Tag Archive for Windows

A Rocking Windows Evening

A Rocking Windows EveningMSFT has decided that if you can find 9 friends that don’t mind being pitched, you could be chosen to host a Windows 7 House Party and win a free signed copy of Windows7. There are four pre-defined categories for the Windows 7 party: PhotoPalooza, Media Mania, Setting up with Ease, and Family-Friendly Fun. To help spark the partying, MS has posted a unique 6-minute-long video guide to help you get that party rocking…

If the video doesn’t give you enough ideas, the good folks at Download Squad have developed The Windows 7 Party Buzzword Drinking Game [to be played responsibly, of course].

  • Mentioning ‘jumplists’ – Take a drink.
  • ‘Better than Vista’ – Everyone takes a drink.
  • Mentioning any product whose name contains the word ‘Live’: Everyone takes a drink.
  • Saying any product name containing more than 2 words: finish your drink.
  • Mentioning any product name containing more than 4 words: finish your drink, and neck another.
  • ‘My Mac does that already’ – Everyone finishes their drink, and you neck another.
  • Windows crashes: the party’s over. But if there’s any surplus alcohol left, we’d hate to see it go to waste….

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Lessons From A Mega Data Breach

Updated 04-05-09 Wired is reporting that on August 28, 2009, accused hacker, Albert Gonzalez accepted a plea agreement with federal prosecutors in Boston. According to the report’s Gonzalez has agreed to plead guilty to all the charges in a 19-count indictment and will face a sentence of 15 to 25 years for master-minding the mega data breach. He’s also agreed to forfeit nearly $3 million in cash as well as a Miami condo, a BMW car, a Tiffany diamond ring and three Rolex watches that he gave to others as gifts, a Glock 27 firearm seized from him at the time of his arrest and a 350C currency counter, among other items.

The agreement resolves the case against Gonzalez in Massachusetts — which charged him with hacking into TJX, Barnes & Noble, and OfficeMax — as well as a case in the eastern district of New York that charged him with hacking into the Dave & Busters restaurant change. There are still outstanding charges alleging that Gonzalez also hacked into Heartland Payment Systems, Hannaford Brothers, ATMs stationed in 7-11 stores, and two unnamed national retailers.

Gonzalez is scheduled to officially enter his plea at a court hearing on September 11. His lawyer, Rene Palomino, did not return calls seeking comment from the New York Times.

Updated 08-30-09 – On 08-24-09 The Financial Times reported that Gonzalez and crew penetrated a network linking 2,200 Citibank-branded ATMs kiosks inside 7-Eleven stores from late 2007 through to at least February 2008. The ATMs displayed Citibank’s logo. The network and the machines were owned by Texas-based CardTronics, which took in monthly fees from Citi. Reportedly the group lifted card and PIN codes from the system, and their allies manufactured new cards that were used to get about $2m in cash from Citibank ATMs elsewhere. An FBI affidavit said Yuriy Ryabinin of Brooklyn withdrew $750,000 from Citibank accounts in February 2008.

Lessons From A Mega Data BreachThe U.S. Department of Justice handed down an indictment in the Heartland Payment Services data breach on August 17, 2009.  The Heartland, data breach is the largest data theft on record in the U.S. The Feds allege that beginning in October 2006, 28-year-old Albert Gonzalez, aka “segvec,” “soupnazi,” and “j4guar17,” of Miami, FL, and his unnamed co-conspirators, in Russia and Virginia executed the Heartland data breach. This attack led to the theft of over 130 million credit and debit cards accounts. Gonzales faces two counts of conspiracy and conspiracy to engage in wire fraud.

Heartland Payment Systems data breach

accused hacker, Albert Gonzalez

In addition to stealing credit and debit card data from New Jersey-based Heartland Payment Systems; the conspirators also targeted 7-Eleven Inc., and Hannaford Brothers, a supermarket chain based in Maine, along with two other major national retailers whose names were withheld. According to the Government planning for the attacks began in 2006. The indictment says that in October of 2006, Gonzalez and his co-conspirators began to search for potential corporate victims by gathering intelligence such as the credit and debit card systems used by their targets.

7/11 data breach

In August 2007, 7-Eleven was hit with a SQL injection attack which resulted in an undetermined number of accounts being compromised. In November 2007, Hannaford reportedly detected a Trojan designed to skim magnetic stripe information from the checkout stations. This attack compromised 4.2 million accounts. Beginning on or about Dec. 26, 2007, Heartland was hit with a SQL injection attack on its corporate network that resulted in malware being placed on its payment processing system and the theft of more than 130 million credit and debit card numbers and corresponding card data.

According to the indictment, Gonzalez and his cohorts exploited vulnerabilities that are typically in many cybercrime cases. SQL injection attacks were used to insert specially crafted malware designed to evade detection. Once inside the corporate networks, the attackers used sniffers to conducted reconnaissance, find and steal credit and debit card numbers, and other information. According to the DOJ, the group tested their malware by putting it up against about 20 different anti-virus programs. The group used computers in California, Illinois, Latvia, the Netherlands, and Ukraine to stage attacks and store malware and stolen information.

Could have been defended against

While the attacks seem to be phased-in and coordinated, the attackers used classic and well-known methods that could have been defended against, experts say.  Robert Graham, CEO of Errata Security told Dark Reading that the attacks outlined in the indictment basically offer a roadmap for how most breaches occur, “This is how cybercrime is done,” Graham says. “If there is a successful attack against your company, this is roughly what the hackers will have done. Thus, this should serve as a blueprint for your cyber defenses.”

In a Dark Reading article, Rich Mogull, founder of Securosis, says the attacks were preventable, mainly because they employed common hacking techniques that can be foiled.  He points out that the attacks seem to mimic those in an advisory issued by the FBI and Secret Service that warned of attacks on the financial services and online retail industry that targeted Microsoft’s SQL Server. The advisory included ways to protect against such attacks, including disabling SQL stored procedure calls. “This seems to be a roadmap” to these breaches, Mogull says. “The indictment tracks very closely to the nature of attacks in that notice.

The attack took planning and organization, but ultimately it was done with relatively common attack techniques,” said Rohit Dhamankar, director of DVLabs at TippingPoint in an eWeek article, “It just goes to show that even the most basic type of attack can do serious damage and enterprises need to be more vigilant about protecting the outward-facing portions of their networks.

Rick Howard, intelligence director for iDefense, told Dark Reading that enterprises still aren’t closing known holes in their networks and applications. “They were using the same stuff that works all the time,” he says. “And it’s [an example of] another organization not diligent in closing up [vulnerabilities] we know about.”

Prevention

Upesh Patel, vice president of business development at Guardium, told Dark Reading the attackers must have exploited applications with authenticated connections to the database. “Since a SQL Injection attack exploits vulnerabilities in the database, the attack could have occurred from any end-user application that was accessing the database.

Errata’s Graham says the initial attack vector, SQL injection, is often dismissed by enterprises as unimportant. “We always find lots of SQL injection [flaws] with our clients. We talk to them about it, but get push-back from management and developers who claim SQL injection is just a theoretical risk.

As a fix, Graham recommends, ”The simple solution is to force developers to either use ‘parameterized’ queries or ‘sanitize’ input.” He also suggests that SQL-based servers be hardened. “Once they got control of the database, they were able to escalate the attack to install malware on the systems. The simple solution is to remove all features of the database that aren’t needed,” he says, such as “xp_cmdshell,” which attackers commonly abuse. Graham goes on to suggest that anti-virus doesn’t catch custom malware like the attackers wrote for their attacks, so add policies and technologies that can spot unknown threats.

Gonzalez crews’ alleged use of their own sniffers that copied card data from the network could have been thwarted with encryption according to Richard Wang, Sophos Labs‘ U.S. manager. Wang tells InternetNews that the data should have been encrypted while in transit on the wire.

Sopho’s Wang says that the databases need to be secured, “Businesses should secure the application code, and make sure that the underlying server and operating system are up to date with the latest patches.” Securosis’ Mogull says not to use a privileged account for the relational database management system. In a blog post, Mogull says to deploy data leakage protection to see if you can detect any card data internally before the bad guys find it, and l to focus on egress filtering.

This was preventable,” Securosis’ Mogull says of the major breaches. “There was some degree of sophistication — like they knew HSMs — but definitely the main way they got in is not the most sophisticated.

Gonzalez, who is in federal custody, faces a maximum sentence of 20 years in prison on wire fraud conspiracy, and another five years on conspiracy, plus $250,000 for each charge. In May 2008, the U.S. Attorney’s Office for the Eastern District of New York charged Gonzalez with an alleged role in the hacking of a computer network run of restaurant chain Dave & Buster’s. The trial on those charges is scheduled to begin in Long Island, N.Y., in September.

In August of 2008, the Department of Justice announced more indictments against Gonzalez and others for a number of retail hacks affecting eight major retailers and involving the theft of data related to 40 million credit cards. Those charges were filed in the District of Massachusetts. Gonzalez is scheduled for trial on those charges in 2010.

rb-

The work we do on behalf of our clients often includes many of the steps highlighted in this incident. We always insist that vendors harden any servers brought on to a client’s site and that unnecessary services be removed. Before we recommend the Owner accept any installation, the vendor has to fully patch the OS and any applications provided. More recently we have started to include internal and external facing port scans.

Heartland Payment Systems Reports Breach

TJX Hacker Charged With Heartland, Hannaford Breaches

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

Nokia Tries Wireless Electricity

Nokia Tries Wireless ElectricityIf someday the researchers at Nokia (NOK), are right you will be able to use wireless electricity to charge your mobile. Putting your cell phone in standby mode may no longer cause the dreaded vampire power. Vampire power is often described as pointlessly wasting electricity with little benefit other than a small red light and instant start-up.

Nokia logoAccording to an article in the UK’s Guardian, Nokia is developing a mobile phone charging system that is able to power itself on nothing more than ambient radiowaves that constantly surround us. The Guardian article points out that radiowaves power the old crystal radio sets and modern radio frequency identification (RFID) tags.

Nokia claims that its system is able to scavenge enough ambient electromagnetic radiation emitted from Wi-Fi transmitters, cell-phone antennas, TV towers, and other sources miles away to run a cell phone. Individually the energy available in each of these signals is minute, but by harvesting radio waves across a range of frequencies it all adds up, said Markku Rouvala, one of the researchers who developed the device at the Nokia Research Center in Cambridge, UK.

Nokia’s device uses a wide-band antenna and two very simple passive circuits. The design of the antenna and the receiver circuit makes it possible to pick up frequencies from 500 megahertz to 10 gigahertz and convert the electromagnetic waves into an electrical current. The second circuit is designed to feed this current to the battery to recharge it.

Even if you are only getting microwatts (mW), you can still harvest energy, provided your circuit is not using more power than it’s receiving,” Rouvala told Technology Review. So far the researchers have been able to harvest up to 5 mW. Their next goal is to get in excess of 20 mW, enough power to keep a phone in standby mode indefinitely. but not enough to actually use the phone to make or receive a call the researcher says.  Rouvala says that his group is working towards a prototype that could harvest up to 50 mW of power, enough to slowly recharge a switched-off phone.

Earlier this year, Joshua Smith at Intel and Alanson Sample at the University of Washington, in Seattle, developed a temperature-and-humidity sensor that draws its power from the signal emitted by a 1.0-megawatt TV antenna 4.1 kilometers away. This only involved generating 60 mW.  Smith says that 50 mW could need around 1,000 strong signals and that an antenna capable of picking up such a range of frequencies would cause efficiency losses along the way.

Harry Ostaffe, head of marketing for Pittsburgh-based company Powercast, which sells a system for recharging sensors from about 15 meters away with a dedicated radio signal told Technology Review, “To get 50 milliwatts seems like a lot.

If Nokia’s claims stand up, then it could push energy harvesting into mainstream consumer devices and improve their environmental footprint. Steve Beeby, an engineer and physicist at the University of Southampton, U.K., who has researched harvesting vibrational energy, adds, “If they can get 50 milliwatts out of ambient RF, that would put me out of business.” He says that the potential could be huge because MP3 players typically use only about 100 milliwatts of power and spend most of their time in lower-power mode.

According to Technology Review. Nokia is being cagey with the details of the project, but Rouvala is confident about its future: “I would say it is possible to put this into a product within three to four years.” Ultimately, though, he says that Nokia plans to use the technology in conjunction with other energy-harvesting approaches, such as solar cells embedded into the outer casing of the handset.

rb-

As I have chronicled in the past and here, wireless power is a good solution looking for a way to be implemented. Wireless power has now hit the GartnerHype-Cycle.” According to the July 2009 Gartner Hype-Cycle, Wireless Power has just entered the “Peak of Inflated Expectations” zone and is still 5-10 years from mainstream adoption. 

This technology holds many benefits to the environment (less wasted electricity) and user convenience (how many proprietary power adapters do you have?), it is yet to be seen if consumer demand can overcome the inertia of the status quo and the power of big money lobbying by the coal, nuclear and utilities. Right now my money is on the money.

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

RIP Windows XP

Updated – 08-08-08 Business PC buyers are still overwhelmingly opting for Microsoft’s (MSFT) Windows XP according to HP (HPQ). Rob Kingston, Group Manager of Commercial Product Marketing for HP said in an article in APC, “Looking into the crystal ball, I don’t think businesses will see much value in upgrading to Vista until late next year, and even so, Microsoft will probably have come out with something else by then.”

RIP Windows XPToday 06-30-08 was the last day Windows XP was officially available for purchase from retail outlets, major resellers, and OEM hardware manufacturers. That of course does not mean XP is completely gone. There is still a handful of ways to get your mitts on XP.

  • Users that have Vista Ultimate and Vista Business licenses can choose to downgrade to Windows XP if they wish. Dell (DELL) is offering the downgrade option through January 31, 2009, and HP will offer the XP downgrade option on most of its business desktops and notebooks through at least July 30, 2009.
  • Smaller software resellers will be able to sell Windows XP until January 2009, they just can’t buy any more copies.
  • Another place to look would be eBay, as always, Caveat emptor.
  • Microsoft will continue to sell XP for ultraportable laptops or Nettops such as the ASUS (2357) Eee.

Microsoft says it will continue to offer tech support for Windows XP until the end of 2009 and offer limited support in some form until 2014 by then, Microsoft should have released Windows 7, the next version of its desktop OS.

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedIn, Facebook, and Twitter. Email the Bach Seat here.

Anti-Spyware Best Practices

·Anti Spy-ware Best PracticesAnti Spy-ware Best PracticesMake a spyware protection company policy. To protect your business’s best interests, anti-spyware protection should be required software on every computer.

Use more than one anti-spyware application

Regardless of what anti-spyware vendors claim, you almost always need more than one program to protect against a lot of adware and spyware. Experts say the best protection you can get is only probably around 70% using a combination of the two leading anti-spyware programs.

Use a centrally managed anti-spyware solution

Centrally managed software usually works best for companies with more than just a handful of computers. Spyware protection is no different. There are several vendors, such as Webroot and CA, which offer such software. If you have roughly 10 or more Microsoft (MSFT) Windows-based computers and want to save time, effort, and money in the long term, you should definitely consider this route.

Use a layered defense

The best defense against any information threat is a layered defense. You have a greater chance of defending against spyware if you use anti-spyware software combined with anti-virus software, personal firewalls, and host anomaly detection/intrusion prevention software. You can even help prevent infections at the network perimeter by utilizing spam and content filtering for inbound emails.

Lockdown your systems

A spyware defense that deserves separate mention is to configure Windows and Internet Explorer to be more secure. There are simple things you can do that will make a world of difference. For starters, make sure your systems are configured to be “hardened” from the elements. Roberta Bragg has written extensively on this topic at SearchWindowsSecurity.com. These hardening tricks are very easy to implement, and you can even push a lot of them out via Active Directory Group Policies.

Also, configure Internet Explorer (or whichever browser you use) to have pop-up blocker protection. This feature is built into most new browsers, and there are several well-known third-party applications for this. A good one for Internet Explorer is the free Google toolbar. It not only blocks most pop-up ads that harbor spyware, it also serves as a quick and convenient way to perform Google queries while browsing the Internet.

Use a more secure browser

Internet Explorer is a huge target for pop-ups, phishing, executable code, and other hacker vectors. If possible, use a more secure Web browser such as Firefox or Opera. These browsers likely have 99% or more of the functionality your users need with less hassle.

Install anti-spyware protection before new computers are deployed

Rather than installing spyware protection and cleaning utilities after you suspect infections, put it on systems before they’re deployed into the wild. For existing systems, simply install your favorite anti-spyware application such as Spybot Search and Destroy, Ad-Aware, or PestPatrol (or a combination of two or more). Let the software clean your systems and simply keep it running full-time in the background to act as a preventative layer to keep your systems protected.

Protect every Windows-based system on your network

Anti-spyware software is no longer just for workstations – it needs to be on servers, laptops, and any system running Windows – regardless of whether or not they are networked. Windows is the OS of choice for most spyware infections (at least for now) so make sure every single Windows-based system has protection.

Remote users might not be receiving updates

If you have remote users, remember that their systems may not be receiving the proper anti-spyware and other software updates.

Educate your users

User gullibility, ignorance, and carelessness are the main causes for infection. People clicking “yes” or “OK” in pop-up windows allowing software to be installed opens up the floodgates. Downloading and running seemingly innocuous programs doesn’t help the cause either. Educate your users on what to do and what not to do. Give them examples of what can happen when spyware infects a computer and how that relates to their everyday job functions. It’s amazing how much buy-in you can get using this technique.

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.