Thứ Hai, 13 tháng 6, 2005

A Phishing Primer


Picture credit: Stern
Excel web sharing - spreadsheet collaboration over the Internet made easy with BadBlueI received this email today, related to some earlier blog postings on the epidemic of phishing.

Not sure what phishing is? Sure you do: it's the plethora of emails you receive asking you to reset your PayPal account information, notifying you that your CitiBank account may have been compromised, and a myriad of variations thereof. All are designed to get you to sign-in to a "false store-front" that appears to be a real financial site. But instead of logging on to a real website, your account and password data are sent directly to the crooks running the scam.

Back to the email I received. In part, it read:

We are trying to compose a short but clear guide to email to our customers and put on our site to warn our customers what to look out for - what is the customer information email you have seen? Would be great if you have some examples of the good, bad and ugly.


Here's a simple summary. The following is a typical phishing email, courtesy of Wikipedia:

From: eBay Billing Department
To: xxx@yyy.com
Subject: Important Notification

We regret to inform you that your eBay account could be suspended if you don't re-update your account information. To resolve this problems please click here and re-enter your account information. If your problems could not be resolved your account will be suspended for a period of 3-4 days, after this period your account will be terminated.

For the User Agreement, Section 9, we may immediately issue a warning, temporarily suspend, indefinitely suspend or terminate your membership and refuse to provide our services to you if we believe that your actions may cause financial loss or legal liability for you, our users or us. We may also take these actions if we are unable to verify or authenticate any information you provide to us.

Due to the suspension of this account, please be advised you are prohibited from using eBay in any way. This includes the registering of a new account. Please note that this suspension does not relieve you of your agreed-upon obligation to pay any fees you may owe to eBay.

Regards,
Safeharbor Department
eBay, Inc

This is an automatic message. Please do not reply.


If you ever receive an email purporting to be from a financial website, please follow this simple step:

Never click on a link in an email to visit a sensitive website. Visit the site directly by using your browser bookmarks or by typing in the address in the browser's address bar.


That's the easiest way to be a safe surfer in the wonderful world of phishers.
 

New Scientist on the BlueTooth Vulnerability


(Picture credit http://www.tomsnetworking.com)
Excel-web sharing of spreadsheetsI wrote a bit last week on the implications of the recently discovered vulnerabilities in the BlueTooth protocol. The weaknesses, combined with hacking innovations such as the BlueSniper rifle, make it easy to sniff or even co-opt BlueTooth networks at distances in excess of a mile. New firmware, anyone?

The best description of the vulnerability I've yet read is this excerpt from an article in New Scientist:

During pairing, two Bluetooth devices establish the 128-bit secret “link key” that they then store and use to encrypt all further communication. The first step requires the legitimate users to type the same secret, four-digit PIN into both devices. The two devices then use this PIN in a complex process to arrive at the common link key.

Whitehouse showed in 2004 that a hacker could arrive at this link key without knowing the PIN using a piece of equipment called a Bluetooth sniffer. This can record the exchanged messages being used to derive the link key and feed the recordings to software that knows the Bluetooth algorithms and can cycle through all 10,000 possibilities of the PIN. Once a hacker knows the link keys, Whitehouse reasoned they could hijack the device.

But pairing only occurs the first time two devices communicate. Wool and Shaked have managed to force pairing by pretending to be one of the two devices and sending a message to the other claiming to have forgotten the link key. This prompts the other device to discard the link key and the two then begin a new pairing session, which the hacker can then use.

In order to send a “forget” message, the hacker must simply spoof one of the devices personal IDs, which can be done because all Bluetooth devices broadcast this automatically to any Bluetooth device within range.

“Having it done so easily is surprising,” says Schneier. He is also impressed by the fact that Wool and Shaked have actually implemented Whitehouse’s idea in real devices.

They show that once an attacker has forced two devices to pair, they can work out the link key in just 0.06 seconds on a Pentium IV-enabled computer, and 0.3 seconds on a Pentium-III. “This is not just a theoretical break, it’s practical,” says Schneier.


New Scientist: New hack cracks 'secure' Bluetooth devices
 

Moving men and material into space


(Picture credit http://www.thespacereview.com)
Excel-web sharing of spreadsheetsInteresting article on the challenges of transporting people and material into near-Earth orbit. Say, logistic support for a Mars colony or an interstellar mission, for instance:

"What you need is a launch system that stays on the ground"... One option is laser propulsion. Researchers at [RPI] have shown that they can propel an object weighing 5 ounces 300 feet into the air with a laser. A real-life version that could launch people in a vehicle "about the size of a Volkswagen" would require a 1,000-megawatt laser located on top of a mountain, he said...

...Another option is the Slingotron. "It is a huge slingshot affair that accelerates your payload on a spiral track and then, zoom--off to outer space," he said. It would kill humans but could be used for cargo.

A third option is the space elevator, a large structure made of customized molecules that could spring people into outer space, according to proponents...


Project Orion (The Space Site)
Dyson himself worked on Orion, a project to land people on Mars, in the 1950s and 1960s. Orion, which would have been built by a submarine company in Connecticut, would have literally been a spaceship.

"We were going to walk on Mars with our notebooks and draw pictures of everything. It would have been true 19th century exploring," he laughed.

To propel it out of orbit, however, would have required exploding 3,000 atomic bombs, one every two seconds. The bombs would have been tossed out of a hole in the plate in the ship, delivered by "essentially what was a glorified coke machine," he said.

Engineering prototypes and simulations showed that the project would work, and it would have cost far less than Apollo. The original plan was to get to Mars by 1965 and the moons of Saturn by 1970.

"The fatal flaw of this scenario, of course, was radioactive fallout," he said, the ill-effects of which were being discovered at the time. "Technically, it worked very well, but it was political death."


Let's colonize space for fun
 

Fineman on Imus


(Picture credit http://en.wikipedia.org)
Excel-web sharing of spreadsheetsLast week, Newsweek's Howard Fineman visited the Don Imus program and had some interesting commentary regarding Watergate and the Felt affair.

Fineman noted that upon his entrance to the Columbia School of Journalism (where else?), his hero was Pulitzer Prize-winner Theodore White, who had authored the best-selling Making of the President  book series.

Upon leaving Columbia, Fineman's new heroes were Woodward and Bernstein, two journalists who transformed the art of beltway reporting. Everything that the pair stood far was not positive, according to Fineman. The key negative point?

Journalism became a de facto opposition party.

Over a period of time, this consistent anti-administration bias gave rise to the likes of Fox News chieftan Roger Ailes. Ailes and Fox News became "the opposition to the opposition party".

In this same vein, the Cassandra Report has its own take on journalism as the opposition party: MSM/DNC - a singular noun.
 

Chủ Nhật, 12 tháng 6, 2005

A Hike up Sandia Mountain



Picture credit: http://www.newmexicoliving.com
Excel web sharing - spreadsheet collaboration over the Internet made easy with BadBlueBrooke has a good write up -- with plenty of pictures -- on his hike up Sandia Mountain. The peak is 10,678 feet above sea level. Challenging under normal circumstances, the trek can be especially taxing for low-landers operating under a self-imposed time constraint.

Hike up Sandia
 

Bizarre, yet useful, Search Sites



I'd like to point out a couple of search sites that I found courtesy of a James Fallows article in the New York Times.

Excel web sharing - spreadsheet collaboration over the Internet made easy with BadBlueThe first is a search portal called Mr. Sapo. Mr. Sapo provides instant comparative access to all major search engines using a simple button metaphor. Enter a search term, then click any of the buttons to see the results for the specified engine. Bizarre name? Check. Odd interface? Checkety check. Pretty darn useful? Check and mate, beenizzle*.

Excel web sharing - spreadsheet collaboration over the Internet made easy with BadBlueThe Mr. Sapo site pointed me to a new search engine with which I was unfamiliar: Exalead. It is very, very interesting. Search on a term and you get a plethora of sidebar windows along with the traditional results. The sidebar windows provide drill-down capabilities over a variety of categories:

  • Related terms

  • Related categories

  • Geographic location of web site

  • Document type

  • Screen captures of each resulting site

  • In other words, support for down-selecting the search results using several useful criteria. Check it out.

    *I am licensed to use teen/hip-hop lingo, given two teens in my current household.
     

    Thứ Bảy, 11 tháng 6, 2005

    So you want to be a phisher


    Picture credit: http://tecfa.unige.ch
    Excel web sharing - spreadsheet collaboration over the Internet made easy with BadBlueLike most Internet users, I've been awash in a deluge of phishing attempts of late. Unlike most users, though, I enjoy tracking down the source of the spam mails, the location of the false storefronts, and their owners. I think I've nailed down the typical modus operandi . Here's the lifecycle of a typical phishing scam, at least so far as I can tell.

  • Phisher uses IRC or similar means to surreptitiously meet with other blackhats and trade, purchase or otherwise acquire stolen credit-card data

  • Phisher uses stolen credit-card to purchase domain name (optional)

  • Phisher uses stolen credit-card to open a shared web hosting account

  • Phisher creates false storefront on new site

  • Phisher uses IRC or similar means to acquire list of open mail-servers or spamming accounts that can be used to send phishing emails

  • Phisher uses mass-mailing software to dispatch thousands or millions of phishing emails to direct victims to the bogus site

  • Phisher waits for the dough to roll in

  • After enough complaints arrive, the web hosting provider will inevitably determine that the bogus site needs to be shut down. At this point the phishing scam -- at least temporarily -- comes to a screeching halt.

    Can we learn anything from this lifecycle?

    I think we can. Hosting providers need to implement a little bit of technology: call it an anti-phishing package (APP). The package would be a process running on each shared server. Using the server's log files, APP would perform the following tasks:

  • Detect any new site (i.e., less than 90 days old) that receives a sudden burst of traffic

  • Examine the traffic for form submissions (GETs or POSTs)

  • Examine the traffic for pages named login, auth, etc.

  • In the event that any or all of these criteria are met, APP sends an automatic email to system administrators. They can then examine the suspect site and shut it down if necessary.

    I would hope that the major shared hosting providers are already running a process like APP.