<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>©атсн²² (in)sесuяitу &#187; Technology</title>
	<atom:link href="http://blog.c22.cc/category/technology/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.c22.cc</link>
	<description>Because we&#039;re damned if we do, and we&#039;re damned if we don&#039;t!</description>
	<lastBuildDate>Thu, 11 Mar 2010 14:31:33 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='blog.c22.cc' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/1b6c05a022094e3a7342e6b645c9cfce?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>©атсн²² (in)sесuяitу &#187; Technology</title>
		<link>http://blog.c22.cc</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.c22.cc/osd.xml" title="©атсн²² (in)sесuяitу" />
	<atom:link rel='hub' href='http://blog.c22.cc/?pushpress=hub'/>
		<item>
		<title>Playing with iPhone profiles</title>
		<link>http://blog.c22.cc/2009/12/04/playing-with-iphone-profiles/</link>
		<comments>http://blog.c22.cc/2009/12/04/playing-with-iphone-profiles/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 12:47:18 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[APN]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone configuration tool]]></category>
		<category><![CDATA[passcode]]></category>
		<category><![CDATA[profiles]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1096</guid>
		<description><![CDATA[It&#8217;s not often that I talk about a GOOD feature of the iPhone. Don&#8217;t get me wrong, I love my iPhone and it&#8217;s really changed the way I work and communicate, however Apple really only want you to use the device they want, not how you want. Still, I&#8217;ve recently been fighting with a few [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1096&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s not often that I talk about a<strong> GOOD</strong> feature of the iPhone. Don&#8217;t get me wrong, I love my iPhone and it&#8217;s really changed the way I work and communicate, however Apple really only want you to use the device they want, not how you want. Still, I&#8217;ve recently been fighting with a few issues while traveling. The largest of these is the need to constantly change my APN settings whenever I fly somewhere. I usually travel with a small collection of pay as you go sim cards so that I can just touchdown, plug in the sim and charge enough credit to cover a few days, weeks of data transfer. You&#8217;d be surprised at the prices you can find even on pay as you go nowadays. Anyway, this is all well and good, but wouldn&#8217;t it be nice if the APN settings (APN name, username and password) was automatically detected. Some sim cards do this, however most don&#8217;t <em>(my O² sim card even fills it in with incorrect info)</em>. Today I finally had a chance to look at the iPhone configuration tool offered by Apple.</p>
<p>The iPhone configuration tool gives you a range of options to configure a single or multiple iPhones. It also offers the chance to do some security related configurations that you can&#8217;t achieve directly on the iPhone itself. The 2 things I was particularly  interested in where the Passcode and APN <em>(advanced)</em> settings.</p>
<h4><a href="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool1.png"><img class="size-medium wp-image-1119 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="iphoneconfigtool" src="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool1.png?w=300&#038;h=212" alt="" width="300" height="212" /></a></h4>
<p>Wether you&#8217;re using this in a corporate of home environment, the configuration tool can help improve the security of your iPhone, as well as making it easier to turn settings on/of as required.</p>
<h4>Passcode</h4>
<p>By default the iPhone allows for a 4 character passcode to lock down your phone. This is great, but I&#8217;ve lost count the amount of times I&#8217;ve seen people type in their passwords. It&#8217;s not hard to remember a 4 digit passcode, and as iPhone doesn&#8217;t randomize the layout of the numbers on the screen, it&#8217;s easy enough to figure out the password even without seeing which numbers are selected. Luckily the iPhone configuration tool gives you the chance to correct this.</p>
<p><a href="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-passcode.png"><img class="alignleft size-medium wp-image-1100" style="border:7px none;margin:7px;" title="iphoneconfigtool-passcode" src="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-passcode.png?w=272&#038;h=164" alt="" width="272" height="164" /></a>Through the configuration tool you can set the advanced settings not possible to do directly on the iPhone itself. These settings include the complexity <em>(including the number of non-alphanumeric characters required)</em>, minimum length, maximum password age, password history and failed attempts.</p>
<p>Alongside these typical settings you can also set the auto-lock and grace period times. Most importantly, from my perspective, you can enable the device erase function <em>(this can also be enabled on the device directly)</em>.</p>
<p>When it comes to mobile devices, password enforcement is becoming more and more important. With the limited keyboard functionality and repetition of password entry <em>(how many times a day do you type in your iPhone passcode ?)</em> it&#8217;s important to make sure users <em>(whether enterprise or home)</em> don&#8217;t simplify the passcode too much. It&#8217;s very convenient to use 9999 as your passcode, but it&#8217;s not hard to shoulder-surf.</p>
<p style="text-align:left;"><img class="size-full wp-image-1109 aligncenter" style="margin-top:6px;margin-bottom:6px;" title="4andlongpasscode" src="http://c22blog.files.wordpress.com/2009/12/4andlongpasscode.png?w=515&#038;h=246" alt="" width="515" height="246" />The above images show the default 4 character PIN style password, and the more extensive passcode options you can enable through iPhone configuration tool. The more security conscious may have noticed there are 3 images and not just 2. If you allow users to set digit only passcodes <em>(i.e. an 8 character passcode like 12345678)</em> then your users will be prompted <strong>ONLY</strong> to enter numeric values. If the user sets a more complex alphanumeric password, then they will be given a full keyboard for entry. This isn&#8217;t a BIG security issue, but it does tell you what kind of passcode they&#8217;ve selected without you needing to know the passcode itself. Still, it&#8217;s better than a 4 digit passcode <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<h4 style="text-align:left;">APN (advanced)</h4>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-advanced.png"><img class="size-medium wp-image-1101 alignright" style="margin:6px;" title="iphoneconfigtool-advanced" src="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-advanced.png?w=300&#038;h=179" alt="" width="300" height="179" /></a></p>
<p>The second feature that interest me is the advanced page, which allows you to set the APN and Proxy information. For me this is really handy. I can go into the configuration tool and create a profile for each APN setting combination that I need. When going between countries I can simply pull up the .mobileconfig file from my email <em>(make sure you&#8217;ve got it cached)</em> and apply it to the iPhone.</p>
<p>The advanced settings page also allows you to set a proxy for your communications. I&#8217;ve not had a chance to play with this setting yet to see what kind of security enhancement can be gained from this. In theory it would be nice to force ALL communications over an SSL secured proxy. This could then connect back to a trusted system to give you an extra layer of protection between your phone and home base. When travelling to a possibly dangerous environment <em>(I&#8217;m thinking China, Russia, Ukraine, etc&#8230;)</em> it would be nice to feel just a little bit more secure.</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-profiles1.png"><img class="size-full wp-image-1116 aligncenter" style="margin-top:5px;margin-bottom:5px;" title="iphoneconfigtool-profiles" src="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-profiles1.png?w=571&#038;h=276" alt="" width="571" height="276" /></a>The good thing about profiles is that you can add and remove them at will. You can also have more than 1 profile active on the iPhone at once <em>(as you can see I&#8217;ve got 4 currently)</em>. This allows you to add and remove them whenever you need to. It also means you can have a profile that applies your security settings and separate ones that apply just the APN info <em>(as it&#8217;s likely to change more often than you security configuration)</em>. I&#8217;ve not had a chance yet to look at what happens when you set multiple profiles to contain settings that clash. I get the feeling that the LAST profile applied will override the earlier ones, but at the moment that&#8217;s just speculation on my part.</p>
<h4 style="text-align:left;">.mobileconfig</h4>
<p style="text-align:left;">The files you export from the iPhone configuration tool are simple XML files. So if you find yourself out and about without the tool, you can still open the file up in a text editor and change the settings as required. If you do a Google search for &#8220;mobileconfig iphone&#8221; you&#8217;ll find a number of sites discussing the format. You can also checkout the enterprise deployment documentation <a href="http://www.apple.com/support/iphone/enterprise/" target="_blank">HERE</a> for more hints. You can also download the configuration tool from the same location<em> (Windows / OSX only)</em>.</p>
<p style="text-align:left;"><strong>Edit</strong>: After posting I did a little followup on the contents of the .mobileconfig file. When looking at the files created to implement specific APN settings, I noticed the following string s in the XML :</p>
<pre style="padding-left:30px;"> &lt;key&gt;apns&lt;/key&gt;
 &lt;array&gt;
   &lt;dict&gt;
     &lt;key&gt;apn&lt;/key&gt;
     &lt;string&gt;payandgo.o2.co.uk&lt;/string&gt;
     &lt;key&gt;password&lt;/key&gt;
     &lt;data&gt;
     <span style="color:#ff0000;"><strong>cGFzc3dvcmQ=</strong></span>
     &lt;/data&gt;
     &lt;key&gt;username&lt;/key&gt;
     &lt;string&gt;vertigo&lt;/string&gt;
  &lt;/dict&gt;
&lt;/array&gt;
</pre>
<p>I can almost see people holding their heads in their hands. Yes, the password is stored Base64 encoded. I can understand why Apple have done this <em>(to avoid issues with special characters corrupting the XML)</em>. However Base64 isn&#8217;t encryption. Luckily the APN settings are usually publicly available. However the .mobileconfig file can also contain data such as WPA keys, mail account passwords, and even LDAP and Exchange server settings. Surely these are protected in the XML by default right ?</p>
<pre style="padding-left:30px;">&lt;key&gt;LDAPAccountDescription&lt;/key&gt;
 &lt;string&gt;LDAP Account&lt;/string&gt;
 &lt;key&gt;LDAPAccountHostName&lt;/key&gt;
 &lt;string&gt;server&lt;/string&gt;
 &lt;key&gt;LDAPAccountPassword&lt;/key&gt;
 &lt;string&gt;<strong><span style="color:#ff0000;">SecretLDAPpassword</span></strong>&lt;/string&gt;
 &lt;key&gt;LDAPAccountUseSSL&lt;/key&gt;
 &lt;true/&gt;
</pre>
<p>That&#8217;s what we like to see. Clear text passwords&#8230; However it&#8217;s not all bad, there is a solution, even if it&#8217;s not the default. When exporting the .mobileconfig file from the iPhone configuration tool, you can select to sign and encrypt the file. The downside of this, is that you need to tie the .mobileconfig to an iPhone that has been registered in the iPhone configuration tool. This may not always be convenient, especially when your CFO is shouting that his wireless settings are wrong as he&#8217;s waiting for the 9th hole at the local golf club. Still, at least Apple have thought about the security risks. When creating a single profile for your entire corporation however, you&#8217;ll either need to register each iPhone in the configuration tool before exporting the file, or use the less secure, unencrypted, option.</p>
<p>So, if you&#8217;re a corporate using this feature for your CEO&#8217;s iPhone, remember to store the .mobileconfig in a safe place and use the sign and encrypt option <em>(not the default, at least in my testing)</em>. If you&#8217;re a penetration tester, add this filetype to your list of files to look for next time you exploit a users system. You never know what you might find. If you want to know how bad it really is, try the following Googledork &#8220;filetype:mobileconfig&#8221;.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1096/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1096/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1096/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1096&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/12/04/playing-with-iphone-profiles/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool1.png?w=300" medium="image">
			<media:title type="html">iphoneconfigtool</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-passcode.png?w=300" medium="image">
			<media:title type="html">iphoneconfigtool-passcode</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/12/4andlongpasscode.png" medium="image">
			<media:title type="html">4andlongpasscode</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-advanced.png?w=300" medium="image">
			<media:title type="html">iphoneconfigtool-advanced</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/12/iphoneconfigtool-profiles1.png" medium="image">
			<media:title type="html">iphoneconfigtool-profiles</media:title>
		</media:content>
	</item>
		<item>
		<title>Find files between 2 dates</title>
		<link>http://blog.c22.cc/2009/11/29/find-files-between-2-dates/</link>
		<comments>http://blog.c22.cc/2009/11/29/find-files-between-2-dates/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 14:39:13 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[date]]></category>
		<category><![CDATA[find]]></category>
		<category><![CDATA[tip]]></category>
		<category><![CDATA[touch]]></category>

		<guid isPermaLink="false">http://blog.c22.cc/?p=1052</guid>
		<description><![CDATA[I thought I&#8217;d share a little tip I found recently. I was searching for a way to find files created between 2 dates on a Linux box. There&#8217;s a lot of reasons you might want to do this. Maybe you need to archive some files, maybe you&#8217;ve been breached and need to check what files [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1052&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://c22blog.files.wordpress.com/2009/11/38663865_e3fb1ed42b.jpg"><img class="alignright size-medium wp-image-1053" style="border:6px;margin:6px;" title="38663865_e3fb1ed42b" src="http://c22blog.files.wordpress.com/2009/11/38663865_e3fb1ed42b.jpg?w=220&#038;h=240" alt="" width="220" height="240" /></a>I thought I&#8217;d share a little tip I found recently. I was searching for a way to find files created between 2 dates on a Linux box. There&#8217;s a lot of reasons you might want to do this. Maybe you need to archive some files, maybe you&#8217;ve been breached and need to check what files have been modified. Whatever the reason, these are the commands to run that will do the job for you.</p>
<ul>
<li>touch -m -t 200901010000 /tmp/startdate</li>
<li>touch -m -t 200801012359 /tmp/enddate</li>
<li>find . -newer /tmp/startdate ! -newer /tmp/enddate</li>
</ul>
<p>The <a title="man touch" href="http://unixhelp.ed.ac.uk/CGI/man-cgi?touch" target="_blank">touch</a> commands will create 2 reference files with the timestamp 01.01.2009 00:00 and 01.01.2009 23:59. Using these reference files you can then run the <a title="man find" href="http://unixhelp.ed.ac.uk/CGI/man-cgi?find" target="_blank">find</a> command to find everything newer than the first file, but NOT newer than the second file. Remember to delete the files from /tmp when you&#8217;re done <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<ul>
<li>rm /tmp/startdate /tmp/enddate</li>
</ul>
<p>I&#8217;ll try and write-up a script for the <a title="PenTester Scripting" href="http://www.pentesterscripting.com/" target="_blank">PenTester Scripting</a> project when I get some time.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/1052/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/1052/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/1052/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/1052/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/1052/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/1052/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/1052/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/1052/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/1052/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/1052/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=1052&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/11/29/find-files-between-2-dates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/11/38663865_e3fb1ed42b.jpg?w=273" medium="image">
			<media:title type="html">38663865_e3fb1ed42b</media:title>
		</media:content>
	</item>
		<item>
		<title>Filling your ipod&#8230;</title>
		<link>http://blog.c22.cc/2009/09/05/filling-your-ipod/</link>
		<comments>http://blog.c22.cc/2009/09/05/filling-your-ipod/#comments</comments>
		<pubDate>Fri, 04 Sep 2009 23:22:42 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[podcasts]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=780</guid>
		<description><![CDATA[Over some drinks at the last CERT.AT meeting in Vienna, the topic of security podcasts came up. It&#8217;s a topic that seems to be discussed a lot, and everybody has there own set of favourite podcasts that they listen to. So I&#8217;ve finally had time to sit down and go through my podcast list to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=780&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="margin:5px;" src="http://blogs.oracle.com/fusionecm/podcast.png" alt="" width="171" height="171" />Over some drinks at the last <a href="http://cert.at" target="_blank">CERT.AT</a> meeting in Vienna, the topic of security podcasts came up. It&#8217;s a topic that seems to be discussed a lot, and everybody has there own set of favourite podcasts that they listen to. So I&#8217;ve finally had time to sit down and go through my podcast list to pull out some of the ones I feel are worth listening to. Podcasts are a personal thing. Some people like highly technical podcasts, other like more operational style topics. I try to mix them up a little to get a bit of everything. Hope you enjoy, and if there&#8217;s something good that&#8217;s not on my list, please let me know. I can&#8217;t promise I&#8217;ll listen, but I&#8217;d be happy to try it out.</p>
<ul>
<li>
<h4>Social Media Security Podcast &#8211;&gt; <a href="http://phobos.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=329032812" target="_blank">iTunes Link</a></h4>
<ul>
<li>Social Media Security<span style="color:#800000;"> <strong>[24.12.2009: Not currently active]</strong></span></li>
<li><span style="color:#800000;"><span style="color:#000000;">Lots of great social media tips and tricks&#8230;</span><strong><br />
</strong></span></li>
</ul>
</li>
</ul>
<ul>
<li>
<h4>Eurotrash Security Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=343212779" target="_blank">iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Explicit</span>: Security interviews and news<span style="color:#800000;"> <strong>[24.12.2009: Newly added]</strong></span></li>
<li><strong></strong>Hosted by Wim Remes, Dale Pearson, Craig Balding, and Chris John Riley<strong><br />
</strong></li>
</ul>
</li>
</ul>
<ul>
<li>
<h4>TRACsec Podcast &#8211;&gt; <a href="http://www.tracsec.com/rss/episode-feed.xml" target="_blank">RSS Link</a></h4>
<ul>
<li>Security interviews and news <span style="color:#800000;"><strong>[24.12.2009: Newly added]</strong></span></li>
<li><span style="color:#800000;"><span style="color:#000000;">Hosted by Arron &#8220;Finux&#8221; Finnon, </span></span>Tom Mackenzie, and Chris John Riley<span style="color:#800000;"><strong><br />
</strong></span></li>
</ul>
</li>
</ul>
<ul>
<li>
<h4>BruCON Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=324473282" target="_blank">iTunes Link</a></h4>
<ul>
<li>The official Brucon conference podcast <strong>[24.12.2009: Not currently active]</strong></li>
</ul>
</li>
</ul>
<ul>
<li>
<h4>Cloud Security Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=327012714" target="_blank">iTunes Link</a></h4>
<ul>
<li>Cloud security news, events, analysis and interviews</li>
<li>Hosted by Craig Balding &amp; Chris Hoff</li>
</ul>
</li>
<li>
<h4>Crypto-Gram Security Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=83256114" target="_blank">iTunes Link</a></h4>
<ul>
<li>Audio version of Bruce Schneier&#8217;s Monthly Crypto-Gram Newsletter</li>
</ul>
</li>
<li>
<h4>Cyberspeak &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=108218375" target="_blank">iTunes Link</a></h4>
<ul>
<li>Computer crime and forensics podcast</li>
</ul>
</li>
<li>
<h4>Exotic Liability &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=312280089" target="_blank">iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Explicit</span><span style="color:#000000;">: Exotic Liability will push you into the new generation of Security</span></li>
<li><span style="color:#000000;">The only podcast to merge stripper jokes with security topics<br />
</span></li>
</ul>
</li>
<li>
<h4>GRM N00bs Security Podcast&#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=327765976" target="_blank"> iTunes Link</a></h4>
<ul>
<li>The GRM n00bs chat about various security topics</li>
<li>New podcast, a little rough around the edges, but hey, I don&#8217;t see you <em>(or me)</em> doing any better <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </li>
</ul>
</li>
<li>
<h4>(HPR) Hacker Public Radio &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=281699640" target="_blank">iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Explicit</span><span style="color:#000000;">: Technology, Open Source, Hacking &#8211;&gt; Various topics, released daily &#8211; Community Driven</span></li>
<li><span style="color:#000000;">Checkout the <a href="http://hackerpublicradio.org/" target="_blank">website</a> for more information on how to take part</span></li>
<li><span style="color:#000000;">See episode 315, 420 and 445 for my contributions<em> (so far&#8230;)</em><br />
</span></li>
</ul>
</li>
<li>
<h4>Hak5 &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=117137282" target="_blank"> iTunes Link</a></h4>
<ul>
<li><span style="color:#008000;">Video</span>: Put together a band of IT ninjas, security professionals and hardcore gamers, Hak5 isn&#8217;t your typical tech show</li>
</ul>
</li>
<li>
<h4>Internet Storm Center Threat Update&#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=276609412" target="_blank">iTunes Link</a></h4>
<ul>
<li>Monthly podcast covering current network security threats</li>
</ul>
</li>
<li>
<h4>Network Security Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=125724709" target="_blank">iTunes Link</a></h4>
<ul>
<li>Podcasting talking about the security issues that are relevant today such as consumer privacy and PCI-DSS.</li>
</ul>
</li>
<li>
<h4>OWASP Security Podcast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300769012" target="_blank">iTunes Link</a></h4>
<ul>
<li>Join a wide variety of web application security experts as they examine the multiple aspects of application and software security.</li>
<li>Also posted are audio recordings from OWASP conferences</li>
</ul>
</li>
<li>
<h4>Pauldotcom Security Weekly &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=91472687" target="_blank"> iTunes link</a></h4>
<ul>
<li>IT Security news, research, vulnerability discussions and interviews &#8211;&gt; <em>one of the best podcasts around</em></li>
<li>Checkout iTunes for a video feed also (not updated often)<em><br />
</em></li>
</ul>
</li>
<li>
<h4>Risky Business &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=216478078" target="_blank"> iTunes Link</a></h4>
<ul>
<li>Australian podcast discussing the latest security news, with interviews and discussion peices.</li>
</ul>
</li>
<li>
<h4>RB2 (Risky Business 2)&#8211;&gt;<a href="//risky.biz/feeds/rb2" target="_blank">Feed Link</a></h4>
<ul>
<li>Recorded conference presentations, single-shot interviews with industry players, freelance contributions and more.</li>
</ul>
</li>
<li>
<h4>SANS Internet Storm Center StormCast &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=304863991" target="_blank">iTunes Link</a></h4>
<ul>
<li>Daily microcasts sum,marizing information security issues of the last 24 hours</li>
<li>Short and sweat. Great to keep yourself up-to-date on new attacks and issues</li>
</ul>
</li>
<li>
<h4>SecuraBit &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=280048405" target="_blank"> iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Explicit</span>: Computer security podcast brough to you by Anthony Gartner, Chris Gerling, Chris Mills, and Jason Muellner.</li>
</ul>
</li>
<li>
<h4>Security Justice &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=283494270" target="_blank">iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Explicit</span>: Discussing security regarding technology and computers but also providing information and news about physical security.</li>
</ul>
</li>
<li>
<h4>SMBMinute &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=290082972" target="_blank"> iTunes Link</a></h4>
<ul>
<li>Technology for SMB&#8217;s</li>
</ul>
</li>
<li>
<h4>SpiderLabs Radio &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300567984" target="_blank"> iTunes Link</a></h4>
<ul>
<li>Monthly DJ Mixes and interviews with Spiderlabs security professionals</li>
<li>Mostly music, but worth it for the interviews even if you don&#8217;t need music to hack to <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </li>
</ul>
</li>
<li>
<h4>Tenable Network Security &#8211;&gt; <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=329735657" target="_blank">iTunes Link</a></h4>
<ul>
<li>Official podcast of Tenable Network Security and the Nessus vulnerability scanner</li>
<li>Corporate podcast. Newly formed with Paul from pauldotcom.</li>
</ul>
</li>
<li>
<h4>2600: The Hacker Quarterly&#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=73330650" target="_blank"> iTunes Link</a></h4>
<ul>
<li>The Hacker Quarterly. Combined feed of Off the Hook and Off the Wall shows.</li>
<li>Lots of fundraisers, but occassionally interesting content</li>
</ul>
</li>
<li>
<h4>Midwest Teen Sex Show &#8211;&gt;<a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=257342095" target="_blank"> iTunes Link</a></h4>
<ul>
<li><span style="color:#ff0000;">Non-Security, hilarious<span style="color:#000000;">/</span><span style="color:#008000;">VIDEO</span><span style="color:#000000;">: Podcast for teens and adults covering the wonderful, awkward, stimulating, sticky world of sex.</span></span></li>
<li><span style="color:#ff0000;"><span style="color:#000000;">Trust me, you WILL laugh a lot. Unless of course you hate sex and jokes, in which case, don&#8217;t even click the link <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
</span></span></li>
</ul>
</li>
</ul>
<p><span style="color:#ff0000;"><span style="color:#000000;">Well there it is, my shortened list of security podcasts <em>(currently)</em>. I tend to switch and change depending on whats happening at the time and what my schedule is like. I&#8217;ve also skipped a few that don&#8217;t seem to be updating very regularly as their is a chance they&#8217;re off the air (blue box podcast, sploitcast spring to mind). I also snuck in one non-security podcast at the end. Give it a shot, it&#8217;s hilarious in an educational and strange way.If you&#8217;re into Linux as well, checkout the guys at <a href="http://www.jupiterbroadcasting.com/" target="_blank">Jupiter Broadcasting</a>.<br />
</span></span></p>
<p><span style="color:#ff0000;"><span style="color:#000000;">As I said before, if you&#8217;ve got some podcasts <em>(good ones that is. Please don&#8217;t link me to Security NOW)</em> that aren&#8217;t on my list, just let me know, and I&#8217;ll give them a shot.</span></span></p>
<p><span style="color:#800000;"><strong>[24.12.2009: Updated]</strong></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/780/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/780/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/780/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/780/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/780/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/780/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/780/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/780/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/780/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/780/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=780&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/09/05/filling-your-ipod/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://blogs.oracle.com/fusionecm/podcast.png" medium="image" />
	</item>
		<item>
		<title>Fixing Cydia</title>
		<link>http://blog.c22.cc/2009/07/19/fixing-cydia/</link>
		<comments>http://blog.c22.cc/2009/07/19/fixing-cydia/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 07:01:48 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[cydia]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[mobilesubstrate]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/2009/07/19/fixing-cydia/</guid>
		<description><![CDATA[At some point in the last 24 hours Saurik released a couple of updates to Mobilesubstrate through Cydia. Usually I try to keep updated with the latest and greatest (I&#8217;m a technology junkie) so I ran the upgrade will I grabbed my morning cup of tea (I&#8217;m also English after all). Normally after an upgrade [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=683&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="border:5px;margin:5px;" src="http://myi.gr/wp-content/uploads/2009/05/30cydia.png" alt="" width="230" height="344" />At some point in the last 24 hours <a href="http://www.saurik.com/" target="_blank">Saurik</a> released a couple of updates to Mobilesubstrate through Cydia. Usually I try to keep updated with the latest and greatest (I&#8217;m a technology junkie) so I ran the upgrade will I grabbed my morning cup of tea (I&#8217;m also English after all). Normally after an upgrade you&#8217;ll see a prompt to restart springboard, however with this update the phone rebooted part way through the install. A worrying signal. After the reboot everything seemed to be fine, except Cydia refused to start fully. After showing the default Cydia screen fir a few seconds, Cydia would disappear.</p>
<p>After a couple of reboots to make sure the issue wasn&#8217;t going to solve itself, I had a quick look on <a href="http://twitter.com/saurik" target="_blank">Saurik&#8217;s twitterfeed</a> but he had no mention of the issue. Several followers however were having the same issue. Time to find a solution.</p>
<p>I dropped to the terminal (although making an SSH connection would also have done the trick) and su&#8217;d to root. For those new to this the default password for root is alpine and if you&#8217;ve upgraded to version 3.0 this <strong>WILL</strong> have been reset. So change the root and mobile users passwords using &#8216;passwd&#8217; before somebody else connects and does <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  Anyway, I digress.</p>
<p>After getting root access it&#8217;s time to see what state the mobilesubstrate and cydia packages were in. After an &#8216;apt-get update&#8217; (to get the updated package lists) and and &#8216;apt-get install cydia&#8217; it looks like the package is corrupted, as I&#8217;m prompted to run the dpkg configure</p>
<p style="padding-left:30px;">dpkg -<!-- -->-configure -a</p>
<p>After this is completed, I reran the &#8216;apt-get install cydia&#8217;, and then an &#8216;apt-get upgrade&#8217; to reinstall the failed mobilesubstrate and  in my case the new VoIP 3G app. After another reboot (type reboot at the prompt or whatever your preferred method is) things seem to be running fine again.</p>
<p>For those with short attention spans .:</p>
<ul>
<li>Shell access (terminal or ssh)</li>
<li>Su to root</li>
<li>dpkg -<!-- break to make the command appear correctly -->-configure -a</li>
<li>apt-get update</li>
<li>apt-get install cydia (if this fails add &#8211;fix-missing)</li>
<li>apt-get upgrade (to install mobilesubstrate correctly)</li>
<li>reboot</li>
</ul>
<p>I hope this solves your issues as easily as it did mine. Let me know if you have any issues.</p>
<p><span style="color:#800000;">Update</span>: There are a few <a href="http://iphonehelp.in/2009/04/15/how-to-resolve-cydia-crash-problem-while-loading-data-screen/" target="_blank">other guides</a> going around telling you to connect the iphone to your system (or useiFile) and then delete specific files. I&#8217;ve not tested these fixes, but the chance of deleting files you need are always there. I&#8217;d suggest using the easy fix using apt-get before trying the file deletion route. However it&#8217;s a personal choice.</p>
<p><span style="color:#800000;">Update</span>: As a few comments have noted, the nice people at wordpress reformed the -<!-- -->- into a single &#8211; when displaying the page. This should now be fixed using the magic trickery of HTML comments to split the two characters <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> &#8211;&gt;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/683/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/683/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/683/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=683&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/07/19/fixing-cydia/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://myi.gr/wp-content/uploads/2009/05/30cydia.png" medium="image" />
	</item>
		<item>
		<title>Protecting your browsing with iPhone SSH tunnels</title>
		<link>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/</link>
		<comments>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/#comments</comments>
		<pubDate>Sun, 21 Jun 2009 11:25:27 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[3proxy]]></category>
		<category><![CDATA[encrypted]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=540</guid>
		<description><![CDATA[Most of the time I feel relatively secure when I&#8217;m browsing the web or checking twitter on my iPhone. That said, I rarely use the built in wireless for these purposes, and rely instead on the reasonably good 3G network in Austria. When I&#8217;m out of the country I usually try to buy a pay-as-you-go [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=540&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;">Most of the time I feel relatively secure when I&#8217;m browsing the web or checking twitter on my iPhone. That said, I rarely use the built in wireless for these purposes, and rely instead on the reasonably good 3G network in Austria. When I&#8217;m out of the country I usually try to buy a pay-as-you-go sim card and pay for the daily data transfer. This isn&#8217;t as expensive as you&#8217;d think. For example in the Netherlands it costs around €3.50 per day of data transfer. Not cheap if you&#8217;re using it long-term, but if you&#8217;re only there for a couple of days it&#8217;s a lot cheaper than paying for a hotel WLAN that&#8217;s insecure and only works inside the hotel. Still, this solution doesn&#8217;t work everywhere and isn&#8217;t for everyone. The fallback is to use whatever wireless you can find, insecure or not. This is something I&#8217;ve been fighting with for a while now. Stemming (mostly) from my unwillingness to setup a VPN server (my home ADSL isn&#8217;t good enough quality, and doesn&#8217;t have a fixed IP) or pay a huge price for a VPN solution through my existing hosting provider (thanks for the cheap hosting Dreamhost).</p>
<p style="text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/06/iphone_http_proxy.png?w=200"><img class="size-medium wp-image-543 alignright" style="border:5px none;margin:5px;" title="iPhone HTTP Proxy Settings" src="http://c22blog.files.wordpress.com/2009/06/iphone_http_proxy.png?w=100&#038;h=150" alt="iphone_http_proxy" width="100" height="150" /></a>The iPhone (at least version 2.2.1) supports the use of HTTP proxies when connecting via a wireless connection. This is great. Surely I can setup an SSH Tunnel to my server and tell the iPhone to use this as a SOCKS proxy. As with everything on the iPhone however, simple always turns into complicated very quickly. I experimented with this solution and found that the HTTP proxy support was really just that, HTTP proxy support and nothing else. So back to the drawing board. I searched for another solution and settled on using the 3proxy application (in cydia for those lucky enough to have a jailbroken iPhone) to setup a local HTTP proxy.</p>
<p style="text-align:left;">A few requirements to get this up and running on your iPhone.</p>
<ul style="text-align:left;">
<li>A Jailbroken iPhone (or iPod Touch)</li>
<li>SSH Client installed</li>
<li>3proxy (available in cydia)</li>
<li>terminal application</li>
<li>An SSH server (setup for either password or certificate access)</li>
<li>Backgrounder (or some other way to run commands and have them running in the background)</li>
<li>OPTIONAL: iFile (easy file editing)</li>
</ul>
<p style="text-align:left;">Starting off we&#8217;ll take a look at the configuration of 3proxy. By using the following configuration you tell 3proxy to forward all traffic to a second proxy server, this time a SOCKS proxy (in this case my SSH tunnel).</p>
<pre style="padding-left:30px;text-align:left;">#!/usr/bin/3proxy
daemon
auth iponly
log /var/log/3proxy.log D
rotate 5
fakeresolve
internal 127.0.0.1
allow * * 127.0.0.1
parent 1000 socks5+ 127.0.0.1 8081
proxy -p8080 -a -i127.0.0.1</pre>
<p style="text-align:left;">The quick rundown on the above configuration.</p>
<ul style="text-align:left;">
<li>#!/usr/bin/3proxy &#8211; Tells the script what interpreter program to use</li>
<li>daemon -  Tells 3proxy to run as a background process</li>
<li>auth iponly &#8211; sets the authorization to be ip restricted</li>
<li>log &#8211; Setup a log that rotates daily (the D option)</li>
<li>rotate 5 &#8211; Sets the number of log files to keep before rotating</li>
<li>fakeresolve &#8211; Tells 3proxy to route DNS lookups through the proxy</li>
<li>internal &#8211; Listen in the internal interface only</li>
<li>allow &#8211; Currently set to * for all (you can limit this by username/password or IP, however this caused issues in testing)</li>
<li>parent &#8211; This is where we&#8217;re setting the next proxy in the chain (1000 is always use this parent, SOCKS5+ is the type and then the SSH tunnel listening ip and port)</li>
<li>proxy &#8211; this final command tells 3proxy to start a proxy on port 8080 using anonymous proxy mode (-a) and listen only in internal loopback</li>
</ul>
<p style="text-align:left;">You can find more configuration information on the <a title="3proxy" href="http://3proxy.ru/doc/html/man3/3proxy.cfg.3.html" target="_blank">3proxy</a> website. Although leaving the allow set to * (all) is a concern, remember that the proxy is only listening on the localhost address and from outside the port is blocked.</p>
<p style="text-align:center;"><a href="http://c22blog.files.wordpress.com/2009/06/iphone_portscan1.png"><img class="size-medium wp-image-548 alignnone" style="border:4px;margin:4px;" title="iphone_portscan" src="http://c22blog.files.wordpress.com/2009/06/iphone_portscan1.png?w=300&#038;h=89" alt="iphone_portscan" width="300" height="89" /></a></p>
<p style="text-align:left;">Now that we&#8217;ve got the 3proxy.cfg file saved (mines stored in /usr/bin with the 3proxy executable) you&#8217;ll need to run chmod +x to make it executable. Next up is the SSH Tunnel, and doing this on an iPhone isn&#8217;t much different to a normal linux system (just harder to type for obvious reasons). I opted to add a certificate for quick easy access and restricted access to the certificate to the root user on the iPhone (you have changed your root password right ???). I added the private key to ~/.ssh/id_dsa (or id_rsa, your choice) and setup a bash script to kick off the SSH tunnel (typing that command each time gets boring fast).</p>
<pre style="padding-left:30px;text-align:left;">ssh -D 8081 -N -C username@remotehost.your.domain -2 -p 64000 -i /home/root/.ssh/id_dsa</pre>
<p style="text-align:left;">The above command is a simple SSH tunnel setup to connect to port 64000 on remotehost.your.domain and logon as the user username using the certificate file stored in /home/root/.ssh/id_dsa. It will then setup a local listener on port 8081 and dynamically route all traffic coming to this port through the SSH tunnel. As we&#8217;re treating the tunnel as a SOCKS proxy we don&#8217;t need to have anything else setup at the other end (no other proxy server waiting to route the requests) although you could setup privoxy or any other kind of proxy if you wanted more control.</p>
<p style="text-align:left;">So, now that we have the two parts of our configuration ready we just need to drop to the shell and kickoff the SSH Tunnel (using your bash script), and then startup the 3proxy using the /usr/bin/3proxy.cfg command. I&#8217;ve linked it all into a single bash script to make things a little quicker.</p>
<p>In testing Safari works pretty well (minor decrease in performance as you&#8217;d expect). Twitterfon was the second application I tested. Although this follows the HTTP proxy rule, it still insists on doing DNS lookups for advertising outside of the proxy. This is also the case for a couple of other applications. Mail doesn&#8217;t follow the HTTP rules, however you can easily setup additional 3proxy ports for these, or use SSL and make sure your DNS is all piped over the local listener and through the SSH tunnel (3proxy supports a DNS caching proxy, tcp and udp forwarding proxies also).</p>
<div class="mceTemp">
<pre style="padding-left:30px;text-align:left;"><a href="http://c22blog.files.wordpress.com/2009/06/safari_noproxy1.png" target="_blank"><img class="size-thumbnail wp-image-556" style="margin-top:5px;margin-bottom:5px;" title="Safari No Proxy" src="http://c22blog.files.wordpress.com/2009/06/safari_noproxy1.png?w=150&#038;h=87" alt="Safari No Proxy" width="150" height="87" /></a><a href="http://c22blog.files.wordpress.com/2009/06/twitter_noproxy2.png" target="_blank"><img class="size-thumbnail wp-image-558" style="margin-top:5px;margin-bottom:5px;" title="Twitterfon No Proxy" src="http://c22blog.files.wordpress.com/2009/06/twitter_noproxy2.png?w=150&#038;h=87" alt="Twitterfon No Proxy" width="150" height="87" /></a><a href="http://c22blog.files.wordpress.com/2009/06/twitterfon_socks.png" target="_blank"><img class="size-thumbnail wp-image-559" style="margin-top:5px;margin-bottom:5px;" title="Twitterfon Socks Proxy" src="http://c22blog.files.wordpress.com/2009/06/twitterfon_socks.png?w=150&#038;h=87" alt="Twitterfon Through Proxy" width="150" height="87" /></a></pre>
</div>
<p style="text-align:left;"><strong>Supported</strong>:</p>
<ul style="text-align:left;">
<li>Safari</li>
<li>Twitterfon (partially: Advert DNS lookups are still a possible concern/attack vector)</li>
<li>Cydia</li>
<li>AppStore</li>
<li>iTunes</li>
<li>Youtube</li>
<li>Weather</li>
<li>GRiS</li>
<li>WordPress (partially: As with the Twitterfon issue, the DNS appears to ignore the HTTP proxy settings)</li>
</ul>
<p style="text-align:left;">Obviously these were just the applications I tested. I&#8217;d suggest running your own tests to ensure that you&#8217;re seeing the same results.</p>
<p style="text-align:left;"><strong>Not-Supported</strong>:</p>
<ul style="text-align:left;">
<li>Mail (setup a port forwarder to achieve support for email)</li>
<li>Siphon (This is a real disappointment)</li>
<li>F-Stream</li>
<li>&#8230; probably more, so your mileage may vary</li>
</ul>
<p style="text-align:left;">If you test any other applications please let me know and I&#8217;ll add it to my list.</p>
<p style="text-align:left;">Once you&#8217;ve finished using the SSH Tunnel and proxy, remember to kill -9 them using the console.</p>
<p style="text-align:left;"><strong>TODO</strong>:</p>
<ul style="text-align:left;">
<li>Test with alternative &#8220;allow&#8221; settings to restrict access further (username/password too easy)</li>
<li>Prevent initial DNS lookup on SSH Tunnel (i.e. dyndns service)</li>
<li>Log Bug with Twitterfon regardin DNs lookups</li>
<li>Find an easier way to trigger the tunnel &amp; 3proxy build-up/tear-down</li>
<li>Resolve issue of tunnel disconnecting when screen gets locked (FOR loop ???)</li>
<li>Use the tunnel for 3G connections (paranoid much !!!)</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/540/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/540/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/540/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=540&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/06/21/iphone-ssh-tunnel/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/06/iphone_http_proxy.png?w=200" medium="image">
			<media:title type="html">iPhone HTTP Proxy Settings</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/06/iphone_portscan1.png?w=300" medium="image">
			<media:title type="html">iphone_portscan</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/06/safari_noproxy1.png?w=150" medium="image">
			<media:title type="html">Safari No Proxy</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/06/twitter_noproxy2.png?w=150" medium="image">
			<media:title type="html">Twitterfon No Proxy</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/06/twitterfon_socks.png?w=150" medium="image">
			<media:title type="html">Twitterfon Socks Proxy</media:title>
		</media:content>
	</item>
		<item>
		<title>MS09-012: Fixing “Token Kidnapping”</title>
		<link>http://blog.c22.cc/2009/04/15/ms09-012-fixing-%e2%80%9ctoken-kidnapping%e2%80%9d/</link>
		<comments>http://blog.c22.cc/2009/04/15/ms09-012-fixing-%e2%80%9ctoken-kidnapping%e2%80%9d/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 06:58:20 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Penetration Test]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patches]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=468</guid>
		<description><![CDATA[This was the headline that grabbed my attention this morning on the Microsoft Security &#38; Defence Blog. Had Microsoft finally patched the token impersonation flaw (or feature as Microsoft regard it) that is used by the Incognito tool to allow a compromised system level account to impersonate local or domain users. In short no, and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=468&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>This was the headline that grabbed my attention this morning on the <a title="Microsoft Blog" href="http://blogs.technet.com/srd/archive/2009/04/14/ms09-012-fixing-token-kidnapping.aspx">Microsoft Security &amp; Defence Blog</a>. Had Microsoft finally patched the token impersonation flaw (or feature as Microsoft regard it) that is used by the <a title="Incognito" href="http://sourceforge.net/projects/incognito">Incognito</a> tool to allow a compromised system level account to impersonate local or domain users. In short no, and I say that with mixed feelings.</p>
<p>As a penetration tester, I can breath a sigh of relief and know that this attack vector is still open. As a defender, the chance that Microsoft had changed the way this functionality works to block the attack was a welcome update to protect our systems. Still, you can&#8217;t expect Microsoft to repair something they see as a feature and the way things should work. Some things aren&#8217;t meant to be repaired I guess.</p>
<h3>Testing</h3>
<p>Just to make sure that Microsoft hadn&#8217;t broken the Incognito functionality while messing with the way tokens work, I ran a couple of tests against a Windows XP service pack 2 machine.</p>
<p>I started off with an unpatched version and ran the trusty MS08-067 exploit to get a meterpreter shell.</p>
<blockquote><p>./msfcli exploit/windows/smb/ms08_067_netapi payload=windows/meterpreter/bind_tcp LHOST=192.168.0.104 RHOST=192.168.0.103 E</p>
</blockquote>
<p>This functioned as you&#8217;d expect and resulted in a meterpreter shell running under the Local System Account. After running the &#8220;use incognito&#8221; command I listed the tokens using &#8220;list_tokens -u&#8221;.</p>
<p><a href="http://c22blog.files.wordpress.com/2009/04/incognito1.png"><img class="aligncenter size-medium wp-image-469" title="incognito1" src="http://c22blog.files.wordpress.com/2009/04/incognito1.png?w=300&#038;h=226" alt="incognito1" width="300" height="226" /></a></p>
<p>Taking the local account &#8220;pentestuser&#8221; as the token to impersonate, I ran &#8220;impersonate_token PENTEST-3C73D9Cpentestuser&#8221;</p>
<p><a href="http://c22blog.files.wordpress.com/2009/04/incognito2.png"><img class="aligncenter size-medium wp-image-470" title="incognito2" src="http://c22blog.files.wordpress.com/2009/04/incognito2.png?w=300&#038;h=48" alt="incognito2" width="300" height="48" /></a></p>
<p>Success, as expected on the unpatched system. Next up, I patched the system, rebooted and repeated the same msfcli exploit (MS08-067). This time however the exploit failed on the first run as it couldn&#8217;t isolate the exact service pack version. Metasploit listed it as Service Pack 2+ (which is technically correct). Re-running the command completed the exploit however.</p>
<p><a href="http://c22blog.files.wordpress.com/2009/04/incognito3_after-patch.png"><img class="aligncenter size-medium wp-image-471" title="incognito3_after-patch" src="http://c22blog.files.wordpress.com/2009/04/incognito3_after-patch.png?w=300&#038;h=223" alt="incognito3_after-patch" width="300" height="223" /></a></p>
<p>Even after the patch everything seems fine in the token list.</p>
<p><a href="http://c22blog.files.wordpress.com/2009/04/incognito4_after-patch.png"><img class="aligncenter size-medium wp-image-472" title="incognito4_after-patch" src="http://c22blog.files.wordpress.com/2009/04/incognito4_after-patch.png?w=300&#038;h=57" alt="incognito4_after-patch" width="300" height="57" /></a></p>
<p>The final test, impersonation of the PENTEST-3C73D9Cpentestuser user. As before this went off without a hitch, giving us access to the local user without error.</p>
<h3>Conclusion</h3>
<p>Microsoft have patched the flaws listed in <a title="MS09-012" href="http://www.microsoft.com/technet/security/bulletin/MS09-012.mspx">KB952004</a> without effecting the Incognito tool (or the implementation of the tool within Metasploit). Good for attackers, bad for defenders. But you can&#8217;t always have it both ways can you. I doubt that we&#8217;ll be seeing a patch against the token impersonation flaw used in incognito anytime soon, if at all.</p>
<p>I&#8217;m heading to Blackhat Europe in a few hours (courtesy of a last minute press registration). If you&#8217;re there feel free to drop me a line and buy me a drink <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  &#8212; &gt; contact <span style="color:#888888;">[at]</span> c22 <span style="color:#888888;">[dot]</span> cc</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/468/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/468/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/468/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=468&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/04/15/ms09-012-fixing-%e2%80%9ctoken-kidnapping%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/incognito1.png?w=300" medium="image">
			<media:title type="html">incognito1</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/incognito2.png?w=300" medium="image">
			<media:title type="html">incognito2</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/incognito3_after-patch.png?w=300" medium="image">
			<media:title type="html">incognito3_after-patch</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/incognito4_after-patch.png?w=300" medium="image">
			<media:title type="html">incognito4_after-patch</media:title>
		</media:content>
	</item>
		<item>
		<title>DECT Interception</title>
		<link>http://blog.c22.cc/2009/04/04/dect-interception/</link>
		<comments>http://blog.c22.cc/2009/04/04/dect-interception/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 17:45:03 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Penetration Test]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[DECT]]></category>
		<category><![CDATA[penetration testing]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=458</guid>
		<description><![CDATA[I&#8217;ve been playing about with the com-on-air and tools from dedected for a few weeks now. Results are mixed, as those who&#8217;ve sat through eth few demos I&#8217;ve run can certainly attest to. Things are still in the early phases for the dedected tools and as much as I love what&#8217;s already there, it&#8217;s not [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=458&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_461" class="wp-caption alignleft" style="width: 258px"><a href="http://c22blog.files.wordpress.com/2009/04/screenshot1.png?w=300"><img class="size-medium wp-image-461" style="border:5px;margin:5px;" title="dect_cli" src="http://c22blog.files.wordpress.com/2009/04/screenshot1.png?w=248&#038;h=183" alt="dect_cli" width="248" height="183" /></a><p class="wp-caption-text">dect_cli</p></div>
<p>I&#8217;ve been playing about with the com-on-air and tools from <a title="DEDECTED" href="https://dedected.org" target="_blank">dedected</a> for a few weeks now. Results are mixed, as those who&#8217;ve sat through eth few demos I&#8217;ve run can certainly attest to. Things are still in the early phases for the dedected tools and as much as I love what&#8217;s already there, it&#8217;s not really ready for the mainstream yet. Don&#8217;t get me wrong, whats been done is already amazing work, but for the penetration testers amongst you wanting to grab a com-on-air card from ebay and starting running tests, things aren&#8217;t always going to be 100%. Still, it makes managers sit up and pay attention if demonstrated correctly.</p>
<p>As an example of the issues, I&#8217;ve build the drivers and tools from source on 3 or 4 systems now (Fedora, Debian, and Backtrack 3 and 4). Compiling resulted in mixed results (some compile errors) and random capture failures (just capturing static as if the course was encrpyted). You&#8217;ll also probably get a few kernel panics before you learn to respect the driver and not expect hotswap support just yet. After one too many hit and miss captures from the compiled versions, I opted to go for the <a title="Chaox-ng" href="http://chaox.wordpress.com/" target="_blank">Chaox-ng</a> boot USB which includes everything (yes I do mean everything) built in. I find that this USB boot option just adds to the effect when it comes to demos. You turn up with a PCMCIA card and a 1 GB USB stick. That and any laptop will do the job.</p>
<div id="attachment_460" class="wp-caption alignright" style="width: 310px"><a href="http://c22blog.files.wordpress.com/2009/04/screenshot-10.png?w=300"><img class="size-medium wp-image-460" style="border:5px none;margin:5px;" title="Wireshark SVN" src="http://c22blog.files.wordpress.com/2009/04/screenshot-10.png?w=300&#038;h=228" alt="Wireshark SVN" width="300" height="228" /></a><p class="wp-caption-text">Wireshark SVN</p></div>
<p>The Chaox-ng distro includes the drivers and tools compiled to perfection (no capture issues here). The latest version also includes the SVN version of Wireshark (with DECT PCAP support). Kismet newcore is compiled in with the DECT plugin if you want to play about with this as well. About the only thing missing is the Metasploit auxiliary modules, but that always was just a Proof of Concept and not very functional. Personally I stick to using the &#8216;dect_cli&#8217; tool (alongside pcapstein, pcap2chan and Wireshark). For those that are interested I&#8217;ve uploaded a few packet captures for you to take a look at.</p>
<h3>Plantronics CS60 Captures (Encrypted B-Channel)</h3>
<ul>
<li>Keepalive traffic capture (pcap) &#8212; <a title="Plantronics CS60 - Keepalive" href="http://storage.c22.cc/RFPI_00_8c_20_81_48_keepalive_fp-pp.pcap" target="_blank">HERE</a></li>
<li>Headset pairing process (pcap) &#8212; <a title="Plantronics CS60 - Pairing 1" href="http://storage.c22.cc/RFPI_00_8c_20_81_48_pairing1_fp-pp.pcap" target="_blank">Capture 1</a>, <a title="Plantronics CS60 - Pairing 2" href="http://storage.c22.cc/RFPI_00_8c_20_81_48_pairing2_fp-pp.pcap" target="_blank">Capture 2</a> and <a title="Plantronics CS60 - Pairing 3" href="http://storage.c22.cc/RFPI_00_8c_20_81_48_pairing3_fp-pp.pcap" target="_blank">Capture 3</a></li>
<li>Austrian speaking clock (pcap) &#8212; <a title="Plantronics CS60 - Austrian Speaking Clock (Encrypted)" href="http://storage.c22.cc/RFPI_00_8c_20_81_48-Speakingclock.pcap" target="_blank">HERE</a></li>
</ul>
<h3>Siemens GIGASET (Unencrypted B-Channel)</h3>
<ul>
<li>German Test Call (pcap) &#8212; <a title="Siemens GIGASET - German Test Call PCAP" href="http://storage.c22.cc/dump_2009-02-16_17_12_29_RFPI_00_99.pcap" target="_blank">HERE</a></li>
<li>German Test Call (g721, wav) &#8212; <a title="Siemens GIGASET - German Test Call Audio" href="http://storage.c22.cc/output.g721.wav" target="_blank">HERE</a></li>
</ul>
<div id="attachment_464" class="wp-caption alignleft" style="width: 240px"><a href="http://c22blog.files.wordpress.com/2009/04/screenshot-121.png?w=300"><img class="size-medium wp-image-464" style="border:5px;margin:5px;" title="kismet-newcore" src="http://c22blog.files.wordpress.com/2009/04/screenshot-121.png?w=230&#038;h=159" alt="kismet-newcore" width="230" height="159" /></a><p class="wp-caption-text">kismet-newcore</p></div>
<p>The Plantronics PCAP&#8217;s are interesting to look at and see how the communications between the base unit and headset are handled. At this point I&#8217;ve not looked too much into the encryption implmented. From a couple of test calls the Plantronics appears to initiate the call and then encrypt a fraction of a second after the call begins. I&#8217;m leaning towards a standard implementation of DSC (DECT Standard Cipher) instead of a propriatary Plantronics implementation. Pity, as I was hoping for something in the pairing process that would signal a handshake and key creation process. I&#8217;ll leave the encyption work to people much smarter than me however. I just like to play with the new toys <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>DSAA (DECT Standard Authentication Algorithm) has already been reversed (see details <a title="DSAA" href="https://dedected.org/trac/wiki/DSAA-Analysis" target="_blank">here</a> and the paper on the subject <a title="DSAA Paper" href="https://dedected.org/trac/attachment/wiki/DSAA-Analysis/Attacks%20on%20the%20DECT%20authentication%20mechanisms.pdf" target="_blank">here</a>). So next up will be the DSC hopefully. We&#8217;ll have to see how much longer the &#8220;Security through obscurity&#8221; of DECT works. I hope, for their sake, that they&#8217;ve implemented defence-in-depth <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/458/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/458/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/458/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=458&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/04/04/dect-interception/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/screenshot1.png?w=300" medium="image">
			<media:title type="html">dect_cli</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/screenshot-10.png?w=300" medium="image">
			<media:title type="html">Wireshark SVN</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/04/screenshot-121.png?w=300" medium="image">
			<media:title type="html">kismet-newcore</media:title>
		</media:content>
	</item>
		<item>
		<title>Man in the Middling Printers</title>
		<link>http://blog.c22.cc/2009/03/22/man-in-the-middling-printers/</link>
		<comments>http://blog.c22.cc/2009/03/22/man-in-the-middling-printers/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 09:30:20 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Penetration Test]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[mitm]]></category>
		<category><![CDATA[printers]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=435</guid>
		<description><![CDATA[This one has been rattling around in my head for a while, and since I&#8217;ve found myself with a few spare minutes, it&#8217;s time I wrote it up for your enjoyment and mine. This is certainly nothing new, but its one of those things that people seem to discount when performing penetration testing. After all, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=435&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright" style="border:7px;margin:7px;" src="http://shoponline.com.sg/images/Epson%20ACL-CX11NF%20Printer.jpg" alt="" width="277" height="330" />This one has been rattling around in my head for a while, and since I&#8217;ve found myself with a few spare minutes, it&#8217;s time I wrote it up for your enjoyment and mine. This is certainly nothing new, but its one of those things that people seem to discount when performing penetration testing. After all, printers aren&#8217;t really cool anymore.</p>
<p>MITM attacks are often talked about together with credential stealing or traffic manipulation (inserting javascript into http streams). The new tool from Inguardians (<a title="The Middler" href="http://www.inguardians.com/tools/" target="_blank">the Middler</a>) is a prime example of where the focus is right now. Although the middler was designed as a tool for performing attacks on all kinds of protocols, the examples provided with the alpha all focus on http(s) traffic. However what I want to talk about was using MITM attacks to steal confidential data in the form of print jobs.</p>
<p>When it comes to stealing data, most of the time you&#8217;re going to need a valid username/password to gain access. Sure you can exploit systems, use pass the hash or go the social engineering route, but you&#8217;re going to need access. However in this day and age of the failed paperless office, why go to those lengths when you can just steal the documents straight from the print queue. We all know how to perform ARP or DNS poisoning  to insert a system into the flow of traffic, but with printers this job can be made so much easier due to the overall lack of security on print devices.</p>
<p>There are four easy methods for stealing print jobs that spring to mind, other than using standard ARP or DNS spoofing attacks.</p>
<ol>
<li><strong>Physical access</strong> &#8211; A majority of printers offer unprotected access to the menu. Through physical access you can change the printers IP address and assume the original for yourself.</li>
<li><strong>Telnet access</strong> &#8211; Not seen so often in modern printers, but can give you complete access if the passwords are blank or left at default. Again, reset the IP address and assume the original.</li>
<li><strong>Webserver access</strong> &#8211; Most modern printers offer a web interface for easy configuration. Brute-Force is an option here as they rarely enforce lockouts or use domain credentials. Again, reset the IP address and assume the original.</li>
<li><strong>Denial of Service</strong> &#8211; Crude but effective. This isn&#8217;t really a MITM attack, as you&#8217;d not be able to forward on the print job. Just drop the printer off the network (turn it off if you have to) and steal it&#8217;s IP.</li>
</ol>
<p>Once you&#8217;ve gained access and stolen the IP address of the remote printer, there are a couple of ways to steal the print jobs. I started off by playing about with netcat using a simple netcat relay (and using tcpdump to copy the traffic).</p>
<blockquote><p>mknod backpipe p<br />
nc -l -p 9100 0&lt;backpipe | nc &lt;new printer ip&gt; 9100 0&gt;backpipe</p></blockquote>
<p>The problem with this is that it would work on the first print job and then lockup. This is because the netcat relay would make the connection and leave it running. All subsequent print jobs would fail. Back to the drawing board.</p>
<p>My second attempt included the -w1 timeout for the second half of the netcat relay . This forces the connection to be dropped after 1 second of inactivity. This worked a little better but still not perfectly. I also threw in tee to prevent having to use tcpdump to capture the traffic (-a sets append).</p>
<blockquote><p>mknod backpipe p<br />
nc -l -p 9100 0&lt;backpipe | tee -a capture.out | nc &lt;new printer ip&gt; -w1 9100 0&gt;backpipe</p></blockquote>
<p>The best results came from using the above command in a loop. I wrote a small bash script to do this. This is something to play with (your mileage may vary).</p>
<blockquote><p>#!/bin/bash<br />
i=1<br />
PRNIP=10.10.10.10</p>
<p>while true; do<br />
echo &#8220;Print jobs captured = $i&#8221;<br />
nc -l -p 9100 0&lt;backpipe | tee -a capture-$i.out | nc $PRNIP -w1 9100 0&gt;backpipe<br />
i=$i+1<br />
done</p></blockquote>
<p>As an alternative to netcat I also tested the use of iptables to perform a prerouting of the traffic.</p>
<blockquote><p>echo 1 &gt; /proc/sys/net/ipv4/ip_forward</p>
<p>iptables -F</p>
<p>iptables -t nat -F</p>
<p>iptables -X</p>
<p>iptables -t nat -A PREROUTING -p tcp &#8212; dport 9100 -j DNAT &#8211;to-destination &lt;new printer ip&gt;</p></blockquote>
<p>The problem I can see here is that PREROUTING is performed before any of the traffic will be visible to TCPDUMP. So although we&#8217;re routing all the traffic to the printer, we can&#8217;t dump any of the print jobs. I&#8217;m no iptables expert by any stretch of the imagination. So maybe there is a way to do this easily without extra tools. I&#8217;ll have to try playing with the mangling rules and see if I can get some better results with iptables.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/435/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/435/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/435/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/435/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/435/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/435/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=435&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/03/22/man-in-the-middling-printers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://shoponline.com.sg/images/Epson%20ACL-CX11NF%20Printer.jpg" medium="image" />
	</item>
		<item>
		<title>Twitter moves to protect against TinyURL attacks</title>
		<link>http://blog.c22.cc/2009/02/07/twitter-moves-to-protect-aginast-tinyurl-attacks/</link>
		<comments>http://blog.c22.cc/2009/02/07/twitter-moves-to-protect-aginast-tinyurl-attacks/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 23:43:45 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[tinyurl]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=407</guid>
		<description><![CDATA[It&#8217;s been a topic of conversation for a while now. The use of TinyURL&#8217;s within Twitter and other social media sites. For those of you who don&#8217;t know what a TinyURL is, I&#8217;ll give an example.
I want to post you a link to my website, however with Twitter I only have a maximum of 140 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=407&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a topic of conversation for a while now. The use of TinyURL&#8217;s within Twitter and other social media sites. For those of you who don&#8217;t know what a TinyURL is, I&#8217;ll give an example.</p>
<p>I want to post you a link to my website, however with Twitter I only have a maximum of 140 characters. To maximise the space and make things easier for users, the Twitter gods decided to convert the (usually) long links into a smaller link using the <a title="TinyURL" href="http://tinyurl.com/" target="_blank">TinyURL</a><a title="TinyURL" href="www.tinyurl.com" target="_blank"></a> service. You can checkout the service for yourself. You simply paste in the long link and get back a smaller one that still works the same way.</p>
<p><span style="color:#800000;">FULL URL</span> &#8211;&gt; http://c22blog.wordpress.com/2009/02/07/mobile-devices-lowering-web-security/</p>
<p><span style="color:#800000;">TinyURL</span> &#8211;&gt; http://tinyurl.com/btsfs5</p>
<p>As you can see, the second one is a lot easier to read and pass on. Anyway, back to the point at hand.</p>
<p>Twitter have implemented a new feature (currently restricted to their <a title="search.twitter.com" href="http://search.twitter.com" target="_blank">search.twitter.com</a> area) that adds an [expand] button after the TinyURL. As you can imagine, this allows you to expand the link and see where it really points to. This is obviously a good thing for security, as you never know where that TinyURL could take you. XSS attacks are all around us <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<div id="attachment_408" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-408" style="border:5px;margin:5px;" title="expand" src="http://c22blog.files.wordpress.com/2009/02/expand.png?w=300&#038;h=44" alt="Expand link --&gt; search.twitter.com" width="300" height="44" /><p class="wp-caption-text">Expand link @ search.twitter.com</p></div>
<div id="attachment_409" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-409" style="border:5px;margin:5px;" title="contract" src="http://c22blog.files.wordpress.com/2009/02/contract.png?w=300&#038;h=42" alt="contract link @ search.twitter.com" width="300" height="42" /><p class="wp-caption-text">contract link @ search.twitter.com</p></div>
<p>Here&#8217;s hoping that the feature comes to the standard Twitter time-line soon.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/407/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/407/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/407/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=407&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/02/07/twitter-moves-to-protect-aginast-tinyurl-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/02/expand.png?w=300" medium="image">
			<media:title type="html">expand</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/02/contract.png?w=300" medium="image">
			<media:title type="html">contract</media:title>
		</media:content>
	</item>
		<item>
		<title>Mobile devices lowering web security</title>
		<link>http://blog.c22.cc/2009/02/07/mobile-devices-lowering-web-security/</link>
		<comments>http://blog.c22.cc/2009/02/07/mobile-devices-lowering-web-security/#comments</comments>
		<pubDate>Fri, 06 Feb 2009 23:17:56 +0000</pubDate>
		<dc:creator>ChrisJohnRiley</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[mobile computing]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://c22blog.wordpress.com/?p=397</guid>
		<description><![CDATA[It&#8217;s been over a month now since I finally made the move to an iPhone. For the last 6 months or so I&#8217;ve been using a Blackberry (with mixed results) but this was mostly business use. The one thing that struck me when I started using the iPhone for Internet use, reading blogs, and access [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=397&subd=c22blog&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-399" style="border:6px;margin:6px;" title="iphone_kbd1" src="http://c22blog.files.wordpress.com/2009/02/iphone_kbd1.jpg?w=254&#038;h=238" alt="iphone_kbd1" width="254" height="238" />It&#8217;s been over a month now since I finally made the move to an iPhone. For the last 6 months or so I&#8217;ve been using a Blackberry (with mixed results) but this was mostly business use. The one thing that struck me when I started using the iPhone for Internet use, reading blogs, and access services like twitter, was the keyboard. I know it sounds strange, but having to click through 3 different menus just to get to the special keys portion of the keyboard puts a serious dent in your typing speed. Once you&#8217;re used to things, then it&#8217;s OK to work with. However this started me thinking how many average users of the iPhone (or blackberry, Nokia, G1, &lt;insert current mobile device of the week here&gt;) have given up constantly typing their suitably complex web-mail or forum password and changed it to something easier and quicker to enter on a mobile keypad.</p>
<p>With things constantly moving towards mobile computing (like it or not) the input of passwords will become more and more of an issue. Devices are getting smaller and smaller, keyboard and input is moving from the standard layout, to miniature input, gestures, and handwriting recognition. These are difficult enough to deal with as it is, without having to make sure you get it 100% correct. After all, you can&#8217;t having a spelling mistake in your password and get away with it.</p>
<p>So, how long before we start to see a shift in password use on web-services to more mobile friendly passwords. For example, those displayed on the main iPhone keypad. This means no special characters or numbers. Unless the web-service forces strong passwords, users will go with convenience over security most of the time. This is just human nature. This increasingly limited input range will it easier to brute-force the passwords of mobile users and reduce overall security. Just as we&#8217;ve finally started to get the general public to embrace complex passwords. One step forward, and two steps back.</p>
<p>Hopefully this doesn&#8217;t spell a return to the use of &#8220;god&#8221;, &#8220;sex&#8221;, &#8220;love&#8221; and &#8220;secret&#8221; as our main passwords of choice.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/c22blog.wordpress.com/397/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/c22blog.wordpress.com/397/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/c22blog.wordpress.com/397/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/c22blog.wordpress.com/397/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/c22blog.wordpress.com/397/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/c22blog.wordpress.com/397/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/c22blog.wordpress.com/397/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/c22blog.wordpress.com/397/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/c22blog.wordpress.com/397/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/c22blog.wordpress.com/397/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.c22.cc&blog=1599597&post=397&subd=c22blog&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.c22.cc/2009/02/07/mobile-devices-lowering-web-security/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">ChrisJohnRiley</media:title>
		</media:content>

		<media:content url="http://c22blog.files.wordpress.com/2009/02/iphone_kbd1.jpg" medium="image">
			<media:title type="html">iphone_kbd1</media:title>
		</media:content>
	</item>
	</channel>
</rss>