Your daily source of Pwnage, Policy and Politics.

[display_podcast]

Episode 352 – IPv6 DoS, $IPv4, EU, MySQL, Dumpster Diving, BofA & SCADA


ISDPodcast Episode 352 for March 28, 2011.  Tonight's podcast is hosted by Rick Hayes, Keith Pachulski, and Varun Sharma.

    

Announcements:

CarolinaCon

When: April 29th, 30th, and May 1st, 2011
Where: Holiday Inn – Glenwood Avenue in Raleigh, NC
http://www.carolinacon.org/

SANS Mentor:  Security 401: SANS Security Essentials Bootcamp Style (Matthew Romanek)
When: Thursday, May 5, 2011 – Thursday, July 7, 2011
Where: Federal Way, WA 
http://www.sans.org/mentor/details.php?nid=24569
Discount Code:  MRPOD10 for 10% savings

SANS: SANS Security 504: Hacker Techniques, Exploits & Incident Handling (Dave Shackleford)
When:  Sunday, May 15, 2011 – Friday, May 20, 2011
Where: Baltimore, MD

My Hard Drive Died

Data Recovery Expert Certification
When: June 6-10, 2011
Where: Atlanta, GA
http://www.myharddrivedied.com/data-recovery-training



@DerbyCon

When: September 30th – October 2, 2011
Where: Louisville, KY
http://www.derbycon.com/

ISDpodcast Mailing List:  http://groups.google.com/group/isdpodcast

Information Security Leaders Survey:
https://www.surveymonkey.com/s/isl-2011-certsurvey



Hackers for Charity Cookbook:  http://www.hackersforcharity.org/hackers-for-charity/hackers-for-charity-cookbook/
Hackers for Charity Cookbook is asking the hacker community to contribute their best recipes to be included in a Hackers Cookbook. ALL PROCEEDS GO TO HACKERS FOR CHARITY!!! 100%.  Submit your best recipes to cookfu@304geeks.com for consideration. First round of submissions are due by 4/1/2011 

Developers Survey:
Chris John Riley needs your help!  He needs developers to complete a quick (10 question) online survey.  The results will be used in an upcoming presentation at BSidesLondon.   So please take the time and take the survey: http://www.surveymonkey.com/s/FH9PFY6 or http://svy.mk/eNJzNC


Intro/Outro Music provided by JimmyZ (http://soundcloud.com/jimmyz)

 

StoriesTool:  IPv6 Denial of Service (DoS) Tool.  http://isdpodcast.com/files/single_ra.tar.gz.  Uses THC IPV6 ATTACK TOOLKIT, to generate single Router Advertisement (RA) messages with different source addresses.  Rather than flood the network as with flood_router6, it allows you to target the IPv6 stack in Microsoft Windows XP, Windows Server 2003, Windows Vista, Windows Server 2008, and Windows 7 to cause a denial of service (CPU consumption and system hang) by sending a lower number at a slower rate.  Original idea came from http://samsclass.info/ipv6/proj/proj8x-124-flood-router.htm.  All we did was create the appropriate single_ra.c and slow_flood script.  This affects all systems on the local-link.

System1:

System2:


 

Source: http://www.bbc.co.uk/news/technology-12859585

Source: http://blog.internetgovernance.org/blog/_archives/2011/3/23/4778509.html

 

Microsoft has offered to pay $7.5m (£4.7m) for net addresses from bankrupt telecoms firm Nortel.  The 666,624 IP version 4 (IPv4) net addresses were put up for auction as part of the sell-off of Nortel's assets.  Blocks of IPv4 are valuable because the pool of this generation of address is close to running dry.  It was predicted that a market in IPv4 would appear among companies facing a costly migration to the newer IPv6.

 

Details of the sale were contained in papers filed to a Delaware bankruptcy court and show that Microsoft's bid was the highest of the 80 firms asked if they wanted to make an offer for the IP addresses.

 

The deal is yet to be approved by that court and anyone who objects to it can file their comments before 4 April.

 

If it goes through, Microsoft will get hold of 470,016 of the IP addresses instantly and the remaining 196,608 will be released as former customers of Nortel are moved to other telecoms firms.

 

IP addresses are used to identify individual computing devices on the internet and private networks.

 

IPv4 allows for a maximum of approximately 4.3 billion devices.

 

That number seemed enough in the early 1980s when the standard was first proposed, however the rapid growth in personal computers, smartphones and other internet connected devices means that addresses have been rapidly running out.

 

Net firms are in the process of moving to version 6 of the IP addressing scheme, which offers more than 3 undecillion individual numbers (3 with 38 noughts)

However, the migration is happening very slowly.

 

In the interim, it is expected that IPv4 addresses will become increasingly valuable.

 

It is not clear why Microsoft wants to buy Nortel's supply, however many companies are keen to avoid the cost of changing their networking systems over to IPv6 compatible equipment.

 

The Microsoft-Nortel deal values the IPv4 address blocks at $11.25 (£7) each, higher than the price many firms charge for a .com domain. This was indicative, said experts, that the market for IPv4 addresses was heating up.

 

Registries that oversee the allocation of net addresses are also working on plans for a re-circulation system that takes IPv4 addresses from firms that are using IPv6 and releases them for use by others.

 

Geordy's comments: Supposedly IPv4 address blocks have not been recovered because it's a highly laborious task to do all of the proper checks to make sure the address is not in use and that makes it cost prohibitive.  Now looking at this though, if we are talking about $11.25 per address, I would guess that we could easily outsource the task abroad for a fraction of that cost.  Is IPv6 the future or is a cycle of address recovery and auctioning blocks off a reasonable stopgap measure for now?  I almost missed this story but when you stop and think about it for a minute, you realize this is the tip of a huge iceberg .  Beyond that, shouldn't IANA be selling these addresses and not (what's left of) Nortel? 

 

The European Commission, including the body's diplomatic arm, has been hit by what officials said Thursday was a serious cyberattack.  The attack was first detected on Tuesday and commission sources have said that it was sustained and targeted.

External access to the commission's e-mail and intranet has been suspended and staff have been told to change their passwords in order to prevent the "disclosure of unauthorized information," according to an internal memo to staff. Staff at the commission, the European Union's executive and regulatory body, have also been told to send sensitive information via secure e-mail.

The event came just days ahead of the European Council summit being held on Thursday and Friday. The summit brings together the leaders of E.U. member states and crucial decisions will be made on economic strategy, the war in Libya and the future structure of the E.U.

This led to early speculation that the source of the attacks may be Libya, but the commission was quick to rule this out. The attack is thought to be similar to the cyberattack on the French government in the run up to the G20 Summit in February 2010. That assault involved malware and targeted e-mail, with some of the related stolen information redirected to China.

Commission administration spokesman Antony Gravili said officials would not speculate on the source of the attacks in such a sensitive security matter. He did, however, confirm that the attackers targeted the information of some commission officials, in particular at the External Action Service, the body's foreign diplomatic arm.

"We are already taking urgent measures to tackle this. An inquiry's been launched. This isn't unusual as the Commission is frequently targeted," said Gravili. He added that there was no concrete evidence that the attack is linked to the E.U. summit.

Source: http://techie-buzz.com/tech-news/mysql-com-database-compromised-sql-injection.html

An email was sent out earlier today on the Full-Disclosure mailing list, detailing the compromise of numerous MySQL websites along with portions of their database containing usernames and passwords.
 

MySQL offers database software and services for businesses at an enterprise level as well as services for online retailers, web forums and even governments. The vulnerability for the attack, completed using blind SQL injection and targeted servers including MySQL.com, MySQL.fr, MySQL.de and MySQL.it, was initially found by "TinKode" and "Ne0h" of Slacker.Ro (according to their pastebin.com/BayvYdcP dump of the stolen credentials) but published by "Jackh4x0r".

 

The stolen database contain both member and employee email addresses and credentials, as well as tables with customer and partner information and internal network details. Hashes from the database have been posted, with some having been already cracked.

 

A submission to XSSed.com also details an XSS (Cross Site Scripting) vulnerability affecting MySQL.com that may have provided a secondary entry point for compromising visitors or employees with the organization since early January of 2011.

 

This is definitely a shame for the folks behind MySQL since they were bought by Sun and later on by Oracle (through the Sun acquisition). MySQL is used by millions of users for small and medium sized databases, including by the popular blogging software WordPress.

 

The email sent to Full Disclosure lists out all the databases, tables and even some password hashes for the users at MySQL.com. There has been no response from MySQL on this issue yet. We have contacted them for a comment and will update this post once more information becomes available.

More updates coming soon….

 

This hack also compromised the database at Sun.com, more info on this at http://tinkode27.baywords.com/

 

More details are available here: http://blog.sucuri.net/2011/03/mysql-com-compromised.html

 

 

Dumpster diving isn't something Saskatchewan's privacy commissioner makes a habit of, but this time Gary Dickson says he was left with little choice.  Dickson and two assistants had to wade through a massive recycling dumpster this week to recover medical files. They sorted through paper more than 1 1/2 meters (5ft) deep after getting a tip directing them to the container behind the Golden Mile Shopping Centre in Regina.
"People would have every right to be concerned, to think that their most personal information is in a large recycling bin for anybody (to read)," Dickson said Thursday.
"In this case, you could stick your hand in through one of the small windows and pull out a file and look at your neighbour's hysterectomy report or whatever.
"It's important … that people in our province have some sense of comfort that when one of these things is disclosed, this kind of a breach, that it's dealt with immediately and their information is safe and is protected. So we seized all of this stuff immediately and the only way we could do that was getting into the recycling bin."
It took a couple of hours to go through the dumpster. Dickson estimates they found more than 1,000 files that should have been shredded.
Whoever tossed the files had to know what they were, he said.
"There was no way this was caught between a couple of old newspapers. No, this was a large volume. Somebody would have had to make numerous trips or either had a massive cart to haul this stuff out to the recycling bin in the first place," said Dickson.
"It would take some time and some considerable effort to dispose of all these things in that fashion."
He's trying to track down who was responsible for throwing out the data, which contained lab results, diagnostic images and other personal health information.
It isn't the first time Dickson has been called about abandoned medical files and he's disappointed that problems keep arising.
The commissioner said doctors, regional health authorities and other health professionals have long been told to follow Saskatchewan's Health Information Protection Act. The act says trustees have to safeguard personal health information in their custody.
There are fines of $50,000 for individuals and $500,000 for organizations for breaching the act.
Dickson said part of his frustration is that no one has ever been prosecuted since the law was enacted in September 2003. He's concerned about what message that sends about the importance officials attach to health privacy breaches.
Justice Minister Don Morgan said the prosecutions branch decides what to pursue on a case-by-case basis and isn't going to "engage in a witch hunt."
But Morgan acknowledged the public is left with the impression that people are getting away with something.
"Of course they have that impression. I mean I have that impression and I don't like it," said Morgan.
"It's being investigated. Maybe this will be the one, and I certainly hope that this would be the one, that would lead to a prosecution."
Health Minister Don McMorris said it was disconcerting to have the privacy commissioner dumpster diving for medical records.
"Absolutely unacceptable," said McMorris.
"The government's role is to make sure that legislation is there and followed. This is a case where obviously it wasn't followed."
McMorris said the government has been talking with the Saskatchewan Medical Association and the College of Physicians and Surgeons of Saskatchewan about strengthening rules for dealing with personal records.

Source:   http://www.geektech.in/archives/615

As H D Moore said on Twitter, either he is the hacker or a lunatic off his meds. For some reason, he sounds a lot like LIGATT in some of his sentences. For example:

"I’m not a group of hacker, I’m single hacker with experience of 1000 hackers, I’m single programmer with experience of 1000 programmers, I’m single planner/project manager with experience of 1000 project
managers, so you are right, it’s managed by a group of hackers, but it was only I with experience of 1000."

Either someone with serious USI, or someone capable.

For me, though, this alone defeated his argument that he has the experience of thousand hackers:

"It was not really a managed hack. At first I decided to hack RSA algorithm, I did too much investigation on SSL protocol, tried to find an algorithm for factoring integer, analyzed existing algorithms, for now I was not able to do so, at least not yet, but I know it’s not impossible and I’ll prove it."

Factoring integers is a NP time algorithm. Its not NP-complete, but its still a hard problem. So if he solves the factorization problem, then he has broken down a whole bunch algorithms that the crypto world is based on; and Comodo hack is the least of our problems.

 

 

Thousands of Bank of America customers' account information could be in jeopardy after a major security breach.

 

Christy Clark went to a Royal Oak drug store Friday, but when her debit card was declined, she knew something was wrong. “I was very embarrassed,” Clark said.

 

She went straight to the Bank of America branch near 12 Mile Road near Woodward Avenue in Royal Oak to report the problem.

 

When she arrived, she was surprised to see the lobby packed with customers who experienced the same issue. “When I entered the branch, that’s when I realized this was a bigger problem,” Clark told Local 4.

 

Bank of America told Local 4 this involves more than $100,000 worth of transitions(sic). Bank employees told Clark they issued a number of temporary debit cards to customers who discovered money was missing from their account. Two bank staffers said they were also victims of this crime.

 

A spokesperson for Bank of America said they are trying to figure out exactly how widespread the problem is. The bank issued this statement to Local 4, “In the event that a skimming device has been used, we are reaching out to those customers to block their cards.” Christy Clarke is grateful the bank is taking action to protect customers’ money. “They could have cleaned out my account.”

 

It remains unclear if these accounts were hacked into internally, or if someone outside the company committed the crime. It is also unclear if this problem is limited to Michigan, or customers across the nation are impacted. Bank of America is investigating all possibilities to see where the money went.

 

Bank of America said if any suspicious activity is flagged on your account, it will be shutdown immediately.

Geordy's comments
: and this will keep happening over and over again until there is sufficient public outrage or federal regualtion that leads to changing our broken banking system.  It's amazing how little security there really is when it comes to something that all of us find as vitally important as our money.  It's continually amazing that it's cheaper for the bank just to accept these losses than to work towards a solution. 

 

 

A Russian security company plans to release an upgraded exploit pack for industrial control software that incorporates a raft of new vulnerabilities released by an Italian security researcher.

 

The three-person company, called Gleg, is based in Moscow and specializes in vulnerability research. It recently began focusing on problems within SCADA (supervisory control and data acquisition) systems, which are used in factories, utilities and many other kinds of industrial applications, said Yuriy Gurkin, Gleg's CEO.

 

Gleg works with the Miami company Immunity, which sells a tool called Canvas, which is a framework for penetration testers wanting to try out the latest exploits against software vulnerabilities, along the same lines as the Metasploit tool.

 

Gleg supplies Immunity with exploit packs, which are add-ons with specific kinds of exploits, for Canvas. Gleg's main product is Agora, which integrates with Canvas. Agora is regularly updated with publicly disclosed zero-day, or new, vulnerabilties and those discovered by its research team.
All works represented here are compiled from various sources (email, IRC, forums, and original author/websites). If the original work is copyrighted it is presented under the fair use of a copyrighted work, Copyright Act of 1976, 17 U.S.C. ยง 107, for purposes of criticism, comment, news reporting, teaching, and research. No use is directly intended as an infringement of copyright. Attribution is always given to the original source, if known. To have any copyrighted material removed, please contact isdpodcast[at]isdpodcast[dot]com.