<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; Government</title> <atom:link href="http://m32consulting.com/category/security/government/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Tue, 13 Mar 2012 21:54:58 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>German Researchers Find &#8220;Massive&#8221; Flaws In Cloud Security</title><link>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=german-researchers-find-massive-flaws-in-cloud-security</link> <comments>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/#comments</comments> <pubDate>Wed, 26 Oct 2011 18:53:23 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Cloud]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Firewalls]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[amazon]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[aws]]></category> <category><![CDATA[computing]]></category> <category><![CDATA[ec2]]></category> <category><![CDATA[EucalyptusEucalyptus (computing)]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[information security]]></category> <category><![CDATA[network]]></category> <category><![CDATA[s3]]></category> <category><![CDATA[soap]]></category> <category><![CDATA[tw]]></category> <category><![CDATA[XML]]></category> <category><![CDATA[XSS]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=221</guid> <description><![CDATA[NetworkWorld has a very interesting writeup about a report that six German Information Security researchers published outlining very massive and highly exploitable flaws in Cloud Computing services; specifically Amazon&#8217;s EC2 and S3 as well as Eucalyptus Cloud Computing Software. Old concepts like XSS and what is referred to as XML Signature Wrapping attacks on the SOAP interfaces [...]]]></description> <content:encoded><![CDATA[<div
class="zemanta-img" style="margin: 1em; display: block;"><div
class="wp-caption alignright" style="width: 266px"><a
href="http://commons.wikipedia.org/wiki/File:Cloud_computing_icon.svg" target="_blank"><img
class="zemanta-img-configured" title="Cloud computing icon" src="http://upload.wikimedia.org/wikipedia/commons/thumb/1/12/Cloud_computing_icon.svg/256px-Cloud_computing_icon.svg.png" alt="Cloud computing icon" width="256" height="179" /></a><p
class="wp-caption-text">Image via Wikipedia</p></div></div><p>NetworkWorld has a very interesting writeup about a report that six German Information Security researchers published outlining very massive and highly exploitable flaws in <a
class="zem_slink" title="Cloud computing" href="http://en.wikipedia.org/wiki/Cloud_computing" rel="wikipedia">Cloud Computing</a> services; specifically <a
class="zem_slink" title="Amazon EC2" href="http://aws.amazon.com/ec2/" rel="homepage">Amazon&#8217;s EC2</a> and S3 as well as Eucalyptus Cloud Computing Software. Old concepts like XSS and what is referred to as <a
class="zem_slink" title="XML Signature" href="http://en.wikipedia.org/wiki/XML_Signature" rel="wikipedia">XML Signature</a> Wrapping attacks on the <a
class="zem_slink" title="SOAP" href="http://en.wikipedia.org/wiki/SOAP" rel="wikipedia">SOAP</a> interfaces of the aforementioned cloud services. Very troubling and a large blow to the legitimacy of  security in the cloud.</p><p><a
title="All Your Clouds are Belong to us – Security Analysis of Cloud Management Interfaces" href="http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf" target="_blank">The full PDF of the German researchers&#8217; findings can be found here.</a></p><p>&nbsp;</p><p><a
title="Researchers find &quot;massive&quot; security flaws in cloud architectures" href="http://www.networkworld.com/news/2011/102611-security-cloud-252406.html" target="_blank">NetworkWorld Article</a></p><h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6><ul
class="zemanta-article-ul"><li
class="zemanta-article-ul-li"><a
href="http://www.pcworld.com/article/242598/researchers_demo_cloud_security_issue_with_amazon_aws_attack.html">Researchers Demo Cloud Security Issue With Amazon AWS Attack</a> (pcworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://r.zemanta.com/?u=http%3A//www.infoworld.com/d/cloud-computing/researchers-demo-cloud-security-issue-amazon-aws-hijacking-attack-177179&amp;a=59897468&amp;rid=9fea2dfa-23e7-4226-869e-44aec161f55a&amp;e=e607e310bd8532578036b34a2b4a2074">Researchers demo cloud security issue with Amazon AWS hijacking attack</a> (infoworld.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.physorg.com/news/2011-10-cloud-gaps.html">Cloud computing: Gaps in the &#8216;cloud&#8217;</a> (physorg.com)</li><li
class="zemanta-article-ul-li"><a
href="http://www.networkworld.com/news/2011/102611-researchers-demo-cloud-security-issue-252403.html?source=nww_rss" target="_blank">Researchers demo cloud security issue with Amazon AWS attack</a> (networkworld.com)</li></ul><div
class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><img
class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/pixy.gif?x-id=9fea2dfa-23e7-4226-869e-44aec161f55a" alt="" /></div>Tags: <a
href="http://m32consulting.com/tag/amazon/" title="amazon" rel="tag">amazon</a>, <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/aws/" title="aws" rel="tag">aws</a>, <a
href="http://m32consulting.com/tag/computing/" title="computing" rel="tag">computing</a>, <a
href="http://m32consulting.com/tag/ec2/" title="ec2" rel="tag">ec2</a>, <a
href="http://m32consulting.com/tag/eucalyptuseucalyptus-computing/" title="EucalyptusEucalyptus (computing)" rel="tag">EucalyptusEucalyptus (computing)</a>, <a
href="http://m32consulting.com/tag/exploit/" title="exploit" rel="tag">exploit</a>, <a
href="http://m32consulting.com/tag/information-security/" title="information security" rel="tag">information security</a>, <a
href="http://m32consulting.com/tag/network/" title="network" rel="tag">network</a>, <a
href="http://m32consulting.com/tag/s3/" title="s3" rel="tag">s3</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/soap/" title="soap" rel="tag">soap</a>, <a
href="http://m32consulting.com/tag/tw/" title="tw" rel="tag">tw</a>, <a
href="http://m32consulting.com/tag/xml/" title="XML" rel="tag">XML</a>, <a
href="http://m32consulting.com/tag/xss/" title="XSS" rel="tag">XSS</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/10/german-researchers-find-massive-flaws-in-cloud-security/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Virus targets US Predator and Reaper drones</title><link>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=virus-targets-us-predator-and-reaper-drones</link> <comments>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/#comments</comments> <pubDate>Fri, 07 Oct 2011 21:29:53 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[attack]]></category> <category><![CDATA[code]]></category> <category><![CDATA[computer virus]]></category> <category><![CDATA[cybersecurity]]></category> <category><![CDATA[drone]]></category> <category><![CDATA[keystroke]]></category> <category><![CDATA[malicious code]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[MQ-9 ReaperMQ-9 Reaper]]></category> <category><![CDATA[nist]]></category> <category><![CDATA[predator]]></category> <category><![CDATA[reaper drones]]></category> <category><![CDATA[War on TerrorismWar on Terrorism]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=216</guid> <description><![CDATA[A computer virus has infected the cockpits of America&#8217;s Predator and Reaper drones, logging pilots&#8217; every keystroke as they remotely fly missions over Afghanistan and other war zones. The name of the virus is yet to be known, as details are still emerging about how the malicious code got into the systems in the first [...]]]></description> <content:encoded><![CDATA[<p>A computer virus has infected the cockpits of America&#8217;s Predator and Reaper drones, logging pilots&#8217; every keystroke as they remotely fly missions over Afghanistan and other war zones. The name of the virus is yet to be known, as details are still emerging about how the malicious code got into the systems in the first place. Could this be a belligerent enemy to US forces attacking their main weapon in use for remote regions? Ars Technica has the story after the jump.</p><p><a
href="http://arstechnica.com/business/news/2011/10/exclusive-computer-virus-hits-drone-fleet.ars">Computer virus hits US Predator and Reaper drone fleet</a>.</p>Tags: <a
href="http://m32consulting.com/tag/attack/" title="attack" rel="tag">attack</a>, <a
href="http://m32consulting.com/tag/breaches/" title="Breaches" rel="tag">Breaches</a>, <a
href="http://m32consulting.com/tag/code/" title="code" rel="tag">code</a>, <a
href="http://m32consulting.com/tag/computer-virus/" title="computer virus" rel="tag">computer virus</a>, <a
href="http://m32consulting.com/tag/cybersecurity/" title="cybersecurity" rel="tag">cybersecurity</a>, <a
href="http://m32consulting.com/tag/drone/" title="drone" rel="tag">drone</a>, <a
href="http://m32consulting.com/tag/keystroke/" title="keystroke" rel="tag">keystroke</a>, <a
href="http://m32consulting.com/tag/malicious-code/" title="malicious code" rel="tag">malicious code</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/mq-9-reapermq-9-reaper/" title="MQ-9 ReaperMQ-9 Reaper" rel="tag">MQ-9 ReaperMQ-9 Reaper</a>, <a
href="http://m32consulting.com/tag/nist/" title="nist" rel="tag">nist</a>, <a
href="http://m32consulting.com/tag/predator/" title="predator" rel="tag">predator</a>, <a
href="http://m32consulting.com/tag/reaper-drones/" title="reaper drones" rel="tag">reaper drones</a>, <a
href="http://m32consulting.com/tag/war-on-terrorismwar-on-terrorism/" title="War on TerrorismWar on Terrorism" rel="tag">War on TerrorismWar on Terrorism</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2011/10/virus-targets-us-predator-and-reaper-drones/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Conficker: The Proactive Worm Ahead Of The Curve</title><link>http://m32consulting.com/2010/08/conficker-the-proactive-worm-ahead-of-the-curve/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=conficker-the-proactive-worm-ahead-of-the-curve</link> <comments>http://m32consulting.com/2010/08/conficker-the-proactive-worm-ahead-of-the-curve/#comments</comments> <pubDate>Sun, 08 Aug 2010 19:26:15 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Breaches]]></category> <category><![CDATA[Cryptography]]></category> <category><![CDATA[Customer]]></category> <category><![CDATA[Exploits]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Net Issues]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[botnet]]></category> <category><![CDATA[buffer overflow]]></category> <category><![CDATA[Conficker]]></category> <category><![CDATA[Conficker Working Group]]></category> <category><![CDATA[Downadup]]></category> <category><![CDATA[Downup]]></category> <category><![CDATA[Kido]]></category> <category><![CDATA[MD6]]></category> <category><![CDATA[nist]]></category> <category><![CDATA[RSA]]></category> <category><![CDATA[scareware]]></category> <category><![CDATA[SHA-3]]></category> <category><![CDATA[worm]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=152</guid> <description><![CDATA[An interesting article over at The Register shows how the now infamous ~6 million strong Conficker botnet/worm stays ahead of the curve in terms of Information Security by staying proactive and paranoid in how it is managed. Although the classification of the worm only goes from A through E, the botnet itself is ever-evolving; creating [...]]]></description> <content:encoded><![CDATA[<p>An interesting article over at The Register shows how the now infamous ~6 million strong Conficker botnet/worm stays ahead of the curve in terms of Information Security by staying proactive and paranoid in how it is managed. Although the classification of the worm only goes from A through E, the botnet itself is ever-evolving; creating a nightmare for researchers world-wide in detection and cleansing of infected machines. It is unknown who runs the botnet, but it is known that the technical skill behind its command is very much on the bleeding-edge of security as well as social engineering. For instance, the worm uses simple exploits to infect Windows machines, but it phones home to domain names which can no longer be predicted and shut-down to receive new instructions and updates to the code that infects the machine. It has used scareware in the past to spread as well, such as bogus security software. It has even gone so far as to actually remove or fix other security threats on an infected machine to avoid detection. It constantly stays up-to-date and often mitigates even the newest anti-malware tools designed to remove it.</p><p>What makes it so hard to remove is its inability to be cracked. It has used the MD6 cryptographic hash function that was a candidate for the NIST SHA-3 Hash Competition with a 4096-bit RSA key. Even when a buffer-overflow vulnerability was discovered in MD6, the botnet&#8217;s owner corrected the implementation within a matter of days. There is an entire working group called The <a
title="Conficker Working Group" href="http://www.confickerworkinggroup.org/wiki/" target="_blank">Conficker Working Group</a> tasked entirely to the botnet, which has yet to break-in and take any sort of control away from whoever runs it.</p><p><a
href="http://www.theregister.co.uk/2010/08/05/conficker_analysis/" target="_blank">In-depth article at The Register</a></p>Tags: <a
href="http://m32consulting.com/tag/botnet/" title="botnet" rel="tag">botnet</a>, <a
href="http://m32consulting.com/tag/buffer-overflow/" title="buffer overflow" rel="tag">buffer overflow</a>, <a
href="http://m32consulting.com/tag/conficker/" title="Conficker" rel="tag">Conficker</a>, <a
href="http://m32consulting.com/tag/conficker-working-group/" title="Conficker Working Group" rel="tag">Conficker Working Group</a>, <a
href="http://m32consulting.com/tag/downadup/" title="Downadup" rel="tag">Downadup</a>, <a
href="http://m32consulting.com/tag/downup/" title="Downup" rel="tag">Downup</a>, <a
href="http://m32consulting.com/tag/kido/" title="Kido" rel="tag">Kido</a>, <a
href="http://m32consulting.com/tag/md6/" title="MD6" rel="tag">MD6</a>, <a
href="http://m32consulting.com/tag/nist/" title="nist" rel="tag">nist</a>, <a
href="http://m32consulting.com/tag/rsa/" title="RSA" rel="tag">RSA</a>, <a
href="http://m32consulting.com/tag/scareware/" title="scareware" rel="tag">scareware</a>, <a
href="http://m32consulting.com/tag/sha-3/" title="SHA-3" rel="tag">SHA-3</a>, <a
href="http://m32consulting.com/tag/worm/" title="worm" rel="tag">worm</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/08/conficker-the-proactive-worm-ahead-of-the-curve/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>CYBERCOM’s Secret Code Demystified</title><link>http://m32consulting.com/2010/07/cybercom%e2%80%99s-secret-code-demystified/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cybercom%25e2%2580%2599s-secret-code-demystified</link> <comments>http://m32consulting.com/2010/07/cybercom%e2%80%99s-secret-code-demystified/#comments</comments> <pubDate>Sat, 10 Jul 2010 01:27:36 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Cryptography]]></category> <category><![CDATA[Government]]></category> <category><![CDATA[Hacking]]></category> <category><![CDATA[Security]]></category> <category><![CDATA[cybercom]]></category> <category><![CDATA[hash md5]]></category> <category><![CDATA[hexadecimal code]]></category> <category><![CDATA[infosec]]></category> <category><![CDATA[integrity checks]]></category> <category><![CDATA[md5 algorithm]]></category> <category><![CDATA[md5 hashes]]></category> <category><![CDATA[security problem]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=75</guid> <description><![CDATA[As I posted earlier this week, a hexadecimal code was discovered on the gold ring encircling US Cyber Command&#8217;s newly released logo. That code was 9ec4c12949a4f31474f299058ce2b22a and it sent the NetSec community on a challenge. To the untrained eye, it looks like just a bunch of numbers and letters. To those in the InfoSec/NetSec field, it [...]]]></description> <content:encoded><![CDATA[<p>As I posted earlier this week, a hexadecimal code was discovered on the gold ring encircling US Cyber Command&#8217;s newly released logo. That code was 9ec4c12949a4f31474f299058ce2b22a and it sent the NetSec community on a challenge. To the untrained eye, it looks like just a bunch of numbers and letters. To those in the InfoSec/NetSec field, it looks like a 128-bit MD5-hash. MD5 hashes are derived from an algorithm that &#8220;digests&#8221; the data into a hexadecimal result like the one here. They are often used in file integrity checks to ensure the data is exactly what it should be without any corruption or tampering.</p><p><img
class="size-medium wp-image-79 alignright" title="cyber-command-logo" src="http://m32consulting.com/wp-content/uploads/2010/07/cyber-command-logo-477x480.jpg" alt="US CYBERCOM" width="229" height="230" /></p><p>Around 2004, the MD5 algorithm had started to show vulnerabilities and signs of age. It is now fairly easy to reverse these hashes to reveal the original data. Obviously this is a big security problem. The NIST and DHS has a policy that requires all government agencies to use more complex hashing functions after 2010. Considering US CYBERCOM is one of the most secretive and secured entities of the publicly known US Government and intimately tied to the NSA, I would imagine there may be more than meets the eye to the new logo and we&#8217;ll come across more interesting things the geeks over there threw in to challenge us.</p><p
style="text-align: center;"><p><a
href="http://science.dodlive.mil/2010/07/08/cybercom%e2%80%99s-secret-code-demystified/">CYBERCOM’s Secret Code Demystified</a>.</p>Tags: <a
href="http://m32consulting.com/tag/cybercom/" title="cybercom" rel="tag">cybercom</a>, <a
href="http://m32consulting.com/tag/hash-md5/" title="hash md5" rel="tag">hash md5</a>, <a
href="http://m32consulting.com/tag/hexadecimal-code/" title="hexadecimal code" rel="tag">hexadecimal code</a>, <a
href="http://m32consulting.com/tag/infosec/" title="infosec" rel="tag">infosec</a>, <a
href="http://m32consulting.com/tag/integrity-checks/" title="integrity checks" rel="tag">integrity checks</a>, <a
href="http://m32consulting.com/tag/md5-algorithm/" title="md5 algorithm" rel="tag">md5 algorithm</a>, <a
href="http://m32consulting.com/tag/md5-hashes/" title="md5 hashes" rel="tag">md5 hashes</a>, <a
href="http://m32consulting.com/tag/security-problem/" title="security problem" rel="tag">security problem</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/07/cybercom%e2%80%99s-secret-code-demystified/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 13/37 queries in 0.086 seconds using disk: basic
Object Caching 2105/2171 objects using disk: basic

Served from: m32consulting.com @ 2012-05-20 22:54:02 -->
