<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paranoid Prose</title>
	<atom:link href="http://www.paranoidprose.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paranoidprose.com</link>
	<description>reading to keep you up at night</description>
	<lastBuildDate>Fri, 27 Jan 2012 16:19:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>all your encryption passwords are belong to the cops</title>
		<link>http://www.paranoidprose.com/2012/01/27/all-your-encryption-passwords-are-belong-to-the-cops/</link>
		<comments>http://www.paranoidprose.com/2012/01/27/all-your-encryption-passwords-are-belong-to-the-cops/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 16:19:44 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[deep thoughts]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=771</guid>
		<description><![CDATA[Interesting and depressing post from Ars Technica: A federal judge has ruled that a Colorado woman can be compelled to decrypt her encrypted laptop so that the police can inspect it for incriminating evidence. The woman, Ramona Fricosu, is a defendant in a mortgage scam case. She had argued that the Fifth Amendment&#8217;s privilege against [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 610px"><img title="Miranda" src="http://www.houstoncriminallawjournal.com/uploads/image/mrianda.jpg" alt="" width="600" height="600" /><p class="wp-caption-text">...but you do have to give up your passwords</p></div>
<p>Interesting and depressing post from Ars Technica:</p>
<blockquote><p>A federal judge has ruled that a Colorado woman can be compelled to decrypt her encrypted laptop so that the police can inspect it for incriminating evidence. The woman, Ramona Fricosu, is a defendant in a mortgage scam case. She had argued that the Fifth Amendment&#8217;s privilege against self-incrimination protected her from having to disclose the password to her hard drive, which was encrypted using PGP Desktop.</p></blockquote>
<p>The rest of the sordid details can be found <a href="http://arstechnica.com/tech-policy/news/2012/01/judge-fifth-amendment-doesnt-protect-encrypted-hard-drives.ars" target="_blank" onclick="pageTracker._trackPageview('/outgoing/arstechnica.com/tech-policy/news/2012/01/judge-fifth-amendment-doesnt-protect-encrypted-hard-drives.ars?referer=');">here</a>.</p>
<p>It seems to me that forcing someone to reveal a password to  a computer which might contain incriminating documents should be construed in the same way as forcing them to provide other self incriminating testimony.   Just saying&#8230;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2012%2F01%2F27%2Fall-your-encryption-passwords-are-belong-to-the-cops%2F&amp;title=all%20your%20encryption%20passwords%20are%20belong%20to%20the%20cops" id="wpa2a_2" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2012_2F01_2F27_2Fall-your-encryption-passwords-are-belong-to-the-cops_2F_amp_title=all_20your_20encryption_20passwords_20are_20belong_20to_20the_20cops?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2012/01/27/all-your-encryption-passwords-are-belong-to-the-cops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>doing the shmoo</title>
		<link>http://www.paranoidprose.com/2012/01/27/doing-the-shmoo/</link>
		<comments>http://www.paranoidprose.com/2012/01/27/doing-the-shmoo/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 16:02:50 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[my travels]]></category>
		<category><![CDATA[useful stuff]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=767</guid>
		<description><![CDATA[Greetings from Washington, DC &#8211; the home of corrupt politicians, sleazy lobbyists, democracy destroying SuperPACs and Moby Dick House of Kebab.  I&#8217;m here to attend ShmooCon, which is (IMHO) one of the better security cons out there.  I&#8217;ll be blogging about what I learn over the next few days, so stay tuned for some cutting [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Capitol Building" src="http://b5media_b4.s3.amazonaws.com/28/files/2008/07/uscapitolbuildingstatueinwashingtond1.jpg" alt="" width="333" height="500" />Greetings from Washington, DC &#8211; the home of corrupt politicians, sleazy lobbyists, democracy destroying SuperPACs and <a href="http://www.mobysonline.com/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.mobysonline.com/?referer=');">Moby Dick House of Kebab</a>.  I&#8217;m here to attend <a href="http://www.shmoocon.org/" onclick="pageTracker._trackPageview('/outgoing/www.shmoocon.org/?referer=');">ShmooCon</a>, which is (IMHO) one of the better security cons out there.  I&#8217;ll be blogging about what I learn over the next few days, so stay tuned for some cutting edge security goodness.  Interested in anything specific on the schedule?  Drop me a line at al@al-berg.com or DM me at @alberg on the Twitter.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2012%2F01%2F27%2Fdoing-the-shmoo%2F&amp;title=doing%20the%20shmoo" id="wpa2a_4" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2012_2F01_2F27_2Fdoing-the-shmoo_2F_amp_title=doing_20the_20shmoo?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2012/01/27/doing-the-shmoo/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>your printers may not explode, but they might give hackers entree into your networks</title>
		<link>http://www.paranoidprose.com/2012/01/02/your-printers-may-not-explode-but-they-might-give-hackers-entree-into-your-networks/</link>
		<comments>http://www.paranoidprose.com/2012/01/02/your-printers-may-not-explode-but-they-might-give-hackers-entree-into-your-networks/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 22:09:48 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=756</guid>
		<description><![CDATA[So, remember a few weeks back, when the tech press got really silly, warning us that hackers could set our HP printers on fire remotely?  Well, it turns out that there was a security story about HP printers, but the press really missed the boat on what was actually important.  At the 28th Chaos Communications [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 370px"><img class=" " title="Bomb" src="http://files.turbosquid.com/Preview/Content_2009_07_13__20_08_45/bomb1.jpg930ec69f-2900-4f4d-bdcb-a92471fc0c82Larger.jpg" alt="" width="360" height="360" /><p class="wp-caption-text">No, this is NOT HP&#39;s latest printer...</p></div>
<p>So, remember a few weeks back, when the tech press got really silly, warning us that <a href="http://gawker.com/5863388/hackers-could-turn-your-printer-into-a-flaming-death-bomb" onclick="pageTracker._trackPageview('/outgoing/gawker.com/5863388/hackers-could-turn-your-printer-into-a-flaming-death-bomb?referer=');">hackers could set our HP printers on fire remotely?</a>  Well, it turns out that there was a security story about HP printers, but the press really missed the boat on what was actually important.  At the 28th Chaos Communications Congress (held in Berlin last week), the Columbia University researchers whose work was totally misconstrued by the press <a href="http://events.ccc.de/congress/2011/Fahrplan/events/4780.en.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/events.ccc.de/congress/2011/Fahrplan/events/4780.en.html?referer=');">presented their work</a>.  No, hackers cannot set your printer on fire &#8211; but they can install malware on hundreds of millions HP printers shipped since 2005, either by connecting to the printer and replacing its normal firmware with evil firmware or by getting one of your users to print out a specially crafted document which also carries their nefarious code.  Once this hack is done, your printer will become a silent (but deadly) bridgehead into your network.</p>
<p>UPDATE:  <a href="http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449&amp;jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0" target="_blank" onclick="pageTracker._trackPageview('/outgoing/h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c03102449_amp_jumpid=em_alerts_us-us_Dec11_xbu_all_all_1514802_101529_printersandmultifunctionscanners-copiers-faxes_critical_000_0&amp;referer=');">Here&#8217;s a list</a> of all of the printers affected by this vulnerability.</p>
<p>The researchers had two demos.  In the first, they caused the infected printer to silently send a copy of every document it printed to an attacker&#8217;s printer out on the Internet.  Demo two had the infected printer acting looking for internal systems vulnerable to a Windows XP exploit and then acting as a relay for the attacker to control them from outside the firewall.  This was pretty scary stuff&#8230; let&#8217;s say I send a crafted document purporting to contain a 50% off coupon for a local restaurant to your users&#8230; how many times (and on how many printers) would this get printed?</p>
<p>This hack is made possible by the fact that some HP printers allow their firmware to be updated without any authentication or digital signature and that all of the code within the printer runs as a super user.  It also points out the need for anti malware protections for embedded devices like printers, routers and the like.  The guys at Columbia are working on a project to do this.</p>
<p>As an aside, these same researchers scanned the Internet for accessible HP printers &#8211; they found over 75,000 of them, located at private companies, governments, educational institutions and in other places.  Infecting just a small percentage of these systems would provide someone with a very stealthy botnet that would be extremely difficult to remove.  The researchers feel that it may be possible for the attackers to install their code permanently, so that the only ways to get rid of the infection would be by replacing (soldered on surface mount) hardware components or trashing the printer altogether,</p>
<p>So&#8230; what to do?</p>
<p>First, update your HP printers&#8217; firmware to the latest (December 2011 or later) firmware version, which can be found over on <a href="http://www8.hp.com/us/en/support-drivers.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www8.hp.com/us/en/support-drivers.html?referer=');">the HP support website.</a>  The new drivers require printer firmware updates to be digitally signed by HP.</p>
<p>Next, make sure that your printers cannot be accessed from the Internet.  For most of my readers, I don&#8217;t think this will be an issue, but you never know&#8230; scan your Internet facing IPs for port 9100, which is used to submit print jobs and firmware updates to HP printers.</p>
<p>Third, limit where your printers can send traffic to&#8230; is there any good reason to allow a printer outbound access to the Internet?  Not that I can think of.  Putting printers on an isolated VLAN which can ONLY talk to the print server limits the damage that can be done using this attack.  Of course you really need to make sure that your print servers are patched and properly isolated as well &#8211; and when eas the last time you took a look at your print servers?</p>
<p>We&#8217;ve all got some work to do, people but more importantly, we need to look at embedded systems like printers, routers, access points, and the like in a new way &#8211; as potential malware targets with the computing power to take down our networks and no antivirus protection.  I can just about guarantee that the bad guys will be researching this in 2012 &#8211; it is just too juicy a target to ignore.</p>
<p>If you are a security pro or are responsible for printers in your organization, I&#8217;d recommend spending an hour watching the video of this presentation to get the full story.</p>
<p><iframe src="http://www.youtube.com/embed/njVv7J2azY8" frameborder="0" width="560" height="315"></iframe></p>
<p>&nbsp;</p>
<p>Happy New Year, all.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2012%2F01%2F02%2Fyour-printers-may-not-explode-but-they-might-give-hackers-entree-into-your-networks%2F&amp;title=your%20printers%20may%20not%20explode%2C%20but%20they%20might%20give%20hackers%20entree%20into%20your%20networks" id="wpa2a_6" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2012_2F01_2F02_2Fyour-printers-may-not-explode-but-they-might-give-hackers-entree-into-your-networks_2F_amp_title=your_20printers_20may_20not_20explode_2C_20but_20they_20might_20give_20hackers_20entree_20into_20your_20networks?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2012/01/02/your-printers-may-not-explode-but-they-might-give-hackers-entree-into-your-networks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>hacking 1903 style for the lulz</title>
		<link>http://www.paranoidprose.com/2011/12/31/hacking-1903-style-for-the-lulz/</link>
		<comments>http://www.paranoidprose.com/2011/12/31/hacking-1903-style-for-the-lulz/#comments</comments>
		<pubDate>Sun, 01 Jan 2012 00:27:34 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[hacks]]></category>
		<category><![CDATA[humor]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=754</guid>
		<description><![CDATA[OK&#8230; this story is a bit older than that movie&#8230; but it is even cooler &#8211; hacking 1903 style for the lulz!]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter" title="marconi" src="http://projectbritain.com/calendar/images/march/marconi.jpg" alt="" width="436" height="296" /></p>
<p style="text-align: center;">OK&#8230; <a href="http://www.newscientist.com/article/mg21228440.700-dotdashdiss-the-gentleman" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.newscientist.com/article/mg21228440.700-dotdashdiss-the-gentleman?referer=');">this story</a> is a bit older than that movie&#8230; but it is even cooler &#8211; hacking 1903 style for the lulz!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F31%2Fhacking-1903-style-for-the-lulz%2F&amp;title=hacking%201903%20style%20for%20the%20lulz" id="wpa2a_8" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F31_2Fhacking-1903-style-for-the-lulz_2F_amp_title=hacking_201903_20style_20for_20the_20lulz?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/31/hacking-1903-style-for-the-lulz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>the world&#8217;s first hacker movie?</title>
		<link>http://www.paranoidprose.com/2011/12/31/the-worlds-first-hacker-movie/</link>
		<comments>http://www.paranoidprose.com/2011/12/31/the-worlds-first-hacker-movie/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 23:56:36 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[humor]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=749</guid>
		<description><![CDATA[I just watched Hot Millions, a 1968 film which just might be the world&#8217;s first hacker film&#8230; with Peter Ustinov as the hacker.  As a computer security professional, I can state that this is a completely factual and realistic portrayal of the challenges we face every day &#8211; including blowing the lid off of the [...]]]></description>
			<content:encoded><![CDATA[<p>I just watched <a href="http://www.imdb.com/title/tt0063094/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.imdb.com/title/tt0063094/?referer=');">Hot Millions</a>, a 1968 film which just might be the world&#8217;s first hacker film&#8230; with Peter Ustinov as the hacker.  As a computer security professional, I can state that this is a completely factual and realistic portrayal of the challenges we face every day &#8211; including blowing the lid off of the critical blue lights which protect computers from embezzlers and other evil doers (other than the cleaning lady).  A must view for all security pros and those that love them.</p>
<p><object id="ep" width="400" height="325" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowfullscreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://i.cdn.turner.com/v5cache/TCM/cvp/container/mediaroom_embed.swf?context=embed&amp;videoId=16682" /><embed id="ep" width="400" height="325" type="application/x-shockwave-flash" src="http://i.cdn.turner.com/v5cache/TCM/cvp/container/mediaroom_embed.swf?context=embed&amp;videoId=16682" allowfullscreen="true" allowscriptaccess="always" /></object></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F31%2Fthe-worlds-first-hacker-movie%2F&amp;title=the%20world%26%238217%3Bs%20first%20hacker%20movie%3F" id="wpa2a_10" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F31_2Fthe-worlds-first-hacker-movie_2F_amp_title=the_20world_26_238217_3Bs_20first_20hacker_20movie_3F?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/31/the-worlds-first-hacker-movie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>this hash can give your servers indigestion</title>
		<link>http://www.paranoidprose.com/2011/12/31/this-hash-can-give-your-servers-indigestion/</link>
		<comments>http://www.paranoidprose.com/2011/12/31/this-hash-can-give-your-servers-indigestion/#comments</comments>
		<pubDate>Sat, 31 Dec 2011 21:27:46 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[hacks]]></category>
		<category><![CDATA[useful stuff]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=744</guid>
		<description><![CDATA[When Microsoft comes out with an out of cycle security advisory (and during a holiday week, no less), you know something big is up.  This week&#8217;s bulletin highlights a denial of service attack and two privilege escalation vulnerabilities that affect web sites built on top of ASP.NET.   The most serious privilege escalation vulnerability could [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 366px"><img title="hash" src="http://www.fsis.usda.gov/images_recalls/033_2007_HASH10.jpg" alt="" width="356" height="292" /><p class="wp-caption-text">Doesn&#39;t that look tasty...</p></div>
<p>When Microsoft comes out with an <a href="http://technet.microsoft.com/en-us/security/bulletin/ms11-100" target="_blank" onclick="pageTracker._trackPageview('/outgoing/technet.microsoft.com/en-us/security/bulletin/ms11-100?referer=');">out of cycle security advisory</a> (and during a holiday week, no less), you know something big is up.  This week&#8217;s bulletin highlights a denial of service attack and two privilege escalation vulnerabilities that affect web sites built on top of ASP.NET.   The most serious privilege escalation vulnerability could allow an attacker to execute commands on a system by sending specially crafted web requests.</p>
<p>The denial of service issue is related to a flaw in the way that ASP.NET (as well as PHP, Ruby and Java) handle the hash tables which are used to pass information from user web inputs to the web server.  By sending specially crafted requests to vulnerable web servers, it is possible to tie up all of their CPU resources and make them unavailable to legitimate users.  This attack was revealed at this past week&#8217;s Chaos Communications Congress in Berlin &#8211; you can watch the presentation <a href="http://youtu.be/R2Cq3CLI6H8" target="_blank" onclick="pageTracker._trackPageview('/outgoing/youtu.be/R2Cq3CLI6H8?referer=');">here</a>.</p>
<p>There is a very good technical description of the DoS problem and attack <a href="http://cryptanalysis.eu/blog/2011/12/28/effective-dos-attacks-against-web-application-plattforms-hashdos/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/cryptanalysis.eu/blog/2011/12/28/effective-dos-attacks-against-web-application-plattforms-hashdos/?referer=');">here</a>.</p>
<p>The DoS flaw is also present in PHP, Python, some Java web frameworks, and Ruby.   <a href="http://tomcat.apache.org/tomcat-7.0-doc/changelog.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/tomcat.apache.org/tomcat-7.0-doc/changelog.html?referer=');">Apache Tomcat 7.0.23 </a>contains a workaround fix which limits the number of parameters accepted in a POST request.  <a href="http://www.php.net/archive/2011.php#id2011-12-25-1" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.php.net/archive/2011.php_id2011-12-25-1?referer=');">PHP version 5.4.0</a> will include a workaround fix for this problem, but is not yet ready for production use.   <a href="http://www.ruby-forum.com/topic/3312298" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.ruby-forum.com/topic/3312298?referer=');">Ruby version 1.9 and higher has a fix</a> which solves the problem by randomizing the hash tables.</p>
<p>Given the recent &#8216;hacktivist&#8217; activity we have been seeing, it would not surprise me if this attack was used against sites in the financial industry as well as in the public sector.  In any case, the Microsoft patch is a must for your web facing ASP.NET systems now.  The US-CERT&#8217;s <a href="http://www.kb.cert.org/vuls/id/903934" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.kb.cert.org/vuls/id/903934?referer=');">vulnerability page</a> for this issue is a good place to keep track of vendors&#8217; responses as more platforms are found to be vulnerable.</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F31%2Fthis-hash-can-give-your-servers-indigestion%2F&amp;title=this%20hash%20can%20give%20your%20servers%20indigestion" id="wpa2a_12" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F31_2Fthis-hash-can-give-your-servers-indigestion_2F_amp_title=this_20hash_20can_20give_20your_20servers_20indigestion?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/31/this-hash-can-give-your-servers-indigestion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>authentication via butt-prints?</title>
		<link>http://www.paranoidprose.com/2011/12/28/authentication-via-butt-prints/</link>
		<comments>http://www.paranoidprose.com/2011/12/28/authentication-via-butt-prints/#comments</comments>
		<pubDate>Wed, 28 Dec 2011 21:17:22 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[authentication]]></category>
		<category><![CDATA[humor]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=742</guid>
		<description><![CDATA[From the &#8220;you can&#8217;t make this stuff up&#8221; file&#8230; Cars of the future may use the driver’s rear end as identity protection, through a system developed at Japan’s Advanced Institute of Industrial Technology. A report surfaced earlier this month that researchers there developed a system that can recognize a person by the backside when the [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 233px"><img class=" " title="Pork Butt" src="http://www.competitionplus.com/2005_08/photos/nhra_indy/pork_butt.jpg" alt="" width="223" height="210" /><p class="wp-caption-text">Tasty snack... or identity theft tool??</p></div>
<p>From the &#8220;you can&#8217;t make this stuff up&#8221; file&#8230;</p>
<p><strong>Cars of the future may use the driver’s rear end as identity protection, through a system developed at Japan’s Advanced Institute of Industrial Technology. A report surfaced earlier this month that researchers there developed a system that can recognize a person by the backside when the person takes a seat. The system performs a precise measurement of the person’s posterior, its contours and the way the person applies pressure on the seat. The developers say that in lab tests, the system was able to recognize people with 98 percent accuracy.  </strong></p>
<p><strong></strong>To get to the bottom of this story,<a href="http://www.physorg.com/news/2011-12-unleash-car-seat-rear.html" onclick="pageTracker._trackPageview('/outgoing/www.physorg.com/news/2011-12-unleash-car-seat-rear.html?referer=');"> read more here</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F28%2Fauthentication-via-butt-prints%2F&amp;title=authentication%20via%20butt-prints%3F" id="wpa2a_14" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F28_2Fauthentication-via-butt-prints_2F_amp_title=authentication_20via_20butt-prints_3F?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/28/authentication-via-butt-prints/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>beware the thumb (drive) of doom</title>
		<link>http://www.paranoidprose.com/2011/12/26/beware-the-thumb-drive-of-doom/</link>
		<comments>http://www.paranoidprose.com/2011/12/26/beware-the-thumb-drive-of-doom/#comments</comments>
		<pubDate>Tue, 27 Dec 2011 02:53:06 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=737</guid>
		<description><![CDATA[So, you just found a USB thumb drive that someone left behind on a bus/train/taxi/spaceship&#8230; read this article BEFORE you plug it in to your computer&#8230; and, come to think of it, before you use a thumb drive to store anything remotely important or private.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="thumb drive" src="http://www.instablogsimages.com/images/2008/10/19/severed-thumb-usb_xlHOn_2263.jpg" alt="" width="330" height="247" />So, you just found a USB thumb drive that someone left behind on a bus/train/taxi/spaceship&#8230; read <a href="http://nakedsecurity.sophos.com/2011/12/07/lost-usb-keys-have-66-percent-chance-of-malware" target="_blank" onclick="pageTracker._trackPageview('/outgoing/nakedsecurity.sophos.com/2011/12/07/lost-usb-keys-have-66-percent-chance-of-malware?referer=');">this article</a> BEFORE you plug it in to your computer&#8230; and, come to think of it, before you use a thumb drive to store anything remotely important or private.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F26%2Fbeware-the-thumb-drive-of-doom%2F&amp;title=beware%20the%20thumb%20%28drive%29%20of%20doom" id="wpa2a_16" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F26_2Fbeware-the-thumb-drive-of-doom_2F_amp_title=beware_20the_20thumb_20_28drive_29_20of_20doom?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/26/beware-the-thumb-drive-of-doom/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>stale java</title>
		<link>http://www.paranoidprose.com/2011/12/01/stale-java/</link>
		<comments>http://www.paranoidprose.com/2011/12/01/stale-java/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 23:22:41 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=730</guid>
		<description><![CDATA[I hate Java.  Not the country or the beverage, but the programming language.  Actually, not so much the language, but the way that it is used and distributed to PC and Mac users.  A recent report from Microsoft stated that between one third and one half of the malware that they saw between 3Q 2010 [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 290px"><img class=" " title="Map of Java" src="http://www.lonelyplanet.com/maps/asia/indonesia/java/map_of_java.jpg" alt="" width="280" height="210" /><p class="wp-caption-text">oops - wrong Java!</p></div>
<p>I hate Java.  Not the country or the beverage, but the programming language.  Actually, not so much the language, but the way that it is used and distributed to PC and Mac users.  A recent report from Microsoft stated that between one third and one half of the malware that they saw between 3Q 2010 and 2Q 2011 was written in Java.  Java is a natural target for malware writers &#8211; it is cross platform and is installed on just about every computer used to connect to the Internet.  Java is a force multiplier for the bad guys.   Like any other software, the Java Runtime Environment (JRE), which allows Java applets to run on your computer, has its share of security flaws which are then exploited by attackers.  Recently, one &#8220;pernicious&#8221; Java exploit which had only been available for purchase in the &#8220;computer underground&#8221; was <a href="http://krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/krebsonsecurity.com/2011/11/public-java-exploit-amps-up-threat-level/?referer=');">made available in the Metasploit toolkit</a>, which allows less skilled attackers to use it to craft their attacks.</p>
<p>If you are reading this on a computer that you own personally, stop right now and make sure that you are running the latest version of Java and other browser plugins on your system &#8211; <a href="http://browsercheck.qualys.com" target="_blank" onclick="pageTracker._trackPageview('/outgoing/browsercheck.qualys.com?referer=');">Qualys has a nice site which does this for you automatically</a>.  Go ahead, I&#8217;ll wait&#8230;</p>
<p>In enterprises, upgrading Java is not as easy as it would seem.  Many applications used by business were written with a particular version of Java in mind and they will stop working if you do the &#8220;right thing&#8221; and upgrade the JRE.  As a result, many organizations are stuck with old and vulnerable versions of Java running on their systems.</p>
<p>There are solutions to this problem, involving installation of the new Java Runtime Engine along side the old one and then playing with the PATH or JAVA_HOME environment variables to tell Java which version of the JRE to invoke.  I&#8217;m going to be doing some research on this and will post the results.</p>
<p>In the mean time, a plea to applet developers&#8230; please make your software compatible with the newer, safer versions of Java.  Let&#8217;s close down malware writers&#8217; access via this particular hole.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F01%2Fstale-java%2F&amp;title=stale%20java" id="wpa2a_18" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F01_2Fstale-java_2F_amp_title=stale_20java?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/01/stale-java/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>noted &#8211; the unlikely event</title>
		<link>http://www.paranoidprose.com/2011/12/01/noted-the-unlikely-event/</link>
		<comments>http://www.paranoidprose.com/2011/12/01/noted-the-unlikely-event/#comments</comments>
		<pubDate>Thu, 01 Dec 2011 21:04:32 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[my travels]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=726</guid>
		<description><![CDATA[As I am spending the month of December circling the planet on aircraft, this article from The Paris Review resonated with me&#8230;]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Man on fire" src="http://www.blog.spoongraphics.co.uk/wp-content/uploads/2008/04/safety-illustration.gif" alt="" width="270" height="209" />As I am spending the month of December circling the planet on aircraft, <a href="http://www.theparisreview.org/blog/2011/11/28/the-art-of-not-drowning/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.theparisreview.org/blog/2011/11/28/the-art-of-not-drowning/?referer=');">this article from The Paris Review</a> resonated with me&#8230;</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.paranoidprose.com%2F2011%2F12%2F01%2Fnoted-the-unlikely-event%2F&amp;title=noted%20%26%238211%3B%20the%20unlikely%20event" id="wpa2a_20" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save_url=http_3A_2F_2Fwww.paranoidprose.com_2F2011_2F12_2F01_2Fnoted-the-unlikely-event_2F_amp_title=noted_20_26_238211_3B_20the_20unlikely_20event?referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2011/12/01/noted-the-unlikely-event/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

