Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Wednesday, August 10, 2011

BlackHat 2011 and Defcon 19

The scene in Las Vegas last week on the wireless security front was quiet and reserved. There was a veritable dearth of WLAN issues to report on at either BlackHat or Defcon. Sure there was the Wi-Fi hacking UAV and Vivek Ramachandran's normal Wi-Fi security and hacking class, also the wireless water meter 900mhz hack and 1 or 2 new WEP attacks (like WEP needs any more attacks against it, isn't complete penetration in under 5 minutes fast enough?) but nothing really new and interesting. Most of the talks were about making your PSKs long and secure to shield you from, "Sniff now, Crack Later" (using Rainbow Tables found here and here) and talks reminding everyone to monitor their WPA2-EAP implementations against Honeypot Radius WPE (the WPE is not a typo, it stands for, "Wireless Pwnage Edition" and info may be found here and here). This last one is an old vulnerability but many people still have not been keeping an eye on it especially if your organization uses server certificates only in their EAP implementation.

So what does this absence of new WLAN vulnerabilities mean? Are the hackers bored with the ability to enter a company’s WLAN from 125 miles away? Do not bet on it. Has the IEEE, Wi-Fi alliance and FCC finally secured Wi-Fi so that no new vulnerabilities will be forthcoming? I sincerely doubt it. So what is the deal?

My opinion is that people are sitting on some of the latest vulnerabilities and making use of them. Wikipedia states that, “Zero-day attacks occur during the vulnerability window that exists in the time between when a vulnerability is first exploited and when software developers start to develop a counter to that threat.”  Meaning that a hacker can only execute the exploit before it becomes common knowledge. Once the vendor and security community find out about it, then everyone races to plug the hole. In the past, plugging the hole took several months for most major WIPS and WLAN vendors and then several more months before most customers implemented the new release (this was due to the fact that it required a system-wide upgrade). But the world is much more agile now and the ability to dynamically plug a security hole quickly just got a big boost when we at Fluke Networks released our AirMagnet Enterprise version 9.0. The version 9.0 solution has the ability to dynamically update the WLAN Intrusion Prevention System against threats as they become known. We  also broke out the alarm code and implemented a much easier, non-programmatic method for creating the signature and anomaly alarms that make up the system.  This means that from the time a zero-day is known to the time it is implemented can be as little as a day or two. This is a huge benefit for customers but a real drag for hackers. They will now have even more reason to hang on new vulnerabilities. It is also a clarion call to WLAN security researchers to step up their game and look for more fuzzed approaches to WLAN threats and try more anomaly-based alarms. I know our team is so ready here at Fluke Networks so bring it on!

Sunday, August 15, 2010

Entranced!



I am describing my mind and it's fixation with the WikiLeaks/Pfc Manning/Wired Magazine (via Kevin Poulson)/Adrian Lamo/Icelandic Law thing. I am like a person watching a car wreck. I cannot look away. I have not made up my mind on this but I am very intrigued. WikiLeaks may be a criminal enterprise, a heroic counterpoint to secrecy and big brother or we may be watching the evolution of journalism before our very eyes. 

Here is the story so far: Mr. Assange has assisted in the crafting of legislation that was recently passed in Iceland and which subsequently creates a "free press haven" which protects him (and other journalists) from search and seizure and incarceration. He stores his data there and elsewhere where data protection laws exists. He is mirrored by hundreds of other sites and distributes his data globally. Then he leaks 92,000 US military files from Afghanistan (Actually, 77,000 - he keeps some in reserve for Insurance). He shows the horrors of war while continuing to uncover the underhanded practices of individuals, groups, businesses, religions, governments. Private Manning appears to be the leaker and was turned in by Adrian Lamo, the barefoot hacker. The story breaks on the Wired Magazine "Threat Level" blog run by hacker Kevin Poulsen. We learn that Private Manning has a pretty high security clearance and is love with a drag queen from Cambridge, Mass. We have human rights groups joining the military in asking WikiLeaks to edit the documents to protect the people assisting the US Army in Afghanistan. Lastly, we now learn of a potential war within the WikiLeaks "organization" and a potential CyberWar with the US military

He described the original goal of Wikileaks and how it evolved and adapted over time recently at a Berkeley Graduate School of Journalism symposium. This symposium took place just prior to the passage of the law and thus prior to releasing the documents. 

This is a story revolves around hackers. There are hackers at the center, hackers at the news outlets, hackers whistle-blowing on the hacker whistle-blower. This story is crawling with them.

Rather than debate the moral and ethical issues or try and talk about the impact on the newly changing journalistic world or the case details I would like to discuss what the heck happened to those pesky kids inspired by the movie WarGames and Captain Crunch.

In the past 20 years or so hackers have been portrayed by the media consciousness as teenage nerds disillusioned with their place in the world. Kids who get bullied in school and fight back by hacking into NORAD or AT&T or whatever. They have been shown as dweebs and techno punks. I never thought that any of these images were very accurate. Stories about real hackers never seemed to jibe with the images of Hollywood or the mainstream news.

I have been to a few hacker conventions and know a few hackers myself (let us not have a semantic debate about the term - Hacker - that fight was lost awhile back in 1983 if not before. It has many meanings but ask someone on the street in Des Moines or Tulsa and they have a very particular image in mind. In this I omit those folks who steal grandmas credit cards or push child porn and their ilk).  The folks I have met and know are crafty and witty. They spurn convention. They want to know how things work without having someone do the work for them. They love pranks and hate injustice. Some are very vain and cruel. They want information to be free to all. Others are gregarious and kind. All of them have one thing on common, they are all very smart. You have to be smart in a subculture where "what you know" and "what you can do" are the means to establish your status. 

I do not think that the general hacker populace cares one bit how they are portrayed in the media regardless in the past 10 years or so many of them grew up. Those 13 year old kids who in 1983 watched David Lightman hack into WOPR are now 40 and they are doing things.

Originally, they started out in a predictable way. They continued to hack into systems they did not like. They started network sit-ins. They defaced the sites of organizations they didn't like. Then they really evolved.

They started coordinating efforts of anti-WTO protesters in Seattle in 2000 and protesters at the Democratic National convention in Denver in 2008. All groups were open as targets as long as the hackers thought they were making news or changing the public opinion.

Assange and his crew wanted to change the way the media and "just folks" got their information. He wanted to link up all these bloggers with too much time on their hands with original source material and let them get the news unfiltered and then voice their opinions. well, It didn't work out quite how he planned but is doing something. What this something is we will see in the coming months.

The Hacker ethos has finally hit the mainstream. Google (net neutrality issues aside) has sponsored with Yahoo, Microsoft and others some "Random Hacks of Charity" and defied the work of the Chinese government to expose opposition party chinese nationals. Bill Gates wants to make a difference with his charities and has convinced many billionaires to follow his lead. 

J0hnnyhax, otherwise known as Johnny Long, and some friends went to Africa and started Hackers for Charity with the goal of, "proving that hackers have amazing skills that can transform charitable organizations. We’re about stepping into the gap to feed and educate the world’s most vulnerable citizens. We are virtual, geographically diverse and different." He has done amazing work in Uganda setting up labs and user groups, computer education and training. Recently he has been despondent, however. His blog posts the following, 
"HFC has done little relative to our collective capability.
We can throw an 802.11 signal a world-record distance of 275km using junk hardware. We can rootkit Android before it’s released, hack GSM, hijack global DNS, pick every lock on the planet, beat international news agencies to the punch, and weed our way into previously untrodden shadows of the digital world. There is amazing skill in our community. We build robots just because we can, and tweak just about every technology on the planet to unbelievable ends. We are motivated and brilliant. We are self-organizing and ultra-productive when assaulting “impossible” projects. We break, bend, and then re-create the rules. But can we really, honestly do some good in the world? My answer used to be a resounding “YES!” Now, my answer is a much-too-passive “Maybe”.
Yes, with me and my family on the ground here in Uganda, some positive things have happened (http://www.hfc-uganda.org). But is that work reflective of the power of our community? Hardly."

The rent for HFC just doubled in Uganda and Johnny despairs. 

The world is changing. Hackers are growing up. They are attempting to do what previous of generations of folks have tried time after time. They want the world to be fair. They want to contribute. they want to make a difference. It is a hard, long, twisting road and is uphill both ways. Giving up or giving in would be easy and just chugging along in the normal pay-earning life with all our normal problems of home, job, family and personal life seem to be enough to consume all our time. Where will this go?

Will HFC continue? Will Assange get arrested? Will Google divide the Internet into haves and have nots or will it refrain from being evil? I am entranced. I cannot look away. It is magic in the making.

Tuesday, April 20, 2010

Hackers Love Gray Powell

I am sure by now that all of you have heard of the next gen iPhone that was left behind by an Apple Engineer at a Redwood City bar. Heck it's now even on the New York Times. I feel bad for the guy and am a little miffed at Gizmodo for sharing his name. But now that is is already out there everyone knows him, Gray Powell. I am not interested in talking about the technology or the, "Human" situation. I am interested in, "Speed to Market".

You see, the thing that really amazes me is how fast hackers have capitalized on this Internet meme. in less than 24 hours they have created hundreds of websites to fool you into clicking on an executable that will bring your poor computer to it's knees.

Take a look at this image I saved of a Google search for Gray Powell.

Notice all the nice "This site may harm your computer" notes that Google was so kind to add?

In less time than it takes to say, "Famously Secretive Silicon Valley Computer Firm", hackers have lined up to take advantage of you.

Surf carefully young padawan.

Wednesday, January 13, 2010

A Brief note on the the Google/Chinese intrusion/withdrawl

I just wanted to publicly put my support behind Google's choice to put their foot down after the Chinese government sponsored intrusions into their networks.

By now, I am sure, many of you may have heard about this, but for those who have not here is their statement and some links:
We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.

You can test if they are sticking to thier guns by searching the Chinese Google site yourself at http://www.google.cn/


If they choose to have a spine and stick to this they will finally resolve their problems with their own motto, "Don't be Evil". Let's hope they do.

Tuesday, June 9, 2009

Disposable Income??

iFixit.jpeg

Well here we are, half way through 2009. This year saw the culmination of, arguably, the worst financial crisis since the Great Depression. Yada yada yada. We have heard this all before.


I thought we were going to talk about Wi-Fi?


Well today I thought I would talk about disposable computers. Several weeks ago an associate of mine saw her beloved 17 inch iMac G5 all-in-one start to shut down for no apparent reason. She had Apple Care and had no problem trucking it down to the local Apple Store Genius Bar for a looksie.


They had her Mac for a week and then called and said, "you better come down here". When she got there they broke it to her gently, her mac was dead. The logic board was failing and a replacement would cost more than the worth of the unit. A few tears were shed before she realized this would mean she would need a new iMac - STAT!


So she cam home with a new improved 20 inch, Aluminum Bezel, Glass front, 2.66GHz Intel Core 2 Duo iMac .


The poor old unit sat next to the front door accumulating dust until I stripped some parts off of it and sent the remainder to the recycling plant here in San Francisco where they are used to this kind of recycling, as I am sure they are elsewhere these days.


I felt bad. Seemed like a waste.


Then I did the worst thing a husband can do to a Wife's computer. I spilled a drink on my wife's MacBook. I freaked out, flipped the unit over, yanked out the mag-safe power cable and the battery and spent the next several hours wiping it down and blowing air through the unit to get it dry. I failed, the next morning she had a host of keyboard and restart issues. She was not happy, however, to her credit, she was not super mad at me either, just at the situation.


So, guess what I did? Yep. I took the unit down to the Apple Store, where again the Genius Bar Dude said it was covered by AppleCare and that they would call us in a few days and tell us what was up. And guess what the verdict was? 800 dollars, 100 dollars cheaper than the Brand New Macbook. Worth the investment? Probably not.


Now here is where most folks would start to rail against the new disposable society. Everything from cell phones to TVs are all disposable now. Right? Wrong.


Not me. Why? Well I have a small contribution to make to help stop this madness.


I found two places that were willing, with a little effort, to show me how to take care of these problems myself. No fancy Apple Store Genius, know-it-all, Fixer Upper, dude (BTW, most of the time, they do not even do their own repairs at Apple, they farm it out). It should be mentioned that I am no stranger to this kind of stuff. Awhile back I repaired my first original AirPort Basestation by replacing a burnt out capacitor. Heck, a logic board replacement for the MacBook doesn't even involve soldering


The first site I am sharing is run by a pair of guys who were in college and decided to try and fix their Mac themselves, then they were fixing their pals computers and then, weell, they said, You do it. They started iFixit. Ifixit will sell you the parts and show you how to replace them. This, of course, voids the warranty, but, hey, you were going to throw it out and get a new one anyway, right?


Here is their story in their words



It bugged us that most consumer devices lacked repair instructions. We think it should be easy for people to learn how to fix things.



So we wrote some instructions the first chance we got. And we posted them online, for free. For the first time, it was easy for someone with no technical background or experience to take apart a Mac. Our step-by-step instructions were enabling people to repair Macs they wouldn't have been able to repair on their own.



We thought the instructions would be useful to our customers -- and they were. But it turned out that they were useful to a lot of other people as well! We've heard repair success stories from forensic detectives, field translators, and even kids. From New York to Alaska, Tibet to the Faroe Islands, people have used our guides to fix their stuff. They saved money, they kept their Macs out of the landfill, and they did it completely by themselves.



And the amazing thing? They enjoyed doing it. It's fun to take stuff apart. It's interesting to see what's inside that magic iPod you carry around every day. It's gratifying to fix it with your own hands. Don't believe us? Try it! Fix your Mac yourself. Show a friend how to fix something.



We're all in this thing together, and if we work together we can fix the planet. Join us.

Neat! And they are helping the environment while making a good buck or two in the process. Oh, and not just Macs, Nintendos, Palm Pre's, iPones and iPods, and even bananas


Next up, I found there guys, The Powerbook Medic folks. Theyare similar to iFixit in that they sell parts and show you how to fix stuff. They also will fix it for you (for a reasonable fee) and they also have video tutorials on YouTube



youtubelogo.jpeg

Lastly, they have made their own Mac Tablet PC from an old MacBook - it looks pretty sweet


MacTablet.jpg



The total cost to fix my Wife's Macbook now looks to be around $250-$350. A far cry from the $800 plus I was quoted to do the same thing by the Apple Store. Don't get me wrong, AppleCare is awesome. It has saved my bottom so many times. Well worth every penny, but aside from that, do we really need to be tossing out so many electronics in this day and age?


So it turns out you do not have to chuck out that pretty awesome Apple MacBook after all. I am sure there are sites for Dell, Toshiba, Gateway, Sony and homegrown BYO (build it yourself) FrankenPuters and others as well. A quick google search shows you that anyone can do this kind of repair.


Oh, now, how I wished I could go back and get that iMac G5.



UPDATE!

We finally got the MacBook back from Apple and now it will not boot. It booted before, just had crazy keyboard shenanigans. Now, Dead.



So now we have to move forward with the plan. I will update as I do it.

Sunday, January 28, 2007

How to Increase Your Wi-Fi Signal

OK, this guy is dorky and the tin-foil hat/antenna he made is so ghetto BUT his thing on carrier waves and the CAT 5 wrapped cell phone - pure genius.

Friday, January 19, 2007

Hey, I was on TV!

So a long time ago, I was asked by my V.P. of Marketing at the time, Rich Mironov (One of the best Marketing guys I know, BTW), to assist our PR firm with a show they were putting together. Tactical to Practical on the History Channel. It is a show where in the first half hour they show the military doing something really cool and then, for the second half hour they show you how you, The average American, can do something similar with stuff you can pick up from Frys.


It was a fun shoot. I brought along a friend of mine, Jon Erikson, who wrote a fabulous book called the Art of Exploitation. One of the most well received books on security exploits I know of. He and I were to conduct an actual hack over wireless at a hotspot in downtown San Jose for the cameras.


Jon had a few prepared 'splots he wanted to run. One was a MitM attack with stream injection. I would search for, oh, lets say, "shrimp" at Google and he would substitute, say, "giant" for "shrimp" so all the returns from Google were about really big things. Kinda funny but a hard concept to convey in 15 minutes to a TV audience.


The other idea was pretty simple (read:LAME), I would log into my mail account and he would snarf my password and go read my mail. It came off OK and they kept it as the final for the show. It was fun to do and we got a ton of inquiries. I actually get about 15 minutes of airtime. So there is my Andy Warhol quote for the day. Here is the link: Bruce_on_TV

Sunday, December 3, 2006

T-Mobile WPA (Without nasty client sw)


I finally found a tip on the Internet about using t-mobile with WPA without the nasty t-mobile connection software. Those groovy geniuses at TheShmooGroup have a member who did it. The post follows from their forums.
Jouni Malinen jkmaline at cc.hut.fi

Sat Sep 3 13:33:19 MDT 2005
Some time ago, there were couple of questions on how to use wpa_supplicant with the WPA-enabled version of T-Mobile wireless network.
Finally, I had a suitable chance to test this a bit while waiting for my flight at SFO and the connection is indeed working fine. As a proof, this email is actually send over the WPA encrypted T-Mobile network ;-).
The SSID for the network is tmobile1x and it is configured for WPA-Enterprise with TKIP. Authentication is done using EAP-TTLS/PAP using the normal T-Mobile username/password. It was enough to just complete WPA authentication, i.e., no need to go to any web portal page. It took me some time (maybe five or so scan attempts) to find tmobile1x SSID even though I saw six or so APs with tmobile SSID at the same time. Anyway, once the correct SSID was found, association and authentication went through fine.
This network block worked fine (at least at SFO) with madwifi:
network={
ssid="tmobile1x"
key_mgmt=WPA-EAP
scan_ssid=1
identity="username"
password="password"
eap=TTLS
phase2="auth=PAP"
}
--
Jouni Malinen PGP id EFC895FA


I got this working with the Intel ProSet Wireless supplicant. Here are screen grabs of the setup, Insert your own T-Mobile username as required. Also, feel free to click the image for a larger version.