Episode 29- Sony Hack, MacDefender, Dropbox Privacy and ForensicArtifacts.com

In this episode, I talk about the Sony hacks, MacDefender, Dropbox privacy issues, ForensicArtifacts.com and upcoming events in the month of June.

Show Notes:

Sony/PBS Hacks links:

http://arstechnica.com/tech-policy/news/2011/06/sony-hacked-yet-again-plaintext-passwords-posted.ars

http://arstechnica.com/tech-policy/news/2011/05/hacktivists-scorch-pbs-in-retaliation-for-wikileaks-documentary.ars

http://www.informationweek.com/news/security/attacks/229700188

 

Mac Defender, Apple Security Update and Avast A/V Free for Mac:

http://www.tuaw.com/2011/05/19/macdefender-malware-protection-and-removal-guide/

http://www.tuaw.com/2011/05/31/mac-security-update-2011-003-now-available-for-download/

http://www.macrumors.com/2011/06/02/apple-responds-quickly-to-evolving-mac-defender-threat-with-updated-malware-definitions/

http://support.apple.com/kb/HT4657

http://www.tuaw.com/2011/06/01/avast-free-antivirus-for-mac-beta-now-available/

 

Using TrueCrypt with Dropbox:

http://lifehacker.com/5794486/how-to-add-a-second-layer-of-encryption-to-dropbox

 

 

2011 SANS Forensic & Incident Response Summit:

http://www.sans.org/forensics-incident-response-summit-2011/agenda.php

 

2011 Forensic4Cast Awards Voting:

http://www.forensic4cast.com/forensic-4cast-awards/

 

2011 Sleuth Kit & Open Source Digital Forensics Conference:

http://www.basistech.com/about-us/events/open-source-forensics-conference/2011/

 

Upcoming SecurityBSides Events (June):

http://www.securitybsides.com/w/page/12194156/FrontPage

 

2011 Forensic 4cast Awards

Lee over at Forensic 4cast has posted the list of nominees for the 2011 Forensic 4cast Awards as well as the official ballot, which you can find here.  The results of the voting will be announced at the 2011 SANS Forensics & Incident Response Summit being held on June 7 at 4:20pm.

With that said, Cyber Crime 101 has been nominated for the “Best Digital Forensics Podcast” category.  I was floored to find out that the show made it to the finals.  I would first like to thank those that nominated the show and helped it become a finalist.   I also want to thank those who will vote for the show in advance.  It will be much appreciated.  Fingers crossed that the show can pull out a win.

I have a great time putting together the show for you all and finding some way to give back to the community.  I hope to continue to do so in the future.

I also want to wish all of the nominees from all of the categories good luck.

Episode 28- Interview with Hal Pomeranz

Hey guys,

I’m back from a bit of a break.  Thanks for being patient!

Anyway, I had the pleasure of interviewing Hal Pomeranz for this show.  He is the founder of Deer Run Associates and the longest tenured SANS Institute Instructor.

 

Enjoy the show!

 

Joe

Episode 27- Protecting Children Online

In this episode, I talk about protecting kids online, what some of the risks to kids are and what makes them ideal victims.

Show Notes:

Links for Information on Protecting Children Online

National Center for Missing and Exploited Children: http://www.missingkids.com/missingkids/servlet/PublicHomeServlet?LanguageCountry=en_US

NetSmartz: http://www.netsmartz.org/Parents

Carnegie Cyber Academy: http://www.carnegiecyberacademy.com/

KidZui: http://www.kidzui.com/

NetLingo- The Internet Dictionary: http://www.netlingo.com/

Links to News Items-

HackedPrints: http://ialbert.co/2011/03/13/hackedprints/ & http://hackedprints.bigcartel.com/

Mikko Hypponen interview w/ authors of the first PC virus, Brain: http://campaigns.f-secure.com/brain

FouTube LikeJacking on Facebook: http://nakedsecurity.sophos.com/2011/03/12/what-is-foutube-viral-facebook-clickjacking-video-scams-explored/

- Joe G.

Securing your iOS devices

When it comes to mobile device security, no other security measure beats having physical control of the device to keep it from being compromised.  Let’s face it though, we are humans and tend to screw up.  People leave their mobile devices in taxi cabs, buses, the local park bench or in bars/clubs on a regular basis.  So the next best thing to physical security is to have your mobile device set up with a passcode, a good passcode.  In this post I will be discussing passcodes on Apple iOS devices (iPhone, iPad and iPod Touch).  Let’s move on……..

Apple allows users two options when it comes to creating a passcode: Simple or Long.  When you choose the Simple option, it allows for a 4-Digit passcode which has only 10,000 possible combinations.  Choosing the Long passcode option, you can have up to 31 characters for your passcode by utilizing any of the 108 characters available from the virtual keyboard. If you decided to use only 4 characters instead of just digits, the number of possible character combinations  jumps considerably.  Let’s see what possbile combinations we get when choosing the Long passcode option (if I am wrong, please call me on this. I have poor math skills):

4 Characters using just lowercase letters = 456,976

4 Characters using any combination of lowercase letters and 10-digits = 1,679,616

4 Characters using any combination of uppercase and lowercase letters = 7,311,616

4 Characters using any combination of upper/lowercase letters and 10-digits = 14,776,336

4 Characters using any combination of all 108 characters available on the U.S. iOS on-screen keyboard = 136,048,896

So as we can see, just enabling the Long passcode option using more than just a combination of only 4-Digits makes it a lot harder for a bad guy to gain access to your lost/stolen phone (Unless they get a lucky guess). Couple the above numbers of enabling the Long passcode option, with activating the “Erase Data” option which erases your iOS device’s data after 10 failed pasccode attempts and you’ve got youself a pretty secure device.  Daniel Gattermann over on his Cinnamon Thoughts blog did some research on wait intervals for failed login attempts on iOS devices when the “Erase Data” option was selected.  See his table below:





Just remember, you can always restore your iOS device using the computer you synced it to if the device is wiped. Now, let me show you how to get your Long passcode set up……

First from your Home screen, find and tap on the Settings icon:




Then, tap on the General menu option:




Now, scroll down to the Passcode Lock option and tap it:




By default the iOS Passcode is “Off”. Tap “Turn Passcode On” to turn it on:




You will be prompted to enter and then re-enter a 4-Digit Passcode:







Now is a good time to enable the “Erase Data” option:






Now, if you were not to go any further, you would get this “Enter Passcode” dialog screen when returning from sleep or after locking your screen:



Since we want to use a Long Passcode, we are going to continue on. Look for the “Simple Passcode” option. As you will see in the image below, it is switched “On” by default:



Let’s tap on it to activate a Long Passcode. You will need to enter your old 4-Digit passcode and will then be promted to enter and re-enter a new Long Passcode:






You will be returned to the Passcode options page. Notice that Simple Passcode is now “Off”:



Now when returning to your iOS device from sleep or after locking the screen, you will see a new passcode dialog screen:



That is it. Your Long Passcode is now set.  A word of advice, if you are using a passphrase as your passcode you don’t use anything that people who know you (like a co-worker, relative or even the office janitor) can figure out. Things like a pets name, home address or even your favorite car can be gathered about you easily. For more information on how to create good passphrases, check out Episode 2 of the Podcast.

For more information on iOS Device Passcodes check out these two Apple Support pages:
- Understanding Passcodes

- Wrong Passcode Results in Red Disabled Screen

 

-Joe G.

Episode 26- Shmoocon thoughts with iAlbert

In this Episode I have on iAlbert and we have a bit of a review of all that was Shmoocon 2011.  Thanks again to Albert for hanging out and laying down some audio.

Show Notes:

Shmoocon: http://www.shmoocon.org/

Shmoocon 2011 Schedule page with links to presentation videos: http://www.shmoocon.org/schedule

Hackers for Charity: http://www.hackersforcharity.org/

Follow Albert on twitter.

Episode 25- Life After Law Enforcement with Eric Huber

In this episode, I talk with Eric Huber about what awaits Digital Forensics & InfoSec practitioners getting ready to retire from Law Enforcement.  Also, Lee Whitfield has announced that nominations are open for the 2011 Forensic4Cast awards.  Please nominate this show in the category of “Best Digital Forensic Podcast”.  It would be much appreciated!!!

Eric’s Blog, A Fistful of Dongles: http://ericjhuber.blogspot.com/

2011 Forensic4Cast Awards nomination page: http://forensic4cast.com/2011/02/11/forensic-4cast-awards-2011-nominations-are-open/

Episode 24- Trapster Hack, Twitter Spam and more

In this episode, I talk about the Trapster hack, malicious Twitter spam, Steve Jobs taking a leave of absence from Apple, Malware in job applications, the VirusTotal Firefox & Chrome addons, online Grooming, Shmoocon & BSidesCleveland.  See below for links………

Trapster Hack:

http://blog.trapster.com/2011/01/21/sorry/

http://nakedsecurity.sophos.com/2011/01/20/trapster-hack-millions-warned-password-breach/

Malicious Twiiter Spam:

http://sunbeltblog.blogspot.com/2011/01/huge-malicious-twitter-run-blocked.html

http://longurl.org

Steve Jobs on Medical Leave:

http://www.engadget.com/2011/01/17/steve-jobs-takes-medical-leave-from-apple-tim-cook-taking-over/

http://www.maclife.com/article/news/steve_jobs_taking_medical_leave_absence_remains_ceo

IC3 on Malicious Job Applications:

http://www.ic3.gov/media/2011/110119.aspx

VirusTotal Firefox & Google Chrome Browser addons (VTZilla & VTChromizer):

http://www.virustotal.com/advanced.html

MySecureCyberSpace Blog from Carnegie Mellon:

http://www.mysecurecyberspace.com/encyclopedia/index/online-grooming.html

Shmoocon (Jan 28-30, 2011):

www.shmoocon.org

BSidesCleveland (Feb 18, 2011):

http://www.securitybsides.com/w/page/27427415/BSidesCleveland

Free 16GB iPad with SANS vLive! Courses

Didn’t get what you were wishing for last month?  Now through February
2, receive a FREE 16GB iPad(TM) with Wi-Fi with the purchase of any of
the following online courses!

FOR408: Computer Forensic Essentials
vLive! course starts March 1 and meets Tue/Thu evenings

http://www.sans.org/info/66203

MGT414: SANS(R) +S(TM) Training Program for the CISSP(R) Certification Exam
vLive! course starts February 28 and meets Mon/Wed evenings

http://www.sans.org/info/66198

SEC560: Network Penetration Testing and Ethical Hacking
vLive! course starts February 7 and meets Mon/Wed evenings

http://www.sans.org/info/66193

ANY 4-, 5-, or 6- Day Course offered via OnDemand

https://www.sans.org/registration/register.php?conferenceid=1032

To get your free iPad(TM), enter discount code 0112_iPad when you
register for a qualifying course.  Your iPad(TM) will arrive in about
four weeks.  It’s that easy!

For complete information please visit:
http://www.sans.org/online-security-training/specials.php .

Why Take SANS Online Training?
* Learn from SANS’s Top Instructors, including Ed Skoudis, John Strand,
Eric Conrad and Rob Lee

* Eliminate travel expenses and time away from the office

* Receive a complete set of books, course materials and downloadable
.mp3 audio files

* vLive! courses feature LIVE instruction from a top instructor in an
interactive virtual classroom

* OnDemand courses are available at any time and feature integrated
assessment tools

To learn more about our online training options, please visit
http://www.sans.org/online-security-training/ .  Not sure which online
training method is best for you? View a demo of vLive! at
https://www.sans.org/vlive/demo.php or test-drive OnDemand at

http://www.sans.org/ondemand/demos.php.

To receive your free 16GB iPad(TM) with Wi-Fi, you must register and pay
for a qualifying course by February 2, 2011. Qualifying courses include
any 4-, 5-, or 6- OnDemand course and the following vLive! courses:
SEC560 beginning 2/7/11, MGT414 beginning 2/28/11, and FOR408 beginning
3/1/11.  Students are responsible for paying any applicable duties,
taxes or customs fees.  The offer may not be combined with any other
offer or discount program.  Allow up to four weeks for iPad(TM)
delivery.  iPad(TM) is a registered trademark of Apple, Inc..  Apple,
Inc. is not a sponsor of this promotion nor is it affiliated with the
SANS Institute.

REMNux Update Coming Soon

Attention all Malware Analysts……

Lenny Zeltser is putting finishing touches on the next version of REMnux (v 2.0), which is an Ubuntu-based Linux distribution for analyzing malware.  It is set for release this month.  Lenny uses it in the SANS FOR610 course, but it has also been well received by the malware analyst community, and is available at http://REMnux.org.  If you haven’t tried it yet, make sure to give it a spin.

The new version is an incremental update. The goal of this release is to mostly to update the existing tools and to add a few new ones. Most notably:

•    Update Volatility 1.3 to Volatility 1.4 RC1. The version 1.4 includes a different plugin architecture, and has a more streamlined feel from a usability perspective. Also, it includes (partial) support for Windows Vista and 7.
•    Migrate from MHL’s Volatility Analyst Pack plugins to use the Malware Plugins library (malware.py), which is compatible with Volatility 1.4 and includes additional features.
•    Install the latest version of Jsunpack-n, which includes a number of new features, such as proxy support, improved handling of encrypted PDFs, and other updates.
•    Install stunnel to assist with the interception of SSL sessions (is this actually useful?)
•    Install pyOLEScanner.py to assist with malicious Office document analysis
•    Install Tor and Torsocks to ease anonymizing access to malicious websites
•    Install libemu to obtain its sctest tool for analyzing shellcode
•    Install RABCDAsm, a toolkit for reverse-engineering SWF files. (Anyone interested in taking on a project to showcase this tool, btw?)
•    Fix a libnet-dns (Net::DNS) issue related to the operation of INetSim
•    Include some tools from the Malware Analyst’s Cookbook DVD

The goal is not to install every malware analysis tools out there, but to only include those tools that are useful and work well. Also, Lenny is sticking with Enlightenment as the X window manager, because it’s lightweight and it’s very easy to install GNOME or KDE with apt-get when the user wants it.

If you have any recommendations for tools to include in the upcoming version of REMnux, please drop him a note on Twitter (@lennyzeltser) or via http://zeltser.com/about/contact.html

Joe

Subscribe to RSS Feed Follow me on Twitter!