| Lol, what? |
Saturday, October 18, 2014
What?
LinkedIn is always good for a laugh. Here was their recent job recommendation for me:
I admit, I find it exceedingly difficult to "Picture Myself" at the National Security Agency. LinkedIn, maybe you need to work a little bit more on your creepy career stalking software. Still needs some work.
Thursday, October 16, 2014
The Guardian Calls Bullsh*t on Whisper; Whisper Calls Bullsh*t on Guardian
Big drama today re: the popular messaging app Whisper.
Whisper markets itself as anonymous, calling itself “the safest place on the internet”. But The Guardian disagrees. This morning the influential British newspaper published a story alleging that whisper tracks the geographic location of users who have requested that such tracking be disabled - even more alarming, the Guardian claims that Whisper provides location data to the US Department of Defense about Whisper messages sent from military bases, ostensibly to identify whistleblowers. The Guardian also stated that Whisper sends user data to the FBI and MI5.
Whisper's terms of service changed after they found out that the Guardian was moving to publish. Now their TOS explicitly allows user tracking regardless of settings.
Neetzan Zimmerman, speaking for the Whisper corporate office, has responded with a series of online pronouncements that were full of sound and fury; calling the story a "pack of lies" that was "lousy with falsehoods".
Nevertheless, Zimmerman did confirm that Whisper is conducting a "DoD Study", responding to a pointed comment from Washington Post contributor Barton Gellman:
Finally, the Guardian also mentioned the Whisper is designing a Chinese version of the app that will conform to draconian Chinese censorship laws.
Zimmerman has uploaded what he claims is Whispers entire, unedited response to The Guardian via scribd. Because these things have a way of disappearing, a backup copy of Zimmerman's response is also available.
Whisper markets itself as anonymous, calling itself “the safest place on the internet”. But The Guardian disagrees. This morning the influential British newspaper published a story alleging that whisper tracks the geographic location of users who have requested that such tracking be disabled - even more alarming, the Guardian claims that Whisper provides location data to the US Department of Defense about Whisper messages sent from military bases, ostensibly to identify whistleblowers. The Guardian also stated that Whisper sends user data to the FBI and MI5.
Whisper's terms of service changed after they found out that the Guardian was moving to publish. Now their TOS explicitly allows user tracking regardless of settings.
Neetzan Zimmerman, speaking for the Whisper corporate office, has responded with a series of online pronouncements that were full of sound and fury; calling the story a "pack of lies" that was "lousy with falsehoods".
Nevertheless, Zimmerman did confirm that Whisper is conducting a "DoD Study", responding to a pointed comment from Washington Post contributor Barton Gellman:
Finally, the Guardian also mentioned the Whisper is designing a Chinese version of the app that will conform to draconian Chinese censorship laws.
Zimmerman has uploaded what he claims is Whispers entire, unedited response to The Guardian via scribd. Because these things have a way of disappearing, a backup copy of Zimmerman's response is also available.
Learn OpenStack with TryStack
Getting an opportunity to play with OpenStack effectively can be cost-prohibitive. Particularly for developers looking to integrate Keystone API functionality into their applications - you shouldn't have to build your own OpenStack deployment, or cough up boku bucks. Even if you have the resources, time is irreplaceable.
That's where TryStack can come into play. To get going, start by joining the TryStack Facebook group. This is the only down-side to TryStack to my mind. I absolutely *despise* Facebook and everything it stands for. Still, even I managed to reset my long-unused F-Book login to join (they should be rolling out other auth capabilities soon - GitHub is supposed to be next).
Within a day Dan Radez with Red Hat had activated my account, and I was able to spin up a couple of servers and got them routing out to the big bad world. Dan has put together a very easy-to-understand instructional video to help with new users:
That's where TryStack can come into play. To get going, start by joining the TryStack Facebook group. This is the only down-side to TryStack to my mind. I absolutely *despise* Facebook and everything it stands for. Still, even I managed to reset my long-unused F-Book login to join (they should be rolling out other auth capabilities soon - GitHub is supposed to be next).
Within a day Dan Radez with Red Hat had activated my account, and I was able to spin up a couple of servers and got them routing out to the big bad world. Dan has put together a very easy-to-understand instructional video to help with new users:
I should make clear that this is only a testing environment - as a result, instances only stay live for 24 hours before getting wiped. Still, this is more than enough time to confirm functionality using Keystone before, say, pushing a new feature out to your production system.
Enjoy.
Wednesday, October 15, 2014
Windows 10 Technical Preview Testers Should Beware
I try to keep on my toes when it comes to latest distributions of Operating Systems that I use. While I don't use anything bleeding edge that I haven't built with my own hands in production, I like to stay abreast of the latest and greatest.
Windows in in recent years become a drag in this respect. Later iterations have ditched interface features that add nothing to functionality, making adoption a pain, especially for someone in my position that frequently administers servers with a variety of different Windows versions. Thats whats so great about shells - it stays a shell. New features are usually actual features and not visual gimmicks.
So I got myself an early copy of Windows 10. I joined the Windows Insider Program. I downloaded the Windows Technical Preview ISO, which you can download by following that link and using the tester Product Key: NKJFK-GPHP7-G8C3J-P6JXR-HQRJR. I started digging around for some documentation before firing up a VM. And thats when I paused.
Last week it became apparent that the Windows 10 Technical Preview comes equipped with incredibly invasive spyware; it maps networks and devices and monitors keystrokes. Then it takes all of those goodies and ships them back to the Mother Ship in Redmond. Many voices were heralding this uncomfortable news - Hacker News. Even outlets that are loath to pick fights with MS, like Softpedia.
The Technical Preview Privacy Statement that users affirm through downloading the software provides the details in plain language:
"If you open a file, we may collect information about the file, the application used to open the file, and how long it takes any use [of] it for purposes such as improving performance, or [if you] enter text, we may collect typed characters, we may collect typed characters and use them for purposes such as improving autocomplete and spell check features,"
Further research is required before removal instructions can be confirmed. For the time being, if you find it necessary to test this OS, do so on a gapped device. An initial internet connection is required for product activation. After that, get rid of it. I would recommend installing on a VM so you can just delete the install's Virtual NIC and also make sure it can't do anything nasty to devices you might have forgotten about or that a visitor might have, like bluetooth enabled phones.
Windows in in recent years become a drag in this respect. Later iterations have ditched interface features that add nothing to functionality, making adoption a pain, especially for someone in my position that frequently administers servers with a variety of different Windows versions. Thats whats so great about shells - it stays a shell. New features are usually actual features and not visual gimmicks.
So I got myself an early copy of Windows 10. I joined the Windows Insider Program. I downloaded the Windows Technical Preview ISO, which you can download by following that link and using the tester Product Key: NKJFK-GPHP7-G8C3J-P6JXR-HQRJR. I started digging around for some documentation before firing up a VM. And thats when I paused.
Last week it became apparent that the Windows 10 Technical Preview comes equipped with incredibly invasive spyware; it maps networks and devices and monitors keystrokes. Then it takes all of those goodies and ships them back to the Mother Ship in Redmond. Many voices were heralding this uncomfortable news - Hacker News. Even outlets that are loath to pick fights with MS, like Softpedia.
The Technical Preview Privacy Statement that users affirm through downloading the software provides the details in plain language:
"If you open a file, we may collect information about the file, the application used to open the file, and how long it takes any use [of] it for purposes such as improving performance, or [if you] enter text, we may collect typed characters, we may collect typed characters and use them for purposes such as improving autocomplete and spell check features,"
Further research is required before removal instructions can be confirmed. For the time being, if you find it necessary to test this OS, do so on a gapped device. An initial internet connection is required for product activation. After that, get rid of it. I would recommend installing on a VM so you can just delete the install's Virtual NIC and also make sure it can't do anything nasty to devices you might have forgotten about or that a visitor might have, like bluetooth enabled phones.
Tuesday, October 14, 2014
Rackspace Still Offers Free Cloud Servers - With a Few Strings
A few years back - around 2011, Redhat released a Free Cloud server tier to compete with Amazon EC2's offering (IMHO this was an attempt by the big boys to try to annihilate the downside of the market). While EC2 continues to offer free tiny servers, Rackspace bowed out; their minimum offering these days is somewhere around $16 / month.
I came across some references to Rackspace continuing to offer free services, but this time only to OSS developers. The benefits are great for those who qualify; while it sounds somewhat flexible no doubt depending on the marketing gains to attracting a big name project, even somewhat niche projects are being offered $2000/month in free services. That buys a lot of muscle for the smart consumer.
Jesse Noller is the man with the hookup. Send him an email to see what you can get if you meet the requirements.
I came across some references to Rackspace continuing to offer free services, but this time only to OSS developers. The benefits are great for those who qualify; while it sounds somewhat flexible no doubt depending on the marketing gains to attracting a big name project, even somewhat niche projects are being offered $2000/month in free services. That buys a lot of muscle for the smart consumer.
Jesse Noller is the man with the hookup. Send him an email to see what you can get if you meet the requirements.
Labels:
cloud,
developers,
free,
hosting,
Jesse Noller,
open source,
OSS,
rackspace,
servers
Sunday, October 12, 2014
NSA Targets Systems Administrators with no Relations to Extremism
The Details
This is a bit of an old story, but I've found to my unpleasant surprise that the issues surrounding the story are not widely understood or known. Here's the gist: leaks from the US intelligence service have explicilty confirmed that the NSA targets systems administrators that have no ties to terrorism or extremist politics. If you are responsible for building and maintaining networks, the NSA will place you under surveillance both personally or professionally; they will hack your email, social network accounts and cell phone. The thinking behind this alarming strategy is that compromising a sysadmin provides root-level access to systems that enable further surveillance; hack an extremist's computer, and you track just that extremist. Hack a sysadmin's computer, and you can track thousands of users who may include extremists among them (its a strategy that is remarkably similar to the targeting of doctors in war zones).Five years ago such a lead paragraph would be among the most wild-eyed of conspiracy theories. Now, after the Snowden leaks and the work of other sources within the US Intelligence community, the sysadmin targeting scheme has been proven conclusively through supporting documents circulated through a "wiki" style system within the NSA and explained and reported by Ryan Gallagher and Peter Maas of The Intercept. The name of the scheme is I hunt sys admins. The entire document outlining the goals and methods of the I hunt sys admins scheme is available on The Intercept (While I typically publish source documents directly on this website for ease of use, publishing these documents present unique legal concerns that The Intercept is better equipped to handle - I apologize to users for the inconvenience of having to visit a second site to confirm sources but I assure you it is well worth the effort).
There are a few excerpts worth noting explicitly. First and foremost, the document describes that the surveillance typically begins by acquiring the administrator's webmail or Facebook account username. The NSA agent then uses an Agency tool called QUANTUM to inject malware into the admin's account pages. The Intercept has put together a video outlining the QUANTUM tool's capabilities that is worth watching. The existence and capabilities of the tool are themselves also confirmed through extensive NSA documentation. QUANTUM uses a Man-On-The-Side attack to hijack user sessions and redirect traffic to one of the NSA's Tailored Access Operations (TAO) Servers. In this case, the application server used is called FOXACID. The same application is used to compromise Firefox and Tor users (a related program in place at Britain's GCHQ called FLYING PIG offers similar functionality even while using SSL).
QUANTUM has a variety of different uses besides the one outlined above. QUANTUM has a series of plugins that allows NSA agents to take control or IRC networks, compromise DNS queries, run denial of service attacks, corrupt file downloads and replace legitimate file downloads with malware payloads.
The methodology is important as it demonstrates the importance of maintaining operational security even during personal time. These are not attacks that target political or military organizations; they do not even target corporations. They explicitly target individual system administrators.
And there's more.
NSA Agents use the tool Discoroute to retrieve router configurations from passive telnet sessions. NSA documents outline how, rather than use sysadmins to target the corporations they work for, NSA is interested in doing the reverse - using corporate router configurations to target individual sysadmins. For example, using Discoroute, a surveillance agent retrieves the access-list ruleset associated with the router. Using that access-list can reveal home IP addresses that admins use to login to systems remotely. While this may seem to be an egregious security oversight, the access-lists in question are not necessarily for core routers. The access-list could just as easily be retrieved from a PIX; an IP used to allow access to an intranet website.
The I hunt sys admins documents continue by outlining some methods to identify and surveil malicious users. The author of I hunt sys admins references the NSA's access to massive untargeted recordings of SSH sessions. Perhaps we can take some security in that the author apparently does not take it for granted that the NSA can easily decrypt SSH session data. However, quite a bit can be accomplished by analyzing encrypted data. In this instance, I hunt sys admins recommends reviewing the size of SSH login attempts to determine which are successful and which are failed. IP addresses which are recorded failing multiple attempts to large numbers of IPs can safely be identified as belonging to brute force attempters.
Why You Should Care About NSA Surveillance Even if You Do Not Care About NSA Surveillance
This is a website about technology; not politics. Whatever your opinions are about the legitimacy or warrantless surveillance, the actions of the NSA and the other Five Eyes surveillance agencies are having a significant and deleterious impact on the internet and those who build and support it. Additional leaks have demonstrated that NSA provided security firm RSA with $10 million to use the flawed Dual_EC_DRBG random number generator in its unfortunately-named BSAFE cryptographic library, providing a back door to all applications relying on BSAFE. Even more disturbing are confirmations that the NSA has obtained copies of root CA certificates and used them to compromise SSL implemented by major internet services.But why should we care? I'm not guilty and so I have nothing to hide, as the oft-used rationalization goes. Warrantless surveillance by governments is only one consequence of the actions outlined above. Chief among concerns for the admins targeted by these policies that are unconcerned with government surveillance is that actors other than the Five Eyes nations can easily engage in the same practices as explained in the I hunt sys admins documents; frankly, few if any of the I hunt sys admins guidelines were actually invented by NSA. These are techniques designed by criminals, and criminals have massive incentives to continue innovating those techniques. To protect our privacy from criminals we must follow security best practices, and by following best practices we necessarily protect ourselves against government surveillance as well.
The fact remains that sysadmins will remain a desirable target for those seeking to break into protected systems. Protecting those systems and the users who depend on them is part of our mandate as administrators. Now that we know the extent to which the security environment has changed, the question becomes whether we continue to adapt to the new environment to best protect our applications and users, or whether we disregard our mandate.
Labels:
admins,
brute force,
BSAFE,
cryptography,
Dual_EC_DRBG,
hacking,
I hunt sys admins,
national security agency,
nsa,
root CA,
RSA,
security,
spy,
ssh,
ssl,
surveillance,
sysadmins,
systems administrators
Saturday, October 4, 2014
GoDaddy Has Hosted Malicious and Abusive Traffic for over a Year and Doesn't Care
A little over two weeks ago I attempted to contact GoDaddy's Abuse contact about malicious scanning coming from a GoDaddy IP. This post will describe how GoDaddy not only ignored my warnings about this criminal use of their IP space, but has allowed this same scammer to use this same IP to exploit legitimate users for years, ignoring numerous warnings from their own customers, industry security experts and even other hosting companies. I will also explore some possible reasons as to why GoDaddy has become a so-called "Bullet-Proof" host; an honor usually reserved for basement "data centers" from Southeast Asia and Eastern Europe.
This IP tried to scan my server for Wordpress vulnerabilities, and then tried to scrape some content. The traffic was ham-fisted and amateurish; the kind of traffic that is obviously malicious. The attempt was logged, immediately blacklisted, and forwarded to me.
This sort of thing happens all the time. And ordinarily, I am very sympathetic to hosting companies. Most hosting companies spend a lot of money and energy getting rid of scammers that abuse their service in this way. Once, many years ago, I worked for a hosting company where resolving such complaints was one of my primary responsibilities.
We all know that this kind of malicious traffic is a danger to people who are new to the internet; normal folks who just want to blog with their friends or get a little free advertising for their small business. Web pedestrians. But thats not the only danger. Scanning like this devalues the IP space maintained by the hosting company who is used to facilitate it. Scanning gets IPs blacklisted. When the next (legitimate) customer comes around and tries to use one of those IPs, she finds that email doesn't work like it should, and that some people can't get to the websites hosted on her server. This is a huge hassle. Word gets around: this hosting company sells broken IPs. Customers decide to go elsewhere.
GoDaddy has grown large over the years by going in the opposite direction of most hosting companies. Rather than by providing quality resources with well-trained engineering staff, GoDaddy provides half-broken resources with incompetent customer service representatives. GoDaddy is the very bottom of the down market; the catfish of datacenters. I should point out that GoDaddy's approach is not just about low prices. Providers like Linode, for example, appeal to tech-savvy people by providing very good infrastructure with no support. GoDaddy provides unreliable infrastructure with no support. GoDaddy has survived by competing on solely on price for inexperienced customers. Web pedestrians.
Despite GoDaddy's long-standing position as the butt of jokes, the overall opinion is that they have and continue to do the bare minimum. That's why I was so surprised to find them providing long term hosting to scammers. Preventing the use of your data centers to steal from people is, by any measure, the absolute bare minimum.
Here is a sample of the scanning looking for Wordpress vulnerabilities:
And here is a sample of the same host attempting to scrape content:
As you can see, not much is hidden. What I was immediately interested in was this bit about User Agent identification on the last bit of that last log entry. abot is a an opensource webcrawler - a completely legitimate one, I should add. 64.202.161.41 has apparently developed their own fork of abot that they are using to scrape. They are so confident of their relationship with GoDaddy that they have used the GoDaddy name to brand their fork - calling it CrawlDaddy.
This bit of branded hubris gave me a means to start doing some historical research. Most scammers have a fly by night relationship with hosts. A scammer gets at best a few months, and more usually a few days or weeks of abusing a hosting service before they get the boot. You don't name you malware after a hosting provider that you plan on leaving anytime soon.
Sure enough, I found article after article talking about CrawlDaddy. Jetfire Networks, a VPS host, warned their customers of the scanning. Jetfire also blacklisted GoDaddy's IP space from reaching their share hosting customers, apparently to prevent a successful Wordpress exploit. Jetfire had absolutely nothing to do with hosting the attacks - unlike GoDaddy - yet took proactive precautionary measures. Jetfire published their notification October 2013; the earliest reports I found published were from September 2013.
I should note at this point that I am a GoDaddy customer. Several months ago I purchased a single domain name from GoDaddy for 99 cents. The money isn't really the point; the point is that I have a GoDaddy customer ID number. I'm not just some random lunatic to them.
So I emailed GoDaddy. I outlined all the technical details above, confirming those details with valid log data. I provided URLs to websites that also posted valid log data. I even explained to them how they could verify my claims using traffic sampling (netflow, etc). That was over two weeks ago. I received no reply. The host is still online, and from what I can tell, still scanning.
Others have already contacted GoDaddy about 64.202.161.41 over the last year. 64.202.161.41 could just as easily (likely more easily) be scanning other GoDaddy customers. And the scanning continues.
This IP tried to scan my server for Wordpress vulnerabilities, and then tried to scrape some content. The traffic was ham-fisted and amateurish; the kind of traffic that is obviously malicious. The attempt was logged, immediately blacklisted, and forwarded to me.
This sort of thing happens all the time. And ordinarily, I am very sympathetic to hosting companies. Most hosting companies spend a lot of money and energy getting rid of scammers that abuse their service in this way. Once, many years ago, I worked for a hosting company where resolving such complaints was one of my primary responsibilities.
We all know that this kind of malicious traffic is a danger to people who are new to the internet; normal folks who just want to blog with their friends or get a little free advertising for their small business. Web pedestrians. But thats not the only danger. Scanning like this devalues the IP space maintained by the hosting company who is used to facilitate it. Scanning gets IPs blacklisted. When the next (legitimate) customer comes around and tries to use one of those IPs, she finds that email doesn't work like it should, and that some people can't get to the websites hosted on her server. This is a huge hassle. Word gets around: this hosting company sells broken IPs. Customers decide to go elsewhere.
GoDaddy has grown large over the years by going in the opposite direction of most hosting companies. Rather than by providing quality resources with well-trained engineering staff, GoDaddy provides half-broken resources with incompetent customer service representatives. GoDaddy is the very bottom of the down market; the catfish of datacenters. I should point out that GoDaddy's approach is not just about low prices. Providers like Linode, for example, appeal to tech-savvy people by providing very good infrastructure with no support. GoDaddy provides unreliable infrastructure with no support. GoDaddy has survived by competing on solely on price for inexperienced customers. Web pedestrians.
Despite GoDaddy's long-standing position as the butt of jokes, the overall opinion is that they have and continue to do the bare minimum. That's why I was so surprised to find them providing long term hosting to scammers. Preventing the use of your data centers to steal from people is, by any measure, the absolute bare minimum.
Here is a sample of the scanning looking for Wordpress vulnerabilities:
64.202.161.41 - - [08/Sep/2014:10:26:27 -0400] "GET /admin HTTP/1.1" 404 15 "-" "User-Agent\tMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
64.202.161.41 - - [08/Sep/2014:10:26:28 -0400] "GET /wp-login.php HTTP/1.1" 404 15 "-" "User-Agent\tMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
64.202.161.41 - - [08/Sep/2014:10:26:28 -0400] "GET /administrator HTTP/1.1" 404 15 "-" "User-Agent\tMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
64.202.161.41 - - [08/Sep/2014:10:26:28 -0400] "GET /user HTTP/1.1" 404 15 "-" "User-Agent\tMozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0)"
And here is a sample of the same host attempting to scrape content:
64.202.161.41 - - [08/Sep/2014:10:26:26 -0400] "GET / HTTP/1.1" 200 7218 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; CrawlDaddy v0.3.0 abot v1.2.0.0 http://code.google.com/p/abot)"
As you can see, not much is hidden. What I was immediately interested in was this bit about User Agent identification on the last bit of that last log entry. abot is a an opensource webcrawler - a completely legitimate one, I should add. 64.202.161.41 has apparently developed their own fork of abot that they are using to scrape. They are so confident of their relationship with GoDaddy that they have used the GoDaddy name to brand their fork - calling it CrawlDaddy.
This bit of branded hubris gave me a means to start doing some historical research. Most scammers have a fly by night relationship with hosts. A scammer gets at best a few months, and more usually a few days or weeks of abusing a hosting service before they get the boot. You don't name you malware after a hosting provider that you plan on leaving anytime soon.
Sure enough, I found article after article talking about CrawlDaddy. Jetfire Networks, a VPS host, warned their customers of the scanning. Jetfire also blacklisted GoDaddy's IP space from reaching their share hosting customers, apparently to prevent a successful Wordpress exploit. Jetfire had absolutely nothing to do with hosting the attacks - unlike GoDaddy - yet took proactive precautionary measures. Jetfire published their notification October 2013; the earliest reports I found published were from September 2013.
I should note at this point that I am a GoDaddy customer. Several months ago I purchased a single domain name from GoDaddy for 99 cents. The money isn't really the point; the point is that I have a GoDaddy customer ID number. I'm not just some random lunatic to them.
So I emailed GoDaddy. I outlined all the technical details above, confirming those details with valid log data. I provided URLs to websites that also posted valid log data. I even explained to them how they could verify my claims using traffic sampling (netflow, etc). That was over two weeks ago. I received no reply. The host is still online, and from what I can tell, still scanning.
Others have already contacted GoDaddy about 64.202.161.41 over the last year. 64.202.161.41 could just as easily (likely more easily) be scanning other GoDaddy customers. And the scanning continues.
Subscribe to:
Posts (Atom)

