May 16, 2010

Replacement for Facebook?

I discovered an interesting project the other day where 4 software developers are embarking on a project this summer to develop an open source, distributed, privacy-aware social network. It sounds kind of like what Tor is for surfing this network is for socializing. In the video on the main page they complain that they don't want a central hub handling their messages to their friends.

It's an intriguing project and one that has attracted quite a few supporters. I know this because they launched a donation website where one can donate to their project and receive certain benefits. They said they need at least $10,000 to fund the development of the project: as of 12:00 PM UTC on Sunday May 16 they have 4,493 backers who donated a total of $168,730. I wonder what they'll do with the extra cash.

One wonders if this will seriously compete with Facebook's 350 million users or maybe it will get Facebook to fix their privacy policy which has gotten a beating recently. Time will tell with this.

Check out the project here.

April 13, 2010

Call-For-Papers Info Sec Summit in October


I forgot to mention in my last blog post that we are accepting submissions from presenters and trainers for the Information Security Summit on October 11-13 and 14-15, 2010.

CFP submission deadline is May 15, 2010. We look forward to your participation.

http://www.informationsecuritysummit.org

April 9, 2010

8th Annual Information Security Summit Dates Announced

Dates have been announced for the 8th Annual Information Security Summit. This years event will take place October 14-15, 2010 at Corporate College East in Warrensville Heights, Ohio. Pre-conference training class will take place on October 11, 12, and 13. Corporate College East is located at 4400 Richmond Road between Harvard and Emery Roads In Warrensville Heights. The facility is easily accessible from Interstate 271.

Last years event featured keynote talks from well respected industry leaders Richard Bejtlich, Grady Summers, Joel Snyder, and John O'Leary; over 30 sessions; and attracted over 400 security professionals. The event was a huge success and we will be building on that this year.

Registration is open, take advantage of early bird pricing of $250 before July 1, 2010.

http://www.informationsecuritysummit.org

December 29, 2009

Another Win for the Good Guys: Bye Bye Mega-D Botnet

I just read this great piece of news over at the Sunbelt Software Blog about a top 10 botnet. The botnet, called Mega-D, was said to have 250,000 bots which has been responsible for nearly 12 percent of the world spam. Wow, this is a great win.

The takedown was coordinated by a researcher at FireEye who working with others in the industry and Internet Service Providers, provided U.S. law enforcement with the information needed for the shut down.

Kudos to the FireEye team and others involved on this win! Keep fighting the good fight.

Check out the Sunbelt Blog entry here.

December 18, 2009

Satellite Sniffing Software Used to Monitor Drone Video

According to the New York Times, insurgents in Iraq are using cheap satellite sniffing software to monitor the video feed coming from Drone fighter airplanes. This was discovered when laptops from captured insurgents were analyzed. The software they used is called Sky Grabber and costs only $26. It was designed to download music and movies off of satellite transmissions.

What's very disappointing with all this is that the Drones are not using encryption to secure the video feed. I've heard some reports that they aren't equipped to use encryption which if that's the case it's shameful. I don't see any good reason why we would want the insurgents to see the video data showing what the Drones are seeing. C'mon encrypt the data people!

Article here: http://www.nytimes.com/2009/12/18/world/middleeast/18drones.html?scp=1&sq=drone&st=cse

October 28, 2009

Local northeast Ohio security conference: Summit


It's been a long while since I've posted to my blog, it's been super busy lately. Apologies to my 3 readers - I promise to post more frequently.

This week I'll be at the 7th annual Information Security Summit. This is a 2-day conference held in northeast Ohio, this year it's in Warrensville Heights at Corporate College East, and features over 30 speakers from around the US covering security topics in the areas of governance/risk/compliance (GRC), threats, application security, incident response, network security monitoring, malware, wireless, open source tools, forensics, contingency planning, BCP, phyiscal security, etc. A long list indeed. See complete agenda here.

My role at the Summit is along with several others we help organize, plan, and run the event. I will also be working the NEO Info Sec Forum booth. This is a group I founded 4 1/2 years ago. If you are at the Summit stop by our booth (in room 124 off the atrium) and say hi. Try your hand at a crypto challenge where you can win some cool prizes.

Hope to see you at the Summit.

Side Note: For those of you who can't make it check out the live stream of the conference that Security Justice Podcast is providing!

August 27, 2009

Banks Receive Fake Training CDs from NCUA...oh wait...

As reported by the SANS Internet Storm Center, some banks reported receiving what appeared to be letters and training materials from the National Credit Union Administration (NCUA). The training materials consisted CDs.

Then you hear this over the PA system:
This was a test of the emergency broadcast system. This was only a test.
Closer inspection reveals that the letters were fake and the CDs contained malware. Pretty interesting scam involving physical world and computer security.

Ha. So Brent Huston from Microsolved contacts the SANS folks letting them know that he sent those as part of a penetration test his company was performing. Wow, good test and probably was successful. I bet some people put those CDs in their computers.

This was a great awareness event for training our users. I fully expect to see the criminals start using this technique more. :(

July 27, 2009

Advertising on social media site raises privacy concerns

Quick post about an interesting story I just read...

One day a married man (important to mention) logged into his Facebook account to check his messages. While on his page he was presented with an ad that entised him to visit a singles site. The ad said "Hey Peter. Hot singles are waiting for you!!" So what you ask? Well it just happens that along with the ad was a picture of a woman, that woman happened to be his wife. See below:


As it turns out, a 3rd party advertiser scraped her picture and others off Facebook profiles and used them in their ads. The victim, Cheryl Smith, talks about the incident on her blog.

According to Facebook officials this violates their policy and they have removed this advertiser. They even kicked off two whole advertiser networks for terms-of-service violations (not necessarily related to this particular case).

At first this story gave me a great laugh, but that quickly turned to shock and concern. Shock that an advertiser would use such a tactic, well I guess I've seen worse but still shocked. Concern regarding privacy on social media websites.

The folks at DownloadSquad have a writeup about this incident here and Sunbelt Software talks about it as well.

Want to protect yourself from the scrapers? Read Tom Eston's Facebook Privacy & Security Guide.

July 13, 2009

More Blackhat SEO, Pelosi is Target

The blackhats continue to push their rogue security programs via Search Engine Optimization techniques. This time I ran across a site using US Congress House Speaker Nancy Pelosi's name. It appears to be all sorts of headlines and keywords such as:





pelosi says surge did not work

And there's also some not so flattering phrases:



pelosi insane
pelosi is an idiot
pelosi is a communist

Some well worded SEO there bound to attract search engine hits.

The site contains some Javascript code in it (well not anymore but it was there) which after traveling through a couple redirect sites ultimately takes the visitor to some rogue security software sites. One of which uses drive-by fake scanning tactics. The redirect sites contain quite sophisticated Javascript code to hide their purpose. They also appear to redirect you based on where you came from.

The two rogue websites by the way are:

  • protectionbenefits.cn (83.133.123.113 Germany)
  • securedvirusscan.com (94.102.48.29 Netherlands)
This is in no way "new news" as reported by me earlier this year Ford was a target of these fraudsters and Panda Security has numerous siteings. This surely will continue for as long as they have the ability to operate the sites.
:(

June 18, 2009

Various interesting news and posts


The Web's most dangerous keywords to search for
http://blogs.zdnet.com/security/?p=3457
I've long known that some 75% of all screensavers found on the Internet via Google search contain malware but thought that some of these words were interesting: free games, work from home, iphone, barack obama. Something else interesting is the finding that when searching for lyrics keywords or phrases with the word 'free' in them one of four sites contain malicious code. Talk about blackhat SEO.

Building an Automated Behavioral Malware Analysis Environment using Open Source Software by Jim Clausing
http://www.sans.org/reading_room/whitepapers/tools/building_an_automated_behavioral_malware_analysis_environment_using_open_source_software_33129
Looks very promising. On my reading list.

Ex-DOS and Microsoft Exec Heading Up DHS Cyber Post
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9133855
Earlier this month Secretary Napolitano of the U.S. Department of Homeland Security named Philip Reitinger as Director of the National Cyber Security Center in DHS. This is a newly formed office in DHS. Previously Philip had held positions in DOD Cyber Crime Center and was leading the Trustworthy Computing initiative at Microsoft. Philip replaces Rod Beckstrom who vacated the post earlier this year citing lack of funding and internal support. I wish Philip all the best and hope he's able to get what he needs to get things done there.