Showing posts with label InfoSec. Show all posts
Showing posts with label InfoSec. Show all posts

Thursday, February 14, 2008

ScamAlert: Phishers Target BDO Clients! (BDO Phishing Attempt)

I just received news that BDO (Banco de Oro) is now being targetted by an amateurish phishing attempt. I call it amateurish because the phishers did not even attempt to camouflage the URL to their fake password-stealing website.

Here's the email as sent by the phishers:

Banco de Oro is carrying out a new security prevention exercise this season.
We are updating all accounts to our new SSL server to reduce all
risks of Online Fraud.

Please click on Re-activate Your Online Banking to update your account information to the new SSL server.

http://www.aimcomm.org/mambo2/admini...media/bdo.html


Online Banking Security Team
Banco de Oro © 2008.
All Rights Reserved
Talkin' Tech readers... you have been warned!

Tuesday, October 30, 2007

jailbreakme.com: Jailbreak Your iPhone/iPod Touch By Visiting a website.

I have mixed feelings about this "easiest jailbreaking method ever".  By just visiting jailbbreakme.com, a previously "virgin" iPhone/iPod Touch will be jailbreak-ed opening it to 3rd party applications with minimal user intervention.  This is made possible through the TIFF exploit discovered by a PSP hacker named Niacin.

Well and good for those who does not want to muck around with using SSH (or WinSCP) -- which is a vast majority of iPhone/iPod Touch owners.

But... this also opens up the iPhone/iPod Touch to the dark side of the web.  Picture this:  a "virgin" iPhone/iPod Touch visits a seemingly "harmless website" using Mobile Safari.  But in the background, the seemingly "harmless website" is now capable of running a background process in the iPhone/iPod Touch doing something sinister (like sending out the whole contact list as an email to the hacker, or simply messing up with the system file... bricking the device).

Now, if an iPhone/iPod Touch was jailbreak-ed using jailbreakme.com, the process also patches the system, fixing the TIFF exploit.  Those that have jailbreak-ed their devices using the more arcane methods also has the option to download the TIFF exploit fix.  But what about the majority of users that kept their units untouched?  They are all vulnerable to these types of "attacks".

This is my fear at the moment.  I think Apple will address this TIFF exploit weakness on the iPhone/iPod Touch.  Once Apple releases the official fix through another software update, the firmware 1.1.1 fiasco may happen once again and will render countless devices useless, until the hacking community finds yet another way to circumvent Apple's "fixes".

I guess I'll just have to be content with what I have now -- an iPod Touch with extended capabilities thanks to the iPhone/iPod Touch hacking community (with some level of confidence that it is somewhat safe from the TIFF exploit).

The solution to this conundrum? Apple should immediately release the SDK for this platform and let the developer community enrich the iPhone/iPod Touch platform.

Blogged with Flock

Saturday, October 27, 2007

ISO 20001:2005 Training!

Some of my readers might be thinking why I've been only posting pics for the past week.  Well, there's an important reason for this: I've been sent by my company to a week-long certification training on ISO 20001:2005 Lead Auditors Training.

ISO 20001 is basically BS7799 which, in a nutshell, deals mostly with Information Security audit -- an integral part of my career as an Information Security Specialist.  I will not pretend to know all the aspects of information security and this training has equipped me with the working knowledge of the standards I need to reference from time to time in order to do Information Security Assessment.  A big addition to my arsenal of knowledge because before the training, I am capable of doing the legwork in Information Security Assessment (Vulnerability Testing and Penetration Testing) but I hardly know anything about the pre-assesment part of my job (doing preliminary security audit).

Although I didn't ask for the training, I'm thankful that the company I work with has sent me to this one (it is an expensive and tiring week for me though).  Now I'm well on my way to being a well-rounded information security specialist. :)

Blogged with Flock

Thursday, October 18, 2007

Inquirer.Net: Don’t make your cell phone your confidante

MANILA, Philippines―With cellular or mobile phones becoming almost like miniature computers with memory cards and all, you will have to take extra care when discarding an old one.
Don’t make your cell phone your confidante

This is exactly how a lot of local "scandals" have started:  clueless cellphone owner records himself/herself on the phone with a partner doing the "jiggy".  Months later the cellphone breaks and needs repairs.  Clueless cellphone owner wants to save some money opts to have the cellphone repaired at a neighborhood cellphone stall.  Cellhone technician finds the video, downloads it and "shares" it with his friends.

That scenario is actually a bit tame considering a lot of people are storing sensitive information like credit card numbers, ATM Card PINs, and passwords on their cellphones.  What's worse is that they simply store these data on their cellphone's notepad application!

Here's some tip to those who can't help but store confidential information on their cellphones:
  • If possible, use a "wallet" program that requires some sort of a password before sensitive information can be displayed.  Such programs are available for your cellphone depending on the make and model.  If your phone does not support this, don't store confidential informaton on them!
  • Before selling your cellphone, make sure to restore it to "factory default".  Doing so will wipe out all data on your device.
  • Always have your phone repaired at authorized service center.  If you insist on having it done elsewhere, make sure that you are around while they service your phone to make sure that data is not copied by the "technician".

Blogged with Flock

Tuesday, September 11, 2007

Good News: Worlds Most Powerful Super Computer Cluster running Windows, Bad News:...

Good news to Windows fanboys out there: A New Zealand-based computer scientist Peter Gutman says that a Windows-based computer cluster can be classified as one of the top 10 most powerful super computers in the world.

The bad news is this Windows-based super computer is a part of a botnet dubbed as the "Storm Worm Botnet".

So, how did this Windows-based super computer came into being? According to uberreview.com:

The Storm Worm has spread primarily through infected email attachments, video attachments and infected web pages. The most recent being a malicious .exe file on a page titled “Download Tor.” The rootkit that the Storm Worm installs makes it all but impossible to remove from an infected PC. If you have been infected with the Storm Worm, the easiest means for removal is a fresh installation of Windows.

Now, I'm really glad I'm running OS X and Linux.

technorati tags:, ,

Blogged with Flock

Saturday, August 25, 2007

Sony Games' BioShock Demo with Free Rootkit

This one goes to the dirty tricks department. After the rootkit brouhaha on their audio CDs, Sony is at it again. This time, they have sneaked a rootkit on the highly anticipated game BioShock as reported by GamingBob.

What's really creepy about this news report is that the rootkit looks legitimately from Sony and the "game" is actually just a demo -- A FRICKING DEMO!

Yet another reason why I shy away from non-hardware Sony products. :(


technorati tags:, ,

Blogged with Flock

Friday, August 03, 2007

Stop Thief! Laptop Alarm for PC


Someone has finally came out with a PC-based alarm program for laptops! Mac users has been enjoying a program called iAlertU -- a program that sound an alarm when someone with sticky fingers attempts to steal a MacBook/MacBook Pro but PC Laptop users were left behind.

Not anymore! Available at syfer.nl, a PC-based Laptop Alarm is now freely downloadable. Although the program is not as flashy as its Mac counterpart, it is enough to give PC laptop users with a certain degree of security when using their gadget.

Here's a rundown of its features as showcased in its homepage:

Secure your laptop where ever you are. The alarm is activated when someone tries to log off or shut down your laptop to take it with him.

When the laptop is disconnected from AC-power (someone pulls the AC adapter plug out) the alarm will go off!

When your USB mouse is pulled out the alarm will go off! If someone wants to take your laptop he will definitely pull your mouse out.

technorati tags:,

Blogged with Flock

Thursday, July 19, 2007

Enigma Machine for Sale!

There is an eBay auction for an authentic Enigma machine! I got pretty excited with this because my current job designation is "InfoSec Specialist" and one of the things that gets me off these days is cryptography. For the uninitiated, the Enigma machine was used by the German army during World War II to send encrypted messages to their people in the field -- very much like how we encrypt our email messages using PGP/GPG.

The piece is supposed to be in "museum condition" (whatever that means) but the current bid price as of this writing ($13,100) is too much for my battered wallet.

I'm sure people who are fascinated with old tech will quickly snap this baby up.

technorati tags:, ,

Blogged with Flock

Wednesday, December 13, 2006

Vista Security: Back to the Old Drawing Board!

Don't look now but the much touted Microsoft Vista's most basic "security" is already cracked with weeks before its widespread release. InfoWorld reports that hackers already has worked around the licensing/activation stumbling block Microsoft has implemented on Vista.

This involves running a virtual activation server using a VMWare image, pointing a Vista installation to that virtual server and viola: free Vista installation! The VMWare image is an image of a Key Management Service that distributes Microsoft Vista for corporate installations. Using this Key Management Service image, an unscrupulous person can install any number of computers with a fully activated copy of Microsoft Vista without having to go through Microsoft's own activation routine.

Hmm... now I'm having second thoughts about the much touted "security" of Microsoft Vista -- if the simple activation/installation security can be worked around by skillful hackers, I shudder to think what additional security nightmares Microsoft would face once Vista is "officially" released.

Another reason why I'm glad I'm using a Mac.

Tuesday, November 28, 2006

Oki's Iris Recognition Technology: Cellphone Theft Deterrent and more...

With the Iris Recognition Technology for Mobile Terminals, cellphone users can how sigh a breath of relief and the peace of mind that another layer of protection will soon be available to them. Developed by Oki Electric of Japan, this technology can help lock out unauthorized users of a cellphone from ever using the unit if it is stolen.

It can also be used to authenticate users when doing online transactions, the users' iris can actually replace the tapping out of complex password to gain access to their online accounts. Oki Electric will be exhibiting this technology at the ITU Telecom World in Hong Kong this coming December.

If proven viable, this technology can then be ported over to computer applications, saving users from having to memorize at least half a dozen passwords to the different systems and applications that they need to access.

Friday, October 20, 2006

Good News: Internet Explorer Is Finally Released; Bad News: Vulnerability for IE 7 Discovered

Way to go Microsoft! Days after its long-awaited release, a vulnerability has already been discovered in Internet Explorer 7. The vulnerability (dubbed as "Internet Explorer 7 "mhtml:" Rediction Imformation Disclosure") has been discovered by a security firm called Secunia and according to them, this particular vulnerability affects a fully patched MS Windows XP SP2 running Internet Explorer 7.0.

Back to the old drawing board!

Wednesday, October 18, 2006

New iPods Shipped With Windows Virus/Trojan Too?

This report comes in hot in the heels of the reported virus-tainted McDonalds MP3 players that McDonalds Japan distributed.

An Apple Support Page says that less than 1% of iPods sold after September 12, 2006 were infected with RavMonE.exe Trojan. Apparently, the devices were infected at their manufacturer prior to delivery. That is the official statement of Apple.
Small Number of Video iPods Shipped With Windows Virus
A quick research on "RavMonE.exe" reveals, however, that the actual Trojan that *may* infect the users of the less than 1% of the iPods is called Troj/Bdoor-DIJ and RavMonE.exe is the file where Troj/Bdoor-DIJ attaches itself on the infected Windows system. Windows users with up-to-date anti-virus should be able to detect and delete this critter before it causes damage.

As expected this Trojan does not affect Apple/OS X users because... well.. I think I better stop here before another OS Wars starts.

Monday, October 16, 2006

McDonalds MP3 Player Prize Is Infected with Trojan

Got this from newlaunches.com

Last August, McDonalds Japan and Coca Cola had a promo wherein a customer has to send a "special code" printed on their softdrink cup via SMS to win an MP3 player. 10,000 winners got their hands on the MP3 player which were apparently pre-loaded with 10 music tracks but with an unexpected bonus: A Trojan horse program called QQPass!
mcdonalds.jpg
Symantec considers QQPass as a "low-risk" threat **but** remember that the said trojan came in through a hardware device and was not transmitted via email nor the internet -- meaning QQPass enters the system through its proverbial "front door".

Monday, October 02, 2006

This Just In: Tech Talker is now a Cerfitifed Penetration Tester!

Oh happy day! I just received word that I passed my Certified Penetration Testing Professional exams!

All I need now is something to penetrate...

Friday, September 29, 2006

Pinoy-N.Com HACKED!

The website of the local Nintendo enthusiasts, Pinoy-N, has just been hacked.

Wednesday, September 20, 2006

Torpark Released: Paranoids Rejoiced!


Torpark is a portable browser that is configured to take advantage of TOR (The Onion Router). In a nutshell, Torpark is a browser based on PortableFireFox that preserves the anonymity of its user by using a network of TORs.

The downside of using the TOR network is that access will be slower than usual but that is the tradeoff for preserving your privacy. Torpark has an option not to use TOR but in that mode, anonymity is compromised.

Torpark can be downloaded for *free* here.

InfoSec Alert: New IM Worm Targets AOL Instant Messenger Users

Security experts are warning users of AOL's Instant Messaging service (AIM) that there is a worm that specifically targets them. The worm, dubbed as "W32.pipeline" delivers a file disguised as a JPG image. Once the file is saved and executed on a vulnerable computer, the worm then calls out to various networked computers and downloads a variety of malware including rootkits. W32.pipeline will then spread by sending a copy of itself to all the AIM "buddies" of the infected computer.

More details about this vulnerability can be found at the following sites:

PRNewsWire
RedHerring.com

Again, I'm glad I'm using a Mac. :)

Sunday, September 17, 2006

Friendster is Overcrowded (?)

Got this obvious piece of SPAM from my friendster account:


> ( Manager of Friendster )
> Friendster SYSTEM is getting too crowded!!
> We need you to forward this to at least 20 people. I know this seems like a large number, but we NEED to find out who is using their account. if you do not send this to at least 10 Friendster members, we will delete your account.
> WARNING! We want to find out which users are actually using their account. IF YOU DO NOT PASS this letter to anyone we will delete your account. Sorry for inconvinience.

Well, as far as I can tell, Friendster is far from being overcrowded (MySpace users are far more numerous) and I can't even begin to think how "intelligent" this "manager of friendster" for deleting an account by *not* sending a message to 20 other users.

Well, the bottomline of this post is -- SIMPLY IGNORE THAT OBVIOUS SPAM and please, if you're not sure about the veracity of a message you get, don't forward them...

Sunday, September 10, 2006

Fairuse4WM: How to Make MS Release Patch Faster

One of the niggling problems of using Microsoft Windows is Microsoft's slow/delayed release of critical patches that plugs security holes that allow hackers into your system. This allows hackers/crackers to be one step ahead of users in terms of protecting themselves against security vulnerabilities.

But wonders of wonders, Microsoft was able to deploy a patch that prevents a program called FairUse4WM days after it was released. FairUse4WM is neither a virus nor a security vulnerability. FairUse4WM allows users to strip out the DRM of audio files (mostly music or MP3 files) and allows users who purchased these music to do whatever they want to do with their purchase.

This is a rather disturbing fact since they (Microsoft) prefer to delay legitimate fixes to their inherently flawed OS while they rush over themselves to release a "fix" when their DRM is in jeopardy. What I find really goofy about this is that Microsoft has stopped issuing security patches for "older" Windows versions making users of Windows 98, Windows ME and Windows NT fair game to crackers and botmasters while they have dedicated a team to work around the clock to counteract FairUse4DRM. Is DRM more important than user security? Do they prefer to have a secure DRM than a secure computing environment that is free from virus, spyware and trojans?


FYI: Microsoft releases patches for security vulnerabilities once a month -- a day now dubbed as 'Patch Tuesday'.