Wednesday, November 24, 2010
Mint.com and Fidelity login errors
Thursday, August 27, 2009
Fidelity password fail
Convenient, yes? The problem is that this means the "secure" password I had chosen, which contained upper and lower-case letters and numbers, was actually being stored by Fidelity as a string on numbers.
For example, suppose your password is "MaGic8" . Using the phone keypad mapping for letters this becomes the number 624428. The sad thing is you can log in to Fidelity.com using 624428 as your password. You could also type in "NCHHCU" since this maps to the same numbers.
In this example, there are 4096 (4^6) different passwords that an attacker could enter and that would all allow them access to your account.
Instead of 62 or more possibilities per character (uppercase, lowercase and digits), you're effectively using 10 possibilities per character. That's a drop in entropy of 10 bits (or a factor of 1000) for a 6-character password.
What's odd is that they don't seem to do the same thing for the user ID - typing in the numbers your ID maps to doesn't work.
Thursday, October 02, 2008
AntiVirus XP vendor sued
Yay! From ZDNet's ZeroDay blog today:
"The software purveyor behind AntiVirus XP, a fake anti-virus package, has been sued and will hopefully be put out of business."
This is great news - even better would be if they are forced to remove their badware from all the machines they've infected. It was sad to see the public Internet machine in our hotel in Manuel Antonio, Costa Rica, infected with this crap. (See the screenshot I took.) I was tempted to try removing it, but doing tech support on vacation is not my idea of fun.
Update: 10/02/2008
I didn't realize that Microsoft and the Washington State Attorney-General are the ones suing over this. Kudos to both! Brian Krebs (Washington Post) and Bruce Schneier also wrote about this. (The comments are pretty sad - I had no idea how prevalent this stuff is...)
Wednesday, April 16, 2008
He's a remorseless killing machine...
Has Mark Dowd simply outclassed us? Should we pack it up and quit?
Yes. But don’t feel bad about that. You’re a human being, and he’s a remorseless killing machine. Big Blue crushed Kasparov, and now he’s not the prime minister of Russia! At a certain point, you have to concede the field, moving on to games where human beings still have the advantage. Computers haven’t solved Go, for instance. For us researchers, I suggest we take advantage of Mark Dowd’s robotic inability to love, and take up the arts, such as watercolors or interpretive dance.
This comment comes at the end of the 2nd post commenting on Mark's recent software security paper on Flash. The paper itself is quite brilliant - going from a write-AV on a NULL dereference, to running unverified ActionScript and pwning Flash.
For a more high-level summary see these posts: #1, #2 on the Matasano blog.
Incidentally, enabling ASLR on Vista would be a way to mitigate against this attack, but sadly Adobe haven't yet released a version of Flash with the required option set in their binary. If you're geeky and want to turn this on yourself, you can use a recent link.exe from Visual Studio or the WDK like so:
Wednesday, February 13, 2008
Dual-booting Vista and Ubuntu / Linux
The tricky thing was that I wanted to keep using Vista Bitlocker Drive Encryption (BDE), since my laptop has a TPM and having the drive encrypted means I don't need to worry as much about having my laptop stolen and all my data being up for grabs. BDE is a bit tricky to set up at the best of times, but luckily at work we have a Remote Installation Services (RIS) server that makes it a lot easier.
So, I booted my laptop, selected a network boot, and selected the Vista Bitlocker setup from the RIS menu. This re-paritions your drive and creates two partitions for Windows to use (one small one for the Bitlocker boot stuff, and the main one for your Vista install). I selected the manual setup option so I could create two more partitions for Linux to use (one for extfs3 and one for swap). Then The Vista setup trundled along and within an hour I had a nice Vista setup (with Office 2007 installed already - how sweet it that!?)
At this stage, BDE is not yet enabled on your Vista drive - you need to go into the control panel and enable it. But I knew I wanted to hold off until my Ubuntu install was done, otherwise when the Ubuntu install changed the Master Boot Record (MBR) on the hard drive, Bitlocker would "throw a wobbly". (Yes, that's the technical term)
The next step was to insert the Ubuntu 7.10 CD and reboot the machine from it. The Ubuntu install is very slick and went without any hitches. Now when my laptop rebooted, I was presented with the GRUB boot loader, which let me choose between Ubuntu or Vista.
Now at this point I should mention that I subsequently found out that this is not the best order to do things. This blog has incredible information, but sadly I only found out about it after I had installed Vista and Ubuntu. The preferred order is to install Ubuntu first, then install Vista... (That way the Vista boot loader is one sitting in the MBR) However, using the information from the afore-mentioned blog, you can quite easily get the system working even if you've installed things in the "wrong" order like I did.
The key pages to read for instructions are this one and this one. The modified steps I used, based on the info in these pages, is then:
- Step 1 – Install GRUB on the Linux partition (outside of MBR) (See step 1 here)
- Step 2 – Get a copy of Linux boot sector (See step 2 here)
- Step 3 - Boot into the Vista Recovery Environment (RE) using the Vista DVD / RIS server. You'll need to run bootrec.exe and tell it to fix the MBR record. (See this page for info)
- Step 4 - You should be able to reboot from the hard-drive and Vista will load automatically (there will be no option to boot Ubuntu since Vista doesn't know about it yet...) Log in to Vista, and...
- Step 4 - Set up Windows Vista Boot Manager to boot Linux. (See step 4 here)
- Step 5 - Enable BitLocker on Windows Vista (See step 7 here)
(I also removed Vista from the GRUB boot menu, since we're now using the Vista loader to boot into Vista. This is pretty easy to do, just edit /boot/grub/menu.lst and remove the Vista entries form the end of the file).
Step 4 will take a few hours as it needs to encrypt the hard-drive contents, but once that is done you should be set...
Wednesday, November 28, 2007
Mind 'ow you search...
Ways to stay safe(r):
- Use Vista on a 64-bit machine with hardware DEP enabled, and UAC enabled
- Run as a normal user (not an admin)
- Don't install anything when a website prompts you, unless you know and trust the website, are really are sure it's something you need, and it's signed by a trusted publisher.
- Uninstall Quicktime :)
Tuesday, September 18, 2007
Phishing
The message was also forced into plain-text mode, so the fake URL for PayPal was clear, but I decided to paste it into IE7 anyway, just to see how the Phishing Filter handled it. Sadly the website was not automatically recognized as a phishing site (I submitted it, so hopefully it will be recognized soon)
To recognize that this is a phishing page, notice the server address (the stuff after http://) is a weird domain name ending in .co.kr. The :81 is a port number - almost all normal websites won't have this in their URLs. Ignore anything after the '/' following the port - that looks like PayPal, but in fact it can be whatever the bad guy wants.
Incidentally, some phishing sites use server addresses that look more valid, such as www.paypal.somefunkyname.co.kr.
The phishing page is pretty brazen. First you have to "log in" with your email and password (anything you enter will be accepted). Then you are prompted to hand over all your private information: name, address, DOB, phone, credit card number + CVV2 and ATM pin. Why anyone would give their ATM PIN to a website purporting to be PayPal I don't know - perhaps the phishing folks just though they might get lucky?
They also ask for the last six digits of your SSN - I guess they don't ask for the whole thing since people are used to entering the last few digits only, and think this is safe. No-one apart from your employer and the IRS should ever need your SSN - even the last four digits! (And I think with the last six digits, the bad guys can figure out the remainder based on your ZIP code/State of residence).
I hope people now know to never enter this sort of personal information on a website - especially one linked to in an email.
Wednesday, April 11, 2007
Tuesday, April 03, 2007
Time to get your Windows updates
Monday, April 02, 2007
Fun with cookies
Recently at work the topic of HTTP cookies came up. (For some background info on HTTP cookie, see this). Most websites that provide a logon form (username & password) use cookies to allow you to save your logon information ("Remember my information on this computer"). Sites also use cookies to store user information if you don't tell the computer to remember your information - these cookies stay around as long as your web browser is open.
Why is this bad? One reason is that it's sometimes possible for people to steal your logon information using what's calls Cross-Site Scripting (XSS). I won't go into that here, but will share some simple mechanisms you can use to inspect cookies, and mess with them. (Nothing here is really new or revolutionary, but was new to me, so I thought I'd share it...)
It turns out your web browser is capable of showing you the cookies for any page you're viewing: just paste
javascript:{alert(document.cookie);}in the address bar. You should see a window pop up with cookie information, such as this (from Google) :

Some websites requiring a logon will have your username and password right there in the cookie (making it easy for someone to use them if stolen). One example of such a site is www.cellartracker.com. If you have an account there, log on and then use the above javascript to see your info - nifty, eh?
Now let's pretend we're an attacker that has stolen cookies from someone. How would you use them to log into a website? Again, Javascript makes this really easy. Let's take www.cellartracker.com as an example again (I'm not bashing on them, their site is great!)
Log out (if you were logged in), and look at your cookie using the above Javascript. It should only contain one entry, e.g.:
ASPSESSIONIDCCDSQTRS=DNCMEHMBIFCJIPMIOBJOMJIFNow let's "inject" the logon information we stole (you can use your real CellarTracker information if you have an account). Type in the following in the address bar, replacing
javascript:{document.cookie="Password=your passwordThe webpage will change to display the cookie values you just set. No problem, just re-enter www.cellartracker.com in the address bar. You should now see the page for logged-in users...; User=your username";}
Tweaking cookies using Javascript is an interesting way to do targeted deletion of cookies you don't want hanging around (instead of erasing all cookies). This website covers Javascript and cookies in more depth, and has some examples of deleting cookies.
Note that there's a way to prevent all of the above: HTTP-Only cookies. This tells the web browser to not expose the cookies to the web page in any way (so no script access). They are still sent to the web site when you make requests, but malicious script code running in your browser can't see them or modify them...