<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; Security</title> <atom:link href="http://m32consulting.com/category/security/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Tue, 13 Mar 2012 21:54:58 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>Critical Flaw In RDP Exposes ALL Versions of Windows To Remote Code Execution Risk</title><link>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk</link> <comments>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/#comments</comments> <pubDate>Tue, 13 Mar 2012 21:54:58 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Corporate]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[attacker]]></category> <category><![CDATA[black tuesday]]></category> <category><![CDATA[code]]></category> <category><![CDATA[code execution]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[isc]]></category> <category><![CDATA[microsoft]]></category> <category><![CDATA[network]]></category> <category><![CDATA[RDP]]></category> <category><![CDATA[rdp protocol]]></category> <category><![CDATA[release]]></category> <category><![CDATA[remote desktop]]></category> <category><![CDATA[risk]]></category> <category><![CDATA[SANS]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[vulnerability]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[worm]]></category> <category><![CDATA[Wormable]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=245</guid> <description><![CDATA[An EXTREMELY critical flaw in Microsoft&#8217;s RDP protocol (Remote Desktop) has been discovered and disclosed by Microsoft today. This vulnerability is about as critical as they get; especially for corporate customers. In short, any attacker who sends specially crafted code to any computer running Microsoft Windows that hat has Remote Desktop enabled can essentially take control of [...]]]></description> <content:encoded><![CDATA[<div
class="wp-caption alignright" style="width: 266px"><a
href="http://en.wikipedia.org/wiki/File:Remote_desktop_connection_icon.PNG" target="_blank"><img
class="zemanta-img-inserted zemanta-img-configured" title="Remote Desktop Connection Icon" src="http://upload.wikimedia.org/wikipedia/en/b/b0/Remote_desktop_connection_icon.PNG" alt="Remote Desktop Connection Icon" width="256" height="256" /></a><p
class="wp-caption-text">Image via Wikipedia</p></div><p>An <strong>EXTREMELY </strong>critical flaw in <a
class="zem_slink" title="Microsoft" href="http://www.forbes.com/companies/microsoft/" rel="forbes" target="_blank">Microsoft&#8217;s</a> <a
class="zem_slink" title="Remote Desktop Protocol" href="http://en.wikipedia.org/wiki/Remote_Desktop_Protocol" rel="wikipedia" target="_blank">RDP</a> protocol (<a
class="zem_slink" title="Remote Desktop Services" href="http://www.microsoft.com/windowsserver2008/en/us/rds-product-home.aspx" rel="homepage" target="_blank">Remote Desktop</a>) has been discovered and disclosed by Microsoft today. This vulnerability is about as critical as they get; especially for corporate customers. In short, any attacker who sends specially crafted code to any computer running Microsoft <a
class="zem_slink" title="Windows" href="http://www.microsoft.com/WINDOWS" rel="homepage" target="_blank">Windows</a> that hat has Remote Desktop enabled can essentially take control of it. Microsoft has already released an article about it <a
title="Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387)" href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020" target="_blank">here</a> (<a
href="http://technet.microsoft.com/en-us/security/bulletin/ms12-020">MS12-020</a>).</p><p>All users are advised to update their machines as soon as possible, as this nasty exploit has the potential to become very nasty, very fast.</p><p>&nbsp;</p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.networkworld.com/news/2012/030912-microsoft-to-patch-windows-bug-257141.html?source=nww_rss" target="_blank">Microsoft to patch Windows bug called &#8216;Holy Grail&#8217; by one researcher</a> (networkworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://support.microsoft.com/kb/2671387" target="_blank">KB 2671387</a> (support.microsoft.com)</li><li
class="zemanta-article-ul-li"><a
href="http://isc.sans.edu/diary.html?storyid=12775&amp;rss" target="_blank">March 2012 Microsoft Black Tuesday, (Tue, Mar 13th)</a> (isc.sans.edu)</li><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/businesscenter/article/251760/microsoft_issues_urgent_patch_for_wormable_rdp_vulnerability.html" target="_blank">Microsoft Issues Urgent Patch for &#8216;Wormable&#8217; RDP Vulnerability</a> (pcworld.com)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=90b6d9d2-10a7-4c47-a2a0-e7ebc640d755" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/attacker/" title="attacker" rel="tag">attacker</a>, <a
href="http://m32consulting.com/tag/black-tuesday/" title="black tuesday" rel="tag">black tuesday</a>, <a
href="http://m32consulting.com/tag/code/" title="code" rel="tag">code</a>, <a
href="http://m32consulting.com/tag/code-execution/" title="code execution" rel="tag">code execution</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/isc/" title="isc" rel="tag">isc</a>, <a
href="http://m32consulting.com/tag/microsoft/" title="microsoft" rel="tag">microsoft</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/rdp/" title="RDP" rel="tag">RDP</a>, <a
href="http://m32consulting.com/tag/rdp-protocol/" title="rdp protocol" rel="tag">rdp protocol</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/remote-desktop/" title="remote desktop" rel="tag">remote desktop</a>, <a
href="http://m32consulting.com/tag/risk/" title="risk" rel="tag">risk</a>, <a
href="http://m32consulting.com/tag/sans/" title="SANS" rel="tag">SANS</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a>, <a
href="http://m32consulting.com/tag/windows/" title="Windows" rel="tag">Windows</a>, <a
href="http://m32consulting.com/tag/worm/" title="worm" rel="tag">worm</a>, <a
href="http://m32consulting.com/tag/wormable/" title="Wormable" rel="tag">Wormable</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2012/03/critical-flaw-in-rdp-exposes-all-versions-of-windows-to-remote-code-execution-risk/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>DreamHost Shell/FTP Account Database Compromised, ALL Passwords Reset</title><link>http://m32consulting.com/2012/01/dreamhost-shellftp-account-database-compromised-all-passwords-reset/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=dreamhost-shellftp-account-database-compromised-all-passwords-reset</link> <comments>http://m32consulting.com/2012/01/dreamhost-shellftp-account-database-compromised-all-passwords-reset/#comments</comments> <pubDate>Sun, 22 Jan 2012 23:37:02 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[blog]]></category> <category><![CDATA[breach]]></category> <category><![CDATA[cms]]></category> <category><![CDATA[Compromised]]></category> <category><![CDATA[isc]]></category> <category><![CDATA[Password]]></category> <category><![CDATA[Server]]></category> <category><![CDATA[ssh]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[user data]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=240</guid> <description><![CDATA[According to DreamHost&#8217;s Status and Blog, staff noticed some unusual activity on one of their databases that held user login information for shell accounts. While the passwords were mostly  encrypted, hackers &#8220;hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted,&#8221; according to  DreamHost CEO Simon [...]]]></description> <content:encoded><![CDATA[<div
class="wp-caption alignright" style="width: 271px"><a
href="http://en.wikipedia.org/wiki/File:Dreamhost_logo.svg" target="_blank"><img
class="zemanta-img-inserted zemanta-img-configured" title="DreamHost Logo" src="http://upload.wikimedia.org/wikipedia/en/thumb/8/88/Dreamhost_logo.svg/261px-Dreamhost_logo.svg.png" alt="DreamHost Logo" width="261" height="261" /></a><p
class="wp-caption-text">Image via Wikipedia</p></div><p>According to <a
title="Changing Shell/FTP Passwords due to Security Issue" href="http://www.dreamhoststatus.com/2012/01/20/changing-ftpshell-passwords-due-to-security-issue/" target="_blank">DreamHost&#8217;s Status</a> and <a
title="Security Update" href="http://blog.dreamhost.com/2012/01/21/security-update/" target="_blank">Blog</a>, staff noticed some unusual activity on one of their <a
class="zem_slink" title="Database" href="http://en.wikipedia.org/wiki/Database" rel="wikipedia" target="_blank">databases</a> that held user login information for shell accounts. While the passwords were mostly  encrypted, hackers &#8220;hacker found a legacy pool of unencrypted FTP/shell passwords in a database table that we had not previously deleted,&#8221; <a
href="http://blog.dreamhost.com/2012/01/21/security-update/comment-page-1/#comment-173554" target="_blank">according to  DreamHost CEO Simon Anderson.</a></p><p>As a precaution, ALL shell/FTP account passwords were reset by DreamHost. While it will cause some inconvenience for users trying to access their sites over SSH/FTP, the implications are much more serious. A lot of <a
class="zem_slink" title="Content management system" href="http://en.wikipedia.org/wiki/Content_management_system" rel="wikipedia" target="_blank">CMS systems</a> store their database username and passwords in plaintext on configuration files. If whoever gained access to DreamHost&#8217;s <a
class="zem_slink" title="Shell account" href="http://en.wikipedia.org/wiki/Shell_account" rel="wikipedia" target="_blank">shell account</a> database and managed to decrypt the information, then they would have unmitigated access to not only sites&#8217; files, but they could potentially (and most likely) gain access to the back-end database driving those sites with all user data. This could be a very major breach of user data from one of the largest web hosts in the United States.</p><p>DreamHost is being unusually mum about the technical details about the hack and is angering customers over their negligence regarding out-dated server software. While most front-end software is kept up-to-date, their back-end software is grossly outdated and there appears to be no real effort nor care by DreamHost to keep <a
class="zem_slink" title="Operating system" href="http://en.wikipedia.org/wiki/Operating_system" rel="wikipedia" target="_blank">OS</a> and back-end software updated. What makes things worse is that DreamHost&#8217;s official stance on their security solution is to not disclose what technologies they use. Rather than taking a proactive and relatively transparent stance to their own security systems, the company has decided to take-up a reactive and a &#8220;security through obscurity&#8221; stance.</p><p>&nbsp;</p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://blog.sucuri.net/2012/01/dreamhost-security-issue-prompts-ftp-password-resets.html" target="_blank">DreamHost Security Issue Prompts FTP Password Resets</a> (sucuri.net)</li><li
class="zemanta-article-ul-li"><a
href="http://www.dreamhoststatus.com/2012/01/20/changing-ftpshell-passwords-due-to-security-issue/" target="_blank">Changing Shell/FTP Passwords due to Security Issue</a> (dreamhoststatus.com)</li><li
class="zemanta-article-ul-li"><a
href="http://blog.dreamhost.com/2012/01/21/security-update/" target="_blank">Security Update</a> (dreamhost.com)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=c530b2f2-94db-478a-92fe-e72eecf6eb1d" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/blog/" title="blog" rel="tag">blog</a>, <a
href="http://m32consulting.com/tag/breach/" title="breach" rel="tag">breach</a>, <a
href="http://m32consulting.com/tag/cms/" title="cms" rel="tag">cms</a>, <a
href="http://m32consulting.com/tag/compromised/" title="Compromised" rel="tag">Compromised</a>, <a
href="http://m32consulting.com/tag/isc/" title="isc" rel="tag">isc</a>, <a
href="http://m32consulting.com/tag/password/" title="Password" rel="tag">Password</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/server/" title="Server" rel="tag">Server</a>, <a
href="http://m32consulting.com/tag/ssh/" title="ssh" rel="tag">ssh</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/user-data/" title="user data" rel="tag">user data</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2012/01/dreamhost-shellftp-account-database-compromised-all-passwords-reset/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Mobile Carriers In Very Hot Water Over Carrier IQ &#8220;Rootkit&#8221;</title><link>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit</link> <comments>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/#comments</comments> <pubDate>Thu, 01 Dec 2011 19:04:55 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Customer]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Your Rights]]></category> <category><![CDATA[Android]]></category> <category><![CDATA[CarrierIQ]]></category> <category><![CDATA[Cell]]></category> <category><![CDATA[developers]]></category> <category><![CDATA[eckhart]]></category> <category><![CDATA[galaxy]]></category> <category><![CDATA[isc]]></category> <category><![CDATA[kit]]></category> <category><![CDATA[Logs]]></category> <category><![CDATA[middleware]]></category> <category><![CDATA[power]]></category> <category><![CDATA[release]]></category> <category><![CDATA[Rootkit]]></category> <category><![CDATA[Samsung]]></category> <category><![CDATA[SMS]]></category> <category><![CDATA[Sprint]]></category> <category><![CDATA[Trevor Eckhart]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[violation of privacy]]></category> <category><![CDATA[XDA Developers]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=229</guid> <description><![CDATA[I first took attention to Carrier IQ when it was discovered by custom ROM developers for the phone I personally have; the Sprint Epic4G made by Samsung. The device is part of the massively popular Galaxy S line of Android-powered devices that virtually every major cellular carrier in the world sells. Around June, it was [...]]]></description> <content:encoded><![CDATA[<div
class="wp-caption alignright" style="width: 213px"><a
href="http://www.crunchbase.com/company/carrier-iq" target="_blank"><img
class="zemanta-img-inserted zemanta-img-configured" title="Image representing Carrier IQ as depicted in C..." src="http://www.crunchbase.com/assets/images/resized/0003/4918/34918v1-max-450x450.png" alt="Image representing Carrier IQ as depicted in C..." width="203" height="63" /></a><p
class="wp-caption-text">Image via CrunchBase</p></div><p>I first took attention to <a
class="zem_slink" title="Carrier IQ" href="http://www.crunchbase.com/company/carrier-iq" rel="crunchbase" target="_blank">Carrier IQ</a> when it was discovered by custom ROM developers for the phone I personally have; the Sprint Epic4G made by Samsung. The device is part of the massively popular Galaxy S line of Android-powered devices that virtually every major cellular carrier in the world sells. Around June, it was discovered that this software records virtually everything a user does with their phone from each screen-tap to every site they visit to recording audio and even the physical orientation of the device itself.</p><p>A thread (which I now cannot find on <a
class="zem_slink" title="XDA Developers" href="http://xda-developers.com/" rel="homepage" target="_blank">XDA-Developers</a>) outlined this &#8220;middleware&#8221; and it was surmised that individual Carriers like Sprint used it solely for coverage and troubleshooting issues. An effort was undertaken to remove this software from the Android Linux kernel as it was discovered to hinder the device&#8217;s performance. Developers notably had a very difficult time removing Carrier IQ, but managed to eventually remove it for their custom Android ROMs.</p><p>Fast forward to Fall of 2011 where a developer named Trevor Eckhart decided to look into Carrier IQ a bit deeper and found that Carrier IQ was essentially a rootkit and actually recorded almost all actions performed with a device it was installed on and phoned home with that information. He has released a video showing proof of Carrier IQ recording his location with location turned off, un-encrypted HTTPS streams, all SMS messages sent/received, and even EVERY touch of the device screen he makes.</p><p><a
href="http://www.youtube.com/watch?v=T17XQI_AYNo">Carrier IQ Part #2</a></p><p>Essentially what everything boils down to is that carriers can spy on literally everything you do with your phone. This is obviously a blatant violation of privacy rights and repercussions are sure to come. Developing&#8230;</p><p>&nbsp;</p><p>&nbsp;</p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/article/245229/carrier_iq_rootkit_logs_everything_on_millions_of_phones.html" target="_blank">Carrier IQ Rootkit Reportedly Logs Everything On Millions Of Phones</a> (pcworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://gizmodo.com/5864123/you-can-test-your-android-for-carrier-iq-sort-of" target="_blank">You Can Test Your Android For Carrier IQ (Sort Of) [Carrier Iq]</a> (gizmodo.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.businessinsider.com/carrier-iq-2011-12" target="_blank">People Are Freaking Out About Carrier IQ, The Hidden Smartphone Program That Tracks Everything You Do</a> (businessinsider.com)</li><li
class="zemanta-article-ul-li"><a
href="http://techcrunch.com/2011/12/01/carrier-iq-how-to-find-it-and-how-to-deal-with-it/" target="_blank">Carrier IQ: How To Find It, And How To Deal With It &#8211; TechCrunch</a> (techcrunch.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.businessinsider.com/blackberry-carrier-iq-2011-12" target="_blank">Silicon Alley Insider: RIM: We Do Not Authorize Carrier IQ On BlackBerry Phones (RIMM)</a> (businessinsider.com)</li><li
class="zemanta-article-ul-li"><a
href="http://gigaom.com/2011/12/01/verizon-no-carrieriq-no-way/" target="_blank">Verizon: No CarrierIQ, No way</a> (gigaom.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.zdnet.com/blog/hardware/so-theres-a-rootkit-hidden-in-millions-of-cellphones/16708" target="_blank">So, there&#8217;s a rootkit hidden in millions of cellphones</a> (zdnet.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.textually.org/textually/archives/2011/12/029871.htm" target="_blank">Phone &#8216;Rootkit&#8217; Maker Carrier IQ May Have Violated Wiretap Law In Millions Of Cases</a> (textually.org)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=d3d557d6-4c31-40d8-900f-c3eaee90d41f" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/android/" title="Android" rel="tag">Android</a>, <a
href="http://m32consulting.com/tag/carrieriq/" title="CarrierIQ" rel="tag">CarrierIQ</a>, <a
href="http://m32consulting.com/tag/cell/" title="Cell" rel="tag">Cell</a>, <a
href="http://m32consulting.com/tag/developers/" title="developers" rel="tag">developers</a>, <a
href="http://m32consulting.com/tag/eckhart/" title="eckhart" rel="tag">eckhart</a>, <a
href="http://m32consulting.com/tag/galaxy/" title="galaxy" rel="tag">galaxy</a>, <a
href="http://m32consulting.com/tag/isc/" title="isc" rel="tag">isc</a>, <a
href="http://m32consulting.com/tag/kit/" title="kit" rel="tag">kit</a>, <a
href="http://m32consulting.com/tag/logs/" title="Logs" rel="tag">Logs</a>, <a
href="http://m32consulting.com/tag/middleware/" title="middleware" rel="tag">middleware</a>, <a
href="http://m32consulting.com/tag/power/" title="power" rel="tag">power</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/rootkit/" title="Rootkit" rel="tag">Rootkit</a>, <a
href="http://m32consulting.com/tag/samsung/" title="Samsung" rel="tag">Samsung</a>, <a
href="http://m32consulting.com/tag/sms/" title="SMS" rel="tag">SMS</a>, <a
href="http://m32consulting.com/tag/sprint/" title="Sprint" rel="tag">Sprint</a>, <a
href="http://m32consulting.com/tag/trevor-eckhart/" title="Trevor Eckhart" rel="tag">Trevor Eckhart</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/violation-of-privacy/" title="violation of privacy" rel="tag">violation of privacy</a>, <a
href="http://m32consulting.com/tag/xda-developers/" title="XDA Developers" rel="tag">XDA Developers</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/12/mobile-carriers-in-very-hot-water-over-carrier-iq-rootkit/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>German Researchers Find &#8220;Massive&#8221; Flaws In Cloud Security</title><link>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=german-researchers-find-massive-flaws-in-cloud-security</link> <comments>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/#comments</comments> <pubDate>Wed, 26 Oct 2011 18:53:23 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Cloud]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Firewalls]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[amazon]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[aws]]></category> <category><![CDATA[computing]]></category> <category><![CDATA[ec2]]></category> <category><![CDATA[EucalyptusEucalyptus (computing)]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[information security]]></category> <category><![CDATA[network]]></category> <category><![CDATA[s3]]></category> <category><![CDATA[soap]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[XML]]></category> <category><![CDATA[XSS]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=221</guid> <description><![CDATA[NetworkWorld has a very interesting writeup about a report that six German Information Security researchers published outlining very massive and highly exploitable flaws in Cloud Computing services; specifically Amazon&#8217;s EC2 and S3 as well as Eucalyptus Cloud Computing Software. Old concepts like XSS and what is referred to as XML Signature Wrapping attacks on the SOAP interfaces [...]]]></description> <content:encoded><![CDATA[<div
class="zemanta-img" style="margin: 1em; display: block;"><div
class="wp-caption alignright" style="width: 266px"><a
href="http://commons.wikipedia.org/wiki/File:Cloud_computing_icon.svg" target="_blank"><img
class="zemanta-img-configured" title="Cloud computing icon" src="http://upload.wikimedia.org/wikipedia/commons/thumb/1/12/Cloud_computing_icon.svg/256px-Cloud_computing_icon.svg.png" alt="Cloud computing icon" width="256" height="179" /></a><p
class="wp-caption-text">Image via Wikipedia</p></div></div><p>NetworkWorld has a very interesting writeup about a report that six German Information Security researchers published outlining very massive and highly exploitable flaws in <a
class="zem_slink" title="Cloud computing" href="http://en.wikipedia.org/wiki/Cloud_computing" rel="wikipedia">Cloud Computing</a> services; specifically <a
class="zem_slink" title="Amazon EC2" href="http://aws.amazon.com/ec2/" rel="homepage">Amazon&#8217;s EC2</a> and S3 as well as Eucalyptus Cloud Computing Software. Old concepts like XSS and what is referred to as <a
class="zem_slink" title="XML Signature" href="http://en.wikipedia.org/wiki/XML_Signature" rel="wikipedia">XML Signature</a> Wrapping attacks on the <a
class="zem_slink" title="SOAP" href="http://en.wikipedia.org/wiki/SOAP" rel="wikipedia">SOAP</a> interfaces of the aforementioned cloud services. Very troubling and a large blow to the legitimacy of  security in the cloud.</p><p><a
title="All Your Clouds are Belong to us – Security Analysis of Cloud Management Interfaces" href="http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf" target="_blank">The full PDF of the German researchers&#8217; findings can be found here.</a></p><p>&nbsp;</p><p><a
title="Researchers find &quot;massive&quot; security flaws in cloud architectures" href="http://www.networkworld.com/news/2011/102611-security-cloud-252406.html" target="_blank">NetworkWorld Article</a></p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/article/242598/researchers_demo_cloud_security_issue_with_amazon_aws_attack.html">Researchers Demo Cloud Security Issue With Amazon AWS Attack</a> (pcworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/cloud-computing/researchers-demo-cloud-security-issue-amazon-aws-hijacking-attack-177179&amp;a=59897468&amp;rid=9fea2dfa-23e7-4226-869e-44aec161f55a&amp;e=e607e310bd8532578036b34a2b4a2074">Researchers demo cloud security issue with Amazon AWS hijacking attack</a> (infoworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.physorg.com/news/2011-10-cloud-gaps.html">Cloud computing: Gaps in the &#8216;cloud&#8217;</a> (physorg.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.networkworld.com/news/2011/102611-researchers-demo-cloud-security-issue-252403.html?source=nww_rss" target="_blank">Researchers demo cloud security issue with Amazon AWS attack</a> (networkworld.com)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=9fea2dfa-23e7-4226-869e-44aec161f55a" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/amazon/" title="amazon" rel="tag">amazon</a>, <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/aws/" title="aws" rel="tag">aws</a>, <a
href="http://m32consulting.com/tag/computing/" title="computing" rel="tag">computing</a>, <a
href="http://m32consulting.com/tag/ec2/" title="ec2" rel="tag">ec2</a>, <a
href="http://m32consulting.com/tag/eucalyptuseucalyptus-computing/" title="EucalyptusEucalyptus (computing)" rel="tag">EucalyptusEucalyptus (computing)</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/information-security/" title="information security" rel="tag">information security</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/s3/" title="s3" rel="tag">s3</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/soap/" title="soap" rel="tag">soap</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/xml/" title="XML" rel="tag">XML</a>, <a
href="http://m32consulting.com/tag/xss/" title="XSS" rel="tag">XSS</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Virus targets US Predator and Reaper drones</title><link>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=virus-targets-us-predator-and-reaper-drones</link> <comments>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/#comments</comments> <pubDate>Fri, 07 Oct 2011 21:29:53 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[code]]></category> <category><![CDATA[computer virus]]></category> <category><![CDATA[cybersecurity]]></category> <category><![CDATA[drone]]></category> <category><![CDATA[keystroke]]></category> <category><![CDATA[malicious code]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[MQ-9 ReaperMQ-9 Reaper]]></category> <category><![CDATA[nist]]></category> <category><![CDATA[predator]]></category> <category><![CDATA[reaper drones]]></category> <category><![CDATA[War on TerrorismWar on Terrorism]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=216</guid> <description><![CDATA[A computer virus has infected the cockpits of America&#8217;s Predator and Reaper drones, logging pilots&#8217; every keystroke as they remotely fly missions over Afghanistan and other war zones. The name of the virus is yet to be known, as details are still emerging about how the malicious code got into the systems in the first [...]]]></description> <content:encoded><![CDATA[<p>A computer virus has infected the cockpits of America&#8217;s Predator and Reaper drones, logging pilots&#8217; every keystroke as they remotely fly missions over Afghanistan and other war zones. The name of the virus is yet to be known, as details are still emerging about how the malicious code got into the systems in the first place. Could this be a belligerent enemy to US forces attacking their main weapon in use for remote regions? Ars Technica has the story after the jump.</p><p><a
href="http://arstechnica.com/business/news/2011/10/exclusive-computer-virus-hits-drone-fleet.ars">Computer virus hits US Predator and Reaper drone fleet</a>.</p>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/breaches/" title="Breaches" rel="tag">Breaches</a>, <a
href="http://m32consulting.com/tag/code/" title="code" rel="tag">code</a>, <a
href="http://m32consulting.com/tag/computer-virus/" title="computer virus" rel="tag">computer virus</a>, <a
href="http://m32consulting.com/tag/cybersecurity/" title="cybersecurity" rel="tag">cybersecurity</a>, <a
href="http://m32consulting.com/tag/drone/" title="drone" rel="tag">drone</a>, <a
href="http://m32consulting.com/tag/keystroke/" title="keystroke" rel="tag">keystroke</a>, <a
href="http://m32consulting.com/tag/malicious-code/" title="malicious code" rel="tag">malicious code</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/mq-9-reapermq-9-reaper/" title="MQ-9 ReaperMQ-9 Reaper" rel="tag">MQ-9 ReaperMQ-9 Reaper</a>, <a
href="http://m32consulting.com/tag/nist/" title="nist" rel="tag">nist</a>, <a
href="http://m32consulting.com/tag/predator/" title="predator" rel="tag">predator</a>, <a
href="http://m32consulting.com/tag/reaper-drones/" title="reaper drones" rel="tag">reaper drones</a>, <a
href="http://m32consulting.com/tag/war-on-terrorismwar-on-terrorism/" title="War on TerrorismWar on Terrorism" rel="tag">War on TerrorismWar on Terrorism</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>WordPress.org Possibly Compromised, Resets ALL Passwords</title><link>http://m32consulting.com/2011/06/wordpress-org-possibly-compromised-resets-all-passwords/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=wordpress-org-possibly-compromised-resets-all-passwords</link> <comments>http://m32consulting.com/2011/06/wordpress-org-possibly-compromised-resets-all-passwords/#comments</comments> <pubDate>Wed, 22 Jun 2011 00:40:44 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Addthis]]></category> <category><![CDATA[BuddyPress]]></category> <category><![CDATA[cms]]></category> <category><![CDATA[code]]></category> <category><![CDATA[Compromised]]></category> <category><![CDATA[founder]]></category> <category><![CDATA[Matt Mullenweg]]></category> <category><![CDATA[News]]></category> <category><![CDATA[W3 Totalcache]]></category> <category><![CDATA[WordPress]]></category> <category><![CDATA[wordpress plugins]]></category> <category><![CDATA[wordpress.org]]></category> <category><![CDATA[WPTouch]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=206</guid> <description><![CDATA[WordPress founder Matt Mullenweg posted on WordPress.org&#8217;s News page today that several popular WordPress plugins had changes committed to them that had been determined to not be from their developers. The commits actually added back doors that would compromise potentially hundreds of thousands of WordPress installations that utilized them. As a precautionary measure, all changes were reverted for these [...]]]></description> <content:encoded><![CDATA[<p><a
title="Passwords Reset" href="http://wordpress.org/news/2011/06/passwords-reset/" target="_blank">WordPress founder Matt Mullenweg posted on WordPress.org&#8217;s News page today</a> that several popular WordPress plugins had changes committed to them that had been determined to not be from their developers. The commits actually added back doors that would compromise potentially hundreds of thousands of WordPress installations that utilized them. As a precautionary measure, all changes were reverted for these plugins and ALL passwords to WordPress.org, BuddyPress.org, and bbPress.org reset. There aren&#8217;t many more details as of yet, but there is sure to be a witch hunt over the integrity of WordPress.org&#8217;s security as well as all code that powers the CMS.</p>Tags: <a
href="http://m32consulting.com/tag/addthis/" title="Addthis" rel="tag">Addthis</a>, <a
href="http://m32consulting.com/tag/buddypress/" title="BuddyPress" rel="tag">BuddyPress</a>, <a
href="http://m32consulting.com/tag/cms/" title="cms" rel="tag">cms</a>, <a
href="http://m32consulting.com/tag/code/" title="code" rel="tag">code</a>, <a
href="http://m32consulting.com/tag/compromised/" title="Compromised" rel="tag">Compromised</a>, <a
href="http://m32consulting.com/tag/founder/" title="founder" rel="tag">founder</a>, <a
href="http://m32consulting.com/tag/matt-mullenweg/" title="Matt Mullenweg" rel="tag">Matt Mullenweg</a>, <a
href="http://m32consulting.com/tag/news/" title="News" rel="tag">News</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/w3-totalcache/" title="W3 Totalcache" rel="tag">W3 Totalcache</a>, <a
href="http://m32consulting.com/tag/wordpress/" title="WordPress" rel="tag">WordPress</a>, <a
href="http://m32consulting.com/tag/wordpress-plugins/" title="wordpress plugins" rel="tag">wordpress plugins</a>, <a
href="http://m32consulting.com/tag/wordpress-org/" title="wordpress.org" rel="tag">wordpress.org</a>, <a
href="http://m32consulting.com/tag/wptouch/" title="WPTouch" rel="tag">WPTouch</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/06/wordpress-org-possibly-compromised-resets-all-passwords/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>British Game Developer Codemasters Breached, Tens of Thousands of Accounts Compromised</title><link>http://m32consulting.com/2011/06/british-game-developer-codemasters-breached-tens-of-thousands-of-accounts-compromised/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=british-game-developer-codemasters-breached-tens-of-thousands-of-accounts-compromised</link> <comments>http://m32consulting.com/2011/06/british-game-developer-codemasters-breached-tens-of-thousands-of-accounts-compromised/#comments</comments> <pubDate>Mon, 13 Jun 2011 17:55:17 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[bbc]]></category> <category><![CDATA[british game]]></category> <category><![CDATA[codemasters]]></category> <category><![CDATA[Compromised]]></category> <category><![CDATA[Facebook]]></category> <category><![CDATA[offline]]></category> <category><![CDATA[personal data]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=203</guid> <description><![CDATA[British game developer Codemasters, who develops games for almost every platform out there, has had its site breached and has had &#8216;tens of thousands&#8217; of customers&#8217; personal data stolen. According to the BBC:  The firm described the data theft as "significant" saying names, addresses, phone numbers and dates of birth were all taken on 3 [...]]]></description> <content:encoded><![CDATA[<p>British game developer Codemasters, who develops games for almost every platform out there, has had its site breached and has had &#8216;tens of thousands&#8217; of customers&#8217; personal data stolen. <a
title="Personal data stolen from UK developer Codemasters" href="http://www.bbc.co.uk/news/technology-13731822" target="_blank">According to the BBC</a>:</p><pre> The firm described the data theft as "significant" saying names, addresses, phone numbers and dates of birth were all taken on 3 June.</pre><p>The company has since taken its website offline and visitors are now directed to Codemasters&#8217; Facebook page for the meantime. This is yet another example of companies learning the hard way that IT security infrastructure is not something that should be neglected.</p><p>Details on who was responsible for the theft and methods used to carry out the attack are as of yet unknown.</p>Tags: <a
href="http://m32consulting.com/tag/bbc/" title="bbc" rel="tag">bbc</a>, <a
href="http://m32consulting.com/tag/british-game/" title="british game" rel="tag">british game</a>, <a
href="http://m32consulting.com/tag/codemasters/" title="codemasters" rel="tag">codemasters</a>, <a
href="http://m32consulting.com/tag/compromised/" title="Compromised" rel="tag">Compromised</a>, <a
href="http://m32consulting.com/tag/facebook/" title="Facebook" rel="tag">Facebook</a>, <a
href="http://m32consulting.com/tag/offline/" title="offline" rel="tag">offline</a>, <a
href="http://m32consulting.com/tag/personal-data/" title="personal data" rel="tag">personal data</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/06/british-game-developer-codemasters-breached-tens-of-thousands-of-accounts-compromised/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>LulzSec Hacks Sony&#8230;Again&#8230;And Scores PSN Source Code</title><link>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=lulzsec-hacks-sony-again-and-scores-psn-source-code</link> <comments>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/#comments</comments> <pubDate>Tue, 07 Jun 2011 00:56:38 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Corporate]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[ACHIEVEMENT]]></category> <category><![CDATA[Cell]]></category> <category><![CDATA[floating point]]></category> <category><![CDATA[geohotz]]></category> <category><![CDATA[George Hotz]]></category> <category><![CDATA[IBM]]></category> <category><![CDATA[ibm cell processor]]></category> <category><![CDATA[legal assault]]></category> <category><![CDATA[lulz]]></category> <category><![CDATA[LulzSec]]></category> <category><![CDATA[OtherOS]]></category> <category><![CDATA[pbs]]></category> <category><![CDATA[playstation 3]]></category> <category><![CDATA[point performance]]></category> <category><![CDATA[ps3]]></category> <category><![CDATA[psn]]></category> <category><![CDATA[release]]></category> <category><![CDATA[sony hq]]></category> <category><![CDATA[Source]]></category> <category><![CDATA[supercomputer]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=201</guid> <description><![CDATA[LulzSec, also known as Lulz Security, which has become infamous for their past and more recent hacks including PBS and Sony, has hacked Sony HQ&#8230;again. This time they scored around 54 megabytes of the developer&#8217;s source code to the PlayStation Network. What does it mean? Hold on to your butts. The group published a press [...]]]></description> <content:encoded><![CDATA[<p>LulzSec, also known as Lulz Security, which has become infamous for their past and more recent hacks including PBS and Sony, has hacked Sony HQ&#8230;again. This time they scored around <a
title="LulzSec Claims Another Sony Hack" href="http://www.wired.com/threatlevel/2011/06/lulzsec-sony-again/" target="_blank">54 megabytes of the developer&#8217;s source code to the PlayStation Network</a>. What does it mean? Hold on to your butts.<a
title="ACHIEVEMENT UNLOCKED: HACK SONY 6 TIMES!" href="http://lulzsecurity.com/releases/sownage_2_press_release.txt" target="_blank" class="broken_link"> The group published a press release detailing the hack</a> while simultaneously releasing all stolen code to the public through various channels. The implications of this are enormous, as Sony&#8217;s PSN is now wide-open to any exploits found in the previously obfuscated code. Expect Sony&#8217;s problems to continue for a while.</p><p>The targeting of Sony stems from their<a
title="Sony Settles PlayStation Hacking Lawsuit" href="http://www.wired.com/threatlevel/2011/04/sony-settles-ps3-lawsuit/" target="_blank"> legal assault on George Hotz, otherwise known as GeoHotz,</a> who had found and published a way to circumvent protection mechanisms on the PlayStation 3. This was a big deal after the company removed the &#8220;Other OS&#8221; feature through a firmware update that allowed the installation of Linux on the console to use the powerful IBM Cell processor that powers the machine. The PS3 has been known to be used by organizations like the US Air Force in supercomputer clusters due to the Cell processor&#8217;s vastly superior floating-point performance which is highly desired for processing large amounts of data for modeling.</p><p>Stay tuned&#8230;</p>Tags: <a
href="http://m32consulting.com/tag/achievement/" title="ACHIEVEMENT" rel="tag">ACHIEVEMENT</a>, <a
href="http://m32consulting.com/tag/cell/" title="Cell" rel="tag">Cell</a>, <a
href="http://m32consulting.com/tag/floating-point/" title="floating point" rel="tag">floating point</a>, <a
href="http://m32consulting.com/tag/geohotz/" title="geohotz" rel="tag">geohotz</a>, <a
href="http://m32consulting.com/tag/george-hotz/" title="George Hotz" rel="tag">George Hotz</a>, <a
href="http://m32consulting.com/tag/ibm/" title="IBM" rel="tag">IBM</a>, <a
href="http://m32consulting.com/tag/ibm-cell-processor/" title="ibm cell processor" rel="tag">ibm cell processor</a>, <a
href="http://m32consulting.com/tag/legal-assault/" title="legal assault" rel="tag">legal assault</a>, <a
href="http://m32consulting.com/tag/lulz/" title="lulz" rel="tag">lulz</a>, <a
href="http://m32consulting.com/tag/lulzsec/" title="LulzSec" rel="tag">LulzSec</a>, <a
href="http://m32consulting.com/tag/otheros/" title="OtherOS" rel="tag">OtherOS</a>, <a
href="http://m32consulting.com/tag/pbs/" title="pbs" rel="tag">pbs</a>, <a
href="http://m32consulting.com/tag/playstation-3/" title="playstation 3" rel="tag">playstation 3</a>, <a
href="http://m32consulting.com/tag/point-performance/" title="point performance" rel="tag">point performance</a>, <a
href="http://m32consulting.com/tag/ps3/" title="ps3" rel="tag">ps3</a>, <a
href="http://m32consulting.com/tag/psn/" title="psn" rel="tag">psn</a>, <a
href="http://m32consulting.com/tag/release/" title="release" rel="tag">release</a>, <a
href="http://m32consulting.com/tag/sony-hq/" title="sony hq" rel="tag">sony hq</a>, <a
href="http://m32consulting.com/tag/source/" title="Source" rel="tag">Source</a>, <a
href="http://m32consulting.com/tag/supercomputer/" title="supercomputer" rel="tag">supercomputer</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/06/lulzsec-hacks-sony-again-and-scores-psn-source-code/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>The Evolved GPU: Password Killer?</title><link>http://m32consulting.com/2011/06/the-evolved-gpu-password-killer/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-evolved-gpu-password-killer</link> <comments>http://m32consulting.com/2011/06/the-evolved-gpu-password-killer/#comments</comments> <pubDate>Sun, 05 Jun 2011 22:42:35 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Cryptography]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[computing]]></category> <category><![CDATA[cuda]]></category> <category><![CDATA[gpu]]></category> <category><![CDATA[GPUs]]></category> <category><![CDATA[nvidia]]></category> <category><![CDATA[OpenCL]]></category> <category><![CDATA[parallel processing]]></category> <category><![CDATA[Password]]></category> <category><![CDATA[password schemes]]></category> <category><![CDATA[power]]></category> <category><![CDATA[processing units]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=154</guid> <description><![CDATA[Since the advent of Open CL and technologies like Nvidia&#8217;s CUDA that use the massive potential in the evolved design of today&#8217;s Graphics Processing Units to aid in other areas of computing that require massive repetitive, parallel processing power, there has been a lot of new applications that were before impractical with standard CPUs to [...]]]></description> <content:encoded><![CDATA[<p>Since the advent of Open CL and technologies like Nvidia&#8217;s CUDA that use the massive potential in the evolved design of today&#8217;s Graphics Processing Units to aid in other areas of computing that require massive repetitive, parallel processing power, there has been a lot of new applications that were before impractical with standard CPUs to do. One of them is brute-forcing passwords. The trend in the modern GPU mixed with Moore&#8217;s law  may actually make even some of the strongest password schemes obsolete. ZDNet&#8217;s Adrian Kingley-Hughes <a
title="Cheap GPUs are rendering strong passwords useless" href="http://www.zdnet.com/blog/hardware/cheap-gpus-are-rendering-strong-passwords-useless/13125" target="_blank">has a good writeup on it and the implications  that may come of the trend in GPUs</a>.</p>Tags: <a
href="http://m32consulting.com/tag/computing/" title="computing" rel="tag">computing</a>, <a
href="http://m32consulting.com/tag/cuda/" title="cuda" rel="tag">cuda</a>, <a
href="http://m32consulting.com/tag/gpu/" title="gpu" rel="tag">gpu</a>, <a
href="http://m32consulting.com/tag/gpus/" title="GPUs" rel="tag">GPUs</a>, <a
href="http://m32consulting.com/tag/nvidia/" title="nvidia" rel="tag">nvidia</a>, <a
href="http://m32consulting.com/tag/opencl/" title="OpenCL" rel="tag">OpenCL</a>, <a
href="http://m32consulting.com/tag/parallel-processing/" title="parallel processing" rel="tag">parallel processing</a>, <a
href="http://m32consulting.com/tag/password/" title="Password" rel="tag">Password</a>, <a
href="http://m32consulting.com/tag/password-schemes/" title="password schemes" rel="tag">password schemes</a>, <a
href="http://m32consulting.com/tag/power/" title="power" rel="tag">power</a>, <a
href="http://m32consulting.com/tag/processing-units/" title="processing units" rel="tag">processing units</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/06/the-evolved-gpu-password-killer/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>phpMyAdmin Exploit Used To Launch New SSH Brute-Force Attack</title><link>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack</link> <comments>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/#comments</comments> <pubDate>Fri, 13 Aug 2010 01:55:13 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[dd.txt]]></category> <category><![CDATA[dd_ssh vmsplice.txt]]></category> <category><![CDATA[phpmyadmin]]></category> <category><![CDATA[ssh]]></category> <category><![CDATA[vm.c]]></category> <category><![CDATA[vmsplice]]></category> <category><![CDATA[vulnerability]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=160</guid> <description><![CDATA[An older vulnerability in phpMyAdmin (CVE-2009-1151) is now being exploited by a botnet known as dd_ssh. Details are still emerging, but it appears that this new bot originated from 91.193.157.206 according to SANS. If the exploit of CVE-2009-1151 is successful on vulnerable phpMyAdmin installs, the files vmsplice.txt, dd.txt, and, in some instances, vm.c are downloaded from the aforementioned IP. The last [...]]]></description> <content:encoded><![CDATA[<p>An <a
title="Debian security bulletin" href="http://www.debian.org/security/2010/dsa-2034" target="_blank">older vulnerability in phpMyAdmin</a> (<a
href="http://www.securityfocus.com/bid/34236/info" target="_blank">CVE-2009-1151</a>) is now being exploited by a botnet known as dd_ssh. Details are still emerging, but it appears that this new bot originated from 91.193.157.206 according to SANS. If the exploit of CVE-2009-1151 is successful on vulnerable phpMyAdmin installs, the files vmsplice.txt, dd.txt, and, in some instances, vm.c are downloaded from the aforementioned IP. The last of those files mentioned contains the vmsplice local root exploit (<a
title="NVD CVE2008-0600" href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-0600" target="_blank">CVE2008-0600</a>). After being compromised, the infected installations start making connections to multiple addresses on ports 54509 and 54510; most likely for command &amp; control. SANS ISC is actively monitoring this apparent new botnet and has noticed a notable up-tick in machines scanning SSH lately.</p><p><a
href="http://isc.sans.edu/diary.html?storyid=9370" target="_blank">More Info Over at SANS ISC</a> and thanks goes to <a
href="http://www.dslreports.com/forum/r24640843-Botnet-Trend-phpMyAdmin-SSH-Attacks" target="_blank">Briareos over at BroadBand Reports for the quick fact-finding</a> and possible discovery.</p><p><a
href="http://support.f5.com/kb/en-us/solutions/public/11000/700/sol11719.html" target="_blank">June Security Advisory posted by F5 on identifying any suspicious activity and mitigating the exploit</a></p>Tags: <a
href="http://m32consulting.com/tag/dd-txt/" title="dd.txt" rel="tag">dd.txt</a>, <a
href="http://m32consulting.com/tag/dd_ssh-vmsplice-txt/" title="dd_ssh vmsplice.txt" rel="tag">dd_ssh vmsplice.txt</a>, <a
href="http://m32consulting.com/tag/phpmyadmin/" title="phpmyadmin" rel="tag">phpmyadmin</a>, <a
href="http://m32consulting.com/tag/ssh/" title="ssh" rel="tag">ssh</a>, <a
href="http://m32consulting.com/tag/vm-c/" title="vm.c" rel="tag">vm.c</a>, <a
href="http://m32consulting.com/tag/vmsplice/" title="vmsplice" rel="tag">vmsplice</a>, <a
href="http://m32consulting.com/tag/vulnerability/" title="vulnerability" rel="tag">vulnerability</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/08/phpmyadmin-exploit-used-to-launch-new-ssh-brute-force-attack/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 37/63 queries in 0.048 seconds using disk: basic
Object Caching 5024/5098 objects using disk: basic

Served from: m32consulting.com @ 2012-05-20 22:51:31 -->
