<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: login]]></title>
    <link>http://securityratty.com/tag/login</link>
    <description></description>
    <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Embassy of Brazil in India Compromised]]></title>
      <link>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</link>
      <guid>http://securityratty.com/article/d16a985654ea698c4e0d3ab5e394be74</guid>
      <description><![CDATA[Only an amateur or unethical competition would embedd malicious links at the Embassy of Brazil in India's site , referencing their online community. With the chances of an Embassy involvement into the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s1600-h/brazil_embassy_india_compromised_1.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxJCIZifgI/AAAAAAAACc0/7XHc2f7BAQo/s200/brazil_embassy_india_compromised_1.JPG" /></a>Only an amateur or unethical competition would embedd <a href="http://securitylabs.websense.com/content/Alerts/3228.aspx">malicious links at the Embassy of Brazil in India's site</a>, referencing their online community. With the chances of <a href="http://www.brazilembassy.in/">an Embassy</a> involvement into the fake antivirus software industry close to zero,<br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s1600-h/brazil_embassy_free_web_space_rogue.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SRxE9OAVBCI/AAAAAAAACck/u5qhnNXJyoE/s200/brazil_embassy_free_web_space_rogue.JPG" /></a>The compromise is a great example of a mixed use of pure malicious domains in a combination with compromised legitimate ones and on purposely registered accounts at free web space providers, hosting the blackhat SEO content. However, digging deeper we expose the entire malicious doorways ecosystem pushing PDF exploits, banker malware and Zlob variants. The malicious attackers embedded links to their blackhat SEO farms advertising fake security software, and also a link to a traffic redirection doorway<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><b>epmwckme.dex1.com</b><br />
<b>htkobaf.dex1.com</b><br />
<b>ogbucof.dex1.com</b><br />
<b>segundomuelle.com/mex/antivirus</b><br />
<b>jgzleaa.dex1.com</b><br />
<b>igpran.ru/services/tolstye</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s1600-h/obfuscation_brazil_embassy.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SRxFRKFC0LI/AAAAAAAACcs/hsjTDmrLtbo/s200/obfuscation_brazil_embassy.JPG" /></a>The active and redirecting <b>traff .asia</b> (89.149.251.203) is currently serving a fake account suspended notice - "<i>This account has been suspended. Either the domain has been overused, or the reseller ran out of resources.</i>" but is whatsoever redirecting us to <b>antimalware09 .net</b>. This particular traffic redirection doorway is actively redirecting us to a command and control server running a well known web malware exploitation kit which is currently serving PDF exploits. <b>&nbsp;</b><br />
<br />
<b>google-analyze .com/socket/index.php</b> (216.195.59.77) from where we're redirected to <b>google-analyze.com/tracker/load.php</b> which is serving system.exe (Trojan-Spy.Win32.Zbot.ehk; Win32.TrojanSpy.Zbot.gen!C.5), and <b>google-analyze .com/tracker/pdf.php</b> (Exploit:Win32/Pdfjsc.G; Exploit.JS.Pdfka.w; Bloodhound.Exploit.196). Naturally, within the live exploit URLs there are multiple IFRAMEs redirecting us to more of this group's campaigns. <b>google-analyze .com</b>&nbsp; has multiple IFRAMEs pointing to <b>google-analystic .net</b> (209.160.67.56), yet another traffic redirection doorway further exposing their campaigns.<br />
<br />
For instance, <b>google-analystic .net/in.cgi?20</b> loads <b>google-analystic.net/tea.php</b> (209.160.67.56) where <b>google-analystic .net/in.cgi?8</b> is redirecting to <b>91.203.93.61 /in.cgi?2</b> taking us to <b>91.203.93.61 /25/2/</b> where we deobfuscate the javascript leading us to the exact location of the PDF exploit - <b>91.203.93.61 /25/2/getfile.php?f=pdf</b>. This is just for starters. <b>google-analystic .net/in.cgi?9</b> redirects to <b>mangust32 .cn/pod/index.php</b> (218.93.202.102) where they serve load.exe (Backdoor:Win32/Koceg.gen!A) at <br />
<b>mangust32 .cn/pod2/load.php</b> and load.exe at <b>mangust32 .cn/eto2/load.php</b>, moreover, <b>google-analystic .net/in.cgi?10</b> leads us to <b>mmcounter .com/in.cgi?id194</b> (94.102.50.130) a traffic management login which is no longer responding. The last IFRAME found within google-analystic points to <b>busyhere .ru/in.cgi?pipka</b> which redirects to <b>beshragos .com/work/index.php</b> (79.135.187.38) where once we<br />
deobfuscate the script, we get to see the PDF exploit location <b>beshragos.com /work/getfile.php?f=pdf</b>.<br />
<br />
What's contributing to the increase of PDF exploits durin the last month? It's an updated version of a web based malware exploitation tool, which despite the fact that it remains proprietary for the time being, will leak in the next couple of weeks causing the usual short-lived epidemic.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/dutch-embassy-in-moscow-serving-malware.html">The Dutch Embassy in Moscow Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/us-consulate-st-petersburg-serving.html">U.S Consulate in St. Petersburg Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/syrian-embassy-in-london-serving.html">Syrian Embassy in London Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/have-your-malware-in-timely-fashion.html">French Embassy in Libya Serving Malware</a><b> <br />
</b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GVhoN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GVhoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1M6tN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1M6tN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BksVn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BksVn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=u03In"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=u03In" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HzjZN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HzjZN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9KBON"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9KBON" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2Qbtn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2Qbtn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/451892286" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 06:47:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/embassy">embassy</category>
      <category domain="http://securityratty.com/tag/php">php</category>
      <category domain="http://securityratty.com/tag/traffic redirection doorway">traffic redirection doorway</category>
      <category domain="http://securityratty.com/tag/syrian embassy">syrian embassy</category>
      <category domain="http://securityratty.com/tag/exploit">exploit</category>
      <category domain="http://securityratty.com/tag/live exploit urls">live exploit urls</category>
      <category domain="http://securityratty.com/tag/cgi">cgi</category>
      <category domain="http://securityratty.com/tag/pdf exploits durin">pdf exploits durin</category>
      <category domain="http://securityratty.com/tag/pdf exploits">pdf exploits</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/451892286/embassy-of-brazil-in-india-compromised.html">Embassy of Brazil in India Compromised</source>
    </item>
    <item>
      <title><![CDATA[Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts]]></title>
      <link>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</link>
      <guid>http://securityratty.com/article/3526509fda78c56c9b6d343cf188d78d</guid>
      <description><![CDATA[Security researchers at RSAs FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or...]]></description>
      <content:encoded><![CDATA[Security researchers at RSA&#8217;s FraudAction Research Lab have uncovered how a banking Trojan may have stolen the login credentials of as many as 300,000 online bank accounts. The Sinowal (AKA Torpig or Mebroot) trojan has also stole email and FTP account login details. Previous attempts to track the source of the Trojan were unsuccessful.
The haul [...]]]></content:encoded>
      <pubDate>Fri, 31 Oct 2008 17:12:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/online bank accounts">online bank accounts</category>
      <category domain="http://securityratty.com/tag/previous attempts">previous attempts</category>
      <category domain="http://securityratty.com/tag/aka torpig">aka torpig</category>
      <category domain="http://securityratty.com/tag/login credentials">login credentials</category>
      <category domain="http://securityratty.com/tag/sinowal">sinowal</category>
      <category domain="http://securityratty.com/tag/security researchers">security researchers</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/haul">haul</category>
      <source url="http://cyberinsecure.com/undetectable-sinowaltorpig-trojan-steals-more-than-300000-bank-accounts/">Undetectable Sinowal/Torpig Trojan Steals More Than 300,000 Bank Accounts</source>
    </item>
    <item>
      <title><![CDATA[One Sinowal Trojan + One Gang = Hundreds of Thousands of Compromised Accounts ]]></title>
      <link>http://securityratty.com/article/1a4969d994be490ce3b3ac9a5e6ec848</link>
      <guid>http://securityratty.com/article/1a4969d994be490ce3b3ac9a5e6ec848</guid>
      <description><![CDATA[The RSA FraudAction Research Lab would like to share its startling findings based on its tracking and research of the Sinowal Trojan, also known as Torpig and Mebroot . Our findings based on the data...]]></description>
      <content:encoded><![CDATA[The RSA FraudAction Research Lab would like  to share its startling findings based on its tracking and research of the Sinowal  Trojan, also known as <a href="http://en.wikipedia.org/wiki/Torpig">Torpig</a> and <a href="http://www.f-secure.com/weblog/archives/00001510.html">Mebroot</a>.  Our findings based on the data we have collected on this Trojan over the course  of almost three years &ndash; including information regarding its design and its  infrastructure &ndash; indicate that this may be one of the most pervasive and advanced  pieces of crimeware ever created by fraudsters.

We recently discovered that, dating back as  early as February 2006, <B>the Sinowal Trojan has compromised and stolen login  credentials from approximately 300,000 online bank accounts</b>... ]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sinowal trojan">sinowal trojan</category>
      <category domain="http://securityratty.com/tag/trojan">trojan</category>
      <category domain="http://securityratty.com/tag/findings based">findings based</category>
      <category domain="http://securityratty.com/tag/online bank accounts">online bank accounts</category>
      <category domain="http://securityratty.com/tag/login credentials">login credentials</category>
      <category domain="http://securityratty.com/tag/fraudsters">fraudsters</category>
      <category domain="http://securityratty.com/tag/research">research</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/share">share</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1378">One Sinowal Trojan + One Gang = Hundreds of Thousands of Compromised Accounts </source>
    </item>
    <item>
      <title><![CDATA[Massive SQL Injection Attacks - the Chinese Way]]></title>
      <link>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</link>
      <guid>http://securityratty.com/article/42e493c2424af4f8ef6cc5dd581317bf</guid>
      <description><![CDATA[From copycats and &quot;localizers&quot; of Russian web malware exploitation kits , to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QH40puDsgXY/s1600-h/security_company_hacking_tools.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP46U3HSQHI/AAAAAAAACUY/QO3L0OWKJcY/s200-R/security_company_hacking_tools.JPG" /></a>From <a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">copycats</a> and <a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">"localizers" of Russian web malware exploitation kits</a>, to suppliers of original hacking tools, the Chinese IT underground has been closely following the emerging threats and the obvious insecurities on a large scale, and so is either filling the niches left open by other international communities, or coming up with tools setting new benchmarks for massive SQL injection attacks, like the case with this one :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/3GOnK2TsSRk/s1600-h/search_engines_mass_SQL_injection.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5DX0GzAtI/AAAAAAAACUg/pdCwjwri7LM/s200-R/search_engines_mass_SQL_injection.JPG" /></a>"<i>A professional web site vulnerability scanning, use of tools, SQL injection is a new generation of tools to help Web developers and site of the station quickly find vulnerabilities in order to be able to effectively prepare Security work. At the same time, the tool to Web developers to demonstrate the ways in which hackers are using these vulnerabilities, hackers, as well as through the loopholes to do things, can effectively raise the safety awareness of relevant personnel.</i>"<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/Mm7pCwd7LT4/s1600-h/search_engines_mass_SQL_injection2.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DkEEtbqI/AAAAAAAACUo/qMaY93_QOvY/s200-R/search_engines_mass_SQL_injection2.JPG" /></a>Nothing's wrong with the marketing pitch at the first place, but going through the features, the "massive SQL injections through search engine reconnaissance" and automatic page rank verification which you can see in the attached screenshots, ruin the "security auditing" marketing pitch. The tool not only allows easy integration of potentially vulnerable sites obtained through <a href="http://ddanchev.blogspot.com/2007/07/sql-injection-through-search-engines.html">search engines reconnaissance</a>, but also, is prioritizing the results based on the probability for successful injection, next to the page rank of the domains in question. A simple demonstration offered by the company is also, directly enticing its users to "localize" the search engine reconnaissance, by filtering the search results for a particupar country, in this case they used French sites for one of the demos. Here are some excerpts from its CHANGE log speaking for themselves :<br />
<br />
"<i><b>2008.7.15 release version 1.3 </b><br />
&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/37LsW8yh_AE/s1600-h/chinese_SQL_injector.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5DyBXVu7I/AAAAAAAACUw/ub8OVgeWC6Y/s200-R/chinese_SQL_injector.png" /></a><i>- New powerful "automatic machine cycle" feature&nbsp;</i><br />
<i>- Automatic machine cycle is to provide assistance to the advanced user manual into the use of a very&nbsp;</i><br />
<i>- powerful and flexible module, the main sites used for some special filtering into the hand, is almost a&nbsp;</i><br />
<i>- universal tool, you can achieve the following: <br />
&nbsp;</i><br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/xYACViJuVn4/s1600-h/chinese_SQL_injector2.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SP5D-g3FyAI/AAAAAAAACU4/oPVCur3PMgI/s200-R/chinese_SQL_injector2.png" /></a><i>1. In support of GET / POST / COOKIES in a variety of ways, such as the injection.&nbsp;</i><br />
<i>2. Scan the key to the page (background, upload, WebShell, databases, backup files, etc.).&nbsp;</i><br />
<i>3. According to the dictionary to violence landing back-guess solution WebShell password and password (required to verify that the code can not guess solution).&nbsp;</i><br />
<i>4. Page language does not limit the types and databases (to provide specific statements into the database).&nbsp;</i><br />
<i>5. At the same time, support for the circulation of the two variables and two dictionaries, fast running and violent content of the database solution to guess a password.</i>"<br />
<br />
It gets even more interesting in terms of the massive SQL injection attacks mentality which is pretty evident on all fronts :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/0fb6Epapby0/s1600-h/chinese_SQL_injector3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5ELiLoBiI/AAAAAAAACVA/nmrC87TeCxo/s200-R/chinese_SQL_injector3.png" /></a>"<i>- The use of the three search engine sites scans to invade the side to complete<br />
- in scanning probe into the Web site ranking points<br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site. <br />
- New "sequence document scanners" <br />
- What is the sequence document scanners role? Upload to find loopholes, some of the procedures to upload the file after the upload will be renamed, rename the way the system is usually based on time or incremental increase in the number prefix code for the upload process, if not to return after the file name, Upload files to know the url is usually very difficult to sequence the use of paper scanner can be scanned out</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/Y5mM2l7Q6K4/s1600-h/chinese_SQL_injector4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SP5FUvl0FhI/AAAAAAAACVY/DU7feV1pnjU/s200-R/chinese_SQL_injector4.png" /></a><i><br />
- The best reverse domain name query engine, and quasi-wide <br />
- in scanning the database of basic information, an increase of the database of information related to the process, the link has information on the database server user login (sa need permission) <br />
- control of the interface had a big adjustment, the interface process easier to understand and operate. <br />
- based on a significant site of the wrong mode of access to a comprehensive code optimization and more accurate access to the content, accuracy and access to show progress. <br />
- added, "VBS upload to download", "upload directory Web site viewer," "FTP upload to download configuration file" function to make it more convenient for the sa rights to use the site.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/R77obP_vxig/s1600-h/chinese_SQL_injector5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FgfdkSbI/AAAAAAAACVg/ORo853Aicy4/s200-R/chinese_SQL_injector5.png" /></a><i><br />
- point into the types of improved detection order to improve the efficiency of detection. <br />
- improved automatic keyword detection, automatic keyword detection more accurate. <br />
- probe into the points the way to improve and increase the use of automatic detection of the keyword detection. <br />
- type of database to improve the detection, the use of the contents of the length of the failure to detect the type of database automatically switch to the probe through the keyword. <br />
- automatically save and load solution has been to guess the tree structure of the database, guess Solutions has been the content and structure of the database will automatically save and open the next time the injection point will be automatically made available, the solutions do not have to guess again, the continuity of work Greatly increased.&nbsp;</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/DcQNU5crc5k/s1600-h/chinese_SQL_injector6.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="131" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SP5FrcWctII/AAAAAAAACVo/9zGp4bsPB2U/s200-R/chinese_SQL_injector6.png" width="200" /></a><i><br />
- solved from the database to read large amounts of data (on hundreds of thousands or millions of records), the half-way card program will die. <br />
- increased significantly on the wrong model of ASP.NET and SQL Server2005 significant mode of dealing with mistakes, error messages can be extracted from a Web directory! <br />
- significant amendments to the wrong mode, some of the injected one by one point in the field or access to the contents of the issue can not be successful (error code in hand); for increased access to specific points table and into the field.&nbsp;</i><br />
<i><br />
- amendments to the text of a significant error patterns to detect and correct use of loopholes in the system can be used more to expand. (Text significantly in the wrong mode in version 1.1 already supported, but in the version 1.2 upgrade in the process of scanning to improve the performance of the Gaodiao careless. -_-#) <br />
- on a variety of encoded text can be significantly wrong in the right-compatible, able to correctly handle the ASP.NET page of the text marked wrong. Through custom error keyword, truly compatible with any language, any coding error message. <br />
- crack anti-improvement and enhancement. <br />
- An increase of auto-detection feature keywords.&nbsp;</i><br />
<i><br />
- Mssql database specifically for significant points into the wrong mode of detection and the use of up and down the hard work, and many other software can not detect the point of injection can also be used. <br />
- Automatic save and load access to the database, to allow manual known to add tables and fields for solutions to guess. <br />
- Can be used to amend the degree of accuracy; optimize the code to reduce memory footprint; enhance the stability of multi-threading. <br />
- Significant amendments to the wrong mode solution guess the contents of the database must be checked first field defects.</i>"<br />
<br />
The public version of the tool has been in the while for over an year, with a VIP version available to customers only.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=PsITM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=PsITM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBO9M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBO9M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=owYAm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=owYAm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LTzNm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LTzNm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LaPQM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LaPQM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=go5fM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=go5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rYJ9m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rYJ9m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/427878843" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 21 Oct 2008 12:18:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyword detection">keyword detection</category>
      <category domain="http://securityratty.com/tag/detection">detection</category>
      <category domain="http://securityratty.com/tag/database">database</category>
      <category domain="http://securityratty.com/tag/database solution">database solution</category>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/upload process">upload process</category>
      <category domain="http://securityratty.com/tag/text">text</category>
      <category domain="http://securityratty.com/tag/load solution">load solution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/427878843/massive-sql-injection-attacks-chinese.html">Massive SQL Injection Attacks - the Chinese Way</source>
    </item>
    <item>
      <title><![CDATA[Designing a Malicious Processor]]></title>
      <link>http://securityratty.com/article/b9e9bea2fb5860d2b7a3f8f7fae049a6</link>
      <guid>http://securityratty.com/article/b9e9bea2fb5860d2b7a3f8f7fae049a6</guid>
      <description><![CDATA[From the LEET '08 conference: &quot; Designing and implementing malicious hardware ,&quot; by Samuel T. King, Joseph Tucek, Anthony Cozzie, Chris Grier, Weihang Jiang, and Yuanyuan Zhou. Abstract
Hidden...]]></description>
      <content:encoded><![CDATA[<p>From the LEET '08 conference:  "<a href="http://www.usenix.org/event/leet08/tech/full_papers/king/king.pdf">Designing and implementing malicious hardware</a>," by Samuel T. King, Joseph Tucek, Anthony Cozzie, Chris Grier, Weihang Jiang, and Yuanyuan Zhou.</p>

<blockquote><b>Abstract:</b>

<p>Hidden malicious circuits provide an attacker with a stealthy attack vector. As they occupy a layer below the entire software stack, malicious circuits can bypass traditional defensive techniques. Yet current work on trojan circuits considers only simple attacks against the hardware itself, and straightforward defenses. More complex designs that attack the software are unexplored, as are the countermeasures an attacker may take to bypass proposed defenses.</p>

<p>We present the design and implementation of Illinois Malicious Processors (IMPs). There is a substantial design space in malicious circuitry; we show that an attacker,<br />
rather than designing one specific attack, can instead design hardware to support attacks. Such flexible hardware allows powerful, general purpose attacks, while remaining surprisingly low in the amount of additional hardware. We show two such hardware designs, and implement them in a real system. Further, we show three powerful attacks using this hardware, including login backdoor that gives an attacker complete and highlevel access to the machine. This login attack requires only 1341 additional gates: gates that can be used for other attacks as well. Malicious  processors are more practical, more flexible, and harder to detect than an initial analysis would suggest.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=SqBOM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=SqBOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GlHeM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GlHeM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 08:39:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/design hardware">design hardware</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/additional">additional</category>
      <category domain="http://securityratty.com/tag/additional hardware">additional hardware</category>
      <category domain="http://securityratty.com/tag/hardware">hardware</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/flexible hardware">flexible hardware</category>
      <category domain="http://securityratty.com/tag/specific attack">specific attack</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/designing_a_mal.html">Designing a Malicious Processor</source>
    </item>
    <item>
      <title><![CDATA[Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility]]></title>
      <link>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</link>
      <guid>http://securityratty.com/article/a3a826883c2875f86d3d818f4095efc1</guid>
      <description><![CDATA[A security expert has demonstrated that Googles Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users login credentials....]]></description>
      <content:encoded><![CDATA[A security expert has demonstrated that Google&#8217;s Gmail service suffers from security flaws that make it trivial for attackers to create authentic-looking spoof pages that steal users&#8217; login credentials. Google Calendar and other sensitive Google services are susceptible to similar tampering.
A proof-of-concept (PoC) attack, published by Adrian Pastor of the GNUCitizen ethical hacking collective, exploits [...]]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 19:05:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sensitive google services">sensitive google services</category>
      <category domain="http://securityratty.com/tag/users login credentials">users login credentials</category>
      <category domain="http://securityratty.com/tag/spoof pages">spoof pages</category>
      <category domain="http://securityratty.com/tag/adrian pastor">adrian pastor</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/google calendar">google calendar</category>
      <category domain="http://securityratty.com/tag/security expert">security expert</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/collective">collective</category>
      <source url="http://cyberinsecure.com/another-google-bug-put-users-at-phishing-risk-due-to-domain-flaw-and-frame-injection-possibility/">Another Google Bug Put Users At Phishing Risk Due To Domain Flaw And Frame Injection Possibility</source>
    </item>
    <item>
      <title><![CDATA[U.K. companies offered 'password amnesty']]></title>
      <link>http://securityratty.com/article/ead483e8461105b3bd4621b51c735b26</link>
      <guid>http://securityratty.com/article/ead483e8461105b3bd4621b51c735b26</guid>
      <description><![CDATA[Authentication specialist Cryptocard is offering U.K. businesses the chance to test the company's remote access login service free-of-charge until...]]></description>
      <content:encoded><![CDATA[Authentication specialist Cryptocard is offering U.K. businesses the chance to test the company's remote access login service free-of-charge until year-end.]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/authentication specialist cryptocard">authentication specialist cryptocard</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/chance">chance</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/year-end">year-end</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/101008-uk-companies-offered-password.html?fsrc=rss-security">U.K. companies offered 'password amnesty'</source>
    </item>
    <item>
      <title><![CDATA[MSP Snapshot Monitoring with EM7]]></title>
      <link>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</link>
      <guid>http://securityratty.com/article/5288692e82e0f23665e5086e43db9ed4</guid>
      <description><![CDATA[Between the fifth anniversary for ScienceLogic and the Inc 500 milestone, weve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally...]]></description>
      <content:encoded><![CDATA[<p>Between the <a href="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008" target="_blank">fifth anniversary for ScienceLogic</a> and the Inc 500 milestone, we’ve become very nostalgic about the beginnings of the company and EM7. For instance, did you know that EM7 was originally designed with managed service providers in mind? Not so surprising when 5 of the first 6 employees (including all 3 founders) came from hosting and MSP backgrounds and had first-hand experience with the daily trials and tribulations of MSP operations – and the tools that didn’t quite work for them.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas.jpg"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="184" alt="John at Interop Vegas" src="http://blog.sciencelogic.com/wp-content/uploads/2008/10/john-at-interop-vegas-thumb.jpg" width="244" align="left" border="0"></a>Here we talk to John Proctor, who started out as one of our first customers (and the first MSP customer). And he believed in it so much, he eventually became part of the ScienceLogic team. (Remember &#8220;I&#8217;m not only the President, I&#8217;m also a client&#8221; from <a href="http://www.hairclub.com/inthenews_article1.php" target="_blank">the Hair Club for Men</a>?)
<p>John shares his perspectives about the service provider world and why he took a chance on a little-known product called EM7.
<p><strong>ScienceLogic:</strong> What is your background? How many years have you worked as a service provider and for what types of companies?
<p><strong>John Proctor:</strong> I have been working with Service providers for over twelve years. I worked at a major regional service provider for six years and before that I designed and built national and international networks for ISP’s and Fortune 500 companies as a consultant for PriceWaterhouseCoopers and WorldComm.
<p><strong>ScienceLogic:</strong> You were one of the first customers of EM7 – why did you choose it and how did you get over the hurdles associated with using a start-up company’s product?
<p><strong>John Proctor:</strong> We were actually customer number five. Back in 2004 when we evaluated and purchased EM7 we could see that EM7 provided about 80% of what we were looking for in one integrated solution right out of the box. One of the things that sold us on EM7 was that the ScienceLogic founders had all previously worked for a service provider, so we knew they understood our business and our challenges. But in the end, it comes down to features. Once we compared EM7 functionality to the alternatives, it was clearly a “no brainer.”
<p><strong>ScienceLogic:</strong> What other alternatives were being considered?
<p><strong>John Proctor:</strong> Well, we had started with a few point solutions, but as our business and product offerings matured, this resulted in a growing number of point solutions. What started with 3 or 4 ended up as 14 separate tools. They all had strengths but what they didn’t have was integration and because of this they could not scale. And, if the tools could not scale, our business could not grow.
<p>So, naturally we started looking at framework solutions, but they are expensive to buy, expensive to implement, and expensive to maintain. At one point, we even considered some open source projects. There were several that showed promise, but we would still be stuck with tools that were not integrated. So then we considered hiring developers to cobble something together that would work for our business. The only problem with this alternative was that we felt it would take 6 to 8 months before we could have something viable to work with.
<p><strong>ScienceLogic:</strong> What products were you using before EM7? What were your goals?
<p><strong>John Proctor:</strong> Before we purchased EM7 we used 14 different point solutions to deliver our products and services to the marketplace. Tools like NetCool, Openview, Argent, Heat, What’s Up Gold as well as several other point solutions, vendor specific applications and manually updated spreadsheets. And, as I mentioned before, this does not scale. This also adds a great deal of complexity when you begin to consider business continuity and disaster recovery. All these tools were vital to the delivery of our products and services. Any service provider will tell you it is all about uptime. So if the product is uptime, the tools used to deliver it have to be available 24&#215;7x365.
<p>Our goals were simple: scale and redundancy. As it turns out, the solution was simple as well. EM7 provided a tool that could replace the functionality of almost half of the existing point solutions and the applications that could not be replaced were integrated with EM7 to provide our staff with a “single pane of glass” to see the status and performance of each area of the business from one application. We had visibility into everything from facility systems to applications using EM7.
<p>ScienceLogic also delivers an extensible configuration that addressed uptime and redundancy. We deployed collectors throughout our network that reported back to a central pair of redundant database servers and with this configuration we were able to perform backups and add capacity without taking the system down.
<p><strong>ScienceLogic:</strong> Why are service providers different from enterprises? How are their needs different?
<p><strong>John Proctor:</strong> First and foremost, service providers face the same challenges that only the largest enterprises ever face and they also have many unique challenges that only service providers experience.
<p>One challenge we faced was that we had multiple datacenters in different states. They were all interconnected with plenty of bandwidth between each site, but the tools were not designed to be used across the WAN. Our staff in our remote data center did not have the same access as our staff in the corporate office. Since EM7 is web-based, it immediately eliminated this problem.
<p>Another challenge is that service providers must manage systems across multiple domains. Back in the early version of a specific tool we were using before EM7, the only way you could implement it across multiple domains was to put the same username and password on every computer that you monitored. Beyond the security concerns, maintenance was a nightmare. Anytime we had to change the password, we would get locked out of dozens upon dozens of systems. When the password was changed on the monitoring server, it would attempt to login to the remote machines and fail. Repeated attempts would result in the account getting locked. I think that vendor eventually addressed this issue, but service providers seldom find tools that were designed for their unique situations.
<p><strong>ScienceLogic:</strong> How is EM7 geared to service providers?
<p><strong>John Proctor:</strong> Enterprise IT is a trusted part of the business; they are one of the team. Service providers are outsiders that must earn trust by showing the customer exactly what they are doing.
<p>EM7 provides a multi-tenant environment that allows service providers to manage systems across many different customers while at the same time providing the customer access to see the same information but only what’s relevant to them.
<p>EM7 was built by service providers and even includes a few features just for them. Two of my favorites are bandwidth billing and the emergency notification system. Take bandwidth billing, for instance. EM7 provides a way to collect bandwidth utilization, store subscription information, and calculate a bill from any one of about 10 different methodologies. And at the end of the billing period, EM7 sends the completed report out to whomever you chose via email.
<p>Another unique service provider feature is the emergency notification system. EM7 allows the provider to track what customers used their unique infrastructure components. If they have to perform maintenance on the infrastructure component or have a problem they can send an email to all of the impacted customers in a matter of minutes.
<p><strong>ScienceLogic:</strong> What trends do you see for service providers? What about big trends such as virtualization and cloud computing – how will they impact service providers?
<p><strong>John Proctor:</strong> Virtualization is really hot for service providers right now and for the same reasons as in the enterprise. Service providers run data centers and data centers must be powered and cooled. So, anytime they can use a virtual server instead of adding physical equipment it is a good thing. But then you add the complexity that multiple customers reside on the same host and you must track things like bandwidth utilizations by guest OS, and it all gets a little harder. Lucky for us this is not a problem for EM7.
<p>I still think it’s early days for cloud computing. Depending on who you talk to, much of what service providers (especially the big ones) have already been doing with SAAS offerings and hosted applications could be described as cloud computing already. In which case, service providers are ahead of the game. But whatever the “final” definition, cloud computing actually shares many similarities with virtualization – in that service providers (or enterprises) will need to be able to manage far more “devices” in real-time with “zero downtime” expectations by customers. What this really means is that you’re going to see much more automation in provisioning and IT monitoring tools to handle the scale and speed with which things can change in the data center given vm migration and the talked-about switching between “clouds” that can be used for high availability. </p>
]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 12:51:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/service providers">service providers</category>
      <category domain="http://securityratty.com/tag/service providers experience">service providers experience</category>
      <category domain="http://securityratty.com/tag/service providers seldom">service providers seldom</category>
      <category domain="http://securityratty.com/tag/impact service providers">impact service providers</category>
      <category domain="http://securityratty.com/tag/em7 functionality">em7 functionality</category>
      <category domain="http://securityratty.com/tag/em7 sends">em7 sends</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service provider world">service provider world</category>
      <source url="http://blog.sciencelogic.com/msp-snapshot-monitoring-with-em7/10/2008">MSP Snapshot Monitoring with EM7</source>
    </item>
    <item>
      <title><![CDATA[Root of Trust ?]]></title>
      <link>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</link>
      <guid>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</guid>
      <description><![CDATA[Ive given some talks this year about the Internets insecure infrastructure stressing that fundamental protocols such as BGP and DNS cannot really be trusted at the moment. Although they work just fine...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;ve given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080211-mailserver.pdf">some</a> <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080915-ISPsecurity.pdf">talks</a> this year about the Internet&#8217;s insecure infrastructure &#8212; stressing that fundamental protocols such as <a href="http://www.bgp4.as/">BGP</a> and <a href="http://oreilly.com/catalog/9780596100575/">DNS</a> cannot really be trusted at the moment. Although they work just fine most of the time, they are susceptible to attacks which can mean, for example, that you visit the wrong website, or your email is intercepted.</p>
<p>Steps are now being taken, <a href="http://voices.washingtonpost.com/securityfix/2008/08/dns_security_mandatory_for_all.html">rather faster</a> since Dan Kaminsky came up with a <a href="http://www.doxpara.com/?p=1185">really effective DNS poisoning attack</a>, to secure DNS by using <a href="http://www.dnssec.net/">DNSSEC</a>.</p>
<p>The basic idea of DNSSEC is that when you get an answer from the DNS it will be signed by someone you trust. At some point the &#8220;trust anchor&#8221; for the system will be &#8220;.&#8221; the DNS root, but for the moment there&#8217;s <a href="http://www.unbound.net/documentation/howto_anchor.html">just a handful of &#8220;trust anchors&#8221; one level down</a> from that. One such anchor is the &#8220;.se&#8221; country code domain for Sweden. Additionally, Brazil (.br), Puerto Rico (.pr), and Bulgaria (.bg) have signed their zones, but that&#8217;s about it for today.</p>
<p>So, wishing to get some experience with the <a href="http://www.sparknotes.com/lit/bravenew/">brave new world</a> of DNSSEC, I decided that Sweden was <a href="http://www.cartoonbank.com/item/25468">the &#8220;in&#8221; place to be</a>, and to purchase &#8220;cloudba.se&#8221; and roll out my first DNSSEC signed domain.</p>
<p>The purchase wasn&#8217;t as easy as it might have been &#8212; when you buy a domain, Sweden <a href="http://www.iis.se/docs/general_conditions.pdf">insists</a> that people provide their <a href="http://www.papersplease.org/id.html">identity numbers</a> (albeit they have absolutely no way of checking if you&#8217;re telling the truth) &#8212; or if a company they want a VAT or registration number (which are checkable, albeit I suspect they didn&#8217;t bother). I also found that they don&#8217;t like spaces in the VAT number &#8212; which held things up for a while!</p>
<p>However, eventually they sent me a PGP signed email to tell me I was now the proud owner of &#8220;cloudba.se&#8221;.  Unfortunately, this email wasn&#8217;t in RFC3156 PGP/MIME format (or any other format that my usually <a href="http://en.wikipedia.org/wiki/Turnpike_(software)">pretty capable email client</a> understood).</p>
<p>The email was signed with key 0xF440EE9B which was reassuring because the <a href="http://www.iis.se/">.se registry</a> gives the fingerprint for this key on their website <a href="https://domainmanager.iis.se/start/customerservice">here</a>. Rather less reassuringly footnote (*) next to the fingerprint says &#8220;<em>.SE signature for outgoing e-mail. (**) June 1 through August 31.</em>&#8221; (the (**) is for a second level of footnote, which is absent &#8212; and of course it is now September).</p>
<p>They also enable you to fetch the key through a link on <a href="http://www.iis.se/support">this page</a> to their &#8220;PGP nyckel-ID&#8221; at <a href="http://subkeys.pgp.net:11371/pks/lookup?op=get&#038;search=0xFCEC5128F440EE9B">http://subkeys.pgp.net</a>.</p>
<p>Unfortunately, fetching the key shows that the signature on the email is invalid.</p>
<p>Since the email seems to have originated in the Windows world, but was signed on a Linux box (giving it a mixture of 0D 0A and 0A line endings), then pushed through a three year old copy of <a href="http://search.cpan.org/dist/MIME-tools/">MIME-tools</a> I suppose the failure isn&#8217;t too surprising. But strictly the invalid signature means that I shouldn&#8217;t trust the email&#8217;s contents at all &#8212; because the contents have definitely been tampered with since the signature was applied.</p>
<p>Since the point of the email was to get me to login for the first time to the registry website and set my password to control the domain, this is a little <a href="http://www.cartoonbank.com/item/32907">unfortunate</a>.</p>
<p>Even if the signature had been correct, then should I trust the PGP key?</p>
<p>Well it is pointed to from the registry website which is a Good Thing. However, they do themselves no favours by referencing a version on <a href="http://www.rossde.com/PGP/pgp_keyserv.html">the public key servers</a>. I checked who had signed the key (which is an <a href="http://www.pgpi.org/doc/pgpintro/#p20">alternative way of trusting its provenance</a> &#8212; since the email had arrived to a non-DNSSEC secured domain). Turned out there was no-one I knew, and of 4 individual signatures, 2 were from expired keys. The other signature was the IIS root key &#8212; which sounds promising. That has 8 signatures, once again not people I know &#8212; but only 1 from a non-expired key, so perhaps I can get to know some of the other 7?</p>
<p>Of course, anyone can sign a key on a public key server, so perhaps it makes sense for .se to suggest that people fetch a key with as many signatures as possible &#8212; there&#8217;s more chance of it being signed by someone they know. Anyway, I have now added my own signature, using an email address at my nice shiny new domain. However, it is possible that I may not have increased the level of trust <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/09/signers.png" alt="" title="Signers of the .se PGP key" class="aligncenter size-full wp-image-381"></p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/public key servers">public key servers</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/iis root key">iis root key</category>
      <category domain="http://securityratty.com/tag/key 0xf440ee9b">key 0xf440ee9b</category>
      <category domain="http://securityratty.com/tag/pgp">pgp</category>
      <category domain="http://securityratty.com/tag/pgp nyckel-id">pgp nyckel-id</category>
      <category domain="http://securityratty.com/tag/public key server">public key server</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/29/root-of-trust/">Root of Trust ?</source>
    </item>
    <item>
      <title><![CDATA[Hype Alert: Internet Shopping Carts Are Secure]]></title>
      <link>http://securityratty.com/article/6f0706e64d78d354492017803497a079</link>
      <guid>http://securityratty.com/article/6f0706e64d78d354492017803497a079</guid>
      <description><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled Internet Shopping Carts are Secure
OMG...really
To be fair, I realize the author is speaking from the...]]></description>
      <content:encoded><![CDATA[My blog reader fed me a nugget today that set off my hype monitor, specifically a post entitled <a href="http://hubpages.com/hub/Internet-Shopping-Carts-Are-Secure" taget="_blank">Internet Shopping Carts are Secure</a>. <br />OMG...really?<br />To be fair, I realize the author is speaking from the eCommerce perspective, rather than that of an information security practitioner, but here's where the trouble begins:<br /><span style="font-style:italic;">"Shopping cart service providers have developed secure ecommerce shopping cart solutions for any business owner looking to enhance their current online store, or create a new one. Some ecommerce shopping cart solution providers are even receiving PABP (Payment Application Best Practice) certification which supports PCI compliance requirements for all businesses accepting credit card payments online."</span><br />This may be true in part, but it is by no means an all-inclusive claim. Shopping carts continue to be sieve-like, even when apparently reviewed per <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI</a> standards.<br />Allow me to elaborate.<br />We'll kick off our hype eliminating effort with a simple Google dork: <a href="http://www.google.com/search?hl=en&q=inurl%3A%22cart.cfm%22&btnG=Search" target="_blank"{>inurl:"cart.cfm"</a> (picking on ColdFusion again, but man, they make it easy)<br /><a href="http://www.gmpartsdirect.com/cart.cfm" target="_blank">GM Parts Direct: Your Shopping Cart</a> jumped right out at me for a number of reasons.<br />First, I sensed XSS vulns lurking like a Geiger counter senses radiation. Sound <a href="http://www.ringelkater.de/Sounds/2geraeusche_gegenst/geigerzaehler.wav" target="_blank">effect</a> for edification. :-)<br />Second, the page contained one of the growing number of aforementioned conversion-driving website <a href="http://sealserver.trustwave.com/cert.php?customerId=w6ordzctHpqOVGcB1cmBsViTpDGC2k&size=105x54&style=normal&language=en" target="_blank">security</a> seals. <br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s1600-h/GMparts.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SN1tYvapkkI/AAAAAAAAADg/6k1ncKqufL4/s320/GMparts.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250473012396397122" /></a><br /><br />Tick, tick, click...the Gieger counter is getting louder. <br />Trustwave claims that the site operator "is enrolled in Trustwave's Trusted Commerce™ program to validate compliance with the Payment Card Industry Data Security Standard (PCI DSS) mandated by all the major credit card associations including: American Express, Diners Club, Discover, JCB, MasterCard Worldwide, Visa, Inc. and Visa Europe."<br />Methinks that <a href="https://www.trustwave.com/" target="_blank">Trustwave's</a> Trusted Commerce program is missing a few fundamental security checks. Remember, XSS in PCI regulated sites, according to the <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI DSS</a>, indicates that a site is not compliant (see section 6.5.4) if vulnerable to XSS.<br />Uh-oh.<br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s1600-h/GMparts_xss_trustwave.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SN1wVI4q8FI/AAAAAAAAADo/ZzFA7u8xNCA/s320/GMparts_xss_trustwave.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5250476249048608850" /></a><br />All it takes is a fake login page, as opposed to our friends at <a href="http://xssed.com/" target="_blank">XSSED.com</a>, and...well, you get the point.<br />Simply, this is one of an endless number of shopping cart not secure, and not PCI compliant. For shame. You need only browse the <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">Holisticinfosec.org Advisories</a> page to find multiple ecommerce platforms and shopping carts that are missing the mark. Trust me, these are a fraction of the <a href="http://secunia.com/advisories/search/?search=shopping+cart" target="_blank">problem</a>.<br />ecommerce<>security<br />ecommerce<><a href="http://msdn.microsoft.com/en-us/library/ms995349.aspx" target="_blank">SDL</a><br />ecommerce<>PCI<br />website security seal<>security<br />Sigh.]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 11:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ecommerce">ecommerce</category>
      <category domain="http://securityratty.com/tag/multiple ecommerce platforms">multiple ecommerce platforms</category>
      <category domain="http://securityratty.com/tag/ecommerce sdl">ecommerce sdl</category>
      <category domain="http://securityratty.com/tag/ecommerce perspective">ecommerce perspective</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/cart solutions">cart solutions</category>
      <category domain="http://securityratty.com/tag/cart">cart</category>
      <category domain="http://securityratty.com/tag/ecommerce security">ecommerce security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/hype-alert-internet-shopping-carts-are.html">Hype Alert: Internet Shopping Carts Are Secure</source>
    </item>
  </channel>
</rss>
