FreeNAS: Open Source Network Attached Storage (NAS)

FreeNAS is an embedded open source NAS (Network-Attached Storage) distribution based on FreeBSD, supporting the following protocols: CIFS (samba), FTP, NFS, TFTP, AFP, RSYNC, Unison, iSCSI (initiator and target) and UPnP.  FreeNAS supports additional services such as a Bittorent client, UPnP server, iTunes/DAAP server, and network bandwitdh measurement.  Take a look at the complete featurelist on the official website.

 FreeNAS logo

http://www.freenas.org/

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

(IN)SECURE Magazine Issue 24 released

Covered topics:

* Writing a secure SOAP client with PHP: Field report from a real-world project
* How virtualized browsing shields against web-based attacks
* Review: 1Password 3
* Preparing a strategy for application vulnerability detection
* Threats 2.0: A glimpse into the near future
* Preventing malicious documents from compromising Windows machines
* Balancing productivity and security in a mixed environment
* AES and 3DES comparison analysis
* OSSEC: An introduction to open source log and event management
* Secure and differentiated access in enterprise wireless networks


Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Windows utility: Disable wireless when connected via ethernet

Free Windows utility that automatically disaplyes your wireless network interface when your computer is connected via a cable network connection:

http://www.wlanbook.com/disable-wireless-connected-lan-xp-vista/

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Hack In The Box (HITB) Ezine is launched

Message from hackinthebox.org:

Welcome to 2010! We are proud to announce the immediate availability of our newly ‘reborn’ HITB ezine! You can grab your digital copies here:

https://www.hackinthebox.org/misc/HITB-Ezine-Issue-001.pdf

As some of you may know, we’ve previously had an ezine that used to be published monthly, however the birth of the HITBSecConf conference series has kept us too busy to continue working on it. Until now that is…

As with our conference series, the main purpose of this new format ezine is to provide security researchers a technical outlet for them to share their knowledge with the security community. We want these researchers to gain further recognition for their hard work and we have no doubt the security community will find the material beneficial to them.

We have decided to make the ezine available for free in the continued spirit of HITB in “Keeping Knowledge Free”. In addition to the freely available PDF downloads, combined editions of the magazine will be printed in limited quantities for distribution at the various HITBSecConf’s around the world – Dubai, Amsterdam and Malaysia. We aim to only print somewhere between 100 or 200 copies (maybe less) per conference so be sure to grab a copy when they come out!

Happy New Year once again and we hope you enjoy the zine!

Zarul Shahrin – zarulshahrin@hackinthebox.org
Editor, HITB Ezine

http://www.hitb.org

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

BackTrack 4 Final Download

The final version of BackTrack 4 was released yesterday. It is available for download here from torrent or direct download links.

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Ernst & Young’s 2009 Global Information Security Survey

The Ernst & Young global information security survey takes a closer look at how organisations are specifically addressing the changing environment, including the risks, challenges, increasing regulatory requirements and new technologies. The survey identifies and examines potential opportunities for improvement and important short-term and long-term trends that will shape information security in the coming years.

Ernst & Young’s 2009 Global Information Security Survey Download

Official Press Release: Brand protection a major force driving Information Security

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

OpenNebula: Open Source Virtualisation

OpenNebula is an open and flexible tool that fits into existing data center environments to build any type of Cloud deployment. OpenNebula can be primarily used as a virtualization tool to manage your virtual infrastructure in the data-center or cluster, which is usually referred as Private Cloud. OpenNebula supports Hybrid Cloud to combine local infrastructure with public cloud-based infrastructure, enabling highly scalable hosting environments. OpenNebula also supports Public Clouds by providing Cloud interfaces to expose its functionality for virtual machine, storage and network management.

http://www.opennebula.org/

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

OWASP Top 10 2010

The Open Web Application Security Project (OWASP) released a new top 10 list at its conference in Washington, D.C.

A1 –Injection

A2 –Cross Site Scripting (XSS)

A3 –Broken Authentication and Session Management

A4 –Insecure Direct Object References

A5 –Cross Site Request Forgery (CSRF)

A6 –Security Misconfiguration(NEW)

A7 –Failure to Restrict URL Access

A8 –UnvalidatedRedirects and Forwards (NEW)

A9 –Insecure Cryptographic Storage

A10 -Insufficient Transport Layer Protection

Two new items appeared in the list, that were not in the Top 10 2007 list: Security Misconfiguration, and UnvalidatedRedirects and Forwards.  The two items that dropped out of the list are Malicious File Execution and Information Leakage and Improper Error Handling.

The list, currently in Release Candidate stage can be downloaded from the OWASP website here.

UPDATE: The final version of the OWASP Top 10 2010 has been released.

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

iPhone Warez

It seems like the warez scene for iphone apps is finally kicking off (or I must have missed it completely when it happened in the past).  PPCWarez, previously known for distributing cracked applications & games for the Windows Mobile platform, have opened a section for iPhone applications.  It seems to be pretty straightforward too to install these applications on a jailbroken iphone:

  • Open Cydia, and add the source http://cydia.hackulo.us
  • Also via Cydia, Install the AppSync application and reboot your iphone
  • Drag your downloaded iphone application into your iTunes Library
  • Sync your iphone via iTunes

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

(IN)SECURE Magazine 22 released

Topics covered in this issue:

- Using real-time events to drive your network scans
- Review: Data Locker
- The Nmap project: Open source with style
- Enterprise effectiveness of digital certificates: Are they ready for prime-time?
- A look at geolocation, URL shortening and top Twitter threats
- How “fake stuff” can make you more secure
- Making clouds secure
- Q&A: Dr. Herbert Thompson on security ROI and RSA Conference
- Book review – Cyber Crime Fighters: Tales from the Trenches
- Top 5 myths about wireless protection
- Securing the foundation of IT systems
- A layered approach to making your Web application a safer environment
- In mashups we trust?
- Adopting the security best practice of least privilege
- Is your data recovery provider a data security problem?
- New strategies for establishing a comprehensive lifetime data protection program
- Security for multi-enterprise applications
- EU data breach notification proposals: How will your business be affected?
- Book review – 97 Things Every Software Architect Should Know
- Safety in the cloud: How CIOs can ensure the safety of their data as they migrate to cloud applications
- Vulnerability management

http://www.net-security.org/insecuremag.php

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Bypassing the Windows 7 activation

A method to bypass the Windows 7 online activation scheme has been found, approximately 3 months before the official Windows 7 release took place. My Digital Life published an article how the Windows 7 activation scheme was bypassed.   With this method Windows 7 can be permanently activated online and will pass Windows Genuine Advantage (WGA) validation.

SLP (System-Locked Pre-installation) and SLIC (Software Licensing Internal Code) are the mechanisms used by OEM computer manufacturers to factory activate pre-installed Windows operating system on computers so that activation process of Windows is done automatically once a user boots his new computer for the first time. From a leaked Windows 7 .ISO the boot.wim file was extracted to retreive the OEM SLP key, plus the OEM activation certificate. Using a loader, a SLIC that results in a valid validation can be emulated before Windows boots.

At this time different Windows 7 activators are already spreading the Internet for Windows 7 Ultimate, the only Windows 7 version that was leaked until current.

Windows 7 was released to manufacturing on 22nd of July 2009.  The official Windows 7 release date for the retail market is the 22nd of October 2009.

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

(IN)SECURE Magazine Issue 21 released

Table of contents:

* Malicious PDF: Get owned without opening
* Review: IronKey Personal
* Windows 7 security features: Building on Vista
* Using Wireshark to capture and analyze wireless traffic
* “Unclonable” RFID – a technical overview
* Secure development principles
* Q&A: Ron Gula on Nessus and Tenable Network Security
* Establish your social media presence with security in mind
* A historical perspective on the cybersecurity dilemma
* A risk-based, cost effective approach to holistic security
* AND MORE!

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

PayPal Horror Stories

Still in my fraud awareness mood, I was reading an article stating that the Dutch website Marktplaats.nl where you can buy and sell goods will start accepting paypall payments soon.

When reading the comments of users on the article, I was astonished by the amount of Dutch people that were frauded by selling items and accepting PayPal payments. The typical PayPal fraud scenario would like like this:

  • A buyer (the counterfeiter) buys goods using PayPal
  • The seller receives the money for the goods and sends the object the buyer bought
  • The buyer lodges a claim to PayPal for a non-authorised payment that took place with his PayPal account
  • PayPal transfers the money back from the buyer to the seller’s account without requiring consent of the buyer
  • The buyer received the goods and didn’t pay for it
  • The seller’s PayPal account is frozen; he lodges a claim against the buyer
  • PayPal rejects the claim if the seller cannot provide all the receipts of sending the goods
  • The buyer is frauded and cannot lodge another claim since PayPal only allows 1 claim per transaction.

I know when buying/selling goods online, making payments via website such as MoneyGram and Western Union is a no go, but these PayPal stories were new to me.

Read out the story on this page of the poor man who’s business went bankrupt by PayPay fraudsters.

3 statements listed on paypalwarning.com to remind users of the control you give to PayPal when using the service:

  • Can PayPal hold my money with no explanation?  The answer is YES.
  • Can PayPal freeze my account for no reason?  The answer is YES.
  • Can PayPal take money out of my account without my knowledge? The answer is YES.

Personally I do have a Paypal account as well.  I used it only once in the past, but as of now, i’ll think twice before I will commit into another PayPal transaction.

Check out other horror stories at:

http://www.aboutpaypal.org/
http://www.paypalwarning.com/

http://www.paypalsucks.com/

http://www.screw-paypal.com/

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Gumtree.com.au Fraud Scams

The last 2 months I have been looking around on the Internet to buy a car over here in Australia. I am amased by the amount of active fraud scammers trying to trick people into transferring money to them.In most cases they come up with a story that they have a car for sale, but they are currently staying overseas at the time, so meeting in person is not possible. They offer a ‘almost new’ car, low kilometers, lots of extra’s for a bargain price. The only drawback is obviously that you have to transfer them your money first before they will ship the car to you.

Here’s all the scam emails I received when responding to cars advertised on the gumtree.com.au website:

Re: Reply to your “2006 TOYOTA COROLLA HATCHBACK” Ad on Gumtree

from Emilio Narsete <emilio.narsete13@rocketmail.com>

Hello ,
Thank you for your enquiry regarding my vehicle.
The vehicle is in perfect working condition i’m the only owner and it has 2009 Rego so you will have no problem registering and licensing the vehicle.
I’ve worked in Australia for the past 3 years and since the birth of my son in January 2009 i came home to Italy.
The vehicle is in Australia at DAS freight department and i have full access(i can deliver the vehicle anywhere in Australia).
I will arrange delivery on my cost to your home address and you will have a 5 days period for inspection.
The total price includes (stamp duty, registration, transfer fee, and insurance).
We can use an escrow agreement to facilitate payment so that we both can be 100 % protected.
I will also supply some more pictures as soon as i get home from work.
If you are interested,please reply with the following information’s in order to arrange shipping at DAS freight department:
-Your full name ;
-Full delivery address(with postal code);
Regards ,


RE: Reply to your “TOYOTA RAV4 2003″ Ad on Gumtree

from tommy dreamer <tommydreamer1@live.co.uk>

Hello,
Sorry for the delayed response, but I’m in Cameroon right now
and I have been very busy.Anyway,thank you for your interest in buying
the car. The car is located in Cameroon right now and has Australian/Cameroon papers.It’s been a great car for my wife to drive but we now need something a little bigger seeing as how she is pregnant.So all that I want to do now is to sell
the car at this price, because I need to sell it fast(I already made a
deposit here to buy another one).The title is clean and you will have
absolutely no problems to register the car in the States.I will tell
you a few words about the car..
my TOYOTA RAV4 2003″ car with  manual transmission it is in immaculate
condition with approximately 56,500 miles on it,rust free , no scratch and hasn’t been
involved in any accident. The motor runs very well.The interior looks
great(NO SMOKING).This car needs nothing,the title is clear ,it is not
a salvage one. I want this transaction to go smoothly enough as I am
caught in the middle of some very important events and have little
time at my disposal. I already have tons of emails so I hope you
understand that I need to sort them out. The car is like new, in
perfect conditions,accident free, no scratches, no special marks, no
need for additional repairs what so ever. a genuine road runner ready
to be yours, but only if you shall understand and you won’t make me
loose time as it has already happened to me.

The price is $3,500 THIS IS MY LAST PRICE.I will not negotiate
the price.I will take in consideration only those buyers who are
really interested in buying the car ,to be sure that I don’t waste my
time with endless discussions.This way,I shall be assured of the
serious intentions .
So if you are interested please email me back for next step.
Regards !! call me on

Hi again,
Look how we will do this step:

Before leaving I had prearranged shipping and also the payment with MoneyBookers. so my presence in Cameroon isn’t necessary(The car is locked in a MoneyBookers warehouse Cameroon ready for delivery).The  price of car $3,500 includes all the shipping costs and insurance, so you won’t have to pay any extra charges.
Here is what I suggest: we will use MoneyBookers which acts like an escrow service , you make a deposit of 1/4 the price of the car in a MoneyBookers managed trust fund ( they hold the money until you receive the car ), I send the car over( the car will be delivered with the title, owner’s manual, 2 sets of keys, service records, and of course the bill of sale authorised and signed by me),I will offer a 14 day period from the day you receive it from the shipping company,you can inspect it, take it to a mechanic to check it out, drive it and then if you decided to keep it, you’ll confirm to MoneyBookers the sale so that they can start paying me and then you send me the remaining money. If, by any reason, you will not be satisfied with it ( even though I can assure you that it is exactly as described), you can return it at my expense for a full refund of your money, no questions asked.I think this is more than fair for the both of us.
NOTE: The deposit (down payment) is refundable, and is just a security measure, to make sure that you are serious, and that I am not going to ship the car, and loose time and money.

So if you are interested to go ahead with the deal, please reply with your full name and shipping address so I can ask MoneyBookers to open a case! After, they will contact you explaining all the details regarding the payment..
I’m looking forward to hear from you.

Thank you,
tommy

RE: 2005 MAZDA 3 SP23 48200 km

from Vanessa Cubriel <vanessa.cubriel@googlemail.com>

Hello,
First of all I want to thank you for your interest for my car. I sell at this price(AU$5,000.00) because i just finished the divorce with my husband. When the divorce has finished i own this car. Now as a women i don’t need. This car is in excellent working conditions, no scratches, flaws or any kind of damage, slightly used in 100% working and looking conditions and comes with a clear title, 3 months transferable warranty. From the beginning you have to know that for the payment I request ONLY secure pay, I prefer the payment to be done using eBay services. We will use a safe payment method because I am affiliated at eBay and I have a purchase protection account for $20.000.00Au. The final price that I want for this car is AU$5,000.00 including shipping and handling.
PS If you are interested in buying it please provide me your full name and address so I can initiate the deal through eBay.
I will wait your answer(if you are interested to buy) very soon!!
Thank you and have a nice day

Vehicle Features*

  1. 17In Alloy Wheels
  2. 6 Speaker Stereo

I replied to every of those scammers that I reported them to the police.  Interestingly enough, at a later stage when I showed my interest in another car advertised, I get a reply from exactly the same email address! The fact that they don’t even recognise my name means they are trying to perform this kind of fraud on massive scales!

If you have a similar experience, you can find all info you need for reporting these kinds of scams in Australia on the following page: http://www.scamwatch.gov.au/content/index.phtml/tag/reportascam#h2_160

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print

Software Assurance Maturity Model (SAMM)

The Software Assurance Maturity Model (SAMM) is an open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization. The resources provided by SAMM will aid in:

Evaluating an organization’s existing
software security practices

Building a balanced software security program
in well-defined iterations

Demonstrating concrete improvements
to a security assurance program

Defining and measuring security-related activities
within an organization

SAMM was defined with flexibility in mind such that it can be utilized by small, medium, and large organizations using any style of development. Additionally, this model can be applied organization-wide, for a single line-of-business, or even for an individual project.

As an open project, SAMM content shall always remain vendor-neutral and freely available for all to use.

http://www.opensamm.org/

Bookmark or share this message
  • Facebook
  • LinkedIn
  • Digg
  • del.icio.us
  • Live
  • TwitThis
  • Google Bookmarks
  • email
  • Print