader a good yank and fiddle around with it a minute to make sure there isn't anything stuck on there.

Recently my wife's card was used for some fraudulent transactions, and while we still don't know (investigation is underway) how people got the card, the bank did catch the fraud.

You have to be careful out there, even in my small town recently, the local gas station had skimmers installed, which were promptly removed -- but still, you have to be aware of the threat out there.

ATM Skimmers: Separating Cruft from Craft — Krebs on Security.

(Sorry about posting links to other articles recently, I am just trying to keep all my links in one place instead of spreading it across the Internet on a bunch of social media applications.  I figure if I just post everything here, it propagates out.)

Contact Me

You may contact me at the following email address:

joel.esler [at] me.com

Follow me on Twitter: http://twitter.com/joelesler

or

Call me below:



Type YOUR name and number in the above Google Voice box to contact me.

Tuesday, June 1

Google ditches Windows on security concerns

Trying not to bash Windows here, as I personally think that Windows 7 is a much better operating system than it's predecessors.  However, I think this is interesting.  I've seen this happen at several companies lately.  While Google has been very Mac centric for awhile now, according to friends I have in the company, a conscience effort to move everyone off the platform in such a big company is an interesting effort.

FT.com / Technology - Google ditches Windows on security concerns.