<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: easily]]></title>
    <link>http://securityratty.com/tag/easily</link>
    <description></description>
    <pubDate>Thu, 16 Oct 2008 11:24:58 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The DDoS Attack Against Bobbear.co.uk]]></title>
      <link>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</link>
      <guid>http://securityratty.com/article/290801c330ee41caec63af5966719ea1</guid>
      <description><![CDATA[When you get the &quot;privilage&quot; of getting DDoS-ed by a high profile DDoS for hire service used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s1600-h/ddos_for_hire_bobbear.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SSNmn4J-fjI/AAAAAAAACeM/iaTooLo_YGA/s200/ddos_for_hire_bobbear.png" /></a>When you get the "privilage" of <a href="http://blogs.zdnet.com/security/?p=2188">getting DDoS-ed by a high profile DDoS for hire service</a> used primarily by cybercriminals attacking other cybercriminals, you're officially doing hell of a good job exposing <a href="http://www.bobbear.co.uk/">money laundering scams</a>.<br />
<br />
The attached screenshot demonstrates how even the relatively more sophisticated countersurveillance approaches taken by a high profile DDoS for hire service can be, and were in fact bypassed, ending up in a real-time peek at how they've dedicated 4 out of their 10 BlackEnergy botnets to Bobbear exclusively.<br />
<br />
Perhaps for the first time ever, I come across a related DoS service offered by the very same vendor - <b>insider sabotage on demand given they have their own people in a particular company/ISP in question</b>. Makes you think twice before considering a minor network glitch what could easily turn into a coordinated insider attack requested by a third-party. Moreover, now that I've also established the connection between this DDoS for hire service and one of the command and control locations (all active and online) of one of the botnets used in the <a href="http://blogs.zdnet.com/security/?p=1670">Russia vs Georgia cyberattack</a>, the <a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">concept of engineering cyber warfare tensions</a> once again proves to be <a href="http://ddanchev.blogspot.com/2008/08/whos-behind-georgia-cyber-attacks.html">a fully realistic one</a>. <br />
<br />
<b>Related posts:</b><br />
<a href="http://blogs.zdnet.com/security/?p=1095">A U.S military botnet in the works</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/ddos-attack-graphs-from-russia-vs.html">DDoS Attack Graphs from Russia vs Georgia's Cyberattacks</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/botnet-on-demand-service.html">Botnet on Demand Service</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attack Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/new-ddos-malware-kit-in-wild.html">A New DDoS Malware Kit in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vAULN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vAULN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ReZlN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ReZlN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Xyy4n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Xyy4n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jkNqn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jkNqn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=R21XN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=R21XN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=vKYRN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=vKYRN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Mwlxn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Mwlxn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/458461988" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 05:35:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ddos">ddos</category>
      <category domain="http://securityratty.com/tag/ddos attack">ddos attack</category>
      <category domain="http://securityratty.com/tag/ddos-ed">ddos-ed</category>
      <category domain="http://securityratty.com/tag/ddos malware kit">ddos malware kit</category>
      <category domain="http://securityratty.com/tag/ddos attack graphs">ddos attack graphs</category>
      <category domain="http://securityratty.com/tag/hire service">hire service</category>
      <category domain="http://securityratty.com/tag/profile ddos">profile ddos</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <category domain="http://securityratty.com/tag/blackenergy botnets">blackenergy botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/458461988/ddos-attack-against-bobbearcouk.html">The DDoS Attack Against Bobbear.co.uk</source>
    </item>
    <item>
      <title><![CDATA[Chertoff: We're Closing that Boarding-Pass Loophole]]></title>
      <link>http://securityratty.com/article/3b5d0643ba1c89f45e89e3a29eb5104e</link>
      <guid>http://securityratty.com/article/3b5d0643ba1c89f45e89e3a29eb5104e</guid>
      <description><![CDATA[Five years later, the Department of Homeland Security gets around to fixing a security hole that allows people to easily fly under an alias, bypassing anti-terror name...]]></description>
      <content:encoded><![CDATA[Five years later, the Department of Homeland Security gets around to fixing a security hole that allows people to easily fly under an alias, bypassing anti-terror name screening.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=7bd5c081d16f1327492d06ca5f79d021" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=7bd5c081d16f1327492d06ca5f79d021" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=oUuKN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=oUuKN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=pWmYn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=pWmYn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=jGlsn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=jGlsn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=L3EzN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=L3EzN" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=p0jSN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=p0jSN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=FcgYn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=FcgYn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=pEzPn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=pEzPn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=kg0tN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=kg0tN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/456393341" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/456393343" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 15:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/anti-terror">anti-terror</category>
      <category domain="http://securityratty.com/tag/alias">alias</category>
      <category domain="http://securityratty.com/tag/easily">easily</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/456393343/chertoff-were-c.html">Chertoff: We're Closing that Boarding-Pass Loophole</source>
    </item>
    <item>
      <title><![CDATA[Storage, security raises issues for telepresence]]></title>
      <link>http://securityratty.com/article/206d37de03f912b3f28716515256bf07</link>
      <guid>http://securityratty.com/article/206d37de03f912b3f28716515256bf07</guid>
      <description><![CDATA[If high-quality copies of corporate meetings can be easily recorded, both vendors and users will have to determine how best to safeguard such...]]></description>
      <content:encoded><![CDATA[If high-quality copies of corporate meetings can be easily recorded, both vendors and users will have to determine how best to safeguard such information.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9b0902b29b5a4443de3eada35cdd7737:%2FiNNF3CXImc20l54cqrQtIT30sb85smevNB%2B9ypr%2FIpdabJHAgDNAfXMnymlz4Er2s6eue5Bt2eV'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0925fb4d78f830158f3a9a85feb7d6c6:Xl%2BsN5aTcyR%2B0OiDgeZQW5JJH40QrjpNvaJno%2FoCDAf1qUEFRh9QatTrdEWPA4KzFdZtV%2BovrG7OGA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:487be14c56afc8b1c59e3f6bebfcc073:qKgPOIld1caJ3XC7DqIMlUW4pESn9kuCFOTP9tWMffDCWJfJ0osAMXKWLM7hNxgTrH5E9qXz9rVsJg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:6b9df8db1e0082456fd8ae0b3d4fe270:a%2FTQZdXRNWYiFPYi6DTO0JUz9g5A%2FwRAvU5ASvy2vUDllZ38XarrPGUzqGK8zfosHVLCa25y3TTqvw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e957417ecab8e77f05482d4e57e3d129" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e957417ecab8e77f05482d4e57e3d129" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/high-quality copies">high-quality copies</category>
      <category domain="http://securityratty.com/tag/meetings">meetings</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/determine">determine</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/easily">easily</category>
      <category domain="http://securityratty.com/tag/safeguard">safeguard</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=e957417ecab8e77f05482d4e57e3d129">Storage, security raises issues for telepresence</source>
    </item>
    <item>
      <title><![CDATA[DIY Skype Malware Spreading Tool in the Wild]]></title>
      <link>http://securityratty.com/article/7529aecdb25c1d7756e201282f8fb4a0</link>
      <guid>http://securityratty.com/article/7529aecdb25c1d7756e201282f8fb4a0</guid>
      <description><![CDATA[Who needs to build hit lists by harvesting user names when a usability feature allows you to expose millions of users to your latest social engineering campaign? That seems to be the mentality of yet...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRrVzCeAVmI/AAAAAAAACbk/KZPV_8gp9AY/s1600-h/skype_.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRrVzCeAVmI/AAAAAAAACbk/KZPV_8gp9AY/s200/skype_.JPG" /></a>Who needs to <a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">build hit lists</a> by <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">harvesting user names</a> when a usability feature allows you to expose millions of users to your latest social engineering campaign? That seems to be the mentality of yet another Skype malware spreading tool, which just like the majority of publicly obtainable tools is aiming to contact everyone, everywhere.<br />
<br />
The tool's main differentiation factor is its feature of harvesting the personal information of users it has managed to detect randomly, that's of course in between the mass spamming of malicious URLs. However, despite it's DIY nature allowing someone to easily launch a malware campaign spreading across Skype, the tool is lacking the segmentation features offered by related <a href="http://ddanchev.blogspot.com/2008/09/skype-spamming-tool-in-wild-part-two.html">Skype spamming tools</a>. Just like in a cybercrime 1.0 world where <a href="http://ddanchev.blogspot.com/2007/09/diy-exploits-embedding-tools.html">DIY exploit embedding tools</a> were favored due to the lack of web malware exploitation kits, in a cybercrime 2.0 world these DIY tools matured into IM malware spreading modules easily attached to any infected host given the botnet master is looking for such a functionality.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/skype-spamming-tool-in-wild-part-two.html">Skype Spamming Tool in the Wild - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/skype-spamming-tool-in-wild.html">Skype Spamming Tool in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Harvesting Youtube Usernames for Spamming</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/uncovering-msn-social-engineering-scam.html">Uncovering a MSN Social Engineering Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/msn-spamming-bot.html">MSN Spamming Bot</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/diy-fake-msn-client-stealing-passwords.html">DIY Fake MSN Client Stealing Passwords</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">Thousands of IM Screen Names in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/yahoo-messenger-controlled-malware.html">Yahoo Messenger Controlled Malware</a><b><br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=17vrN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=17vrN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gPgTN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gPgTN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Hh4Wn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Hh4Wn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=DOhVn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=DOhVn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=AzUMN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=AzUMN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=VlNQN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=VlNQN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nFj2n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nFj2n" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/450936920" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 08:43:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/skype malware">skype malware</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/publicly obtainable tools">publicly obtainable tools</category>
      <category domain="http://securityratty.com/tag/wild">wild</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/diy tools">diy tools</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/450936920/diy-skype-malware-spreading-tool-in.html">DIY Skype Malware Spreading Tool in the Wild</source>
    </item>
    <item>
      <title><![CDATA[The Skein Hash Function]]></title>
      <link>http://securityratty.com/article/c65ce3834e7790e113fa9e1fd1504568</link>
      <guid>http://securityratty.com/article/c65ce3834e7790e113fa9e1fd1504568</guid>
      <description><![CDATA[NIST is holding a competition to replace the SHA family of hash functions, which have been increasingly under attack . (I wrote about an early NIST hash workshop here
Skein is our submission (myself...]]></description>
      <content:encoded><![CDATA[<p>NIST is <a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">holding a competition</a> to replace the SHA family of hash functions, which have been <a href="http://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html">increasingly under attack</a>.  (I wrote about an early NIST hash workshop <a href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_1.html">here</a>.)</p>

<p>Skein is our submission (myself and seven others: <a href="http://en.wikipedia.org/wiki/Niels_Ferguson">Niels Ferguson</a>, <a href="http://th.informatik.uni-mannheim.de/People/Lucks/">Stefan Lucks</a>, <a href="http://www.hifn.com/executiveTeam.aspx?id=182">Doug Whiting</a>, <a href="http://www-cse.ucsd.edu/~mihir/">Mihir Bellare</a>, <a href="http://www.cs.washington.edu/homes/yoshi/">Tadayoshi Kohno</a>, <a href="http://www.pgp.com/about_pgp_corporation/management.html">Jon Callas</a>, and Jesse Walker).  <a href="http://www.schneier.com/skein.pdf">Here's</a> the paper:</p>

<blockquote><strong>Executive Summary</strong>

<p>Skein is a new family of cryptographic hash functions.  Its design combines speed, security, simplicity, and a great deal of flexibility in a modular package that is easy to analyze.</p>

<p>Skein is fast.  Skein-512 -- our primary proposal -- hashes data at 6.1 clock cycles per byte on a 64-bit CPU.  This means that on a 3.1 GHz x64 Core 2 Duo CPU, Skein hashes data at 500 MBytes/second per core -- almost twice as fast as SHA-512 and three times faster than SHA-256.  An optional hash-tree mode speeds up parallelizable implementations even more.  Skein is fast for short messages, too; Skein-512 hashes short messages in about 1000 clock cycles.</p>

<p>Skein is secure.  Its conservative design is based on the Threefish block cipher.  Our current best attack on Threefish-512 is on 25 of 72 rounds, for a safety factor of 2.9. For comparison, at a similar stage in the standardization process, the AES encryption algorithm had an attack on 6 of 10 rounds, for a safety factor of only 1.7.  Additionally, Skein has a number of provably secure properties, greatly increasing confidence in the algorithm.</p>

<p>Skein is simple.  Using only three primitive operations, the Skein compression function can be easily understood and remembered.  The rest of the algorithm is a straightforward iteration of this function.</p>

<p>Skein is flexible.  Skein is defined for three different internal state sizes -- 256 bits, 512 bits, and 1024 bits -- and any output size.  This allows Skein to be a drop-in replacement for the entire SHA family of hash functions.  A completely optional and extendable argument system makes Skein an efficient tool to use for a very large number of functions: a PRNG, a stream cipher, a key derivation function, authentication without the overhead of HMAC, and a personalization capability.  All these features can be implemented with very low overhead.  Together with the Threefish large-block cipher at Skein core, this design provides a full set of symmetric cryptographic primitives suitable for most modern applications.</p>

<p>Skein is efficient on a variety of platforms, both hardware and software.  Skein-512 can be implemented in about 200 bytes of state.  Small devices, such as 8-bit smart cards, can implement Skein-256 using about 100 bytes of memory.  Larger devices can implement the larger versions of Skein to achieve faster speeds.</p>

<p>Skein was designed by a team of highly experienced cryptographic experts from academia and industry, with expertise in cryptography, security analysis, software, chip design, and implementation of real-world cryptographic systems.  This breadth of knowledge allowed them to create a balanced design that works well in all environments.</blockquote></p>

<p><a href="http://www.schneier.com/code/skein_NIST_CD_101308.zip">Here's</a> source code, text vectors, and the like for Skein.  Watch the <a href="http://www.schneier.com/skein.html">Skein website</a> for any updates -- new code, new results, new implementations, the proofs.</p>

<p>NIST's deadline is Friday.  It seems as if everyone -- including many amateurs -- is working on a hash function, and I predict that NIST will receive at least 80 submissions.  (Compare this to the 21 submissions NIST received -- five were rejected as not being complete --  for the AES competition in 1998.)  I expect people to start posting their submissions over the weekend.  (Ron Rivest already <a href="http://people.csail.mit.edu/rivest/Rivest-TheMD6HashFunction.ppt">presented</a> MD6 at Crypto in August.)  Probably the best place to watch for new hash functions is <a href="http://planeta.terra.com.br/informatica/paulobarreto/hflounge.html">here</a>; I'll try to keep a listing of the submissions myself.</p>

<p>The selection process will take around four years.  I've previously called this sort of thing a cryptographic demolition derby -- last one left standing wins -- but that's only half true.  Certainly all the groups will spend the next couple of years trying to cryptanalyze each other, but in the end there will be a bunch of unbroken algorithms; NIST will select one based on performance and features.</p>

<p>NIST has stated that the goal of this process is not to choose the best standard but to choose a good standard.  I think that's smart of them; in this process, "best" is the enemy of "good."  My advice is this: immediately sort them based on performance and features.  Ask the cryptographic community to focus its attention on the top dozen, rather than spread its attention across all 80 -- although I also expect that most of the amateur submissions will be rejected by NIST for not being "complete and proper."  Otherwise, people will break the easy ones and the better ones will go unanalyzed.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=RsFiM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=RsFiM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=VuObM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=VuObM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 01:35:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skein">skein</category>
      <category domain="http://securityratty.com/tag/hash function">hash function</category>
      <category domain="http://securityratty.com/tag/function">function</category>
      <category domain="http://securityratty.com/tag/implement skein-256">implement skein-256</category>
      <category domain="http://securityratty.com/tag/implement">implement</category>
      <category domain="http://securityratty.com/tag/skein hashes data">skein hashes data</category>
      <category domain="http://securityratty.com/tag/skein website">skein website</category>
      <category domain="http://securityratty.com/tag/hashes data">hashes data</category>
      <category domain="http://securityratty.com/tag/key derivation function">key derivation function</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_skein_hash.html">The Skein Hash Function</source>
    </item>
    <item>
      <title><![CDATA[Applying SDL Principles to Legacy Code]]></title>
      <link>http://securityratty.com/article/92d969d155d0bac3cdff2f17709cb618</link>
      <guid>http://securityratty.com/article/92d969d155d0bac3cdff2f17709cb618</guid>
      <description><![CDATA[Hello, this is Scott Stender from iSEC Partners, one of the SDL Pro Network partners. As security consultants, we at iSEC work with a variety of companies to drive security throughout their...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Hello, this is Scott Stender from iSEC Partners, one of the SDL Pro Network partners.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As security consultants, we at iSEC work with a variety of companies to drive security throughout their development cycle. <SPAN style="mso-spacerun: yes">&nbsp;</SPAN><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>Clients with mature security processes ask that we help carry out parts of their process, from requirements analysis to penetration testing.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Other clients need help defining their security processes, and we help define and kickoff a program based on the Microsoft SDL, other defined processes, or variations thereof, depending on the client’s needs and abilities.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Whether participating in an existing process or helping define one, I personally have been lucky enough to have seen my fair share of successes and failures, and it is this perspective that I hope to share in this guest post.<?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>I find that legacy code poses a unique challenge for organizations rolling out a new security process.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Often, the resources dedicated to maintaining older code are a small fraction of those devoted to new features or products.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Furthermore, the original developers for such features have often moved on, leaving no subject matter experts to drive reviews.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The astute reader will ask “How do I apply the principles of the Microsoft SDL to legacy code when I have no development resources and nobody knows how it works?”<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>The answer is “Start small, and build expertise over time.”<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>A Rising Tide Lifts All Boats<o:p></o:p></FONT></FONT></B></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>The best thing a security engineering team can do to improve security in the short term is to drive code quality, and the first step in this process is to define and enforce a secure coding standard.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This helps on two fronts:<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><o:p></o:p></FONT></FONT></P>
<P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT face=Calibri size=3>1.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>It will improve code quality and reduce implementation flaws across the entire code base.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Unlike other security processes, driving a secure coding standard is <I style="mso-bidi-font-style: normal">relatively</I> easy to accomplish across an entire code base, regardless of the code’s age, by a focused security team.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>That is not to say that it is easy without qualification – a large batch of spaghetti code will require a lot of work to untangle!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Such an effort can only be called “easy” when compared to, say, comprehensive identification and remediation of design flaws across legacy features.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Even so, improving code quality through the use of secure coding standards offers a unique combination of high impact, applicability to features, and ability to be carried out by a core team that makes it a sensible first step.<o:p></o:p></FONT></FONT></P>
<P class=MsoListParagraphCxSpMiddle style="MARGIN: 0in 0in 0pt 0.5in"><o:p><FONT face=Calibri size=3>&nbsp;</FONT></o:p></P>
<P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"><SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"><SPAN style="mso-list: Ignore"><FONT face=Calibri size=3>2.</FONT><SPAN style="FONT: 7pt 'Times New Roman'">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </SPAN></SPAN></SPAN><FONT size=3><FONT face=Calibri>The security team might notice that some sections of code have more standards violations or outright flaws than others.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>This is an instance of vulnerability clustering, a concept that has been used to predict vulnerability rates and improve quality in the functional realm.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The evidence is anecdotal, but it stands to reason that portions of code that consistently violate secure coding standards are good places to start looking for other classes of security flaw.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These are security hotspots, and should be high on the prioritized list for further review.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Security testing may also be applied to legacy code, but initial activities should be considered on a case-by-case basis based on the expected return on investment.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Such testing ranges from using inexpensive off-the-shelf tools to exercise common interfaces to rather expensive custom testing and formal analysis.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is worthwhile to begin with off-the-shelf tools, such as those that target file parsers or web applications, and tools created as part of your greater secure development efforts.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>These can help identify easily-found flaws and suggest improvements to the coding standards.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Comprehensive security testing, on the other hand, is best tackled after the Legacy Security Push.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>The Legacy Security Push<o:p></o:p></FONT></FONT></B></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Coding standards and basic testing provide bang for the buck, but formal security processes seek to provide security assurance.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The challenge for legacy code is that it needs to play catch-up.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Security processes that occur early in the development cycle, such as requirements analysis, design review, and threat modeling, are particularly difficult to achieve years after the fact.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The main goal of the Legacy Security Push is to create the deliverables from these efforts, the most important of which are security requirements and a full risk analysis.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>It may sound trivial, but security requirements are essential.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Not only do they define proper operation for the system in question, they also define assumptions that are suitable for relying systems.<SPAN style="mso-spacerun: yes">&nbsp;&nbsp; </SPAN>It is very common to find security flaws in legacy systems that arise from well-intentioned but incorrect assumptions such as “I assume that the <I style="mso-bidi-font-style: normal">Foo</I> authenticates server <I style="mso-bidi-font-style: normal">Bar</I> when initiating a bank transfer.”<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It stands to reason that <I style="mso-bidi-font-style: normal">Foo</I> would do so for such an important activity, but this assumption must be validated.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>It is very common for older features to have been deployed in and written for different environments where the security assumptions that are "obvious" today just didn't apply at the time.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>When reviewing legacy systems, the first step is to identify such requirements.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>If the original architects, developers or managers are available, they can provide valuable insight at this stage.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>More often than not this is not the case, and analysis must instead rely on what documentation is present and interaction between the software and its consumers.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The goal is the same as in requirements analysis during project inception, except that in this case one must turn the process on its head and reverse engineer requirements from system behavior.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>At the conclusion of this effort, requirements can be theorized – “<I style="mso-bidi-font-style: normal">Foo</I> must authenticate its server <I style="mso-bidi-font-style: normal">Bar</I> before initiating a bank transfer.”<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Risk analysis can be performed once a plausible set of requirements have been identified.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Threat modeling is a more structured means of performing such an analysis, with the eventual goal of identifying means by which requirements can be violated by an attacker.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>As with requirements analysis, original developers would be a valuable resource to consult.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>With or without such help, the first step is to identify how the software works.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>In many cases, help is not available and performing this task requires a great deal of effort.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>For features of moderate size, this author has spent upwards of a month reading code, using process profiling tools, and walking through the software with a debugger to identify program flow and security-sensitive functionality. <o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Once completed, actual system behavior should be documented and compared against the requirements theorized.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN><SPAN style="mso-spacerun: yes">&nbsp;</SPAN>It might be that the requirements should be re-evaluated (New requirement:<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Do not assume that <I style="mso-bidi-font-style: normal">Foo</I> requires server authentication) or the system may need to be changed (New bug:<SPAN style="mso-spacerun: yes">&nbsp;&nbsp; </SPAN><I style="mso-bidi-font-style: normal">Foo</I> does not verify the CN for <I style="mso-bidi-font-style: normal">Bar</I>).<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>At the end, this information should be sufficient to support a comprehensive threat modeling exercise where security requirements, risks, and their mitigations can be documented.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><B style="mso-bidi-font-weight: normal"><FONT size=3><FONT face=Calibri>Next Steps<o:p></o:p></FONT></FONT></B></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Bringing a legacy feature up to par with its newer kin requires a relatively small number of items:<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>improved code quality, clear security requirements, and a thorough threat model.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>As we have seen, performing even these tasks is quite the effort!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>I am sure that it is little comfort to be reminded that accomplishing these tasks has simply laid the foundation, and that the true benefit is that the newly-reviewed legacy feature is able to participate fully in the security processes that remain: reviewing cross-component security requirements and assumptions, comprehensive testing, and incident planning, to name a few.<o:p></o:p></FONT></FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT size=3><FONT face=Calibri>Unfortunately, there is no silver bullet in security assurance.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>The soundness of the design and implementation of legacy software is just as important as in newer software, which is why any complete secure software development process will look backwards as well as forwards.<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Feature by feature, from higher priority to lower, the overall security of the software improves as legacy code receives the full security treatment it deserves.<o:p></o:p></FONT></FONT></P><SPAN style="FONT-SIZE: 11pt; LINE-HEIGHT: 115%; FONT-FAMILY: 'Calibri','sans-serif'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA; mso-ascii-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-theme-font: minor-bidi">Did you find the silver bullet?<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Might you think that defining security requirements is unnecessary?<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Perhaps “It is old and has not been attacked yet.” is a valid security strategy!<SPAN style="mso-spacerun: yes">&nbsp; </SPAN>Please comment below or email me directly at <A href="mailto:scott@isecpartners.com"><FONT color=#0000ff>scott@isecpartners.com</FONT></A> and share your thoughts.</SPAN><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9018591" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 14:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/legacy code">legacy code</category>
      <category domain="http://securityratty.com/tag/mature security processes">mature security processes</category>
      <category domain="http://securityratty.com/tag/security processes">security processes</category>
      <category domain="http://securityratty.com/tag/cross-component security requirements">cross-component security requirements</category>
      <category domain="http://securityratty.com/tag/security requirements">security requirements</category>
      <category domain="http://securityratty.com/tag/processes">processes</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/requirements">requirements</category>
      <category domain="http://securityratty.com/tag/legacy code poses">legacy code poses</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/10/27/applying-sdl-principles-to-legacy-code.aspx">Applying SDL Principles to Legacy Code</source>
    </item>
    <item>
      <title><![CDATA[Princeton report rips N.J. e-voting machines as easily hackable]]></title>
      <link>http://securityratty.com/article/8e10e052f009b65852e6f05141e2137d</link>
      <guid>http://securityratty.com/article/8e10e052f009b65852e6f05141e2137d</guid>
      <description><![CDATA[A Princeton University report sharply criticizes the e-voting machines used in New Jersey and elsewhere as unreliable and potentially prone to...]]></description>
      <content:encoded><![CDATA[A Princeton University report sharply criticizes the e-voting machines used in New Jersey and elsewhere as unreliable and potentially prone to hacking.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:df778f84e140bf8072efa1b8872bbb9a:nbDmABLmMRqhwIGd8IGGScPdY9cothC9QzDISP%2FKAJfqiSEq3PoUPL%2F%2Fm7yof0mDTI2L7mLLMozN'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ccf26ff1630bc1357e78763f7fd4dbd4:Ts9rYpim7nbGGFOq29SCq7wdP8T6Wi0vf0TFVMIuo7aimMqueuG7fHzhBSVMKrZjh1AzqO1Qej%2FxEg%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:63989c2d46e2819b07760db37fd124d1:9C72n4qbTfDFTKagTS62qH11CwZ3cPUaav05ldkEpf%2FPLCLvZ0TGUqABHhBqPQT%2FBU1SyiaCO%2FJIxg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e931a3723ab63ff337dc7cd8989bf61f:9uk1egTJ7jEMq51uYKLm2CsIlMLslNMkhEnGOXtIZ%2BnJy6ooaEGJ1qsGmR4K6fulyT1qedD5eik2ng%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>      <a href="http://www.pheedo.com/click.phdo?s=7ea08076029ebe6cd511cc0f45ec9bdf"><img alt="" style="border: 0;" border="0" src="http://www.pheedo.com/img.phdo?s=7ea08076029ebe6cd511cc0f45ec9bdf"/></a>
  <img src="http://www.pheedo.com/feeds/tracker.php?i=7ea08076029ebe6cd511cc0f45ec9bdf" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 27 Oct 2008 01:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/machines">machines</category>
      <category domain="http://securityratty.com/tag/unreliable">unreliable</category>
      <category domain="http://securityratty.com/tag/jersey">jersey</category>
      <category domain="http://securityratty.com/tag/prone">prone</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=7ea08076029ebe6cd511cc0f45ec9bdf">Princeton report rips N.J. e-voting machines as easily hackable</source>
    </item>
    <item>
      <title><![CDATA[Compromised Portfolios of Legitimate Domains for Sale]]></title>
      <link>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</link>
      <guid>http://securityratty.com/article/5b1e0d15dd199fd7476dbd877e605255</guid>
      <description><![CDATA[Is the demand for access to compromised legitimate portfolios of domains -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s1600-h/compromised_web_hosting_portfolio.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img alt="" border="0" id="BLOGGER_PHOTO_ID_5260712558797708434" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQHOMySS3JI/AAAAAAAACWQ/Hs8QGER1I60/s200/compromised_web_hosting_portfolio.jpg" style="cursor: pointer; float: left; height: 103px; margin: 0pt 10px 10px 0pt; width: 200px;" /></a>Is the demand for access to <a href="http://ddanchev.blogspot.com/2008/08/compromised-cpanel-accounts-for-sale.html">compromised legitimate portfolios of domains</a> -- where the price is based on the pagerank and is shaped by the number of domains in question -- the main growth factor for the increasing supply of such stolen accounting data, or is it the result of cybercriminals data mining their botnets for accounting data that would provide them with access to such <a href="http://ddanchev.blogspot.com/2008/09/adult-network-of-1448-domains.html">portfolios of high trafficked domains with clean reputation</a>? Moreover, would such a data mining approach made easily possible due to the availability of botnet parsing services and stolen accounting data dumps streaming directly from a botnet, would in fact be the more efficient approach in injecting their malicious presence on as many hosts as possible, next to the plain simple <a href="http://ddanchev.blogspot.com/2008/10/massive-sql-injection-attacks-chinese.html">massive SQL injection approach</a>?<br />
<br />
As always, it's a matter of who you're dealing with, and their understanding of the exclusiveness of a particular underground item at a given period of time. This exclusiveness is inevitably going to increase due to the fact that they're several "vendors" that are already purchasing access to such portfolios, as well as compromised Cpanel accounts as a core business, the access to which they would later on either resell at a higher price enjoying the underground market's lack of transparency, or directly monetize and break-even immediatelly. As for this particular proposition for an account with 404 domains in it, it's interesting to monitor how the seller is soliciting bids from multiple sources by leaving the price an open topic, clearly indicating his low profile into the underground ecosystem. How come? An experienced seller or buyer would be offering or requesting page rank verification respectively.<br />
<br />
With nearly each and every aspect of cybercrime already available as a service, or literally outsourced as a process to those supposidely excelling into a particular practice, building capabilities for data mining botnets is no longer a requirement, with the people behind the botnets monetizing all the data coming from it by soliciting deals of accounting data dumps based on a particular country only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KaXaM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KaXaM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5JUrM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5JUrM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iASQm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iASQm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=H5nPm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=H5nPm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=OsSgM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=OsSgM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=WgfUM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=WgfUM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=o6U7m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=o6U7m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/430818024" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 24 Oct 2008 06:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data dumps based">data dumps based</category>
      <category domain="http://securityratty.com/tag/data dumps">data dumps</category>
      <category domain="http://securityratty.com/tag/domains">domains</category>
      <category domain="http://securityratty.com/tag/cybercriminals data">cybercriminals data</category>
      <category domain="http://securityratty.com/tag/portfolios">portfolios</category>
      <category domain="http://securityratty.com/tag/based">based</category>
      <category domain="http://securityratty.com/tag/access">access</category>
      <category domain="http://securityratty.com/tag/botnets">botnets</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/430818024/compromised-portfolios-of-legitimate.html">Compromised Portfolios of Legitimate Domains for Sale</source>
    </item>
    <item>
      <title><![CDATA[A horse's ass approach to virtualization security - Part 3 - Data is the "constant"]]></title>
      <link>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</link>
      <guid>http://securityratty.com/article/af1e0093472ebbd2f739b12a4817fa7e</guid>
      <description><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments

See part one and two here

Virtualization enables organizations to optimally manage...]]></description>
      <content:encoded><![CDATA[The third in the series where I am trying to think through the current approaches to securing virtual environments...<br /><br />See <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization.html">part one</a> and <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">two here</a>...<br /><br />Virtualization enables organizations to optimally manage their infrastructure resources. It can provide significant cost benefits (by sharing resources), flexibility (by just-in-time allocation of resources where they are needed), and agility (speed of provisioning resources).  Therefore, organizations have been able to virtualize:<br /><ul><li><span style="font-weight: bold;">Devices/OS</span>: Companies such as VMWare, Citrix, Microsoft, and Sun are providing hypervisor, virtual machine, and virtual device solutions where several virtual “devices,” “servers,” or “desktops” can mimic separate physical devices.</li><li><span style="font-weight: bold;">Networks</span>: Virtualized networks enable dynamic collaboration by slicing bandwidth into virtual, isolated channels that can be assigned to a particular set of devices, real or virtual.  Setting up new connections and collaborative environments becomes extremely easy.</li><li><span style="font-weight: bold;">Applications</span>: Virtual applications can either be streamed down to execute on local desktops (Microsoft App-V or Altiris SVS) or executed remotely from server farms such as Citrix XenApp.  This allows applications to be portable and accessible from anywhere while reducing inter-application conflicts.</li></ul>However, organizations will never be able to virtualize the fourth element, I talked about in teh <a href="http://bitarmor.blogspot.com/2008/10/horses-ass-approach-to-virtualization_22.html">second blog</a> post — the data itself. The focus of device, network, and application virtualization is about flexibility, resource sharing, and agility. This involves short life spans, since these elements are brought up to fulfill a specific short term task, and upon completion, they are brought down or even deleted. Data, however, has a lifetime <span style="font-weight: bold; font-style: italic;">beyond </span>the short term and will therefore live on for further use or analysis in a non-virtual or subsequent virtual world.<br /><br />This makes data the “constant” in a dynamically changing environment — even if the location of data itself is virtualized. Data will also have the longest lifetime of the four elements in the infrastructure and thus will have to live “outside” of the virtual environment. Therefore, from a security standpoint, it is imperative that data becomes the focus of protection - and we dont just continue protecting the infrastructure.  Data is the critical asset, and since it travels across boundaries and lives longer than virtual elements, it can be easily compromised.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=nM7eM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=nM7eM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=xKbIm"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=xKbIm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=JcSvM"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=JcSvM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/430031380" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 23 Oct 2008 16:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/devices">devices</category>
      <category domain="http://securityratty.com/tag/virtual devices">virtual devices</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <category domain="http://securityratty.com/tag/virtual applications">virtual applications</category>
      <category domain="http://securityratty.com/tag/subsequent virtual world">subsequent virtual world</category>
      <category domain="http://securityratty.com/tag/virtual environments">virtual environments</category>
      <category domain="http://securityratty.com/tag/non-virtual">non-virtual</category>
      <category domain="http://securityratty.com/tag/virtual machine">virtual machine</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/430031380/horses-ass-approach-to-virtualization_23.html">A horse's ass approach to virtualization security - Part 3 - Data is the "constant"</source>
    </item>
    <item>
      <title><![CDATA[6 Months And Counting For Microsoft On CVE-2008-1436]]></title>
      <link>http://securityratty.com/article/630af6ad6042b9974b3ce04fba8e2039</link>
      <guid>http://securityratty.com/article/630af6ad6042b9974b3ce04fba8e2039</guid>
      <description><![CDATA[In April of this year Microsoft issued what seemed to be a rather serious security advisory: Vulnerability in Windows Could Allow Elevation of Privilege (951306) . Microsoft never provides gory...]]></description>
      <content:encoded><![CDATA[In April of this year Microsoft issued what seemed to be <a href="http://www.microsoft.com/technet/security/advisory/951306.mspx">a rather serious security advisory: Vulnerability in Windows Could Allow Elevation of Privilege (951306)</a>.

Microsoft never provides gory details to vulnerabilities even after they've been patched, but by following <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1436">the CVE entry from it</a> you can get links to sites like <a href="http://xforce.iss.net/xforce/xfdb/41880">IBM's ISS</a> which are willing to say more, or even to get <a href="http://www.securityfocus.com/data/vulnerabilities/exploits/28833.zip">proof-of-concept exploit code from SecurityFocus</a>. The vulnerability allows authenticated attackers potentially to elevate privileges to LocalSystem.

Here we are, 6 months later, and Microsoft still has not patched this vulnerability. What's up with that? "Dustin" from the Microsoft Security Response Center <a href="http://blogs.technet.com/msrc/archive/2008/10/13/questions-about-microsoft-security-advisory-951306.aspx">recently addressed the question in a blog on Technet</a>, following an update to the advisory to note the availability of the proof-of-concept code.

It's worth noting that this vulnerability isn't really near the top of the scare list. Most of those 3rd parties you see linked on the CVE page rank it down a few notches. Even the usually hyperbolic Secunia calls it "Less Critical" (2 out of 5, 1 step up from "Not Critical"). Furthermore, back in April Microsoft provided workarounds which it says are effective against the proof-of-concept, at the cost of some administrative burden. They also say that they are unaware of any real-world attacks on this vector. You can find more details from Microsoft on the bug <a href="http://blogs.iis.net/nazim/archive/2008/10/14/token-kidnapping-in-windows.aspx">in Nazim's IIS Security Blog</a> and <a href="http://blogs.technet.com/swi/archive/2008/10/13/service-isolation-explanation.aspx">the Security Vulnerability Research & Defense blog</a>.

Still, 6 months! What Dustin said was "...we began our investigation and immediately realized it would not be trivial to address this issue without introducing new risks." They're still testing and developing a fix. 6 months later. It would seem that the obvious fixes all cause some serious problem, perhaps breaking 3rd party code.

Is this inherently unreasonable? It's getting there. The list of affected software includes most of the important versions of Windows. It may be that some of the time this has taken has gone to working with my speculative 3rd parties to update their own software, so that the fix won't have the same impact.

But let's not forget that this is not an easily exploitable bug. It's not wormable in any way and by the time it's invoked other serious breaches of security have to have happened. So I guess it's worth it for Microsoft to take their time doing it right.
<p><a href="http://feedads.googleadservices.com/~a/RrBOYL-vi28uTXzJfQn7Myh9IXc/a"><img src="http://feedads.googleadservices.com/~a/RrBOYL-vi28uTXzJfQn7Myh9IXc/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/YD0XPCfBCKk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 11:24:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/defense blog">defense blog</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/iis security blog">iis security blog</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security vulnerability research">security vulnerability research</category>
      <category domain="http://securityratty.com/tag/april microsoft">april microsoft</category>
      <category domain="http://securityratty.com/tag/april">april</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/YD0XPCfBCKk/6_months_and_counting_for_microsoft_on_cve20081436.html">6 Months And Counting For Microsoft On CVE-2008-1436</source>
    </item>
  </channel>
</rss>
