Wednesday, February 20, 2008

MoinMoin Vulns



Courtesy of a Secunia Feed I ran across the vulns in MoinMoin -- which I my wiki of choice for work or play. I don't allow any authenticated users to edit pages or upload files (apart from me) but I was paranoid enough to take my wiki down for a bit until I've had a chance to understand the issues more or until Ubuntu releases a package.

Update
franz-g4:~ mdfranz$ python hackmoin.py
MoinMoin host: i.e: http://127.0.0.1:8000/
MoinMoin host ( include http and /): http://www.threatmind.net/secwiki/
Ok, the file: README was created, and you can logging setting the cookie MOIN_ID='README' in your browser.


Yeah the exploit does indeed create (overwrite?) a README file in your data/user directory that looks like this:

aliasname=ilikecolombianpeople
css_url=
date_fmt=
datetime_fmt=
disabled=0
edit_on_doubleclick=0
edit_rows=20
editor_default=text
editor_ui=freechoice
email=just@nonrootuser.co
enc_password={SHA}hzAn1bupZwrTEQuFWlZA3TsEcVc=
language=
last_saved=1203553839.72
mailto_author=0
name=nonroot
quicklinks=podriamos-insertar-codigo-php-aqui-verdad-que-si
remember_last_visit=0
remember_me=1
show_fancy_diff=1
show_nonexist_qm=0
show_page_trail=1
show_toolbar=1
show_topbottom=0
subscribed_pages=
theme_name=modern
tz_offset=0
want_trivial=0
wikiname_add_spaces=0

So the question is, so what? Can this be used to erase/reset the password of the Admin user? Not sure. But I did discover a shitload of user preference files in my wiki, yikes! I'm sure they are harmless... I guess the key issue is whether this exploit would allow you to overwrite an existing admin users (through the web UI you can't create a new user for one that already exists, IIRC).

It would definitely appear that if you can guess the time based filename etime.time.anothertime you could.

And here is what the exploit looks like in your logs:

stinkmonkey.cable.rcn.com - - [21/Feb/2008:00:29:47 +0000] "POST /secwikiUserPreferences/ HTTP/1.1" 404 229 "-" "Python-urllib/2.4" "-"
stinkmonkey.cable.rcn.com - - [21/Feb/2008:00:30:10 +0000] "POST /secwikiUserPreferences/ HTTP/1.1" 404 229 "-" "Python-urllib/2.4" "-"
stinkmonkey.cable.rcn.com - - [21/Feb/2008:00:30:39 +0000] "POST /secwiki/UserPreferences/ HTTP/1.1" 200 23341 "-" "Python-urllib/2.4" "-

And yeah it took me 3 times because I kept forgetting the slash (as you can see) and because I'm a "jackass" (to use tqbf's favorite expletive

Tuesday, February 19, 2008

Winter Bedtime Snack


What are blogs for if not showing off your kids and wearing funny hats

Deb of the Day: conntrack

So I was trying (unsuccessfully) to get pyctd installed and was looking doing the dselect dependency dance (yeah, I'm old school) and I ran across conntrack

Being spoiled with PF (or pfctl actually) I always wondered how you could do this in Linux.

# conntrack -E
[UPDATE] tcp 6 30 LAST_ACK src=192.168.2.170 dst=72.14.205.83 sport=52241 dport=80 packets=9 bytes=2262 src=72.14.205.83 dst=24.136.2.99 sport=80 dport=52241 packets=7 bytes=606
[UPDATE] tcp 6 120 TIME_WAIT src=192.168.2.170 dst=72.14.205.83 sport=52241 dport=80 packets=9 bytes=2262 src=72.14.205.83 dst=24.136.2.99 sport=80 dport=52241 packets=8 bytes=658
[NEW] tcp 6 120 SYN_SENT src=192.168.2.170 dst=72.14.205.83 sport=52242 dport=80 packets=1 bytes=64 [UNREPLIED] src=72.14.205.83 dst=24.136.2.99 sport=80 dport=52242 packets=0 bytes=0
[UPDATE] tcp 6 60 SYN_RECV src=192.168.2.170 dst=72.14.205.83 sport=52242 dport=80 packets=1 bytes=64 src=72.14.205.83 dst=24.136.2.99 sport=80 dport=52242 packets=1 bytes=60
[UPDATE] tcp 6 432000 ESTABLISHED src=192.168.2.170 dst=72.14.205.83 sport=52242 dport=80 packets=2 bytes=116 src=72.14.205.83 dst=24.136.2.99 sport=80 dport=52242 packets=1 bytes=60 [ASSURED]
[NEW] udp 17 30 src=192.168.100.25 dst=216.106.191.180 sport=123 dport=123 packets=1 bytes=76 [UNREPLIED] src=216.106.191.180 dst=24.136.2.99 sport=123 dport=123 packets=0 bytes=0
[UPDATE] udp 17 30 src=192.168.100.25 dst=216.106.191.180 sport=123 dport=123 packets=1 bytes=76 src=216.106.191.180 dst=24.136.2.99 sport=123 dport=123 packets=1 bytes=76
# conntrack -L | wc -l
41

"Against" Globalization and Other Laws of Nature




So the Wisconsin Exit Pools show Dems are "against globalization." What the hell does that even mean? I supposed these clowns are against gravity, death, getting pregnant if you don't use contraception, seasons, what else? Maybe they'll vote for Hillary, too.

Sunday, February 17, 2008

YouTube and SCADA: Even Better

Yeah I really need to get some sleep, but out of diapers.

No More SCADA Lists for Me!

At least when I'm irritable from lack of sleep caused by high availability fun. Rad's post on fuzzing was the final straw and bridge began to creak and buckle with SCADA-Drug-Dealer-Gate. Waste of time. Raises blood pressure too much. See ya. Zero tolerance for this... Long story short, not only is L2 fuzzing with SPIKE *not* a topic worth following, has nothing to do with SCADA.

Industrial Defender and "The Wire"

I've been wanting to blog about Season 2 of The Wire (and Omar, one of the best characters, who is supposedly Obama's favorite character, on his favorite show) for a while, but an amusing email forward on the SCADA mailing list from Full Disclosure, called SCADA Security Corruption gives me the opportunity to blog about SCADA and my favorite TV show.



Several years back JP and I spoke at some "security day" at Rockwell Automation in Cleveland, afterwards we got lost on the way to the airport (my driving, no doubt) in some pretty scary areas that looked like The Wire. Based on that experience I don't think JP or any members of Industrial Defender are involved in any sort of illegal activity I've seen on Season 2 of The Wire including customs violations, murder, or sex slavery.

But then again, what is more accurate, google search results or HBO shows? I guess we'll never know. Maybe there is a vast conspiracy of SCADA Security Consultants, Vendors, and Researchers all plotting to not only to annihilate critical infrastructive in a single decisive blow (ordered from abroad, no doubt) and sell drugs.

This reminds me of the time I saw a message thinking that I was the one who stole the IOS source code back in 2005, after all my name was Franz, too.

Saturday, February 16, 2008

Ruby vs. Python (.NET Style)



If Ruby has the lead on the JVM it appears the opposite is true for Python, as Iron Python is miles ahead on .NET (or should I say .DLR/.CLR?). Still trying to build Iron Ruby it about 3-4 CPU-hours in. Of course slow ass Thinkpad-IO which is killing VMWare isn't helping, and the bloat of Visual C# Express 2008 which itself took an hour or two to install over the network.

Wednesday, February 13, 2008

If you have to ask?

12,008

I actually think McCain is right on Iraq (there was an interesting piece on NPR yesterday with a LTC who is retiring, how the average low-intensity conflict last 10 years and only 40% of insurgencies are successful) but this is pretty damn funny.


Tuesday, February 12, 2008

No Thanks I Make...

If you haven't seen this from Season 2 from the BBC Office it is a must watch. How many computer security professionals does this bloke resemble?

SCADA Superheroes!



Continuing on a theme I obviously lack the self discipline that Dale has when it comes to IT vs. SCADA debates as I've been rehashing impossible issues with the SCADA Security Comic Book Crowd over on the new SCADASEC mailing list. Of course it is difficult (if not impossible, but entertaining nonetheless) to have a dialogue with folks that have no idea what you are talking about and are not interested in technical discussions and whose "hearts are hardened" (to get Biblical for a moment) but its been fun to blow off steam (while waiting for the Obama landslide) and sharpen my email skills which have been sort of languishing since I left Cisco. Ah for those happy days of arguing with PSIRT about the dangers of releasing tools that would bring down the Internet.

I did learn that Walt doesn't want me to be involved in securing the refinery "down the street" from where he lives. Well that makes two of us. But of course Jake get's the best line and is once again at least rational.

Matt, I think this point is sort of like asking whether Superman or Batman would win if they got in to a fight. There is no point in asking the question because neither character is real.


See in the upside down of the control systems security not only is CERT arming attackers when they release advisories but the most dangerous enemy is an IT security consultant that has not drunk down the SCADA Kool Aid (patch-free) down in long draughts!


Any security expert who has not carefully internalized these significant differences between enterprise IT security requirements and plant and SCADA security requirements can actually be an active danger to the plant or SCADA implementation-- as dangerous as an uncontrolled attacker.


And kudos to Leif Erickson for being a good sport!

Sunday, February 10, 2008

S.M.A.R.T. on Gutsy T-61

After my my dismal report on my T-61's SATA performance I've been wondering about whether I have everything tweaked right and I tonight I ran across an entry on Thinkwiki about SMART.

Basically if you install the smartmontools package you get a utility called smartctl that allows you to do stuff like


root@gutsy61:~# smartctl -a /dev/sda
smartctl version 5.37 [i686-pc-linux-gnu] Copyright (C) 2002-6 Bruce Allen
Home page is http://smartmontools.sourceforge.net/

=== START OF INFORMATION SECTION ===
Device Model: ST9120822AS
Serial Number: 5LZ1Q720
Firmware Version: 3.CLF
User Capacity: 120,034,123,776 bytes
Device is: Not in smartctl database [for details use: -P showall]
ATA Version is: 7
ATA Standard is: Exact ATA specification draft version not indicated
Local Time is: Sun Feb 10 19:49:22 2008 CST
SMART support is: Available - device has SMART capability.
SMART support is: Enabled

=== START OF READ SMART DATA SECTION ===
SMART overall-health self-assessment test result: PASSED

General SMART Values:
Offline data collection status: (0x00) Offline data collection activity
was never started.
Auto Offline Data Collection: Disabled.
Self-test execution status: ( 0) The previous self-test routine completed
without error or no self-test has ever
been run.
Total time to complete Offline
data collection: ( 426) seconds.
Offline data collection
capabilities: (0x53) SMART execute Offline immediate.
Auto Offline data collection on/off support.
Suspend Offline collection upon new
command.
No Offline surface scan supported.
Self-test supported.
No Conveyance Self-test supported.
Selective Self-test supported.
SMART capabilities: (0x0003) Saves SMART data before entering
power-saving mode.
Supports SMART auto save timer.
Error logging capability: (0x01) Error logging supported.
General Purpose Logging supported.
Short self-test routine
recommended polling time: ( 1) minutes.
Extended self-test routine
recommended polling time: ( 57) minutes.

SMART Attributes Data Structure revision number: 10
Vendor Specific SMART Attributes with Thresholds:
ID# ATTRIBUTE_NAME FLAG VALUE WORST THRESH TYPE UPDATED WHEN_FAILED RAW_VALUE
1 Raw_Read_Error_Rate 0x000f 100 067 034 Pre-fail Always - 196651010
3 Spin_Up_Time 0x0003 099 099 000 Pre-fail Always - 0
4 Start_Stop_Count 0x0032 100 100 020 Old_age Always - 822
5 Reallocated_Sector_Ct 0x0033 100 100 036 Pre-fail Always - 0
7 Seek_Error_Rate 0x000f 059 055 030 Pre-fail Always - 111693386018
9 Power_On_Hours 0x0032 100 100 000 Old_age Always - 149348897784391
10 Spin_Retry_Count 0x0013 100 100 034 Pre-fail Always - 0
12 Power_Cycle_Count 0x0032 100 100 020 Old_age Always - 902
187 Unknown_Attribute 0x0032 100 100 000 Old_age Always - 0
189 Unknown_Attribute 0x003a 048 048 000 Old_age Always - 52
190 Temperature_Celsius 0x0022 062 052 045 Old_age Always - 656801830
191 G-Sense_Error_Rate 0x0032 100 100 000 Old_age Always - 26
192 Power-Off_Retract_Count 0x0032 001 001 000 Old_age Always - 4294967291
193 Load_Cycle_Count 0x0022 026 026 000 Old_age Always - 148448
194 Temperature_Celsius 0x001a 038 048 000 Old_age Always - 38 (Lifetime Min/Max 0/16)
195 Hardware_ECC_Recovered 0x0012 070 042 000 Old_age Always - 196651010
196 Reallocated_Event_Count 0x0010 099 099 000 Old_age Offline - 157255932577023
197 Current_Pending_Sector 0x003e 100 100 000 Old_age Always - 0
198 Offline_Uncorrectable 0x0000 100 100 000 Old_age Offline - 0
199 UDMA_CRC_Error_Count 0x0032 200 200 000 Old_age Always - 0
200 Multi_Zone_Error_Rate 0x0000 100 253 000 Old_age Offline - 0
202 TA_Increase_Count 0x0000 100 253 000 Old_age Offline - 0

SMART Error Log Version: 1
No Errors Logged

SMART Self-test log structure revision number 1

SMART Selective self-test log data structure revision number 1
SPAN MIN_LBA MAX_LBA CURRENT_TEST_STATUS
1 0 0 Not_testing
2 0 0 Not_testing
3 0 0 Not_testing
4 0 0 Not_testing
5 0 0 Not_testing
Selective self-test flags (0x0):
After scanning selected spans, do NOT read-scan remainder of disk.
If Selective self-test is pending on power-up, resume after 0 minute delay.


Here is an article that explains all this junk and smartmontools and this runs on FreeBSD too so this is something to consider on that front, too.

Tuesday, February 05, 2008

Nothing more to say about California


It will be interesting to see how these look in the morning.

And how the delegates get awarded.

I imagine Texas should be closer.

4 Speeches Tonight (and Kansas!)

What's up with these Home Depot's up here closing at 9:30? So I had the misfortune of catching Romney's speech on NPR on the way back. The usual Pre-Globalism cliches that might have worked in the 80s. Make America Great Again, because some country in Asia (where kids still starve and need our vegetables) might surpass us by the end of the 21st century.

Countries (or continents) that have the education level or the fortitude (my 2 weeks in China back in 2004, when we adopted my daughter, convinced me the place was on fire and a force to be reckoned with) deserve to take our jobs away, whether manufacturing or software engineering.

Deal with it! Read some Tom Peters! Go PSF!

McCain's speech was gracious and classy but expectedly mediocre.

I'm so sick of his "my friends" schtick.

No comments on Hillary (except the yellow has to go, Blondes should not wear yellow), but Obama's was amazing. He nailed it. Among the best I heard so far.

If my wife is any indication of change in traditional Democratic voters (vs. fed up Independent Republicans like myself who voted in a Democratic primary for the first time in their lives today) over the last months, the tide has turned.

Around Thanksgiving she liked the idea of Obama (and had actually read his book) but didn't think he had a chance and saw Hillary as the safe choice. And saw defeating the Republicans as the #1 goal.

But with 73% of Kansas (where I was born, actually, but hardly ever lived) for Obama?

And the national unity message continously being refined (along with softly sticking it to the Clintons).

Truly Amazing.

If California no more than a 5 point spread, how can this not be seen as an Obama victory?

Sunday, February 03, 2008

Snowdog!


Please don't cancel school again tomorrow!

Waiting for Super Obama Ad?


So I'm guess Obama's Supposed Superbowl Ad: Join isn't going to show in IL, but look where some of the footage for this ad is shot? Yeah, that's Zilker Park. And that's the Hyatt there on the right, where I presented at in 2000 for some SBC seminar about the February DDOS attacks. That's where we (back when it was just three of us) saw Lucinda on a hot September. I'm guessing there are quite a few Obama bumperstickers in my old neighborhood. And I'm not a huge football fan but I'm pleased with the first half and of course I'm rooting for the Giants.

After watching the ad 3-4 times, what is interesting is the sense of momentum (and of a growing movement?) that it conveys in just 30 seconds. I hope this is real. There isn't that much substance to it, but for someone who is approaching 40 (and more a child of Reagan than Nixon) and only saw videos of protest marches from the 1960s, it seems to have a "60s feel" to it. And In a good way. I wonder how boomers view this ad? Do they resent Obama co-opting this imagery? Although it is upbeat, I like the deft swipe near the end:
We want something new. We want to turn the page. The world as it is, is not the world that it has to be.
Much like his platform, I do not agree with everything in the ad, but I like it anyway. This doesn't mesh with my favorite John Chambers quote from the tech crash in 2001 ("deal with the world the way it is, not the way you like it to be") but I like it anyway. I certainly do not care for the the burned out HMMV juxtaposed against privileged college kids who have not and will never don a uniform, but it is better than the sanctimonious alternative.

Saturday, February 02, 2008

Stupid T-61 vs Dell Optiplex 330 Gutsy Shootout

So I was wondering graphics performance on my son's new workstation is so much worse than on my Thinkpad. In particular bzflag, because I thought they both had the same Intel graphics card, when I bought it. And I was sure it wasn't the CPU? Well it turned out I was wrong and my little benchmark to unzip the Thoughtpolice FreeBSD 6.2 VM had some suprising results. Yeah I know I should get some real benchmarking software but I didn't feel like it.


-rw-r--r-- 1 mfranz mfranz 230671277 2008-02-02 18:08 freebsd-6.3-i386.zip

Intel(R) Pentium(R) Dual CPU E2140 @ 1.60GHz (1GB)
82G33/G31 Express Integrated Graphics Controller
real 0m22.276s
user 0m10.480s
sys 0m1.540s


Intel(R) Core(TM)2 Duo CPU T7300 @ 2.00GHz (1.5 GB)
Mobile GM965/GL960 Integrated Graphics Controller

real 0m45.863s
user 0m10.669s
sys 0m1.492s

Just as I suspected (after finding how fast is your disk it is the IO that is killing my Thinkpad.

root@nikplex330:~/vms# hdparm -t /dev/sda

/dev/sda:
Timing buffered disk reads: 278 MB in 3.02 seconds = 92.13 MB/sec

root@gutsy61:~/torrents# hdparm -t /dev/sda

/dev/sda:
Timing buffered disk reads: 120 MB in 3.04 seconds = 39.44 MB/sec

Of course I'm also using reiserfs on my laptop (out of habit and b/c I've never had any issues) but doubt there should be double.

No wonder my VM's lag so bad some times.

Monday, January 28, 2008

CIO Magazine: What Decade is This?

I ran acrosss an absurd article called You Used Perl to Write WHAT? on one of my Java feeds.
Perl is the granddaddy of the open-source scripting languages, with the 1.0 release seeing the light of day way back in 1987. By comparison, PHP wasn't released until 1994, and Python didn't have its 0.9 release until 1991—only the Unix shells themselves have an older pedigree.
While there are no doubt some pretty intense apps written in Perl, it's time has passed. There are some rare but unfortunate situations when writing shell scripts is justified (*UNIX startup scripts for one), there is no excuse for initiating any new Perl projects in the 21st century.

Perl is not a wise elder. Perl is on life support and it is time to remove the feeding tube or call in Dr. Kevorkian.

Saturday, January 26, 2008

What's is it with the seniors and the newer Compaq ILOs?



It's been a crazy/busy week (hence no blogs) and all I will say is that the newer lights out management boards in HP DL-145G3's and DL-380G5's are on "my list!" I'm watching you! You piece of $*%&#! Although most of it is Java hell, to be honest.

But enough of that, the South Carolina exit polls again showed how the over 60 crowd (traditional Democrats, yuck, probably folks that liked Mondale or Dukakis) tilt for Billary. On the one hand it sort of makes me queasy to hear the Billary on the attack, but its pretty funny how on several of the Air America radio shows I listen to in traffic (Stephanie Miller) or shuttling back in forth between various buildings (Ed Shultz) are going off on the Clintons.

If these Bush-haters are so down on the Clintons, it really does seem the Democratic Party is on edge of screwing themselves over again! Only a patronizing knucklehead like Kerry or a sighing windbag like Gore could lose to Bush. It is not just the genius of Rove, but lack of creative thinking on the damn parties.

Thursday, January 17, 2008

Eee PC for President!


Continuing on a theme I made it by the CDW showroom in Vernon Hills yesterday during lunch and stumbled across a black Asus Eee PC on display.

I spent about 15 minutes unsucesfully trying to find the X-Term (it is there through a key sequence I later found it) and trying out various apps (sans Internet one's because there weren't any open hotspots) are the highlights/impressions:
  • The OS was pretty responsive. OpenOffice 2.x loaded slightly faster than on my T-61
  • Keyboard is really small and difficult to type on initially, but one could get use to it
  • Feels cheap but not flimsy
  • Screen is decent
  • Speakers (and web cam) seemed surprisingly good
  • Startup/shutdown was was within a matter of seconds
  • It appeared to be Kwin + ICEWM
  • The trackpad button was really hard to click, took a surprising amount of effort

One downside was the offical ASUS web sites on the product are awful. I couldn't find any decent manuals but I did find the GPL source. Pretty much everthing requires flash but the EeeUser Wiki had lots of good stuff.

Pretty appealing as a portable Linux platform especially if you consider that the 2G versions are around the same price as an Ipod Touch.

Wednesday, January 16, 2008

"This" close to wiping XP from my T-61

Slow bootup time, flaky WPA with Linksys box at home, and (the last straw, this morning) problems with the Sprint Mobile Broadband connection manager, plus I need the partition. Yeah about time.

Tuesday, January 15, 2008

MacBook Air Wins Michigan!


I'm not sure who the creepy guy (who I sort of resemble If I'd get a haircut) standing next to Romney, but I bet he's not thinking about the the new MacBook Air he just pre-ordered.

Of course neither am I, since I believe in ultraportables that weigh nearly 5 pounds.

But of course they are seductive, although if they are really the same footprint as the MacBooks that is just too big, no matter how thin.

But watching the guided tour was a hell of lot more interesting than the way things have been going in the campaign for the last week and the prospect of a Hillary vs. Mitt matchup is so depressing I won't even go there.

The only comfort is the knowing that we get what we deserve.

Sunday, January 13, 2008

BinData for Ruby Fuzzers

Not that I'm into fuzzing binary protocols/file formats anymore. But if I still wasted my time on that sort of nonsense BinData looks useful enough for that sort of thang:


= BinData is a declarative way to read and write structured binary data.

This is a performance release. Execution speed has been doubled and memory usage has been decreased by about 25%.

== What is BinData?

Do you ever find yourself writing code like this?

io = File.open(...)
len = io.read(2).unpack("v")
name = io.read(len)
width, height = io.read(8).unpack("VV")
puts "Rectangle #{name} is #{width} x #{height}"

It's ugly, violates DRY and feels like you're writing Perl, not Ruby.

Here's how you'd write the above using BinData.

class Rectangle < BinData::Struct
. endian :little
. uint16 :len
. string :name, :read_length => :len
. uint32 :width
. uint32 :height
end

io = File.open(...)
r = Rectangle.read(io)
puts "Rectangle #{r.name} is #{r.width} x #{r.height}"

BinData supports signed/unsigned integers, strings, null terminated strings, arrays, choices and user defined structures.

Saturday, January 12, 2008

HBO's The Wire, Ubuntu DVD Playback, and the best low cost Linux PC for Kids



So the older PIII/Celeron-class boxes I've built for my son are too slow for bzflag so that I'm considering building/getting him a new PC. I'm not wild about it, but he's been using my highest end box at home (an Optiplex GX-620 Pentium D). A Mac Mini would be perfect, but they are just too damn expensive. The price difference between a comparably equipped Dell-n-Optiplex Desktop is probably $300-400. Not worth it.

I've priced out the following at $462: OptiPlex 330 Desktop Intel® Pentium® Dual Core Processor E2160 (1.80GHz, 1M, 800MHz FS, 1GB, 250GB SATA, 3 Year Warranty, Intel X3100, with DVD-ROM.

This is obviously overkill and I could probably skimp and cut $75-100, but since he actually won't be using it that much (although it will be in his room) I can use another VMWare server Box.

So it needs wireless, but since I've had marginal luck with with USB/PCI 802.11 cards under Linux, I'm leaning towards getting a Linksys bridge just so I don't have to mess with it.

He also needs to be able to play music and he's comfortable with the GNOME music tools.

The last considerations was DVD playback. I remember compiling xine, dvdcss and friends from source 5-6 years ago on my T-22 at Cisco but I haven't played a DVD on Linux since then.

Well Linux has come a long way since then and it was a snap on Gutsy was a simple as adding the mediubuntu repository and installing totem-xine. Oh and the other great thing about medibuntu is the dvdrip works great. Kids are hard on DVD's (meaning food and scratches) it only makes sense to rip them so they can watch them over and over.

Oh and you must watch The Wire (which is is supposedly Barack Obama's favorite show) and I do like Omar, as well.

Friday, January 11, 2008

Not SCADA, But Close Enough



While I previously bemoaned Hoff's comments on SCADA his post on train control system hacking is on target. And arguing whether something is SCADA is pointless potato/patato exercise unless you are Joe Weiss (or in the UK, where it does rhyme with patato.)

For me this issue is whether some non-physical-layer electronic attack (I consider jamming a physical-layer attack) against COTS components can effectively used to alter some physical system.

That could be a building control system, that could be rail control system, that could be IP video surveillance and card readers, that could be hacking a food manufacturer to stamp to incorrect expiration date on a bottle of beer.

It's all good. It's all in scope for the FUD game.

Thursday, January 10, 2008

Wow A Ruby Modbus Implementation

Since we know all the cool kids use Ruby (but the smart kids use Python) so cool kids that want to "play SCADA" can now use RModbus to bring down the power grid!

I didn't play around with this because I think the best Open Source Modbus implementation (for SCADA hacking) is Jamod which I previously with Jython but would now probably use JRuby since I'm no longer smart anymore.

Tuesday, January 08, 2008

At least "Mac is Back"

Even if Obama can come from behind (still stuck at 36-39 now, damnitt!) this is a victory for Hillary. But least Romney (and Huckabee and Rudy) were defeated tonight. After all I'm just one of those goofy conservative leaning Independents are smitten by Obama and line up much more ideologically and practically (particularly in terms of Iraq) with McCain. And a party that picked Gore and Kerry (just like a party that picked W) deserves what they get.

Some of these daily dish reader responses nail it:


It's times like this when I remember that political parties, not the American public, choose the nomines. The Democrats turned out for Hillary. If they want her, they can have her. Just please God, give me McCain as the alternative. Otherwise, I'm out.


and


As a lifelong Democrat, come February 6th, I am rerolling (as the kids with their fancy computer games like to say) Independent. This party would rather brawl with, and lose to, the Republicans out in the schoolyard than try to come together and achieve anything loftier than keeping Roe v. Wade as good law.

Someone get me a McCain '08 sticker ... These current Dems would have nominated Adlai Stevenson over Kennedy in 1960


Although I have no idea which party affiliation I filled out a year ago when I got my driver's license up here, but I'm guessing it wasn't Dem.

Wow exploitable MSFT TCP/IP Vulns! Is it 1998 or 2008?

While I'd expect this kind of shit from Cisco (don't ask me what that even means and it definitely has nothing to do with anyone from Finland or the fact I've drinking horribly strong Nordic beer lately) but I was shocked to see MS08-001. Very cool. Maybe I do remember looking at IGMPv3 back in the day and thinking what a mess, so maybe this isn't such a suprise. Nonetheless, seems very old school and maybe there is some attack surface below HTTP.
A denial of service vulnerability exists in TCP/IP due to the way that Windows Kernel processes fragmented router advertisement ICMP queries. ICMP Router Discovery Protocol (RDP) is not enabled by default and is required in order to exploit this vulnerability. However, on Windows 2003 Server and on Windows XP, RDP can be turned on by a setting in DHCP or by a setting in the registry. On Windows 2000, RDP can be turned on by a setting in the registry. An anonymous attacker could exploit the vulnerability by sending specially crafted ICMP packets to a computer over the network. An attacker who successfully exploited this vulnerability could cause the computer to stop responding and automatically restart.
and
A remote code execution vulnerability exists in the Windows kernel due to the way that the Windows kernel handles TCP/IP structures storing the state of IGMPv3 and MLDv2 queries. Supported editions of Microsoft Windows XP, Windows Server 2003, and Windows Vista all support IGMPv3. In addition to IGMPv3, Windows Vista supports MDLv2, which adds multicast support for IPv6 networks. An anonymous attacker could exploit the vulnerability by sending specially crafted IGMPv3 and MLDv2 packets to a computer over the network. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Friday, January 04, 2008

Yuppie Elites for Obama!

Whether or not I'm a yuppie elite, count me in!
As Hillary Clinton looks to rebound in New Hampshire, it appears one part of her strategy will be to cast Barack Obama as the favorite of yuppie elites who aren't looking for experienced leadership so much as they are wanting to ride a trend or indulge a sentiment.
I would like to not feel ill when I hear the Commander in Chief (I was enlisted) on the radio the way I did during Clinton and Bush II. If that is indulging a sentiment, sue me.

I've always wanted to know if I'm a member of the cherished Middle Class politicians alway talk about and pander to? These Middle Class folks I keep hearing about, can they be software engineers or have ever cashed in stock options or worked for Bay Area companies?

I might have been a yuppie elite when I lived in laid back Central Austin neighborhood with lots of 40-something hippie-artistic types (oh the scent of Cannabis wafting across Burnet road), but up here in Skokie on a single income, struggling to pay for overpriced housing, expensive [public] pre-schools, with a few grand in unpaid mental health bills, where I'm afraid to even drive in these old-money North Shore neighborhoods in our brand new Honda minivan. Is that "Middle Class" enough? Maybe Hill is my gal? Forgot about manufacturing, will Edwards should fight to keep my high paying security job from being outsourced to an MSSP? No, I don't want a damn thing. I just want government (and the executive branch, because Congress is a lost cause) to have the appearance of being civil and competent. That's all I ask.

Thursday, January 03, 2008

Could be a long evening (NOT!)


So the Real Time Stats pretty cool, if maddening. God help the Democrats if "Mr. I'll fight for you" so we can have the best jobs. After all we deserve it because just because we are Americans, damnitt!

Update: An hour later, Obama up by 7% with Hillary in 3rd!!!!

And this is a decent explanation which jives with my experience with Obama: following the urging of Radio Paradise (back in June) I wrote to all my representatives about the increased royalities that Internet Radio stations were about to pay. I received a response in less than a day from Senator Obama (I assume a staffer, I hope!) 3 months later from Durban's office and whoever the Representative from Skokie/Evanston: Never.

Wednesday, January 02, 2008

21st Century Ethernet, False Prophets, and other Absurdities



Once again the SCADA Mailing list provides lots of heat but little light. The thread started out mysteriously enough with myrcurial's assertion that in '08 SCADA was just but too lame to bother hacking (on a related note check out Dale's recap of Ralph Langners view on CCC Hacking SCADA) degraded into the usual whining. Much like the Obama vs. Clinton, a lot of the argument falls out based on age and experience, with some of the more senior folks having some crazy ideas not based in reality. I swear I heard the dumbest Hillary supporter on All Things Considered this afternoon, you know the one that wanted Hillary right after Bill.

As much as I tried,there is nothing to say here except to ponder each of this and their ironic potential, especially when taken out of context:

"we have met the enemy and it is Ethernet."

More and more, thanks to very clever marketing departments, customers are ever more eager to convert their "old" industrial control networks to Ethernet. Perfectly adequate systems that are running isolated and safe.

Whuy? Well, Ethernet is just so cool, so 21st century. Web browser interface, etc... What could be cooler? Techs and engineers want to work with the latest technology, it improves the resume, makes one more marketable, right?

What results from this rush to Ethernet?

Well, for one thing, there is clearly a lack of decent IT talent to maintain that many critical SCADA systems (many existing personnel can barely understand serial networks - believe me, 25+ years in the business - I know.)

Ethernet invites connection to company LANs through firewalls.

Firewalls get penetrated due to the same lack of IT talent to maintain their robustness.

Joe Weiss speaks the truth. The you-know-what is going to hit the fan, it's just a question of time.

Friday, December 28, 2007

Down Came the Snow, Down went RCN Cable

Coicidentally with the snow today, RCN went to hell again but my Debian EVDO Router was ready. Actually got rid of the OpenWRT box (wasn't using the wireless anyway) and switched to wvdial, which has done a great job of automatically running pppd if the connection drops.

/etc/rc.local
if mount /dev/sr0 -t iso9660 /mnt
then
echo "Found Novatel u727"
sleep 3
umount /dev/sr0
eject /dev/sr0
fi

echo "1" > /proc/sys/net/ipv4/ip_forward
iptables -A POSTROUTING -t nat -o ppp0 -j MASQUERADE
sleep 10
wvdial &


/etc/wvdial.conf
[Dialer Defaults]
Modem = /dev/ttyUSB0
Baud = 460800
Init = ATZ
ISDN = 0
Modem Type = USB Modem
Phone = #777
Username = ''
Password = ''
Carrier Check = no
Stupid Mode = yes


Obviously need to clean up the iptables rules, although I'm not terribly worried about it.

Best WRT54G (v3) for Intel 4965AGN

I've been having a hell of a time with the Wireless card in my T-61and my Linksys router (firmware v1.02.0, Jan. 16, 2007) for the last few days. No problems with the OSX on either my Powerbook G4 (Broadcom) or my wife's Macbook (Atheros). Some of these were screwups on Ubuntu but there definitely appear to be some issues with this card and some Linksys WPA configurations. Under XPSP2, I was becoming dissasociated 3-4 times an hour and with WPA2 Personal (TKIP+AES) would not even work with LInux

I believe these are the default settings which seem to work the best:

WPA Personal
AES
Group Key Renewal - 3600

If you don't believe me, at least believe Chris Rock

Although not as good as the line about him not being afraid of "the media" robbing him at an ATM machine, this isn't bad either

“I love Hillary Clinton,” he continued, “but to me she is the Democratic version of George Bush: someone who is running, and the only reason you know who this person is is because of their name.”

But seriously, Check out Obama's latest speech from Iowa

That's the kind of change that's more than just rhetoric - that's change you can believe in. It's change that won't just come from more anger at Washington or turning up the heat on Republicans. There's no shortage of anger and bluster and bitter partisanship out there. We don't need more heat. We need more light. I've learned in my life that you can stand firm in your principles while still reaching out to those who might not always agree with you. And although the Republican operatives in Washington might not be interested in hearing what we have to say, I think Republican and independent voters outside of Washington are. That's the once-in-a-generation opportunity we have in this election.

I've been pretty cynical about politics (and most things over the years) but I actually contributed a few bucks to his campaign. I haven't decided who I'll vote for (or if I'll even vote) but I do know for damn sure who won't be getting my vote: Clinton or Romney.

Wednesday, December 26, 2007

Novatel u727 on Debian Etch

I previously blogged on getting this card working on Ubuntu but obviously nobody tried my instructions because it wouldn't have worked. The bizarre thing is that in order to get the USB serial devices to show up, you have to first mount the "Novatel CD" device that gets detected, unmount it, and then eject it. This only has to be done once after the device is powered up ( meaning if you unplug it) so here is what I added to the /etc/rc.local an old Optiplex 100 running Etch so things get automatically setup.

if mount /dev/sr0 -t iso9660 /mnt
then
echo "Found Novatel u727"
sleep 3
umount /dev/sr0
eject /dev/sr0
sleep 10
pppd call sprint
fi

The only thing left is to add an iptables commnad to masquerade everything out the ppp0 interface and I have my backup EVDO gateway. Well and change the default route on a box or two -- or get VRRP working.

So the next time RCN hits the fan (must have been the weather) I'll power up this box and plugin the EVDO adapter and I'll be good to go.

Sunday, December 23, 2007

Aspen: A Python Web Server You Can Get Excited About



A year ago (or at least over Christmas and New Years) I was playing a lot with Django (and reading about WSGI) so its fitting I ran across Aspen.


Aspen is designed around the idea that there are basically two kinds of websites, publications and applications, differentiated by their organization and interface models. A publication website organizes information into individual pages within a hierarchical folder structure that one navigates by browsing. In an application website, on the other hand, data is not organized into hierarchical pages but is dealt with via a non-browsing interface such as a search box.

The HTML version of this documentation is an example of a publication website: a number of hypertext documents organized into sections. If we weren't using LaTeX (or if I knew how to use it better), the sections would probably be encoded in folders. Gmail is a pure application website, one which organizes and presents information non-hierarchically. Most websites, however, are hybrids. That is, within an overall hierarchical organization you will find both individual pages of information as well as applications such as a site search feature, or a threaded discussion forum.

Publication websites are actually a subset of application websites, of course. An application site can use any interface metaphor; a publication is an application that uses the familiar folder/page metaphor to organize and present its information. Therefore, every website is fundamentally an application.

Aspen enables the full range of websites: publications, applications, and hybrids. It uses the filesystem for the hierarchical structure of publication and hybrid websites, and provides a mechanism for including applications within that hierarchy.


Based on the screencast, it looks very cool. Why? It is so un-Ruby: well documented, it supports multiple frameworks (a Python HTTP server that support PHP!) and Conan O'Brien-style talking faces. Hopefully I'll be able to squeeze some time away from baby care to play around with it.

Saturday, December 22, 2007

Open Source NAC and A [Kind of/Sort Of] Agentless Endpoint Posture Assessment for Debuntu Boxes

Previously I described a quite common situation I've encountered where non-compliant laptops and OS's are used by members of security teams, frequently in violation of technology/security policy (anyone else know the term "shadow IT"?) Another use case might by highly-skilled/trusted security consultants that could own your ass if they wanted to and probably already have the keys to the kingdom. A reader noted that one solution would be just to grant an exception to policy for these [already] trusted users, but this doesn't sit too well with me.

I personally would like to have some additional layer of monitoring above and beyond good-faith adherence to policy and the desire to do the right thing. The various Open Source NAC toolsets that are out there (many which seem to be developed within Universities) such as packetfence, FreeNAC, or RINGS seem like overkill and clearly inappropriate for this sort of user base.

What I had in mind was something much lighter weight that:
  • Runs with user-level privileges
  • Requires minimal level of installation, perhaps simple Ruby/Python script minimal to no third party libraries
  • Communicates to a server vs. having the server interrogate the client (i.e. no agent listening for connections back from a centralized server)
  • Provides flexible execution (run as a startup script or within desktop environment, gnome-session something or other)
  • User authentication against to some sort of directory server (so we can associate a given endpoint with a user)
An initial environment would be Debian/Ubuntu (although OSX would be nice, too) that could provide the following information to a Rails/Django web app
  • Linux kernel version and running kernel modules
  • Last apt-get update
  • Hardware (both real and virtual)
  • Whether or not filesystem encryption is enabled (look for /dev/mapper stuff)
  • Information about packages (such as the output of a dpkg -l)
  • Listening services (netstat or lsof)
  • Network information (interfaces, routing)
This assumes that there is something NAC-like (in the sense of segregating non-compliant PC's to a certain network/tunnel) or that users will voluntarily run some sort of script upon login.

That being said, as easy as this is to imagine, I'm sort of ambivalent about the usefulness of something like this (perhaps I've heard too many of the arguments about NAC "fighting the last war"), but it doesn't seem like it would be terribly difficult or time consuming to whip up a small client script that pulled together some basic Linux system information and sent it to a CRUD webapp to provide some basic auditing and reporting. And it wouldn't be much of a stretch to add some policy definition/enforcement based on the data or tie it to a iptables/PF box with anchors to implement different access profiles. Obviously, unlike most of the commercial (or even the Open Source) NAC solutions) this is a L3, n-hop-away solution. No 802.1x, no DHCP, no VLAN assignment, but it is actually deployable and might immediately provide some useful (and perhaps even actionable) information that is higher fidelity than a scan the endpoint with Nmap/Non-Auth Nessus or use passive device/app fingerprinting which seems a waste of time for the problem at hand.

Is there anything out there along these lines?

Thursday, December 20, 2007

Sprint Novatel u727 on Ubuntu 7.10

Add vendor and product options to /etc/modules

usbserial vendor=0x1410 product=0x4100

Disable automounting of USB serial devices with gnome-volume-properties

Otherwise the USB Serial devices won't show up and you would have to unmount WTF that image that is being mounted from the

Create /etc/ppp/peers/sprint
/dev/ttyUSB0 # modem
115200 # speed
921600 # works, abt 60kbytes/sec on S620
#1036800 # doesn't work
defaultroute # use cellular network for default route
usepeerdns # use the DNS servers from the remote network
nodetach # keep pppd in the foreground
crtscts # hardware flow control
lock # lock the serial port
noauth # don't expect the modem to authenticate itself
local # don't use Carrier Detect or Data Terminal Ready
user
ppp
#passive
debug
lcp-echo-failure 4 # prevent timeouts (1of2)
lcp-echo-interval 65535 # prevent timeouts (2of2)
connect "/usr/sbin/chat -v -f /etc/chatscripts/sprint-connect"

Create /etc/chatscripts/sprint-connect

TIMEOUT 10
ABORT 'BUSY'
ABORT 'NO ANSWER'
ABORT 'ERROR'
SAY 'Starting SPRINT connect script\n'

# Get the modem's attention and reset it.
"" 'ATZ'
# E0=No echo, V1=English result codes
#OK 'ATE0V1'

OK 'ATDT#777'
CONNECT

Start pppd

root@gutsy61:~# pppd call sprint
Starting SPRINT connect script
Serial connection established.
using channel 1
Using interface ppp0
Connect: ppp0 <--> /dev/ttyUSB0

I might add links to the source materials (cause I obviously didn't come up with this all on my own) but this should work.

Hello Sprint EVDO Goodbye AT&T DSL!



Although I haven't yet managed to cancel my AT&T DSL order yet (I only had 5-6 hops before giving up, which reminded me of the reason I a year ago never to use them again) but after 24 hours I've given up. The service tech was nice enough, but DSL Self Install kit never arrived and I could never get a dial tone. Maybe the three daisy-chained telephone network interfaces had something to do with it. Or maybe it was the rats nest mix of Cat 5 and 1950's era kit, but I started looking for wireless alternatives. I've only been logged with the Novatal U727 (on my Powerbook, it supposedly works with Linux, too) for 32 minutes but so far so good.

Wednesday, December 19, 2007

WTF is "spock power" and why does it think I know Wietse Venema?

Well some folks in my LinkedIn network are now sending me spock trust invitations. Sure why not? Live on the edge. Invite more identity theft. Some of the obvious differences (besides all the tagging) between LinkedIn are that (I guess) you can trust someone and they might not trust you and that you (and your community?) can vote on various attributes (tags?). Another nice feature was the automatically generated (via google) content that you can also vote on. For example I was able to vote down a Matthew Franz's (in Arizona) MySpace page. Maybe I should get one of those too, assuming they let folks over 30 even use it. Nah.

Tuesday, December 18, 2007

Smartphones, Dementia, and the Demise of the PDA Market


I've never been a fan of $300 phones that can easily be dropped [into a bathtub] by your kids, or eaten by your dog but I ordered one of the Palm Centro's (from Sprint) over the weekend. Of course I had to cancel the order because not only did boneheads at Sprint interrupt an important call with my son's Dr. yesterday to confirm the order I placed over the weekend, but they wanted me to fax a copy of my drivers license and a bank statement F--- that. Like I have time to fax something somewhere. And I'm certainly not going to give them a bank statement. Why the hell do they need that if they've already done a credit check?

But, basically, I have felt like I've been losing my mind.

I have assumed most of the administrative/transportation/[child|pet]care duties while my wife recovers from the C-section. I can't remember names. I don't have all the phone numbers of neighbors, zillions of school officials I'm dealing with, various meds, and I only can only remember the times of appointments to the nearest 4 hour granularity.

I needed a PDA! That will solve my problems. But who uses PDA's anymore? Do they even sell them? Or perhaps a phone with decently calendaring and todo lists. That's all I want. No MP3 player. No camera. No shitty web browser. Why don't these devices exist? There were a couple of Samsung's (since the first little Startec I had when I worked at SBC I have loathed Motorola devices) that might have worked, but I don't want to sign another contract to get a decent price.

So I desperation, I picked up a Z22 (you can't spit without running across a Best Buy on this side of town, but good luck finding a Sprint store, of course now I just realized they sell Centro's at Best Buy, but no matter). Small and $99 and I didn't need to get new cell service. Whether or not it actually works, the GTD principle of dumping as much of the things you have to do/decide to do onto paper (or some electronic form) to avoid thinking about them (as a means of de-cluttering and de-stressing) has always seemed appealing. And it appears to be working.

And the Z22 feels very comfortable and soothing. I've had 5-6 PalmOS devices over the last decade. My 2nd CLIE was pro bably the best (before my dog cracked the screen) but Sony exited the market 3-4 years ago. It is a shame, because palm got a so many things right: a simple desktop and graffiti. I have looked at Window Mobile, Pocket PC, or WTF it is called but it just feels klunky. And of course you can't sync to Linux or use something like JPilot or pilot-link right?

Monday, December 17, 2007

Quick Blog Break to Retain Sanity (and Ron Paul cracks $12 million)

Back in May I first blogged on Paul. BTW, the number of political blogs are directly proportional to the stresses and strains of everyday living, but who would have thought they'd play Bush as Paul crosses 12 Million (Youtube video) and gets Andrew Sullivan's endorsement

But the deeper reason to support Ron Paul is a simple one. The great forgotten principles of the current Republican party are freedom and toleration. Paul's federalism, his deep suspicion of Washington power, his resistance to government spending, debt and inflation, his ability to grasp that not all human problems are soluble, least of all by government: these are principles that made me a conservative in the first place. No one in the current field articulates them as clearly and understands them as deeply as Paul. He is a man of faith who nonetheless sees a clear line between religion and politics. More than all this, he has somehow ignited a new movement of those who love freedom and want to rescue it from the do-gooding bromides of the left and the Christianist meddling of the right. The Paulites' enthusiasm for liberty, their unapologetic defense of core conservative principles, their awareness that in the new millennium, these principles of small government, self-reliance, cultural pluralism, and a humble foreign policy are more necessary than ever - no lover of liberty can stand by and not join them.
He's the real thing in a world of fakes and frauds. And in a primary campaign where the very future of conservatism is at stake, that cannot be ignored. In fact, it demands support.



Paul is likable enough, but I'd still have side with the only other authentic candidate on the Republican side. I mean I like crazy (McCain, like Paul has that sort of crazy edge) but Paul is just too out there. But I doubt either will get the nomination, barring a miracle. Of course the amazing thing is that (about 14 hours into my wife's labor) we watched the last Republican debate and she actually liked Huckabee. (And she will vote for Hillary, if she gets the nomination) And I'm still struggling with how the Christian Right can actually support him, when he sounds socially (if probably not culturally) liberal enough. Weird.

Back to the kid-ferry.

Sunday, December 16, 2007

Into the World


I've gotten hooked on Andrew Sullivan's the View from your window so I thought I'd add mine.

The snow has finally stopped and we are going home.

Thursday, December 13, 2007

Welcome Samuel Austin!




12/12 @ 10:38 CST - 8 lbs 14 oz much bigger than expected!


(Would have got this up sooner but had to setup a quick squid over SSH to get through websense)

Tuesday, December 11, 2007

AntiDote for Bad Customer Service Experience and Icy Roads

Between dealing with RCN and a clueless United Behavioral Health rep yesterday thinking I last had service in 2001 (this is my first bad experience with them, otherwise they are awesome and kick Magellan's ass) there is a need for some humor so check out the Immanual Kant Attack Ad (by Nietzsche) and Ron Paul's favorite Super Hero and Andrew Young's absurd comments on [Bill] Clinton and Obama who claims he was the first black president because he has slept with more black women than Obama.

Oh and on the not funny (but reassuring that conservative support for Obama is not a vast right wing conspiracy) this National Review article mocking the Messianic Obama.

Unfortunately, must leave warm Panera, get on the icy roads, and go to work.

RCN Cable Internet: Fun while it lasted



I knew I should have learned more about Cable when I was at Cisco (although I vaguely remember trolling EDCS for one of my projects so the CMTS acronym sounds familiar) but my 2nd attempt at using Cable provider is coming to an end, anyway. After 10 months of nearly blip-free service (not bad for $29.95 a month) with RCN, things have gone to hell in the last week. God I miss Speakeasy, but a year after swearing never to give another dime to AT&T/SBC, signed up for AT&T Yahoo DSL and even bought one of their little gateways so I don't have to muck with PPPoE (I hope) over the weekend just in case. I don't look forward to dealing with AT&T but what can you do? Maybe two shitty $29.95 Internet Services are better than a single decent $55/month service. And we'll actually have a land line for a change.

Although working as first line support for a consumer Internet provider (even if you are offshore) must suck, it was a surreal experience dealing with them for 3 hours last night, but I did learn a little bit about these mysterious cable modems

Toshiba Cable Modem Diagnostics Page

CM Info: MODEL PCX2500 ; HW_REV 9.2.3 ; SW_REV 1.0.14
MAC Address 00-00-39-xx-xx-xx SerialNO. 3316470xxx Version Capability D1.0

CmStatus:todEstablished ServerBootState:waitingForTftp
sysUptime:0d:00h:02m:15s CMTS MAC Address:00-30-B8-C6-EB-90
Last CmStatus - prior reset:

Power Level:
Received: -13.1 dBmV Transmitted: 45.1 dBmV

Received SNR: 28.0 dB

Frequency:
Downstream: 735.000 MHz Upstream: 33.000 MHz

User Set Parameter:
Polling Time: No Polling

So besides the high packet loss, on all my devices (2 routers and 2 different laptops) I kept getting leases for 192.168.100.2 (the tech support folks said it must be a configuration error on my end) which reminded me AirLink Cellular Modems we used in the SCADA Honeynet, where the modem itself has a DHCP server which temporarily assigns you a private address before forwarding your DHCP requests and then turning into bridge mode (or whatever) and then your interface finally gets a public address. So I unplugged the coax and sure enough I got a private address (192.168.100.1 was the router) did a quick TCP scan and found the web server up (see the display above) Didn't bother with UDP, would probably find TFTP and some other stuff. Of course one of the bizarre things was that at some point during all my troubleshooting I saw the 172.30.88.1 (the tech said this was also the Cable modem) attempting to ping a 208.x.x.x address. But I saw that on the Ethernet side? Something clearly must not have been well on the modem. And try as I could, I ended up hanging up, because there was obviously going to be no resolution.

Saturday, December 08, 2007

Saint Barack of Iowa


So after reading the latest cover story on Obama it's starting to get creepy how how the conservative press (and perhaps even certain kinds of conservatives, which I am probably one) are fawning over Obama. What is up with this? Is this support real or is a cynical Anything But Hillary agenda based on the foregone conclusion that the Republicans have no chance in '08.

In my case, I've only voted in two Presidential elections since I was of age (1988 and 2004) and I voted for a Bush in both, but real soon now you are likely to see Obama '08 bumper stickers on both our blue Hondas and I might even contribute 25 bucks. Both would be a first for me and this might be the explanation of why someone who can't help find Rumsfeld and Cheney amusing (and not frightening) would even consider Obama

This is the Obama trick, and it explains why, despite his very liberal voting record in the Senate (and in the Illinois Senate before that), he is not viewed as a left-wing ideologue. When a student asks Obama for his views on the Second Amendment, he reminds his audience that he taught constitutional law at the University of Chicago and is thus familiar with the arguments regarding the right to bear arms. He acknowledges "a tradition of gun ownership in this country that can be respected," and says that his academic studies convinced him gun ownership "is an individual right and not just the right of a militia."


Or perhaps I'm just politically schizophrenic, since I certainly do not agree with his entire platform -- particularly on Iraq, which I'm much more in line with McCain. Of course my strange enthusiasm for Obama (although I'm ambivalent about his speech at Google but I did like his "not bubble sort" answer to a Google interview question) leads to some interesting discussions with my wife who "likes" Obama (and has actually read his memoir, I have not) but is willing to settle for Hillary because she thinks Obama is unelectable. And she thinks the "Republican machine would crush him." She also thinks McCain will be the Republican candidate. I wish that were the case (and I liked McCain in 2000) but it ain't gonna happen.

Wednesday, December 05, 2007

SCADA Compromise in 08? Bring it On!


So as yet another sign that SCADA is out of the closet, it made Hoff's 2008 [In]Security Predictions.

Be-Afraid-A of a SCADA compromise...the lunatics are running the asylum! Remember that leaked DHS "turn your generator into a roman candle" video that circulated a couple of months ago? Get ready to see the real thing on prime time news at 11. We've got decades of legacy controls just waiting for the wrong guy to flip the right switch. We just saw an "insider" of a major water utility do naughty things, imagine if someone really motivated popped some goofy pills and started playing Tetris with the power grid...imagine what all those little SCADA doodads are hooked to...


Call me cynical, but was has changed to make things worse in the last five years that would increase the liklihood of a "SCADA Compromise" (WTF that means). While things are probably different (meaning better, more rational) inside in large asset owners, in public forums the IT vs. Control System debate is as unealthy as it was back in 2003. Many control systems folks are still intent on making broad generalizations based their own bad experience with "IT".

What we're seeing here is a clash of technological focus and philosophies. IT departments don't do risk analysis the way Control Engineers do. Often things are replaced only because they're going to be out of date real soon now. Many throw software and servers at the wall until something useful sticks. I've heard estimates that up to 1/3 of all IT projects are regarded as failures. Few seem to see anything wrong with this. They take the risk anyway, knowing that the payoff can be very lucrative. Conversely, the control engineer tends to run a risk analysis on everything before making a move. They're very conservative and often don't change anything unless there are no parts for it any more and they've run out of spares. Their bosses are penny pinchers. They won't spend money to invest in anything that isn't broken.


and
And the fundamental difference between the IT department and the industrial control system engineer is that the engineers usually work at the application level. There is very little knowledge of the OS under the hood.

It pretty easy to come of with counterexamples for these. For every Areva admin that has no clue about Windows 2000 and TPKT/COTP, I'll bet there is an Oracle DBA that is equally clueless about Solaris 2.8 and TCP/IP.

But the more interesting question of about high visibility critical infrastructure compromise scenarios is why they aren't happening vs. how they could happen.

Tuesday, December 04, 2007

Conveniance Laptops/Operating Systems in the Enterprise



In most of the [security] teams I've been a part of in large companies, the first step an engineer would do upon receipt of new hardware (whether lease or purchase) was to immediately purge the box of the official corporate (always Windows) install and install your own OS (typically some Linux flavor, but perhaps BSD). More recently, you might purchase you own hardware (often a Mac) possibly in clear violation of the corporate security policy.

If you needed a rationale, it was because the standard IT image didn't allow you to do your job. Yeah you might be able to build and run libdnet/libpcap based apps on Windows, but why would you want to. You needed the right network, development, and security tools -- which in an of themselves are most definitely a violation (that is if the policy applied to you, since you were special, you were a security genius!). A fringe benefit was that you were free of the nasty IT-installed agents that suck the life out of laptops and the corporate spyware monitoring your every move. Oh yeah, and you also were more up to date on security packages than the IT build.

So with NAC and other endpoint control regimes designed to stamp out these rogue systems, there is the real possibility of controlling access to campus or remote access networks to "supported systems." What is a passive aggressive security guy to do? Sure, there are ways to subvert these controls, but you want to do the right thing, sort of. It is one thing to simply ignore policies that really weren't designed for you in the first place. It is another to actively thwart countermeasures. And then there is stuff in between like reverse engineering the "software token" so that a Linux user can enjoy the benefits of hardware token free authentication that the Windows users enjoyed.

And no this last example wasn't me (I'm not smart or motivated enough) but you know who you are!

Sunday, December 02, 2007

Control System Security: Two Man Enter One Man Leave



Because I know a lot of the players and because its sort of quaint, I continue to follow the trials and tribulations of "SCADA Security" community I used to be part of while I was at Cisco and later, Digital Bond. I'd love to do the color commentary, but I'll just hit the highlights and let you make up your own mind. But believe me I am biting my tongue.

I'm assuming this whole spat started with Dale's Blog on a Wonderware NetDDE Vulnerability which led to Joe's Weiss Cybersecurity disclosures– the game everybody can play:

The way that the cybersecurity establishment has presented the Wonderware disclosure on the Digital Bond website clearly shows the lack of control system expertise in the cybersecurity “industry.” It IS an industry, and it is filled with people from IT security and cryptographic analysis backgrounds who have rarely, if ever, set foot in a control room for a process plant, refinery, or power plant.

It isn’t enough to be able to understand a vulnerability. It is every bit as important to understand the relative danger of the vulnerability IN CONTROL SYSTEMS. For example, the Wonderware disclosure isn’t very dangerous. Why not? Because the vulnerability disclosed is limited to a very small population of control systems using an outdated version of the Wonderware software. Like the ICONICS issue, revealing a vulnerability without a corresponding assessment of its impact is not only detrimental, but could be viewed (and certainly would be by Wonderware and ICONICS, for example) as unnecessarily injurious to their brands.

Which was followed by an exchange between Dale and Walt that almost didn't happen.
We have a serious problem in cybersecurity in control systems…we don’t have enough “cybersecurity experts” who know anything about process control or factory automation. We have a bunch of soi-disant experts who descended on control systems (remember, they’re the guys who thought every control system was “SCADA”?) because they saw a big market, and have been spreading FUD ever since. Recently, a Wonderware vulnerability has been disclosed, and the disclosure is making the rounds. Several months ago, an ICONICS vulnerability was disclosed, causing ICONICS significant distress. Why? Well in both cases, the vulnerability was, although accurately described, not dangerous.

Followed by Walt's attempt to trick Dale (and preach to the choir) on the Australian SCADA Mailing List

Since you have referenced the exchange Dale and I have had on my blog, I'm curious to hear YOUR answer to the question I kept asking Dale, and he kept not answering.

Here's what I asked, repeatedly. "Do you disagree with my premise: that in order to adequately advise people about cybersecurity in the process industries, significant familiarity with those industries and control systems is required?"

Dale didn't answer. I'd be delighted to hear others' answers.

What's behind all of this. Maybe we we are at a tipping point of some sorts. a power shift? All this talk of "the establishment." Perhaps we are at that point in martial arts movies where blood is dripping down over one of the fighter's eyes and he starts to get desperate and defensive. And then swing wildly. This is also before he cracks his neck with his hands and motions with both fingers to "bring it on." Before getting kicked in the head. And then the credits scroll.

Or perhaps it is just the same inane "IT vs. SCADA" conversation that has been raging for the past 5 years.

Yeah Jjakpae is an awesome Korean martial arts (taekwandoe) movie. A must see.

Saturday, December 01, 2007

Using Hashes Like it is 1999

This week I picked up [what I thought would be] a quick logfile analysis task. Things started out great. I took the time to look at the logfile format and generalized 4-5 different messages (with appropriate regexes to get the data I needed) generated by the security device. Next I extended a basic "logrunner" class I wrote last month for analyzing the debug output from the Intel FreeBSD drivers (basically you do some sysctl's and it dumps some kernel messages to see counters missed, received packets--much better than netstat).

In my logrunner class, you basically can "attach" various simple regex matches and a symbol and you get a nice hash back with the values you want and it hides all the low-level details of matching or handling time stamps, etc. (HINT: If you are mucking with syslog files in Ruby and you are not using the Time API, you are a fool, but I digress).

After a few hours in I thought things were going fine, before some distractions kept me from working on it again until until the next afternoon (I overconfidently estimated this would take about 4 hours from start to finish), so I was in a rush. The initial desire to develop something be a more general purpose tool and that was designed properly was replaced with the brute force, quick hack, get-r-done approach.

I ended up iterating through the output hashes output by the logrunner tool to create more hashes some with the IP address as a key, others with a username as the key. And all of this pointed to at least another hash (or two) so I ended up with something like:

blah[blah][blah] = { 1 => { a => b, c => d }, 3 => { a=> q, d => z } }

This would have been a trivial task except there was no single session identifier (or even username or IP address) on each line that I could tie the various pieces of data together. Then I kept getting confused (and alternating between |k| and |k,v| with my Ruby blocks) it took my longer than I had hoped but I was done in about 7. I had the output I wanted. Went from a few hundred megs of logs to a nice Excel-friendly CSV file. And I thought I was done.

Until Friday afternoon, when I found it some additional data was needed. Extracting the data wasn't a problem (that was done in 5 minutes), but correlating it and getting the report format was. Should I add another hash? Redefine the hashes I'd written? Five o'clock on Friday (with restless hungry kids) is not a time for clarity of thought, but this morning I realized the Ruby I was written was as unreadable as the Perl I used to write back in the day.

Spending the afternoon driving out in the snow which turned to sleet which turned to rain finally beat some sense into me. I mapped out the data on paper (this time) and did right. Came up with 6 simple classes (2 base and 4 sub) to abstract away the hashes and ended up with less than 1/10th of the lines of code in the main loop and a 1/3 of the iterations. Nothing fancy, no Ruby foo, nothing that couldn't be done in Python. And the code is actually readable. The moral of the story? If you are using hashes 4-6 levels deep you have a problem. Stop, step away from the keyboard and come up with a cleaner design. Do it right the first time, you won't regret it. Because quick hacks have a funny way of running on systems for a long, long time.