Monday, March 06, 2006

DVD of the (past) weekend

Hi folks, as I've been down for a couple of days, I'm actively updating my blog, so watch out for some quality posts later on and apologies for the downtime. Thanks for the interest and the questions received whatsoever!





So, after the "Lone Gunmen", and "The Outer Limits - Sex And Science Fiction Collection" it was about time we go beyond cyberspace with the second part of the "Lawnmower man" a classic techno thriller, with a lot of VR, Cyberpunks, and futuristic scenarious.





Favo quote from part one - "I find a way out, or I die in this diseased main frame" which is also worth watching as a matter of fact. I'm so excited of seeing Ray Kurzweil's views of the future in a DVD box. I am especially interested into Cyberware, and the biological adaptation with technologies. As a matter of fact, there have already been reported cases of people with implanted RFID chips, and while they wish they had Johnny Mnemonic's view of the Internet, that must be some kind of a joke. Picture yourself scanned and monitored wherever you go while walking around with a false sense of security. RFID is a lot of buzz, I feel the potential for information sharing, and resources cutting is outstanding, still, the levels of security or lack of understanding on the privacy implications is the biggest downsize so far.



Would we someday build an AI that would crawl the Universe forever colonizing the obeying the morale we learnt "it" to? I find this such a great idea :)





Some resources on Cyberware and Cyberpunks :

The Cyberpunk Project
Cyberpunk
"Cyberpunks in Cyberspace"
Cyberanarchists, Neuromantics and Virtual Morality
Cyberpunks and their online activities
Cyberpunk - Ebook

Cyberware Technology
Realistic and Affordable Cyberware Opponents for the Information Warfare BattleSpace
Cyberware Implants





Technorati tags :
, , , , ,

Monday, February 27, 2006

Get the chance to crack unbroken Nazi Enigma ciphers

Nice initiative I just came across to. From the "M4 Message Breaking Project" :



The M4 Project is an effort to break 3 original Enigma messages with the help of distributed computing. The signals were intercepted in the North Atlantic in 1942 and are believed to be unbroken. Ralph Erskine has presented the intercepts in a letter to the journal Cryptologia. The signals were presumably enciphered with the four rotor Enigma M4 - hence the name of the project.


This project has officially started as of January 9th, 2006. You can help out by donating idle time of your computer to the project. If you want to participate, please follow the client install instructions for your operating system:

Unix Client Install
Win98 Client Install
Win2000 Client Install
WinXP Home Client Install
WinXP Pro Client Install



The first message is already broken as a matter of fact, and looks like that :



Ciphertext :

nczwvusxpnyminhzxmqxsfwxwlkjahshnmcoccakuqpmkcsmhkseinjus
blkiosxckubhmllxcsjusrrdvkohulxwccbgvliyxeoahxrhkkfvdrewezlx
obafgyujqukgrtvukameurbveksuhhvoyhabcjwmaklfklmyfvnrizr
vvrtkofdanjmolbgffleoprgtflvrhowopbekvwmuqfmpwparmfha
gkxiibg



Deciphered and in plain text :

From Looks:Radio signal 1132/19 contents:Forced to submerge during attack, depth charges. Last enemy location08:30h, Marqu AJ 9863, 220 degrees, 8 nautical miles, (I am) following(the enemy). (Barometer) falls (by) 14 Millibar, NNO 4, visibility 10.



You no longer need the NSA to assist in here, still they sure have contributed a lot while "Eavesdropping on Hell", didn't they?



Distributed Computing is a powerful way to solve complex tasks, or at least put the PC power of the masses in use. It's no longer required to hire processing power on demand from any of these jewels, but download a client, start participating, or find a way to motivate your future participants. In my previous post "The current state of IP spoofing" I commented on the ANA Spoofer Project and featured a great deal of other distributed projects. Meanwhile, the StartdustAThome project also started gaining grounds, so is it ETs, Space dust, global IP spoofing susceptibility, or unbroken Nazi's ciphers - you have the choice where to participate!



Technorati tags :
, , ,

Saturday, February 25, 2006

DVD of the Weekend - The Outer Limits - Sex And Science Fiction Collection

"A sextet of sci-fi tales opens with Alyssa Milano as a woman whose "close encounter" leaves her with an insatiable lust in "Caught in the Act"; the sole survivor of a nuclear holocaust gets some computer-generated companionship in "Bits of Love," with Natasha Henstridge; Sofia Shinas is "Valerie 13," a robot whose emotions become all-too-human; a man who's lived his life onboard a mysterious spaceship meets his female counterpart in "The Human Operators," with Jack Noseworthy and Polly Shannon; a nerd becomes a ladies man via a high-tech "image enhancer" in "Skin Deep," with Antonio Sabato, Jr. and Adam Goldberg; and an alien plant becomes a deadly and
seductive "Flower Child," with Jud Taylor."



Get it, find out more, and listen to the wisdom from previous episodes.

Friday, February 24, 2006

One bite only, at least so far!

Apple's OS X has always been positioned as a juicy target even though it's market share is almost non-existent compared to Microsoft's domination. And while converting iPod customers into MAC users hasn't shown any progress so far and I doubt it would, malware authors are as always actively experimenting or diversifying the threatscape. One question remains unclear, why would someone want to own a MAC, compared to owning hundreds of thousands of Windows PCs out there? To me, it's not about achieving the scale necessary for a Botnet, rather, experiment, show that it's possible through POC releases, or basically start attacking the living in a safe heaven until for now, MAC users.



Recently, an OS X trojan appeared, second (nice attitude from Apple on embracing the inevitable!), one followed, and besides "worming" a vulnerability and experimenting with propagation methods, I don't really think it's the big trend everyone is waiting for, a standard POC(Cabir), whose core function would empower a generation of variants for years to come.



I just came across this from Trifinite's blog :



"Trifinite.group member Kevin has published a paper detailing the techniques he used in the development of the InqTana Bluetooth worm that targets vulnerable Mac OS X systems. There has been significant confusion surrounding this worm, so here are some salient points:



- The concurrent release of the OS X Leap.A and InqTana.A worms is coincidental


- There is no conspiracy, AV vendors and Apple were notified about Kevin's progress in developing this worm in advance of making details publicly available


- Both 10.3 and 10.4 systems are vulnerable until patched with APPLE-SA-2005-05-03 and APPLE-SA-2005-06-08


- InqTana prompts before infecting *by design*, Kevin was just trying to be nice, but the worm could easily spread silently



Kevin's paper is available at http://www.digitalmunition.com/InqTanaThroughTheEyes.txt. Comments can be directed to the BlueTraq mailing list. Our sympathies to those organizations who were affected by the false-positive signatures published by overzealous AV companies."



It clarifies a lot I think, mostly that, while architecture and OS popularity have a lot to do with security and incentives for attacks, "InqTana.A itself has absolutely nothing to do with Leap.A. My work was done completely independent of the author of Leap. The day after I sent out queries to the AV companies about my code I was shocked to see another OSX worm had already been in the news. While my worm sat in the mail spools of several AV companies they were busy writing about the "First Trojan/Worm for OSX"."



Leakage of IP, or I'm being a paranoid in here? Wired also has some nice comments.



Technorati tags :
, , , , , ,

Give it back!

According to a recent article "Secret program reclassifies documents" :



"Researcher Matthew Aid has discovered a secret reclassification program that has moved thousands of declassified pages out of the National Archives and Records Administration's facility in Maryland. Some groups, such as George Washington University's Nation Security Archive, are fighting to end the program, arguing that the government has no right take back information it has published. The reclassification has been ongoing since 1999 as the Central Intelligence Agency, the Defense Intelligence Agency, and the Defense and Justice departments take back information they say had been inadvertently published. The National Security Archive describes some of the documents that have been reclassified as uninteresting and mundane."



And from The National Security Archive :



"Washington, D.C., February 21, 2006 - The CIA and other federal agencies have secretly reclassified over 55,000 pages of records taken from the open shelves at the National Archives and Records Administration (NARA), according to a report published today on the World Wide Web by the National Security Archive at George Washington University."



OSINT has greatly evolved from President Nixon's remark in respect to the CIA “What use are they? They’ve got over 40,000 people over there reading newspapers.”, whereas Secrecy is a major weakness to the national security of a country in a very complex way. I feel that sometimes, you need the average citizen's unbiased opinion on a major issue, but I guess I'm not into politics, just figuring out what is going on at the bottom line!



More on Secrecy, Intelligence, Misc :

Making Intelligence Accountable
Why Spy? The Uses and Misuses of Intelligence (1996)
Intelligence Analysis for Internet Security : Ideas, Barriers and Possibilities
U.S. Electronic Espionage : A Memoir
Terrorism prevention in Russia : one year after Beslan
Crypto Law Survey
Cryptome
Project on Government Secrecy
Shhh!!: Keeping Current on Government Secrecy



Technorati tags :
,

Master of the Infected Puppets

In some of my previous posts, "What are botnet herds up to?", "Skype to control Botnets", "The War against Botnets and DDoS attacks", and "Recent Malware Developments", I was actively providing resources and updating my blog readers (thanks for the tips and the info sharing, I mean it!) related to one of the most relevant threats to the Internet ( more trends and bureaucracy ) - Botnets.





I recently came across a well researched report giving a very in-depth overview and summary of important concepts related to Botnets. Recommended bed time reading, and here's an excerpt :





"In this paper we begin the process of codifying the capabilities of malware by dissecting four widely-used Internet Relay Chat (IRC) botnet codebases. Each codebase is classified along seven key dimensions including botnet control mechanisms, host control mechanisms, propagation mechanisms, exploits, delivery mechanisms, obfuscation and deception mechanisms. Our study reveals the complexity of botnet software, and we discusses implications for defense strategies based on our analysis"





Some of the findings that I also came across in my "Malware - future trends" search worth mentioning are :







- "The overall architecture and implementation of botnets is complex, and is evolving toward the use of common software engineering techniques such as modularity." Namely, no one is interested in reinventing the wheel again, and the Simple Botnet/Malware Communication Protocol I've once mentioned (originally came across the concept here) could give the malware scene an impressive scale, but could it also put AV vendors and researchers in favorauble position where exploiting protocol weaknesses is more beneficial than current approaches?







- "Shell encoding and packing mechanisms that can enable attacks to circumvent defensive systems are common. However, Agobot is the only botnet codebase that includes support for (limited) polymorphism"







Smart! Mainly because of the fact that "The malware delivery mechanisms used by botnets have implications for network intrusion detection and prevention signatures. In particular, NIDS/NIPS benefit from knowledge of commonly used shell codes and ability to perform simple decoding. If the separation of exploit and delivery becomes more widely adopted in bot code (as we anticipate it will), it suggests that NIDS could benefit greatly by incorporating rules that can detect follow-up connection attempts."



-"All botnets include a variety of sophisticated mechanisms for avoiding detection (e.g., by anti-virus software) once installed on a host system."






Retention instead of acquisition of new zombies would tend to dominate from my point of view. Patching the hosts themselves, hiding presence, dealing with the easy to detect idle zombie's presence, TCP obfuscations, tests for debuggers, are among the current methods used.





Botnets will continue to dominate due to their concept and potential for growth, and while monitoring and doing active research is still feasible, encrypted communications as a logical development should also be researched as a concept, but how many *public* IRC servers, if such are used, support SSL encryption?







Technorati tags :
, , ,

Contact