Monday, July 21, 2008

Here be dragons


If you haven't seen this yet have a look. Yes the brilliant webcomic xkcd sometime ago did a Map of the internet, I used to have this posted on my wall at work so the newer employees could come have a look when they were visiting to ask a question, it really shows how immense it all is.
But then while looking at one of my bookmarks on network security using darknets for a post on an internet forum I found this: a map of malisciousness. Awesome. It really is interesting to see the concentrations of either compromised machines or general evil-doers in the world. The thing that gets me and got me when I first looked at it was why is the 10.0.0.0 range have so many hits, its a private range, then I looked closer. Why are a few of the "bogan" address ranges getting hits. The only thing I can think is IP spoofing, and if so who would spoof a 10 address. Why not spoof 1.3.3.7 (fun) or something else, everyone knows 10 is internal... anyway post your thoughts.
Oh yeah we haven't quite won the DNS thing yet either. The multi-vendor patch was just that a patch, there are still inherent flaws in the system. Like the new one disclosed with DNS that passes through NAT (see most DNS servers as NAT means some decent IP sharing) it is annoying but it is a fight we have to keep on. See here for the article. It is basically NAT routers being lazy and not letting the port be the random one that the DNS server wants it to be. This randomness doesn't make DNS invulnerable to the poisoning attack I mentioned earlier, it just makes it much, much harder. So to have some routers (people like netgear don't release patches after it is 5+ years old) destory the hard work must be really annoying.
Yep I am dedicating this blog now to more security related topics like the one above. I am still going to keep an update on the kids and all things family. Like little Anne who all of sudden decided she didn't want to be immobile and is not only started crawling in the last few weeks but also pulling herself up to stand and also taking little steps (as long as her hand is held, or holding on to something). She has even said Mama, and what sounded like more after she stole a biscuit from me.
Geoffrey is really coming along too, he is saying Daddy and Mommy more and more, and when annoyed Morgan and Fiona come out too.
Peace out all, except those to Lazy to fix their NAT code.

Sunday, July 13, 2008

DNS vulnerabilites and Sydney IT Security Group


101 posts, yay.


Not really as I imported all those journal entries from 2003 and before, so it is more.
On family news, Anne is trying to walk, and Geoffrey is in potty training. She is only 9 months old, and only crawls when on carpet but she is stubborn. She sees Geoffrey walk and wants to run after him, she pulls herself up onto the coffee table or kiddie couch and looks around, heck she even tries to stand on the spot; which just means she ends up with her bum in the air, her legs straight and her hands stretched down to the ground to steady herself.
I have been going at my new job now for a few weeks and am starting to get the hang of some things. It is a little odd though with all of the people in my team being in a different state than me, and having met none of them other than my boss Jamie, who came up my first week to train me.
I am getting to know the guys in the different groups around me, from technical services, and Infrastructure. We play table tennis on Fridays and I am not the worst one here...YAY.
This is why we run Linux at home: (even Billy G has issues with Windows) , you want to install something, no need to run a web browser to find all the bits you need. Then hunt, hunt, fill out a form telling them your name, date of birth and pant size. Just either apt-get install "program name" and it gets all the stuff it needs. Or run synaptic.
*Now onto security.
As you may or may not have heard there was a big update released for basically the whole internet. See here and here for a test of your own dns.
Basically it boils down to a bad guy being able to put incorrect entries into your ISP or works DNS cache that would point you to the wrong site. So instead of going to google.com it could take you to a hackers version, or whatever. This would also effect email.
Now this kind of thing does happen occasionally, but this was seen as such a big issue (it could basically destroy the internet if unchecked and unpatched), that CERT who handles these issues let all the Vendors and developers know. Giving them time to write a patch for release on the same day. Very, very impressive.
Not only Microsoft but Unix, Linux, BSD , Cisco, Checkpoint, all of them released a patch for their varied DNS implementations. Yahoo who uses an older *nix implementation of DNS, Bind8 managed to simply comit to abandoning it in favour of the newer patched Bind9.
The question I put forward, is this finally a time of security as an institution. Security how it should be done, globablly. Sure it is still relying on Admins at the other end, but with Auto updates being the norm, it should be fine. This to me seems a step in the right direction, and I am sure even a couple years ago this wouldn't have happened. Will this one day lead us to a security utopia free of vulnerabilites and insecurites, no. But it may lead to sharing and assistance cross platform.
Speaking of security, there is talk of an IT Security group being started up in Sydney, and I maybe taking the reigns. It will be sponsored by Microsoft but if I take the reigns I plan on being vendor neutral, all-be-it Microsoft has some nice claims to fame, and even with all their foibles and hatred that is flung at them, they do try and do some stuff right. Operating systems are tools, you should use the right tool for the right job.
Peace out all, specially those lovely CERT engineers.

Sunday, June 22, 2008

The times they are a changing.


I have decided to remove the old standard picture up the top to make the blog more central. It has been there since I had my website on geocities in 97, so it is over 10 years now.
Other changes have happened. I got a new job and have started: Internal to a company as a Security specialist. I started Wednesday. So far it has been a very good experience, almost everything I have seen has been setup in a way that I would do, which is a good sign. Even have a table tennis table and I am not the worse player in the IT team.
In other news Marion bought us a yearly Zoo pass so Geoffrey, Anne, Fiona and myself have gone to the Zoo a couple of times now, check my flickr for some of the photos. Another photo you will spot there is our care hitting 666km.. heheh. It has gone well beyond that ominous number now, and even had it's first service.
Today we had a nice morning tea with Anthea and Michael, and Geoffrey was sad to see them go. Geoffrey has started drawing and painting, he has chalk and loves chalking the coffee table, so I am looking over at our chalked table... He is cute, he has started playing mummy and daddy against each other too, when one of us says no, he looks at the other for input.
Well I guess that is enough of my inane ramblings.
Peace out all.

Thursday, May 22, 2008

Happy birthday to me


So my birthday has been and gone, probably not the best in memory, but it happens. I did however get a new job, in dedicated security, which is awesome. We also got our new car, a Hyundai Elantra.
Anne is now crawling, and Geoffrey is talking more and more when he feels like it, saying things like thankyou, and apple, best yet has been trying to say helicopter he said applecopter.
My site is now hosted externally and backed up to my servers at home, as our power bill and the heat in (even though it is winter) in the server room was ridiculous. When I have time and more money, I will get the site back locally, but the superb performance of Google apps has really turned me towards outsourcing the hosting of our stuff, it is not like there is any data in our email or websites that is confidential.
I even found an add-on for firefox that allows me to use GPG through my google apps, so that is soon to be setup with my old morganstorey.com key.
Scary change in the world of security, see here. The good ole US of A, has decided to pass legislation that all devices that can store data coming into the USA can be copied in its entirety to their storage. This data can be kept indefinitely. I am sure this will mean that it will be indexed, anything encrypted will be brute forced and broken, and hey some senator may make a fortune when he sells it on to marketers, spammers, and the like.
The general consensus is to backup, delete then wipe your drive of pretty much any personal data or corporate data, something like eraser works well here, then simply fetch the data over some kind of VPN or secure connection from your server when you need it. People have even gone to lengths of removing their "home" hard drive, and plugging in their "traveling to the Draconian states of America" drive.
Sure their could be some terrorist smuggling in data on how to build a bomb... there could be but couldn't he/she just surf the net and find 70billion ways to do this when he gets into the country.
I can see how this is going to increase the need for teleconferencing, and reduce people's desire to take business trips to the USA. It is already happening with some companies moving their head office's elsewhere in the world.
Well Peace out all, especially the American's they need it the most.

Monday, April 28, 2008

Happy birthday Anthea


Sorry for not calling I have been flat out with work, then home to more work... lovely, but it pays the bills I'll call tomorrow I promise.
In other news Anne has started holding onto stuff and sorta standing for a second before Mummy catches her, gonna post a picture to my flickr now. Oh yeah I got flickr and youtube , and facebook . Yay I am (cringe) web 2.0.
Well I am beyond exhausted now, I had 5 hours sleep last night and have been working since 8am, so I am off to bed.
Peace out all.
eXTReMe Tracker