Saturday, May 31, 2008

Stunned Ickes?



So getting the kids back into a routine after a trip is always a challenge, but it was complicated by the DNC meeting. Just too hard not to watch. Even for my 9 year old. He was transfixed, although he obviously didn't get it all. We started watching when at the "15" vote and chants of "Denver, Denver, Denver" and I wasn't really sure who wont until it became obvious.

And Ickes was quite a treat. How many times did he say "ass?" He did say that, right? And who did he say became more eloquent the more he drank?

Classy, if a bit bitter. But didn't really represent himself (or Clinton) all that well, but I guess we should have expected that. "Hijacked!?"

These Democrats. First Florida in 2000 and now this circus.

(LULAC, hehe, I remember them from Texas)

Pretty rich. The real question is the all this an act to fire up the Hillary supporter and torpedo Obama or do they really believe what they are saying?

(You know, the whole are you a liar if you know you are a liar question. And Is lying to yourself really lying?)

So the new count is Obama: 2,052, and Clinton: 1,877.5 with 2118 necessary to win?

But maybe the fun is really over and I can go back to blogging mostly on Linux again

This Hillary Supporter is an "American" who will vote for McCain

It would be pretty fun to be in DC right now to see stuff like this

Thursday, May 29, 2008

PLA vs. SCADA

From China’s Cyber-Militia: Chinese hackers pose a clear and present danger to U.S. government and private-sector computer networks and may be responsible for two major U.S. power blackouts.

One prominent expert told National Journal he believes that China’s People’s Liberation Army played a role in the power outages. Tim Bennett, the former president of the Cyber Security Industry Alliance, a leading trade group, said that U.S. intelligence officials have told him that the PLA in 2003 gained access to a network that controlled electric power systems serving the northeastern United States. The intelligence officials said that forensic analysis had confirmed the source, Bennett said. “They said that, with confidence, it had been traced back to the PLA.” These officials believe that the intrusion may have precipitated the largest blackout in North American history, which occurred in August of that year. A 9,300-square-mile area, touching Michigan, Ohio, New York, and parts of Canada, lost power; an estimated 50 million people were affected

And Nmap cause the Florida blackout?

A second information-security expert independently corroborated Bennett’s account of the Florida blackout. According to this individual, who cited sources with direct knowledge of the investigation, a Chinese PLA hacker attempting to map Florida Power & Light’s computer infrastructure apparently made a mistake. “The hacker was probably supposed to be mapping the system for his bosses and just got carried away and had a ‘what happens if I pull on this’ moment.” The hacker triggered a cascade effect, shutting down large portions of the Florida power grid, the security expert said. “I suspect, as the system went down, the PLA hacker said something like, ‘Oops, my bad,’ in Chinese.”

And who has heard of Cybrinth or Stephen Spoonamore?

Stephen Spoonamore, CEO of Cybrinth, a cyber-security firm that works for government and corporate clients, said that Chinese hackers attempt to map the IT networks of his clients on a daily basis. He said that executives from three Fortune 500 companies, all clients, had document-stealing code planted in their computers while traveling in China, the same fate that befell Gutierrez.

I saw prove it. Show me the logs of an informed attacker demonstrating knowledge of their target device, protocol, or application. Not, random script-kiddie crap from Chinese Universities. Been there seen that -- as has anyone that has set up a honeynet.

Show me a journalist that has a clue on this topic.

Hat Tip: Marc Ambinder.

Tuesday, May 27, 2008

Air America: MIA in the Rustbelt

So I'm smack dab in the middle of a rustbelt rest area (my daughter is struggling with her PBJ bagel from Einsteins, yeah nice than the ones in Indiana) and scanning the dial there must have been a half-dozen different AM stations playing Limbaugh, and no Air America. No wonder this neck of the woods went to Hillary.

So was forced to listen to RUSH and it was quite amusing (before I became too disgusted) This half-wit women calling in asking for advice from Rush on how to "sell McCain" to her liberal California friends. And I swear there was a 30 seconds and lots of groans before Rush could come up with an answer. "He loves his country. He is for the war," was about the best he could come up with. Wasn't sure he supported the Bush tax cuts or not. Back on the road.

Saturday, May 24, 2008

My VPS (yearly) cost 2.85 Tanks of Gas

So I've been running a VPS box over on RimuHosting for a couple of years now and have been really happy, but I'm trying to "get lean with my IT" just like at my last employer. Plus my wiki has been down since the MoinMoin Vulns, and I really haven't missed it so I figure I'll pull the plug and create a wiki over on http://code.google.com/p/blogfranz/ as well as use there SVN repo for config files and code snippets I want to remember. (For example I just comitted my fluxbox keys and startup scripts)

Why the hell not? Google already owns the keys to the kingdom might as well give them everything else, so that if some dangerous Web 2.0 hacker would compromise my whole virtual presence. What you can do!

Olbermann: Unforgiveable

OpenSolaris 2008.5 Isn't So Bad


OpenSolaris has come along way from that nasty red and blue console based installer I remember using back in the 90s. A nice GNOME based LiveCD. 32/64 bit. GRUB & GNOME. Tolerable package management although there must be some other repos somewhere. Imagine, having to have to built pcap and tcpdump from scratch in 2008, the horror. But it worked!

What didn't work (on my T-61):
  • Xen Dom0 (this is a known issue)
  • Sound
  • Intel 4965 has been sporadic
  • Novatel 727 EVDO card (probably just haven't figure it out yet)
  • VirtualBox/xVM (problems with kernel modules. probably fixable)
  • Compiz (totally hangs the box)
Sort of weird that the JDK isn't installed. But overall they did a nice job with the GNOME theme. Fonts look better than most Linux distributions and seems quite snappy. And of all things nmap (4.20) and NmapFE are in default install. Funny.

Friday, May 23, 2008

Is there a distro that supports dom0 out of the box (on my T-61)?

Not Hardy, Not Edgy, Not FC 8 or 9, Not OpenSolaris 2008.5, Not OpenSUSE 10.3/11. Not CentOS 5.1.

I give up.

Thursday, May 22, 2008

Anatomy of An SSH Brute Force Attempt (In Pictures)

Just for fun I decided to turn on SSH on the dirty interface on my highly secure Debian firewall to see what shows up in LCE.

First I filter on all TCP/22 activity



I'm actually most concerned with the valid logins first so I check them



Whew. Only 2 logins, those are probably OK.I could check and see who they are but I'm too lazy and I'm anxious to get to the invalid logins:



But I want to get a better sense of time. Big spike right has I was recovering from getting the kids ready for school.


I back up to look at the two types of events I'm seeing during this period of attack: failed passwords and invalid users. I actually discovered the other day that there is an SSH error message for failed login attempts where the username is valid but when it doesn't match the address in the AllowUser option of sshd_config. I thought that was cool. Not sure why I'm not seeing these here.



and





Yep, Italy again


inetnum: 141.250.0.0 - 141.250.255.255
netname: UNIPG-NET
descr: Universita' degli Studi di Perugia
descr: Centro Ateneo Servizi Informatici, CASI
country: IT
admin-c: OG6-RIPE
tech-c: FG757-RIPE
status: ASSIGNED PI
remarks: Perugia Academic and Research Network
mnt-by: GARR-LIR
source: RIPE # Filtered

Tuesday, May 20, 2008

OpenSUSE 11 Beta 3 Impressions



My Thinkpad's started dying today, so after doing the long slow drive wipe to what was left, I tried OpenSUSE 11 (64 Bit) Gnome LiveCD, and here the first impressions:
  • Much prettier than Ubuntu, I like all the green (vs. the Ubuntu brown)
  • First Linux distro to get the resolution right through the GUI for a widescreen flat screen with my Thinkpad (only got display mirroring
  • Wireless worked flawlessly
  • Compiz worked flawlessly and snappily (although sound died after it installed)
  • Gstreamer plugins (for Totem) worked if a bit clumsily and Flash plugin auto installation failed (in contrast to Gutsy and Hardy)
  • Seems snappier, not sure if that is the 64 bit kicking in (always been too conservative) about that.
  • Repository auto updates have improved significantly since the last time I used SUSE much
No reason to try this on the server, but I may run this when my new drive shows up in the mail.

Sunday, May 18, 2008

Where did you obtain your academic qualifications to make these statements, Mr. Aitel?

Dave Aitel wrote a must read editorial over on Security focus called Thinking Beyond the Ivory Towers

In the information-security industry, there are clear and vast gaps in the way academia interacts with professional researchers. While these gaps will be filled in due time, their existence means that security professionals outside the hallowed halls of colleges and universities need to be aware of the differences in how researchers and professionals think.

I saw firsthand this gap when my group at Cisco funded security research at some of the leading Computer Science (and even information security) programs (that should know better) in the nation. You'd be surprised how difficult it was to find 4-5 projects to fund a quarter.

Anecdotally, I saw an absolute lack of understanding by some doctoral students (and their well credentialed advisors) about which attacks (against protocols, for example, like basic concepts of the what sort access was needed to the network) were practical or even how they would go about conducting them. No clue. And all the formal methods and literature review meant nothing.

And all I needed was my lame English & History degree from Texas A&M to see that -- well and some experience developing (or even just running) an attack tool or two. Even script-kiddie knowledge would suffice.


BTW, the title comes from the comment from Dr. Neal Krawetz, PhD

UUID and Fstab and Reiserfs (or lack therof) in CentOS

About a month ago, I forgot to blog on the Ubuntu wiki page UsingUIID which shows you how to get the UUID of a filesystem which is now necessary for fstab (has been since at least Edgy).

In short, use the vol_id command:

root@gx620:~# vol_id /dev/sda2
ID_FS_USAGE=filesystem
ID_FS_TYPE=reiserfs
ID_FS_VERSION=3.6
ID_FS_UUID=15987a57-dd66-4276-8645-931291ef7fc4
ID_FS_UUID_ENC=15987a57-dd66-4276-8645-931291ef7fc4
ID_FS_LABEL=
ID_FS_LABEL_ENC=
ID_FS_LABEL_SAFE=


And given all the Debian pain (yes, code and operational diversity is good--and not blindly following the results of automated tools!), I actually put CentOS 5 on my main server at home until I realized that reiserfs (which I've used for quite some time for some irrational reason) is only available with CentOS Plus. Screw that. Ubuntu 8.04 LTS it is.

Best Kids Video: Sabatoge vs. Jozin z Bazin

Which is the least inappropriate for a 9 year old?



or (warning very catchy and gets stuck in your head)

Friday, May 16, 2008

Forgot about Iran, Obliterate W VA (But Spare Jessco!)



This Huffington Post Article has some pretty scary stuff. My wife (who was raised in the Mississippi Delta) thinks this is WORSE than Mississippi.

Wednesday, May 14, 2008

Encrypting Firmwire and Logic (who would have thought)

Haven't read any of my Control Engineering spam for ages but
Protect intellectual property: Encrypt firmware, control code
caught my eye tonight:

Opto 22 released the “Secure Strategy Distribution System, as part of PAC Project version 8.2, the company's flagship automation software suite that includes control programming, HMI development, OPC connectivity, and enterprise database integration components. The software gives OEMs and machine builders the ability to encrypt firmware and control programs so they can only be uploaded or downloaded to a controller via use of a secure encryption key," the company says.

Tuesday, May 13, 2008

AppleCare has been great, well, except...



So I finally wiped my 12" G4 last week and decided to finally get it looked at. Wednesday, less than a 5 minute wait with tech support, who spoke English (obviously one of of those hard working white Americans) and didn't even seem like she was reading off a script. Friday, brought into the Genius Bar. She (notice a pattern here, kind of like when mid year of my 2nd year of teaching, I realized the class that I had the best discussions with was 70% girls) ran some diagnostics could reproduce the problem, but shipped it out anyway and I got it back today by Fedex. They replaced the hard drive. Great! Should have done this a long time.

Except the the awful grinding noise is back again there (obviously a fan) and I've already started populating my PowerBook with apps.

Repeat the process or live with it?

Monday, May 12, 2008

Simon vs. Hoff: Who is Baiting? Who is Switching? And why does this smell like SCADA?

Mainly because I need to get a non-political blog in the top position again (because I'm certainly no expert on virtualization security, but I am a virtualization end user who wants to know! ) but Simon Crosby's reaction to Hoff gives me a feeling of deja view in terms of the bait-and-switch approach to vulns I've heard from some SCADA vendors (or control systems standards efforts) over the years.

Although slightly more sophisticated than spouting off how many bits of encryption a protocol uses, saying that a given protocol is not Internet-facing, or claiming that to fix an implementation flaw in a weak protocol you should upgrade to protocol that uses SSL, some of the security cliches (or at worst, half truths) that undermine his credibility, and even I can recognize include:
  • Open source is more secure...
  • He mentions viruses and virus vendors in his first breath.
  • Equating security fixes with security/insecurity (and slamming VMWare!)
  • Bringing up EAL something or other
  • Mentioning TPM in any context
Knowing a thing or two about mania, I'm also curious about this sort of manic efforts (apart from making it so small you can't even see it) to secure the hypervisor, and whether he is willing to admit that there are some classes of attacks against guests (or, obviously, against the hypervisor) that are unique (or perhaps only possible) in a virtualized environment and that they care about? Or will the AV vendors solve these, too?

Done. There no more faux Hillary (or Hilter) on top. Can sleep now.

Thursday, May 08, 2008

Funniest YouTube in A While



Even better if you've seen Der Untergang but amazingly well done!

But obviously quite vulgar so don't watch if you are easily offended. (I warned you!)

Best Line: "The Voters have stolen my nomination"

Runner Up: "I'm so sick of drinking whisky with those pigs"