<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aten Labs &#187; rants</title>
	<atom:link href="http://atenlabs.com/blog/category/rants/feed/" rel="self" type="application/rss+xml" />
	<link>http://atenlabs.com/blog</link>
	<description>San Diego&#039;s Premier IT Security Consultancy</description>
	<lastBuildDate>Tue, 24 Jan 2012 20:48:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Get your creep on</title>
		<link>http://atenlabs.com/blog/get-your-creep-on/</link>
		<comments>http://atenlabs.com/blog/get-your-creep-on/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 20:48:24 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[rants]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=223</guid>
		<description><![CDATA[About a week ago, I stumbled across this post in google reader: Console Cowboys -I always feel like somebodies watching me. I read it, I was impressed, and it immediately reminded me of previous work I&#8217;ve done. In collaboration with @achillean we scanned the whole internet looking for ddwrt routers with a directory traversal vuln, [...]]]></description>
			<content:encoded><![CDATA[<p>About a week ago, I stumbled across this post in google reader:</p>
<p><a href="http://console-cowboys.blogspot.com/2012/01/trendnet-cameras-i-always-feel-like.html" target="_blank">Console Cowboys -I always feel like somebodies watching me.</a></p>
<p>I read it, I was impressed, and it immediately reminded me of <a href="http://www.shodanhq.com/research/geomac" target="_blank">previous work I&#8217;ve done</a>. In collaboration with <a href="http://twitter.com/achillean" target="_blank">@achillean</a> we scanned the whole internet looking for ddwrt routers with a directory traversal vuln, and wrote a script to step through the findings.The result was a map you could use to find routers based on their mac addresses. The vulnerability was information disclosure of the wan mac address, which likely would have been found by the google street view cars, and the skyhook cars during their sweeps, so if you know the wan mac address of a router, you can translate that to a physical location on a map. I thought this would be perfect to apply the same formula to &#8211; except in this case it would be difficult to pinpoint where the camera actually existed unless there was some kind of information disclosure in the video stream itself.</p>
<p><strong>Now let me make this abundantly clear: </strong>Nothing is getting recorded or saved. The output here are IMG SRC html links to cameras on the internet. Your browser renders those image streams directly from the cameras. Nothing gets saved or written unless you explicitly choose to save something &#8211; kind of like watching television &#8211; unless you dvr something or god forbid still own a vcr, in the same manner, you have to choose to record things. That onus is on the viewer.</p>
<p>The author of the console-cowboys blogpost wrote a script to do all the proper API calls against shodan to search for the cameras, then another loop to manually test each result found for the path that shows video. If an HTTP 200 OK was returned for the path, the url was saved.</p>
<p>I took that script, and simply added IMG SRC tags to the output, also adding threading during the checks and one or two small performance tweaks &#8211; my second python script ever, and I&#8217;m already using threads! (I was kind of proud of this <img src='http://atenlabs.com/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> )</p>
<p>The results looked something like this. Very simple, but effective:</p>
<p>&nbsp;</p>
<blockquote>
<p style="text-align: center;"><a href="http://atenlabs.com/blog/wp-content/uploads/2012/01/Screen-shot-2012-01-24-at-11.35.26-AM.png"><img class="aligncenter size-large wp-image-224" title="Screen shot 2012-01-24 at 11.35.26 AM" src="http://atenlabs.com/blog/wp-content/uploads/2012/01/Screen-shot-2012-01-24-at-11.35.26-AM-1024x767.png" alt="" width="450" height="337" /></a></p>
</blockquote>
<p style="text-align: left;">Each image there is actually video. The cameras each output mjpg straight to the browser, so firefox and chrome were both happy to render video. The trouble was that I found more than 550 cameras &#8211; so loading that html into a browser caused my ram and cpu to spike.. a lot. It also wanted 2 megs a second (MEGS, not megabits..) of bandwidth just to view the cameras. So I used the split command to tear the huge list into 6 parts, each list containing 100 cameras, and one with ~56 or so. I posted it off the main website before having writing the script &#8211; there were several pastebins floating around with the camera list already, so adding html tags to that was dead easy.  I had 200-300 cams in one giant html posted maybe 5 days ago. Everyone had a laugh, and one friend even <a href="https://twitter.com/#!/iameltonjohn/status/161670955847000064" target="_blank">interacted with one of shops</a>. It was all in good fun for about a week.</p>
<p style="text-align: left;">Last night I had a member of the information security community raise a concern with me. There was a discussion, and in the end I was berated and called names. As such, I&#8217;ve taken down the cam streams from my site. However, I&#8217;m absolutely happy to post my script that  generated all the cam streams, since its just a updated version of the console-cowboys posting. I encourage you to <a href="http://www.shodanhq.com/data/buy" target="_blank">buy a shodan account</a> like I did, get an API key and have a look at the sort of things people find valuable enough to put on camera. You&#8217;d be surprised. Most of it is HORRIFICALLY BORING, but some of the cameras are streaming labs and industrial areas with what appear to be scada devices and other interesting stuff. I&#8217;m glad that the girl in the pizza shop had a sense of humor about it, so good on her for that.</p>
<p style="text-align: left;">I also encourage you to do some research before you buy something like an internet-enabled camera so that you better understand what it is you&#8217;re getting yourself into &#8211; there&#8217;s a chance your camera has not only a &#8216;known vulnerability&#8217;, but a flat out hardcoded backdoor, like these cameras. This is BY DESIGN. Trendnet wrote in a back door.</p>
<p style="text-align: left;">Anyhow, I was going to use this as material for my LayerOne presentation if my CFP submission got approved but if there are more infosec patrons out there like our generous benefactor here I can expect more headaches the more I talk about this stuff, so I&#8217;ll have to think of something else (sorry Noid/Datagram/M).</p>
<p style="text-align: left;"><strong>Now for the meat!</strong></p>
<p style="text-align: left;">Here&#8217;s the script: <a href="http://www.atenlabs.com/camcreep.py" target="_blank">camcreep.py</a></p>
<p>You&#8217;ll need to install gevent and shodan modules for python. Google can help you with that.</p>
<p>You&#8217;ll need a shodan API key: <a href="http://www.shodanhq.com/api_doc" target="_blank">Shodan API key</a> (insert it where it says &#8216;key =&#8217; .. you&#8217;ll see)</p>
<p>I ran this on my mac with 150 threads. It returned about 10,000 results from shodan, and took Just a hair shy of 7 minutes to run.</p>
<p>The script outputs &#8220;camlog_new.html&#8221;. Thats one giant monolithic file with ALL the cameras. You&#8217;ll want to use the linux &#8216;split&#8217; command to slice it up into various files. I manually added the page links to the bottom of those files since there were only 6 of them.</p>
<p>Also, since I did this all using chrome, I was using <a href="http://chromeunderground.blogspot.com/2011/12/ultimate-chrome-flag-extension.html">&#8220;Ultimate Chrome Flag&#8221;</a> which is a really neat extension that lets you see some IP GeoData about the site you&#8217;re on. If you right click, then open a cam stream in a new tab, you should see the little flag on the right hand side of the URL bar &#8211; that will at least tell you what city or major geographic region the camera you&#8217;re viewing is in.</p>
<p><strong>Happy Hunting!</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/get-your-creep-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adding context</title>
		<link>http://atenlabs.com/blog/adding-context/</link>
		<comments>http://atenlabs.com/blog/adding-context/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 23:24:25 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[ligatt]]></category>
		<category><![CDATA[poor security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[tentler]]></category>
		<category><![CDATA[tsk tsk]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=120</guid>
		<description><![CDATA[However good or bad you think you are at security, this may put a few details into perspective for you: In the last few weeks Ligatt Security has been &#8220;making headlines&#8221; with their 90&#8242;s-esque hackers-style commercials and advertisements &#8211; the three most notable of which advertise that large black men, 12 year old boys, and [...]]]></description>
			<content:encoded><![CDATA[<p>However good or bad you think you are at security, this may put a few details into perspective for you:</p>
<p>In the last few weeks <a href="http://www.ligattsecurity.com/">Ligatt Security</a> has been &#8220;making headlines&#8221; with their 90&#8242;s-esque hackers-style commercials and advertisements &#8211; the three most notable of which advertise that large black men, 12 year old boys, and &#8220;hackers&#8221; with what appear to be ethernet-enabled projectorgoggles are &#8220;out to get you&#8221;. Their fear-based marketing campaign slants the average computer users security experience using the standard &#8220;if you don&#8217;t hire us, your life is pretty much over&#8221; routine.</p>
<p>It&#8217;s a pretty huge bag of fail &#8211; I really hope this is a learning experience for them. One of the more important &#8216;scout badges&#8217; I&#8217;ve earned in my time as a contractor so far is &#8220;practice what you preach&#8221;. A &#8220;large&#8221;, publicly traded &#8220;information security company&#8221; probably should have taken the time to do some <a href="http://en.wikipedia.org/wiki/Cross-site_scripting"><strong><em>BASIC SECURITY</strong></em></a> on their own website &#8211; <a href="http://tinyurl.com/2cxv2d8">CLICKY!</a></p>
<p><a href="http://tinyurl.com/2cxv2d8"><img src="http://atenlabs.com/blog/wp-content/uploads/2010/06/Screen-shot-2010-06-06-at-4.05.54-PM-300x244.png" alt="virtually lol-inducing. wow, i actually typed that." title="Ligatt Security isnt very secure" width="300" height="244" class="aligncenter size-medium wp-image-122" /><br />
</a><br />
<strong><em>EDIT</em>: After a couple of twitter posts about this they&#8217;ve firewalled me off of the host. Firewalling one guy isn&#8217;t gonna help guys, I&#8217;m certain I&#8217;m not the only person to have found a CORNUCOPIA of publicly available vulnerabilities on your site.<em></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/adding-context/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paranoia, anybody?</title>
		<link>http://atenlabs.com/blog/paranoia-anybody/</link>
		<comments>http://atenlabs.com/blog/paranoia-anybody/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 02:37:08 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[rants]]></category>
		<category><![CDATA[4square]]></category>
		<category><![CDATA[absurdity]]></category>
		<category><![CDATA[facepalm]]></category>
		<category><![CDATA[foursquare]]></category>
		<category><![CDATA[getting]]></category>
		<category><![CDATA[knee jerk]]></category>
		<category><![CDATA[paranoia]]></category>
		<category><![CDATA[rob]]></category>
		<category><![CDATA[robbed]]></category>
		<category><![CDATA[someone]]></category>
		<category><![CDATA[using]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=99</guid>
		<description><![CDATA[So in a previous post, I discussed &#8220;Convergence Theory&#8220;, which is the concept that argues people will &#8220;go with the crowd&#8221;. There&#8217;s a new fad in town, and it&#8217;s all about ditching foursquare because you think you&#8217;re going to get robbed. In this case, frankly, I&#8217;m appalled. This is absurdity at its best. Lets all [...]]]></description>
			<content:encoded><![CDATA[<p>So in a previous post, I discussed &#8220;<a href="http://en.wikipedia.org/wiki/Crowd_psychology#Convergence_theory">Convergence Theory</a>&#8220;, which is the concept that argues people will &#8220;go with the crowd&#8221;. There&#8217;s a new fad in town, and it&#8217;s all about ditching foursquare because you think you&#8217;re going to get robbed.</p>
<p>In this case, frankly, I&#8217;m appalled. This is absurdity at its best. Lets all get on the paranoia choo-choo with <a href="http://mashable.com/2010/02/17/pleaserobme/">Jennifer Van Grove</a> and the silly website she&#8217;s blogging about, cancel our foursquare accounts, and go hide at home in fear. Sorry to call you out like this Jen, but this is purely knee-jerk baseless paranoia. If someone sees me IN THE PARKING LOT AT THE GROCERY STORE, then they also know I&#8217;m not home. This isn&#8217;t anything new.</p>
<p>The common complaint I have with blogposts and arguments like this is that people never think two steps ahead. Nobody ever considers engaging their foresight muscle and actually thinking this sort of thing through to conclusion.</p>
<p>I&#8217;m a security-minded person. That means I have to very often think like an attacker. I have to plan out &#8220;missions&#8221;, I have to completely exhaust all nefarious ideas and plotting in an effort to fortify the clients that hire me to make them more secure. This exercise allows me to put on an attackers hat and logistically consider courses of action in an effort to understand things like the frame of mind and context of an attacker.</p>
<p>In the last few weeks I&#8217;ve seen a lot of folks all of the sudden &#8220;realize&#8221; that when checking into foursquare this tells the internet that &#8220;you&#8217;re not at home&#8221;. Disappointingly enough the first thing that short-sighted people think is &#8220;OH GOD THIS MEANS EVERYONE KNOWS I&#8217;M NOT HOME. I&#8217;M GOING TO GET ROBBED!&#8221;. I cannot articulate using text exactly the style in which I face-palmed. To bring some clarity to those who have chosen to forego foresight, I&#8217;ve made this handy flow-chart. Have a look:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/paranoid-foursquare.jpg"><img class="aligncenter size-medium wp-image-100" title="paranoid-foursquare" src="http://atenlabs.com/blog/wp-content/uploads/2010/02/paranoid-foursquare-241x300.jpg" alt="" width="241" height="300" /></a></p>
<p>Simply put: If you&#8217;re going to rob someone, you have to put a little thought into it. You may be shot. You may be caught on camera. You may have to deal with nosy neighbors. Do you even know who this person is or where they live? Think about it for more than 30 seconds. If you&#8217;re still convinced that foursquare will get you robbed, print this chart out, and put it over your display using a stapler.</p>
<p>Stop being paranoid. Stop following the crowd. Wake up.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/paranoia-anybody/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Dealing with liars, slander and libel.</title>
		<link>http://atenlabs.com/blog/dealing-with-liars-slander-and-libel/</link>
		<comments>http://atenlabs.com/blog/dealing-with-liars-slander-and-libel/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 02:22:44 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[absurd]]></category>
		<category><![CDATA[absurdity]]></category>
		<category><![CDATA[david]]></category>
		<category><![CDATA[ed]]></category>
		<category><![CDATA[hober]]></category>
		<category><![CDATA[kaiser]]></category>
		<category><![CDATA[libel]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[newb]]></category>
		<category><![CDATA[newbies]]></category>
		<category><![CDATA[noobs]]></category>
		<category><![CDATA[o'connor]]></category>
		<category><![CDATA[rog]]></category>
		<category><![CDATA[rogelio]]></category>
		<category><![CDATA[roger]]></category>
		<category><![CDATA[rustad]]></category>
		<category><![CDATA[scubacuda]]></category>
		<category><![CDATA[slander]]></category>
		<category><![CDATA[socal]]></category>
		<category><![CDATA[socallinux.org]]></category>
		<category><![CDATA[troll]]></category>
		<category><![CDATA[trolling]]></category>
		<category><![CDATA[wannabes]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=90</guid>
		<description><![CDATA[Having been practicing information security on a freelance basis for roughly 2 years now, I&#8217;ve quickly come to learn that the information security industry is very incestuous &#8211; teeming with folks that think the standard &#8220;how to survive prison&#8221; methodology works for information security. Find someone who&#8217;s made a name for themselves, beat the everliving [...]]]></description>
			<content:encoded><![CDATA[<p>Having been practicing information security on a freelance basis for roughly 2 years now, I&#8217;ve quickly come to learn that the information security industry is very incestuous &#8211; teeming with folks that think the standard &#8220;how to survive prison&#8221; methodology works for information security. Find someone who&#8217;s made a name for themselves, beat the everliving crap out of them, assume their former glory. This is a problem. Primarily because it doesn&#8217;t work, and secondly because nobody has ever been able to do it right and get their intended results.</p>
<p>Moreso is a problem when people who have openly admitted their noviceness in linux, security and other things of a technical nature decide to take up a crusade. They&#8217;re loud, boisterous and spend lots of energy on a &#8217;cause&#8217; that they simply don&#8217;t understand. The first thing that comes to mind when thinking about these people is an angry neanderthal &#8211; angry that the wind blew out his fire, who then goes and bludgeons his neighbor with a rock out of rage, or the salem witch trials where women were called out as witches and burned alive, their pleas of innocence ignored.</p>
<p>This is exactly what I&#8217;m dealing with &#8211; novices, newbies and beginners who know little to nothing about information security, the industry surrounding it &#8211; picking up a torch and going on a crusade because of something they don&#8217;t understand.</p>
<p>I&#8217;ve been dealing with a small handful of these people, and it seems the further along I get in growing my business, the more opportunity these trolls think they have to shoot me down. I&#8217;m going to draw out, chronologically the whole series of events from then until now &#8211; including how I&#8217;ve contacted attorneys, sent cease and desist notices, and how I personally have suffered, and the friends and loves ones around me have have suffered because two guys in Riverside simply cannot act like adults. It&#8217;s a long ride, but for those interested in the whole story, end to end, read on.</p>
<p>I apologize to those who&#8217;s names I&#8217;m about to drop, who I told I&#8217;d keep out of this &#8211; but at this point it&#8217;s unavoidable. I have to name names to tell the story.</p>
<p><span id="more-90"></span>Two years ago I was just starting out freelancing. Like any energetic entrepreneur I had gotten my hands on some new hardware and some new software and was training myself to become more useful to organizations big or small which could benefit from my skills. A friend of mine, <a href="http://twitter.com/dantecl">Dante</a> invited me to a user group in Riverside. He said some people I already talk to on twitter go, and that it&#8217;s a group of linux guys. Now &#8211; I&#8217;ve been doing linux sysadmin work since 2000. I&#8217;ve met a LOT of linux sysadmins &#8211; so what I was expecting was essentially a bunch of hackers. People who work with linux, are enthusiastic about linux and have an interest in the security of linux. Oh boy was I wrong. The only linux people that were there I could count on two fingers &#8211; Myself and Dante. Everyone else may as well have come fresh from a  &#8221;Welcome to your first time booting ubuntu&#8221; class. They were &#8216;linux enthusiasts&#8217;, alright &#8211; about learning it from the ground up. No practical or vocational experience to speak of.</p>
<p>Now this was back in December of 2008, so my recollection of the EXACT events is a bit hazy. I want to say that Dante and I were among the first few people there. We met a guy named Chris and I think another person who I cannot recall at a restaurant before going to the coffeeshop. As we ate dinner everyone seemed cheerful. I was talking about my new consultancy, and spreading the word that I was openly looking for information security consulting work and hoped to give a demonstration about wireless security. After dinner we moved to the coffeeshop and I think one or two more people were there to meet us &#8211; David Kaiser being one of them. As we sat down, I got out my equipment and booted into a backtrack3 live CD. As we sat and talked, people asked me what the extra hardware was for &#8211; I explained that this was a tool used to do vulnerability assessments, and crack WEP networks to demonstrate the difference between WEP and WPA/WPA2 networks. I explained I was going to give them a demonstration. <strong>People seemed enthusiastic about it &#8211; nobody contested it at all or in any way gave me the impression that &#8220;what you&#8217;re about to do is not okay&#8221;. </strong>Afterall I did <strong>THE EXACT SAME THING </strong>at <a href="http://http://refreshsd.org/calendar/2009/01/Refresh-January-2009">Refresh San Diego</a> which is held at Qualcomm and I was applauded for it. Here is <a href="http://vimeo.com/2847947">part one</a> and <a href="http://vimeo.com/2879833">part two</a> of the video of my presentation &#8211; Give them a watch and see for yourself!</p>
<p>I explained that I was going to do a LAN attack to demonstrate <a href="http://atenlabs.com/blog/foursquare-sending-passwords-in-the-clear/">how important it is to transmit credentials with some degree of encryption</a>. Again, nobody contested it. In fact, Dante sported a bit of a grin sitting across from me. Being a regular participant in <a href="http://www.google.com/search?hl=en&amp;safe=off&amp;q=defcamp+san+diego&amp;aq=f&amp;aqi=&amp;oq=">DEFCAMP</a>, an information security based set of challenges that I used to run during <a href="http://barcampsd.org">BarCamp San Diego</a>, Dante knew exactly what was about to happen &#8211; the people in the audience whos first knee-jerk reaction is to flip out would play their part, and flip out. No damage would be done, but these newbies would have a new found enlightenment and would experience first hand what could happen if an actual malicious attacker were to attack them. This form of exercise puts the &#8220;attacker&#8221; and the &#8220;victim&#8221; right next to eachother so that everything can be seen end-to-end. This gives the &#8220;victim&#8221; insight into how the attack is carried out &#8211; and helps them understand why we use certain measures to protect against it. Having spent 3 years now organizing BarCamp San Diego and DEFCAMP, I had a direct hand  creating a warm and friendly environment for people to learn. I made a mistake assuming that even though there were 3 people there who had regularly attended BarCamp San Diego, that warm and friendly environment made its way up to Riverside that night.</p>
<p>Shortly after I had setup the equipment, Roger Rustad and another person showed up. Roger sat next to Dante, and this other person sat to my right, at the end of the table. I told Roger and his friend I was playing with backtrack3 and I was going to show demonstrate an attack. Again, the immediate response was met with <strong>enthusiasm</strong>.</p>
<p>I began by running a commonly known, commonly used application called <a href="http://ettercap.sourceforge.net/">ettercap</a>. This is a tool that is found on nearly every security linux distribution live-cd, backtrack3 being one of them. It&#8217;s designed to function exactly as I had used it &#8211; as a learning tool. By default, ettercap supports SSH and SSL decryption by way of forging certificates when already &#8216;in the middle&#8217;. Rogers friend browsed to gmail and was presented with a security certificate error very similar to this one.</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/orkut-ssl-certificate-error-1.jpg"><img class="aligncenter size-full wp-image-91" title="orkut-ssl-certificate-error-1" src="http://atenlabs.com/blog/wp-content/uploads/2010/02/orkut-ssl-certificate-error-1.jpg" alt="" width="480" height="250" /></a>I was surprised that he was unphased by this &#8211; a security certificate error for GMAIL? He clicked &#8220;okay&#8221; to the popup and continued on to gmail. Once he did that, I saw his gmail credentials pop up in the message window in ettercap. I raised my hand, interrupted everyones side conversations and asked</p>
<blockquote><p><strong>Who here just browsed to gmail.com?</strong></p></blockquote>
<p>The guy next to me raised his hand. I turned my laptop to him and showed him the captured credentials. His facial expression changed &#8211; he got angry.</p>
<blockquote><p><strong>What the hell is this?!</strong></p></blockquote>
<p><strong><span style="font-weight: normal;">He asked, throwing his arms into the air. </span></strong></p>
<blockquote><p><strong>You clicked to approve an invalid security certificate for gmail.com</strong></p></blockquote>
<p>I replied.</p>
<p>At this point the guy got VERY angry. He started yelling at me, he stood up, he told me he was going to punch me in the face and then smash my laptop and throw it across the room.</p>
<blockquote><p><strong>Dude, Relax &#8211; Do you think that if I was going to be doing this maliciously or actually trying to steal credentials, I would have SHOWN YOU what I just did? Calm down &#8211; this was only an exercise. I&#8217;m not keeping any of this, its on a Live CD.</strong></p></blockquote>
<p>He calmed down, and the conversations began again. About 5 minutes later Roger looked up at me and asked something like</p>
<blockquote><p><strong>Did you delete that log?</strong></p></blockquote>
<p>I was confused.. the conversation went something like this:</p>
<blockquote><p><strong><em>Hm? Delete what log?</em></strong></p>
<p><strong>The password you just captured. The logs. For that app you used.</strong></p>
<p><strong><em>There is no log. I closed the application already, so nothing was kept, but ettercap doesn&#8217;t log by default. And even if it did, I could simply reboot and everything that&#8217;s in memory would get wiped.</em></strong></p>
<p><strong>Then you need to stop what you&#8217;re doing and reboot right now!</strong></p>
<p><strong><em>What? Why? I just told you that I&#8217;m not keeping anything, why are you raising your voice at me?</em></strong></p>
<p><strong>You need to delete whatever it is you have over there and reboot right now! Thats fucked up! </strong></p>
<p><strong><em>Roger &#8211; Do you understand what a LiveCD is? You boot into it, everything stays in RAM, and when you reboot, it&#8217;s all gone. I didn&#8217;t keep any logs, I didn&#8217;t save any data &#8211; this was a demonstration. What the hell would I do with his password anyway? Hes changing it as we speak.</em></strong></p></blockquote>
<p>I forget where the conversation went from there, but it was clear that Roger clearly thought I was up to no good. I&#8217;m still bewildered at what he thought I could do with an expired password, but it was abundantly clear he was not interested in listening, and simply wanted me to obey his commands. After I gracefully shut down backtrack I rebooted my workstation and removed the backtrack3 cd and showed it to him, as well as turning my laptop around to demonstrate that I was now back in OSX.</p>
<p>This seemed to make him happy. The only two people at the table that had any issue with it had arrived over an hour late to the meetup, and still did not have any issue with what I was doing until I captured someones credentials. I have no idea what they thought I was going to do when I said &#8220;I&#8217;m going to give a demonstration&#8221; &#8211; perhaps they thought I was going to show a powerpoint presentation, or give a talk &#8211; maybe in retrospect I should have said &#8220;I&#8217;m going to do a live demonstration&#8221; instead of &#8220;I&#8217;m going to demonstrate an attack&#8221;. At this point I can only speculate what I could have done to inhibit the rage that Roger and his friend demonstrated, screaming, yelling, threatening me with violence and destruction of property. I took it in stride. I figured someone would come to their senses eventually. Dante and I sat quietly watching this whole thing transpire, waiting for the rage to subside. I thought it was interesting that Roger was more upset than the guy whos credentials were captured.</p>
<p>Eventually people got tired, people decided it was time to go home, I shook hands with a lot of people, I exchanged business cards with them as well &#8211; it seemed that the meetup went swimmingly, with the exception of that little bit of bad business where I was going to get &#8220;punched in the face and my laptop smashed&#8221;. This was on a Friday or a Saturday night, if I recall, because the next morning I woke up to a fairly ghastly email.</p>
<p>Roger had written a long drawn out email to the mailing list, and CC&#8217;ed me &#8211; written in the context of a board member, or some other lofty authority figure, calling me out on &#8220;stealing passwords&#8221;.</p>
<p>WHOA WHOA WHOA &#8211; I thought to myself, when I left the meetup last night everything was kosher. People shook my hands, people took my business cards. He goes on to say how the group should form some sort of committee to talk about &#8220;what happened&#8221; and &#8220;how they&#8217;re going to address it&#8221;.</p>
<p>What? Did something happen after I left? What &#8220;needs to be addressed&#8221;? They&#8217;re talking like someone admitted to the group that they had a heroin problem and there needed to be an intervention.</p>
<p>I hit reply all and composed a reply telling Roger to calm down again, and going on to say that starting a witch hunt was a stupid way to express his frustration, and that it wouldn&#8217;t do any good because the &#8220;witch&#8221; wasn&#8217;t hiding. My reply went to Roger but not to the group &#8211; apparently my attempts to join the mailing list were not approved by the administrator.</p>
<p>After about 20 minutes, my phone rang. It was Roger. He called and in a very stern and angry tone of voice began scolding me for misbehaving at his meetup group. I explained again, ad nauseum this time that there was no issue &#8211; I apologized for scaring him and his friend, and hurting his feelings and posed a very simple question:</p>
<blockquote><p><strong>Do you think that I was actually being malicious? Do you think that after telling everyone at the meetup that I was trying to go into consulting that I would immediately thereafter start trying to capture their credentials? What do you think I would do with them anyway? </strong></p></blockquote>
<p>Roger was not interested in pursuing a logical line of questioning or reason. Nor was he interested in answering any of my questions or allowing me to speak. He continued to talk over me and insisted that I should &#8220;talk to the group&#8221; about it. I explained that I had tried, but all of my emails to the mailing list were rejected. He then admitted that he <strong>knowingly told members of the group false information about what had happened.</strong> He told me that he had other phone calls with other meetup members who were of a less technical nature and used phrases like &#8220;I don&#8217;t know what he captured&#8221; and &#8220;I don&#8217;t know, he may have seen everything!&#8221;.</p>
<p>At this point I lost my temper.</p>
<blockquote><p><strong>Do you realize what you&#8217;ve done? You&#8217;ve started a panic. You&#8217;ve told a bunch of people lies &#8211; why did you tell these people that I captured stuff? You know I didn&#8217;t capture anything but what you saw &#8211; you were sitting RIGHT ACROSS FROM ME. I even showed you that I rebooted. Why would you tell people that their credentials were compromised if you didn&#8217;t know? I thought we were friends! Why would you throw me under the bus like that? You could have called me and plainly asked me what I captured. You could have given all those people who had questions my phone number or email address and told them to contact me directly &#8211; but you didn&#8217;t. Instead you spread fear and doubt. Instead, you made up a story about &#8220;Dan the evil hacker&#8221; who came to your meetup group and &#8220;did something bad&#8221;, which apparently did not yield any results, hurt anybody, or cause any damage whatsoever. You&#8217;ve started a witch hunt.</strong></p></blockquote>
<p>After my rant, Roger agreed that he could have phrased things differently to the people he talked to before calling me. He called one member of the group &#8211; who is a blind person, and flat out told him &#8220;Go change ALL your passwords! I have no idea what Dan captured! he could be spying on you right now!&#8221;. From what I&#8217;m told the blind person went into a panic &#8211; because of what Roger told him, not because of what happened at the coffee shop. Again, when people exited the coffeeshop the night of the meetup &#8211; everyone was happy, and people exchanged business cards with me.</p>
<p>At this point Roger said something like &#8220;well, no harm no foul. I guess we can move past it. Friends?&#8221;</p>
<p>My response was &#8220;Are you out of your fucking mind? You just threw me under the bus to a room full of people, and now that I&#8217;ve proven you wrong using your own words you want to be friends? How the hell can I ever trust you again? If you ever came to one of my talks you would shit your pants and label me a terrorist, then call 911. I cant trust you anymore, you&#8217;re not my friend &#8211; you&#8217;re just a troll&#8221;</p>
<p>That was that. I hung up on Roger and never spoke to him again.</p>
<p>However in June of 09 I had just landed my first Sarbanes Oxley IT compliance audit. I was VERY excited. My client and I were exchanging the required paperwork when I got an email stating they had googled me in doing some due diligence and found a forum thread &#8211; created by Roger with a duplicate of what was on the mailing list. I told him the story, I linked him to the Qualcomm RefreshSD talk and said that to the best of my ability I was unable to put to rest two attendees of a meetup group who were absolutely terrified of information security. I encouraged him to read the threads and to see the inconsistencies &#8211; there were absolutely no replies from me &#8211; they had blocked me from being able to reply or retort, and people who were not even in attendance of the meetup joined in the fun to badmouth me, call me a script kiddie and make baseless accusations and tell stories about things that &#8220;may have happened&#8221;.</p>
<p>I thought I had lost the deal for certain &#8211; but I got a call back from my client and he explained that after reading the threads it was abundantly clear that these were baseless accusations and that &#8220;You cant believe everything you read on the internet&#8221;. I was happy to have the client move forward.</p>
<p>My stomach sank though. &#8220;Crap&#8221;, I thought. &#8220;This is a big deal &#8211; if clients are finding this when googling me before I start work &#8211; this means I&#8217;m going to have to explain this to *EVERYONE*. Oh man, this is going to suck.&#8221;</p>
<p>So I composed an email to Roger, and David:</p>
<blockquote><p>Hello David,</p>
<blockquote><p>I was notified today by a client of mine that there are some scathing remarks about me publically available on the socallinux.org forums.</p>
<p>I&#8217;d like for you to make those private.</p>
<p>It&#8217;s pretty clear that you and your LUG friends don&#8217;t like me very much &#8211; and that&#8217;s fine &#8211; you&#8217;re allowed to hold whatever opinions you want.</p>
<p>My problem is that I&#8217;ve been put in a compromising situation &#8211; a discussion thread that I have no part in writing pages upon pages of scathing remarks and labeling me as a &#8220;script kiddie&#8221; &#8211; I can also see that all of my responses to roger were not included, so the whole thing is even taken out of context and is one sided as my responses and arguments are nowhere to be found.</p>
<p>The bottom line it&#8217;s hurting my ability to freelance which is how I pay my bills and rent.</p>
<p>Whatever I may have done to slight you, Im certain it didn&#8217;t cause you any grief when it came to eating and paying for where you live.</p>
<p>I&#8217;ll ask you kindly to either remove the posts or make them private.</p>
<p>Thanks in advance</p></blockquote>
<blockquote><p>-Dan<br />
atenlabs.com</p></blockquote>
</blockquote>
<p>It was ignored. I sent another letter after my first stating that when using the phrases &#8220;Not formally disclosing&#8221;, &#8220;When Dan set out to steal passwords&#8221; and &#8220;Doing things in secret&#8221; were outright lies &#8211; legally considered libel, and that they were hurting my ability to put food on the table. I used stern language in saying that if the mailing list items and forum posts were not taken down, I would be forced to come back with an attorney.</p>
<p>At that point I got a polite message back from Roger plainly giving me his address, phone number and other details &#8211; a symbolic way to say &#8220;bring it on&#8221;.</p>
<p>So I did. I hired an intellectual property attorney in Solana Beach who was referred to me by a family practice attorney. I spent a few days going over what had happened with my attorney &#8211; having him read the whole thread, showing him how ettercap works, how backtrack works and other technical details required to properly understand what happened, and what Roger and David chose to write &#8211; and how they GROSSLY differ.</p>
<p>My attorney agreed that Roger and David were being libelous, and composed a cease and desist letter stating the facts and asking Roger and David to at the bare minimum make the mailing list private. I had lost a handful of contracts already because of all the negative comments already, and I had to &#8216;stop the bleeding&#8217;. I was quickly approaching bankruptcy.</p>
<p><a href="http://atenlabs.com/blog/cease-and-desist.pdf">Here is a copy of the cease and desist letter.</a></p>
<p>I asked that the letter be sent certified mail so that we could ensure delivery. About a week later my attorney called me to let me know that both letters, one to Roger Rustad and the other to David Kaiser were both rejected. I chuckled &#8211; they had called my bluff and failed. I asked him then to send it via email, and CC me &#8211; which he did.</p>
<p>Two days after that happened, the forum on their site dissapeared. I had considered it a victory, and stopped thinking about it. I was traveling and I got a phone call from another perspective client who wanted to have a black box penetration test done against software they were developing. &#8220;Wonderful!&#8221; I exclaimed, and we exchanged NDAs and service contracts and began talking on the phone.</p>
<p>A couple days into the talks, I get a call from one of the other contracting companies in on the deal &#8211; they tell me that this client googled me, found some mailing list items about &#8220;some dispute&#8221;, and got cold feet &#8211; thereby abandoning the contract.</p>
<p>I was infuriated. I googled myself and found what exists today &#8211; a single thread on a mailing list where my full name is used very often &#8211; the same baseless allegations and accusations are made &#8211; dating all the way back to December of 2008.</p>
<p>I called my attorney back and asked him what I should do. He explained that immediately to take them to court over it could easily cost 10 to 15 thousand dollars and it may be months before the case is accepted into court, and it could be even longer to get a judgement against them. I sighed, wishing I had the money to move forward, and we agreed to put the case on hold until I was able to save up enough money to proceed. I&#8217;ve since started a savings account for this.</p>
<p>In the mean time, I had hired some friends who are SEO experts to help me at the very least bring to light all of the presentations, the community leadership, free audits and other things I&#8217;ve done in the last 5 years to help bring the tech community here together, and help spread an air of welcome and open learning.</p>
<p>After a couple weeks I had started making a lot of good progress &#8211; until one day I noticed that new entries in their mailing list had caused the thread in google to float higher in the rankings. I read it &#8211; Roger and David had began writing back to the mailing list describing how I was building a case against them for libel and defending themselves to their friends &#8211; using MORE libel. Since I had, and still have absolutely no input on that thread (They&#8217;ve since firewalled me) I cannot even issue a rebuttal on their list. Soon afterwards I started seeing things like this spammed in the comments on a handful of blogs I write on:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/commentlog.png"><img class="aligncenter size-full wp-image-92" title="commentlog" src="http://atenlabs.com/blog/wp-content/uploads/2010/02/commentlog.png" alt="" width="732" height="107" /></a></p>
<p>Whaaaaat? I looked up that IP and it&#8217;s the general area that Roger lives in. Roger full on decided to start a blackhat SEO campaign against me. He just couldn&#8217;t leave it alone. I followed the link to the blogspot URL and I saw this:</p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/blogger-site.png"><img class="aligncenter size-medium wp-image-93" title="blogger-site" src="http://atenlabs.com/blog/wp-content/uploads/2010/02/blogger-site-300x279.png" alt="Roger Rustad Blackhat SEO" width="300" height="279" /></a></p>
<p>I was a bit taken back &#8211; Perhaps my first cease and desist to Roger didn&#8217;t really sink in &#8211; I was explaining legally that I was going to pursue a lawsuit against him for damages, being able to cite in writing dollar figures for clients that walked away who directly cited his writings and Davids writings. Now he does this? SEO suicide? Does he like it in court? What? I&#8217;d love it spelled out for me.</p>
<p>The situation instantly changed from &#8220;Trolls on the internet&#8221; to  &#8221;I&#8217;m being attacked on the internet for no good reason, years after the fact&#8221;.</p>
<p>The next occurrence was again something that made me recoil &#8211; A member of BarCamp San Diego chiming into a completely unrelated mail thread directly citing Rogers email thread, calling me out to be a &#8220;fox in a henhouse&#8221; as a reply to my email about Zipline coming online. The accuser being one of a handful of people who tried to execute a coup de tas against BarCamp San Diego a few years ago. Again, entirely not surprising. It seems all this negative energy directed at me by Roger and David has garnered the attention of other folks who think badly of me. Again, best I can do is chalk it up to convergence theory &#8211; trolls &#8220;going with the crowd&#8221; &#8211; people attacking me for fun solely because other people are doing it.</p>
<p>This was a lot easier to control as I was actually able to respond to the thread. The conversation did not last long as the more that Roger and Hober talked, the clearer it became that this was about hurting me in the public eye. Their goal was to make me hurt in the pocketbook &#8211; and they accomplished that goal. All the negativity spread by Roger and Hober caused clients to walk away from me. Roger even attacked BarCamp directly, trying to link the spotless reputation of a wonderful tech community in San Diego to his previous baseless allegations of me being somehow evil. It was because of his aggressive and warrantless attacks on BarCamp San Diego that security turned him away at the door.</p>
<p>One of the subjects in the longer version of my  <a href="http://vimeo.com/8846292">How Not to be a Freelancer</a> talk was to mention &#8220;Never do business as yourself, get a fictitious business name, or an LLC&#8221;. I briefly mentioned it &#8211; but this whole debacle is directly what that bullet point addresses. I should have bought an LLC in the beginning and worked under the company name &#8211; I&#8217;m now paying the price.</p>
<p>Dan Kaminsky said it best <strong>&#8220;You can&#8217;t join the war, then walk out on the battlefield and expect NOT to get shot&#8221;</strong>.</p>
<p>This morning (Feb 9) I got call from Road Runner &#8211; my ISP. They explained that they had received a complaint that someone was &#8220;attacking&#8221; someone else from one of my IP addresses. I was told this happened at something like 3:15 in the morning. I asked the caller for more information, so I was sent a small excerpt from what looked like an apache log file which had no destination host information whatsoever. It was something like ten lines deep and contained a very old and poorly executed directory traversal attack, which appeared to be unsuccessful. I rolled my eyes. Anyone could do this to their own webserver, and then use a one-line regular expression in VI to forge the source IP. At 3:15 in the morning? On a weeknight? The same Night I had <a href="http://twitter.com/Viss/status/8828684127">picked up my girlfriend from LAX</a>? I&#8217;d be up at 3:15 in the morning trying to hack someone and not spending time with my girlfriend? Seriously?</p>
<p>Looks like Roger and David are up to no good &#8211; again. They aren&#8217;t happy leaving me alone at this point, with the damage they&#8217;ve already done to me. Its abundantly clear that whenever their standard troll lifestyles come grinding to a halt, I&#8217;m that torch they can pick back up again and wave around. I exist to these two solely as a toy.</p>
<p>My speculation is that its <a href="http://en.wikipedia.org/wiki/Crowd_psychology">convergence theory</a> &#8211; the idea that someone speaking to a crowd can influence the crowds direction &#8211; as very clearly made evident by the non-technical fellowship their group is comprised of, as well as the well-documented evidence that if left alone their stories get more and more audacious. Even now I&#8217;m seeing Rogers friends message me directly on twitter in an attempt to further yet MORE baseless accusations.</p>
<p>At this point I have to identify what is really going on here. I&#8217;ve spent so much time in &#8216;defensive&#8217; mode trying to do damage control, I didn&#8217;t take the time to do any due diligence on my attacker(s). After about half an hour looking around on the internet, I was able to find some facts &#8211; entirely NOT surprising facts:</p>
<p><a href="http://www.linux-archive.org/debian-user/33346-debian-equiv-windows-procmon.html">Roger Rustad is new to linux.</a></p>
<p><a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/gcacheindex01.png">Roger Rustad has directories full of &#8220;newbie documents&#8221;</a> <a href="http://atenlabs.com/blog/wp-content/uploads/2010/02/gcacheindex02.png">(And another!)</a></p>
<p><a href="http://www.groupstudy.com/archives/associate/200309/msg00041.html">Roger Rustad is very new to linux, again</a></p>
<p><a href="http://socallinux.org/pipermail/linuxusers/2008-January/002360.html">Roger Rustad demonstrates his lack of ability to google for an answer</a></p>
<p><a href="http://markmail.org/message/3gm3tbjvzdfvgkyn">Roger Rustad doesn&#8217;t know that you can get viruses by email</a></p>
<p><a href="http://biznik.com/members/roger-rustad">Roger Rustad is a self-proclaimed &#8220;linux hippie&#8221;</a></p>
<p>How could someone who is so green when it comes to networking and linux think that they could accuse people of being so evil &#8211; especially when they don&#8217;t understand the accusation? Why on earth is it Roger who&#8217;s doing all this attacking and not the guy whos credentials I captured? That guy I&#8217;ve never heard from again!</p>
<p>I&#8217;m not even sure what their endgame is &#8211; capturing traffic is not an end, its a means. When <a href="http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/">REAL attackers</a>, <a href="http://atenlabs.com/blog/state-of-the-pwnion/">REAL blackhats</a> capture credentials they do it by the thousands. By the <a href="http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/">TENS of thousands</a>. Attackers then use these captured credentials to send phishing emails in attempts to somehow steal money or <a href="http://www.wired.com/threatlevel/2010/02/hackers-steal-carbon-credits/">other valuable information</a>, or further compromise the accounts to send more malware or spread botnet code. Real attackers don&#8217;t go to coffee shop meetups and share the credentials they captured.</p>
<p>Every time I try to think through why they would want to do this the end I come to is &#8220;purely for their own entertainment&#8221;. They stand to gain nothing, I don&#8217;t have a competing business, I&#8217;ve left them completely alone &#8211; and even my attorney agrees with me that what they&#8217;re doing is grounds for a lawsuit.</p>
<p>Michael Caine said something that sums this situation up nicely, in a movie he was in a while ago:</p>
<blockquote><p><strong>&#8230;Because he thought it was good sport. Because some men aren&#8217;t looking for anything logical, like money. They can&#8217;t be bought, bullied, reasoned or negotiated with. Some men just want to watch the world burn.</strong></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/dealing-with-liars-slander-and-libel/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Twitter, DNS, the &#8220;Iranian cyber army&#8221; and panic &#8211; an analysis</title>
		<link>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/</link>
		<comments>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/#comments</comments>
		<pubDate>Fri, 18 Dec 2009 08:44:45 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[capture]]></category>
		<category><![CDATA[captured]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[ettiquite]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[poison]]></category>
		<category><![CDATA[poisoned]]></category>
		<category><![CDATA[sensationalism]]></category>
		<category><![CDATA[sensationalist]]></category>
		<category><![CDATA[theft]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=85</guid>
		<description><![CDATA[Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com. With the information that I know now (12:40am, 12/18): The host which contained the landing page was hosted with bluehost. This tells us a few things They didn&#8217;t have the [...]]]></description>
			<content:encoded><![CDATA[<p>Status.twitter.com tells us that DNS records were overwritten temporarily tonight by attackers to redirect HTTP traffic to another host that was originally destined for twitter.com.</p>
<p>With the information that I know now (12:40am, 12/18):</p>
<p>The host which contained the landing page was hosted with bluehost. This tells us a few things</p>
<ul>
<li>They didn&#8217;t have the infrastructure to do packet captures, or credential theft. Bluehost does shared hosting.</li>
<li>Any attempt to do so would have thrown TONS of SSL errors, and very likely DDoS&#8217;ed the server hosting the landing page. (Twitter had HUNDREDS of servers, these guys had 1.). All of your twitter apps would have thrown errors, or flat out stopped working.</li>
<li>Twitters security infrastructure was left untouched, and was not a target of the attack.</li>
</ul>
<p>I&#8217;ve been watching twitter scroll with sensationalism and panic, people yelling &#8220;OH GOD TWITTER GOT HACKED EVERYONE CHANGE YOUR PASSWORDS NOW&#8221;.</p>
<p>Please &#8211; don&#8217;t do that.</p>
<p>Its going to make everyones job harder who have to work on this situation, it incites panic and causes people to prematurely flip out and do things they probably shouldn&#8217;t do.</p>
<p>I&#8217;ve had to deal with this in the past &#8211; people throwing their arms in the air and screaming about passwords being compromised when they in fact weren&#8217;t. It did not end well.</p>
<p>Please &#8211; think before you hit send.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/twitter-dns-the-iranian-cyber-army-and-panic-an-analysis/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Hacking someones personal brand</title>
		<link>http://atenlabs.com/blog/hacking-someones-personal-brand/</link>
		<comments>http://atenlabs.com/blog/hacking-someones-personal-brand/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 20:53:21 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[branding]]></category>
		<category><![CDATA[dan]]></category>
		<category><![CDATA[daniel]]></category>
		<category><![CDATA[dave]]></category>
		<category><![CDATA[david]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[kaiser]]></category>
		<category><![CDATA[personal]]></category>
		<category><![CDATA[rog]]></category>
		<category><![CDATA[roger]]></category>
		<category><![CDATA[rustad]]></category>
		<category><![CDATA[tentler]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=75</guid>
		<description><![CDATA[I know two trolls. Roger Rustad, and David Kaiser &#8211; they run socallinux.org. If you read anything these two post on socallinux.org you can quickly determine they use this mailing list to defame whomever they choose &#8211; and because their mailing list gets both spidered by google, and mirrored by list-serv they get pretty much [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-76" title="Troll definition" src="http://atenlabs.com/blog/wp-content/uploads/2009/12/Screen-shot-2009-12-10-at-12.27.07-PM.png" alt="Troll definition" width="473" height="111" />I know two trolls. Roger Rustad, and David Kaiser &#8211; they run socallinux.org.</p>
<p>If you read anything these two post on socallinux.org you can quickly determine they use this mailing list to defame whomever they choose &#8211; and because their mailing list gets both spidered by google, and mirrored by list-serv they get pretty much automatic SEO. Multiple domain names replicating messages. And if the mailing list gets any activity for any reason the SEO goes up.</p>
<p>This is like a troll sniper rifle. You want someone to go down in flames, or you just want to make them real miserable? Talk smack about them somewhere that gets spidered by google and replicated to other sites. If anyone googles them, they&#8217;ll find listserv messages, mail-archive.com and google cache results all parroting the original messages.</p>
<p>Google is like the force. It can be used for good and evil. In this example, we&#8217;re looking at using it for evil.</p>
<p><span id="more-75"></span></p>
<p>I never really took personal branding seriously until it bit me &#8211; and upon this realization immediately found a pretty blatant &#8216;vulnerability&#8217;. Well, it&#8217;s not REALLY a vulnerability, it preys on peoples inclination to believe what they read as fact and not take any time to check up on it &#8211; so it&#8217;s more like a social hack, or social engineering. This presents an attack vector that historically could only be used by larger media outlets.</p>
<p>Now, we have google, and google cache &#8211; these tools can be used to make someone miserable for a long period of time, or sway peoples opinion on things &#8211; or to make people believe whatever you choose.</p>
<p>Google your name. Seriously &#8211; open a new tab and type your name into google &#8211; see what comes up. Go at least 3-5 pages deep.</p>
<p>Is there anything in there that would prevent a company from hiring you, or a new client from signing a contract with you?</p>
<p>There isnt? &#8211; well thats a good sign!</p>
<p>What if I started writing emails on a tiny, but public email list (like listserv, or google groups), or wrote a few blog posts talking about how evil you were, and some evil things you&#8217;ve done &#8211; even if you&#8217;d done no such evil? That might not fare so well for you the next time someone does their homework on you.</p>
<p><em>&#8220;But thats libel&#8221; </em>you say. True, that is in fact libel. People lying about you in print.</p>
<p><em>&#8220;You can sue for that!&#8221;</em> Yep &#8211; you can! It&#8217;ll cost you, probably in excess of 5 or 10 grand and you&#8217;ll end up with a court order to the defendants issuing them to take down whatever needed to be taken down (Unless you sue for damages &#8211; for example if you can prove that clients walked away from you and companies won&#8217;t hire you because they found this stuff on google).</p>
<p><em>&#8220;Wow thats a headache&#8221;</em> It absolutely is.</p>
<p>The bottom line is unless you&#8217;re prepared to throw 5-10 thousand dollars at the problem you won&#8217;t be able to do much other than ask nicely, and if asking nicely doesn&#8217;t get the job done you&#8217;re sorta boned. If you do have the money though, libel is libel &#8211; and if you can prove in court its libel, you win. Period.</p>
<p>So in summation: Using google to attack people, hurt brand names and generally troll has a VERY high success rate &#8211; but  you&#8217;re liable to get sued.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/hacking-someones-personal-brand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Go to hell, Time Warner.</title>
		<link>http://atenlabs.com/blog/go-to-hell-time-warner/</link>
		<comments>http://atenlabs.com/blog/go-to-hell-time-warner/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 23:31:17 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[rants]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[bad]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[cable]]></category>
		<category><![CDATA[ignorance]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[poor]]></category>
		<category><![CDATA[practice]]></category>
		<category><![CDATA[service]]></category>
		<category><![CDATA[staff]]></category>
		<category><![CDATA[terrible]]></category>
		<category><![CDATA[time]]></category>
		<category><![CDATA[uneducated]]></category>
		<category><![CDATA[warner]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=70</guid>
		<description><![CDATA[Let me begin by touching on the geographic disposition of internet service providers. I&#8217;m in 4s ranch, a community inside of San Diego. The cable provider is Time Warner, the phone service is PacBell and its etched into granite. I tried getting DSL from speakeasy when I first moved here but PacBell said they couldn&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p>Let me begin by touching on the geographic disposition of internet service providers. I&#8217;m in 4s ranch, a community inside of San Diego. The cable provider is Time Warner, the phone service is PacBell and its etched into granite. I tried getting DSL from speakeasy when I first moved here but PacBell said they couldn&#8217;t do it because &#8220;The cost of running the copper where it needs to go exceeds the money we&#8217;ll make by selling this line&#8221;. I was stuck with Time Warner.</p>
<p><span id="more-70"></span></p>
<p>From the beginning I got their &#8220;Business class&#8221; cable. It was 150/month for what I needed. The cablemodem would randomly drop its signal leaving me with no connection and customers that were down. It still does it. With no explanation from Time Warner.</p>
<p>The contract I signed with them was for 1 year. Within that year, they were contractually obligated to an SLA and some other things, and during that year it was pretty easy to get them on the phone, and get them to respond to issues I&#8217;ve had with their (terrible) service. Once that contract ran out, however &#8211; suddenly it was like pulling teeth to get my &#8216;accounts manager&#8217; on the phone. When I did track down the guy he told me that it was someone elses job now and to go deal with them &#8211; but they were nowhere to be found either.</p>
<p>It&#8217;s now been just a tick over four years I&#8217;ve had this line with Time Warner. I should also explain that running a business out of my home, I had two accounts on the same physical line &#8211; a home television account (which I&#8217;ve cancelled) and the business internet account. The sad part is that apparently they have no system to keep track of these things and the installers really could care less because they&#8217;re practically anonymous.</p>
<p>A few months ago I cancelled my cable and took the leap to watching what I&#8217;d normally watch on TV, on sites like hulu. This saved me over 100/mo. I&#8217;ll describe what I did</p>
<ul>
<li>Paid my final bill (which was in excess of $200), bringing my balance to 0.</li>
<li>Called Time Warner, Cancelled my cable. They told me that as long as I had the cable box, the billing would continue.</li>
<li>I returned the cable box 3 days later.</li>
<li>A month goes by</li>
<li>I get another bill from time warner for 90 dollars.</li>
<li>I call asking about the bill, wondering what it was, and the following conversation transpired:</li>
</ul>
<blockquote><p>I&#8217;m sorry sir, you still had basic cable, thats what the bill was for.</p>
<p><em>I don&#8217;t understand. Why did I still have basic cable?</em></p>
<p>I don&#8217;t know, sir. Its just what the system shows.</p>
<p><em>Does your system show that I called and cancelled my cable?</em></p>
<p>Yes, it does</p>
<p><em>So why didn&#8217;t you guys cancel my cable?</em></p>
<p>Sir, you could have plugged your tv into the wall and gotten basic cable, that&#8217;s why you were charged.</p>
<p><em>Why would I do that if I EXPLICITLY called to cancel my cable?</em></p>
<p>I don&#8217;t know sir, thats just what my system shows.</p>
<p><em>Isn&#8217;t basic cable something like 12 dollars a month?</em></p>
<p>Something like that, yes.</p>
<p><em>So how on earth could I amount a 90 dollar bill in a month with only basic cable, AFTER I&#8217;ve asked you to cancel my cable?</em></p>
<p>I don&#8217;t know sir, you&#8217;ll have to talk to someone else about it.</p></blockquote>
<ul>
<li>Now I&#8217;m getting BOTH bills from Time Warner *AND* the collection company they&#8217;ve hocked me out to. The last time I sent someone to collections (yes, I&#8217;m a business owner too, and I&#8217;ve had to deal with people who don&#8217;t pay) the procedure was to take the money the collections people give you and let them keep what they collect from the victim. Time Warner wants me to pay them *AND* the collection agency? This is completely absurd and completely not acceptable.</li>
</ul>
<p>The best part is that when I cancelled my television account with Time Warner they sent a truck out to disconnect the line &#8211; the same line I use for my business internet. This brought me down for a day and I was furious &#8211; I called them and again, they had pretty much nothing to say. I&#8217;ll be running this one up the flagpole, recording all my conversations with them and posting everything. I&#8217;m looking forward to posting audio of their representatives basically telling me &#8220;We&#8217;re bending you over the sink for 90 dollars, and we dont know why&#8221;.</p>
<p><strong>EDIT:</strong> Also, I&#8217;ve been noticing that to their consumer market they&#8217;re offering &#8217;24 megabit gaming service&#8217;. They have failed to explain why consumers that pay 20/mo can get nearly twice the bandwidth a business account can get, and adamantly refuse that its possible to do what their own ads are saying. I get these in the mail, you see. Against my will. I get ads from a company I already have products from, advertising to me WHAT I ALREADY OWN.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/go-to-hell-time-warner/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>State of the pwnion.</title>
		<link>http://atenlabs.com/blog/state-of-the-pwnion/</link>
		<comments>http://atenlabs.com/blog/state-of-the-pwnion/#comments</comments>
		<pubDate>Thu, 06 Aug 2009 20:08:45 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[speculation]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[amazon]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[computing]]></category>
		<category><![CDATA[ec2]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hak5]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[kaminsky]]></category>
		<category><![CDATA[mitnick]]></category>
		<category><![CDATA[paradigm shift]]></category>
		<category><![CDATA[pwn]]></category>
		<category><![CDATA[pwned]]></category>
		<category><![CDATA[pwnion]]></category>
		<category><![CDATA[rantpost]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[stressed induced headache]]></category>
		<category><![CDATA[zf]]></category>
		<category><![CDATA[zf0]]></category>
		<category><![CDATA[zf05]]></category>
		<category><![CDATA[zf05.txt]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=56</guid>
		<description><![CDATA[message begins Personal details were revealed, emails, chat logs &#8211; pretty scary stuff &#8211; and very sobering. A clear demonstration that things like cross site scripting and the spreading of malware (likely for the use of cascading spam or addition to botnets) is the least of our problems. Also clear proof that people who consider [...]]]></description>
			<content:encoded><![CDATA[<pre>message begins</pre>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Personal details were revealed, emails, chat logs &#8211; pretty scary stuff &#8211; and very sobering. A clear demonstration that things like cross site scripting and the spreading of malware (likely for the use of cascading spam or addition to botnets) is the least of our problems. Also clear proof that people who consider themselves security folks have to be very wary of using creature comforts such as reusing passwords or even operating a wordpress blog (3 updates in a month?! and 2.8.2 is vulnerable? gaw!).</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">The textfile the group distributed was called zf05.txt and after skimming it&#8217;s abundantly clear that wordpress played a huge part in these folks getting rooted. Almost every example was sort of an &#8216;all in one&#8217; server that was used for &#8216;whatever&#8217;. Its also become clear that jam packing one server with a bunch of services makes it more vulnerable to compromise. Ever heard of KISS? &#8220;Keep it simple, stupid&#8221;. It&#8217;s used very commonly among engineers, computer people &#8211; you name it. Anyone that has to build things or design things. The minute you start adding complexity for no reason the proverbial altimeter begins its decline.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">People who fake tech exacerbate things. There are groups that call themselves &#8220;tech&#8221; when in reality they are simply PR or Marketing. The Web 2.0 craze has hypnotized people into putting almost everything they think and do &#8216;behind the scenes&#8217;. They let someone else worry about it. Some ruby programmers I&#8217;ve met are incapable of manually issuing a sql query. Others are incapable of interacting with sql unless they have phpmyadmin. These folks generate a requirement to artificially make systems more complex and less secure entirely to suit their evergrowing hatred of looking things up themselves or actually learning anything about the technology they use every day. The easiest way to think about it is this: Think of some people. Now think of these people all owning cars. Think of these people now requiring something as simple as an oil change, a tire change, or a simple tune up. Now think of these people taking their cars to a shop to get work done &#8211; for whatever reason: maybe they lack the tools, maybe their HOA doesn&#8217;t allow them to perform work on their cars on the grounds (those HOA people desperately need to be stabbed in the lungs, by the way) or maybe they just don&#8217;t know how. Now lets imagine these people have the work done, and are talking to the mechanics as they are preparing the invoice behind the counter. The mechanic begins to explain how their oil was changed, and these people abjectly refuse to learn or understand how this works even from a top-level non-technical aspect &#8211; they plug their ears and yell &#8220;NO! NO! AAALALALALA!! NOT LISTENING NO NOOOO! ALLALAAAAAA!&#8221;.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">These people strongly support a fancy new term. &#8220;Cloud Computing&#8221;. Cloud computing will make this worse for everyone.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Let me jump away for a moment. I&#8217;d like to point out a fact. The attackers that distributed zf05.txt made a valid point &#8211; a point I&#8217;ve tried to make to peers, friends and clients alike &#8211; If your site/data are on shared hosting and you consider them secure that may mitigate some amount of risk. But if the other people hosting their data are vulnerable and your data is on the same system, you&#8217;re still vulnerable.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Now we have some ingredients &#8211; lets make a stew. Lets take these bits of information and put them all together and let it simmer.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- Non technical people whos requirements and behavior are insecure and promote systems being rooted</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- Systems with lots of various services running on them</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- A new trend of mashing these systems together to form giant systems that do the same thing, ending up being bigger and more powerful</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- Commonly used software being exploited within a week of a patch.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">Mix in a bowl with a wisk until creamy. Add a teaspoon of extra virgin olive oil to a cast-iron skillet. Add a bit of freshly cracked pepper to the oil and some freshly pressed/minced garlic. Let simmer until the pepper and garlic begin to bubble, then pour the mixture from the bowl into the skillet and add a squeeze of fresh key lime if you wish. Cook until firm or golden brown, flip once, then serve! Let stand for 10 minutes to cool. What do you get? What does it smell like? (Well if people actually taste of chicken then that may make one hell of a breakfast omlette). We dont know. Here&#8217;s why we don&#8217;t know:</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- &#8220;Business people&#8221; like the idea of getting rid of systems administrators and IT overhead</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- &#8220;Cloud Computing&#8221; does not have a security model yet</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- There are no standards &#8211; this stuff is too new</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">- Far too many people are comfortable being hacked, and say &#8220;oh there&#8217;s nothing important on that sit/box&#8221;</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">.. Really, guys? You don&#8217;t use that same wordpress password everywhere? For your bank, for gmail, for your car insurance or your mobile provider to login? If a blackhat gets that password you&#8217;re really okay with it? If thats the case, I&#8217;d like you to kindly leave the internet, never to return. Please &#8211; do us all a favor, for the people that like keeping their privates private and their secrets secret, go away.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">So we&#8217;re going to take all of these insecurities, vulnerabilities and holes &#8211; package them up with non-technical people demanding insecure practices so that they don&#8217;t have to learn or think and we&#8217;re going to replicate this ad nauseum and store the results in one gigantic computer grid system? Awesome. Maybe I should trade in my whitehat for a black one &#8211; since thats obviously where all the focus, media, fear and money are going to be. Or maybe I&#8217;ll just make my white hat bigger &#8211; perhaps people will come to their senses and listen to fact and reason. Perhaps not. I guess we&#8217;ll see.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">I&#8217;m not the only one, either&#8230;</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">http://darkreading.com/securityservices/security/app-security/showArticle.jhtml?articleID=218102139&amp;cid=RSSfeed</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">http://www.sensepost.com/blog/3706.html &#8211; open the ppt, this was the defcon talk. they pwned amazon ec2.</div>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow-x: hidden; overflow-y: hidden;">http://evilpacket.net/ &#8211; see the &#8216;theft of a rackspace cloud api key&#8217;. These guys got root on the rackspace/mosso cloud.</div>
<p>I was late to hear &#8211; by a day. Thats 10 years in internet time, we all know. If you&#8217;re not in InfoSec you probably didn&#8217;t hear. Maybe you heard somewhere, irc, twitter, other bits of the intarnets that Kevin Mitnick got hacked. Everyone chuckled. As it turns out a whole bunch of people got compromised. People I know personally who I consider friends. Rob Fuller, Dan Kaminsky, the Hak5 group and a handful of others, including Kevin Mitnick.</p>
<p>Personal details were revealed, emails, chat logs &#8211; pretty scary stuff &#8211; and very sobering. A clear demonstration that things like cross site scripting and the spreading of malware (likely for the use of cascading spam or addition to botnets) is the least of our problems. Also clear proof that people who consider themselves security folks have to be very wary of using creature comforts such as reusing passwords or even operating a wordpress blog (3 updates in a month?! and 2.8.2 is vulnerable? gaw!).</p>
<p><span id="more-56"></span></p>
<p>The textfile the group distributed was called zf05.txt and after skimming it&#8217;s abundantly clear that wordpress played a huge part in these folks getting rooted. Almost every example was sort of an &#8216;all in one&#8217; server that was used for &#8216;whatever&#8217;. Its also become clear that jam packing one server with a bunch of services makes it more vulnerable to compromise. Ever heard of KISS? &#8220;Keep it simple, stupid&#8221;. It&#8217;s used very commonly among engineers, computer people &#8211; you name it. Anyone that has to build things or design things. The minute you start adding complexity for no reason the proverbial altimeter begins its decline.</p>
<p>People who fake tech exacerbate things. There are groups that call themselves &#8220;tech&#8221; when in reality they are simply PR or Marketing. The problem here is that they advertise themselves as &#8220;technical solutions&#8221; to their clients &#8211; so the problem cascades &#8211; lots of sites/apps that go online with very very poor security which ultimately get compromised. The Web 2.0 craze has hypnotized people into putting almost everything they think and do &#8216;behind the scenes&#8217;. They let &#8220;someone else&#8221; worry about it. Guys, If YOU aren&#8217;t going to worry about the safety of your own data, NO ONE ELSE WILL. Some ruby programmers I&#8217;ve met are incapable of manually issuing a sql query. Others are incapable of interacting with sql unless they have phpmyadmin. These folks generate a requirement to artificially make systems more complex and less secure entirely to suit their evergrowing hatred of looking things up themselves or actually learning anything about the technology they use every day. The easiest way to think about it is this: Think of some people. Now think of these people all owning cars. Think of these people now requiring something as simple as an oil change, a tire change, or a simple tune up. Now think of these people taking their cars to a shop to get work done &#8211; for whatever reason: maybe they lack the tools, maybe their HOA doesn&#8217;t allow them to perform work on their cars on the grounds (those HOA people desperately need to be stabbed in the lungs, by the way) or maybe they just don&#8217;t know how. Now lets imagine these people have the work done, and are talking to the mechanics as they are preparing the invoice behind the counter. The mechanic begins to explain how their oil was changed, and these people abjectly refuse to learn or understand how this works even from a top-level non-technical aspect &#8211; they plug their ears and yell &#8220;NO! NO! AAALALALALA!! NOT LISTENING NO NOOOO! ALLALAAAAAA!&#8221;.</p>
<p>These people strongly support a fancy new term. &#8220;Cloud Computing&#8221;. Cloud computing will make this worse for everyone.</p>
<p>Let me jump away for a moment. I&#8217;d like to point out a fact. The attackers that distributed zf05.txt made a valid point &#8211; a point I&#8217;ve tried to make to peers, friends and clients alike &#8211; If your site/data are on shared hosting and you consider them secure that may mitigate some amount of risk. But if the other people hosting their data are vulnerable and your data is on the same system, you&#8217;re still vulnerable.</p>
<p>Now we have some ingredients &#8211; lets make a stew. Lets take these bits of information and put them all together and let it simmer.</p>
<ul>
<li> Non technical people whos requirements and behavior are insecure and promote systems being rooted</li>
<li> Systems with lots of various services running on them</li>
<li> A new trend of mashing these systems together to form giant systems that do the same thing, ending up being bigger and more powerful</li>
<li> Commonly used software being exploited within a week of a patch.</li>
</ul>
<p>Mix in a bowl with a wisk until creamy. Add a teaspoon of extra virgin olive oil to a cast-iron skillet. Add a bit of freshly cracked pepper to the oil and some freshly pressed/minced garlic. Let simmer until the pepper and garlic begin to bubble, then pour the mixture from the bowl into the skillet and add a squeeze of fresh key lime if you wish. Cook until firm or golden brown, flip once, then serve! Let stand for 10 minutes to cool. What do you get? What does it smell like? (Well if people actually taste of chicken then that may make one hell of a breakfast omlette). We dont know. Here&#8217;s why we don&#8217;t know:</p>
<ul>
<li>&#8220;Business people&#8221; like the idea of getting rid of systems administrators and IT overhead</li>
<li> &#8220;Cloud Computing&#8221; does not have a security model yet</li>
<li>There are no standards &#8211; this stuff is too new</li>
<li> Far too many people are comfortable being hacked, and say &#8220;oh there&#8217;s nothing important on that sit/box&#8221;</li>
</ul>
<p>.. Really, guys? You don&#8217;t use that same wordpress password everywhere? For your bank, for gmail, for your car insurance or your mobile provider to login? If a blackhat gets that password you&#8217;re really okay with it? If thats the case, I&#8217;d like you to kindly leave the internet, never to return. Please &#8211; do us all a favor, for the people that like keeping their privates private and their secrets secret, go away.</p>
<p>So we&#8217;re going to take all of these insecurities, vulnerabilities and holes &#8211; package them up with non-technical people demanding insecure practices so that they don&#8217;t have to learn or think and we&#8217;re going to replicate this ad nauseum and store the results in one gigantic computer grid system? Awesome. Maybe I should trade in my whitehat for a black one &#8211; since thats obviously where all the focus, media, fear and money are going to be. Or maybe I&#8217;ll just make my white hat bigger &#8211; perhaps people will come to their senses and listen to fact and reason. Perhaps not. I guess we&#8217;ll see.</p>
<p>I&#8217;m not the only one, either&#8230;</p>
<p><a href="http://darkreading.com/securityservices/security/app-security/showArticle.jhtml?articleID=218102139&amp;cid=RSSfeed">http://darkreading.com/securityservices/security/app-security/showArticle.jhtml?articleID=218102139&amp;cid=RSSfeed</a> &#8211; Black Hat hackers mouths are beginning to water.</p>
<p><a href="http://www.sensepost.com/blog/3706.html">http://www.sensepost.com/blog/3706.html</a> &#8211; open the ppt, this was the defcon17 &#8220;clobbering the cloud&#8221; talk. they pwned amazon ec2.</p>
<p><a href="http://evilpacket.net/">http://evilpacket.net/</a> &#8211; see the &#8216;theft of a rackspace cloud api key&#8217;. These guys got root on the rackspace/mosso cloud (you&#8217;re not supposed to be able to get a shell on rackspace&#8217;s cloud).</p>
<p>So you tell me, guys &#8211; what&#8217;s it going to be?</p>
<pre>message ends</pre>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/state-of-the-pwnion/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Making Security Research Relevant</title>
		<link>http://atenlabs.com/blog/making-security-research-relevant/</link>
		<comments>http://atenlabs.com/blog/making-security-research-relevant/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 01:50:07 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[and]]></category>
		<category><![CDATA[be safer]]></category>
		<category><![CDATA[consulting]]></category>
		<category><![CDATA[diego]]></category>
		<category><![CDATA[for]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[hire]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[infrastucture]]></category>
		<category><![CDATA[it]]></category>
		<category><![CDATA[san]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[us]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=32</guid>
		<description><![CDATA[I&#8217;m very very open and transparent about security, technology and what I do. I&#8217;ve written documentation so thorough that my clients have ended the contracts stating &#8220;we dont need you anymore &#8211; with these docs we can do the work ourselves&#8221; &#8211; in the grander scheme of things thats awesome. I love it when clients [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m very very open and transparent about security, technology and what I do. I&#8217;ve written documentation so thorough that my clients have ended the contracts stating &#8220;we dont need you anymore &#8211; with these docs we can do the work ourselves&#8221; &#8211; in the grander scheme of things thats awesome. I love it when clients learn from me and it makes me feel really good about what I do &#8211; especially if it sticks the first time &#8211; but it certainly is prohibitive towards me paying my rent.</p>
<p>I&#8217;ve been very vocal in the last year about what I do &#8211; to the point it manifests itself as talks I give during BarCamp (LA and San Diego), and Refresh San Diego which is held at Qualcomm. Here is my most recent talk</p>
<p><center><object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2847947&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=2847947&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object><br /><a href="http://vimeo.com/">Security 102, part 1</a> from <a href="http://vimeo.com/viss">Dan Tentler</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p><object width="400" height="300"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="movie" value="http://vimeo.com/moogaloop.swf?clip_id=2879833&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" /><embed src="http://vimeo.com/moogaloop.swf?clip_id=2879833&amp;server=vimeo.com&amp;show_title=1&amp;show_byline=1&amp;show_portrait=0&amp;color=&amp;fullscreen=1" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="400" height="300"></embed></object><br /><a href="http://vimeo.com/">Security102, part 2</a> from <a href="http://vimeo.com/viss">Dan Tentler</a> on <a href="http://vimeo.com">Vimeo</a>.</p>
<p>Video courtesy of <a href="http://twitter.com/northlight">@northlight</a></center><br />
<span id="more-32"></span><br />
Additionally, here is a talk that I&#8217;ve been doing at BarCamp San Diego that approaches security from a people perspective &#8211; meaning: If you can&#8217;t hack the systems, hack its operators. This story describes how people are willing to give away information to a<a href="http://blogs.wsj.com/biztech/2008/04/16/security-is-no-match-for-chocolate-and-good-looking-women/?mod=WSJBlog"> pretty girl who hands out chocoloate</a>. Heres my Talk:</p>
<p><center><object classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" width="437" height="370" id="viddler"><param name="movie" value="http://www.viddler.com/player/3e908112/" /><param name="allowScriptAccess" value="always" /><param name="allowFullScreen" value="true" /><param name="wmode" value="transparent"/><embed src="http://www.viddler.com/player/3e908112/" width="437" height="370" type="application/x-shockwave-flash" allowScriptAccess="always" allowFullScreen="true" wmode="transparent" name="viddler" ></embed></object><br />
Videos couresty of <a href="http://twitter.com/northlight">@northlight</a><br />
</center></p>
<p>I&#8217;ve decided that it&#8217;s in everyone&#8217;s best interests to at least have a dialog about security. That being said I&#8217;m now offering free consultations! To my amazement I&#8217;ve even had a few people turn down FREE HOURS from me. For the first time in quite a while I was literally without words.</p>
<p>I thought it best at that point to illustrate exactly what I mean by security. </p>
<ul>
<li><a href="http://twitpic.com/14u50">This</a> is a screenshot of the last ten days of SQL injection exploits posted to <a href="http://milw0rm.com">milw0rm.com</a>. This is *ONLY* SQL injections, not any other vulnerabilities (for everyone that thinks using magic_quotes_gpc is safe, <a href="http://search.twitter.com/search?max_id=1131544205&#038;page=2&#038;q=magic_quotes_gpc">think again</a> (and <a href="http://twitter.com/Viss/statuses/1077256407">again</a> and <a href="http://twitter.com/DjYXA/statuses/1050507177">again</a>)</li>
<li><a href="http://www.securityfocus.com/vista">Securityfocus</a>, which is a major vendor for security information has its own section JUST for Microsoft Vista.</li>
<li><a href="http://twitpic.com/kjgx">ONE command</a> line will give you a command shell on a vulnerable windows machine. That leads to installing malware, stealing passwords, reading emails &#8211; the whole nine yards &#8211; just like theyre sitting AT your computer, or on your server.</li>
<li><a href="http://twitpic.com/104fo">Using WEP for wireless security is a joke</a>. If you don&#8217;t use WPA you may as well not bother encrypting. That also leads to people sniffing your information out of the air &#8211; passwords, credentials, AIM/Yahoo conversations &#8211; everything.</li>
<li>The web2.0 community is just <a href="http://twitpic.com/rqzy">making things worse</a> by being willfully ignorant</li>
</ul>
<p>The point I&#8217;m trying to get across is that security isn&#8217;t just installing a virus scanner and an adware scanner and making sure your system is free of viruses. Code is developed every day that <a href="http://www.google.com/search?num=100&#038;hl=en&#038;lr=&#038;ie=ISO-8859-1&#038;q=%22supplied+argument+is+not+a+valid+MySQL+result+resource%22">exposes crucial information to the world, which is then indexed by google</a>. Security isn&#8217;t just about viruses, its about making your private information stay private &#8211; in all cases. Error messages that leak information such as filenames, database names, database tables, usernames etc just help attackers gain further entry into systems.</p>
<p>I do more than just security work &#8211; I&#8217;m a full-fledged Systems Architect with over ten years of experience in the field. Once you build a large scale enterprise environment, it has to be secured, right?<br />
Every once in a while during conversations at meetups I tell people that I&#8217;m a Security Researcher and a Systems Architect and they end up asking me later &#8220;so what do you actually DO?&#8221;. So heres a short list:</p>
<ul>
<li>Information Tecnhnology(IT) and Information Security(InfoSec) consulting: working directly with sales, marketing and PR departments to coach bloggers, twitter users and writers on what terminology to use, what new technology is out there, what is safe, what isn&#8217;t safe, figures and reports on the latest attacks, bot nets, viruses and other threats influencing the world</li>
<li>MSSQL and MySQL database administration, design, tuning, and security</li>
<li>Designing networks: switches, routers, firewalls, intrusion detection, backups, redundancy</li>
<li>Workflow Management: Setting up HRIS systems, ticketing systems, automating things like installations, software deployments, antivirus and other workstation maintenance procedures, creating a documentation repository using mediawiki</li>
<li>Emerging Technologies: Staying abreast of all new versions of software and hardware available, defining when and what to upgrade, planning upgrades, defining when and how to scale, choosing the right hardware and software for the job, identifying when to decommission old equipment or software and how execute it</li>
<li>Security: Staying abreast of all current and anticipated versions of software frameworks, firmwares, networking and phone equipment, defining what software and appliances need to be secured and or upgraded, defining what network resources get deployed where in the clients landscape and subequently documenting everything along the way</li>
</ul>
<p>There is no environment alien to me, no operating system I do not have experience with, no development/scripting language I have no experience with and there is no limit to what can be done with the proper resources.</p>
<p>The Rates for hours at AtenLabs are fiercely competitive and in our wake we leave nothing but courage, confidence, and smiling clients.</p>
<p>If you&#8217;re even thinking about contacting us for us for a free consultation &#8211; stop thinking and contact us.</p>
<p><center><a href="mailto:dan@atenlabs.com">info@atenlabs.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/making-security-research-relevant/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Post Mortem</title>
		<link>http://atenlabs.com/blog/post-mortem/</link>
		<comments>http://atenlabs.com/blog/post-mortem/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 21:21:32 +0000</pubDate>
		<dc:creator>Dan Tentler</dc:creator>
				<category><![CDATA[insight]]></category>
		<category><![CDATA[rants]]></category>
		<category><![CDATA[review]]></category>
		<category><![CDATA[speculation]]></category>
		<category><![CDATA[training]]></category>
		<category><![CDATA[postmorem]]></category>
		<category><![CDATA[sec101]]></category>
		<category><![CDATA[security101]]></category>

		<guid isPermaLink="false">http://atenlabs.com/blog/?p=8</guid>
		<description><![CDATA[So security101 went fairly well &#8211; people didn&#8217;t show up until later, and I had spent too much time screwing aroung with ettercap and MITM attacks to have enough battery to complete the entirety of the talk with all the examples I had hoped for. Some of the attendees ended up asking lots of questions [...]]]></description>
			<content:encoded><![CDATA[<p>So security101 went fairly well &#8211; people didn&#8217;t show up until later, and I had spent too much time screwing aroung with ettercap and MITM attacks to have enough battery to complete the entirety of the talk with all the examples I had hoped for.</p>
<p>Some of the attendees ended up asking lots of questions so the &#8216;flow&#8217; I had envisioned sort of went out the window &#8211; but I&#8217;d much rather have people interested and actively asking me questions: It shows interest. I&#8217;d rather have interest then have them all silent while I blather on and on.</p>
<p>We all ended up at my place afterwards and I was giving short demos on MITM dns tomfoolery, rewriting all queries for microsoft.com to linux.com, and doing SSL MITM attacks against hotmail using ettercap. Pretty fun stuff!</p>
<p>I&#8217;ll be holding the class again for anybody that missed it the first time and wants to have it again, but I haven&#8217;t chosen a date yet.</p>
<p>If you&#8217;re interested in a date, please leave a comment! I&#8217;d like to hold the class when more people can attend.</p>
]]></content:encoded>
			<wfw:commentRss>http://atenlabs.com/blog/post-mortem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

