Tag Archives: Hacking

Progress for GSM Knacken in der Universität Freiburg

Die spannende Welt der mobilen Protokolle (GSM, GSM-R, TETRA, UMTS, etc.) Hacking wird immer offizielle Forschungsaktivitäten von Universitäten.

Die Investitionen in opensource Code Versionen von Knack-Software zu machen ist die Gelegenheit geben, Studenten der Universität, daran zu arbeiten, es zu verbessern und zu tun starke Forschung.

Die Universität Freiburg hat soeben das Papier praxisgerechte GSM-Verschlüsselung A5 / 1 zusammen mit einem gsmframencoder Support-Tool, um den Schnupfen, Dekodierung und Crack-Verfahren zu verbessern.

Öffnungszeiten Hardware, Software öffnen, zeigen Öffnen Protokoll die Schwäche von jeder Art von proprietären Verfahren oder Verfahren für den Bau-up Kommunikation und Security-Technologien.

Es sollte das Ziel eines jeden Wissenschaftler sein, um zu versuchen zu öffnen-up und knacken jede Art von proprietären und geschlossenen Technologie zu zwingen die Industrie, auf geht nur mit interoperablen und offenen Ansatz bei der Gestaltung Telekommunikationsprotokollen.

Teilen

TETRA Hacking kommt: OsmocomTETRA

Es ist sehr spannend zu sehen, die Freisetzung von OsmocomTETRA die erste opensource SDR ( Software Defined Radio )-Implementierung von TETRA-Demodulator, PHY und MAC unteren Schichten.

Es ist das TETRA-Version von GSM AirProbe , die Zugriff auf die Daten und Rahmen von TETRA Kommunikationsprotokoll entsperren, wodurch große Hacking Gelegenheit!

Nun, da auch TETRA-Technologie eröffnet worden sollten wir erwarten, während dieser 2011 auf opensource TETRA-Sniffer sehen und wahrscheinlich auch TEA-Verschlüsselung (die Tetra Encryption Algorithm) geknackt!

TETRA ist von Polizei, Rettungsdienst und Militaries als Alternative mobiles Kommunikationsnetz, das auch ohne die Verfügbarkeit der Netzabdeckung (nur Handy-zu-Handy ohne Basisstation) funktioniert und bieten einige spezielle Dienstleistungen mit hoher Verfügbarkeit eingesetzt.

Ich schrieb über TETRA in my slide Wichtige Voice Security Protocol schreiben .

In OsmocomBB Mailinglisten gab es bereits Diskussionen über einige TETRA-Netz-Status:

  • Belgien Police TETRA ASTRID-Netz: unverschlüsselt
  • Deutsch Police Test TETRA-Netz in Aachen: unverschlüsselt
  • Einige Ex-jugoslawia TETRA-Netz: unverschlüsselt
  • Netherland C200 TETRA-Netz: TEA2 mit statischen Schlüsseln verschlüsselt
  • UK Airwave TETRA-Netz: TEA2 mit TEA2 verschlüsselt

Es wird wirklich Spaß, diese neue Polizei und Rettungsdienst Hacking auf dem Rückweg von alten analogen Zeiten auf die neuen digitalen Funkgeräte sehen :-)

Teilen

ESSOR, European Secure Software Defined Radio (SDR)

Ich hatte einen Blick auf European Defense Agency Website und fand die ESSOR Projekt, ein Projekt für Arbeit 106mln EUR, strategische Verteidigung Kommunikations-Produkte auf neuen Entwicklung finanziert Software Defined Radio Ansatz.

SDR Ansatz ist ein revolutionäres System, das völlig verändert ist der Weg, Wissenschaftler und Industrie ist Ansatz jede Art von Wireless-Technologie.

Grundsätzlich anstatt sie zu verbrennen Hardware-Chip, der die meisten der Radiofrequenz-Protokolle und Techniken zu implementieren, werden sie in "Software" zu spezialisierten Radio Hardware, auf eine Menge unterschiedlicher Frequenz arbeiten können geschoben, als Funkschnittstelle für eine Vielzahl von verschiedenen Radio-Protokolle.

Zum Beispiel die USRP (Universal Software Radio Peripheral) ab Ettus Forschung , dass die Kosten 1000 2000USD voll beladen, Trog der opensource gnuradio haben Rahmen, opensource Umsetzung gesehen:

Und vieles mehr Protokolle und Übertragungstechnologien.

Diese Art von neuer Ansatz zur Funkübertragungssystem destinated den Weg Funksystem ändern umgesetzt werden, so dass neue Fähigkeiten wie den "Radio-Protokoll selbst" in Software zu aktualisieren, um "Radio-Protokoll" Verbesserungen bieten.

In der kurzen Laufzeiten haben wir auch sehr stark Sicherheitsforschung gesehen mit SDR-Technologien wie der GSM Cracken und dem Bluetooth-Sniffing .

Wir können erwarten, dass andere Technologien, Schwachen durch Design, sondern geschützt durch die Beschränkung auf Hardware-Geräte, um die niedrigen Level-Protokolle zu hacken, wird bald gehackt werden. In der ersten Liste, ich würde wirklich gerne die Hacken von TETRA, eine Technologie, mit geschlossenen Denkweise und geheime Verschlüsselungsalgorithmen geboren, etwas, was ich wirklich nicht mag sehen ;-)

Teilen

Remote Abfangen snom VoIP-Telefone

Ich schlage vor, das Lesen der Ferne Antippen VoIP-Telefone "auf VoIP Security Alliance Blog von Shawn Merdinger .

Ein konkretes Beispiel dafür, wie aktuelle Telefonie-Infrastruktur werden immer anfälliger für Cyber-Angriffe.

Teilen

27C3 - CCC Congress CFP: Wir kommen in Frieden

Wir kommen in Frieden

189322778_8cb9af1365_m.jpg

Wir kommen in Frieden, sagte, dass die Eroberer der Neuen Welt.

Wir kommen in Frieden, sagt die Regierung, wenn es zu kolonisieren, zu regulieren und Militarisierung der neuen digitalen Welt kommt.

Wir kommen in Frieden, sagen die nationalstaatlichen Unternehmen, die sich um die Netto-Kette und den Benutzern, ihre glänzenden neuen Geräten zu monetarisieren eingestellt haben.

Wir kommen in Frieden, sagen wir, als Hacker, Geeks und Nerds, wenn wir uns vorgenommen in Richtung der realen Welt und versuchen, es zu ändern, weil es in unserer natürlichen Umgebung, dem Cyberspace eingedrungen ...

Call for Paper für die Teilnahme an 27C3 CCC Kongress ist offen, und ich sah nie eine so spannende Auszahlung :-)

Wir sehen uns am 30. Dezember 2010 in Berlin!

Teilen

GSM Knacken in Penetrationstests Methoden (OSSTMM)?

Da die meisten Leser dieses Blogs wissen bereits, in den vergangenen Jahren gab es eine Vielzahl von Aktivitäten im Zusammenhang mit der öffentlichen Forschung für GSM Wirtschaftsprüfungs-und Rissbildung.

Allerdings, wenn es den Medien viel Aufmerksamkeit auf GSM Rissbildung Forschungsergebnissen, um die Werkzeuge machen das Knacken war wirklich frühzeitig und immer noch sehr ineffizient.

Jetzt Frank Stevenson , norwegisch Kryptoanalytiker bereits brach das Content Scrambling System von DVD-Video-Disc, die Teilnahme an der A51 Cracken Projekt gestartet von Karsten Nohl , veröffentlicht Kraken , eine neue verbesserte Version der A51 Kracksystem.

Es ist interessant zu bemerken, dass WiFi Cracken hatte eine ähnliche Geschichte, wie die erste WiFi wep Cracken Entdeckung war ziemlich langsam in früheren Techniken aber später Korek, ein Hacker arbeitet an Rissbildung Code, die Verbesserung der System angreifen drammatically.

Das ist die Geschichte von Sicherheit Forschungskooperation Sie eine Suche zu starten, gehen Sie folgendermaßen jemand es und zu verbessern, einige andere folgen und verbesserte ihn und am Ende erhalten Sie das Ergebnis ein.

Lesen Sie mehr auf der Kraken GSM Cracking Software-Release .

Und bleiben Sie dran, wie nächste Woche bei Blackhat Conference Karsten Nohl erläutert die Details der erforderlichen Hardware-Setup und detaillierte Anweisungen, wie es zu tun :-)

Ich würde wirklich gerne, um diese Tools in eingearbeitet sehen Penetration Testing Linux Distribution BackTrack mit OSSTMM Methodik Durchsetzung des Tests für GSM-Abfangen und Mann in der Mitte :-)

Wenn die Dinge ausgehen, dass Weg und Ettus Forschung (Der Produzent USRP2 Software-Radio für kostengünstige GSM Signal Empfangen verwendet) nicht abgenommen werden, können wir immer noch sehen dies.

Teilen

Web2.0 Privatsphäre Leck in Mobile Apps

Sie wissen, dass web2.0 Welt ist es viel Leck jeglicher Art (Profiling, Profiling, Profiling) in Bezug auf Datenschutz und Nutzer ist beginnt ist besorgt darüber.

Benutzer kontinuierlich downloaden Anwendungen ohne Kenntnis der Details, was sie tun, zum Beispiel iFart nur weil es cool, sind Spaß und irgendwann nützlich sind.

Bei den Mobiltelefonen Benutzer installieren von 1000% bis zu 10.000% mehr Anwendungen als auf einem PC, und die apps können Malware enthalten oder andere unerwartete Funktionalitäten.

Kürzlich InfoByte analysiert UberTwitter Client und entdeckte, dass der Client war undicht und Senden, um ihre Server viele persönliche und sensible Daten wie:

- Blackberry PIN

- Telefonnummer

- E-Mail Adresse

- Positionierung Geographic Information

Lesen Sie mehr über UbertTwitter 'Spyware' Features Entdeckung hier durch InfoByte .

Es ist eine Vielzahl von Anwendungen undichte private und sensible Informationen, sondern nur niemand haben einen Blick auf sie.

Sollte obligatorische Vorratsspeicherung von Daten und Privatsphäre Politik wurde ein Teil der Entwicklung von Anwendungen und Einreichung Leitlinie für den mobilen Einsatz?

Imho ein Benutzer müssen nicht nur über die Einsatzmöglichkeiten und API-Nutzung gewarnt werden, sondern auch, was mit, welche Art von Informationen, es wird innerhalb der Handy umgehen zu tun.

Capabilities bedeutet Ermächtigung der Anwendung auf eine bestimmte Funktionalitäten nutzen, um beispielsweise Geolocation-API zu verwenden, aber was die Anwendung tun wird und wer diese Informationen, sobald der Benutzer haben es zugelassen bieten?

Das ist eine Sicherheit Profilebene dass Handy-Hersteller nicht zur Verfügung stellt und sie sollten, weil sie den Schwerpunkt auf die Information und nicht auf der Anwendung Zulassung / Genehmigung in Bezug auf die Nutzung von Gerätefunktionen.

ps ja! ok! Ich bin damit einverstanden! Diese Art von Post müsste 3-4 Seiten lange Diskussion, wie das Thema ist heiß und sehr gelenkig, aber es ist Samstag morgen und ich muss gehen!

Teilen

Blackberry Sicherheit und Verschlüsselung: Devil or Angel?

Blackberry haben gute und schlechte Ruf in Bezug auf seine Fähigkeit, Sicherheit, abhängig von welchem ​​Blickwinkel man es betrachtet.

Dieser Beitrag ist es eine von Informationen zusammengefassten eingestellt zu lassen, dem Leser die get-Bild, ohne viel eine Position als RIM Blackberry und betrachtet werden kann, je nach Standpunkt, eine extrem sichere Plattform oder einem extrem gefährlich.

bblock.jpg

Lassen Sie geht weiter.

Auf der einen Seite Blackberry ist es eine Plattform, viele Verschlüsselungs-Features, Sicherheits-Features überall Gerät verschlüsselt (mit benutzerdefinierten Krypto), Kommunikation verschlüsselt (mit benutzerdefinierten proprietäre Protokolle wie IPPP), sehr gute Erweiterte Sicherheitseinstellungen, Verschlüsselung Rahmen von Certicom ( jetzt im Besitz von RIM ).

Auf der anderen Seite sind sie nicht liefern nur ein Gerät, sondern eine Überlagerung Zugangsnetz, genannt BIS ( Blackberry Internet Service ), das ist ein global weltweit Wide Area Network, wo Ihre blackberry eingeben, solange Sie oder suchen Sie mit Hilfe checkmail blackberry.net AP ist.

Wenn Sie oder eine Anwendung, verwenden Sie den APN blackberry.net Sie nicht nur die Verbindung zum Internet mit dem Träger Internetanschluss, aber Sie sind in der RIM-Netzwerk Eingabe das wird Proxy und als Gateway zum Internet zu erreichen.

Genau das gleiche passiert, wenn Sie einen Einsatz in Firmen haben: Sowohl der BB-Vorrichtung und die Corporate BES auf die RIM-Netzwerk, die als eine Art vpn Konzentration Netzwerk .

Also im Grunde alle Kommunikation Quertrog RIM Service-Infrastruktur in verschlüsselter Form mit einem Satz proprietäre Verschlüsselung und Kommunikationsprotokolle.

Nur so als Hinweis, ich glaube, dass Google über gtalk blackberry.net APN, eine Vereinbarung getroffen, um den Service innerhalb des Netzes auf die BB BB Nutzer bieten bieten. Wenn Sie gtalk installieren Sie erhalten 3 hinzugefügt Service-Bücher , die auf GTALKNA01 dass der Name GTALK Gateway im RIM-Netzwerk, um intra-BIS Kommunikation und als GTALK Gateway zum Internet ist.

Die Mobilfunkbetreiber sind in der Regel nicht einmal erlaubt, den Datenverkehr zwischen dem BlackBerry-Gerät und dem Blackberry-Netzwerk zu inspizieren.

So RIM und Blackberry sind irgendwie einzigartig für ihren Ansatz, da sie eine Plattform, ein Netzwerk und einen Service alle gebündelt und bieten Ihnen nicht nur "bei dem Gerät und der Software", aber der Benutzer und die Unternehmenskultur sind immer gebunden und mit dem Service Netzwerk.

Das ist gut und das ist schlecht, weil es bedeutet, dass RIM sehr gute Sicherheits-Features und Fähigkeiten, um Informationen, Geräte und Zugang zu Informationen auf verschiedenen Ebene gegen Dritte zu schützen.

Aber es ist immer schwierig, die Bedrohungen und Risiken im Zusammenhang mit RIM selbst und wer könnte politischen Druck gegen RIM machen zu schätzen.

Bitte beachten Sie, dass ich nicht sagen: "RIM ist an Ihre Daten suchen", sondern eine objektive Risikoanalyse: Denn wie die Plattform RIM getan haben Autorität auf dem Gerät, auf dem Informationen on-the-Gerät und auf die Information, dass das Kreuz Netzwerk. (Lesen Sie mein Mobile Security Slides ).

Zum Beispiel betrachten wir die selben Kontext für Nokia-Handys.

Sobald das Nokia-Gerät verkauft wird, hat Nokia nicht befugt auf dem Gerät, noch auf die Informationen on-the-Gerät noch auf den Informationen, die das Netz zu überqueren. Aber es ist auch wahr, dass Nokia nur das Gerät und stellen nicht die durch Mehrwertdienste wie die Enterprise-Integration (Der RIM VPN-Tunnel), der BIS Zugangsnetz und alle lokalen und Remote-Sicherheit bereitgestellten Funktionen, die Blackberry bieten.

Also ist es eine Frage der Berücksichtigung des Risikos Rahmen in der richtigen Art und Weise bei der Wahl der Plattform, mit einem Beispiel sehr ähnlich zu der Auswahl Microsoft Exchange Server (auf eigene Service) oder ob sich eine SaaS-Dienst wie Google Apps.

In beiden Fällen müssen Sie die Anbieter vertrauen, aber in ersten Beispiel müssen Sie Microsoft vertrauen, dass nicht setzen eine Hintertür auf die Software, während in der 2. Beispiel Sie vertrauen Google, als Plattform und Dienstleister, das heißt nicht zugreifen müssen Ihre Informationen.

So ist es ein anderes Paradigma ausgewertet abhängig von Ihrem Modell Bedrohung werden.

Wenn Ihr Bedrohung Modell können Sie prüfen, RIM als vertrauenswürdige dritte Dienstleister (ähnlich wie google), als es ist ok. Wenn Sie ein sehr hohes Risiko Kontext haben, wie top-secret eins, dann laßt uns überlegen, und bewerten Sie sorgfältig, ob es nicht besser, die Blackberry-Dienste vollständig isoliert von dem Gerät zu halten oder verwenden Sie ein anderes System ohne Interaktion mit Hersteller Servern und Diensten.

Nun, lasst uns wieder einige Forschungs-und einige Fakten über blackberry blackberry und Sicherheit sich.

Vor allem mehrere Regierungen mussten mit RIM zu behandeln, um sie zu zwingen, den Zugang zu den Informationen, die ihre Service-Netzwerke zu überqueren, während andere beschlossen, direkt verbieten Blackberry-Nutzung für hohe Beamte, weil der Server in Großbritannien und den USA gelegen bieten, während andere beschlossen, installieren eigene Backdoors.

Es gibt eine Menge Diskussionen, wenn die Themen RIM Blackberry und Regierungen aus verschiedenen Gründen.

Unterhalb einer Reihe von offiziellen Sicherheitsrelevante Informationen über RIM BlackBerry-Plattform:

Und hier eine Reihe von inoffiziellen Sicherheit und Hacking Informationen auf RIM Blackberry-Plattform:

Because it's 23.32 (GMT+1), i am tired, i think that this post will end up here.

I hope to have provided the reader a set of useful information and consideration to go more in depth in analyzing and considering the overall blackberry security (in the good and in the bad, it always depends on your threat model!).

Prost

Fabio Pietrosanti (naif)

ps i am managing security technology development (voice encryption tech) on Blackberry platform, and i can tell you that from the development point of view it's absolutely better than Nokia in terms of compatibility and speed of development, but use only RIMOS 5.0+ !

Teilen

Celebrating “Hackers” after 25 years

A cult book , ever green since 25 years.

201007010924.jpg

It's been 25 years since “Hackers” was published. Author Steven Levy reflects on the book and the movement.

http://radar.oreilly.com/2010/06/hackers-at-25.html 
Steven Levy wrote a book in the mid-1980s that introduced the term "hacker" -- the positive connotation -- to a wide audience. In the ensuing 25 years, that word and its accompanying community have gone through tremendous change. The book itself became a mainstay in tech libraries.
O'Reilly recently released an updated 25th anniversary edition of "Hackers," so I checked in with Levy to discuss the book's development, its influence, and the role hackers continue to play.
Teilen

IOScat – a Port of Netcat to Cisco IOS

A porting of famous netcat to Cisco IOS router operating system: IOSCat

The only main limit is that it does not support UDP, but that's a very cool tool!

A very good txt to read is Netcat hacker Manual .

Teilen

Mobile Security talk at WHYMCA conference

I want to share some slides i used to talk about mobile security at whymca mobile conference in Milan.

Read here my slides on mobile security .

The slides provide a wide an in-depth overview of mobile security related matters, i should be doing some slidecast about it putting also audio. Maybe will do, maybe not, it depends on time that's always a insufficient resource.

Teilen

iPhone PIN: useless encryption

I recently switched one of my multiple mobile phones with which i go around to iPhone.

I am particularly concerned about data protection in case of theft and so started having a look around about the iPhone provided protection system.

There is an interesting set of iPhone Business Security Features that make me think that iPhone is moving in the right path for security protection of the phone, but still a lot of things has to be done, especially for serious Enterprise and Government users.

201006011551.jpg

For example it turned out that the iPhone PIN protection is useless and it can be broken just plugging the iPhone to a Linux machine and accessing the device like a USB stick.

That's something disturbing my paranoid mindset that make me think not to use sensitive data on my iPhone if i cannot protect my data.

Probably an iPhone independent disk encryption product would be very useful in order to let the market create protection schemas that fit the different risk contexts that different users may have.

Probably a general consumer is not worried about this PIN vulnerability but for me, working within highly confidential envirnonment such as intelligence, finance and military, it's something that i cannot accept.

I need strong disk encryption on my mobile phone.

I do strong voice encryption for it , but it would be really nice to have also something to protect the whole iPhone data and not just phone calls.

Teilen

Exploit code against SecurStar DriveCrypt published

It seems that the hacking community somehow like to target securstar products, maybe because hacking community doesn't like the often revealed unethical approach already previously described in this blog by articles and user's comments.

In 2004 a lot of accusation against Hafner of SecurStar went out because of alleged intellectual property theft regarding opensource codes such as Encryption 4 the masses and legal advert also against the Free and opensource TrueCrypt project .

In 2008 there was a pre-boot authentication hacking against DriveCrypt Plus posted on Full-Disclosure.

Early 2010 it was the time of the fake infosecurity research secretly sponsored by securstar at http://infosecurityguard.com (that now they tried to remove from the web because of embarrassing situation, but backup of the story are available, hacking community still wait for apologies) .

Now, mid 2010, following a research published in December 2009 about Disk Encryption software vulnerabilities made by Neil Kettle (mu-b), Security researcher at digit-labs and Penetration tester at Convergent Network Solutions , DriveCrypt was found to be vulnerable and exploitable breaking on-device security of the system and exploit code has been just released.

Exploit code reported below (thanks Neil for the code release!):

  • Arbitrary kernel code execution security exploit of DriveCrypt: drivecrypt-dcr.c
  • Arbitrary file reading/writing security exploit via unchecked user-definable parameters to ZxCreateFile/ReadFile/ WriteFile: drivecrypt-fopen.c

The exploit code has been tested against DriveCrypt 5.3, currently released DriveCrypt 5.4 is reported to be vulnerable too as it has just minor changes related to win7 compatibility. Can anyone make a double check and report a comment here?

Very good job Neil!

In the meantime the Free Truecrypt is probably the preferred choice for disk encryption, given the fact that it's difficult to trust DriveCrypt, PGP has been acquired by Symantec and there are very bad rumors about the trust that people have in Symantec and there are not many widely available alternatives.

Rumors say that also PhoneCrypt binaries are getting analyzed and the proprietary encryption system could reveal something fun…

Teilen

SecurStar GmbH Phonecrypt answers on the Infosecurityguard/Notrax case: absolutely unreasonable! :-)

UPDATE 20.04.2010: http://infosecurityguard.com has been disabled. Notrax identity became known to several guys in the voice security environments (cannot tell, but you can imagine, i was right!) and so our friends decided to trow away the website because of legal responsibility under UK and USA laws.

UPDATE: Nice summary of the whole story (i know, it's long and complicated to read at 1st time) on SIPVicious VoIP security blog by Sandro Gauci .

Following my discoveries, Mr. Hafner, SecurStar chief exec, tried to ultimately defend their actions, citing absolutely unreasonable excuses to The Reg instead of publicly apologizing for what they have done: creating a fake independent security research to promote their PhoneCrypt product .

He tried to convince us that the person behind IP 217.7.213.59, used by the author of infosecurityguard.com and pointing to their office DSL line, was this hacker Notrax, using their anonymous surfing service and not one of their employees at their office:

“SecurStar chief exec Wilfried Hafner denied any contact with Notrax. Notrax, he said, must have been using his firm's anonymous browsing service, SurfSolo, to produce the results reported by Pietrosanti”

Let's reflect a moment on this sentence… Would really an hacker looking for anonymity spend 64 EUR to buy their anonymity surfing service called surfsolo instead of using the free and much more secure TOR (the onion router) ?Then let's reflect on this other piece of information:

  • The IP 217.7.213.59 is SecurStar GmbH's office DSL line
  • On 217.7.213.59 they have installed their VoIP/Asterisk PBX and internet gateway
  • They promote their anonymous proxy service for “Anonymous p2p use” ( http://www.securstar.com/products_ssolo.php ). Who would let users do p2p from the office dsl line where they have installed their corporate VoIP PBX ? If you do VoIP you can't let third party flood your line w/ p2p traffic, your phone calls would became obviously unreliable (yes, yes, you can do QoS, but you would not place an anonymous navigation proxy on your company office DSL line…).
  • Which company providing an anonymous navigation service would ever use their own office IP address? Just think how many times you would have the police knocking at your door and your employees as the prime suspects. (In past i used to run a TOR node, i know the risks…). Also think how many times you would find yourself blacklisted on google as a spyware bot.
  • Mr. Hafner also says “We have two million people using this product. Or he may have been an old customer of ours”. 2M users on a DSL line, really?
  • I don't use Surfsolo service, however their proxies are probably these ones:

surfsolo.securstar.net – 67.225.141.74

surfsolo.securstar.com – 69.16.211.133

Frankly speaking I can easily understand that Mr. Hafner is going do whatever he can to protect his company from the scandal, but the “anonymous proxy” excuse is at the very least suspicious.

How does the fact that the “independent research” was semantically a product review of PhoneCrypt, along with the discovery that the author come from the SecurStar GmbH IP address offices, along with the anonymity of this Notrax guy (SecurStar calls him a “well known it security professional” in their press release..) sound to you?

It's possible that earth will get an attack from outer space that's going to destroy our life?

Statistically extremely difficult, but yes, possible. More or less like the “anonymous proxy” story told by Mr. Hafner to cover the fact that they are the ones behind the infosecurityguard.com fake “independent security review”.

Hey, I don't need anything else to convince myself or to let the smart person have his own thoughts on this.

I just think that the best way for SecurStar to get out of this mess would probably be to provide public excuses to the hacking community for abusing the name and reputation of real independent security researches, for the sake of a marketing stunt.

Grüße,

Fabio Pietrosanti

ps I am currently waiting for some other infos that will more precisely confirm that what Mr. Hafner is saying is not properly true. Bleiben Sie dran.

Teilen

Evidence that infosecurityguard.com/notrax is SecurStar GmbH Phonecrypt – A fake independent research on voice crypto

Below evidence that the security review made by an anonymous hacker on http://infosecurityguard.com is in facts a dishonest marketing plan by the SecurStar GmbH to promote their voice crypto product.

I already wrote about that voice crypto analysis that appeared to me very suspicious.

Now it's confirmed, it's a fake independent hacker security research by SecurStar GmbH, its just a marketing trick!

How do we know that Infosecurityguard.com, the fake independent security research, is a marketing trick from SecurStar GmbH?

1) I posted on http://infosecurityguard.com a comments to a post with a link to my blog to that article on israelian ministry of defense certification

2) The author of http://infosecurityguard.com went to approve the comment and read the link on my own blog https://infosecurity.ch

3) Greifen Blog zugespielt er die IP-Adresse, von der er kommt 217.7.213.59 wurde (wo ich gerade angeklickt von WordPress Statistik-Schnittstelle)

4) Unter http:// 217.7.213.59/panel gibt es die IP-PBX-Schnittstelle der SecurStar GmbH Corporate PBX (offen erreichbar Trog das Internet!)

5) Die Namen der internen PBX 100% bestätigen, dass es die SecurStar GmbH ist:

6) Es ist 100% Beweise dafür, dass der anonyme Hacker von http://infosecurityguard.com von SecurStar GmbH ist

Unterhalb der Angaben und Hinweise, die uns entdecken, dass es alles andere als ein unehrlicher Marketing-Tipps und keine unabhängige Sicherheitsforschung ist vermietet.

Kudos to Matteo Flora für seine Unterstützung und für seinen Artikel in Debunking Infosecurityguard Identität !

Die http Überweisung Tricks

Wenn Sie lesen einen Link gehen von einer Website zu einer anderen gibt es eine HTTP-Protokoll-Header, der "Referral", die Ihnen sagen, von welcher Seite sich jemand zu einer anderen Webseite gehen.

Die Verweisung gezeigt, dass die Autoren von http://infosecurityguard.com meine Post zu lesen, weil es von http://infosecurityguard.com/wp-admin/edit-comments.php kam, das ist die Webseite, die Sie verwenden, wie ein WordPress Autor / Editor zu genehmigen / ablehnen Kommentare. Und hier gab es den Link.

Das ist das Log-Eintrag:

217.7.213.59 - [30/Jan/2010: 02.56.37 -0700] "GET / 20100129/licensed-by-israel-ministry-of-defense-how-things-really-works / HTTP/1.0" 200 5795 "http://infosecurityguard.com/wp-admin/edit-comments.php" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3;. NET CLR 1.1.4322;. NET CLR 2.0.50727;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729; InfoPath.2) "

Die TK-Anlage über das Internet offen sagen uns, das ist SecurStar GmbH

Die SecurStar GmbH PBX ist offen im Internet, es enthält alle die Namen ihrer Mitarbeiter und bestätigen uns, dass der Autor http:/infosecurityguard.com dass Unternehmen und ist der anonyme Hacker namens Notrax.

Hier gibt es ihre Forenbeitrag wo die SecurStar GmbH Jungs Debuggen IPCOPfirewall & Asterisk zusammen (so sehen wir auch Details von dem, was sie verwenden), wo es die ip 217.7.213.59.

SecurStarproof.png

Das ist auch richtig Spaß!

Sie verkaufen sichere Telefonie aber ihre Unternehmen Telefonie-System ist offen anfällig im Internet. :-)

Ich dachte an den CEO, Hafner, via SIP Anruf auf seinem internen Desktop-PBX zu verkünden, entdeckten wir ihn Tricks .. : ->

Sie maßen ihre Marketing-Aktivitäten

Mit Blick auf die Protokolle von meiner Website habe ich festgestellt, dass sie wurde Erfassen der google Verteilung von Informationen für die folgenden Stichworte, um zu verstehen, wie effektiv sie in der Lage, konkurrierende Produkte anzugreifen. Es ist sinnvoll, wenn Sie Geld investieren in eine Marketing-Kampagne, die Sie wollen, um die Ergebnisse zu sehen :-)

Sie erreichten meinem Blog und ich angemeldet ihrer Suche:

infosecurityguard + CryptoPhone

infosecurityguard + Gold-lock

217.7.213.59 - [30/Jan/2010: 02.22.42 -0700] "GET / HTTP/1.0" 200 31057 "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3;. NET CLR 1.1.4322;. NET CLR 2.0.50727;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729; InfoPath.2) "

217.7.213.59 - [30/Jan/2010: 04.15.07 -0700] "GET HTTP/1.0 "200 15774 "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3;. NET CLR 1.1.4322;. NET CLR 2.0.50727;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729; InfoPath.2) "


Die Domain-Registrierung Daten
Die Domain hat am 1. Dezember 2009 registriert wurde, nur zwei Monaten zu Beginn der Vorbereitung die unehrliche Marketing-Kampagne:

Domain Name: INFOSECURITYGUARD.COM

Kanzler: GODADDY.COM, INC

Aktualisiert: 01-dec-2009

Creation Date: 01-dec-2009

Die Domain ist anonym Privatsphäre geschützt Trog ein whois Privatsphäre-Service:

Administrative Contact: Privat, Registrierung INFOSECURITYGUARD.COM @ domainsbyproxy.com, Domains by Proxy, Inc. DomainsByProxy.com

Notrax Hacker nicht auf google existieren
Wie Sie alle Hacker, die Öffentlichkeit zu bringen wissen, haben in der Regel Anwesenheit seiner Tätigkeit auf google, Teilnahme an Mailinglisten, Forum, Homepage, vorbei an Forschung, die Teilnahme an Konferenzen, etc, etc.
Die gefälschte Hacker, dass sie uns zu denken, wollte schrieb ein unabhängiges Blog hat noch keine Spur auf google. Nur einige Hit über einen anonymen Browser aufgerufen Notrax aber nichts über diese Hacker.
Vielleicht, wenn die Anonymität SecurStar Tool zur Verfügung gestellt, um ihre Marketing-Agentur, ihnen zu helfen, den Schutz der Anonymität für den gefälschten Forschung, wenn ihr ihnen die anonymen Browser notrax.So die Vermarktung Kerl Nachdenken über die Spitznamen diese gefälschte Hackern verwendet, was? Notrax! :-)

Die "unabhängige Bewertung" vollständig orientiert Bekanntmachung PhoneCrypt

Von den verschiedenen Rückblick, die PhoneCrypt Beurteilung ist nur positiv und erstaunlich gutes Feedback, während die andere nur schlechte Feedback und keine einzige gute Punkt sind.

Wie Sie sich vorstellen können, in jeder Art von unabhängigen Produkt-Evaluation, für alle Produkte gibt es Waren und schlechte Punkte. Nein, in diesem gibt es noch einzige Produkt, das Produkt gut sind und die schlecht sind.

Sie verpassten, um die Sicherheit der Technologie durch die verwendeten Produkte betrachten

Sie vollständig vermieden werden, um über Kryptographie und Sicherheit der Produkte zu sprechen.

Sie haben keine grundlegenden Sicherheitsfunktionen, die in dieser Art von products.That 's sein muss, um nicht zulassen, dass irgendjemand zu sehen, dass sie nicht grundlegende Sicherheitsregeln beim Aufbau ihrer PhoneCrypt gefolgt ausgewertet.
Die Technologie Quelle, keine Transparenz über Algorithmen und Protokolle geschlossen ist, review.Read kein Peer mein neuer Vergleich (von der grundlegenden kryptographischen Anforderung Sicht) Über die Stimme Verschlüsselung Analyse (Kriterien, Fehler und unterschiedliche Ergebnisse) .
Die Ergebnisse sind irgendwie anders als ihre ein.

UPDATE: Wer ist Wilfried Hafner (SecurStar Gründer)?

Ich bekam einen Hinweis von einem Leser über Wilfred Hafner, SecurStar Gründer, CEO und Security-Experte.

Er wurde im Jahr 1997 für Telefonie verbundenen Betrugs verhaftet (ggf. 2. Artikel auf Phrack) verdienen von Telefonie Betrug 254.000 USD verursacht Schäden an lokalen Telcos Trog blueboxing für 1,15 Mio. USD.

Er war nicht zu tun "Blueboxing" für das Vergnügen Phreaking und die Verbindung mit anderen Hackern, sondern um Geld zu verdienen.

Hacking for Profit (und nicht zum Spaß) im Jahr 1997 ... Brrr .... Kein Hacker-Ethik überhaupt!

Alles in allem, ist das erlaubt ist?

Übler Nachrede ein Konkurrent Mengen zu einem unfairen Wettbewerb der Praxis in den meisten Ländern, so ist es fraglich, (um es gelinde auszudrücken), dass SecurStar direkt an einem rechtlich einwandfreien Boden ist hier.
Darüber hinaus gibt es einige spezifische Satzung in bestimmten Jurisdiktionen, die für eine einfache Verbot der Praxis über die wir sprechen zu stellen. Zum Beispiel in der UK das British Institute of Practitioners in Advertising - im Einklang mit dem Schutz der Konsumenten vor unlauteren Handel Regulierung - entschieden, dass:

"Fälschlicherweise behauptet oder der Eindruck entsteht, dass der Händler nicht für die Zwecke seines Handels, Gewerbes, Handwerks oder freien Berufs, oder fälschliches als Verbraucher" ist eine Straftat .

Wir haben keinen Zweifel, dass PRPR (das ist die UK-basierte * PR-Firma für SecurStar GmbH, unter der Leitung von Peter Rennison und Allie Andrews als angegeben in SecurStar Pressemitteilung ) hat ihren Kunden diese Informationen zur Verfügung. Heck, sie * sind * in der UK, sie können einfach nicht ignorieren, dass!

IANAL, aber ich würde nicht überascht, wenn jemand Strafanzeige oder starten Zivilprozesse wegen unlauteren Wettbewerbs gegen SecurStar GmbH werden.
Ob das wird eine Angelegenheit für die strafrechtliche und / oder zivilrechtliche Courts oder nicht ist nicht so wichtig. Es ist jedoch klar genug, dass SecurStar GmbH muss mindestens ethisch fragwürdig und nicht wirklich wert des Vertrauens erscheint.

Netter Versuch, meine Herren ... aber, das nächste Mal tun Sie es einfach nach rechts (ob "rechts" für sie bedeutet "in einer ehrlichen Weise" oder "in einer Weise, nicht erwischt zu werden" Ich werde sie wählen?) "

Fabio Pietrosanti (naif)

Teilen

Dishonest Sicherheit: Die SecurStart GmbH PhoneCrypt Fall

Ich möchte Überlegungen über den Begriff der Ethik, dass ein Security-Unternehmen sollten in Bezug auf die Benutzer, die Medien und die sicherheitspolitische Umfeld aufweisen.

SecurStar GmbH sehr schlimme Dinge machen, dass infosecuriguard.com gefälschte unabhängige Forschung.

Es ist unfair Ansatz in Bezug auf Hacking-Community.

Es ist unfair Marketing bis zum Endverbraucher. Sie sollten nicht durch die Schaffung von gefälschten unabhängige Überprüfung werden austricksen.

Es ist unfair den Wettbewerb auf dem Markt für Sicherheitslösungen.

Lassen Sie uns etwas mehr über diese wichtige Überlegung.

Muss ernst auf kryptographische Produkte. Sie sind kein Spielzeug

When you do cryptographic tools you should be really aware of what you are doing, you must be really serious.

If you do bad crypto people could die.

If you don't follow basic security rules for transparency and security for cryptography you are putting people life at risk.

You are taking the responsibility of this. (I want to sleep at night, don't think SecurStar CEO/CTO care about this…)

Security research need reference and transparency

Security research have to be public, well done, always subject to public discussion and cooperation.
Security research should not be instrumentally used for marketing purpose.Security research should be done for awareness and grow of the knowledge of the worldwide security environment.

Hacking environment is neutral, should not be used instrumentally

Hackers are considered neutral, nerds, doing what they do for their pleasure and passion.

If you work in the security market you work with hackers.

If you use hackers and hacking environment for your own marketing purposes you are making something very nasty.

Hackers give you the technology and knowledge and you use them for your own commercial purpose.

Consideration on the authority of the information online

That's something that pose serious consideration on the authority of information online.An anonymous hacker, with no reference online, made a product security review that appear like an independent one. I have to say that the fake review was very well prepared, it always posed good/bad things in an indirect way. It did not appeared to me at 1st time like a fake. But going deeply i found what's going on.

However Journalists, news media and blogger went to the TRAP and reviewed their fake research. TheRegister, NetworkWorld and a lot of blogs reported it. Even if the author was completely anonymous.

What they have done is already illegal in UK

SecurStar GmbH is lucky that they are not in the UK, where doing this kind of things is illegal .

Fabio Pietrosanti (naif)

Teilen

Licensed by Israel Ministry of Defense? How things really works!

You should know that Israel is a country where if a company need to develop encryption product they must be authorized by the government.

The government don't want that companies doing cryptography can do anything bad to them and what they can do of good for the government, so they have to first be authorized.

Companies providing interception and encryptio n m ust apply to a license because Israel law on this is so restrictive to be similar to china law .

That's because those kind of technologies are considered fundamental for the intelligence and espionage capabilities of Israel country.

To give some example of “Licensed by Israel Ministry of Defense” companies:

GSM encryption products “Licensed by Israel Ministry of Defense” – Gold-lock

Interception of communication products “Licensed by Israel Ministry of Defense” – Verint

HF encrypted Radio “Licensed by Israel Ministry of Defense” – Kavit

Surveillance services and equipment “Licensed by Israel Ministry of Defense” – Multi Tier Solutions

For example how to apply for a “License by Israel Ministry of Defense” if you do encryption technologies in Israel?

Be sure to be an israeli company, click here and fill the forms.

Someone will contact you from encryption-control@mod.gov.il and will discuss with you whether to give you or not the license to sell.

What does the department of defense will require from an israeli company in order to provide them the authorization to make and sell interception and encryption products?

Well, what they want and what they really ask nobody knows.

It's a secret dealing of Israel Ministry of Defense with each “licensed” company.

What we know for sure is that Verint, a “Licensed by Israel Ministry of Defense”, placed a backdoor to intercept companies and governments in the US and Netherland into the interception systems they was selling.

Verint, a Licensed by Israel Ministry of Defense Company, provided to Israel government eavesdropped communications of private and government users in the United States and in the Netherland .

CIA officier reported that Israel Ministry of Defense was known to pay Verint a reimbursement of 50% of their costs in order to have from Verint espionage services trough their commercial activity on selling “backdoored” interception equipment to spy foreign users.

It can be a legitimate doubt that the cooperation within the Israeli Ministry of Defense may be problematic for an Israeli company that want to sell interception and encryption product abroad.

Those companies may be forced to make the interests of Israel Ministry of Defense and not the interests of the customers (like Verint scandal is a real-world example).

So, how would a “Licensed by Israel Ministry of Defense” be a good things to promote?

It represent the risk that the “Israel Ministry of Defense”, like is publicly known that it has already have done with Verint, will interfere with what the company do.

It represent the risk that the “Israel Ministry of Defense” may reasonably provide “reimbursement” of costs paying the company and get what they would likely would like to get.

So, what does really “Israel Ministry of Defense” want from Israel companies doing encryption and interception technologies?

Should we ask ourself whether Israeli companies doing encryption and interception businesses are more interested to do business or to do “outsourced espionage services” for their always paying customer, the “Israel Ministry of Defense”.

For sure, in the age of financial crisis, the Israel Ministry of Defense is a paying customer that does not have budget problem…

Strict control, strict rules, strong government strategic and military cooperation.

Seien Sie vorsichtig.

If you want to read more about this matters, about how technologies from certain countries is usually polluted with their governments military and secret services strategies stay tuned as i am preparing a post about this .

You will much better understand about that subjects on the “Licensed by Israel Ministry of Defense”.

Teilen

Recuva: Nice windows data recovery tool

Not a professional tool but an easy, quick and free one.

If you just accidently deleted some files on windows or your employee leave the company deleting all his data, well that you get out from trouble quickly.

It also came out in a 'portable' version to be loaded from an usb stick drive.

Check Recuva recovery tool

Teilen

Iphone jailbreaking crashing towers? FUD!

It's interesting to read a news about an anti-jailbreaking statement by apple that say that with jailbreaked phones it may be possible to crash mobile operator's towers:

By tinkering with this code, “a local or international hacker could potentially initiate commands (such as a denial of service attack) that could crash the tower software, rendering the tower entirely inoperable to process calls or transmit data,”

So fun, as the Baseband Processor interface of iPhone is precisely the same of Google android and all Windows Mobile powered devices:

Basically the operating system use AT commands (do you remember old hayes modem commands?) with additional parameters documented and standardized by 3GPP that let more deep (but not that much deep) interaction with the mobile networks.

Please note that those AT commands are standard and widely available on all phones and are the interface to the Baseband Processor .

On iPhone that's the list of commands that an from apple point of view could let “a international hacker to crash the tower software” :

Undocumented commands on iPhone

Damn, those European anarchist of Nokia are providing publicly also their AT command sets, and are AVAILABLE TO ANYONE:

Nokia AT Commands

Oh jesus! Also the terrorist oriented Microsoft corporation let third party to use AT commands:

Windows Mobile AT Commands

It's absolutely unacceptable that also RIM, canadian funky against USA, provide access to AT commands:

Blackberry AT commands

And it's unbelivable to see that Google Android also document how the system speak to the Baseband Processor and find on forums that it's ease to access it:

Google Android Basedband Processor

Not to speak to ALL other mobile manufactuer that use the very same approach and let any party to speak via AT commands to the baseband processor of the phone.

Is the baseband processor of iphone buggy and the AT&T tower software buggy so that it's dangerous to let the user make experiment with it?

Probably yes, and so those are only excuse because the software involved are not robust enough.

Apple, be careful, you have the trust of your users because you are apple you always have done things for the user advantages.

Users does like telephone companies that are huge lobbies that try to restrict and control users as much as possible.

If you, Apple, start behaving like a phone company users will not trust you anymore.

Be careful with FUD statements.

Teilen

Letter from a suicide hackers

The concept of freedom of an hacker, killing himself not to loose the most important value of his life.

Read there

Teilen

UAE government placing backdoors into Blackberry devices

Nice attempt to place backdoors inside Blackberry devices.

It seems that UAE government wanted to do something nasty placing backdoors trough software upgrades in Etilsat (local mobile operator) blackberry devices, obviously with the cooperation of the mobile operator itself.

Fortunately, the power of the security community discovered and unveiled the facts. Check it out.

Etisat patch designed for surveillance

Wired magazine: Blackberry spies

Security exists only with transparency.

Teilen

Mobile platform hacking: worms and botnet from phones?

The hacking community is finally starting seriously auditing and hacking Symbian OS, even if it's difficult, hard to work on, unpleasant to debug it .

Es gibt so viele mobile Betriebssysteme (Symbian OS, Nokia S40, Windows Mobile, RIM OS, Mac OS X, Android / Linux, Brew), dass ein Wurm / Virus in der Lage zu nutzen, eine Cross-Plattform-Schwachstelle ist es nur eine Theorie.

Trusted-Computing-Plattformen, Sicherheits-Modell von Java J2ME nur Handys (wie RIM und S40), digitale Signatur überall sind alle Werkzeuge, die massiven Hacker machen auf mobilen Plattform wirklich schwierig.

Es ist schwierig und kostspielig, auf mobilen Plattformen zu entwickeln, ist es schwierig und kostspielig zu tun, dass Hacker auf Plattformen.

Noch in einem sehr schönen Erfolg Papier aus schauen SEC Consult genannt Pwning Nokia-Handys (und andere Symbian-basierte Smartphones) .

Können wir erwarten, daß künftige Würmer oder Botnet auf Handy? Ich erwarte nicht so, zu viele verschiedene OS mit hart-zu-Schlag-Sicherheitsmodell.

Und selbst wenn ein Wurm der Lage wäre, ein einziges mobiles paltform Bugs eindringen, würden Mobilfunkbetreiber in der Lage, sehr schnell blockieren (vgl. wieviele GSM / UMTS-Operator existiert im Vergleich zu Internet Service Provider?).

Teilen

Hacker aus UK Office of Cyber ​​Security angeheuert

Es scheint, dass in Großbritannien das Management beleuchtet wurde, entdeckten sie, dass der effizienteste Weg, um einen Cyber-Krieg kämpfen, um Soldat zu mieten, dass auf dem Schlachtfeld Alltag spielen, nur für Leidenschaft.

UK Beschäftigt 'Naughty Boys' auf andere Hacker Kämpfen UK Beschäftigt 'Naughty Boys' auf andere Hacker Kämpfen

Teilen