New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online.
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 20)
· Marcia's (QA2)
· Bill G's (CO8)
· Paul's (AR 5)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· Recommend Us
· RegChat
· Reviews
· Search (Topics)
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 470
Comments: 13
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image crkatk: WeekEnd Feature: Hackers, Crackers and Gaps in the Wall image
Crack Attack

WeekEnd Feature:
Hackers, Crackers and Gaps in the Wall










by Ian Thompson, CCSP Staff Editor
May 15, 2004


This week has been a bit of a whirlwind. Not only have I had it up to here with some of the silly stuff going on at work, but also the Google news doohickey has come up trumps again. I mean, only last week we were all under a barrage of Sasser-related shenanigans, rewinding clocks (if we knew that this was a work-around) and patching lsass on affected PCs. Good ‘ol Windows 98, s’what I say to that one…

Sven’s another attack going to happen?
Ouch! Weak joke alert system not quite up to speed yet.

Okay, so German police closed in on Sven Jaschan last week, and now he’s not only owned up to writing Sasser, but also for being the original author of NetSky, as predicted in these here pages. Actually, all I do is keep my ear to the ground and listen to the real experts who are busy analysing and pattern matching the millions of examples of viral code captured over the years.

That’s how they are pretty sure he’s the guy (erm, barely). There’s been another version of Sasser released since Sven’s arrest, but according to analysts it was merely a hex-edit of the previous version, perhaps to try and convince others that the actual author is still at large.

This seems like the tip of the iceberg, since there’s perhaps another round of the NetSky/Bagle slanging match being played out here. You see, reports claim that Sven actually fell foul of a tip-off to the Microsoft Anti-Virus Reward Program – the ultimate ‘up yours’ from the rival coders. And by all accounts, he didn’t work alone – police are pursuing several suspects in what may turn out to be an organised coding/distribution ring. At the very least, if the rest of the gang have control over a variety of bot networks, they will fall foul of the German computer sabotage laws.

All in all, you’re just another brick [missing] in the wall.
Pink Floyd clearly missed that word out, but had always meant it to be there. Allegedly.

Remember when Witty whacked ISS BlackIce Defender? Of course you do – unless you are a goldfish – because it was only a few weeks ago. How time flies in computing! Hold on to your modems, ‘cos I suspect that things are going to go screwy for many more users soon.

Symantec, probably the biggest provider of PC security to the masses, has known for about a month of four critical security flaws that affect its entire range of products. Scary. At least the patches were released this week (Thursday 13 May) and all those diligent users with the AutoUpdate feature switched on will now be protected.

I can’t remember – is that feature switched on as a default…?

Remember though that the Witty coders (no, they aren’t witty, but they are Witty coders – sheesh!) had cracked the patch within a day. I recommend that all users of Symantec security products immediately disconnect from the Internet, especially those using dial-up modems, because the exploit for these flaws will be on your box before you can dial up and collect the patch files. But in case you are fed up with waiting for the pigeon to struggle all the way from Symantec to your door, hot update disk in beak, goggles askew and scarf all raged, remember to try rewinding the clock if anything funny starts happening to your PC…

The flaws? Oh, I suppose you could find out more, but basically;

Flaw 1 is a NetBIOS issue – the packets are not handled correctly;
Flaw 2 is a DOS against the Firewall, using a faked DNS request;
Flaw 3 is back with NetBIOS and could give full kernel access through the firewall;
Flaw 4 is a good old buffer overflow exploit.

Apparently, “due to a separate design flaw in the firewall’s handling of incoming packets, this attack can be successfully performed with all ports filtered, and all intrusion rules set.” So says the team that warned Symantec about these babies in the first place. Anyone for ZoneAlarm? Or a plain, simple NAT router – most ‘home user’ (i.e. cheap) hardware versions have firewall capabilities, so it won’t cost much to help Norton WhatEver out a bit.

If you really get spooked, I used to run ZA and Sygate Pro side by side – and you could always chain a couple of hardware routers together, to see how a system copes with four firewalls, plus maybe the XP chocolate fireguard too. Let us know if anything actually makes it through, but do me a favour and don’t invite stuff in to play – you must resist the cheat code and crack sites – RESIST!!!

Tippex, SnoPake, Liquid Paper – what’s the point?
Have you ever seen those pixelated photos or CCTV images, where they replace someone’s face with a shifting pattern of coloured squares? I bet you’ve squinted, just to see if you can blur the rest of the image enough to get a ‘clearer’ picture of the person. We can do this because of the brain’s ability for pattern matching. It’s like those Mensa tests, where there are sequences to follow or codes to decipher. Oh, which reminds me – Mercury Rising was on TV this week – entertaining, but total rubbish: I never hear modem noises when staring at a wordsearch... We are very good at spotting the pattern in things, so good that we often create a pattern where there isn’t one.

However, you’ll have also seen those pictures of official documents with crucial words blocked out in an effort to retain secrecy, even on declassified stuff.

Well, this week, pattern matching proved this to be as weak as a puppy as well. The method used by Claire Whelan, a computer science student at Dublin City University, involved a series of simple steps:

Step one: Scan in the document so it can be realigned properly.
Step two: Determine the font face (this has to be pretty accurate, for reasons that will later become apparent).
Step three: Determine the exact point size of the text.
Step four: Run through the dictionary and see which words will fit the blanked gapes in the font face and size that has been determined on steps two and three, give or take a couple of pixels.
Step five: use semantic guidelines and a bit of common sense – if the sentence doesn’t make sense using a word that fits, then it’s not likely to be the right word.

In the example given byThe Register, the blanked out word in a memo to George Bush in the sentence "An Egyptian Islamic Jihad (EIJ) operative told an XXXXXXXX service at the same time that Bin Ladin was planning to exploit the operative's access to the US to mount a terrorist strike" was judged to have been the word ‘Egyptian’. No shinola, Sherlock – I mean, it was only a member of an Egyptian group who was quoted here.

However, the software used had narrowed the choice down to a few hundred possible words, of which only a ‘Bruce Almighty’ handful made any sense. Using the same techniques, another memo, about how civilian helicopters could be modified for military use (How ‘Airwolf’ of them – a Bell 222 never looked better!), it turns out that South Korea was the source of the knowledge…

Personally, if a kid tried Tippexing out a word on a piece of work submitted at school, it was always possible to read it reversed through the back of the page. And coloured light sometimes shows the text underneath black marker, depending on the ink. You see, it really is just best to put a single line through any corrections and then move on – otherwise I might suffer from a sense of achievement in having read what wasn’t meant to be read.

And finally…
Firemen today rescued an old woman who had become stuck up a tree. “It was amazing – after I’d spent ages trying to talk her down, all the firemen did was put some DentuGrip and a box of Thornton’s Toffee on the garden wall and waited whilst she literally ran down of her own accord”, said one onlooker. Another commented: “What was really amazing was that it was her cat who rang the emergency services – and they believed it! My dog saw a burglar in the house over there, but no-one took him seriously. Got away with a really good B&O system, too”.

cheers, Ian

by Ian Thompson ComputerCops Staff Editor

Ian Thompson is a Network Manager of a 500-PC, 9-server, 1700-user school network and is an ICT teacher at a UK high school near the city of Leeds. He has written articles for the Hutchinson Encyclopedia, plus many resources in support of teaching ICT in the UK schools' National Curriculum.

Copyright © Ian Thompson All Rights Reserved 2004.
Posted on Saturday, 15 May 2004 @ 09:18:06 EDT by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· PHP HomePage
· Microsoft
· Microsoft
· Linux Kernel Archives
· HotScripts
· Google Search Engine
· W3 Consortium
· More about Crack Attack
· News by phoenix22


Most read story about Crack Attack:
Beware Attacker from IP 200.55.7.235 and Whole 200.x.x.x Block

image
Article Rating
Average Score: 5
Votes: 4


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

Send to a Friend  Send to a Friend
image
"Login" | Login/Create an Account | 9 comments | _SEARCHDIS
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: Hackers, Crackers and Gaps in the Wall (Score: 1)
by phoenix22  on Saturday, 15 May 2004 @ 09:25:28 EDT
(User Info | Send a Message) http://computercops.biz
Well no God typo this week!!
God, what a week, eh??
Seems everybody has had a bit of a rush this week.....
Maintaining the usual and sensible seems to be an art, that only a few can manage.
You being one of the select few, Sir Ian.
jd



Re: Hackers, Crackers and Gaps in the Wall (Score: 0)
by Anonymous  on Sunday, 16 May 2004 @ 20:55:52 EDT
did you ever read this in chinese?
wow!
how do they do it?
this is a tough language.



Re: Hackers, Crackers and Gaps in the Wall (Score: 0)
by Anonymous  on Tuesday, 18 May 2004 @ 07:13:25 EDT
For years, I've suspected that Roger Waters used brick in the wall as a sound-alike for p***k with no b***s. (I'll wager that Claire Whelan wouldn't need to employ all 5 steps to suss this one out!)