September 2008


from malwarechallenge.info

Malware has become an ever-present danger in today’s computing world. Due to the constantly changing nature of malware, analysts cannot rely on the traditional means of protection, anti-virus software, to identify and protect their systems.

Analysts now need to be able to analyze malware that anti-virus software does not detect.

This is what the challenge is about.

The 2008 Malware Challenge is the first of what we hope to be an annual challenge where participants will be given a chance to analyze a piece of malware, use their skills to see what they can determine about the malware and win some prizes in the process

I heard about this on Security Justice Episode #5 (http://securityjustice.com/) sounds really interesting!

from XBMC Media Center //

Team-XBMC is proud to announce the first cross-platform Beta version of XBMC media center for Linux, Mac OS X Leopard and Tiger , Windows, and Xbox, in preparation for the upcoming stable release of XBMC, code NAMEd ‘Atlantis’. There are three important news items associated with this release:

1. The first item that is new in this release is the brand new skin “PM3.HD”, a high-definition tribute to Project Mayhem III, which will be gracing screens as the default skin on Linux, Mac OS X, and Windows. Xbox users can, of course, choose to use this skin if they wish as well, and the original Project Mayhem III skin is still packaged with Beta 1 for those who prefer the old-school look. This is in addition to the already awesome selection of skins available for XBMC.

2. The second item is the initial release of “XBMC Live“, a bootable CD which gives users the opportunity to try XBMC on their computer, without touching their harddrive. In addition, XBMC Live allows installation of XBMC, complete with an operating system, onto a USB flash memory sticks for a permanent, fast booting, dedicated set-top-box style installation of XBMC. XBMC Live is designed to support Microsoft’s MCE Remote and USB receiver out-of-the-box.

3. The third item is that the XBMC for Mac release now has initial support for integrating iTunes and iPhoto media into XBMC. For more information on this, please read this developers blog entry; “iTunes and iPhoto integration in XBMC“. The Mac release of Beta 1 also comes bundled with a bonus skin for XBMC, and that is MediaStream by Team Razorfish, this skin can, of course, be downloaded and installed on all XBMC platforms, like all other XBMC skins .

You should know that XBMC ‘Atlantis’ is still in a feature freeze, the final release of which is scheduled for October, and we really need your help in order to make ‘Atlantis’ as stable as possible. We encourage all users to download and use this Beta release in preference to using SVN or the Alpha builds, and test it thoroughly, reporting all bugs to our tracking system.

fromValleywag

Microsoft announcement tomorrow: No more Seinfeld ads!
Microsoft flacks are desperately dialing reporters to spin them about “phase two” of the ad campaign — a phase, due to be announced tomorrow, which will drop the aging comic altogether. Microsoft’s version of the story: Redmond had always planned to drop Seinfeld. The awkward reality: The ads only reminded us how out of touch with consumers Microsoft is — and that Bill Gates’s company has millions of dollars to waste on hiring a has-been funnyman to keep him company.

Ok, say what you will about the ads: Sure they were

  1. About nothing
  2. Weird
  3. Didn’t sell anything?

But what they did was create buzz.. There are only a HANDFUL of commercials that as I am forwarding through my DVR that I will stop and watch. Previously, only the Apple ads, however lately these new Microsoft Ads finally got this distinction as well.

What these ads did, was get people talking about Microsoft again, I mean think about it — for some reason it is **NEWS** that a company is now longer going to be making an AD. That means the ADs were WORKING.

Oh, for those who follow me on twitter, I do not LOVE VISTA. (But Mojave kicks ass)

from Wikileaks

Circa midnight Tuesday the 16th of September EST activists loosely affiliated with the group anonymous gained access to U.S. Republican Party Vice-presidential candidate Sarah Palin s Yahoo email account gov.palin@yahoo.com and passed information to Wikileaks. Governor Palin has come under criticism for using private email accounts to conduct government business and in the process avoid transparency laws. The zip archive made available by Wikileaks contains screen shots of Palin s inbox, two example emails, address book and a couple of family photos. The list of correspondence, together with the account NAME tends to re-enforce the criticism.

The list of emails include an exchange with Alaskan Lieutenant Governor Sean Parnell about his campaign for Congress.

Another screenshot shows Palin s inbox and an e-mail from Amy McCorkell, whom Palin appointed to the Governor s Advisory Board on Alcoholism and Drug Abuse in 2007.

The e-mail, a message of support to Palin, tells her not to let negative press get to her and asks Palin to pray for McCorkell, who writes that I need strength to 1. keep employment, 2. not have to choose.

According to Kim Zetter of Wired Magazine, McCorkell CONFIRMed that she did send the e-mail to Palin.

Following the release of this story, both Sarah Palin s better known account gov.sarah@yahoo.com and the gov.palin@yahoo.com account have been suspended or deleted as revealed by a test email sent to these addresses by Wikileaks. Although the reasons for the deletion of both accounts can not not yet be established, one interpretation is that Palin is trying to destroy her email records.

Wikileaks may release additional emails should they prove be of political substance.
Nb. The ctunnel.com reference in the browser screen shots is to a proxy service used to prevent the activists from being traced.

hmm.. dear evil hackers, please stay away from my yahoo account.

from digininja.org

Jasager is an implementation of Karma designed to run on OpenWrt on the Fon. It will probably run on most APs with Atheros wifi cards but it was designed with the Fon in mind as it is a nice small AP which gives it a lot of scope for use in pentration tests and other related fun.

A quick highlight of features:

  1. Web interface showing currently connected clients with their MAC address, IP address if assigned and the SSID they associated with
  2. The web interface allows control of all Karma features and can either run fully featured through AJAX enabled browsers or just as well through lynx
  3. Auto-run scripts on both association and IP assignment
  4. Full logging for later review
  5. Basic command line interface so you don t have to remember the different iwpriv commands

from PC Pro: News: & CCCKC

Asus is accidentally shipping software crackers and confidential documents on the recovery DVDs that come with its laptops.

The startling discovery was made by a PC Pro reader whose antivirus software was triggered by a key cracker for the WinRAR compression software, which was located on the recovery DVD for his Asus laptop.

He discovered a number of other suspicious files, including:

* A directory called “Crack” that appears to contain serial numbers for other software packages

* A directory containing a large number of confidential Microsoft documents for PC manufacturers, including associated keys and program files

* Various internal Asus documents and source code for Asus software

Also, apparently The MSI Wind linux version was shipping with some screeners on it. http://msiwind.net/linux-version-of-the-wind-delayed-by-ripped-movies/

from teknobites
Just in case you really must bring a vulnerable browser around with you =).

from news.cnet

The auto-suggest feature of Google’s new Chrome browser does more than just help users get where they are going. It will also give Google a wealth of information on what people are doing on the Internet besides searching.

Google Chrome Aww Snap
Unless you have been living in a hole, or simply just too busy argueing with your friends about Palin — you have probably heard that Google released a browser yesterday named ‘Chrome’. Apparently Chrome is an attempt to take on MicroSoft Internet Explorer, but what about their partner Firefox you might ask.. Hell I dont know, surely there is some hurt feelings somewhere.

Anyway, as expected with any new software; Chrome has a lot of bugs.. And I am not using it.

Google Chrome vulnerable to carpet-bombing flaw
http://blogs.zdnet.com/security/?p=1843

Google Chrome Browser URL Handler Crash
http://www.securiteam.com/securitynews/5TP010UPFU.html

DoS vulnerability hits Google’s Chrome, crashes with all tabs
http://blogs.zdnet.com/security/?p=1847

Ars has a great run-through of chrome if you just want a tour!

bye chrome