Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Wednesday, May 19, 2010

Hacking Your Car

Ok, so remember all the brouhaha not so long ago about Toyota cars having sudden acceleration and braking problems? Toyota initially said it was floor mats, and then a braking pedal shim needed to be added.

And then Popular Mechanics piled on and showed conclusively that the braking problems were all mechanical and not electronic.
[Popular Mechanics] But the possibility that a vehicle could go from idling at a traffic light to terrific, uncalled-for and uncontrollable acceleration because the guy next to you at a traffic light answered his cellphone? Or some ghost in the machine or a hacker caused a software glitch that made your car run away and the brakes suddenly simultaneously fail? Not in the least bit likely.

These throttle-by-wire systems are very difficult to confuse—they're designed to be robust, and any conceivable failure is engineered to command not an open throttle but an error message.

Remember how some people were caught being liars and gold diggers? Then there were the graphs and interpolations of data that showed that old people were disproportionately victims of Sudden Unintended Acceleration (SUA) - a not so subtle hint that the geezers were pushing the accelerator when they thought they were pushing the brake. Oops.


And then Toyota came out and said there was a problem with software causing braking problems after all, but it was nothing like this "runaway" problem that people were reporting. And there were Congressional hearings and fines levied and then we all breathed a collective sigh of relief because it was all overblown in the first place.

Remember all that, mister? Do you? Huh, do you?

Well nobody is calling out any companies by name, but a team of geeks led by Stefan Savage, an associate professor with the University of California-San Diego, and Tadayoshi Kohno of the University of Washington successfully hacked a car's computer to make it do all kinds of things you're not "supposed" to be able to do, including "turn off the brakes in a moving car, change the speedometer reading, blast hot air or music on the radio, and lock passengers inside the car".

They built a custom analyzer called CARSHARK and plugged it into the industry standard computer access port under the hood.

In the United States, the federally-mandated On- Board Diagnostics (OBD-II) port, under the dash in virtually all modern vehicles, provides direct and standard access to internal automotive networks. User-upgradable subsystems such as audio players are routinely attached to these same internal networks, as are a variety of short- range wireless devices (Bluetooth, wireless tire pressure sensors, etc.). Telematics systems, exemplified by General Motors’ (GM’s) OnStar [service].

Fuzzing. Much to our surprise, significant attacks do not require a complete understanding or reverse-engineering of even a single component of the car. In fact, because the range of valid CAN packets is rather small, significant damage can be done by simple fuzzing of packets (i.e., iterative testing of random or partially random packets). In- deed, for attackers seeking indiscriminate disruption, fuzzing is an effective attack by itself. [source]
Oh, and then they did the whole thing over again by remote control. Yeah.

Read the entire thing here.

I'm a computer security guy and I find this the Coolest. Thing. Ever. (also scary). So it's not like I'm saying "I told you so" or anything ... OK, who are we kidding? I am saying it. I told you so.

Tuesday, December 1, 2009

Candidate Passes!

Among the many things I've had on my plate lately, one had a deadline associated with it. The GIAC Certified Penetration Tester (GPEN) test had to be taken and passed by Dec 12 of this year.

My test was scheduled for today; I had been studying on and off for several weeks but with distractions. Well, I took the test and only missed 4 questions; 97.33% not too shabby! This old dog hasn't lost his edge yet.

I felt like I had to ramrod it through regardless of the situation or any doubts about my ability.

My hero: Danny Kaye in The Court Jester. It doesn't matter what he actually does, the candidate passes!



Captain of the Guard: [Hawkins is being tested for Knighthood] He must scale a wall in full armor.
[Hawkins is tossed over the wall]
Captain of the Guard: Candidate passes!
[later]
Captain of the Guard: He must bring down a hawk in full flight.
[a hawk with an arrow is tossed on the ground]
Captain of the Guard: Candidate passes.
Hawkins: But I didn't even shoot...
Captain of the Guard: [shouts] Candidate passes!
[later]
Captain of the Guard: He must capture a wild boar with his bare hands.
[a piglet comes out of a chute followed by sound effects of splashing in the mud]
Captain of the Guard: He passes!

Monday, November 23, 2009

Health Care Bill - Geek Style 2

"U.S. Constitution, Article I, Section 7. All bills for raising revenue shall originate in the House of Representatives; but the Senate may propose or concur with amendments as on other Bills."

So how can there be a Senate version of the proposed Health Care (insurance) Reform Bill? Because they are playing games with parliamentary rules, that's why. They just take an existing House bill, gut it, and insert whatever they want into it. This trick is as old as the country probably. Just one of many beefs that I have with the process; and yes, I do have a degree in this.

Here is the text in the current Senate bill where this shell game gets played:

IN THE SENATE OF THE UNITED STATES—111th Cong., 1st Sess.
H. R. 3590

To amend the Internal Revenue Code of 1986 to modify
the first-time homebuyers credit in the case of members
of the Armed Forces and certain other Federal employees,
and for other purposes.

Referred to the Committee on ____ and ordered to be printed

Ordered to lie on the table and to be printed

AMENDMENT IN THE NATURE OF A SUBSTITUTE intended
to be proposed by Mr. REID (for himself, Mr. BAUCUS,
Mr. DODD, and Mr. HARKIN) _____

Viz:
1 Strike all after the enacting clause and insert the following:
[text of bill]


Now I don't know what is so hard about reading these things, assuming that this is the actual bill and not the "plain text version" touted by Sen. Thomas Carper (D.-Del.), a member of the Senate Finance Committee, who claimed that he wouldn't (or couldn't) read the bill before voting on it.

Sure there are a bunch of cross-references to other laws (but that's what libraries are for -- you look them up) and a bunch of self references (paragraph ii, part b), but it's no harder than a programming language where you first:

1) define the variables and functions, and then
2) reference the variables from the main program or sub.

I mean, honestly, if you're not smart enough to read and understand the laws you're voting on, then maybe we need to vote in somebody who can. I'm reading it, and other than needing a few clarifications on what the impact of
‘(2) EXCEPTIONS.—The following provisions of
this title shall apply to a grant made under this section to the same extent and in the same manner as such provisions apply to allotments made under section 502(c):"
means, I don't think it's too hard to follow. You just have to follow each thought to its logical extension (that's the real work). I know what the words mean, the question is what would that really DO to people, markets, actual services in the real world?

Bottom line: if you can program (or read) in any G3 or G4 language, scripting language, or macro language, then you are probably smarter than your average Congressman.

Saturday, November 21, 2009

Health Care Bill - Geek Style

There are some things that only a geek could love about the proposed Senate Health Care Bill -- maybe the only things to love about it.

My U.S. Senator, Jim Webb, alerted me to the health care proposal linked from his Web site. I give him credit for that since I have sent him more than one email stating my opinion (not that he actually read it).

My first attempt to download and read this massive omnibus bill resulted in this error. My default reader couldn't open it, so I was forced to download Adobe Reader.

Sigh. Doesn't bode well.
  • From the graphic you can tell that the file is a healthy size: 2.5 MB and 2,074 pages.
  • According to the properties, the creating program is ACOMP.exe version 2.0, Nov 24 2008 on Windows-- possibly a custom typesetting system or even an AutoLISP compiler.
UPDATE (h/t kalendello) : ACOMP.exe appears to be the "creator" part of Adobe Distiller (a compiler) as seen in this similar code: /Producer (Acrobat Distiller 5.0.5 \(Windows\)) /Creator (ACOMP.exe WinVer 2.0 Nov 24 2008)
  • The original file name is Merge2.lc; LC files may be Textbridge Classic bin file (aka Optical Software Recognition (OCR) scanner software).
  • The PDF software used is Adobe Acrobat Distiller 9.2.0 (Windows)
  • The PDF is secured by Password Encryption using 128-bit RC4
  • The operating system used to create the file is Windows XP or later, as evidenced by the directory name DOCUME~1 (Documents and Settings) and confirmed by the lack of 8 dot 3 restrictions and long file name: patient-protection-affordable-care-act.pdf
  • The user name and home directory of the person who created the final file is "bai".
Opening the file you can immediately see that the file was converted and merged from 9 separate XML files. The header on each page has the following line or similar:
O:\BAI\BAI09M01.xml [file 1 of 9] S.L.C.
  • I have no idea what S.L.C. means.
  • User BAI has a Windows networked mapped drive O: (home or shared drive?) that has a folder called BAI; the file name is BAI09M01.xml. BAI (user's name) 09 (2009?) M01 (no idea)
File 2 of 9 has this header:
O:\ERN\ERN09C11.xml [file 2 of 9] S.L.C.
  • Again a mapped O: network drive, this time folder ERN (home or shared drive), ERN may be the user's initials.
  • File 2 file name: ERN09C11.xml; ERN (user initials) 09 (2009) C11 (no idea)
The rest is just the same:
O:\MAL\MAL09863.xml [file 3 of 9]
O:\BAI\BAI09M04.xml [file 4 of 9]
O:\KER\KER09924.xml [file 5 of 9]

O:\MAL\MAL09852.xml [file 6 of 9]

O:\KER\KER09925.xml [file 7 of 9]
O:\ERN\ERN09B60.xml [file 8 of 9]
O:\OTT\OTT09505.xml [file 9 of 9]

So BAI, MAL, KER, ERN, and OTT put this document together. Interesting.

Other miscellany:
  • Fonts: DeVinne, New Century Schoolbook, Times-Roman, Symbol, Gpospec5
  • PDF version 1.5 (Acrobat 6.x), can be opened by Acrobat 6.0 or greater
  • 8.5 x 11.0 paper

And we determined all that without any special tools at all. Remember to clean up your metadata!

Thursday, November 19, 2009

Real World Crypto

Compare this:
[Slashdot] "It seems that the US Immigration and Customs Enforcement Cyber Crimes Center, known as C3, has replaced its '$8,000 Tableau/Dell server combination' with more efficient and much cheaper $300 PS3s. Each PS3 is capable of 4 million passwords per second, and C3 currently has 20 PS3s with plans to buy 40 more. Naturally this is only being used to break encryption on computers seized with a warrant and suspected of harboring child pornography."
With this:


Sunday, August 23, 2009

Your Facebook, My Data

Besides being a slightly against-the-grain, anti-popular, paranoid by trade person, there is another reason that I refuse to use Facebook: nothing you put there has any expectation of privacy. Whatsoever.

Even if you have restricted who can "Friend" you and look at your pictures, all it takes is one of those friends to give away everything you've ever done and said without even being aware of it.
[Slashdot] "Back in June, the American Civil Liberties Union published an article describing Facebook's complete lack of meaningful security on your and your friends' information. The article went virtually unnoticed.

Now, a developer has written a Facebook 'Quiz' based on the original article that graphically illustrates all the information a Facebook app can get its grubby little hands on by recursively sweeping through your friends list, pulling all their info and posts, and showing it to you.

What's more, apps can get at your information even if you never run the app yourself. Facebook apps run with the access privileges of the user running it, so anything your friend can see, the app they're running can see, too.
Now, lots of people are OK with this kind of thing. They say, "I don't post anything I don't want other people to see." Others just don't realize what's happening under the hood.

But it's this part that weirds me out: "recursively sweeping through your friends list, pulling all their info and posts". That is just a little too Orwellian for my taste. Now I've been in the business long enough to know there is no such thing as true privacy on the Net, but does it have to be broadcast by default?
[ACLU] By default, Facebook’s privacy settings let applications access information on your profile even if you have restricted access to a specific network or friend group (as application privacy settings are separate from profile privacy settings). In addition, Facebook’s default settings allow applications run by your friends to pull information from your profile.
Is that really a sane default? It took us 20 years to beat Microsoft into submission over shipping their software with security settings enabled. Sun Microsystems finally followed suit. Everybody wants the "just works by default" option because it reduces support costs and allows for easy adoption. The problem is, that's crazy insecure. It's just not necessary to have access to all that data just to make a little widget, poll, or app.

The bottom line is, this policy has the company and developers' best interests at heart, not the users. Anybody with the bling-bling app-of-the-day can recursively get your and all your friends' information with a click of the mouse. (Elf bowling anyone?)

With all the skeevy types out there, I just won't be "friending" you any time soon. Sorry. See you in Meatspace.

Friday, August 14, 2009

Hacking The Pump?

Ever wonder how a gas pump works? They are fascinating pieces of technology that we all but take for granted. They mechanics are cool, but ultimately not that complicated. These days the "important" parts are done by computer. (The important part being paying for it.)
[HSW] As the gasoline travels upward into the dispenser, it passes through a flow control valve that regulates the gasoline's flow speed. It does this via a plastic diaphragm that gets squeezed more and more tightly into the pipe as the flow of gas increases, always leaving just enough room for the proper amount of gasoline to get through.

This pipe also contains the flow meter, which is a cast iron or aluminum chamber containing a series of gears or a simple rotor that ticks off units of gas as they pass through. Information about the gas flow is passed on to a computer located in the dispenser, which displays the metered amount of gas in tenths of a gallon.

In the 1970s, glowing LCDs in the form of seven-segment displays began to appear. (The segments in the display could be illuminated by computer to form various numerals and occasionally letters of the alphabet.)

These relatively simple user interfaces are gradually being replaced by full-fledged computer video displays, many running variations on operating systems like Microsoft Windows. These displays can offer information, display the amount of gas being sold and even run advertisements and carry on simple conversations with amused customers.
I actually find these computer / video displays really annoying. I just want to pump gas and leave. I don't want the news, the weather, or a car wash. Since I know a thing or two about computer [in]security, I'm always a bit skeptical about computerizing everything.

So imagine my somewhat amused surprise when I pulled in to fill up at the local gas shack and I see this:
If you look closely you can see this is a Windows computer. The task bar is the lighter bar at the bottom of the screen, the system tray is in the right hand corner, and there are 3 applications/windows open. There is a popup window in the middle of the screen with the classic "Do this / Cancel" combination. I wonder what it says?

If you squint hard (or click for larger image) at my still life with cell phone picture, you can make out the message "An updated version of LogMeIn has been downloaded and is ready for install. Click Update to install the new version now."

Remote access and desktop control to the gas pump? Interesting. Foolish, but interesting. Have these people never heard of EvilGrade, "a toolkit for exploiting products which perform online updates in an insecure fashion"?

Fake updates, plus remote desktop access to the gas pump. Wow. I'll bet nobody ever thought of hacking the pump before now.

It's not that far-fetched. Now I don't know if this computer is controlling the pump, or just the annoy-ware video, but it doesn't matter. I know you're sleeping better at night knowing that Micro$oft products may be controlling the gas pumps and your credit card number. I mean, what could go wrong?

Thursday, April 23, 2009

Bubble Gum and Baling Wire

People who know me will tell you I'm a little gun-shy on trusting our most sensitive data to the cyber-security of others. Call it an occupational hazard. I used to get paid to do bad things to others before truly bad people did it to them for real. It gives you a whole new perspective on things. Therefore, I take reasonable precautions (and some unreasonable ones).

Imagine my dismay when I received notice from my credit card company telling me that my card had been compromised. I always knew it was a question of when, not if. This message was originally posted to my credit card company's intra-web (which I never check) in January. I got a personal email from them yesterday in April.
We are canceling this account because of a recent non-[company] data compromise. You'll receive a new card with a new number to use. When you receive the new card, activate it immediately or your current card will remain active for 20 days after the postmarked date on the envelope containing your new card

Heartland Payment Systems, a national card payment processor, announced this week that it had experienced a security breach within its processing system. We are working to identify members who may have been affected and will begin reissuing cards as soon as Saturday for those cards at greatest risk.
Of course I didn't click on any of the links in the email, but called my credit card company direct for confirmation. When I asked why they were so late in notifying me, the candid answer is that they simply had too many credit cards to check, and they had just identified me as an affected member. To their credit, they notified me the same day and put a new card in the mail the next.

But that still makes me not a Happy Camper. (The least of reasons was that it took me 10 years to memorize that credit card number.) The good news is that I don't appear to have any spurious charges on my account. The bad news is that anything that even smells like identity theft makes my hackles rise.

What stinks is that despite all my personal precautions, this data breach is something I had no control over whatsoever. Once the payment at the vendor is complete it goes directly to a payment processor company like Heartland, which is like a giant payment warehouse. All such processor companies must be PCI DSS compliant (credit card company security standard) and certified, but as the evidence has shown, that doesn't count for a whole lot does it?

While this amounts to a mere annoyance for me, it kind of highlights the fact that the whole system is put together with bubble gum and baling wire, doesn't it?

Monday, March 23, 2009

Botnet Attacks DSL Modems and Routers

Just because you're paranoid doesn't mean that someone not out to get you. ;-)

[slashdot] "The people who bring you the DroneBL DNS Blacklist services, while investigating an ongoing DDoS incident, have discovered a botnet composed of exploited DSL modems and routers. OpenWRT/DD-WRT devices all appear to be vulnerable. What makes this worm impressive is the sophisticated nature of the bot, and the potential damage it can do not only to an unknowing end user, but to small businesses using non-commercial Internet connections, and to the unknowing public taking advantage of free Wi-Fi services. The botnet is believed to have infected 100,000 hosts." A followup to the article notes that the bot's IRC control channel now claims that it has been shut down, though the ongoing DDoS attack on DroneBL suggests otherwise.

This could be your Verizon or Comcast DSL modem (probably not); use a good strong (non-default) password and DON'T administer it from the Internet. Just saying.

Friday, March 6, 2009

PDF exploit is BIG ... JBIG

Forget everything you thought you knew about computer security ... if I don't visit "bad" sites ... if I don't actually open that attachment ... if I just keep my antivirus up-to-date ... if I have a firewall ... nothing bad can happen, right?

Wrong.

Drive-by browser infections are nothing new, cross-site scripting, identity theft, SSL spoofing/man-in-the-middle attacks (think that credit card transaction is safe?) are all part of the new Web 2.0 landscape.

What you don't know will definitely hurt you.

The lastest PDF vulnerability for Adobe Acrobat shows that all it takes is single clicking, hovering over the icon, or viewing in thumbnail mode to get pwned.

Didier Stevens details this latest trio of attacks using the JBIG2Decode vulnerability:

So how is it possible to exploit this vulnerability in a PDF document without having the user open this document? The answer lies in Windows Explorer Shell Extensions.

In the first demo, I just select the PDF document with one click. This is enough to exploit the vulnerability, because the PDF document is implicitly read to gather extra information.

In the second demo, I change the view to Thumbnails view. In a thumbnail view, the first page of a PDF document is rendered to be displayed in a thumbnail. Rendering the first page implies reading the PDF document, and hence triggering the vulnerability.

In the third demo, I use my special PDF document with the malformed stream object in the metadata. When I hover with the mouse cursor over the document (I don’t click), a tooltip will appear with the file properties and metadata. But with my specially crafted PDF document, the vulnerability is triggered because the metadata is read to display the tooltip…

So be very careful when you handle malicious files. You could execute it inadvertently, even without double-clicking the file. That’s why I always change the extension of malware (trojan.exe becomes trojan.exe.virus) and handle them in an isolated virus lab. Outside of that lab, I encrypt the malware.

Thursday, February 19, 2009

FISMA & Your Medical Records On Stim

The new so-called Economic Stimulus Bill (American Recovery and Reinvestment Act) slipped the American taxpayer a Mickey when it comes to health care.
The law directs an existing bureaucracy created by President Bush (the “Office of the National Coordinator for Health Information Technology”) to put together a plan for building this system so that it achieves the “utilization of an electronic health record for each person in the United States by 2014.”

In plain English: Over the next five years, the Obama administration intends to create a federally run electronic exchange that includes every American’s “medical history and problems lists.”

Now, before you run out to the nearest federal office and sign up to put the “medical history and problems” lists for yourself, your spouse and your children into the government’s “nationwide health information technology infrastructure,” you should know the law does not require you—as an individual—to do this.

The “explanatory statement” for Division A explains this. “To the extent that this section calls the national coordinator to ensure that every person in the United States have an EHR by 2014, this goal is not intended to require individuals to receive services from providers that have electronic health records and is aimed at having the national coordinator takes steps to help providers adopt electronic health records,” says the explanation. “This provision does not constitute a legal requirement on any patient to have an electronic health record.”

But if the national coordinator cannot make you—an individual—submit your records to the system, how is the poor guy going get “an electronic health record for each person in the United States by 2014”?

This mystery created by 139 pages in Division A is solved by the 77 pages in Division B: The secretary of health and human services is given a carrot and stick to make doctors and hospitals create EHRs for their patients. Doctors and hospitals that make “meaningful use” of EHRs by the deadline get bonus payments from Medicare. Those that do not get diminishing Medicare payments.

What is “meaningful use”? That is at the discretion of the secretary of HHS, but the law says it will include “electronic prescribing,” “the electronic exchange of health information to improve the quality of health care” and submitting information “on such clinical quality measures and such other measures as selected by the secretary.”

Lastly, the law directs the secretary to ratchet up the “meaningful use” test as time goes on. Or as the “explanation” politely puts it: “The secretary would seek to improve the use of electronic health records and health care quality by requiring more stringent measures of meaningful use over time.”

In other words, once the secretary has your medical file in the system, he is supposed to make your doctor do ever more with it at his command.
Now with that in mind, take a look at the overall state of computer security (FISMA) in the Federal Government as of FY2007 (the last data available). The "overall" grade for the Government was a "C" (up from a "C-" last year).

Given how they manage computer security, do we really want to let these guys manage our most personal details? I'm sure they would be much better when they start rationing our health care.

LinkWithin

Related Posts with Thumbnails