# SANS ISC

# threatpost.com

  • Dear Jailbreaker, Apple Wants to Have a Word with You Sat, 19 May 2012 01:59:50 +0000

    After banning the word "jailbreak" from its app store and music library, Apple today reversed course and again permits the term - slang for hacking into a device to download unauthorized content -- to appear on iTunes and its App Store.

    On Thursday bloggers noticed Apple had censored the word, using the Thin Lizzy album "Jailbreak" as an example. For awhile, the title was listed as "J******k" in Apple's music library, at least its U.S. version. In other instances, digital content continued to bear the full name Jailbreak.

    read more

  • Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops Fri, 18 May 2012 19:34:50 +0000

    Defense giant Northrop Grumman is hiring software engineers to help it carry out "offensive cyberspace operations," according to a recent job posting.

    read more

  • ZTE Score M Android Phone Found to Have Backdoor Installed Fri, 18 May 2012 19:03:41 +0000

    UPDATE--An Android handset produced by Chinese manufacturer ZTE has a backdoor installed that could enable an attacker to take control of an affected device remotely and run arbitrary code. The manufacturer has acknowledged the issue in the ZTE Score M, which includes a harcoded password, and says that it plans to push out a fix soon. 

    read more

  • Global Payments Breach A Year Older Than First Reported Fri, 18 May 2012 19:02:39 +0000

    Alerts issued by Visa and Mastercard earlier this week suggest that a breach at payment processor Global Payments dates to January 2011, a full year earlier than the company initially announced.

    read more

  • Microsoft Adopts CVRF Format for Security Bulletins Fri, 18 May 2012 17:52:11 +0000

    Since the beginning of recorded time, security researchers, software vendors and hackers have been issuing security advisories in all kinds of nutty formats. Some feature excellent ASCII art, some have clever inside jokes and some come from Microsoft. Now, there's a effort underway, called the Common Vulnerability Reporting Framework, to standardize the way that vulnerabilities are reported so that they're in a common, machine-readable format. 

    read more

  • HULK DDoS Tool Smash Web Server, Server Fall Down Fri, 18 May 2012 13:52:56 +0000

    For the aspiring attacker or pen tester, there is no shortage of attack tools, scripts, crimeware kits and exploits available online. But, the Internet being what it is, there's always room for one more. Enter HULK, a new DDoS tool that arrives just in time to coincide with the release of some movie involving the actual Hulk and other CGI-ified mediocre-heroes.

    read more

  • New P2P Zeus Variant Targets Popular Sites with Bogus Offers Fri, 18 May 2012 00:16:02 +0000

    Facebook, Gmail, Yahoo and Hotmail users should beware of rogue rebate offers and new secure payment options aimed at getting them to part with their debit card information.

    Earlier this week Amit Klein, CTO of Trusteer, announced the discovery of a peer-to-peer variant of the Zeus platform that leverages trusted relationships and well-known brands to convince users to sign up for convenient services and better secure debit card transactions. On each site, the attack displays a little differently.

    read more

  • Twitter Implements Do Not Track Thu, 17 May 2012 16:34:34 +0000

    Twitter has implemented the Do Not Track header on its site, giving users the option of telling the site that they do not want to be tracked across other sites on the Web. The implementation is being done through the DNT technology in the Firefox browser.

    read more

  • Author of LilyJade Facebook Plugin Ignores Facebook Cease-and-Desist Thu, 17 May 2012 16:09:23 +0000

    As the tech and investment banking worlds eagerly anticipate Facebook’s long-awaited initial public offering, the world’s largest social network is trying to put stops to a suspicious, but arguably benign, plugin.

    read more

  • White House Security Czar Howard Schmidt Retiring Thu, 17 May 2012 14:54:17 +0000

    Howard Schmidt, the top White House information security adviser, is retiring after more than two years on the job and several decades in security both in government and private industry. Schmidt is in his second stint as the White House security chief and he's leaving at a time when cybersecurity has moved into the top tier of military and economic concerns for the country.

    read more

# Bruce Schneier's blog

  • Friday Squid Blogging: Squid Scalp Massager Fri, 18 May 2012 16:26:57 -0500
    Cheap! As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....
  • Kip Hawley Reviews Liars and Outliers Fri, 18 May 2012 06:06:51 -0500
    In his blog: I think the most important security issues going forward center around identity and trust. Before knowing I would soon encounter Bruce again in the media, I bought and read his new book Liars & Outliers and it is a must-read book for people looking forward into our security future and thinking about where this all leads. For...
  • Cybersecurity at the Doctor's Office Thu, 17 May 2012 12:28:45 -0500
    I like this essay because it nicely illustrates the security mindset....
  • Rules for Radicals Thu, 17 May 2012 07:20:14 -0500
    It was written in 1971, but this still seems like a cool book: For an elementary illustration of tactics, take parts of your face as the point of reference; your eyes, your ears, and your nose. First the eyes: if you have organized a vast, mass-based people's organization, you can parade it visibly before the enemy and openly show your...
  • USB Drives and Wax Seals Wed, 16 May 2012 13:50:05 -0500
    Need some pre-industrial security for your USB drive? How about a wax seal? Neat, but I recommend combining it with encryption for even more security!...
  • Security Vulnerabilities in Airport Full-Body Scanners Wed, 16 May 2012 06:15:10 -0500
    According to a report from the DHS Office of Inspector General: Federal investigators "identified vulnerabilities in the screening process" at domestic airports using so-called "full body scanners," according to a classified internal Department of Homeland Security report. EPIC obtained an unclassified version of the report in a FOIA response. Here's the summary....
  • U.S. Exports Terrorism Fears Tue, 15 May 2012 06:17:04 -0500
    To New Zealand: United States Secretary of Homeland Security Janet Napolitano has warned the New Zealand Government about the latest terrorist threat known as "body bombers." [...] "Do we have specific credible evidence of a [body bomb] threat today? I would not say that we do, however, the importance is that we all lean forward." Why the headline of this...
  • The Trouble with Airport Profiling Mon, 14 May 2012 06:19:44 -0500
    Why do otherwise rational people think it's a good idea to profile people at airports? Recently, neuroscientist and best-selling author Sam Harris related a story of an elderly couple being given the twice-over by the TSA, pointed out how these two were obviously not a threat, and recommended that the TSA focus on the actual threat: "Muslims, or anyone who...
  • Friday Squid Blogging: New Book on Squid Fri, 11 May 2012 16:58:04 -0500
    Kraken: The Curious, Exciting, and Slightly Disturbing Science of Squid. And a review. As usual, you can also use this squid post to talk about the security stories in the news that I haven't covered....
  • Smart Phone Privacy App Fri, 11 May 2012 06:42:22 -0500
    MobileScope looks like a great tool for monitoring and controlling what information third parties get from your smart phone apps: We built MobileScope as a proof-of-concept tool that automates much of what we were doing manually; monitoring mobile devices for surprising traffic and highlighting potentially privacy-revealing flows [...] Unlike PCs, we have little control over the underlying privacy and security...

# TWITTER

# WIRED Threat Level

  • The Ultimate Counterfeiter Isn’t a Crook—He’s an Artist Fri, 18 May 2012 21:28:11 +0000
    Want to design the ultimate counterfeit $100 bill? Hire an artist.
  • Jamming Tripoli: Inside Moammar Gadhafi’s Secret Surveillance Network Fri, 18 May 2012 19:43:57 +0000
    To expose and intimidate dissidents, Gadhafi's spy network tracked every communication in and out of Libya. But the insurgents knew how to fight back.
  • Top Handset Maker Confirms Backdoor in One of Its Models Fri, 18 May 2012 17:58:02 +0000
    One of the world's top mobile-phone handset makers has acknowledged the existence of a backdoor in one of its models.
  • Feds Considering Allowing DVD-Encryption Cracking Fri, 18 May 2012 01:56:17 +0000
    Federal regulators considered testimony Wednesday at UCLA on whether to allow citizens and filmmakers to legally crack DVD encryption meant to protect them from being copied.
  • It’s Tinkerers v. Hollywood as Copyright Office Mulls New Jailbreaking Rules Thu, 17 May 2012 21:51:05 +0000
    To jailbreak or not to jailbreak? That was the question on everybody's mind Thursday as copyright regulators, content creators and digital rights groups battled over whether Americans should have the right to tinker with the devices that they buy.
  • Comcast Suspends Data Cap Temporarily, Will Test New Overage Fees Thu, 17 May 2012 19:48:25 +0000
    Comcast is replacing its strict 250GB monthly data cap for residential users with a higher cap and a way to buy extra data, hoping to stem criticism that the nation's largest cable ISP is throttling the open internet.
  • To Warrant or Not to Warrant? ACLU, Police Clash Over Cellphone Location Data Thu, 17 May 2012 19:02:39 +0000
    A bill that would require law enforcement agents to obtain a probable-cause warrant to collect geolocation data on an individual would be burdensome to criminal investigators and prevent them from gathering the evidence they need to make a case, according to law enforcement witnesses at a hearing on Thursday.
  • Justice Dept. Defends Public’s Constitutional ‘Right to Record’ Cops Thu, 17 May 2012 00:01:26 +0000
    As police departments around the country are increasingly caught up in tussles with members of the public who record their activities, the U.S. Justice Department has come out with a strong statement supporting the First Amendment right of individuals to record police officers in the public discharge of their duties.
  • ‘Dead Man Walking’ Tricks Airport Into Giving Him Top Security Job Wed, 16 May 2012 17:53:25 +0000
    The TSA may have its eagle sights set on your underwear and water bottle, but it failed to miss the real security threat under its nose it was revealed Monday after a supervisor holding a top security job in a New Jersey airport was arrested for using the stolen identity of a dead man.
  • Banned PlayStation Hacker Sees Hope of Return in Jailbreaking Deliberations Wed, 16 May 2012 10:30:04 +0000
    George Hotz settled a civil suit filed against him by Sony for figuring out how to let people play homebrew games on the PlayStation -- in violation of a federal law that prohibits getting around encryption in hardware and software, even if the reason to do it is perfectly legal. He settled the suit by agreeing never to tinker again with a Sony product, but his hacker itch has him anxiously awaiting a looming decision by federal copyright regulators that, for the first time, could legalize videogame-console jailbreaking.

# exploit-db.com

Bg