Nuclear weapons aren't necessary...
Friend pointed me to the cartoon, about why countries in the world (in this case, China) no longer need nuclear weapons. Awesome!
Friend pointed me to the cartoon, about why countries in the world (in this case, China) no longer need nuclear weapons. Awesome!
Reading some of the details in Panda Labs' Annual Report for 2009 and came across these statistics...the math is pretty crazy...
Panda says that they have 40 million variants of malware in their database, collected over 20 years of business.
They indicate that they are collecting 55,000 variants a day.
If you do the math, that means that in the past 365 days, they collected 20 million variants.
So in one year, they collected as many variants of malware, as they have collected in the entire span of their business.
Neato. Somebody has been busy.
chalmer
Was skimming through some interesting reports by Panda Labs. One report (pdf) covers some basic information on banking malware (i.e. malware designed to gather your personal information associated with online banking). The Appendix is particularly interesting. They cover some details on the Zeus Trojan kit. None of the details are new, nor is the combination of them new - still - I found it fun. And available for the low, low price of only $700. For example:
The Trojan runs on the affected user's computer and can carry out the following actions:
- Socket and Proxy server.
- Auto update.
- Using the polymorphic encrypter to generate different copies of itself.
- Capturing certificates.
- Changing local DNS.
- Removing cookies to get the user to re-enter the passwords.
- Capturing screenshots of the affected computers.
- Receiving remote control commands.
- Adding additional fields to a website and monitor the data sent.
- Stealing passwords stored in several programs (Protected Storage data…) and pop3 and ftp passwords, regardless of the port.
Labels: banking, malware, Panda Labs, trojan
Bruce Schneier has a great piece on fear and logic and the nuclear industry.
The best part is the comments. In the comments, you can really see some of the interplay between fears based on facts and logical reasoning and fear based on raw emotions.
It is interesting to see how some commenters compare the risks to other things that we accept as "normal" or "reasonable" VS those commenters who try to support their comments with gut feeling and fear-mongering.
Awesome!
Labels: fear, information security, nuclear
Offensive Security is hosting a series of tutorials related to using the Metasploit framework.
I haven't had the chance to take a look yet...but they sound promising.
These are being released in support of the Hackers for Charity project that Johnny Long is associated with...from the tutorial homepage:
"This free information security training is brought to you in a community effort to promote awareness and raise funds for underprivileged children in East Africa. Through a heart-warming effort by several security professionals, we are proud to present the most complete and in-depth open course about the Metasploit Framework."chalmer
Labels: hacking
Good article on Wired.com about the results of an analysis of passwords used by Hotmail users...
Out of about 10,000 passwords that were studied, the most common was:
123456
Some of the others showed signs of cultural bias, that reveal potential geolocational evidence...i.e. the large number of Spanish names.
chalmer
Labels: password
One of my students made a very interesting comment the other day...about wanting to engage in battle against the dark side.
So what does it mean to engage in battle against the dark side? There are very direct and flamboyants ways to do so. Presuming you work for the government, you may have these exciting jobs:
Labels: hackers, national security
Recently read an article on Multiple Independent Levels of Security (MILS) which used an acronym whose concepts I was familiar with, but that I had not heard before: NEAT. It stands for:
The following linked article from ComputerWorld UK has some interesting quotes about the growth of Windows operating systems in running a number of supercomputers. Apparently Windows has increased their market share by 400%, while in the same period, Linux only increased its market share by only 51%. This sounds pretty impressive, until you take the time to look at the numbers behind the numbers.
Read the article to see what I mean!
One of the principles I share with my students is to try to look at things with a critical eye. This is a great example of how numbers can be misleading.
chalmer
Labels: critical thinking
The new Federal Desktop Core Configuration standard just kicked in. This standardized configuration for government computers should help to limit some of the crazy misconfigurations we see in many government computers. For more info on the FDCC and the sister project Security Content Automated Protocol (SCAP) you can go to these web-sites:
* FDCC
* SCAP
Disregarding the fact that fear is emotional by nature, I recently engaged my students in a discussion of whether our fears are based on:
Bruce Schneier linked to an interesting factoid about the Department of Homeland Security. Seems they are funding scans of a number of open source software project codebases to check for flaws and defects. Coverity is providing the scanner and the software packages include some big ticket items...including a number of items that form the backbone of the Internet (Apache, Linux, etc). Because of the scans, over 7,000 flaws have been fixed to date. The comments by the readers are pretty insightful. I posted my own comment in the mix, just for good measure.
http://www.schneier.com/blog/archives/2008/02/a_good_security.html
eWeek.com posted a great list of 12 applications that are in common use but suffer from an assortment of vulnerabilities. The list has some applications that will surprise you. Don't be surprised that Internet Explorer is not on the list...for good or bad, they do have a reason.
Chalmer
For the astute readers who are looking for a future in expert testimony or may be pursuing to advance your career, some words of advice: be cautious about what you post online in online forums, especially about what questions you ask. During expert testimony, if the opposing counsel can't discredit your facts, they will attempt to discredit you. One method that has been used to do this is to Google your online activity and then try to use that against you. For example, if you post a perfectly innocent question early on in your career that any skilled professional should know the answer to, the opposing counsel can try to make you out to be a bumbling fool.
An associate of mine, in the forensics field, uses several online identities to bolster and protect his reputation. He uses his "professional identity" to answer other newbies' questions and present himself as an expert in the field and he uses his "throw away identities" to ask questions.
Chalmer
Very interesting tool that helps show how subjects are linked with other subjects on the web. This is particularly useful for seeing how people are characterized on the web.
Try TouchGraph and see for yourself.
Chalmer
Labels: productivity
This article from CBS News outlines the potential for malicious code to be found in online media sources, such as the video files served up by YouTube and similar video websites.
The take home message here is not so much that videos are getting corrupted...we knew that it was only a matter of time. The real story is the focus on how creative and ingenius the cracker community is at spreading their malware.
Chalmer
Labels: hackers, vulnerabilities
Interesting article: Going Undercover in the Slimy World of Phishing in eWeek, that describes the criminal business of phishing.
Don't doubt that cyber crime is big business.
Chalmer
Interesting podcast on eWeek.com about IcePack, a hacking toolkit and the spread of hacking tool kits in general.
Some points that stuck out to me include:
* the value associated with malware...meaning the money that people will spend to buy malware
* the interplay between hackers in the community, who buy a toolkit and then modify it to spy on the hackers that they sell or give it to
* the growth in the malware industry in general
Chalmer
Labels: hackers, trojan, vulnerabilities
Story in the Register about hard disks from Maxtor (recently acquired by Seagate) that come pre-formatted AND pre-infected.
Rumors on the street are that the virus that infects the hard disks from Maxtor steal gaming passwords and delete mp3's.
Nice.
Chalmer
Labels: trojan, vulnerabilities
Tim Wilson of Dark Reading shares his experiences during a walk around the White house scanning for open wireless networks.
Several points are pertinent for the astute reader:
* There are a ton of unsecured or poorly secured wireless networks in the world. OK...so that is not a newsflash.
* The author refers to WiGLE, the wireless geographic logging engine.
Read the article and take a look at WiGLE.
Chalmer
Labels: hackers, national security, vulnerabilities