Tuesday, March 13, 2007

Creative People Are "Crazy" ?

According to a study by Vilayanur Ramachandran, creative people technically have a defect in their brains making them able to cross wire different senses to create and innovate different responses.

So, if someone cuts of his own ear, he's not nuts, he was just creative!!! (but if someone does these days, its called plagiarism)

Checkout this interesting article: http://news.com.com/This+is+your+brain+on+TED/2100-11393_3-6166247.html?tag=st_lh

Monday, March 12, 2007

Blackberry 8100 DoS

Blackberry is a hugely implemented secure handheld based email client inside the RIM network. It can retrieve emails for you and notify you when you have new emails straight from your email server.

There's a Denial of Service potential in one of their devices, the 8100 Pearl (v4.2.0.51) which can be easily exploited. A fix is available, so if your organization uses BlackBerry and this particular device/model, please update to a patch.

More info: www.blackberry.com/security/news.jsp

Friday, March 9, 2007

Windows Genuine Advantage (WGA) Contacts Home (even if you click cancel)

Microsoft officially admits that the WGA program will "contact home" even if the user clicks on cancel. Nonetheless, the software giants claim, no private information is transmitted through this, further claiming, this is kind of a survey done for WGA user experience. There's been WGAs and WGA crackers, its a cute lil' battle that promotes newer grounds of security and newer grounds for anarchy :D

Anyway, be genuine..

Read more here: http://www.theregister.co.uk/2007/03/09/ms_wga_phones_home/

Want Faster Streamyx? (Choose a faster streamyx connection)

If you're a Streamyx user like me (Streamyx is the xDSL service by TMNet) and face inconsistent performance with your link then you may want to try this little trick i discovered. This "trick" works with dynamic IP users only like myself. So, whenever you dial, you should get a live IP address from Streamyx. Normally, you would get the IP 60.x.x.x which is part of the IP chunk that TMnet bought. After several tests, i found that the IP 60.x is actually really much slower than the IP 218.x.x.x, also, IP range given to TMNet. You may get the IP 219.x.x.x which is also as slow as the 60.x.x.x IP set, in fact, 219, seem slower than all three!!!.

So, redial until you get 218.x.x.x. and see your streamyx fly :)

NOTE: My tests didn't see improvement in Torrent networks though, it made a huge difference with WWW from America (particularly) and its because the routing path is much lesser than that of the 60.x and 219.x....

So seize the opportunity before even this IP gets "clogged" too.

Happy surfin'

Wednesday, March 7, 2007

Default Router Passwords

Most edge devices (like routers) come with a default passwords which normally is found at the quick setup guide or their manual. But if you are like me, people who don't read manuals, a quick place to find your edge devices passwords would be http://www.routerpasswords.com. Check it out for yourself.

Oh, and once you've accessed the device, CHANGE THE PASSWORD to something complex and document it somewhere safe.

Apple QuickTime Player Remote Heap Overflow

Apple QuickTime Player is reported prone to remote heap overflow vulnerability (exploitable via remotely originated content). Only Windows users are currently affected. Please update to latest at http://www.apple.com/quicktime/win.html

Full advisory can be found at:

http://www.piotrbania.com/all/adv/quicktime-heap-adv-7.1.txt

Kaspersky UPX vulnerability revealed

Problem processing packed files led to infinite loop.

Details of a flaw in UPX processing in the Kaspersky anti-virus engine have been made available, a month after the release of a patch to fix the problem.

The vulnerability, which was reported by iDefense, could be exploited by a maliciously created file to cause the software to go into an infinite loop, leading to denial of service on email servers running Kaspersky scanning in their filters, to degradation of performance on other servers and possible total loss of processing on desktop machines.

Kaspersky is the second vendor to be hit by a UPX-related vulnerability this year, after a similar issue hit Trend Micro in early February.

The flaw was patched by Kaspersky within a few weeks of the initial report, and all users should be automatically protected via automatic updates. The iDefense alert on the problem is here, and details from Secunia are here.

PC Hardware Can Be A Malicious Rootkit

I guess, in time, you would need to run your Antivirus on hardware too to check for malicious code. I guess it would be an expensive exploit, nonetheless it could be exploiting hardware and storing itself in your hardware's firmware.

A good practice from now is to buy reliable manufacturer's hardware and update your firmware when they become available.

News excerpt from http://news.com.com/PC+hardware+can+pose+rootkit+threat/2100-7349_3-6162924.html

ARLINGTON, Va.--PC hardware components can provide a way for hackers to sneak malicious code onto a computer, a security researcher warned Wednesday.

Every component in a PC, such as graphics cards, DVD drives and batteries, has some memory space for the software that runs it, called firmware. Miscreants could use this space to hide malicious code that would load the next time the PC boots, John Heasman, research director at NGS Software, said in a presentation at this week's Black Hat DC event here.

Nessus: Be an instant security auditor

I really like those some proclaimed security auditors who come to you and say they can "detect" security flaws in your products and charge you a butt load of money for it. I must say, they did some good work in convincing you.

But seriously speaking, many so called "sec auditors" out there are just a load of scripting kiddies that run tools then Google the findings and look for resolutions, last but not least, they send you their bill. Well, i am not sure if there's a magician's-code like for security auditors not to "reveal" their tricks to the public, i don't really care actually.

So here's a quick trick to become a sufficient auditor (note, by saying sufficient, i mean, basic or enough-for-now level). Try Nessus 3.0, its a vulnerability scanner for almost anything that have an IP (almost).

Its an awesome tool, that i personally use too when performing auditing but, i would provide this type of auditing for free!.

I would suggest to organizations, large or small, to run a basic security audit on all implemented servers, devices, routers or like i said, anything with an IP to see if its secured at least to known security vulnerabilities out there.

Nessus is fast and agentless that runs on many *nix flavors, Windows, Solaris and Macs and even checks for patch levels if configured to do so. Now, try it out for yourself, but first read the how-to-guide then start. Some scans can crash servers so be extremely careful when running on live environment.

And..drum rolls, best part is, its FREE!!! Enjoy!

Brought to you by the good folks at Tenable (http://www.tenablesecurity.com)
Nessus 3.0 download link. http://www.nessus.org/download/
Nessus 3.0 Faq: http://www.nessus.org/plugins/index.php?view=faq

About
The Nessus vulnerability scanner, is the world-leader in active scanners, featuring high speed discovery, asset profiling, and vulnerability analysis of your security posture. Nessus scanners can be distributed throughout an entire enterprise, inside DMZs, and across physically separate networks.

They can also be made available for ad-hoc scanning, daily scans, and quick-response audits. When managed with the Security Center, vulnerability recommendations can be sent to the responsible parties, remediation can be tracked, and security patches can be audited.

Nessus is supported by a world renowned research team and has the largest vulnerability knowledge base, making it suitable for even the most complex environments.